Privacy Policy

Last updated: 26 July 2026

1. Who we are

LMC TECH LTD ("we", "us", "our") is a private limited company registered in England and Wales.

We are the data controller for the personal data described in this policy. That means we decide how and why your personal data is used, and we are responsible for looking after it.

2. What this policy covers

This policy is deliberately a single document covering everything we do, rather than separate policies for each website and product. It applies to:

  • lmctech.co.uk and lmctraining.co.uk
  • Our web and software development services
  • Our AI readiness consultancy
  • Our training services
  • PackPilot (packpilot.lmctech.co.uk), our training pack generation service
  • Social Jen (socialjen.lmctech.co.uk), our social content and marketplace listing tool
  • Any other software or service we make available, unless we tell you at the time that different terms apply

This last point is deliberate. It means services we launch in future are covered from day one without us having to rewrite this policy, and without us naming products here before they are available to you.

Where a particular service handles data differently, this is set out in section 6.

This policy does not cover third-party websites we link to. Those have their own policies and we are not responsible for them.

3. The personal data we collect

3.1 Information you give us

3.2 Information we collect automatically

  • IP address
  • Browser type and version, device type, operating system
  • Pages visited, time spent, referring site
  • Cookie and similar identifiers (see section 11)
  • Log data from hosted services, such as sign-in times and errors

3.3 Information from third parties

  • Connected social media accounts. Where you connect an account, we receive limited profile information and access tokens from that platform. See section 7.
  • Payment providers. We receive confirmation that a payment succeeded or failed, along with limited details such as the last four digits of a card. We never receive or store full card numbers.

3.4 Special category data

We do not seek to collect special category data (such as health, ethnicity, or religious belief). Please do not send it to us unless we have specifically asked for it and explained why.

4. Why we use your data, and our lawful basis

Under UK GDPR we must have a lawful basis for each use of your data.

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not. You can ask us about that assessment, and you can object (see section 10).

5. What we do not do

To be explicit, because these are the questions people actually ask:

  • We do not sell your personal data. Ever, to anyone.
  • We do not use your content to train AI models, ours or anyone else's, and we use AI providers under terms that prevent them doing so either (see 6.3).
  • We do not use data from your connected social accounts for advertising.
  • We do not build profiles of you by combining data from outside sources.
  • We do not make automated decisions that produce legal or similarly significant effects about you.

6. PackPilot and other hosted services

Some of our services are hosted by us, meaning you create an account and your data is stored on infrastructure we operate. PackPilot works this way.

6.1 What we hold

6.2 How we use it

To operate the service, to support you when something goes wrong, and to keep the service secure. Our staff do not routinely read your content. Access is limited to those who need it, and where a support issue requires someone to look at your content we will normally ask you first.

6.3 Content generated with AI assistance

PackPilot builds packs using a structured template engine. Some sections are additionally refined using large language models.

We use two kinds of AI, and we think you should know which is which:

We use both because combining them gives better output than either alone.

What is sent to Google. Where the Gemini step runs, the information passed to it is limited to your session topic, audience, learning outcomes, organisation name, and compliance notes.

What is never sent to Google. Any policy text you supply is never sent to any model, ours or Google's. It is added to your documents directly afterwards. Your account details, payment information, uploaded logo, and contact details are also never sent.

Training. We use Google's paid API under terms which provide that content submitted through it is not used to train Google's models. We do not use your content to train any model, ours or anyone else's.

Where it goes. Google processes this content on its own infrastructure. See section 13 on international transfers.

If you would rather not. If your organisation cannot send content to a third-party AI provider, contact us at [email protected] before creating packs and we will discuss options.

If we change which AI providers we use, we will update this policy and tell account holders before the change takes effect.

6.4 Third parties involved in your data

To be specific about who else is involved, because "reputable cloud providers" tells you nothing useful:

PackPilot uses no analytics or tracking services, and no advertising or cross-site tracking cookies. A single essential cookie keeps you signed in.

Your account data, pack content, and files are held in a database and file storage that we manage directly, rather than being spread across third-party platforms.

6.5 Personal data about other people

Some documents PackPilot produces, such as attendance registers and certificates, are designed to hold the names of people attending your training. You may also choose to paste in your own organisational policies.

