Last updated: 1 September 2026
This Privacy Policy describes how AWG Reachify collects, uses and protects your personal data when you use our Service. It forms part of our Terms of Service and has been prepared in accordance with the UK GDPR, the EU GDPR and the Data Protection Act 2018. Please read it carefully.
This Privacy Policy explains how AWG Reachify ("Company", "we", "us" or "our") collects, uses, discloses, retains and protects personal data when you access, register for or use our digital business card, bio-link, analytics, near-field communication ("NFC") product ordering and related software-as-a-service platform (the "Service"). This Privacy Policy forms part of, and is incorporated into, the Terms of Service (the "Terms"). Capitalised terms used but not defined here have the meanings given to them in the Terms. If you do not agree with the practices described in this Privacy Policy, you must not access or use the Service. This Privacy Policy has been prepared in accordance with the UK GDPR, the EU GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended) and any other applicable data-protection legislation (collectively, the "Data Protection Legislation").
AWG Reachify is the data controller responsible for the personal data processed through the Service for the purpose of providing, operating, securing and improving the Service. Where you use the Service to create and publish Business Cards or Bio Links that collect personal data of third parties (such as visitors who scan your card or save your contact details), you act as a separate data controller in respect of that data. In such cases, AWG Reachify acts as a data processor on your behalf. You are solely responsible for ensuring that your collection and processing of third-party personal data complies with the Data Protection Legislation, including obtaining any necessary consents and providing any required privacy notices to those individuals. Our contact details, including for data-protection enquiries, are set out in Section 22 (Contact and Data Protection Enquiries).
We process your personal data only where we have a lawful basis to do so. The lawful bases we rely on are: (a) Performance of a contract: processing necessary to provide the Service you have requested, including creating and managing your Account, processing payments, and delivering NFC products. (b) Legal obligation: processing necessary to comply with a legal or regulatory obligation, such as maintaining financial records, responding to lawful requests, and preventing fraud. (c) Legitimate interests: processing necessary for our legitimate interests in operating, securing, improving and developing the Service, provided such interests are not overridden by your rights and freedoms. Our legitimate interests include analytics, security monitoring, service reliability and communication about your Account. (d) Consent: where you have given clear affirmative consent, for example for certain marketing communications or for non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, we have carried out a balancing test to ensure those interests are not disproportionate to your rights. You may contact us to obtain a copy of the relevant balancing assessment.
We collect the following categories of personal data: (a) Account data: your name, email address, role, and any profile details you provide when registering or updating your Account. (b) Payment data: information needed to process payments, such as billing address and transaction identifiers. Full card details are never received or stored by us; they are handled entirely by Stripe, our payment processor. (c) Content data: any text, images, logos, contact details, links and other material you upload, generate or publish through the Service, including the contents of your Business Cards and Bio Links. (d) Usage and analytics data: information about how you and visitors interact with the Service, including page views, card views, QR scans, contact saves, CTA taps, social clicks, device type, browser, IP address (used for approximate location and currency detection), and similar engagement metrics. (e) Technical and log data: log records, timestamps, session identifiers, cookies and similar technologies, and error reports generated when you access the Service. (f) NFC order data: recipient name, shipping address, city, postcode, country, quantity and order notes provided when you order NFC-enabled physical products. (g) Team data: the email addresses and roles of team members you invite, and records of access you grant or revoke. We do not collect special category data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health or sex life) unless you voluntarily include such data in your Content. Where you do, we process it only to the extent necessary to display your Content as you direct, and you remain responsible for the lawfulness of doing so.
We use your personal data for the following purposes: (a) to create, manage and authenticate your Account and to provide the Service you have requested; (b) to process payments through Stripe, manage subscriptions, and handle billing, renewals and refunds; (c) to fulfil NFC product orders, including processing shipping details and communicating order status; (d) to display analytics and engagement metrics within your dashboard, and to enable export of that data where your Plan permits; (e) to detect, prevent and investigate fraud, abuse, security incidents and other unlawful or harmful activity; (f) to communicate with you about your Account, including technical notices, security alerts, support responses and policy updates; (g) to send marketing communications about features, offers and updates, but only where you have consented or where we have another lawful basis, and only where permitted by the Privacy and Electronic Communications Regulations 2003 (as amended); (h) to maintain records required for accounting, tax and regulatory purposes; and (i) to operate, secure, monitor, improve and develop the Service and its features.
