Legal

Privacy Policy

This policy explains what personal information Lifugruna Limited, trading as Throughput Labs, collects through this website and during client engagements, why we collect it, and what rights you have over it.

Last updated: 18 September 2026

1. Who we are

This website is operated by Lifugruna Limited, trading as Throughput Labs ("Throughput Labs", "we", "us", "our"). We are a consulting firm providing enterprise workflow optimization services, delivered on-site and remotely through satellite teams across Europe and North America.

For the purposes of data protection law, Lifugruna Limited is the controller of the personal information described in section 3 of this policy. Where we handle personal information contained in client systems during an engagement, we generally act as a processor on the client's instructions — see section 5.

You can reach us about any privacy matter at [email protected].

2. Scope of this policy

This policy applies to:

  • Visitors to throughputlabs.ai and anyone who submits our enquiry form;
  • Representatives of prospective, current and former clients who correspond with us;
  • Individuals who apply to work with us or who interact with us in a business context.

It does not apply to third-party websites we link to, which operate under their own policies.

3. Information we collect

3.1 Information you give us

When you complete our enquiry form or contact us directly, we collect the information you choose to provide. That typically includes your name, job title, work email address, telephone number, organization name, organization size and sector, the systems you use, and the description of the process you would like us to look at.

Please do not include special category data, personal information about third parties, credentials, or confidential client material in an enquiry form. If you need to share sensitive material, contact us first and we will agree a secure channel and, where appropriate, a non-disclosure agreement.

3.2 Information collected automatically

Our hosting provider and our content delivery network record standard technical data when a page is requested: IP address, date and time, the URL requested, HTTP status code, referring URL, user-agent string and approximate location derived from the IP address. This data is generated by the infrastructure serving the site and is used for security, abuse prevention and diagnostics.

This website does not use analytics, advertising, tracking pixels or behavioural profiling, and it does not set cookies of its own. See our Cookie Policy for detail.

3.3 Information from engagements

During a client engagement we necessarily encounter business contact details of client personnel — names, roles, work email addresses, and records of who performed which step in a process. Where the process under review contains personal information about the client's own customers, employees or patients, we handle it under section 5.

4. How and why we use it

PurposeCategories usedLegal basis (UK/EU GDPR)
Responding to your enquiry and assessing whether we can help Enquiry form data, correspondence Consent; and our legitimate interest in responding to business enquiries
Negotiating, entering into and performing a consulting engagement Business contact details, engagement records Performance of a contract, or steps taken at your request prior to a contract
Operating and securing this website, preventing abuse Technical and server log data Our legitimate interest in the security and availability of our systems
Meeting legal, accounting, tax and regulatory obligations Engagement and billing records Compliance with a legal obligation
Establishing, exercising or defending legal claims Any of the above, as strictly necessary Our legitimate interest in protecting our legal position

We do not sell personal information, we do not share it with data brokers, and we do not use it to train artificial intelligence models.

We do not send marketing email to enquirers who have not asked for it. If we ever introduce a mailing list, it will be opt-in and every message will carry a one-click unsubscribe.

5. Client data during engagements

Our work involves reading process data inside client systems. Our standing practice is as follows.

  • We act on the client's instructions. Where we process personal information held in a client's systems, the client is the controller and we are the processor. A written data processing agreement governs that relationship.
  • We ask for the minimum access that makes the work possible. Access is scoped to the process under review, granted to named accounts under the client's own identity system, logged on the client side, and revoked at the close of the engagement.
  • We prefer data that is not personal at all. Where the analysis does not require identifiers, we ask for pseudonymized or aggregated extracts, and we redact or tokenize personal information before it reaches any model.
  • We do not move client data without agreement. Where residency or sensitivity requires it, work is performed inside the client's own environment, including fully self-hosted model inference with no external API calls in the data path.
  • We do not use client data for anything other than the engagement. It is not reused for other clients, not added to any product, and not used to train models.
  • Case studies are anonymized. Client names, identifying details and exact volumes are withheld, and we obtain agreement before publishing anything derived from an engagement.

6. Sharing and service providers

We keep our supplier footprint deliberately small. We may share personal information with:

  • Infrastructure and hosting providers that operate the servers and the content delivery network behind this website;
  • Business software providers used for email, document storage, scheduling and accounting;
  • Professional advisers such as lawyers, auditors and insurers, where necessary and under a duty of confidentiality;
  • Public authorities, where we are legally required to disclose information;
  • A successor entity, in the event of a reorganization, merger or sale of the business, subject to the protections in this policy.

Service providers act on our instructions under written terms and are not permitted to use the information for their own purposes.

7. International transfers

We operate through teams in several countries, and our service providers may process data outside the country in which you are located. Where personal information is transferred out of the United Kingdom, the European Economic Area or another jurisdiction with transfer restrictions, we rely on an appropriate safeguard — typically an adequacy decision, or Standard Contractual Clauses together with an assessment of the safeguards in the destination country.

You may request information about the safeguards applied to a specific transfer by writing to [email protected].

8. Retention

  • Enquiries that do not lead to an engagement: retained for up to 24 months from the last contact, then deleted.
  • Engagement records: retained for the duration of the engagement and then for the period required by applicable contractual, accounting, tax and limitation rules.
  • Client data accessed during an engagement: our working copies are deleted at the close of the engagement in accordance with the data processing agreement, other than material we are required to retain as evidence of the work performed.
  • Server and security logs: retained for a short operational period, typically not more than 90 days, unless a log is retained for the investigation of a specific incident.

9. Security

We apply technical and organizational measures proportionate to the sensitivity of what we hold. These include encryption in transit, encryption at rest for material held on our own systems, multi-factor authentication on all business accounts, least-privilege access with periodic review, endpoint protection and disk encryption on staff devices, and separation between client engagement environments.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority and affected individuals within the timeframes required by applicable law, and we will notify affected clients without undue delay under the terms of their data processing agreement.

10. Your rights

Depending on where you live, you may have some or all of the following rights in respect of your personal information:

  • Access — to be told whether we hold information about you and to receive a copy;
  • Rectification — to have inaccurate or incomplete information corrected;
  • Erasure — to have information deleted where there is no overriding reason for us to keep it;
  • Restriction — to limit how we use information in certain circumstances;
  • Objection — to object to processing carried out on the basis of legitimate interests, and to object to direct marketing at any time;
  • Portability — to receive certain information in a structured, machine-readable format;
  • Withdrawal of consent — where we rely on consent, to withdraw it at any time without affecting processing already carried out;
  • Non-discrimination — we will not treat you differently for exercising a privacy right.

To exercise a right, write to [email protected]. We will respond within the period required by applicable law — one month under the UK and EU GDPR, extendable where a request is complex. We may need to verify your identity before acting.

If your personal information sits inside a client's systems and we are acting as a processor, please direct your request to that organization. If you send it to us, we will forward it to them and assist them in responding.

If you are not satisfied with our response, you have the right to complain to your local data protection authority. We would appreciate the chance to address your concern first.

11. Cookies

This website does not set cookies of its own and does not use analytics or advertising trackers. Full detail, including the third-party requests the site makes, is in our Cookie Policy.

12. Children

This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Changes to this policy

We may update this policy to reflect changes in our practices or in the law. The "last updated" date at the top of the page always shows the current version. Where a change is material, we will take reasonable steps to bring it to the attention of clients and enquirers.

14. Contact us

For any question about this policy, or to exercise a right:

Lifugruna Limited, trading as Throughput Labs.

Questions about how we handle data?

We are happy to walk your security or privacy team through our access model before any engagement begins.