1. Introduction
Quantica Labs Ltd (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the SurveyAgent platform (“the Service”), in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable data protection legislation.
- Data Controller
- Quantica Labs Ltd (Company No. 17124284, incorporated in England & Wales)
- Registered Office
- 14a Mill Close, Borrowash, Derby, England, DE72 3GU
- Contact Email
- info@surveyagent.co.uk
- Contact Telephone
- 07964 588513
- Data Protection Contact
- Benjamin James Naylor, Director
- ICO Registration Number
- Pending — application submitted July 2026
2. Data We Collect
We collect and process the following categories of personal data:
- Account Information: Name, email address, telephone number, business name, and professional role
- Authentication Data: Encrypted password credentials (bcrypt-hashed, never stored in plaintext), session tokens, and optional two-factor authentication (TOTP) secrets
- Business Data: Survey leads, job details, pricing information, service areas, and related correspondence entered into the platform by users
- Transaction Data: Payment records, Stripe account identifiers, commission calculations, and invoice references
- Usage Data: Login timestamps, IP addresses, user-agent strings, and pages visited within the platform (retained in security audit logs)
- Communication Data: Emails and SMS messages sent through the platform’s automated notification system (e.g., lead alerts, quote notifications, booking confirmations)
3. Legal Basis for Processing
We process your personal data under the following lawful bases:
- Contract Performance (Article 6(1)(b)): Processing necessary for the performance of the contract between you and Quantica Labs Ltd for the provision of the SurveyAgent service
- Legitimate Interests (Article 6(1)(f)): Processing necessary for the operation, security, and improvement of the platform, including audit logging and fraud prevention
- Consent (Article 6(1)(a)): Where you have given specific consent for particular processing activities
- Legal Obligation (Article 6(1)(c)): Where processing is necessary to comply with a legal obligation, including HMRC record-keeping requirements
4. How We Use Your Data
Your personal data is used exclusively for the following purposes:
- Providing and maintaining the SurveyAgent platform and its core functionality
- Managing your account, authentication, and access permissions
- Processing and distributing survey leads between platform users
- Facilitating payment processing, commission calculations, and financial reconciliation
- Sending platform notifications related to leads, bookings, and account activity
- Providing customer support and resolving technical issues
- Ensuring platform security, detecting suspicious activity, and preventing unauthorised access
5. Sub-Processors and Third-Party Services
Quantica Labs Ltd does not share, sell, rent, or disclose your personal data to any third party for marketing, advertising, analytics, or profiling purposes.
The following sub-processors are used solely to operate the Service. Each is bound by a Data Processing Agreement (or equivalent contractual terms) that requires them to process personal data only on our documented instructions and to apply appropriate technical and organisational security measures:
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Render Services, Inc. | Application hosting, database hosting, log storage | All platform data | United States (Oregon) |
| Stripe Payments Europe Ltd | Payment card processing and subscription billing | Cardholder data, transaction records, billing contact | Ireland / United States |
| Resend, Inc. | Transactional email delivery | Recipient email, name, message contents | United States |
| The SMS Works Ltd | Transactional SMS delivery | Recipient mobile number, message contents | United Kingdom |
| Vapi, Inc. | Voice AI call handling (where activated by the firm) | Caller phone number, call transcripts, recordings | United States |
| HaveIBeenPwned | Breached-password detection (anonymised k-anonymity check) | Truncated SHA-1 hash prefix only; no email, name, or full password is transmitted | Australia / United Kingdom |
Independent controllers. Where you connect your Xero accounting account to SurveyAgent, Xero (Xero (UK) Limited) acts as an independent data controller for the accounting records held in your Xero organisation. Data written from SurveyAgent into Xero (invoices, contacts, payments) is thereafter governed by Xero’s own privacy policy in addition to ours.
We will notify registered platform users of any material change to this sub-processor list at least 30 days before it takes effect, unless the change is required for security or legal reasons in which case notice will be given as soon as practicable.
6. Data Storage and Security
We apply the following technical and organisational measures to protect your personal data:
- Encryption in transit: All traffic between your browser and our servers is encrypted using TLS 1.2 or higher; HTTP Strict Transport Security (HSTS) is enforced with a one-year policy on all subdomains.
- Encryption at rest: Sensitive third-party access tokens (e.g., Xero OAuth refresh tokens) are encrypted with AES-256-GCM using a per-installation encryption key held only in production infrastructure.
- Password protection: User passwords are salted and hashed using bcrypt with a cost factor of 12. Passwords found in known public data breaches are automatically rejected at registration and password change (using the HaveIBeenPwned k-anonymity API, which never receives the full password).
- Brute-force protection: Login endpoints are rate-limited per IP address and per user account. Accounts are temporarily locked after 10 failed login attempts with progressive backoff.
- Session security: Session cookies are HttpOnly, Secure, and SameSite=Lax. Sessions expire after 30 days of inactivity and are invalidated on password change.
- Two-factor authentication: TOTP-based two-factor authentication is available for all users and required for account owners and super-administrators.
- Security headers: All application responses include a Content Security Policy, X-Frame-Options: DENY (via frame-ancestors), X-Content-Type-Options: nosniff, and Referrer-Policy: strict-origin-when-cross-origin.
- Audit logging: Security-relevant events (logins, password changes, administrative actions, data exports, deletions) are recorded in an append-only audit log retained for a minimum of 12 months.
