Draft for launch readiness — entity and contact details being finalised. Not final legal terms.

Legal

Privacy Policy

Last updated: 6 August 2026

Product: FoundryHQ Website: https://foundryhq.agency Application: https://app.foundryhq.agency Last updated: 6 August 2026

1. Who we are

This Privacy Policy explains how FoundryHQ (“FoundryHQ”, “we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit our websites, create an account, or use the FoundryHQ service.

DetailValue
Legal entityFoundryHQ
Company numberCompany number to be confirmed
Registered officeRegistered office address to be confirmed
Trading nameFoundryHQ
Privacy contactfoundryhq.agency@gmail.com

For UK GDPR purposes, we are the data controller of personal data described in this policy, except where we process data solely on a customer’s documented instructions as a processor (see section 4).

2. Scope

This policy covers:

  • visitors to https://foundryhq.agency and related marketing pages;
  • users of https://app.foundryhq.agency and the FoundryHQ dashboard;
  • account admins, billing contacts, and trial/paid subscribers;
  • business contact data made available inside the product (see section 4);
  • people who email or otherwise contact us.

This policy does not cover third-party websites or tools you connect or visit from our service.

3. Personal data we collect

3.1 Data you provide

  • Account data: name, work email, password or auth identifiers, company/agency name, role (if provided).
  • Billing data: billing name, billing email, payment method details processed by our payment provider (we do not store full card numbers).
  • Support and correspondence: messages, attachments, and feedback you send us.
  • Outreach content you create: email drafts, notes, pipeline stages, and other content you enter into FoundryHQ.

3.2 Data collected automatically

  • Device and log data: IP address, browser type, device type, pages viewed, referring URL, approximate location derived from IP, timestamps, and diagnostic logs.
  • Cookie and similar technologies: see our Cookie Policy.
  • Usage data: feature use (for example, leads viewed, pipeline moves, AI draft generation events) to operate, secure, and improve the service.

3.3 Data from payment and infrastructure providers

Our providers may return limited information needed to run the service (for example, Stripe customer id, subscription status, failed payment flags, fraud signals).

3.4 Business lead database data

FoundryHQ provides a UK-focused database and workflow around newly opened and expanding local businesses and related professional/business information (such as business name, sector, location, and publicly observable growth or opening signals).

This dataset may include personal data where a sole trader, partner, or individual professional is identifiable (for example, a person’s name used as a trading name, or a publicly listed work email).

Source categories (to be completed before launch):

Source categoryExamplesPersonal data possible?
Public company registries (to be confirmed)e.g. public company registriesYes/No
Public websites and listings (to be confirmed)e.g. public websites / listingsYes/No
Licensed data providers (to be confirmed)e.g. licensed data providersYes/No

We will not knowingly seek to include special category data (health, politics, religion, etc.) in the lead database.

4. How roles work (controller vs processor)

4.1 We act as controller when we:

  • operate our websites and accounts;
  • bill subscriptions;
  • secure, monitor, and improve FoundryHQ;
  • build, maintain, and license the shared lead intelligence dataset and product analytics;
  • communicate with you about the service.

4.2 We act as processor when you:

  • upload or enter your own contacts, notes, or customer lists; or
  • store pipeline/CRM content that relates to your prospects or clients,

and we process that content only to provide the service to you.

Where we are your processor, you are responsible for providing an appropriate privacy notice to your contacts and for ensuring you have a lawful basis to process and message them.

4.3 AI features

When you use one-click AI outreach drafting, we process the lead context and your prompts/inputs to generate a draft. Drafts are suggestions only. Unless a feature expressly says otherwise, you review and send messages from your own email tools/accounts. Do not submit special category data or irrelevant personal data into prompts.

5. Purposes and lawful bases (UK GDPR)

PurposeExamplesLawful basis
Provide the serviceAccount creation, login, dashboard, pipeline, lead browse, AI draftsContract (Art. 6(1)(b))
Billing and account administrationSubscription at £79 per month, invoices, dunning, cancellationContract; legal obligation for tax records
Secure and prevent abuseLogs, fraud/spam detection, troubleshootingLegitimate interests (Art. 6(1)(f)); legal obligation where applicable
Improve productAggregated feature analytics, quality review of AI outputsLegitimate interests
Service communicationsService notices, billing emails, material product changesContract; legitimate interests
Direct marketing to prospects about FoundryHQEmail/LinkedIn to potential agency customersLegitimate interests and/or consent where required (PECR)
Operate shared business lead datasetCollecting and making available UK local business intelligenceLegitimate interests (B2B intelligence), balanced against individual rights; contractual necessity where supplied as part of paid service
Comply with lawResponding to lawful requests, keeping required recordsLegal obligation

Legitimate interests balancing: For B2B lead intelligence and service marketing, we consider the professional context of the data, transparency, data minimisation, retention limits, and easy objection routes. You may object at any time using the contact details below.

