Legal
Privacy
policy.
How Boring Software Ltd collects, uses, and protects your personal data and the lead data you process through Hawfinch.
Last updated: 7 October 20261. Information we collect
Boring Software Ltd, company number 16328193 ("we", "us", "Hawfinch"), collects information in two main categories.
1.1 Account information
Your name, email address, company name, and billing details, which you provide when you request a demo, sign a contract, or correspond with our team.
1.2 Platform data
The lead records, campaign configurations, buyer routing rules, validation results, and analytics that you create or process through the Hawfinch platform.
1.3 Technical data
Limited technical data such as IP addresses, browser type, and access timestamps when you log in to the dashboard or call our API.
2. How we use your information
We use account information to provision and maintain your account, respond to support requests, send service-critical communications (such as maintenance notices and security alerts), and process billing.
Platform data is used solely to operate the features you have contracted for, including lead ingestion, HLR validation, waterfall routing, campaign management, and reporting.
We do not sell, rent, or trade your personal data or your lead data to any third party. Aggregated, fully anonymised usage statistics (for example, total API call volumes across the platform) may be used internally to plan infrastructure capacity.
3. Data storage and infrastructure
Hawfinch runs on shared, managed infrastructure. Your lead data, campaign configuration, and analytics are logically separated from every other customer's: every request and query is scoped to your account, and no other customer can access your data. Customers on Enterprise plans can request dedicated infrastructure.
All data is stored in data centres in London, United Kingdom, operated by established cloud providers. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
We do not transfer personal data outside the UK or EEA unless required to do so under a lawful transfer mechanism (such as UK International Data Transfer Agreements), and we will inform you before any such transfer takes place.
4. Data retention
We retain your platform data for the duration of your service agreement. When your contract ends, we keep your account data available for thirty (30) days so that you can export lead records, campaign history, and reporting data via the API or CSV download from the dashboard.
After this export window, all of your account data, including backups, is securely destroyed within sixty (60) days.
Account information (name, email, billing records) may be retained for up to six (6) years after termination to comply with UK financial record-keeping obligations, after which it is also deleted.
5. Third-party services
We work with a small number of third-party processors. These currently include our cloud hosting provider, which runs our servers in London; an HLR provider, which checks phone numbers when you switch on HLR lookups; Apple Push Notification service, which delivers alerts to the iOS app; and a payment provider for billing.
Each processor is bound by a Data Processing Agreement and has been assessed for compliance with UK GDPR requirements. We only share the minimum data necessary for each provider to deliver its service, and your lead data is only shared with the hosting provider that operates the underlying servers and, where you switch on HLR lookups, with the HLR provider, which receives the phone number being checked. Leads you route to your own buyers are delivered on your instructions.
6. Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing based on legitimate interests and the right to withdraw consent where consent is the legal basis.
To exercise any of these rights, please contact us or email [email protected]. We aim to respond to all data rights requests within thirty (30) days.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
7. Cookies and tracking
The Hawfinch marketing site (hawfinch.com) uses Plausible Analytics, a privacy-focused analytics tool that does not use cookies and does not collect personal data. No tracking cookies are set when you browse our public pages.
The Hawfinch platform dashboard uses a small number of strictly necessary session cookies to keep you logged in and to remember your display preferences. We do not use any third-party advertising or remarketing cookies anywhere on our sites.
8. Security
This section describes how we protect your data.
8.1 Encryption
Data at rest is encrypted with AES-256. Data in transit is protected by TLS 1.2 or higher.
8.2 Separation between customers
Each customer's data is logically separated: every request and query is scoped to that customer's account and checked against its access controls, so no other customer can access your data. Dedicated infrastructure is available on Enterprise plans.
8.3 Access controls and testing
Access to production systems is limited to authorised personnel via multi-factor authentication and audited access controls. We test our systems for vulnerabilities and treat critical findings as a priority. Service status and how we monitor it are described on our status page.
9. Mobile application
The Hawfinch iOS application collects and processes the following additional data categories specific to mobile usage.
9.1 Biometric authentication (Face ID / Touch ID)
If you enable biometric lock, the app uses Apple's Local Authentication framework to verify your identity. Hawfinch never receives, stores, or transmits your biometric data. The biometric check runs entirely on your device using Apple's Secure Enclave. We only store a boolean preference indicating whether you have enabled biometric lock.
9.2 Push notifications
If you grant notification permission, Apple assigns a device token that allows us to send alerts about lead activity, campaign status, and other events you have configured. This device token is stored on our servers and is associated with your user account. You can revoke notification permission at any time through your device's Settings app, and we will stop sending push notifications. Device tokens are deleted when you log out or delete your account.
9.3 On-device storage
The app stores your sign-in token in the iOS Keychain on your device. All locally stored data is deleted when you log out.
9.4 Keychain
Your authentication credentials are stored in the iOS Keychain, which is protected by the operating system's hardware-backed encryption. Keychain data is scoped to the Hawfinch app and is not accessible by other applications.
10. Account deletion
You can ask your organisation’s admin to remove your account at any time, or contact us at [email protected]. When an account is deleted, we immediately and permanently delete your user record, all active sessions, and your device tokens. Locally stored data on your device (your sign-in token and cached profile data) is also cleared.
If you are the sole administrator of an organisation, please contact us before deleting your account so that we can assist with data export or ownership transfer. Lead data associated with your organisation is retained in accordance with your service agreement and section 4 (Data retention) of this policy.
11. Data Protection Officer
Boring Software Ltd has appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with this policy and applicable data protection legislation.
You can contact the DPO at [email protected] or by writing to: Data Protection Officer, Boring Software Ltd, 128 City Road, London, EC1V 2NX, United Kingdom.
12. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or platform capabilities. Where we make material changes, we will notify the primary account contact by email at least thirty (30) days before the revised policy takes effect and will display a notice within the platform dashboard.
The "Last updated" date at the top of this page indicates when the policy was most recently revised. Previous versions are available on request.
13. Governing law
This Privacy Policy, and any dispute or claim arising out of or in connection with it, shall be governed by and construed in accordance with the laws of England and Wales.
14. Contact
For any privacy-related questions, data rights requests, or concerns about how we handle your information, please contact us or email [email protected].
Data rights
request?