Legal
Privacy Policy
Last updated: 6 August 2026
Product: FoundryHQ Website: https://foundryhq.agency Application: https://app.foundryhq.agency Last updated: 6 August 2026
1. Who we are
This Privacy Policy explains how FoundryHQ (“FoundryHQ”, “we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit our websites, create an account, or use the FoundryHQ service.
| Detail | Value |
|---|---|
| Legal entity | FoundryHQ |
| Company number | Company number to be confirmed |
| Registered office | Registered office address to be confirmed |
| Trading name | FoundryHQ |
| Privacy contact | foundryhq.agency@gmail.com |
For UK GDPR purposes, we are the data controller of personal data described in this policy, except where we process data solely on a customer’s documented instructions as a processor (see section 4).
2. Scope
This policy covers:
- visitors to https://foundryhq.agency and related marketing pages;
- users of https://app.foundryhq.agency and the FoundryHQ dashboard;
- account admins, billing contacts, and trial/paid subscribers;
- business contact data made available inside the product (see section 4);
- people who email or otherwise contact us.
This policy does not cover third-party websites or tools you connect or visit from our service.
3. Personal data we collect
3.1 Data you provide
- Account data: name, work email, password or auth identifiers, company/agency name, role (if provided).
- Billing data: billing name, billing email, payment method details processed by our payment provider (we do not store full card numbers).
- Support and correspondence: messages, attachments, and feedback you send us.
- Outreach content you create: email drafts, notes, pipeline stages, and other content you enter into FoundryHQ.
3.2 Data collected automatically
- Device and log data: IP address, browser type, device type, pages viewed, referring URL, approximate location derived from IP, timestamps, and diagnostic logs.
- Cookie and similar technologies: see our Cookie Policy.
- Usage data: feature use (for example, leads viewed, pipeline moves, AI draft generation events) to operate, secure, and improve the service.
3.3 Data from payment and infrastructure providers
Our providers may return limited information needed to run the service (for example, Stripe customer id, subscription status, failed payment flags, fraud signals).
3.4 Business lead database data
FoundryHQ provides a UK-focused database and workflow around newly opened and expanding local businesses and related professional/business information (such as business name, sector, location, and publicly observable growth or opening signals).
This dataset may include personal data where a sole trader, partner, or individual professional is identifiable (for example, a person’s name used as a trading name, or a publicly listed work email).
Source categories (to be completed before launch):
| Source category | Examples | Personal data possible? |
|---|---|---|
| Public company registries (to be confirmed) | e.g. public company registries | Yes/No |
| Public websites and listings (to be confirmed) | e.g. public websites / listings | Yes/No |
| Licensed data providers (to be confirmed) | e.g. licensed data providers | Yes/No |
We will not knowingly seek to include special category data (health, politics, religion, etc.) in the lead database.
4. How roles work (controller vs processor)
4.1 We act as controller when we:
- operate our websites and accounts;
- bill subscriptions;
- secure, monitor, and improve FoundryHQ;
- build, maintain, and license the shared lead intelligence dataset and product analytics;
- communicate with you about the service.
4.2 We act as processor when you:
- upload or enter your own contacts, notes, or customer lists; or
- store pipeline/CRM content that relates to your prospects or clients,
and we process that content only to provide the service to you.
Where we are your processor, you are responsible for providing an appropriate privacy notice to your contacts and for ensuring you have a lawful basis to process and message them.
4.3 AI features
When you use one-click AI outreach drafting, we process the lead context and your prompts/inputs to generate a draft. Drafts are suggestions only. Unless a feature expressly says otherwise, you review and send messages from your own email tools/accounts. Do not submit special category data or irrelevant personal data into prompts.
5. Purposes and lawful bases (UK GDPR)
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide the service | Account creation, login, dashboard, pipeline, lead browse, AI drafts | Contract (Art. 6(1)(b)) |
| Billing and account administration | Subscription at £79 per month, invoices, dunning, cancellation | Contract; legal obligation for tax records |
| Secure and prevent abuse | Logs, fraud/spam detection, troubleshooting | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable |
| Improve product | Aggregated feature analytics, quality review of AI outputs | Legitimate interests |
| Service communications | Service notices, billing emails, material product changes | Contract; legitimate interests |
| Direct marketing to prospects about FoundryHQ | Email/LinkedIn to potential agency customers | Legitimate interests and/or consent where required (PECR) |
| Operate shared business lead dataset | Collecting and making available UK local business intelligence | Legitimate interests (B2B intelligence), balanced against individual rights; contractual necessity where supplied as part of paid service |
| Comply with law | Responding to lawful requests, keeping required records | Legal obligation |
Legitimate interests balancing: For B2B lead intelligence and service marketing, we consider the professional context of the data, transparency, data minimisation, retention limits, and easy objection routes. You may object at any time using the contact details below.
