Privacy Policy

Effective 9 June 2026 · Last updated 9 June 2026

Philofounder (the service) is operated by GRANDPOINT LTD. This policy explains what the service collects, why, and how we look after it. We keep the data we hold to what the service genuinely needs to work, and we never sell it.

Who we are (data controller)

Company: GRANDPOINT LTD
Companies House number: 16498233 (incorporated 5 June 2025, England and Wales)
Registered office: 108 St. Helens Street, Ipswich, IP4 2LB, United Kingdom
ICO Data Protection registration: ZC084167
Data Protection Officer: privacy@grandpoint.uk
Product support: hello@philofounder.co.uk

GRANDPOINT LTD is the data controller for personal information processed through Philofounder, registered with the UK Information Commissioner’s Office under reference ZC084167.

What we collect

  • Your email address. Used to sign you in with a single-use link and to send account and compliance notifications.
  • Company information you add. Company name, registration number, officers, deadlines, products, and documents you choose to store.
  • Public register data. Information drawn from Companies House about the companies you track.
  • Data from accounts you choose to connect. When you connect an account, the service reads, on your instruction and read-only:
    • your email inbox (Gmail or Microsoft 365), to find and file finance mail such as invoices, receipts, and registry or HMRC notices;
    • your bank transactions (via Open Banking), to reconcile spending and track the Director’s Loan Account;
    • your VAT position (via HMRC Making Tax Digital): obligations, liabilities, and payments;
    • your connected website, to keep your company profile current.
  • Documents and a CV you upload. Files you add to your cabinet, and the structured background extracted from a CV you choose to upload.
  • Your conversations with Philo. The questions you ask the assistant and its replies, so threads persist for you.
  • Usage, device, and security logs. Including IP address and browser information, needed to run the service and protect your account.

How we use it

We use your data to provide the service: to sign you in, track your deadlines and filings, file documents into your cabinet, reconcile money, answer your questions through Philo, and send you reminders. We do not sell your data, and we do not use it for advertising.

Legal basis for processing (UK GDPR)

Under UK GDPR and the Data Protection Act 2018, we process your data on these bases:

  • Contract: to provide the service you have signed up for.
  • Consent: when you connect an account or upload a CV, you instruct us to access that specific data; you can withdraw it at any time by disconnecting or deleting.
  • Legitimate interest: to keep the service running, secure, and improving, in a way that does not override your rights.
  • Legal obligation: to comply with applicable law.

Connected accounts and external sources

Connections are read-only and made through each provider’s official authorisation flow. We request the narrowest access needed, store the resulting tokens on our servers only (never in your browser), and never use them to send, file, pay, or change anything without asking you first. You can disconnect any account at any time on the Connections page, which revokes our access. The providers are: Google (Gmail), Microsoft (Microsoft 365), your bank via an Open Banking provider (TrueLayer), HMRC (Making Tax Digital), and Companies House.

Service providers we rely on

We use a small number of trusted providers (processors) to run the service. Each processes data only to deliver its part of the service:

  • Vercel, for hosting the application.
  • Supabase, for storing your account and company data.
  • Resend, for sending sign-in links and notification emails.
  • Anthropic, for the Philo assistant; your prompts are processed to generate replies and are not used to train models.

Some providers may process data outside the UK. Where they do, the transfer is covered by appropriate safeguards (such as UK adequacy or the International Data Transfer Agreement).

Data retention

We keep your personal data only for as long as needed to provide the service or as required by law. When you delete a document, disconnect an account, or close your account, we remove the associated data, except where we must keep limited records to meet a legal obligation. We do not retain the raw CV file after extracting your profile.

Your rights under UK GDPR

You have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase your data;
  • restrict processing;
  • data portability;
  • object to processing;
  • withdraw consent at any time.

You can also export or permanently delete all of your workspace data yourself at any time from the Settings page.

To exercise any of these, email our Data Protection Officer at privacy@grandpoint.uk or product support at hello@philofounder.co.uk. You also have the right to complain to the UK Information Commissioner’s Office at any time: ico.org.uk/make-a-complaint (telephone 0303 123 1113).

Security

Sign-in is passwordless and uses single-use links that expire. We will never ask for a password, card details, or banking credentials by email. Sign-in links come only from login@philofounder.co.uk. We apply appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. To report a security concern, email security@grandpoint.uk.

Cookies

We use strictly necessary cookies for sign-in, security, and connecting accounts. See our Cookie Policy for details. We do not use advertising cookies.

Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new effective date and, where appropriate, let you know.

Contact

Questions about this policy or your data? Email our Data Protection Officer at privacy@grandpoint.uk, or product support at hello@philofounder.co.uk. Postal: GRANDPOINT LTD, 108 St. Helens Street, Ipswich, IP4 2LB, United Kingdom.