- PII redaction in logs: Application request logs automatically redact passwords, tokens, hashes, authorisation headers, and mask email addresses and phone numbers before storage.
- Access controls: Access to production databases is restricted to authorised personnel via key-based authentication over TLS. Multi-tenant isolation is enforced at the application layer by account and firm identifiers on every query.
- Backups: Production databases are backed up automatically by our hosting provider with encryption at rest. Backup retention follows the hosting provider’s Pro plan schedule.
7. Data Retention
- Active accounts: Personal data is retained for the duration of your active use of the Service.
- Inactive accounts: Data associated with deactivated accounts is retained for 12 months following deactivation, after which it may be permanently deleted.
- Deleted accounts: Upon a verified account deletion request, personal data is permanently removed within 30 days, subject to overriding legal retention requirements.
- Financial records: Invoices, payment records, and commission records are retained for 6 years plus the current tax year in accordance with HMRC requirements, even where an account is otherwise deleted. Deletion requests will result in pseudonymisation of the personal identifiers within these records rather than full erasure where full erasure would breach a legal obligation.
- Audit logs: Security audit records are retained for a minimum of 12 months to enable breach detection and investigation.
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of Access (Article 15): You may request a copy of all personal data we hold about you.
- Right to Rectification (Article 16): You may request correction of any inaccurate or incomplete personal data.
- Right to Erasure (Article 17): You may request deletion of your personal data, subject to any overriding legal obligations.
- Right to Restrict Processing (Article 18): You may request that we restrict processing of your personal data in certain circumstances.
- Right to Data Portability (Article 20): You may request a copy of your data in a structured, commonly used, machine-readable format (JSON).
- Right to Object (Article 21): You may object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time.
How to exercise these rights. Registered users can exercise the rights of access and portability directly from within the platform: Settings → Privacy & Data → Download my data. Erasure requests can be raised from Settings → Privacy & Data → Request account deletion; verified requests are actioned within 30 days. Alternatively, contact us at info@surveyagent.co.uk. We will respond to all requests within 30 days.
9. User Responsibilities
Each firm using the SurveyAgent platform is an independent data controller in respect of any personal data they input, manage, or process through the Service. This includes, but is not limited to:
- Lead information (names, addresses, contact details of prospective clients)
- Client correspondence and notes
- Staff and team member details
Firms are solely responsible for:
- Ensuring they have a lawful basis for processing any personal data they enter into the platform
- Obtaining appropriate consent from data subjects where required
- Maintaining their own GDPR compliance and (where applicable) ICO registration
- Responding to data-subject access requests relating to data they control
- Ensuring the accuracy of personal data they input
- Complying with all applicable data protection laws in their jurisdiction
Quantica Labs Ltd acts as a data processor in respect of data entered by firms and processes such data only as necessary to provide the Service. A Data Processing Agreement is available on request.
Addition (24 August 2026) for firms that connect Gmail: where a firm connects a Gmail mailbox, we process emails sent on that firm’s behalf through the connected mailbox solely to provide the Service.
10. Data Breach Notification
In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we will:
- Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach
- Notify affected individuals and affected firms (as controllers) without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Document all data breaches, including their effects and remedial actions taken
11. Cookies and Tracking
The SurveyAgent platform uses only essential, strictly necessary cookies:
sa_session— authenticated session cookie (HttpOnly, Secure, SameSite=Lax, 30-day expiry)
We do not use analytics cookies, advertising cookies, tracking pixels, or third-party tracking scripts. No data is shared with Google Analytics, Meta, or any advertising or analytics platform.
12. Children’s Data
The SurveyAgent platform is a business-to-business service and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors.
13. International Transfers
Primary application data (including all customer records, leads, jobs, and audit logs) is hosted by Render Services, Inc. in the Frankfurt, Germany region — an adequate jurisdiction under UK GDPR (European Economic Area). No international transfer mechanism is required for data at rest.
Certain US-based sub-processors process limited data as follows:
- Stripe Payments Europe Ltd (Ireland, controller) with Stripe, Inc. (US) as processor for card processing
- Resend, Inc. (US) — outbound email delivery
- Vapi Labs, Inc. (US) — AI phone assistant (optional add-on)
- OpenAI Ireland Ltd / OpenAI, L.L.C. (US) — AI transcription and prompt processing (optional add-on)
Transfers to the US are protected by the UK Extension to the EU-US Data Privacy Framework where the recipient is self-certified, or otherwise by the ICO’s International Data Transfer Agreement (IDTA) / EU Standard Contractual Clauses combined with the UK Addendum.
We have carried out a Transfer Risk Assessment for each US-based sub-processor and consider the safeguards in place — combined with our own encryption at rest and access controls — adequate under UK GDPR Article 46. A copy of the Transfer Risk Assessment is available to controllers on request.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be notified to registered users via the platform. Continued use of the Service following such notification constitutes acceptance of the updated policy.
The official platform policy dated 9 July 2026 is published here for public access. The only addition since that date is the Gmail-as-connected-mailbox sentence in section 9, dated 24 August 2026.
15. Complaints
If you have a complaint about how we handle your personal data, please contact us at info@surveyagent.co.uk or write to Quantica Labs Ltd, 14a Mill Close, Borrowash, Derby, DE72 3GU in the first instance. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk
Telephone: 0303 123 1113