Skip to main content
Acumen Logic

Free

  • Dashboard
  • Assessments

Pro

  • Drills
  • Analytics
  • Upgrade
  • Help
  • Settings
  • Legal
  • Our website
U

User

  1. Acumen Logic
  2. /
  3. Legal
  4. /
  5. Privacy
Legal

Privacy Policy

Last updated: 27 July 2026

This Privacy Policy explains how Acumen Logic Ltd (“Acumen Logic”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit acumenlogic.co.uk or use the platform at app.acumenlogic.co.uk (together, the “Service”). It is written to comply with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”).

Data controller: Acumen Logic Ltd, a company registered in England and Wales (company number 16032469) with its registered office at 1 Factory Row, Beccles Road, Thurlton, Norwich, NR14 6AJ, United Kingdom. We are registered with the UK Information Commissioner’s Office under registration number ZC076851.

1. Quick summary

  • We collect what we need to run an account, score assessments, take payment and send service messages — nothing more.
  • We never sell your data.
  • Marketing emails are opt‑in only and you can withdraw consent at any time.
  • You can delete your account yourself in Settings, and request access, correction or an export of your data at support@acumenlogic.co.uk.
  • You can complain to the ICO at ico.org.uk at any time.

2. Information we collect

2.1 Information you give us

  • Account: name, email address, password (stored as a salted hash, never in plain text).
  • Profile (optional): target sector, target start date, education level, university, self‑assessed preparation level and weakest reasoning category — you can skip every page of the registration profile.
  • Email verification status: whether your email address has been verified, and the time at which it was verified.
  • Communications: the contents of any message you send to support or enquiries inboxes.
  • Marketing preference: a single opt‑in record kept against your account where you have consented to receive lessons, insights and occasional product offers from us. There is one marketing preference per account, which you can toggle at any time in Settings → Notifications.
  • How you heard about us: the referral‑source answer on the last page of registration.
  • Waiting‑list details: if you join a waiting list — including from the marketing site without an account — we keep the name and email address you give us, and whether you asked for marketing emails. See section 6 for how long, and how to have it removed.

2.2 Information generated by your use of the Service

  • Assessment data: the assessment type, your answers (including the option you selected, time spent on each question, whether you flagged it for review), your score, your category breakdown and your estimated percentile.
  • Drill data: drill session results, sub‑topic mastery and accuracy trends.
  • Activity: last login timestamp, in‑app notifications you have read, accessibility preferences (e.g. reduced motion, larger text).

2.3 Information collected automatically

  • Device and connection data: IP address, approximate location derived from IP, browser, operating system, referring URL.
  • Error data: minimal error‑capture metadata to keep the platform reliable (this runs whether or not you accept analytics cookies, on the basis of legitimate interest under UK GDPR Art. 6(1)(f) — see section 5).
  • Analytics: aggregated usage data — only if you accept analytics cookies. See the Cookie Policy.
  • Where you came from (attribution): if you arrive through a tagged link, we record the referral code and campaign tags that were in that link, the page you landed on and the time, in the al_attr cookie. This is set without asking for consent, because it describes the link rather than you — the reasoning is set out in the Cookie Policy. If you then create an account, that record is copied onto your account once, so we can credit the right partner or society. Legal basis: our legitimate interest in knowing which of our own marketing works and in paying partners correctly (Art. 6(1)(f)). You can object at any time using the contact details in section 12.
  • Security and account audit records: when you sign in, change your password or profile, delete your account, or make a purchase, we write an audit record of what happened, against your account ID. For sign‑ins we also record your IP address and browser user agent; the other events record neither. Legal basis: legitimate interest in account security and fraud prevention (Art. 6(1)(f)).

2.4 Payment data

Card details are entered directly with our payment provider, Stripe, on a page Stripe hosts. We never see or store your card number, and we do not store the last four digits either. What we keep is the Stripe transaction and customer reference, the amount paid, the currency, the plan purchased and the billing country code, so we can reconcile the order — that is all. The name and billing address you give Stripe stay with Stripe.

When you set a password we check it against the Have I Been Pwned breach database so we can warn you if it has appeared in a public breach. Your password never leaves our server: only the first five characters of a one‑way hash of it are sent, which cannot be used to work out the password.

