RUNIQ← Home

Privacy Policy

Last updated: 13 July 2026

This is a template that RunIQ provides as a starting point. Please have it reviewed by your own legal adviser before relying on it.

1. Who we are

RunIQ ("we", "us", "our") is an AI-powered lead follow-up service for UK service businesses, operated from the United Kingdom. For the purposes of UK GDPR and the Data Protection Act 2018, we act as data controller for account and billing data, and as data processor for lead data you upload to the service. You can reach us at hello@runiq.co.uk.

2. What data we collect

  • Account data — your name, email address and password hash.
  • Company data — business name, website, business description and sending preferences.
  • Lead data — enquiry details you or your integrations submit (typically name, email address, phone number and message).
  • Billing data — handled by Stripe; we store customer and subscription identifiers only, never card numbers.
  • Usage and log data — timestamps, IP address, browser and page views for security, debugging and product analytics.
  • Cookies — see our Cookie Policy.

3. How we use it

  • To provide the RunIQ service and send lead follow-up emails on your behalf.
  • To manage your account, subscription and billing.
  • To improve the product, monitor performance and investigate issues.
  • To provide customer support and respond to your requests.
  • To meet our legal and regulatory obligations.

4. Lawful bases

We rely on contract (to provide the service you signed up for), legitimate interests (product improvement, security, direct communication with existing customers), consent (optional marketing and non-essential cookies) and legal obligation (tax, accounting, responding to lawful requests).

5. Sharing and subprocessors

We share data only with vendors who help us run the service:

  • Supabase — database, authentication and file storage.
  • Resend — transactional and follow-up email delivery.
  • Stripe — payments and subscription billing.
  • Anthropic — AI generation of follow-up sequences from your business description.
  • Cloudflare — hosting, DDoS protection and edge compute.

Some of these providers process data outside the UK. Transfers are protected by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses as appropriate. We do not sell personal data.

6. Retention

  • Account and company data — while your account is active plus 30 days after cancellation.
  • Lead data — for the retention period you configure, defaulting to 24 months.
  • Email delivery logs — 12 months.
  • Billing records — 7 years, to meet UK tax and accounting requirements.

7. Your rights

You have the right to access, correct, delete, restrict or object to processing of your personal data, to request portability, and to withdraw consent at any time. Email hello@runiq.co.uk to exercise any of these rights.

You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted by role and protected with row-level security policies and multi-factor authentication. No system is perfectly secure — we will notify affected users and the ICO of any personal data breach as required by law.

9. Children

RunIQ is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children.

10. Changes

We may update this policy from time to time. Material changes will be notified by email to account holders at least 30 days in advance.

11. Contact

Questions or requests? Email hello@runiq.co.uk.