Skip to content
← Back

Legal

Privacy Policy

Last updated: 1 September 2026.

1. Who we are

Foundry is a private community platform for Imperial College London students and alumni interested in the startup ecosystem, operated under the name “Imperial Entrepreneurs”.

The data controller responsible for your personal data is IC Founders Ltd, a company limited by guarantee registered in England and Wales (company number 17171277), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. In this policy “we”, “us” and “our” mean IC Founders Ltd.

Questions about this policy or your data, including any request to exercise your rights, can be sent to contact@imperialentrepreneurs.com.

2. The personal data we collect

We collect only what we need to run a members’ directory and the features you use:

  • Account data — your name and email address. If you sign in with Google, Google provides your name and email to us (see section 4).
  • Profile data (onboarding and after) — the course you study or studied, your graduation year, an optional short bio, an optional profile photograph, optional LinkedIn / GitHub / portfolio links, and (once you complete the post-approval intake) your ranked interests, the venture or role you’re working on, and the sectors and skills you select.
  • Your CV, if you choose to upload one — stored as the file you uploaded. If you tick the separate consent for it, we read the text once to suggest skills from our fixed list for you to confirm — see section 2a below for exactly what that does and doesn’t do.
  • Membership status — whether you are a current student or alum, and your approval status, which our admins set during review.
  • Content you post — the opportunities, events, and VC / grant listings you submit, including any contact email you choose to attach to a listing; and your community posts, including any images you attach and the text you write to describe them.
  • Reports and moderation records — if you report a community post, what you tell us about it; and if one of your posts is removed by an admin, a record of the post and the reason it was removed. See section 8 for how long we keep these.
  • Engagement data — anonymised-to-others counts of views and click-throughs on listings you posted, so you can see how your content performs.
  • Technical and security data — your IP address and request metadata, used by our edge provider and rate limiter to prevent abuse, and limited error diagnostics (e.g. URL, browser, your user ID) if something goes wrong.

We do not deliberately collect special category data (such as health, ethnicity, or political opinions), and we do not ask for payment details — Foundry is free to use. A CV can incidentally carry information from which such things are inferable; we do not extract, infer, or act on any of that — see section 2a.

2a. Your CV: what we do, and don’t do, with it

Uploading a CV is optional, and so is letting us read it. If you tick the separate consent checkbox on upload, we extract the plain text from your CV once, compare it against a fixed list of around 180 skills, and show you the matches as suggestions you can tap to add to your profile. Nothing is added without you choosing to add it.

  • The extracted text is never stored — it exists only for the moment it takes to run that comparison, and is then discarded.
  • The extracted text is never shown back to you or anyone else, sent to a third party, or used for anything except that one comparison.
  • The match is a fixed string comparison, not a model — it can only ever suggest one of the ~180 skills on our list, never anything else.
  • Your CV file itself is kept as you uploaded it (see sections 5 and 8), separately from this suggestion feature, so you can share it or remove it whenever you like.

3. How we use your data, and our lawful basis

Under the UK GDPR we must have a lawful basis for each use of your data:

  • Creating and running your account and verifying your eligibility — to provide the membership service you asked for (performance of a contract under our Terms), supported by your consent at sign-up.
  • Showing your profile in the member directory — your consent. You can withdraw this at any time by editing your profile or deleting your account.
  • Storing a profile photo or a CV you upload — your consent. Both are optional and skippable, and reading your CV to suggest skills needs a separate consent tick, unticked by default.
  • Sending you service / transactional emails (sign-in and password reset, decisions on your application and listings, account and content notices, and replies when you contact us) — necessary to perform our contract with you and our legitimate interest in operating the platform.
  • Keeping the platform secure (anti-bot challenges, rate limiting, abuse prevention) — our legitimate interest in protecting members and the service.
  • Understanding how the product is used (cookieless, pseudonymous analytics) — our legitimate interest in improving Foundry. See our Cookie Policy.

We do not use your data for advertising, we do not sell it, and we do not carry out automated decision-making that produces legal or similarly significant effects about you.

4. Sign-in with Google

If you choose to sign in with Google, Google shares your name, email address, and basic profile identifier with us so we can create or access your account. We only request this basic profile information and do not receive your Google password. Google’s handling of your data is governed by Google’s own privacy policy.