6. PECR and electronic marketing

If we send marketing emails or similar electronic communications about FoundryHQ, we comply with the Privacy and Electronic Communications Regulations (PECR) as applicable to B2B messages, including unsubscribe where required.

Your use of FoundryHQ for outreach: You must comply with PECR, UK GDPR, and any other laws that apply to your campaigns. FoundryHQ supplies data and drafting tools; it does not make you compliant automatically.

7. When we share personal data

We share personal data only as needed with:

  1. Infrastructure and product vendors (hosting, database, authentication, error monitoring, analytics, email delivery, AI model providers) under contract.
  2. Payment processors (for example, Stripe) to take and manage subscription payments.
  3. Professional advisers (legal, accounting) under confidentiality obligations.
  4. Authorities when required by law or to protect rights, safety, and security.
  5. Business transferees if we restructure, merge, or sell assets, subject to appropriate safeguards.

We do not sell personal data in the everyday sense of trading contact lists for money. If that ever changes, we will update this policy before doing so.

8. Sub-processors and key recipients

Complete before launch:

ProviderRoleData location (if known)
StripePayments and subscriptionsSTRIPE_REGION (to be confirmed)
Hosting provider to be confirmedApplication hostingRegion to be confirmed
DATABASE_PROVIDER (to be confirmed)DatastoreRegion to be confirmed
AI provider to be confirmedOutreach draft generationRegion to be confirmed
Email provider to be confirmedTransactional emailRegion to be confirmed
Analytics provider to be confirmedProduct/marketing analyticsRegion to be confirmed

9. International transfers

If personal data is transferred outside the UK, we use an appropriate safeguard such as:

  • UK adequacy regulations; and/or
  • the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs; and/or
  • another lawful transfer mechanism.

10. Retention

Data typeTypical retention
Account profileFor the life of the account, then deleted or anonymised within **30–90** days after closure, unless law requires longer
Billing recordsUsually **6 years** (UK tax/commercial record practice)
Support ticketsUp to **24 months** after closure
Server logs / security logsTypically **30–180 days**, longer if investigating an incident
Lead database recordsReviewed on a cadence aligned to freshness; stale records updated or removed according to our data ops process
Customer-entered CRM notesUntil you delete them or close the account, subject to backups

Exact periods may vary; we keep data only as long as needed for the purposes above.

11. Security

We use appropriate technical and organisational measures, including transport encryption (HTTPS), access controls, least-privilege practices, and vendor due diligence. No method of transmission or storage is fully secure; please use a strong unique password and protect your login.

12. Your rights (UK GDPR)

Subject to legal limits, you can request to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data;
  • restrict processing;
  • object to processing based on legitimate interests, including direct marketing;
  • data portability (where applicable);
  • withdraw consent where processing is consent-based.

How to exercise rights: email foundryhq.agency@gmail.com with enough detail to verify your request.

You may also complain to the Information Commissioner’s Office (ICO): https://ico.org.uk.

Lead database individual rights

If your personal data appears in our business intelligence dataset and you want it corrected or removed, contact foundryhq.agency@gmail.com. We will consider requests in line with UK GDPR, the public/professional nature of the source data, and any exemptions that apply.

13. Children

FoundryHQ is a B2B service for agencies and professionals. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

14. Automated decision-making

We do not use solely automated decision-making that produces legal or similarly significant effects about you as a consumer. AI drafting features generate suggested text for human review.

15. Changes

We may update this policy from time to time. We will post the new version with a revised “Last updated” date and, for material changes, provide additional notice where appropriate (for example, email or in-app notice).

16. Contact

  • Privacy: foundryhq.agency@gmail.com
  • Support: foundryhq.agency@gmail.com
  • Post: Registered office address to be confirmed