Privacy Policy

How Weventures LTD processes personal data in connection with FoundsBoard, an application that stores your work locally on your own device.

Effective

This Privacy Policy governs the processing of personal data by Weventures LTD ("we", "us", "our") in connection with the FoundsBoard application (the "Application") and the website at foundsboard.com (the "Website"). It is issued in accordance with Articles 13 and 14 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

This Policy applies to personal data relating to identified or identifiable natural persons. It does not apply to information that has been anonymised such that no individual can be identified from it, whether directly or indirectly.

1Identity and contact details of the controller

For the purposes of the UK GDPR, the controller in respect of the personal data described in this Policy is:

Weventures LTD167-169 Great Portland Street, 5th FloorLondonUnited KingdomW1W 5PF

We are established in the United Kingdom. Where the General Data Protection Regulation (Regulation (EU) 2016/679) applies to processing described in this Policy by reason of Article 3 thereof, we comply with that Regulation in respect of such processing. We have not appointed a Data Protection Officer, no such appointment being required under Article 37 of the UK GDPR; enquiries under this Policy should be addressed to privacy@foundsboard.com.

2Definitions

In this Policy, the following expressions bear the meanings given to them below. Expressions defined in the UK GDPR and not otherwise defined here bear the meanings given to them in that Regulation.

Agent
A third-party software agent, assistant or model to which you elect to transmit content by means of the Application, including any coding agent installed on or connected to your device.
Application
The FoundsBoard software application supplied for macOS, in any version.
Local Data
The records, files, indexes and preferences created, read or written by the Application within the Workspace or the local storage of your device.
Personal Data
Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the UK GDPR.
Processing
Any operation performed on Personal Data, as defined in Article 4(2) of the UK GDPR.
Waitlist Data
The electronic mail address submitted by a person by means of the Website, together with the date and time of that submission.
Workspace
The directory on your device that you designate for use by the Application, together with its subdirectories.

3Categories of personal data processed

We process one category of Personal Data only, namely Waitlist Data. We do not process any special category data within the meaning of Article 9 of the UK GDPR, nor any personal data relating to criminal convictions or offences within the meaning of Article 10.

Local Data is not processed by us. It is created and retained on your device and does not come into our possession, custody or control at any time. Where Local Data contains Personal Data, you and not we determine the purposes and means of its processing.

4Local Data: what the Application stores and where

The Application reads from and writes to the Workspace. All material it creates is stored within the Workspace, on your device, in openly documented formats that may be read without recourse to us or to the Application:

Records
Tasks, defects, plans, decisions, ideas and notes, stored as Markdown files with a structured front matter block, readable in any text editor.
Board and canvas structure
Ordering, grouping, sections, stages and canvas coordinates, stored as JSON within the Workspace.
Local index
A database file caching the contents of the Workspace so that search and retrieval operate without re-reading every file. The index is derived and not authoritative; its deletion causes no loss of Records, and the Application reconstructs it from the Workspace.
Application preferences
Interface state such as window dimensions, selected theme and the Workspace most recently opened, stored locally by the operating system.

Where the Workspace is or forms part of a version control repository, Records are subject to version control and to distribution by such remote repositories as you have configured. Such repositories constitute your infrastructure and are outside the scope of this Policy and of our control.

5Transmission of data from your device

In its default configuration the Application initiates no outbound network communication. It performs no analytics collection, no telemetry, no crash reporting, no licence verification and no update check that transmits information relating to you, your device or your use of the Application.

5.1 Transmission to an Agent at your instruction

The Application provides functionality by which you may transmit the content of a Record, or the contents of the Workspace, to an Agent. Where you exercise that functionality, the content so transmitted is disclosed to the provider of that Agent, is processed by that provider as controller or processor in accordance with its own terms and privacy notice, and is not disclosed to us. We are not a party to that transmission, we receive no copy of it, and we exercise no control over the subsequent processing of it.

5.2 Transmission to other services at your instruction

The foregoing applies equally to any remote repository, synchronisation service, storage provider or other third-party service that you elect to configure. Data is transmitted to such services upon your instruction and is thereafter governed by the terms of the recipient.

6Data we do not collect

For the avoidance of doubt, we do not collect, receive, store or have access to any of the following:

  • The contents of your Records, files, canvases or Workspace
  • The names of your projects, boards, directories or files
  • Any information as to which features of the Application you use, the frequency or duration of such use, or whether you use the Application at all
  • Your Internet Protocol address, device identifiers, hardware or operating system information, or approximate or precise location
  • Any material transmitted by you to an Agent or to any other third-party service

7The Website and the waitlist

The Website sets no cookies, employs no analytics or measurement technology, and loads no script supplied by a third party. No consent mechanism is presented because no processing requiring consent under the Privacy and Electronic Communications (EC Directive) Regulations 2003 is undertaken.