All payments for the Service are processed by Stripe Payments UK Ltd ("Stripe"). When you make a payment, certain data (such as your email address, billing details and transaction identifiers) is shared with Stripe so that it can process the transaction. We do not receive, access or store your full card number, card verification value or other complete payment credentials. Stripe processes and stores such data in accordance with its own terms of service and privacy policy, which are available at stripe.com. Your use of Stripe's services is also subject to those terms. Transaction metadata, including an application identifier and your user identifier, is attached to Stripe sessions and subscriptions to enable us to reconcile payments with your Account and to report on transactions. We retain billing records for as long as required for accounting, tax and regulatory purposes.
We do not sell, trade or rent your personal data to third parties. We share personal data only as described in this Privacy Policy or as required by law, with the following categories of recipient: (a) Payment processors: Stripe, for the purpose of processing payments, managing subscriptions and handling refunds and chargebacks. (b) Service providers and sub-processors: trusted third parties that assist us in operating the Service, such as cloud hosting, email delivery, analytics, error monitoring and customer-support providers, each acting under contract and bound by confidentiality and data-protection obligations. (c) Team members: where you administer a team Account, the email addresses and roles of your invited members are processed to provide access. Team members may see certain information you choose to share with them within the Service. (d) Public recipients: information you choose to publish on a Business Card or Bio Link is made available to anyone who accesses that published link, in accordance with your publication and sharing settings. (e) Legal and regulatory recipients: where disclosure is required by law, regulation, court order, or to protect the rights, property, safety or security of the Company, our Users or others. In the event of a merger, acquisition, reorganisation or sale of all or part of our business, personal data may be transferred as part of that transaction, subject to the protections described in this Privacy Policy.
The Service is operated from England. Some of our service providers and sub-processors may process personal data outside the United Kingdom or the European Economic Area. Where personal data is transferred outside the United Kingdom, we rely on an adequacy decision where one applies, or on appropriate safeguards such as the International Data Transfer Agreement issued by the Information Commissioner's Office, standard contractual clauses, or another lawful transfer mechanism recognised under the Data Protection Legislation. Where you publish a Business Card or Bio Link, the data you choose to make public may be accessible globally. You are responsible for considering the implications of making personal data publicly available, including any cross-border aspects.
We use cookies and similar technologies (such as local storage) to operate, secure, analyse and improve the Service, to remember your preferences (such as your selected display currency and language), and to provide certain functionality. The cookies we use fall into the following categories: strictly necessary cookies (required for the Service to function), functional cookies (remembering your preferences), analytics cookies (understanding how the Service is used) and, where you have consented, marketing cookies. You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent parts of the Service from working. Further detail is set out in our Cookie Policy, which is incorporated into this Privacy Policy by reference, and your choices are managed through the cookie consent mechanism presented when you first access the Service.
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, tax or regulatory requirements. In particular: (a) Account data is retained while your Account is active and for a reasonable period after closure to allow recovery, audit and dispute resolution; (b) billing and transaction records are retained for the period required by applicable accounting and tax law; (c) analytics and log data is retained for a limited operational period and then aggregated or deleted; and (d) NFC order data is retained for the period necessary to fulfil the order and meet any consumer-law record-keeping requirements. When you close your Account, we will delete or anonymise your personal data in accordance with this section, except where we are required to retain it for legal, regulatory or legitimate security purposes.
Under the Data Protection Legislation, you have the following rights, subject to certain exceptions: (a) The right to be informed about how we use your personal data (this Privacy Policy and any privacy notices provided at the point of collection). (b) The right of access to the personal data we hold about you. (c) The right to rectification of inaccurate or incomplete personal data. (d) The right to erasure ("the right to be forgotten") in certain circumstances. (e) The right to restrict processing in certain circumstances. (f) The right to data portability, where applicable. (g) The right to object to processing carried out on the basis of legitimate interests or for direct marketing. (h) Rights relating to automated decision-making and profiling; we do not carry out solely automated decision-making that produces legal or similarly significant effects. You also have the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal. To exercise any of these rights, contact us using the details in Section 22. We will respond within one month, extendable by a further two months where requests are complex or numerous, in which case we will inform you of the extension and the reasons within the first month. You have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) or your local supervisory authority if you believe our processing of your personal data breaches the Data Protection Legislation.
