Privacy Policy
This policy explains what data we collect, why we collect it, how we use it, and the rights you have. We collect only what we need, and we never sell your data.
Last updated · May 7, 2026
Overview
LomiTech ("we", "us") operates lomitechs.com and provides software engineering services. We are the data controller for personal information collected through the site and the data processor for personal information handled on behalf of clients during engagements.
We comply with the General Data Protection Regulation (GDPR), the UK GDPR, and equivalent data-protection laws in the jurisdictions where we operate.
Data We Collect
Information you give us — name, email, company, project brief, and any details you submit through our contact form, support email, or during an engagement.
Information collected automatically — privacy-respecting analytics (page paths, referrer, country at country-level, device type). We do not use third-party advertising trackers.
Information from clients — when we work on a client's system, we may process personal data belonging to that client's end-users only as instructed by the client under a signed Data Processing Agreement.
How We Use Data
We use personal information to:
- Reply to inquiries and prepare proposals;
- Deliver the services agreed in a Statement of Work;
- Invoice and collect payment;
- Improve the site and product through aggregate analytics;
- Comply with legal, tax, and regulatory obligations.
We do not sell your data, and we do not share it with advertisers.
Legal Bases (GDPR)
We rely on the following legal bases under the GDPR:
- Contract — to negotiate and perform our service agreements;
- Legitimate interest — for analytics, fraud-prevention, and securing our infrastructure;
- Consent — for any optional marketing communications, withdrawable at any time;
- Legal obligation — to keep records required by tax or accounting law.
Retention
Inquiry data is retained for up to twelve months unless an engagement begins. Engagement records are kept for the duration of the engagement plus seven years to satisfy accounting and audit requirements.
Backups follow a rolling thirty-day window. When you request deletion, we remove your data from active systems immediately and from backups within that window.
Security
We protect data with encryption in transit (TLS 1.2+) and at rest, role-based access controls, MFA on all admin tooling, periodic access reviews, and security training for the team.
If we ever experience a data breach affecting your personal information, we will notify you and the relevant supervisory authority within 72 hours, in line with applicable law.
Your Rights
Depending on where you live, you have the right to: access the data we hold about you, correct inaccurate data, request deletion, restrict or object to processing, and request data portability.
You may also lodge a complaint with your local data-protection authority. To exercise any right, email contact@lomitechs.com — we respond within thirty days.
Children's Privacy
Our services are not directed at children under sixteen. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
Changes to This Policy
We may update this policy as our business evolves. We will post material changes here and update the "Last updated" date at the top. For significant changes, we will email registered clients.
Contact
For privacy questions, email contact@lomitechs.com. We treat every request seriously.
Questions about this policy?
Reach us at contact@lomitechs.com — we read every email.