5. Who processes your data on our behalf

Your data is hosted in UK / EU regions. We use the following sub-processors, each under a data processing agreement and each receiving only the data needed for its role:

  • Supabase (EU / London) — database, authentication, and storage. Holds your profile and the content you post.
  • Vercel (EU / Frankfurt) — application hosting and serving.
  • Microsoft Azure (UK South) — image and document storage. Holds images you attach to community posts and any profile photo you upload; these are re-processed on upload, which strips embedded metadata including any location recorded by your camera. It also holds any CV you upload, kept as the file you gave us rather than reprocessed, in a separate, more tightly restricted location that only you and our admins can read.
  • Resend (EU) — sending our service emails; processes the recipient address and message content in transit.
  • Cloudflare (EU) — DNS, inbound contact-email routing, edge security, and the Turnstile anti-bot challenge on our forms. Processes request metadata such as your IP address to block abuse.
  • Upstash (EU) — rate limiting. Stores only short-lived request counters keyed to your user ID or IP; no profile data.
  • Sentry (EU) — error monitoring. May capture technical diagnostics when an error occurs; we do not send it form contents.
  • PostHog (EU) — privacy-friendly, cookieless product analytics (which pages and features are used), tied to a pseudonymous user ID only.

6. International transfers

We aim to keep your data within the UK and EU. Some of our providers are headquartered outside the UK / EU; where any transfer of personal data outside the UK takes place, it is protected by an appropriate safeguard recognised under UK law (such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses).

7. Who can see your data

Your profile (name, course, graduation year, photo, bio, what you’re working on, sectors, skills, and links) is visible to other approved Foundry members in the directory. Your email address is notdisplayed unless you explicitly choose to make a listing’s contact email visible. Your CV is visible only to you and to our admins — it is never shown to other members. Our admins can see all profile data, including email addresses and CVs, for review and operational purposes; every admin view of a member’s CV is individually logged. We do not make your data public on the open internet.

8. How long we keep it

We keep your data while your account is active. When you delete your account (Settings → Delete account) we remove your profile and the content you posted from our live systems. Our admins also run a graduate-cleanup that removes current-student accounts whose graduation year has passed, with a notice giving you the option to reapply as an alum. Residual copies may persist briefly in encrypted backups before being overwritten on our providers’ normal backup cycle.

Some things have a fixed retention period, enforced automatically:

  • Community posts and their images — 7 days. Every post is deleted automatically seven days after it is published, along with any images attached to it. You can delete a post sooner at any time from Community → My posts.
  • Profile photo and CV — until you replace, remove, or your account is deleted. We keep one of each at a time; uploading a new one, removing it, or deleting your account queues the old file for deletion within minutes.
  • Moderation records — 12 months. If an admin removes one of your posts, we keep a record of the removal: the post’s title and text, the reason given, and who removed it and when. We keep this so that a removal can be explained, reviewed, or defended if it is challenged, which is a legitimate interest and, where the record relates to a potential legal claim, is permitted under Article 17(3)(e) UK GDPR even if you ask us to erase your data. It is deleted after 12 months unless a specific dispute is still live.
  • Reports — 12 months. If you report a post, we keep your report, what you told us, and the outcome, on the same 12-month clock.

9. How we protect it

Access to your data is restricted by database row-level security, server-side authorisation checks, and least-privilege access controls. Data is encrypted in transit. We keep the platform patched and monitor for errors and abuse. No system is perfectly secure, but we take reasonable and proportionate measures appropriate to a community of this size.

10. Your rights

Under the UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected — you can edit most of it yourself in your profile;
  • have your data erased — use Settings → Delete account, or contact us;
  • restrict or object to certain processing;
  • data portability (receive your data in a portable format); and
  • withdraw consent at any time, without affecting processing done before withdrawal.

To exercise any of these, email contact@imperialentrepreneurs.com or use the in-app contact form. We will respond within one month.

11. Cookies

We use only strictly necessary cookies (for your sign-in session and security) and run our analytics cookielessly, so we do not show a cookie banner. Full details are in our Cookie Policy.

12. Children

Foundry is intended for Imperial College London students and alumni and is not directed at children under 18. We do not knowingly collect data from anyone under 18.

13. Changes to this policy

We may update this policy from time to time. If we make a material change we will notify members by email at their registered address. The date at the top shows when it was last updated.

14. Contact and complaints

Contact us about your data at contact@imperialentrepreneurs.com. If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We would appreciate the chance to resolve it with you first.