PRIVACY POLICY
Privacy at Levqor
Controlled-proving revision: 11 September 2026
This policy covers LEVQOR LTD's website, First Three application/customer-account processes, support/security administration and the bounded Levqor Pipeline data flows. Professional prospect research and outreach is explained in the separate Business Contact Privacy Notice.
1. Controller identity
LEVQOR LTD is a private limited company registered in England and Wales, company number 16834717, registered office 252 Staines Road, Ilford, England, IG1 2UP. Levqor is a controller where it determines the purposes and means of its website, account, administration, security, prospect research, marketing, suppression and service-management processing.
2. Data we may handle
- business identity, authorised-representative, work-contact and account information;
- First Three application, target profile, exclusions, scope and customer-input information;
- meeting qualification, provenance, attendance, acceptance/dispute and settlement evidence;
- billing-document/payment identifiers and accounting records, without Levqor needing to store full card credentials;
- support, troubleshooting, privacy-request and customer-visible activity records;
- security, audit, request/device/network and abuse-prevention information where generated or necessary;
- preference, objection, unsubscribe and suppression records.
First Three does not require special-category personal data for ordinary prospecting and Levqor does not intentionally seek it for that purpose.
3. Purposes and lawful bases
We process data to answer enquiries and take pre-contract steps; create and secure customer accounts; assess fit and freeze scope; provide, evidence and settle an agreed service; prevent fraud/abuse; operate support and troubleshooting; meet accounting/legal obligations; protect or defend rights; respect marketing objections; and improve service reliability. Depending on the activity, the lawful basis may be contract/pre-contract steps, legitimate interests, legal obligation or consent. PECR requirements are assessed separately from UK GDPR lawful basis.
4. Business-contact data
For indirectly sourced professional contact information, sources, transparency timing, subscriber/channel checks and suppression are described in the Business Contact Privacy Notice. A public source does not create a blanket permission to use personal data.
5. Customer and prospect roles
Levqor and a customer may each be independent controllers for different purposes. A customer receiving a qualified-meeting handoff is responsible for its own subsequent sales use where it determines that use. Processor terms apply only where the facts require Levqor to process personal data solely on documented customer instructions.
6. AI
Controlled AI-assisted tools may support research, drafting, help or analysis. Public AI is not permitted to invent private project, meeting or payment status. Model confidence is not evidence. The current First Three design does not authorise solely automated decisions producing legal or similarly significant effects about an individual.
7. Sharing and providers
We may use service providers for hosting, authentication, communication, payments, analytics/security or other necessary functions and may share data with professional advisers or authorities where lawful and necessary. We do not sell personal data. Provider/subprocessor claims are published only when current evidence supports them.
8. International transfers
Where a provider processes personal data outside the UK, Levqor assesses the actual destination and applicable transfer mechanism and applies the safeguards required by law. We do not claim a transfer mechanism merely because it appeared in historic documentation.
9. Retention
Records are retained only as long as justified by service delivery, accounting/legal requirements, fraud/security, dispute/evidence needs and suppression. Direct-marketing data is reviewed for relevance/freshness. Minimal suppression information may be retained after ordinary prospect data is no longer needed so an objection is not lost through rediscovery.
10. Security
Levqor applies proportionate access, authentication, least-privilege, validation, audit, rate-limit and other security controls appropriate to the service. Customer users must protect authentication links and credentials and report suspected compromise. The Security & Privacy Posture limits public claims to evidenced controls.
11. Your rights
- access personal data
- correct inaccurate personal data
- request erasure where the law provides that right
- restrict processing in applicable circumstances
- object to processing based on legitimate interests
- object at any time to direct marketing
- receive portable data where the right applies
- withdraw consent where consent is the lawful basis
Authenticated customers should use the customer-portal privacy controls where available. Those controls show whether an action was merely validated or actually executed, so the current controlled-proving implementation does not pretend data was exported or deleted when execution is disabled. Public/prospect requests can use the privacy contact route. You may complain to the Information Commissioner's Office.
12. Direct marketing objection
You may object to direct marketing at any time. We stop the relevant use and retain only the minimum suppression information reasonably needed to prevent re-contact for that purpose.
13. Cookies and storage
See the Cookie & Storage Technologies Policy. Non-essential storage/access technologies require the applicable consent where the law requires it.
14. Contact and release caveat
The authenticated customer portal is the preferred route for account-related privacy controls. The published privacy role mailbox is a fallback contact route; its current end-to-end delivery remains unverified until fresh delivery proof closes. This notice does not itself authorise prospect outreach, payment execution, public distribution or broader commercial activation.
15. Changes
We review this notice when purposes, providers, system behaviour or legal requirements materially change and update it before beginning a materially new use where required.