Legal
Privacy Policy
This policy explains how Tibor Molnar, operating as EvolvingLane (“we”, “us”), collects and uses your personal information, and the rights you have under UK data-protection law. Tibor Molnar is the data controller.
It applies to evolvinglane.com, to newsletter subscriptions via evolvinglane.beehiiv.com, to our forms, audit requests and direct purchases, and to general interactions with EvolvingLane. Third-party platforms you use (such as Udemy or Beehiiv) may act as separate controllers under their own privacy notices.
Information we collect
Please do not send special-category information (such as health, biometric, political, religious or sexual-life data) unless we specifically request it and there is a clear reason for it.
- Identity and contact information: name, email, business name, social-media links, website URLs and any contact details you provide.
- Enquiry, audit and service information: your business stage, industry, offerings, revenue ranges, goals, challenges and related context.
- Transaction and contract information: products or services purchased, pricing, payment status, invoices, refunds and correspondence. We do not store full card numbers, payments are handled by the payment provider.
- Newsletter and marketing information: subscription status, consent records, email engagement, preferences and unsubscribe activity.
- Technical and usage information: IP address, device and browser data, pages visited, referrer, approximate location, cookie identifiers and analytics events (subject to consent).
- Communications and feedback: emails, form submissions, reviews, testimonials and support requests.
How and why we use it
We use your information to respond to enquiries; to deliver audits, courses, products and services; to process payments, invoices, refunds and disputes; to operate, secure and troubleshoot the website; to measure website and campaign performance; to send newsletters and offers where you have consented or where UK soft opt-in applies; to honour opt-outs; to keep tax, accounting and legal records; and to improve our services using aggregated feedback and usage patterns.
Our lawful bases are, depending on the activity: performance of a contract or pre-contractual steps; legitimate interests (running and protecting the business, responding to you, improving our services, preventing fraud and keeping records); consent (for non-essential cookies and most marketing); and legal obligation (tax, accounting and record-keeping).
Cookies and similar technologies
Necessary technologies operate without consent. Analytics and marketing technologies, including Google Analytics 4, run only with your consent. We use a consent tool (Cookiebot / Usercentrics) to present choices and record consent. You can accept, reject or adjust non-essential cookies at any time via the cookie banner or the permanent “Cookie settings” control. Withdrawing consent does not affect processing already carried out lawfully.
Marketing
We send newsletters, offers and educational content where you have consented, or where the UK soft opt-in lawfully applies to similar products and services. Every marketing email includes an unsubscribe link, and you can also email us to opt out. Unsubscribing from marketing does not stop necessary service messages about orders, accounts or resources you have requested. We keep a minimal suppression record so we don't contact you again after you opt out.
Automated tools and AI
We use software automation and AI tools to help organise form submissions, draft audit content, summarise information and support delivery. Outputs are reviewed by a person where appropriate. Please don't put confidential or unnecessary personal information into free-text fields. We do not make solely automated decisions that produce legal or similarly significant effects unless we tell you, identify a lawful basis and provide the safeguards the law requires.
Who we share it with
We share information only where reasonably necessary, with service providers and professional advisers, including: our website and forms provider (Carrd and identified form providers); our consent tool (Cookiebot / Usercentrics); analytics (Google Analytics 4, subject to consent); email and newsletter providers (Beehiiv and/or MailerLite); course delivery (Udemy or another platform identified at purchase); automation and business tools (Make, Google Workspace and OpenAI, where used for forms and audit content); and professional advisers such as accountants, lawyers, insurers and IT/security providers. We may also disclose information to regulators, courts or authorities where legally justified. We do not sell your personal information.
International transfers
Some providers process information outside the UK. Where UK law requires safeguards, we rely on adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the standard contractual clauses, or another lawful mechanism, with a risk assessment where required. Contact us for details of the safeguards for a specific transfer.
How long we keep it
- Enquiries that don't become customers: normally up to 24 months after last meaningful contact.
- Customer, order and contract records: normally six years after the relevant accounting period or contract, to meet tax and legal requirements.
- Audit inputs and working files: normally 12 months after delivery, unless a dispute or agreed follow-up applies.
- Marketing subscriptions: until you unsubscribe or withdraw consent, or we clean the list for inactivity.
- Suppression records: for as long as needed to honour your opt-out.
- Legal claims and complaints: for the applicable limitation periods while a matter is active.
Your rights
Under UK data-protection law you can: be informed; request access; correct inaccurate information; request erasure; restrict processing; object to processing; request portability; withdraw consent; and ask about safeguards for any qualifying automated decisions. To exercise a right, email us. We may need to verify your identity. We normally respond within one month, though complex or numerous requests may take longer. Some rights are not absolute and exemptions can apply.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We'd appreciate the chance to resolve things first, so please contact us before you do.
Security, children and changes
We use reasonable technical and organisational measures, including access controls, data minimisation, provider due diligence and backups. No system is completely secure. Our services are for adults and are not directed at children under 18; if you believe a child has provided information, let us know. We update this policy when our services, providers or legal obligations change, and material changes carry the revised effective date shown at the top.
This page reproduces the substance of our published policy. If anything here conflicts with your statutory rights, your statutory rights prevail.