Back to home

Legal

Privacy Policy

Last updated: 7 August 2026

1. Introduction

Re:Lab respects your privacy. This policy explains how we collect, use, store and protect personal data when you visit our investor portal or request access to our seed investment materials. It is written for a global audience and is designed to meet the standards of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Please read this policy carefully. By using the portal you acknowledge that you have read and understood it.

2. Who is the data controller?

Re:Lab is the data controller for the personal data processed through this portal. If you have questions about this policy or how we handle your data, please contact us at hello@relabwellness.com.

We may update our contact details from time to time. Any changes will be reflected on this page.

3. What personal data we collect

We only collect personal data that is necessary for managing investor access and communications. This includes:

  • Identity and contact details: first name, last name, email address, company, job title and country.
  • Verification information: email verification status and one-time passcode activity.
  • Agreement data: your typed legal name, electronic signature record, IP address, browser information and the date and time of NDA execution.
  • Usage data: pages viewed, deck viewing time, clicks, navigation paths and response submissions (such as “I’m interested”, “Book a call” or “Not the right opportunity”).
  • Technical data: IP address, browser type and device information, collected automatically for security and audit purposes.
  • Referral data: when you invite another prospective investor, we collect their email address and any personal note you choose to include.

4. How we use your personal data

We use your personal data to:

  • Verify your identity and grant secure access to the investor portal.
  • Record your electronic signature on our Non-Disclosure Agreement.
  • Provide the investor deck and track engagement so we can understand investor interest.
  • Respond to enquiries, schedule calls and manage investor relations.
  • Send you service-related emails, including verification codes, NDA confirmations and updates to this policy.
  • Send relevant investor communications where you have indicated interest or requested contact.
  • Maintain audit logs for security, legal and compliance purposes.
  • Detect and prevent fraud, misuse or unauthorised access.

5. Legal basis for processing

Under UK GDPR, we process personal data on the following legal bases:

  • Performance of a contract or steps before a contract: to provide access to the portal and the NDA, and to respond to investment interest.
  • Legitimate interests: to secure the portal, prevent fraud, understand investor engagement, improve our materials and manage investor relations.
  • Consent: where you have opted in to receive marketing or investor updates, or where you have invited another prospective investor to the portal.
  • Legal obligation: to comply with applicable law, regulation or court order, and to maintain records required for legal or tax purposes.

6. How we share your data

We do not sell your personal data. We may share it only in the following limited circumstances:

  • Service providers: trusted third parties that provide hosting, authentication, email delivery, analytics, storage and customer-relationship services. They are contractually bound to use your data only for the purposes we specify and to protect it in accordance with this policy.
  • Professional advisers: lawyers, accountants, auditors and insurers where necessary to protect our interests or comply with legal obligations.
  • Legal authorities: if required by law, court order or to protect our rights, property or safety.
  • Re:Lab personnel: authorised employees and administrators who need access to manage investor relations.

7. International transfers

Some of our service providers may process data outside the United Kingdom, including in the European Economic Area, the United States and other jurisdictions. Whenever we transfer personal data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses, adequacy decisions, or other legally recognised transfer mechanisms, so that your data remains protected to a standard equivalent to UK GDPR.

8. Data security

We take data security seriously. We use industry-standard technical and organisational measures, including encryption in transit, access controls, row-level security, audit logging and regular review of our systems. Despite these measures, no method of transmission over the internet or electronic storage is completely secure, so we cannot guarantee absolute security.

9. How long we keep your data

We keep personal data for as long as necessary for the purposes described in this policy, and to comply with legal, accounting and tax requirements. Typically, we retain:

  • Investor registration and verification data for the duration of our relationship with you.
  • NDA signatures and signed documents for at least six years after execution, to support legal claims and compliance.
  • Audit logs and site-visit records for up to two years, or longer if required by law or for security investigations.
  • Marketing preferences and correspondence until you withdraw consent or we no longer need the data.

When data is no longer needed, we securely delete or anonymise it.

10. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”): request deletion of your data in certain circumstances.
  • Right to restrict processing: ask us to limit how we use your data.
  • Right to data portability: receive your data in a structured, commonly used format and transfer it elsewhere.
  • Right to object: object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent: where we rely on consent, you may withdraw it at any time.
  • Right to complain: complain to the UK Information Commissioner’s Office (ICO) if you believe your rights have been breached.

To exercise any of these rights, please contact us at hello@relabwellness.com. We will respond within one month, or longer if permitted by law.

11. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, analyse how the portal is used and detect security issues. Some cookies are essential for the portal to function; others help us understand and improve the experience.

You can manage cookies through your browser settings. Essential cookies cannot be disabled without affecting portal functionality.

12. Children

The portal is intended for professional investors and is not directed at children under 18. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us and we will delete it promptly.

13. Changes to this policy

We may update this policy from time to time to reflect changes in law, our practices or the portal. The date at the top of this page shows when it was last revised. We encourage you to review it periodically. Continued use of the portal after changes means you accept the updated policy.

14. Contact us

For questions about this privacy policy, or to exercise your data protection rights, please contact:

Re:Lab Investor Relations
Email: hello@relabwellness.com

You also have the right to complain to the UK Information Commissioner’s Office: ico.org.uk.