L HAZARD LTD / L HAZARD STORE
Effective & updated: 21 September 2026 · Version 2026-09-21
L HAZARD LTD, company number 17352385, operates L Hazard Store and is responsible for the personal information used for our platform administration. Our registered office is 9 Caxton House, Broad Street, Cambourne, Cambridge, United Kingdom, CB23 6JN. Use Contact → Privacy & data rights, telephone +44 7863 748378, or write to that address to reach us about privacy.
A supplier, seller or other partner may be separately responsible for information it needs for its own services. Before a live service shares information with a new partner, the applicable role, purpose and notice must be made available. We do not treat all partners as having automatic access to your account.
You may provide your name, email address, organisation, contact details, enquiry subject and message, account profile, business verification documents, product records, requests for quotation, quotations and associated trade records. Saved products are linked to your signed-in account. Account administrators may provide invitation details and assigned roles.
The service also processes sign-in and security events, timestamps, session identifiers, request metadata and technical error information. The enquiry service uses a keyed security identifier derived from the connecting network address and email to limit abuse; it does not store the raw network address in the enquiry record. Infrastructure security logs may contain IP addresses.
We receive data directly from you, from an authorised organisation administrator, from counterparties participating in a workflow, and from our own service operation. Current public catalogue examples are demonstration records. Please do not send health information, identity documents, passwords, API keys or payment-card details through the general Contact form.
We use account and workspace information to provide requested facilities and take steps relating to a contract with you. Where you act as an employee or representative of an organisation, our legitimate interest is administering that business relationship and providing its requested service.
We use enquiry details to answer your request, assess a potential business relationship or handle a complaint. The basis is steps at your request before a contract, performance of a contract where relevant, or our legitimate interest in responding to correspondence. Reading the privacy notice is not bundled marketing consent.
We use permissions, audit events and limited technical information for the legitimate interests of keeping the platform secure, investigating abuse and protecting users. We retain or disclose records where required by a legal obligation. If we introduce optional marketing or non-essential tracking, we will explain it separately and obtain consent where required.
Access is limited to people who need it for the relevant function. Enquiries are available to authorised Admin and CEO accounts. Business workflow records may be accessible to authorised organisation members, relevant counterparties and staff according to their role. Publicly approved catalogue information is visible to visitors; private account credentials are not published.
Our hosting infrastructure is provided by Hostinger. The current application, authentication service, database and file storage run on our managed VPS using self-hosted software. Service providers, professional advisers or authorities may receive information where needed to operate the service, comply with law or resolve a dispute. We do not sell enquiry or account data, or provide partners with an unrestricted marketing list.
Our company has a UK registered office and operational coordination in Bangladesh. Authorised personnel may access information from those locations. Hosting, backup and service-provider locations must be considered separately from the location of our registered office.
Where an international transfer is restricted by applicable data-protection law, a valid transfer arrangement is required, such as an applicable adequacy decision or appropriate contractual safeguards with the necessary assessment. Contact us for the current hosting location and applicable transfer information, including how to obtain details of relevant safeguards. This notice does not claim that every country or future integration is already approved for data transfer.
We keep account and workspace information while needed to provide access and manage the relevant relationship. We review enquiry records in light of whether the request is open, the need to document its outcome, any continuing relationship, and applicable legal or dispute requirements. Closing an enquiry does not itself delete the record.
Trade and audit records may need to remain after an account closes to meet accounting, contractual or legal obligations and to establish or defend claims. Retention depends on the type of record and the law that applies; we do not retain it solely because storage is available. You may ask us to explain the retention applicable to your information or request deletion.
The current daily application-backup rotation retains 14 days of backups. Separately retained recovery copies can have a different retention period. Data removed from the active service may remain in restricted recovery copies until they expire or are securely removed; if a backup is restored, applicable deletion requests must be reapplied.
Depending on the applicable law and the processing, you may request access, correction, erasure, restriction or a portable copy of your information. You have the right to object to processing based on legitimate interests, including by telling us your particular circumstances. You may object to direct marketing at any time.
Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Contact → Privacy & data rights provides a route without requiring an account. We may need proportionate identity information before disclosing or changing personal data. We respond within applicable legal time limits; under UK data-protection law the usual period is one month, with an extension only where legally allowed and explained.
Some requests are subject to lawful exceptions, such as retaining records needed for a legal obligation or claim. We will explain a refusal where required. You can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint/ or to another supervisory authority with jurisdiction. You do not have to complain to us first.
We use HTTPS, role-based access, restricted database access and operational backups. Provider credentials entered in the authorised API vault are encrypted and are not returned through public pages. No internet service can guarantee absolute security. Protect your password and report suspected compromise through Contact.
Do not put secrets in business-profile fields or public forms. A verified email address or assigned role does not imply identity checks or product certification beyond the checks actually carried out.
You can browse public pages without creating an account. The contact form requires a name, reply email, department, subject and message so that we can understand and respond to the enquiry. If you prefer not to provide these through the form, use telephone or post. Account and business workflows require the information identified at the relevant step; without it we may be unable to provide that function.
The current service does not make solely automated decisions with legal or similarly significant effects about individuals. Administrative workflow checks support staff decisions; you can request human review of an account restriction. The service is intended for adults and business representatives, not children under 18.
We will update this notice when processing changes and provide additional notice when required. The dated downloadable copy records this version. The Cookie & Storage Policy explains browser storage. A new partner connection does not by itself authorise new data uses.