Privacy Policy

Last updated: 1 September 2026

This policy explains what whyfound does with your information, the lawful bases we rely on under the UK GDPR, and the rights you have. It applies to this website, the diagnostic, paid reports, 1:1 sessions and our emails.

1. Who is responsible for your data

whyfound, operated by Robert Dadzie (sole trader, United Kingdom), is the data controller. For any privacy question or request, email hello@whyfound.com.

2. What we collect

  • Your name, email address and company name, if you provide them.
  • The business type, problem description, frequency, impact and what you have already tried, as you wrote them.
  • Your answers to the diagnostic questions and any pain areas ticked.
  • The report generated from those answers.
  • Purchase records: what you bought, the amount, the currency, the date, the payment status and your Stripe customer reference. We never receive or store your full card number.
  • Booking details for 1:1 sessions: the slot you choose, your time zone and anything you add to the booking notes.
  • Messages you send us through the contact form, the AI assistant or by email.
  • Basic technical and analytics data such as pages viewed and approximate location derived from your IP address.

3. Why we use it, and our lawful basis

  • To deliver what you asked for — generating your report, unlocking your PDF, running your session, answering your message. Lawful basis: performance of a contract, or steps taken at your request before a contract.
  • To take payment and keep records — processing your card payment, issuing receipts, and keeping accounting records. Lawful basis: contract and legal obligation.
  • To improve the service — reviewing anonymised patterns in submissions and asking for feedback after a purchase. Lawful basis: legitimate interests.
  • To send marketing emails — only if you tick the optional opt-in box. Lawful basis: consent, which you can withdraw at any time.

We do not ask for special category data (such as health information) and ask that you do not include it in your answers.

4. Who processes it on our behalf

We use a small number of trusted providers, each bound by a data processing agreement and permitted to use your data only to provide their service to us:

  • Our hosting and database provider, for the website and stored records.
  • Stripe, for payment processing, receipts and tax handling.
  • Our email provider, for report, receipt, booking and feedback emails.
  • Cal.com, for scheduling 1:1 sessions and sending calendar invites.
  • Google Meet, for hosting the video session itself.
  • Our AI provider, for the website assistant that answers questions.

We never sell your data, and we do not share it with anyone for their own marketing.

5. Where it is stored

Your submissions, reports and purchase records are stored in a private database hosted in the European Union. Some providers (for example payment and email services) may process data outside the UK and EU; where they do, transfers are covered by the UK International Data Transfer Addendum or equivalent safeguards.

6. Who can see it

Only the operator of this site. Records are held in a private database that is not readable by other visitors and requires an authenticated administrator sign-in. Reports are not published and are excluded from search engines.

7. How long we keep it

  • Diagnostic submissions and reports: up to two years from the date you submit them.
  • Purchase and payment records: six years plus the current tax year, because UK tax law requires it.
  • Marketing contacts: until you unsubscribe, then removed from the mailing list.

You can ask us to erase your records sooner and we will do so unless we are legally required to keep them.

8. Cookies and analytics

We use only the cookies and local storage needed to run the site (for example remembering your in-progress diagnostic) plus privacy-respecting analytics that tell us how many people visit each page. We do not use advertising or cross-site tracking cookies.

9. Your rights

Under the UK GDPR you can ask us to:

  • Give you a copy of the information we hold about you.
  • Correct anything that is inaccurate.
  • Erase your submission and report permanently.
  • Restrict or object to how we use your information.
  • Send your data to you or another provider in a portable format.
  • Withdraw consent to marketing emails at any time.

Email hello@whyfound.com and we will respond within one month. There is no charge.

10. Security

Data is transmitted over HTTPS and stored with row-level access controls so that records are only reachable by an authenticated administrator. Access to the admin area is protected by a password and, where available, additional verification.

11. Complaints

If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

12. Changes to this policy

We will update this page when our practices change and revise the date at the top. Material changes affecting how we use your data will be explained clearly.

See also our Terms of Service and Refund Policy.

Back to home