7.1 Waitlist Data

Where you submit an electronic mail address by means of the waitlist facility, we record that address together with the date and time of submission. That record constitutes the entirety of the data retained. We do not record your Internet Protocol address, user agent, referring page or any other attribute of the request.

You are not obliged to provide an electronic mail address. Provision is voluntary, and no consequence attaches to withholding it other than that we will be unable to notify you of availability.

8Lawful basis, purpose and retention

We process Waitlist Data on the basis of your consent, given by the act of submission, pursuant to Article 6(1)(a) of the UK GDPR. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Purpose
To notify you, on one or more occasions, that the Application has become available, and to respond to any communication you send to us.
Retention
Until the notification of availability has been despatched, or until you request erasure, whichever occurs first. Waitlist Data is thereafter deleted.
Correspondence
Where you correspond with us, we retain that correspondence for so long as is necessary to deal with the matter and to evidence our handling of it, and thereafter delete it.

We do not use Waitlist Data for marketing unrelated to the Application, and we do not undertake profiling.

9Recipients and international transfers

We do not sell Personal Data, and we do not disclose it to advertisers, data brokers or any other party for their own purposes.

Waitlist Data may be processed on our behalf by our hosting and electronic mail providers acting as processors, in each case under a written contract complying with Article 28 of the UK GDPR. We may further disclose Personal Data where required to do so by law, by a court of competent jurisdiction or by a regulatory authority, or where necessary to establish, exercise or defend legal claims.

Where Personal Data is transferred outside the United Kingdom, such transfer is effected only to a jurisdiction subject to adequacy regulations made under section 17A of the Data Protection Act 2018, or subject to appropriate safeguards within the meaning of Article 46 of the UK GDPR, including the International Data Transfer Addendum issued by the Information Commissioner.

10Automated decision-making

We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 of the UK GDPR.

11Your rights

Subject to the conditions and exemptions provided for in the UK GDPR, you have the right to request access to Personal Data concerning you (Article 15); to obtain rectification of inaccurate data (Article 16); to obtain erasure (Article 17); to obtain restriction of processing (Article 18); to receive data in a structured, commonly used and machine-readable format and to have it transmitted to another controller (Article 20); to object to processing (Article 21); and to withdraw consent at any time (Article 7(3)).

Because the Application transmits nothing to us, these rights are exercisable in practice in respect of Waitlist Data and of correspondence. Requests should be addressed to privacy@foundsboard.com. We will respond without undue delay and in any event within one month of receipt, which period may be extended by two further months where necessary by reason of the complexity or number of requests, in which case we will inform you within one month of receipt. No fee is charged, save that we reserve the right to charge a reasonable fee, or to refuse to act, where a request is manifestly unfounded or excessive.

We may request information reasonably necessary to confirm your identity before acting upon a request.

Local Data is not held by us and is accordingly not susceptible to a request of the kinds described above. It is already within your possession and under your exclusive control.

You have the right to lodge a complaint with the Information Commissioner's Office, being the supervisory authority for the United Kingdom, at ico.org.uk. We invite you to raise the matter with us in the first instance so that we may seek to resolve it.

12Security

Local Data is protected by the security controls of your device, including full-disk encryption, account authentication and such backup arrangements as you maintain. The Application neither augments nor diminishes those controls, and does not transmit Local Data beyond the device.

In respect of data held by us, the Website is served exclusively over HTTPS, and Waitlist Data is not publicly accessible. We implement technical and organisational measures appropriate to the risk in accordance with Article 32 of the UK GDPR. The volume and sensitivity of the data we retain are deliberately minimised, with the consequence that the maximum harm arising from a compromise of our systems is the disclosure of an electronic mail address and a timestamp.

Where a personal data breach occurs which is likely to result in a risk to the rights and freedoms of natural persons, we will notify the Information Commissioner without undue delay and, where feasible, within 72 hours, and will notify affected persons where the breach is likely to result in a high risk to them.

13Children

The Application and the Website are not directed at children. Persons under the age of 16 years should not submit an electronic mail address to the waitlist. Where we become aware that Personal Data relating to a person under that age has been submitted, we will erase it.

14Amendment of this Policy

We may amend this Policy from time to time. Where an amendment materially affects the manner in which Personal Data relating to you is processed — and in particular were the Application ever to transmit data to us — we will publish notice of that amendment at the head of this page not less than 30 days before it takes effect, and where we hold an address for you we will notify you directly.

The effective date and the date of last revision are stated above. The effective date is the date upon which the current version takes effect; the date of last revision is the date upon which its text was last altered.

15Contact

Enquiries and requests concerning data protection should be addressed to privacy@foundsboard.com. All other enquiries should be addressed to hello@foundsboard.com.

Weventures LTD167-169 Great Portland Street, 5th FloorLondonUnited KingdomW1W 5PF