3. Why we use your data and the legal basis

PurposeLegal basis (UK GDPR Art. 6)
Creating and running your account; providing assessments, drills and analytics; sending account‑related and assessment‑result emails.Performance of a contract with you (Art. 6(1)(b)).
Taking payment, issuing receipts, preventing fraud and meeting accounting obligations.Performance of a contract; legal obligation (Art. 6(1)(b) and (c)).
Calculating estimated percentile rankings and category benchmarks (which use your aggregated, de‑identified results alongside other candidates’).Performance of a contract; legitimate interest in the integrity of the benchmarking model (Art. 6(1)(b) and (f)).
Sending marketing emails about our products.Consent (Art. 6(1)(a)). You can withdraw at any time.
Running site analytics and product analytics to improve the Service.Consent for analytics cookies (Art. 6(1)(a) + PECR reg. 6); legitimate interest for first‑party usage logs that do not require cookies (Art. 6(1)(f)).
Securing the Service, detecting abuse and capturing minimal error data.Legitimate interest in operating a reliable, secure platform (Art. 6(1)(f)).
Recording which link or partner brought you to us, so we can credit them and measure our own marketing.Legitimate interest in understanding how people find us and in paying partners correctly (Art. 6(1)(f)). You can object — see section 12.
Complying with court orders, regulator requests or other legal duties.Legal obligation (Art. 6(1)(c)).

4. How we share your data

We do not sell your personal data. The recipients below fall into two groups. The first group are processors — they hold or handle data on our instructions under the data‑processing terms in their standard agreements. The second group are third parties whose content our pages load; they are not sent your account data, but because your browser fetches a file from them they will see your IP address and browser details. We list them so the picture is complete.

RecipientRoleLocation / transfer mechanism
SupabaseDatabase, authentication, file storageUK / EU (Frankfurt & London regions)
Stripe Payments UK LtdPayment processingUK (with onward transfers to Stripe Inc. in the US under SCCs + UK Addendum)
ResendTransactional email delivery (verification, receipts, results)US, under SCCs + UK Addendum
SentryError monitoring; session replay only when you accept analytics cookiesUS, under SCCs + UK Addendum
PostHogProduct analytics — only when you accept analytics cookiesEU instance; UK adequacy
UpstashRate limiting and short‑lived cachingEU regions; UK adequacy
VercelHosting of the platform applicationEU and US edge nodes; SCCs + UK Addendum where relevant
HostingerHosting of the marketing siteEU
Google Analytics (Google Ireland)Aggregated traffic measurement — only when you accept analytics cookiesEU/US; SCCs + UK Addendum
Have I Been PwnedChecking a new password against known public breaches. Receives only the first five characters of a one‑way hash of the password, sent from our server — never your email address and never your IP addressServed via a global content network
Google Fonts (content, not a processor)Serves the typeface used on acumenlogic.co.uk. Your browser requests the font file directly, so Google sees your IP address, browser details and the page you were on. This happens on page load, before any cookie choiceGoogle, global
Tailwind CDN (content, not a processor)Serves a styling script used on acumenlogic.co.uk. Same position as Google Fonts — the provider sees your IP address and browser details on page loadGlobal content network

We may also share data with our professional advisers (lawyers, accountants, auditors) where confidentially necessary, with regulators or courts when legally compelled, and with any successor entity in the event of a sale or restructure (subject to the protections in this policy).

5. International transfers

Some of the recipients above process data outside the UK. Where they do, we rely on one of the following safeguards:

  • The country has been recognised as providing an adequate level of protection by the UK government (e.g. EEA states under the UK adequacy regulations).
  • An International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, signed with the recipient.
  • For US recipients certified to it, the UK extension of the EU‑US Data Privacy Framework.

You can request a copy of the relevant transfer mechanism by contacting support@acumenlogic.co.uk.