Where you put personal data about other people into PackPilot, you remain the controller of that data and we act as your processor. You are responsible for having a lawful basis to share it and for telling those people how their data is used. See section 16 of our Terms of Service.

Please do not enter more personal data than you need, and please do not enter special category data (such as health information about a participant) unless you have a specific lawful basis for doing so. Our services are not designed to hold it.

6.6 How long we keep it

We keep your account and its content for as long as your account is active.

If you close your account, or if it stays inactive for 24 months, we delete or anonymise your content within 90 days. We keep a minimal record that the account existed where we need it for accounting or legal reasons.

You can ask us to delete your data sooner. See section 10.

6.7 Social Jen

Social Jen (socialjen.lmctech.co.uk) is our social content and marketplace listing tool. It is currently in private early access and, like PackPilot, is hosted on servers we operate in the UK.

AI assistance. Social Jen drafts content using large language models. The material sent to the model is what you provide for drafting: your campaign topic, notes or imported text, product briefs, and product photos where you ask for a photo to be analysed for a listing. We currently use Groq (a US provider running open Llama models) alongside our own self-hosted models, under paid API terms which provide that your content is not used to train the provider's models. Your account details, connected-account tokens, and waitlist email addresses are never sent to any AI provider. If we change providers, we will update this policy.

The public page at socialjen.lmctech.co.uk sets no cookies and uses no analytics or tracking. The only personal data it collects is the email address you choose to give the waitlist form.

6.8 Locally-run software

Where we distribute software that runs entirely on your own computer, your content and any connected account credentials stay on your machine, are not transmitted to us, and we have no ability to access them. Deleting the software and its data removes them. We will tell you at the time where this applies to a particular product.

7. Connected social media accounts

Some of our software lets you connect your own social media accounts so that content you have created can be published to those accounts on your instruction.

7.1 What connecting means

You are taken to that platform's own login screen. We never see, receive, or store your password for any social media platform. The platform asks you to approve a specific list of permissions, and you can decline or cancel at any point.

7.2 What we receive

Social Jen can connect accounts on Facebook and Instagram (via Meta), TikTok, LinkedIn, X, YouTube, Threads, Reddit, and Bluesky. The pattern is the same for every platform: we receive an account identifier, basic profile information (so you can see which account you are about to post to), and access tokens scoped to the permissions shown on that platform's consent screen. We request only the permissions needed to publish content you have approved.

Platform specifics for the connections in use today:

Facebook and Instagram (Meta). Meta provides your user and Page identifiers, the details of the Facebook Pages and Instagram professional accounts you choose to connect, and Page access tokens. The permissions requested are limited to managing and publishing content on those Pages and accounts (for example pages_manage_posts and instagram_content_publish). We do not request access to your personal profile posts, friends, messages, or ad accounts.

TikTok. TikTok provides:

  • A user identifier (open_id), specific to our application and not usable to identify you on TikTok by anyone else
  • Basic profile information, such as display name and profile picture, used to show you which account you are about to post to
  • An access token and refresh token, allowing the application to publish content you have approved without you logging in each time

For TikTok the permissions are user.info.basic and video.publish.

Bluesky. Bluesky uses an app password that you create in your own Bluesky settings, rather than an OAuth consent screen. It is stored encrypted like any other token, and you can revoke it in Bluesky at any time.

Across all platforms: we do not read your posts, followers, messages, analytics, or any other account data beyond what is listed above, and we do not have permission to.

7.3 What we do with it

Solely to show you which account content will go to, to publish content you have created and approved, and to keep the connection active so you do not have to reconnect repeatedly.

We do not use it for advertising, we do not sell it, we do not train models on it, and we do not share it with third parties.

7.4 Where it is stored

Account identifiers and tokens are stored in Social Jen's database on our UK-based servers, with access and refresh tokens encrypted at rest. They are used only for the purposes in 7.3, are never shared with third parties, and are deleted when you disconnect the account.

7.5 Content you publish

Content you choose to publish is sent directly to the platform's own API. Once published it is governed by that platform's terms and privacy policy, not ours. Publishing only ever happens as a result of an explicit action by you.

7.6 Disconnecting

You can disconnect at any time from within the software, which deletes the stored tokens and identifier for that platform.

