Version 0.1 (draft) — dated 2026-07-18. This document has not yet been reviewed by a solicitor and must not be relied on as final.

Privacy Policy

Status: DRAFT v0.1 — 2026-07-18. Not yet reviewed by a solicitor. Do not publish to the live site until legal review is complete and all [PLACEHOLDER] fields are filled in.

This privacy policy explains how Embedism Limited ("Embedism", "we", "us", "our"), trading as Factory London, collects, uses, and protects personal data belonging to visitors, customers, and prospective customers of the Factory London website and quoting service (the "Service").

We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are (the data controller)

Embedism Limited
Company number: 11939367(registered in England & Wales)
Registered office: Arch 534, Orphans Yard, Brixton Station Road, London SW9 8QB
Trading name: Factory London
Contact email for privacy queries: [PRIVACY CONTACT EMAIL — PLACEHOLDER, e.g. privacy@embedism.com]

Embedism Limited is the data controllerfor the personal data described in this policy and is registered with the Information Commissioner's Office as a data protection fee payer, registration reference ZB816836.

Data protection contact point

Given our size and the nature of our processing, we are not required by law to appoint a formal Data Protection Officer (DPO). We have nonetheless designated a voluntary internal contact point for data protection queries, reachable at the email address above. Any request relating to your personal data, or any question about this policy, should be sent there in the first instance.

2. Scope

This policy applies to personal data we process through:

  • the Factory London website ([DOMAIN — PLACEHOLDER, e.g. factory.london]);
  • the quote wizard and file upload flow;
  • order processing, production, and delivery/collection;
  • customer support correspondence (email, contact form);
  • magic-link access to quote/order status pages;
  • the staff administration area (for staff members' own account data — see §11).

It does not cover the practices of third-party sites we may link to.

3. What personal data we collect

We collect the following categories of personal data, depending on how you interact with us:

CategoryExamplesWhen collected
Contact detailsName, email address, phone number, company name (business customers)When you request a quote, create an order, or contact us
Delivery/billing addressStreet address, postcode, delivery instructionsWhen you choose delivery rather than collection
Uploaded design filesSTL, 3MF, STEP, DXF, SVG, PDF drawing files you upload for quotingWhen you upload a part in the quote wizard
Derived geometry dataBounding box, volume, surface area, cut-path length, pierce count, and similar measurements extracted from your files by our quoting engineAutomatically, when your file is analysed to generate a price
Order and payment recordsOrder reference, items, prices, VAT, quote history, and — because payment at launch is by bank transfer only — the payer name that appears on our bank statement when you send fundsWhen you place an order and make payment
CommunicationsEmails you send us, contact form submissions, notes staff make on your orderOngoing, as needed to service your order
Technical dataIP address, browser type, and equivalent data captured in server logs and essential cookies (see our Cookie Policy)Automatically, when you use the Service
Account-adjacent dataWe do not operate customer accounts or passwords. Instead, we issue single-use magic-link tokens by email so you can view and act on your quote or order. We store a hashed version of these tokens, plus their issue/expiry/use timestampsWhen a quote or order is created

What we do not collect

  • We do not collect or store card numbers, CVV codes, or other card payment data. At launch, the Service accepts bank transfer only; you pay directly via your own bank, and we never see your card details.
  • If we introduce card payments in future via Stripe, card data will be entered directly into Stripe's own secure payment interface and will not pass through or be stored on our servers. We will update this policy before that happens.
  • We do not knowingly collect special category data (e.g. health, biometric data) through the Service. Please do not include such information in file names, order notes, or messages to us.

4. How and why we use your data (lawful bases)

UK GDPR requires us to have a "lawful basis" for every purpose we process personal data for. The table below sets these out.

