Privacy policy
Last updated: Draft — pending legal review
This notice explains how QoreReach, part of Qore Enterprises, collects and uses personal data when you use our service or visit our website.
TODO before go-live: this is a placeholder drafted for a UK SaaS business. It has not been reviewed by a solicitor and the bracketed details are incomplete. Replace it with reviewed wording before inviting an external customer.
Who we are
QoreReach is operated by Qore Enterprises, a company registered in England and Wales [company number to be confirmed], whose registered office is at [registered address to be confirmed]. For the personal data described in this notice we act as the data controller. Where our customers load their own contact data into QoreReach, they are the controller and we act as their processor under a data processing agreement.
What we collect
Account data you give us, such as your name, work email address, organisation name and billing details. Usage data generated as you work, such as sign-in times, pages visited and actions taken. Customer content you load into the service, including the contacts, companies, opportunities, emails and files belonging to your organisation.
Why we use it and our lawful basis
To provide the service and perform our contract with you; to take payment and prevent fraud, which is in our legitimate interests and required by law; to keep the service secure and reliable, which is in our legitimate interests; and to send service notices you cannot opt out of because they are necessary to the contract. Marketing email to you is sent only with your consent, which you can withdraw at any time.
Sharing
We share personal data with the processors that run the service on our behalf: our hosting and database provider, our email delivery provider, and our payment provider. Each is bound by a written contract and may only act on our instructions. We do not sell personal data.
International transfers
Some of our processors operate outside the UK. Where that happens we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards.
How long we keep it
Account and billing records are kept for the life of the account and for six years after closure, to meet UK accounting and tax requirements. Customer content is kept for as long as your organisation's subscription is active and deleted within [retention period to be confirmed] of closure. Suppression records are kept indefinitely so that people who unsubscribe are never contacted again.
Your rights
Under UK GDPR you may request access to your personal data, ask us to correct or erase it, object to or restrict our processing of it, and ask for a portable copy. You may also complain to the Information Commissioner's Office at ico.org.uk. To exercise any of these rights, email [privacy contact address to be confirmed] and we will respond within one month.
Cookies
We use only the cookies necessary to keep you signed in and to keep the service secure. We do not use advertising or third-party tracking cookies.
Contact
Questions about this notice can be sent to [privacy contact address to be confirmed]. See also our terms of service.