You can also revoke access from the platform's own settings, independently of us. For TikTok: Settings and privacy, then Security and permissions, then Manage app permissions. For Facebook and Instagram: Settings, then Apps and websites (or Business integrations). Revoking there immediately stops the application from being able to post.

7.7 Third-party terms

Your use of a connected platform through our software is also subject to that platform's terms. For TikTok this includes the TikTok Terms of Service and the TikTok Privacy Policy. For Facebook and Instagram this includes the Meta Terms of Service, the Meta Privacy Policy, and the Instagram Terms of Use.

8. Payments

We take payment by Stripe, PayPal, and bank transfer against an invoice, depending on the service and what has been agreed. PackPilot uses Stripe only.

Where you pay by card or through PayPal, your payment details are entered directly with that provider and handled on their systems. We never receive or store your full card number. We receive confirmation of the payment and limited details needed for our records.

Stripe and PayPal are independent data controllers for the payment data they handle. Their own privacy policies apply:

Where we invoice you directly, we hold your billing details and payment records for as long as required by law (see section 9).

9. How long we keep data

Where we no longer need data, we delete it or anonymise it so it can no longer identify you.

10. Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data, which is what this policy is for
  • Access the personal data we hold about you
  • Rectification of data that is inaccurate or incomplete
  • Erasure of your data, in certain circumstances
  • Restrict processing of your data, in certain circumstances
  • Data portability, receiving your data in a portable format
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent at any time, where we rely on consent
  • Not be subject to solely automated decisions with legal or similarly significant effects

To exercise any of these, email [email protected]. We will respond within one month. That can be extended by two further months for complex requests, and we will tell you if that happens.

There is normally no charge. We may charge a reasonable fee, or refuse, if a request is manifestly unfounded or excessive, and we will explain why.

We may ask you to verify your identity before we act, to make sure we do not disclose your data to someone else.

Complaints

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 https://ico.org.uk/make-a-complaint/

11. Cookies

We use cookies and similar technologies on our websites. Non-essential cookies are only set with your consent, which you give through our cookie banner and can change at any time.

Full detail is in our Cookie Policy: https://lmctech.co.uk/cookiep.html

12. Sharing your data

We share personal data only where necessary, and only with:

  • Service providers who help us operate, such as hosting providers, email providers, payment processors, and accountants. They act on our instructions and are bound by contract.
  • Professional advisers, such as accountants, insurers, and lawyers.
  • Authorities, where we are required to by law, or to establish, exercise, or defend legal claims.
  • A buyer, if we sell or reorganise the business. We would tell you, and this policy would continue to apply until replaced.

We do not sell personal data and we do not share it for third-party marketing.

13. International transfers

Our infrastructure is entirely UK-based. Our hosted services run on servers in London, provided by OVHcloud and Linode (Akamai). Your account data, pack content, and uploaded files are stored in the UK.

Some of the third parties we work with are based outside the UK, specifically:

  • Stripe and PayPal, for payments (United States)
  • Google, for Gemini AI processing as described in section 6.3
  • Groq, for Social Jen AI drafting as described in section 6.7 (United States)

Where personal data is transferred outside the UK, we make sure it is protected by one of:

  • An adequacy decision by the UK government covering that country
  • The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses
  • Another safeguard permitted by UK data protection law

You can ask us for details of the safeguards used for a specific transfer.

14. Security

We take appropriate technical and organisational measures to protect your data, including encryption in transit, encryption of sensitive credentials at rest, access controls limiting who can see what, and keeping our systems patched.

No system is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours, and tell you directly where the risk is high.

Please help by using a strong, unique password and telling us immediately if you think your account has been compromised.

15. Children

Our services are for business use and are not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.

Where we deliver training to under-18s, we do so under a separate agreement with the commissioning organisation, which will set out how data is handled.

16. Changes to this policy

We may update this policy. Changes are posted on this page with an updated revision date. Where a change materially affects your rights, we will take reasonable steps to tell you directly.

17. Contact

Questions, requests, or complaints about this policy or your data:

Email: [email protected] Post: LMC TECH LTD, C/O ABC Accounting Services, 1 Willoughton Place, Wharton Close, Gainsborough, Lincolnshire, England, DN21 1EB Web: https://lmctech.co.uk/contact/