6. PECR and electronic marketing
If we send marketing emails or similar electronic communications about FoundryHQ, we comply with the Privacy and Electronic Communications Regulations (PECR) as applicable to B2B messages, including unsubscribe where required.
Your use of FoundryHQ for outreach: You must comply with PECR, UK GDPR, and any other laws that apply to your campaigns. FoundryHQ supplies data and drafting tools; it does not make you compliant automatically.
7. When we share personal data
We share personal data only as needed with:
- Infrastructure and product vendors (hosting, database, authentication, error monitoring, analytics, email delivery, AI model providers) under contract.
- Payment processors (for example, Stripe) to take and manage subscription payments.
- Professional advisers (legal, accounting) under confidentiality obligations.
- Authorities when required by law or to protect rights, safety, and security.
- Business transferees if we restructure, merge, or sell assets, subject to appropriate safeguards.
We do not sell personal data in the everyday sense of trading contact lists for money. If that ever changes, we will update this policy before doing so.
8. Sub-processors and key recipients
Complete before launch:
| Provider | Role | Data location (if known) |
|---|---|---|
| Stripe | Payments and subscriptions | STRIPE_REGION (to be confirmed) |
| Hosting provider to be confirmed | Application hosting | Region to be confirmed |
| DATABASE_PROVIDER (to be confirmed) | Datastore | Region to be confirmed |
| AI provider to be confirmed | Outreach draft generation | Region to be confirmed |
| Email provider to be confirmed | Transactional email | Region to be confirmed |
| Analytics provider to be confirmed | Product/marketing analytics | Region to be confirmed |
9. International transfers
If personal data is transferred outside the UK, we use an appropriate safeguard such as:
- UK adequacy regulations; and/or
- the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs; and/or
- another lawful transfer mechanism.
10. Retention
| Data type | Typical retention |
|---|---|
| Account profile | For the life of the account, then deleted or anonymised within **30–90** days after closure, unless law requires longer |
| Billing records | Usually **6 years** (UK tax/commercial record practice) |
| Support tickets | Up to **24 months** after closure |
| Server logs / security logs | Typically **30–180 days**, longer if investigating an incident |
| Lead database records | Reviewed on a cadence aligned to freshness; stale records updated or removed according to our data ops process |
| Customer-entered CRM notes | Until you delete them or close the account, subject to backups |
Exact periods may vary; we keep data only as long as needed for the purposes above.
11. Security
We use appropriate technical and organisational measures, including transport encryption (HTTPS), access controls, least-privilege practices, and vendor due diligence. No method of transmission or storage is fully secure; please use a strong unique password and protect your login.
12. Your rights (UK GDPR)
Subject to legal limits, you can request to:
- access your personal data;
- rectify inaccurate data;
- erase data;
- restrict processing;
- object to processing based on legitimate interests, including direct marketing;
- data portability (where applicable);
- withdraw consent where processing is consent-based.
How to exercise rights: email foundryhq.agency@gmail.com with enough detail to verify your request.
You may also complain to the Information Commissioner’s Office (ICO): https://ico.org.uk.
Lead database individual rights
If your personal data appears in our business intelligence dataset and you want it corrected or removed, contact foundryhq.agency@gmail.com. We will consider requests in line with UK GDPR, the public/professional nature of the source data, and any exemptions that apply.
13. Children
FoundryHQ is a B2B service for agencies and professionals. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
14. Automated decision-making
We do not use solely automated decision-making that produces legal or similarly significant effects about you as a consumer. AI drafting features generate suggested text for human review.
15. Changes
We may update this policy from time to time. We will post the new version with a revised “Last updated” date and, for material changes, provide additional notice where appropriate (for example, email or in-app notice).
16. Contact
- Privacy: foundryhq.agency@gmail.com
- Support: foundryhq.agency@gmail.com
- Post: Registered office address to be confirmed