PurposeData usedLawful basis
Generating quotes and processing orders (including reviewed quotes for CNC/lathe work)Contact details, uploaded files, derived geometry data, order detailsPerformance of a contract (or steps taken at your request prior to entering a contract)
Producing and delivering your orderDelivery address, order detailsPerformance of a contract
Taking payment and matching bank transfers to ordersOrder reference, payer name on bank statement, payment amount/datePerformance of a contract; legal obligation (accounting)
Sending transactional emails (quote ready, order confirmation, dispatch notice, magic links, etc.)Contact details, order/quote referencePerformance of a contract
Keeping financial and accounting recordsInvoices, order/payment recordsLegal obligation (UK tax and companies legislation, incl. HMRC record-keeping requirements)
Detecting and preventing fraud, abuse, and misuse of the quoting engine (e.g. scraping, automated abuse, chargeback/payment-dispute risk)Technical data, order history, IP address, rate-limiting recordsLegitimate interests — protecting our Service, staff, and other customers from harm
Marketing to business customers (B2B) about our servicesBusiness contact detailsLegitimate interests — reasonable B2B marketing where you have an existing relationship with us and can opt out at any time
Marketing to consumer customersContact detailsConsent — we will only email consumer marketing if you have actively opted in, and you may withdraw consent at any time
Responding to enquiries and providing customer supportContact details, communications, order historyPerformance of a contract / legitimate interests
Improving the quoting engine and pricing accuracy (aggregated/anonymised analysis)Derived geometry data, order outcomesLegitimate interests

You have the right to object to processing based on legitimate interests — see §8.

5. Who we share your data with (processors and sub-processors)

We use a small number of trusted service providers ("processors") to run the Service. They only process personal data on our instructions, under a data processing agreement, and only for the purposes below.

ProcessorRoleData involvedLocation / international transfer safeguard
Vercel Inc.Website hosting, application runtimeAll data transmitted through the Service (in transit; not persisted beyond logs/caching)USA. Transfers are safeguarded by Vercel's UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, or an equivalent UK-recognised transfer mechanism
Neon Inc.Managed Postgres database (system of record for quotes, orders, customers, payments metadata)Contact details, order/quote data, derived geometry data, hashed magic-link tokensData residency depends on selected Neon region; where processing occurs outside the UK/EEA, transfers are safeguarded by IDTA/SCCs
Google LLC (Google Workspace / Google Drive)Storage of uploaded design files and staff production files; company email/workspaceUploaded design files, associated file metadata, staff account dataUSA (with EU/UK regional processing options under Google Workspace). Transfers safeguarded by Google's IDTA/SCC-based data processing terms
Resend (Resend Inc. / Resend Ltd, as applicable)Transactional email delivery (quote/order notifications, magic links)Contact details (name, email), transactional email contentUSA. Transfers safeguarded by IDTA/SCCs
Courier / delivery partner [PLACEHOLDER — name TBC]Delivery of physical ordersName, delivery address, phone number, order referenceUK (domestic delivery)
Stripe Payments Europe / Stripe Inc. (not yet active)Card payment processing — planned for a future phase; disabled at launchWould be limited to payment data entered directly into Stripe's interfaceUK/EEA with US group company; Stripe maintains its own IDTA/SCC-based safeguards. This policy will be updated, and consent/notice given as appropriate, before Stripe processing goes live

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

Where any processor is located outside the UK, we ensure an appropriate safeguard is in place before transferring personal data — principally the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, or reliance on a UK adequacy regulation, in line with Chapter V of the UK GDPR.

6. How long we keep your data (retention)

We keep personal data only for as long as necessary for the purposes it was collected for, and in line with our legal obligations.

Data typeRetention periodNotes
Quote data and uploaded files for quotes that are not accepted (expired, withdrawn, or abandoned in draft)2 yearsIncludes both the database record and the associated Google Drive files, deleted after this period
Uploaded files and geometry data for accepted orders[PLACEHOLDER — default: 2 years from order completion]Kept to support re-orders and warranty queries, unless you ask us to delete them sooner. You may request earlier deletion at any time (see §8); we will retain the minimum order/financial record required by law regardless (see next row)
Financial and order records (invoices, payment records, order references, VAT records)6 yearsFrom the end of the relevant financial year — required under UK tax law (HMRC record-keeping requirements) and the Companies Act 2006
Email logs (transactional email delivery records)1 yearThen deleted. Used for delivery troubleshooting and fraud/abuse investigation
Hashed magic-link tokensDeleted on expiry/rotationAnd in any event no later than the retention period of the quote/order they relate to
Marketing consent records (consumer opt-in)Until consent is withdrawnPlus a short record of the withdrawal for compliance purposes
Staff account dataFor the duration of employment/engagement plus a standard HR retention periodGoverned by our internal HR policies, not this customer-facing policy

When a retention period expires, we delete or anonymise the data (see §12 for how this applies to account/order data specifically) rather than simply marking it inactive.

7. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls restricting staff access to what they need, hashed (not plaintext) storage of magic-link tokens, rate limiting, and input validation on all file uploads. Full detail is in our internal security design document (docs/07-security-gdpr.md), which is not customer-facing but is available on request in summary form.

No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices appropriate to a business of our size.

8. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

  1. Right to be informed — to know how your data is used (this policy).
  2. Right of access — to request a copy of the personal data we hold about you.
  3. Right to rectification — to ask us to correct inaccurate or incomplete data.
  4. Right to erasure ("right to be forgotten") — to ask us to delete your data, subject to our legal obligation to retain financial records for 6 years.
  5. Right to restrict processing — to ask us to pause processing in certain circumstances.
  6. Right to data portability — to receive certain data you provided to us in a structured, commonly used, machine-readable format, or to have it transmitted to another controller.
  7. Right to object — to object to processing based on legitimate interests or for direct marketing (and we will always stop direct marketing on request).
  8. Rights related to automated decision-making — our instant quoting engine (FDM and laser processes) automatically calculates a binding price using a documented pricing algorithm. You may ask a member of staff to review any automated quote, and reviewed processes (CNC/lathe) always involve staff-confirmed pricing.

How to exercise your rights

Email [PRIVACY CONTACT EMAIL — PLACEHOLDER] with your request, quoting your quote/order reference if you have one, so we can locate your data quickly. We may ask you to verify your identity before acting on a request.

We will respond within one month of receiving a valid request. This period may be extended by a further two months for complex or numerous requests, in which case we will tell you why within the first month.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You also have the right to complain to the UK's data protection regulator:

Information Commissioner's Office (ICO)
Water Lane, Wycliffe House, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk / ico.org.uk/make-a-complaint

9. Cookies

The Service uses only strictly necessary cookies (for example, to keep your magic-link session active and to protect forms against cross-site request forgery). We do not use analytics or marketing cookies at launch. Full detail is in our Cookie Policy.

10. Children

Factory London is a business-to-consumer and business-to-business manufacturing quoting service. It is not directed at, or intended for use by, individuals under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Staff and administration area

Staff members access an administration area using their embedism.com Google Workspace account. Staff account data (name, work email, login/session records) is processed as part of our employment relationship and internal IT security, on the lawful bases of legitimate interests and legal obligation (as applicable), and is outside the scope of this customer-facing policy.

12. Automated processing note

Uploaded design files are analysed automatically by our quoting engine to extract geometric measurements (e.g. volume, bounding box, cut-path length) used to calculate a price. For instant-quote processes (FDM, laser cutting) this results in an automated, binding price with no human review by default; you may contact us to ask a member of staff to check any quote. For CNC and lathe work, a member of staff always reviews and confirms the firm price before it becomes binding.

13. Changes to this policy

We may update this policy from time to time, for example to reflect a new processor (such as Stripe going live), a change in law, or a change in how the Service works. The "last updated" date below will change, and where changes are material we will take reasonable steps to bring them to your attention (e.g. a website notice or email to customers with live orders).

14. Contact

Questions about this policy or your personal data:

Embedism Limited
Arch 534, Orphans Yard, Brixton Station Road, London SW9 8QB
Email: [PRIVACY CONTACT EMAIL — PLACEHOLDER]

Document status: DRAFT v0.1, last updated 18 July 2026. This draft is prepared as part of the Factory London design package and must be reviewed by a qualified solicitor before publication. All fields marked [PLACEHOLDER] must be completed prior to publication.