LZ ← Back to site
Legal

Privacy Notice

Version 1.0 · Last updated 1 September 2026

The short version

  • This website sets no cookies. There is no cookie banner because there is nothing to consent to.
  • Nothing is stored in your browser. No local storage, no session storage, no fingerprinting.
  • The contact form does not send us anything. It opens a draft in your own email application. Nothing reaches us until you press send.
  • Analytics are aggregated and cookieless. We cannot identify you from them.
  • One third party sees your IP address simply because you loaded the page: Cloudflare, who host it. Nothing else is loaded from anywhere else — the typefaces are served from this domain.
01

Who is responsible for your data

Latitude Zero is the data controller for the personal data described in this notice. Latitude Zero is the impact strategy practice of Arun Rasuri, based in London, England.

We are not required to appoint a Data Protection Officer, and have not appointed one. Enquiries about this notice go to the address above.

Before publishing — confirm these details. Add the registered company name and number if Latitude Zero trades through a limited company, and add the ICO registration number if one is held. Most UK organisations processing personal data electronically must register with the Information Commissioner's Office and pay an annual data protection fee; sole traders keeping only basic contact records for their own correspondence are sometimes exempt. Check your position at ico.org.uk.
02

What this website collects

Directly, nothing. This site is a single static page. It runs no server-side code of its own, has no database, no user accounts and no login. It sets no cookies and writes nothing to your browser's storage.

The light and dark appearance follows your operating system setting. That preference is read from your browser and never recorded or transmitted.

Personal data reaches us only in the ways set out in sections 03 and 04.

03

The contact form, and how it actually works

The form on the home page is not a normal web form. When you press Request a Conversation, nothing is transmitted to us or to any server. The details you typed are assembled into a draft message and handed to whichever email application your device uses.

That draft sits in your own email programme. We receive nothing unless you choose to send it. If you close the draft, your details go no further — we never see them, and there is no copy anywhere on this website.

Once you do send it, the message is ordinary email, and section 04 applies.

04

When you contact us

If you email, telephone or send us the form draft described above, we hold what you chose to tell us. Typically that is your name, your organisation, your email address or telephone number, and whatever you wrote about your goals.

Why we are allowed to hold it

Our lawful basis is legitimate interests under Article 6(1)(f) UK GDPR: you approached us about professional services, and we have a clear interest in reading and answering you. You would reasonably expect us to. If a conversation becomes an engagement, we rely on performance of a contract under Article 6(1)(b), and on legal obligation under Article 6(1)(c) for the records tax and accounting rules require us to keep.

What we do with it

What we do not do with it

05

Third parties involved in running this site

Loading this page necessarily reveals your IP address to the company that serves it. This is how the web works, but you are entitled to know who they are. This site deliberately keeps that list to one.

WhoWhat they seeWhyWhere
Cloudflare, Inc.
Hosting & CDN
Your IP address, browser type, the page requested, and the time. Held in short-term security and performance logs. To serve the page, and to protect it from attack and abuse. Global network, including servers outside the UK.
Cloudflare Web Analytics Aggregated page views and referrers. No cookies, no fingerprinting, no cross-site tracking, no individual profiles. To know roughly how many people visit and which pages they read. As above.
Cloudflare Web Analytics is deliberately chosen over cookie-based analytics: it counts visits without identifying visitors, which is why this site needs no consent banner.
The typefaces used on this site (Fraunces, Archivo and IBM Plex Mono) are served from this domain rather than from Google Fonts. Your browser therefore makes no request to Google, and no data reaches Google, when you view this site.
06

Transfers outside the United Kingdom

Cloudflare is established in the United States and operates a global network, so some of the data described above is processed outside the UK. Cloudflare relies on recognised safeguards for these transfers — the UK Extension to the EU–US Data Privacy Framework, and the International Data Transfer Addendum to the European Commission's standard contractual clauses.

Any email you send us is held in our business email account, which may also be operated on infrastructure outside the UK under equivalent safeguards.

07

How long we keep things

WhatHow long
An enquiry that does not become an engagementUp to 24 months from our last exchange, then deleted.
Correspondence during an active engagementFor the engagement, then as below.
Records with a tax or accounting purposeSix years from the end of the relevant financial year, as UK law requires.
Cloudflare security and performance logsShort retention set by Cloudflare, not by us.
AnalyticsAggregated counts only. Nothing that could identify you exists to retain.

You can ask us to delete your details sooner. See section 08.

08

Your rights

Under the UK GDPR you have the right to:

To exercise any of these, email arun@latitudezero.uk. We will respond within one month. There is no charge, unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data

Please tell us first — we would rather put it right directly. You also have the right to complain to the UK supervisory authority at any time:

09

Security

This site is served only over an encrypted HTTPS connection, with HTTP Strict Transport Security enabled. It carries a content security policy restricting what the page is permitted to load, and further headers limiting how it can be embedded and what browser features it may use. It has no database and no administrative login, so there is no store of visitor data on this website to be breached.

Security issues can be reported to arun@latitudezero.uk. See /.well-known/security.txt.

10

External links

Where this site refers to other organisations, those organisations run their own websites under their own privacy notices. This notice covers only latitudezero.uk.

11

Changes to this notice

If this notice changes, the version number and date at the top will change with it. Material changes affecting people we already correspond with will be communicated directly.