Scope of this policy
This policy covers demandlabs.io, the public marketing website you are reading now. It explains what the website collects, what the DemandLabs planning platform would collect once you are a customer, and what you can ask us to do about it.
The authenticated product is governed separately. Where a customer organisation loads its own business data into DemandLabs, that processing is controlled by the agreement and data processing terms signed with that organisation, not by this page. If the two ever conflict, the signed agreement wins.
What this website collects
Close to nothing. These pages set no cookies, carry no advertising scripts, no third-party tracking pixels and no cross-site profiling, and nothing you read here is used to build a marketing profile of you.
The site is served through Cloudflare. Like any web server, that edge records ordinary request data so the site can be delivered and defended:
- IP address of the requesting client, which may be truncated or masked at the edge
- Requested URL, HTTP method, response status and byte count
- User agent string and, where sent by your browser, the referring page
- Timestamp of the request and the edge location that served it
We use those records for one purpose: keeping the site up and blocking abuse such as scraping floods and denial-of-service traffic. They are not joined to a marketing profile, not sold, and not used to build an advertising audience.
Cloudflare’s web analytics beacon also runs on the production domain. It is cookieless: it counts page views and page-load timings, it does not fingerprint your device, and it cannot follow you to any other site. It is the only measurement script on demandlabs.io, and blocking it changes nothing about how the site works for you.
The demo request form on the pricing page does not post to a DemandLabs server. It assembles the message locally in your browser and opens it in your own mail client, so nothing is submitted until you press send in your own email application. When you do, the message travels through your own email provider to us. We only ever see what you chose to send.
What the product collects
Once your organisation is a DemandLabs customer, the platform necessarily handles more. In broad terms:
- Account and identity data: name, work email address, organisation, role, and the group memberships your administrator assigns
- Authentication and audit records: sign-in events, permission changes, and a log of the planning actions each user takes
- Business planning data your organisation loads or connects: demand history, orders, inventory positions, supplier and network records, and the external signals you subscribe to
- Usage telemetry: which planning surfaces are used and how the system performs, so we can support and improve the product
For that business planning data DemandLabs acts as a processor. Your organisation decides what to load and what it is used for, and we process it on your organisation’s documented instructions. Personal data inside a customer tenant is the customer’s to correct or delete, and we will support them in doing so.
Why we process it
For website request logs, our basis is legitimate interest in operating and securing a website we publish. For business correspondence you start with us, it is the steps taken at your request before entering a contract, and thereafter the performance of that contract. For product data, it is the contract with your organisation, and their own lawful basis for the underlying records.
Where a jurisdiction requires consent for a specific activity, we ask for it before that activity begins rather than assuming it from continued browsing.
Who else sees it
We keep the list short and functional. Service providers see data only to the extent they must in order to deliver their part of the service, under written terms that bind them to confidentiality and to our instructions. Today those categories are:
- Cloud hosting and content delivery, for serving and protecting the site and the product
- Email and calendar providers, for the correspondence you start with us
- Business systems used to manage a commercial relationship, such as contract and billing records
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not disclose it to data brokers. If that ever changes, this page changes first, with notice.
We may disclose information where we are legally compelled to, and we will tell the affected party unless the law forbids it.
How long we keep it
- Edge request logs: a short operational window measured in days, then discarded or aggregated beyond identification
- Business correspondence: for the life of the commercial relationship and then for the period any applicable statute of limitations requires
- Customer platform data: for the term of the agreement, then deleted or returned within the window that agreement specifies
- Records we must keep for tax, accounting or legal reasons: for the period the relevant law requires, and no longer
Where deletion is not immediately possible because data sits in a backup, we isolate it from active use and let the ordinary backup cycle expire it.
International transfers
DemandLabs is built to keep customer data in the region its customer chooses. Where information does move between regions, for example when a support engineer in one country assists a customer in another, we rely on an approved transfer mechanism such as standard contractual clauses, together with practical measures like encryption in transit and at rest and access limited to named staff.
If your organisation has a data residency requirement, raise it during the commercial conversation. It is a configuration decision, not an exception.
Your rights
If the GDPR or UK GDPR applies to you, you can ask us to give you access to your personal data, correct it, delete it, restrict or object to how we use it, and provide it in a portable form. You may also withdraw a consent you gave, and complain to your national supervisory authority.
If the CCPA or CPRA applies to you, you can ask what personal information we have collected, request that we delete or correct it, and ask us to limit the use of sensitive personal information. You have a right not to be treated differently for exercising any of those rights. As noted above, we do not sell or share personal information for cross-context behavioural advertising, so there is nothing for an opt-out to switch off.
To exercise any of this, write to [email protected]. We will acknowledge within a few working days and answer substantively within one month, or tell you why we need longer. We may ask a question or two to confirm you are who you say you are, and we will not use those answers for anything else.
If the data sits inside a customer tenant, we will point you to the customer organisation that controls it and support them in responding.
Security
Data is encrypted in transit and at rest. Access is restricted to staff who need it for a specific task, granted through named accounts with multi-factor authentication, and logged. The platform supports single sign-on, directory-driven provisioning, and row-level permissions so a customer can constrain who sees what inside their own tenant.
No system is perfect. If we ever suffer a breach affecting personal data, we will notify affected customers and, where required, the relevant regulator, within the timeframes the applicable law sets.
Children
DemandLabs is enterprise software sold to organisations. The website and the product are not directed to children, and we do not knowingly collect personal data from anyone under sixteen. If you believe a child has sent us information, write to [email protected] and we will delete it.
Changes to this policy
This document will change, particularly before launch. The last updated date at the top of the page always reflects the current version. For material changes affecting customers, we will give notice through the account contacts on file rather than relying on you to re-read this page.
Privacy questions, access requests, deletion requests and anything else covered by this page go to one address, monitored by a person rather than a ticket robot.
[email protected]