Privacy policy
Version 1.0 · Draft · UK GDPR and Data Protection Act 2018
This policy explains what the platform collects, why, how long it is kept and who can see it. It matters more than most, because Foundium processes wellbeing signals, financial data, your own words from weekly check-ins, and data about your clients.
1. Who we are and what this covers
Foundium is the data controller for personal data processed through the platform. We are based in the United Kingdom and operate under the UK GDPR and the Data Protection Act 2018.
Where an institution licenses Foundium for a cohort, that institution may be a joint controller for its own members. The split is set out in the data processing agreement signed with them, and it never overrides the sharing settings a member controls.
Our registered company details, ICO registration number and the data protection officer's published contact address are added here before launch.
2. What we collect
Six streams feed the platform. Two ask something of you, four read what you are already doing. Each has its own legal basis.
| Stream | What it holds | Legal basis |
|---|---|---|
| Weekly check-ins | Your own words on focus, wins and blockers, plus the four wellbeing sliders | Contract, and explicit consent for the wellbeing part |
| Session behaviour | Login timing, session length, day-of-week pattern, time on task | Legitimate interest |
| Milestones | What you complete and what you defer, per project | Contract |
| Documents | Contracts, proposals, deliverables and financial documents you upload | Contract |
| Venture or practice data | Stage, sector, clients, rates, revenue, team, availability | Contract |
| Opportunity data | Briefs, grants and calls matched to you, and what you did with them | Legitimate interest |
Data that comes with the work tools
Using the invoicing, contract, time tracking and finance tools means we also process data about your clients: their name, contact details, the value of the work and the payment status. You are the controller of your own client data and we process it on your instruction.
Data we collect automatically
| Category | Examples | Legal basis |
|---|---|---|
| Usage data | Feature usage, session duration, query patterns | Legitimate interest |
| Device data | Browser, operating system, anonymised IP address | Legitimate interest |
| Cookies and local storage | Authentication, preferences, analytics | Consent, and contract for essential |
Integrations you connect
If you connect a bank account through open banking, a calendar or another integration, we collect what that integration permits, for as long as it stays connected. Disconnect it in settings and collection stops immediately.
3. What we do with it
We use your data for the following purposes and no others.
- Run the platform and generate the intelligence output you see in briefs, alerts, chat and matching.
- Operate the work tools: proposals, contracts, invoices, payment links, chasing, time tracking and tax set-aside.
- Process subscription payments and manage your plan.
- Send service notifications, risk alerts and the morning brief.
- Improve our models, on anonymised data only.
- Meet legal, tax and regulatory obligations.
We do not sell personal data. We do not use your client work, your documents or your check-in text to train models that serve anyone else.
4. Wellbeing signals
The four wellbeing signals collected at check-in, and the forecast built from their history, are special category data under Article 9 of the UK GDPR. They are not processed at all without your explicit consent, given separately from the terms.
Consent is asked for once, at sign-up, and can be withdrawn at any time from privacy settings. Withdrawing it stops processing immediately, deletes the signal history within 30 days, and deletes any forecast derived from it.
Wellbeing data is private by default. It is never visible to an adviser, an institution, a brand partner or an investor unless you turn that sharing on yourself, for that specific relationship. There is no setting anywhere else that can override this.
If you never give consent, everything else on the platform still works. Briefs and priorities are generated without the wellbeing input.
5. Who can see what
The table below is the whole picture. On by default means it is included unless you turn it off. Opt in means nothing is shared until you turn it on. Never means it is not shared whatever your settings say.
| Data | You | Adviser | Institution | Brand partner |
|---|---|---|---|---|
| Account data | Full | Never | Never | Never |
| Venture or practice data | Full | Opt in | Opt in | Never |
| Momentum and milestones | Full | On by default | On by default | Never |
| Wellbeing signals | Full | Opt in | Opt in | Never |
| Risk alerts | Full | On by default | On by default | Never |
| Check-in text | Full | Never | Never | Never |
| Session timing | Full | Never | Never | Never |
| Your client data | Full | Never | Never | Never |
| Anonymised aggregate | Full | Never | Never | Opt in |
Processors
We share data with the suppliers that run the service: cloud hosting in the United Kingdom, a regulated payment provider for subscriptions and payment links, and an email delivery provider. Each is bound by a written agreement limiting them to processing on our instructions. The current list of processors is available on request.
We also share data with professional advisers and auditors under confidentiality, and with law enforcement or regulators where we are legally required to.
6. Where it is held
Data is hosted in the United Kingdom. Where a processor operates outside the UK, transfers are made under the UK international data transfer agreement or an adequacy decision, with a transfer risk assessment on file.
7. How long we keep it
| Data | Retention |
|---|---|
| Account, venture and practice data | Two years after the account is closed |
| Wellbeing signals | Deleted within 30 days of deletion request or consent withdrawal |
| Check-in text and session timing | Held while the account is live |
| Documents you upload | Held while the account is live, deleted with the account |
| Invoices and financial records | Six years, as UK tax law requires |
| Your client data | Deleted with the account, or on request at any time |
| Anonymised aggregates | Indefinite, with no individual identifiable |
8. Your rights
Under the UK GDPR you have the rights below. All of them are available from privacy settings or through the contact route, and we respond within 30 days.
- Access a copy of what we hold about you.
- Correct anything inaccurate.
- Delete your data, subject to legal retention.
- Export it in a portable format, supplied as JSON.
- Restrict or object to processing carried out on legitimate interest grounds.
- Withdraw consent for wellbeing processing or the anonymised insight programme.
If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk.
9. Automated decisions
The platform scores, ranks and forecasts. It decides which opportunities to surface, when to release them, what to flag on a document and what order your priorities appear in.
None of it produces a legal or similarly significant effect on you in the sense of Article 22. Nothing is refused, withdrawn or priced differently on the basis of an automated score, and no adviser or institution sees a score that closes a door without a person involved.
You can ask why something was surfaced or flagged. Every output is attributed to the layer and knowledge domain it came from, so the answer is available rather than reconstructed.
10. Security
Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Access inside Foundium is role-based, least-privilege and logged. Access reviews run quarterly and penetration testing runs annually.
If a personal data breach poses a risk to you, we notify the ICO within 72 hours and tell affected members directly.
11. Children
Foundium is for adults working on a venture or a practice. It is not intended for anyone under 18 and we do not knowingly collect data from children. Tell us if you believe a child holds an account and we will delete it.
12. Changes and contact
We will tell you by email and in the platform at least 30 days before a material change takes effect. Minor clarifications are published here with a new version number.
Privacy questions and rights requests go through the contact route on the platform.