Privacy notice
This notice explains how Fleur Lamont Ltd (“we”, “us”) collects and uses personal data when you visit lw.fleurlamont.com, submit the contact form, or use Lamont Works (the Service).
Fleur Lamont Ltd (company number 15762771) is registered in England and Wales. Registered office: 82A James Carter Road, Mildenhall, IP28 7DE. Operations are based around Cramlington, Northumberland. For privacy questions: [email protected].
1. Who this covers
- Website visitors — people browsing the marketing site.
- Enquirers — people who send a message via the contact form.
- Account users — operators invited to use Lamont Works (login required).
Lamont Works is built for business use. It is not directed at children. Do not use the Service if you are under 18.
2. What we collect
2.1 Website and contact form
- Name, email, company name, and the message you type on the contact form.
- Technical request data our servers or security tools may log (for example IP address, user agent, timestamps) to operate and protect the site.
- Analytics for the public marketing pages: the page visited, the referring page, and general device, browser and screen information. Your IP address is processed to derive an approximate country or region and to tell repeat page views apart. No cookie is set and nothing is stored on your device. See section 10.
2.2 Account and workspace data
If you have an account, we process data needed to run the Service, which may include:
- Account details (name, email, authentication credentials, MFA settings where used).
- Operational records you or the Service create: leads, contacts, organisations, tasks, notes, documents, approvals, decisions, key dates, financial entries, and similar business records.
- Chat and assistant messages, drafts, and related AI outputs.
- Event and provenance records (actions taken, AI model usage, approximate cost) used for audit and governance.
- Integration tokens and settings you connect (for example calendar or email credentials), stored for the purpose of providing those features.
- Channel identifiers where you link messaging (for example Telegram chat identity) so we can deliver alerts and accept commands.
3. How we use it (and lawful bases)
Under UK GDPR we rely on these bases as appropriate:
- Contract — to provide Lamont Works to account holders and related support.
- Legitimate interests — to reply to enquiries; secure and improve the Service; understand in aggregate how the public pages are used, using cookieless analytics that identify nobody; keep audit/provenance records that support human approval of AI-assisted actions; prevent abuse. We balance these against your rights.
- Consent — where we ask for it. We do not rely on consent for the analytics described in section 10, because it stores nothing on your device.
- Legal obligation — where the law requires us to retain or disclose information.
We do not sell personal data.
4. Contact form routing
Messages from the public contact form are sent to our automation workflow (n8n.fleurlamont.com) so we can email and message Glen Birkbeck about your enquiry. We use that data only to respond and, if relevant, discuss Lamont Works with you — not for unsolicited bulk marketing lists.
5. AI processing
Lamont Works uses AI models to help draft content, summarise, classify, and assist with operational tasks. Content you enter (and context the Service assembles) may be sent to model providers so those features work. We record provenance of AI use where the product is designed to do so.
Outbound actions that leave your organisation (email, publishes, and similar) are intended to require human approval in the product. AI assists; humans decide.
Model providers may process data outside the UK or European Economic Area. We are working toward stronger EU residency for inference; until that is fully in place, some AI processing may involve international transfers (see section 7).
6. Who we share data with
We share personal data only as needed to run the Service, for example:
- Hosting — infrastructure providers that host Lamont Works and its database (currently including servers in the EU, such as Hetzner).
- AI / model routing — providers used to call language models (for example OpenRouter and the underlying model hosts they route to).
- Email delivery — transactional and operator email (for example Mailjet, or a mailbox provider you connect).
- Messaging — Telegram (or similar) when you connect a channel.
- Calendars and other connectors — Google, Zoho, or similar when you authorise them.
- Payments — Stripe if billing applies to your account.
- Our automation — n8n for contact-form handling as described above.
- Content delivery and network protection — Cloudflare, which proxies requests to this site and to our analytics endpoint and therefore handles connection data in the path.
- Professional advisers or authorities — where required by law or to protect rights.
Processors act on our instructions. If the business is sold or reorganised, data may transfer as part of that transaction under appropriate safeguards.
7. International transfers
Where providers process data outside the UK/EEA, we rely on appropriate safeguards (for example the provider’s standard contractual clauses or an adequacy decision) where required. Ask us if you need more detail about a specific processor.
8. Retention
- Contact form enquiries — kept as long as needed to handle the conversation and for a reasonable follow-up period, then deleted or minimised.
- Account and workspace data — for as long as the Service is used for that account / workspace. Ask us if you want specific records deleted; we aim to act within one month, subject to legal retention needs.
- Chat and assistant messages — stored for operational continuity. There is currently no automated deletion period; contact [email protected] to request deletion.
- Financial, approval, and provenance / audit records — may be retained longer (including around six to seven years where tax or accountability requires) because they support human approval of AI-assisted actions and statutory needs.
Ask [email protected] if you need clarity for a specific dataset.
9. Security
We use access controls, encrypted transport (HTTPS), and operational practices appropriate to a small UK software product. No system is perfectly secure. Tell us promptly if you suspect unauthorised access to your account.
10. Cookies and similar technologies
- Essential — the logged-in app needs session / authentication storage to keep you signed in and secure. These are necessary for the Service.
- Preferences — we may store a consent or preference flag in local storage (for example cookie-consent choices) so we remember your decision.
- Analytics — the public marketing pages use Umami, which we host ourselves on our own infrastructure. No data goes to Google or to an advertising network. It sets no cookie and stores no identifier on your device, so it loads without a consent prompt — the consent requirement attaches to storing or reading information on your device, and this does none of that. What it records is in section 2.1.
The public marketing pages carry no advertising trackers. If you would rather not be counted at all, any standard tracker blocker will stop the script loading, and the pages work normally without it. Browser controls can block cookies; blocking essential auth cookies will prevent login.
11. Your rights
Under UK GDPR you may have the right to:
- access your personal data;
- rectify inaccurate data;
- erase data in certain circumstances;
- restrict or object to certain processing;
- data portability, where applicable;
- withdraw consent where processing is based on consent.
To exercise these rights, email [email protected]. We aim to respond within one month.
The in-app account data export covers your login/account and related platform records. Operational workspace data (for example leads, contacts, notes, and product chat) is available on request via the same address while we continue to develop full self-serve export.
You can complain to the Information Commissioner’s Office (ICO). We would appreciate the chance to resolve concerns first.
12. Changes
We may update this notice. The “Last updated” date at the top will change when we do. Material changes will be reflected on this page; continued use of the Service after updates means you should review the revised notice.
13. Contact
Fleur Lamont Ltd (company number 15762771)
Registered office: 82A James Carter Road, Mildenhall, IP28 7DE, United Kingdom
Operations: Cramlington, Northumberland
Privacy / data protection: [email protected]
General enquiries: [email protected]
Product site: https://lw.fleurlamont.com