Privacy Policy
Last updated 3 August 2026
LegacyLift (“LegacyLift”, “we”, “us”) helps organisations modernise legacy software. We take privacy seriously. This policy explains what personal data we collect, why, and the rights you have over it.
Who this applies to
This policy covers visitors to our website and people who contact us to request access or a demo. Where we act as a processor of a customer's data under a separate agreement, that agreement governs how we handle it.
Information we collect
Information you give us. When you request access or book a demo, we collect the details you submit:
- Your name
- Your work email address
- Your company or organisation
- What you choose to tell us about your systems and needs
Information collected automatically. We collect basic technical and usage data (such as pages viewed, approximate location from IP, and device or browser type) to keep the site running and understand how it is used.
Customer content. If your organisation becomes a customer, we process the source code and data you provide solely to deliver the service. This content is executed only inside an isolated, network-egress-free environment and is not used to train shared models.
How we use your information
- To respond to your request and communicate with you about LegacyLift
- To provide, secure, maintain, and improve our website and services
- To keep records for our legitimate business and compliance needs
- To comply with legal obligations
We do not sell your personal data, and we do not use customer content for advertising.
Legal bases (UK GDPR / GDPR)
Where the UK GDPR or EU GDPR applies, we rely on one or more of the following bases: your consent; our legitimate interests in operating and promoting our business (balanced against your rights); performance of a contract with you or your organisation; and compliance with a legal obligation.
Sharing and disclosure
We share personal data only with:
- Service providers who process it on our behalf under contract (for example, hosting, database, and email providers), and only as needed to provide the service
- Authorities or third parties where required by law, or to protect our rights, safety, or property
- A successor entity in the event of a merger, acquisition, or reorganisation
International transfers
Where personal data is transferred outside the UK or EEA, we put appropriate safeguards in place (such as an adequacy decision or standard contractual clauses) to protect it.
Data retention
We keep personal data only for as long as necessary for the purposes described here, to meet legal or contractual requirements, and to resolve disputes. When it is no longer needed, we delete or anonymise it.
Security
We protect data with encryption in transit, access controls, and least-privilege practices. Untrusted code is executed only in an isolated, sandboxed environment with no network egress, and control-plane secrets are never exposed to it. No system is perfectly secure, but we work hard to protect your information.
Your rights
Subject to applicable law, you may have the right to access, correct, delete, or restrict the processing of your personal data; to object to processing; to data portability; and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority (in the UK, the Information Commissioner's Office). To exercise any of these rights, contact us using the details below.
Cookies
We use a small number of cookies and similar technologies that are essential to run the site, and may use privacy-respecting analytics to understand usage. You can control cookies through your browser settings.
Children
Our website and services are intended for organisations and are not directed at children. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you.
Contact us
For any privacy question or to exercise your rights, contact us at privacy@tanveersingh.dev.