Legal

Privacy notice

Last updated · Nord Group UK Ltd, registered in England and Wales

This notice explains what personal data FoxFace handles, why, on what lawful basis, who else is involved and what you can ask us to do about it. It is written to be read rather than to be defensible, and it covers both the personal data we hold about you and the personal data you hold about your own customers inside the product.

It applies to the foxface.io website and to the FoxFace application. It does not cover any other site you might reach from a link here.

1.Who we are, and which hat we are wearing

FoxFace is operated by Nord Group UK Ltd, a company registered in England and Wales with its registered office in Nottinghamshire. Where this notice says "we", "us" or "FoxFace", it means Nord Group UK Ltd.

There are two distinct relationships in this product, and the difference matters legally.

For personal data about you as our customer or as a visitor to this website, we are the data controller. That covers your account details, your billing information, the contact form on this site and our own operational logs.

For personal data you put into the product about your own customers, their properties and your staff, you are the data controller and we are your data processor. We hold and process that information on your instructions, which are given through the product itself and through the agreement between us. We do not decide what it is used for, we do not use it for our own purposes, and we do not use it to train models.

The data processing terms attached to your subscription form the written contract required by Article 28 of the UK GDPR. If you need a signed copy for your own compliance file, email privacy@foxface.io and we will provide one.

2.What we collect when we are the controller

We collect the minimum needed to run an account and a business relationship, and nothing that exists only to build a marketing profile.

Categories of data

  • Account data: your name, work email address, password (stored only as a salted scrypt hash, never in plain text), organisation name and role.
  • Billing data: company name, billing address, VAT number and subscription history. Card details are entered directly with our payment processor and never reach our servers.
  • Usage and diagnostic data: sign-in times, the browser and operating system reported by your device, IP address, and error traces when something fails.
  • Support and enquiry data: the messages you send us, and our replies.
  • Marketing website data: aggregate page counts held without cookies, plus anything you volunteer through the contact form.

3.Our lawful bases

Every processing activity needs a lawful basis under Article 6 of the UK GDPR. Ours are as follows.

  • Performance of a contract, for providing the product, authenticating you, taking payment and providing support. Without this data there is no account.
  • Legitimate interests, for keeping the service secure, preventing abuse, diagnosing faults, and contacting existing customers about material changes to a service they already pay for. We have balanced these against your rights and consider the processing proportionate; you may object at any time.
  • Legal obligation, for retaining financial records under the Companies Act 2006 and HMRC requirements, and for responding to lawful requests from a regulator or a court.
  • Consent, for the contact form on this site and for any optional marketing email. Consent can be withdrawn at any time without affecting anything already done on that basis.

4.Data you put into the product

Inside FoxFace you will typically hold names, addresses, telephone numbers, email addresses, property details, survey photographs and signatures belonging to your own customers, along with employment-related details of your own staff.

We process that data only to provide the service to you: storing it, calculating with it, rendering it into the documents you generate, transmitting the documents you choose to send, and backing it up. We access individual records only where you ask us to for support, where it is unavoidable to fix a fault, or where the law requires it. Support access is logged.

We do not sell it. We do not share it with advertisers. We do not use it to train machine-learning models. We do not use it to build a market data product.

You remain responsible for having a lawful basis for the data you enter, for telling your own customers how you use it, and for responding to their requests. We will help you meet those requests, and the product exports everything in machine-readable form so that you can.

5.Sub-processors

We use a small number of specialist providers to run the service. Each is bound by a written contract that meets Article 28, and each is limited to the purpose shown.

We keep this list short deliberately. Adding a sub-processor is a decision with a compliance cost for every customer, so we do it rarely. We will give you at least 30 days’ notice before adding a new one, and you may object.

FoxFace sub-processors
ProviderPurposeLocation of processing
NetlifyApplication hosting, content delivery, file storageEuropean Union and United States
NeonManaged PostgreSQL database hostingEuropean Union
StripeSubscription billing and card payment processingEuropean Union, United Kingdom and United States

6.International transfers

Our database is hosted in the European Union. Some hosting and payment infrastructure involves transfers to the United States.

Transfers outside the United Kingdom are made under the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or under UK adequacy regulations where they apply. We carry out a transfer risk assessment before relying on any such mechanism and keep it under review.

If you need the specific mechanism relied on for a named provider for your own records, ask and we will confirm it in writing.

7.How long we keep things

Data is kept for as long as it is needed for the purpose it was collected for, and then deleted. In practice that means the following.

  • Account and product data: for the life of your subscription. On cancellation the account is retained in a recoverable state for 30 days so an accidental cancellation can be undone, then deleted. Backups age out within a further 35 days.
  • Financial records, including invoices and payment records: six years from the end of the accounting period, as required by HMRC and the Companies Act.
  • Support correspondence: two years from the last message in the thread.
  • Contact form enquiries that do not become an account: twelve months.
  • Security and access logs: twelve months, then deleted.

8.Security

Data is encrypted in transit using TLS and encrypted at rest by our database and storage providers. Passwords are stored only as salted scrypt hashes and cannot be recovered by us or by anyone else, which is why a reset issues a new password rather than telling you the old one.

Each organisation’s data is isolated at the database level by row-level security policies, not only by application logic. A query that forgets to scope itself returns nothing rather than returning another company’s jobs.

Two-factor authentication is available on every account and is prompted for owners and administrators, because those accounts control billing and can delete an organisation.

Access by our staff is limited to those who need it, requires two-factor authentication, and is logged. We will notify you without undue delay, and in any event within 72 hours of becoming aware, if a personal data breach affecting your data occurs, along with what we know and what we are doing about it.

9.Analytics, advertising and the application boundary

This is stated explicitly because it is a question we are asked and because the answer is unusual enough to be worth writing down.

No advertising pixel, no conversion tag, no session-recording script and no third-party analytics script is loaded on any authenticated application route. Once you have signed in, the only code running is ours. Your customers’ names, addresses and survey photographs are never in the presence of a third-party script.

The same applies to the token-addressed pages your customers visit to sign a proposal or make a payment. Those pages carry no analytics and no marketing tags of any kind.

On the public marketing pages, we measure aggregate page views without cookies and without any identifier that can be tied back to an individual. See the cookie policy for the detail.

10.Your rights

Under the UK GDPR you have the following rights in respect of personal data for which we are the controller. Where we are your processor, these requests should go to the organisation that holds the data, and we will support them in answering it.

  • Access: a copy of the personal data we hold about you.
  • Rectification: correction of anything inaccurate or incomplete.
  • Erasure: deletion, where we no longer have a lawful reason to keep it.
  • Restriction: to have processing paused while an issue is resolved.
  • Portability: a copy in a structured, commonly used, machine-readable format.
  • Objection: to processing carried out on the basis of legitimate interests, including any profiling.
  • Withdrawal of consent: at any time, where consent was the basis relied on.
  • Not to be subject to solely automated decisions with legal or similarly significant effects. We do not make any.

11.Making a request or a complaint

Email privacy@foxface.io. We will respond within one month, and will tell you within that month if a complex request needs longer, which the law allows up to a further two months. There is no charge unless a request is manifestly unfounded or excessive.

We may ask you to confirm your identity before releasing personal data, which protects you rather than us.

If you are unhappy with how we have handled a request, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, by telephone on 0303 123 1113, or in writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

12.Changes to this notice

We will update this notice when the product or the law changes. The date at the top always reflects the current version.

Where a change materially affects how we handle your personal data, we will tell you by email before it takes effect rather than relying on you noticing a revised date.