These policies are in final legal review.
They reflect how the platform actually handles your data today and will be finalised before launch. Until then they are provided for transparency and are not yet a substitute for formal legal advice.
Data Processing Agreement
Quantamic Solutions Limited (Foxar) · Effective 1 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Quantamic Solutions Limited ("Processor", "we") and the customer ("Controller", "you"). It governs our processing of personal data on your behalf and applies where UK GDPR or EU GDPR apply. If the two conflict, this DPA prevails on the processing of personal data.
1. Roles and subject-matter
You are the controller (or a processor acting for your own controller) and determine the purposes and means of processing your Customer Data. We act as your processor (or sub-processor) and process personal data only to provide the Foxar Service and on your documented instructions, which include the Terms, this DPA, and your configuration and use of the Service.
2. Duration, nature and purpose
Processing lasts for the term of your account plus any period needed for deletion or legally required retention. The nature and purpose is the provision of an AI workforce platform: hosting your records; running AI agents that draft content and respond to messages; sending communications on channels you connect; and processing payments where enabled. Details are set out in Annex A.
3. Our obligations as processor
- process personal data only on your documented instructions, including for transfers, unless required by law (in which case we will inform you unless the law prohibits it);
- ensure personnel authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Annex B (UK GDPR Article 32);
- respect the sub-processor conditions in clause 5;
- taking account of the nature of processing, assist you by appropriate measures to respond to data subject requests (clause 6);
- assist you with security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36);
- at your choice, delete or return the personal data at the end of provision, and delete existing copies unless retention is legally required (clause 8);
- make available information necessary to demonstrate compliance and allow for and contribute to audits (clause 9).
We will inform you if, in our opinion, an instruction infringes UK/EU data protection law.
4. Security
We maintain the measures described in Annex B, appropriate to the risk, and will not materially reduce the overall level of security during the term.
5. Sub-processors
- You give general authorisation for us to engage the sub-processors listed in Annex C to help provide the Service.
- We impose data protection obligations on each sub-processor that are, in substance, equivalent to those in this DPA, and remain responsible for their performance.
- We will give you advance notice (by updating Annex C and, where you subscribe to notifications, by email) before adding or replacing a sub-processor, so you can object on reasonable data protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the Service.
6. Data subject rights
The Service provides features to access, correct, export, and delete Customer Data. Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to data subject requests. If a data subject contacts us directly about your data, we will refer them to you.
7. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your Customer Data, and provide information reasonably available to help you meet your notification duties under Articles 33–34.
8. Return and deletion
On termination, and at your choice, we will delete or return your Customer Data and delete existing copies within a reasonable period, except to the extent we are required by law to retain it (for example statutory accounting or HMRC Gift Aid records), which we will continue to protect under this DPA.
9. Audit
We will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once a year (or following a breach), subject to confidentiality and without compromising other customers' security.
10. International transfers
We process Customer Data in the UK/EU region. Where a transfer outside the UK/EU occurs (for example a sub-processor), it is made under an adequacy decision or appropriate safeguards - the UK International Data Transfer Agreement or Addendum, and/or the EU Standard Contractual Clauses - which are incorporated by reference and completed consistently with Annexes A–C.
11. Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA is governed by the laws of England and Wales.
Annex A - Details of processing
- Categories of data subjects - your donors, supporters, customers, leads, volunteers, staff, and other contacts you load or that interact with your connected channels.
- Categories of personal data - contact details (name, email, phone), messages and conversation history, donation/transaction and Gift Aid records, campaign and CRM records, and any other data you choose to submit.
- Special category data - may include data revealing religious belief (for faith-based charities) where you choose to process it. You are responsible for the Article 9 condition. We do not require special category data to provide the Service.
- Frequency - continuous, for the term of the account.
- Nature and purpose - hosting, AI-assisted drafting and response, messaging on connected channels, analytics, and payment processing, as configured by you.
Annex B - Technical and organisational measures
- Tenant isolation - each customer's data is stored in a separate database; enterprise customers additionally get schema-level isolation between offices, with cross-office references rejected at the database.
- Encryption - data encrypted in transit; storage protected by the hosting provider's encryption.
- Access control - authentication, role- and scope-based authorisation, least-privilege internal access, and short-lived, audited privileged access.
- Action safeguards - sensitive and outbound agent actions are gated for human approval; privileged and money-movement operations are audit-logged.
- Resilience - daily backups, disaster-recovery procedures, and monitoring/alerting.
- Data minimisation and retention - enforced retention windows (see the Privacy Policy) and redaction of contact details on completed records.
Annex C - Sub-processors
Current sub-processors and their function:
- Amazon Web Services - hosting, storage, transactional email (SES), and monitoring. Region: UK/EU.
- Stripe - subscription billing and, where enabled, donation/checkout payment processing.
- Anthropic - AI text generation (Claude).
- Google - AI text/vision generation (Gemini); Workspace integrations you connect.
- OpenAI - AI image generation and transcription.
- xAI - AI image generation (Grok).
- Meta Platforms - WhatsApp/Messenger messaging on channels you connect.
- Telegram - messaging on channels you connect.
- Twilio - voice and SMS on channels you connect.
- Tavily - web search for market-research features, where used.
Additional media/voice providers (for example video generation) apply only where you enable them. We will update this Annex before adding or replacing a sub-processor. Questions: contact@quantamic.digital.