Legal
Privacy Policy
Last updated: 15 September 2026
This policy explains what personal data Automa Foundry collects, why we collect it, and the choices and rights you have. We keep collection to what we need to run our services.
1. Who is responsible for your data
Automa Foundry is the controller of personal data collected through this website and client portal. Contact us about privacy at nathan@automafoundry.com.
2. What we collect
Information you give us
- Account details — your name, business name, email address and a securely hashed password (we never store your password in readable form).
- Communications — messages and requests you send through the portal, and anything you share about your business so we can help.
Information collected automatically
- Session data — a secure cookie that keeps you signed in, and the time your session was created.
- Technical logs — basic server logs such as IP address, browser type and error reports, used for security and troubleshooting.
3. How we use it
- To create and secure your account and let you sign in.
- To communicate with you and deliver the services you request.
- To maintain, protect and improve the platform.
- To meet legal, accounting and regulatory obligations.
We rely on the following legal bases: performing our contract with you, our legitimate interests in running a secure and effective business, compliance with legal obligations, and your consent where we ask for it. We do not sell your personal data, and we do not use your portal messages to train public AI models.
4. Cookies
We use a single strictly necessary cookie to keep you signed in. It is not used for advertising or cross-site tracking. If we introduce analytics or other optional cookies, we will update this policy and ask for your consent where required.
5. Who we share it with
We share personal data only where needed, with:
- Service providers who host our platform, database and email on our behalf, under contracts that require them to protect it.
- AI and software tools used in your engagement, only where you have agreed to their use as part of the work.
- Professional advisers and authorities where required by law or to protect our rights.
Some providers may process data outside your country. Where that happens we use appropriate safeguards, such as standard contractual clauses.
6. How long we keep it
We keep account data and communications for as long as your account is active and for a reasonable period afterwards to handle queries and meet legal obligations (typically up to six years for records linked to invoices). Expired sign-in sessions are removed automatically.
7. Security
Passwords are hashed with bcrypt, sessions use random tokens stored only as hashes, and access to client conversations is restricted to you and authorised Automa Foundry staff. No system is perfectly secure, so please use a strong, unique password.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate data — you can update your profile in the portal at any time.
- Ask us to delete your data or restrict how we use it.
- Object to processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent where we rely on it.
To exercise any of these rights, email nathan@automafoundry.com. You also have the right to complain to your local data protection authority.
9. Children
Our services are for businesses and adults. We do not knowingly collect data from anyone under 18.
10. Changes to this policy
We will post any updates on this page and change the date above. If changes are significant, we will let you know through the portal or by email.

