Last updated: 27 July 2026
This Privacy Policy explains how Acumen Logic Ltd (“Acumen Logic”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit acumenlogic.co.uk or use the platform at app.acumenlogic.co.uk (together, the “Service”). It is written to comply with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
Data controller: Acumen Logic Ltd, a company registered in England and Wales (company number 16032469) with its registered office at 1 Factory Row, Beccles Road, Thurlton, Norwich, NR14 6AJ, United Kingdom. We are registered with the UK Information Commissioner’s Office under registration number ZC076851.
al_attr cookie. This is set without asking for consent, because it describes the link rather than you — the reasoning is set out in the Cookie Policy. If you then create an account, that record is copied onto your account once, so we can credit the right partner or society. Legal basis: our legitimate interest in knowing which of our own marketing works and in paying partners correctly (Art. 6(1)(f)). You can object at any time using the contact details in section 12.Card details are entered directly with our payment provider, Stripe, on a page Stripe hosts. We never see or store your card number, and we do not store the last four digits either. What we keep is the Stripe transaction and customer reference, the amount paid, the currency, the plan purchased and the billing country code, so we can reconcile the order — that is all. The name and billing address you give Stripe stay with Stripe.
When you set a password we check it against the Have I Been Pwned breach database so we can warn you if it has appeared in a public breach. Your password never leaves our server: only the first five characters of a one‑way hash of it are sent, which cannot be used to work out the password.
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Creating and running your account; providing assessments, drills and analytics; sending account‑related and assessment‑result emails. | Performance of a contract with you (Art. 6(1)(b)). |
| Taking payment, issuing receipts, preventing fraud and meeting accounting obligations. | Performance of a contract; legal obligation (Art. 6(1)(b) and (c)). |
| Calculating estimated percentile rankings and category benchmarks (which use your aggregated, de‑identified results alongside other candidates’). | Performance of a contract; legitimate interest in the integrity of the benchmarking model (Art. 6(1)(b) and (f)). |
| Sending marketing emails about our products. | Consent (Art. 6(1)(a)). You can withdraw at any time. |
| Running site analytics and product analytics to improve the Service. | Consent for analytics cookies (Art. 6(1)(a) + PECR reg. 6); legitimate interest for first‑party usage logs that do not require cookies (Art. 6(1)(f)). |
| Securing the Service, detecting abuse and capturing minimal error data. | Legitimate interest in operating a reliable, secure platform (Art. 6(1)(f)). |
| Recording which link or partner brought you to us, so we can credit them and measure our own marketing. | Legitimate interest in understanding how people find us and in paying partners correctly (Art. 6(1)(f)). You can object — see section 12. |
| Complying with court orders, regulator requests or other legal duties. | Legal obligation (Art. 6(1)(c)). |
We do not sell your personal data. The recipients below fall into two groups. The first group are processors — they hold or handle data on our instructions under the data‑processing terms in their standard agreements. The second group are third parties whose content our pages load; they are not sent your account data, but because your browser fetches a file from them they will see your IP address and browser details. We list them so the picture is complete.
| Recipient | Role | Location / transfer mechanism |
|---|---|---|
| Supabase | Database, authentication, file storage | UK / EU (Frankfurt & London regions) |
| Stripe Payments UK Ltd | Payment processing | UK (with onward transfers to Stripe Inc. in the US under SCCs + UK Addendum) |
| Resend | Transactional email delivery (verification, receipts, results) | US, under SCCs + UK Addendum |
| Sentry | Error monitoring; session replay only when you accept analytics cookies | US, under SCCs + UK Addendum |
| PostHog | Product analytics — only when you accept analytics cookies | EU instance; UK adequacy |
| Upstash | Rate limiting and short‑lived caching | EU regions; UK adequacy |
| Vercel | Hosting of the platform application | EU and US edge nodes; SCCs + UK Addendum where relevant |
| Hostinger | Hosting of the marketing site | EU |
| Google Analytics (Google Ireland) | Aggregated traffic measurement — only when you accept analytics cookies | EU/US; SCCs + UK Addendum |
| Have I Been Pwned | Checking a new password against known public breaches. Receives only the first five characters of a one‑way hash of the password, sent from our server — never your email address and never your IP address | Served via a global content network |
| Google Fonts (content, not a processor) | Serves the typeface used on acumenlogic.co.uk. Your browser requests the font file directly, so Google sees your IP address, browser details and the page you were on. This happens on page load, before any cookie choice | Google, global |
| Tailwind CDN (content, not a processor) | Serves a styling script used on acumenlogic.co.uk. Same position as Google Fonts — the provider sees your IP address and browser details on page load | Global content network |
We may also share data with our professional advisers (lawyers, accountants, auditors) where confidentially necessary, with regulators or courts when legally compelled, and with any successor entity in the event of a sale or restructure (subject to the protections in this policy).