6. How long we keep your data

CategoryRetention
Account details (name, email, profile fields)For the life of the account. When you ask us to delete your account, we schedule it and permanently delete everything 14 days later. Pro access ends straight away. The 14 days exist so you can change your mind — email us inside that window and we will stop the deletion. There is no automatic deletion of accounts that simply go unused.
Assessment and drill resultsFor the life of the account; deleted on account closure. Anonymous aggregated bucket counts contributed to the percentile model remain in our benchmarking dataset and cannot be linked back to you.
Purchase records (transaction reference, amount, currency, country code, plan, Stripe customer ID)7 years from the date of purchase, in an archive that survives account closure. Held to meet our HMRC record‑keeping obligations. Personal identifiers (your name, email and address) are not retained in this archive — the canonical customer record is held by our payment processor, Stripe.
Consent records (cookies, marketing, privacy policy acceptance)6 years from the consent event. We keep an append‑only audit trail of consents and withdrawals (timestamp, consent type and version, IP address, user agent) so we can evidence the lawful basis for processing.
Marketing preferenceHeld against your account while it is active and reflected in the live profile. The act of granting or withdrawing the preference is logged separately in the consent audit trail.
Support correspondence3 years from the date of the last interaction, held in our email provider and inbox archives. Cleanup is performed manually.
Account audit records (sign‑ins, password and profile changes, purchases; sign‑in records also hold an IP address and user agent)Kept for as long as we need them to investigate security incidents and payment disputes. We do not currently delete them on a fixed schedule. They survive account closure, but the link to your account is removed at that point, so what remains is not identifiable as yours. We are working to put a defined retention period on this; until then, you can ask us to erase yours using the contact details in section 12 and we will do so unless we need a specific record to defend a payment dispute.
Waiting‑list entries (name, email)Kept until the waiting list they belong to closes, or until you ask us to remove you — whichever is first. Signed‑in users can remove themselves. If you joined from the marketing site without an account, email us and we will delete it. Closing your account does not automatically remove a waiting‑list entry, so tell us if you want both gone.
Rate‑limiting records (IP address, email address)Held very briefly to stop abuse and automatically deleted — between 1 minute and 1 hour depending on the action, and 30 days for payment‑event records used to stop a payment being processed twice.
Server logs and error dataHeld at the hosting layer under our providers’ standard log retention; error and performance data in Sentry under Sentry’s standard retention. We do not set these periods ourselves, so we do not state a number we cannot enforce.

Retention is enforced by a daily automated cleanup process that removes archived purchase and consent records past their expiry window, and by a second daily process that permanently deletes accounts whose 14‑day deletion window has passed. Rows above that say we have no fixed schedule are exactly that — we would rather tell you than publish a period nothing enforces.

7. Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectification of inaccurate or incomplete data (Art. 16).
  • Erasure of your data in defined circumstances (Art. 17).
  • Restriction of processing in defined circumstances (Art. 18).
  • Portability — receive certain data in a structured, machine‑readable format (Art. 20).
  • Object to processing based on legitimate interest, including direct marketing (Art. 21).
  • Withdraw consent at any time, where we rely on consent. Withdrawal does not affect the lawfulness of prior processing.
  • Complain to the ICO (ico.org.uk) without going through us first.

Two of these you can exercise yourself, without asking us. In Settings → Profile you can correct your details. In Settings you can delete your account: it takes your password to confirm, cancels any Stripe billing immediately, and permanently deletes your data 14 days later.

For everything else — access, portability, restriction, objection — email support@acumenlogic.co.uk. We will respond within one calendar month and may extend that by up to two further months for complex requests, in line with UK GDPR Art. 12(3). A copy of your data is produced as a machine‑readable file, so a portability request is usually answered in days rather than weeks.

8. Security

We use TLS for all traffic, encrypted storage at rest, role‑based access on production systems, multi‑factor authentication for admin access, row‑level security on every personal‑data table in our database, and a documented incident response process. Reportable personal‑data breaches will be notified to the ICO within 72 hours of our becoming aware of them, and to affected users where the breach is likely to result in a high risk to their rights and freedoms.

9. Children

The Service is built for university students and graduates and is not directed at children. You must be at least 16 years old to create an account. We do not currently ask for or verify your age — the age limit is a condition of the Terms rather than something the sign‑up form checks. If we discover that we have collected data from a child under 16 without an appropriate basis, we will delete it. If you are a parent or guardian and believe a child has created an account, email us and we will remove it.

10. Automated decision‑making

Percentile rankings and category recommendations are generated by an automated model. They are indicative and do not produce legal or similarly significant effects on you within the meaning of UK GDPR Art. 22. They never form the basis of any decision taken about you by Acumen Logic that affects your legal position, your ability to use the Service, or any third‑party recruitment outcome.

11. Changes to this policy

If we change this policy, we will update the “last updated” date above. Material changes will be notified to active account holders by email or in‑app message at least 14 days before they take effect.

12. Contact

For privacy questions or to exercise any of your rights:

  • Email: support@acumenlogic.co.uk
  • Post: Acumen Logic Ltd, 1 Factory Row, Beccles Road, Thurlton, Norwich, NR14 6AJ, United Kingdom

If you are dissatisfied with our response, you can complain to the Information Commissioner’s Office: ico.org.uk · 0303 123 1113.