Where you create or administer a team Account, you are the Team Owner and a data controller in respect of your team members' personal data. We process team members' email addresses and roles on your behalf as a data processor, in accordance with your instructions through the Service. You are responsible for ensuring that you have a lawful basis to invite team members, that you have provided them with any required privacy information, and that your handling of their data complies with the Data Protection Legislation. We may send welcome and onboarding communications to invited members to enable access to the Service. Team members may update certain of their own profile details. Where you remove a team member, their access is revoked, and their data is handled in accordance with this Privacy Policy and the Terms.
When you publish a Business Card or Bio Link, anyone who accesses that link may interact with it, for example by saving your contact details as a vCard, scanning a QR code, tapping a call-to-action button or clicking a social link. Such interactions are recorded as engagement events to provide analytics to you. Where those interactions involve the personal data of visitors (for example, where a visitor's device or IP address is logged), we process that data only to provide the analytics feature and to secure the Service, and we do so on the basis of our legitimate interests. We do not use visitor engagement data to identify or profile individuals for marketing. You are responsible for ensuring that any personal data you choose to publish or collect through your Business Cards or Bio Links is processed lawfully, including providing any necessary privacy notices to your visitors and obtaining any required consents.
The Service collects and displays analytics relating to your Business Cards and Bio Links, including views, QR scans, contact saves, CTA taps and social clicks. This data is aggregated and presented to you within your dashboard for informational purposes. We also use limited analytics to understand overall Service usage, improve performance and reliability, and detect abuse. Where we use third-party analytics tools, they process data under our instructions and in accordance with applicable data-protection agreements. Analytics data is provided for informational purposes only and is not guaranteed to be accurate, complete or error-free. Where your Plan permits export of analytics, you are responsible for the secure handling and lawful processing of any exported data in accordance with the Data Protection Legislation.
When you order NFC-enabled physical products, we collect the recipient name, shipping address, city, postcode, country, quantity and any order notes you provide. We use this data to fulfil and deliver your order, to communicate order status, and to maintain records for consumer-law and accounting purposes. We share shipping data with delivery and fulfilment partners to the extent necessary to dispatch and deliver your order. We retain order records for the period required to meet legal, tax and consumer-protection obligations, after which they are deleted or anonymised.
Where you have consented, or where we have another lawful basis and it is permitted by the Privacy and Electronic Communications Regulations 2003 (as amended), we may send you marketing communications about features, offers and updates relating to the Service. You can opt out of marketing communications at any time by following the unsubscribe link in any marketing email, by updating your Account settings, or by contacting us. We will honour opt-out requests promptly. We will not send you marketing electronic communications without a lawful basis, and we will not share your personal data with third parties for their own independent marketing purposes.
We take reasonable technical and organisational measures to protect your personal data from loss, theft, misuse, unauthorised access, disclosure, alteration and destruction. These measures include encryption of data in transit and at rest, access controls, authentication, regular security review, and monitoring for suspicious activity. No system or transmission can be guaranteed to be completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with the Data Protection Legislation and within the applicable timeframes.
The Service is not directed at, and is not intended for use by, individuals under the age of eighteen (18) years. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us using the details in Section 22, and we will take steps to delete that data.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects. We may use automated processing for operational purposes such as fraud detection, currency detection and service reliability, but such processing does not result in automated decisions that significantly affect you without human involvement.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations or the features of the Service. The "Last updated" date at the top of this page indicates when the Policy was last revised. Where changes are material, we will use reasonable efforts to notify you, for example by email or by a prominent notice within the Service. Your continued use of the Service after the effective date of any revised Privacy Policy constitutes your acceptance of the revised Policy.
This Privacy Policy is incorporated into, and forms part of, the Terms of Service. In the event of any conflict between this Privacy Policy and the Terms, the Terms shall prevail in respect of non-data-protection matters, and this Privacy Policy shall prevail in respect of data-protection matters. References in the Terms to the Privacy Policy, the Cookie Policy and the Data Protection Legislation have the meanings given to them in those documents.
If you have any questions, requests or complaints about this Privacy Policy or our handling of your personal data, including to exercise any of your data-protection rights, please contact us as follows: Email: hello@awgreachify.com For the attention of: Legal / Data Protection We aim to respond to all enquiries within thirty (30) days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) or your local data-protection supervisory authority. By using the Service, you confirm that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein.