These policies are in final legal review.

They reflect how the platform actually handles your data today and will be finalised before launch. Until then they are provided for transparency and are not yet a substitute for formal legal advice.

Privacy Policy

Quantamic Solutions Limited (Foxar) · Effective 1 July 2026

This policy explains how Quantamic Solutions Limited ("we", "us") handles personal data in connection with the Foxar platform and website. We take a different role depending on the data - see "Our two roles" below.

1. Who we are and our two roles

Quantamic Solutions Limited operates Foxar. Flat 46 Crane Heights, Waterside Way, London, England, N17 9GE.

  • As a controller - for the personal data of our own account holders, website visitors, and prospects (for example the name, email, and billing details of the person who signs up, and website analytics). This policy covers that data.
  • As a processor - for the personal data our customers (charities, nonprofits, and businesses) load into their account about their own donors, supporters, and customers. For that data our customer is the controller and decides why it is processed; we act only on their instructions under a Data Processing Agreement. If you are a donor or customer of an organisation that uses Foxar, please contact that organisation to exercise your rights; we will support them in responding.

2. Personal data we collect (as controller)

  • Account data - name, work email, organisation, role, and login credentials.
  • Billing data - plan, transactions, and limited payment metadata. Card details are handled by our payment provider (Stripe); we do not store full card numbers.
  • Usage and device data - how you interact with the dashboard, log and diagnostic data, and IP address, used to operate, secure, and improve the Service.
  • Communications - messages you send us for support, feedback, or sales.
  • Campaign and referral data - if you arrive on a link that carries campaign parameters (for example utm_source), we record those parameters, the website you came from, and the page you landed on, so we can tell which of our own campaigns work. If you go on to create an account, that record is kept against it. We use no cookies, tracking pixels, or third-party analytics for this.

3. Legal bases (UK GDPR Article 6)

  • Contract - to provide the Service you have signed up for and to bill for it.
  • Legitimate interests - to secure, maintain, and improve the Service and to communicate about it, balanced against your rights.
  • Legal obligation - to meet accounting, tax, and other statutory duties.
  • Consent - where required, for example certain marketing and non-essential cookies; you may withdraw consent at any time.

4. How we use personal data

To create and manage accounts; provide, secure, and improve the Service; process payments; provide support; detect and prevent fraud and abuse; and comply with law. We do not sell personal data, and we do not use customer donor/supporter data (which we process as a processor) to train general-purpose AI models.

5. AI processing

The Service uses third-party AI models to generate text and media on your instruction. Content you submit to an agent is sent to the relevant model provider (see sub-processors) solely to produce the requested output. Our model providers are engaged under terms that do not permit them to use business/API content to train their foundation models. Agent output can be inaccurate and should be reviewed before use.

6. Sub-processors and international transfers

We use a limited set of vetted providers to run the Service. The current categories are:

  • Hosting and infrastructure - Amazon Web Services (compute, storage, email delivery via SES, and monitoring), hosted in the United Kingdom / European Union region.
  • Payments - Stripe (subscription billing and, where enabled, donation and checkout processing).
  • AI model providers - Anthropic (Claude), Google (Gemini), OpenAI, and xAI (Grok) for text, vision, and image generation; and video/voice providers where you enable them.
  • Messaging and communications - Meta (WhatsApp/Messenger), Telegram, and Twilio (voice/SMS), used only for the channels you connect.
  • Web research - Tavily, where the market-research features are used.

A current sub-processor list is maintained in Annex C of our Data Processing Agreement. We keep customer data in the UK/EU region. Where a provider processes data outside the UK/EU, we rely on an adequacy decision or appropriate safeguards (UK International Data Transfer Agreement / addendum or Standard Contractual Clauses).

7. Retention

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. Specific periods include:

  • Account and billing records - for the life of the account and as required for accounting and tax.
  • Gift Aid and donation records processed for charity customers - retained to meet HMRC requirements (currently 6 years) where applicable.
  • Assistant memory and episodic logs - purged after 90 days.
  • Product feedback and NPS responses - retained for a maximum of 24 months, then deleted.
  • Pending-action records containing contact details - sensitive fields are redacted after 90 days on completed items.
  • Email open and click records for customer marketing campaigns - the link to the recipient is removed after 90 days, leaving anonymous totals.
  • Security and audit logs - retained for a limited period for security and compliance, then purged.

8. Security

We apply technical and organisational measures appropriate to the risk, including:

  • logical isolation of each customer's data in a separate database, with additional schema-level isolation between offices for enterprise customers;
  • encryption in transit, access controls and authentication, and least-privilege internal access;
  • approval gates on sensitive and outbound agent actions, audit logging of privileged operations, and monitoring and alerting;
  • daily backups and disaster-recovery procedures.

9. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, and object to processing, to data portability, and to withdraw consent. To exercise these rights over data we hold as a controller, contact us at contact@quantamic.digital. If your data is held by an organisation that uses Foxar (we are their processor), please contact that organisation; we will assist them in responding.

10. Cookies

We use strictly necessary cookies to run the dashboard (for example authentication and preferences). Where we use analytics or other non-essential cookies, we will do so on the basis of your consent and provide controls. A more detailed cookie notice will be linked here.

11. Children

The Service is for organisations and is not directed at children. We do not knowingly collect children's data through our own account relationship.

12. Complaints

If you have a concern we have not resolved, you can complain to the UK Information Commissioner's Office (ico.org.uk), or to your local supervisory authority.

13. Changes and contact

We may update this policy and will post the new version with an updated effective date. Data protection contact: contact@quantamic.digital / contact@quantamic.digital.

A note on email measurement in customer campaigns

When one of our customers sends a marketing email to their own list through Foxar, the message records whether it was opened and whether a link in it was clicked. We do this only for marketing broadcasts a customer chooses to send, never for account or transactional email such as receipts, password resets, or verification codes. What is recorded is limited to the fact of an open or a click, the message it relates to, and the recipient record it belongs to: no IP address, no device or browser details, and no location. The measurement is disclosed to the recipient in the footer of the email itself, next to the one-click unsubscribe. A recipient who has unsubscribed or withdrawn consent is not measured at all, and the link to the recipient record is removed after 90 days, leaving only anonymous totals. For this processing our customer is the controller and we act on their instructions as processor; contact them to exercise your rights.

A note on special category data

Some customers are faith-based charities whose supporter records may reveal religious belief (special category data under UK GDPR Article 9). Where we process such data on a customer's behalf, we do so only on their documented instructions and under the safeguards in the Data Processing Agreement; the customer is responsible for the lawful basis and any Article 9 condition.