Some of the recipients above process data outside the UK. Where they do, we rely on one of the following safeguards:
You can request a copy of the relevant transfer mechanism by contacting support@acumenlogic.co.uk.
| Category | Retention |
|---|---|
| Account details (name, email, profile fields) | For the life of the account. When you ask us to delete your account, we schedule it and permanently delete everything 14 days later. Pro access ends straight away. The 14 days exist so you can change your mind — email us inside that window and we will stop the deletion. There is no automatic deletion of accounts that simply go unused. |
| Assessment and drill results | For the life of the account; deleted on account closure. Anonymous aggregated bucket counts contributed to the percentile model remain in our benchmarking dataset and cannot be linked back to you. |
| Purchase records (transaction reference, amount, currency, country code, plan, Stripe customer ID) | 7 years from the date of purchase, in an archive that survives account closure. Held to meet our HMRC record‑keeping obligations. Personal identifiers (your name, email and address) are not retained in this archive — the canonical customer record is held by our payment processor, Stripe. |
| Consent records (cookies, marketing, privacy policy acceptance) | 6 years from the consent event. We keep an append‑only audit trail of consents and withdrawals (timestamp, consent type and version, IP address, user agent) so we can evidence the lawful basis for processing. |
| Marketing preference | Held against your account while it is active and reflected in the live profile. The act of granting or withdrawing the preference is logged separately in the consent audit trail. |
| Support correspondence | 3 years from the date of the last interaction, held in our email provider and inbox archives. Cleanup is performed manually. |
| Account audit records (sign‑ins, password and profile changes, purchases; sign‑in records also hold an IP address and user agent) | Kept for as long as we need them to investigate security incidents and payment disputes. We do not currently delete them on a fixed schedule. They survive account closure, but the link to your account is removed at that point, so what remains is not identifiable as yours. We are working to put a defined retention period on this; until then, you can ask us to erase yours using the contact details in section 12 and we will do so unless we need a specific record to defend a payment dispute. |
| Waiting‑list entries (name, email) | Kept until the waiting list they belong to closes, or until you ask us to remove you — whichever is first. Signed‑in users can remove themselves. If you joined from the marketing site without an account, email us and we will delete it. Closing your account does not automatically remove a waiting‑list entry, so tell us if you want both gone. |
| Rate‑limiting records (IP address, email address) | Held very briefly to stop abuse and automatically deleted — between 1 minute and 1 hour depending on the action, and 30 days for payment‑event records used to stop a payment being processed twice. |
| Server logs and error data | Held at the hosting layer under our providers’ standard log retention; error and performance data in Sentry under Sentry’s standard retention. We do not set these periods ourselves, so we do not state a number we cannot enforce. |
Retention is enforced by a daily automated cleanup process that removes archived purchase and consent records past their expiry window, and by a second daily process that permanently deletes accounts whose 14‑day deletion window has passed. Rows above that say we have no fixed schedule are exactly that — we would rather tell you than publish a period nothing enforces.
You have the right to:
Two of these you can exercise yourself, without asking us. In Settings → Profile you can correct your details. In Settings you can delete your account: it takes your password to confirm, cancels any Stripe billing immediately, and permanently deletes your data 14 days later.
For everything else — access, portability, restriction, objection — email support@acumenlogic.co.uk. We will respond within one calendar month and may extend that by up to two further months for complex requests, in line with UK GDPR Art. 12(3). A copy of your data is produced as a machine‑readable file, so a portability request is usually answered in days rather than weeks.
We use TLS for all traffic, encrypted storage at rest, role‑based access on production systems, multi‑factor authentication for admin access, row‑level security on every personal‑data table in our database, and a documented incident response process. Reportable personal‑data breaches will be notified to the ICO within 72 hours of our becoming aware of them, and to affected users where the breach is likely to result in a high risk to their rights and freedoms.
The Service is built for university students and graduates and is not directed at children. You must be at least 16 years old to create an account. We do not currently ask for or verify your age — the age limit is a condition of the Terms rather than something the sign‑up form checks. If we discover that we have collected data from a child under 16 without an appropriate basis, we will delete it. If you are a parent or guardian and believe a child has created an account, email us and we will remove it.
Percentile rankings and category recommendations are generated by an automated model. They are indicative and do not produce legal or similarly significant effects on you within the meaning of UK GDPR Art. 22. They never form the basis of any decision taken about you by Acumen Logic that affects your legal position, your ability to use the Service, or any third‑party recruitment outcome.
If we change this policy, we will update the “last updated” date above. Material changes will be notified to active account holders by email or in‑app message at least 14 days before they take effect.
For privacy questions or to exercise any of your rights:
If you are dissatisfied with our response, you can complain to the Information Commissioner’s Office: ico.org.uk · 0303 123 1113.