Master Corporate Legal Policy · Omnibus Notice

Privacy Policy

Effective Date: 4 September 2026

This Master Privacy Policy explains how LVL DIGITAL VENTURES LTD ("we", "us", or "our") collects, uses, processes, stores, and protects personal information across all our business operations, commercial verticals, digital platforms, and consumer applications (collectively, the "Services").

LVL Digital Ventures Ltd operates as a venture studio and multi-discipline digital organization. To provide transparent data protection practices across all client touchpoints, customer journeys, and product ecosystems, this policy governs the following operational branches:

SaaS & Web Software

Cloud software platforms, web apps, automated venture systems (such as LVEL), API services, and team workspaces.

E-Commerce & Products

Direct-to-consumer and B2B online storefronts, digital product downloads, checkout gateways, and fulfillment pipelines.

Digital Agency & Consulting

Client design, engineering, marketing consultations, project deliverables, commercial contracts, and B2B communications.

Mobile Apps (iOS & Android)

Native applications distributed via the Apple App Store and Google Play Store, including device integrations and in-app features.

Regulatory & App Marketplace Governance:

This comprehensive policy satisfies the stringent requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the EU General Data Protection Regulation (EU GDPR), the Privacy and Electronic Communications Regulations (PECR), the California Consumer Privacy Act (CCPA/CPRA), as well as the developer mandates of the Apple App Store Review Guidelines (Guideline 5.1.1 & 5.1.1(v) Account Deletion) and the Google Play Developer Program Policy (User Data & Data Safety).

1. Who We Are (Data Controller)

LVL DIGITAL VENTURES LTD is the data controller responsible for the processing of your personal data under UK and EU data protection laws:

2. Categories of Information We Collect

We collect only the data necessary to provide our services, operate our ventures, fulfill orders, and maintain software reliability. The types of data collected depend on the specific business vertical you engage with:

A. SaaS Platforms & Web Software Applications

B. E-Commerce Storefronts & Digital Product Orders

C. Digital Agency Services & Commercial Client Engagements

D. Mobile Applications (iOS & Android)

E. Mobile Device Permissions (Optional & User-Controlled)

Certain mobile features require explicit operating system permissions. You retain full control to enable, modify, or revoke permissions at any time in your device's native Settings:

F. Corporate Website & General Inquiries

3. Payments & Financial Information

We maintain strict security separation for all commercial payment transactions across our web, e-commerce, SaaS, and mobile channels:

4. Lawful Bases for Processing (UK & EU GDPR)

We process personal data only when an established lawful basis exists under Article 6 of the UK GDPR and EU GDPR:

5. Zero Sale of Data & Tracking Safeguards

6. Third-Party Infrastructure & Sub-processors

We work exclusively with vetted enterprise infrastructure providers bound by rigorous Data Processing Agreements (DPAs) and industry security certifications (SOC 2 Type II, ISO 27001):

7. Account & Personal Data Deletion Requests

We provide comprehensive data autonomy across all our digital products, ensuring strict compliance with Apple App Store Guideline 5.1.1(v) and the Google Play Data Deletion Policy:

Universal Account & Data Deletion Instructions:

1. In-App Mobile Account Deletion: Within any LVL mobile application supporting account creation, you can delete your account directly inside the app by going to Settings > Account > Delete Account. This permanently removes your credentials and associated application data.

2. SaaS & Web Platform Deletion: In our SaaS platforms, workspace administrators or individual account holders can initiate complete profile and workspace deletion via the Account / Organization Settings dashboard.

3. Direct Email Deletion Request: You can submit an omnibus deletion request across any of our services (SaaS, e-commerce records, agency contacts, mobile apps) at any time by emailing our Data Protection Team at contact@lvldigital.co.uk with the subject "Data Deletion Request".

4. Processing & Verification: Verified deletion requests are executed across our active production systems within 30 days. Where applicable, statutory financial and tax transaction records (such as completed e-commerce sales receipts) are retained strictly as required by UK tax law (HMRC statutory retention) and then automatically purged.

8. Children’s Privacy Protection (COPPA, GDPR-K, Google Play Families)

Our platforms, digital products, e-commerce storefronts, agency services, and mobile applications are directed at general audiences and professionals. We do not knowingly collect, solicit, or maintain personal information from children under the age of 13 (or under 16 for residents of the UK and European Economic Area). If we learn that personal data of a child has been collected without verified parental consent, we take immediate action to permanently erase the information. Parents or guardians may direct inquiries or deletion requests to contact@lvldigital.co.uk.

9. Your Statutory Rights (UK GDPR, EU GDPR & CCPA/CPRA)

Under applicable international data protection legislation, you hold specific enforceable rights:

To exercise any statutory right, contact our team at contact@lvldigital.co.uk. We respond to all verified requests within 30 days without charge.

10. Data Security & Encryption Standards

We deploy rigorous technical, operational, and physical controls to safeguard your data against unauthorized access, loss, or alteration:

11. International Data Transfers

Where personal data is transferred or hosted outside the United Kingdom or the European Economic Area (EEA), we ensure appropriate safeguards are implemented. Transfers are governed by the UK International Data Transfer Agreement (IDTA), the UK Addendum, or the European Commission’s Standard Contractual Clauses (SCCs), guaranteeing that recipient entities uphold equivalent data protection levels.

12. Data Retention Schedules

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected:

13. Product-Specific Terms & Ancillary Notices

Individual digital products, specialized SaaS platforms (such as LVEL), or specific mobile applications developed by LVL Digital Ventures Ltd may display supplemental in-product terms or documentation detailing feature-specific data flows. Any such notices supplement and operate alongside this overarching Master Privacy Policy.

14. Changes to This Master Privacy Policy

We may periodically update this Master Privacy Policy to reflect technological improvements, new product launches across our venture studio, or regulatory changes. Any modifications will be posted to this page with an updated Effective Date. For material changes impacting active mobile app or SaaS users, we will provide conspicuous notice via in-app alerts, dashboard banners, or direct email notifications.

15. Contact Us & Regulatory Supervision

If you have any questions, concerns, or requests regarding this Master Privacy Policy or our data protection practices, please contact our Data Protection Team:

If you are a resident of the United Kingdom and believe your personal data has not been processed in accordance with the law, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.