1. Controller and contact details
Stephen Sunday trading as FroggyHub is the data controller for Reacham. Reacham and FroggyHub are product and trading names, not separate incorporated companies.
Address: Stephen Sunday, Ground Floor, Gallery Building, 65-69 Dublin Rd, Belfast, BT2 7HG GB. Privacy, objection, erasure, and support requests: reacham@froggyhub.com.
2. Information we collect
We collect account details such as name, email, authentication and security records; payment and order identifiers from Stripe; the idea, audience, competitors, context, and evidence you submit; report drafts, approvals, delivery and clarification history; support and complaint messages; and limited service, analytics, device, request, and error information needed to operate and protect Reacham.
Receipt-backed research may record public source URLs, dates, metrics, and short permitted quotations or paraphrases. Public handles or quoted material may identify the person who originally published it. We minimize this material and apply source-specific rights rules.
For a bounded buyer-proof run, we may also record a business contact’s public commercial decision, role or business identity, published business contact address and its source, jurisdiction and entity classification, the reason the contact may benefit from Reacham, compliance review evidence, our one initial message, any response, and any objection or opt-out. We do not buy, guess, or enrich personal email addresses for this purpose.
3. Why we use it and our lawful bases
We use account, intake, order, and report information to take steps at your request and perform the Full Demand Map contract. We use payment and accounting evidence to meet legal obligations. We use proportionate source research, security, fraud prevention, support, product analytics, and error information for our legitimate interests in delivering, protecting, and improving a receipt-backed research service.
For the bounded buyer-proof run, our purpose is to identify commercial actors who have publicly described a current market decision and, only where the applicable electronic-marketing rules permit it, send one relevant business message offering a small receipt-backed evidence starter. Where we process a named business contact’s personal data without consent, we rely on legitimate interests only after documenting the purpose, necessity, reasonable expectations, likely impact, and safeguards. Where consent or an opt-in is required, we do not send without it. Contact availability never makes someone a qualified buyer and no automated decision determines whether a person is contacted.
4. Sources and recipients
Most information comes directly from you, Stripe, your use of Reacham, and public or otherwise permitted research sources. Business-contact research may come from a business website, an official corporate register, a public professional profile, a public product or marketplace page, or a public post in which the commercial decision was described. When we contact a person using information obtained elsewhere, the first message identifies Reacham, links to this notice, and explains how to object or opt out.
We disclose information only as needed to service providers, professional advisers, authorities where legally required, or a successor in a properly controlled business transfer. A configured email provider receives the minimum sender, recipient, and message data needed to transmit an approved message; Reacham does not use tracking pixels or remote open beacons for the buyer-proof run.
- Railway and the FroggyHub Postgres infrastructure host the application and primary records.
- Stripe processes Checkout, payments, billing locations, refunds, and payment-risk information.
- Resend or configured email infrastructure sends account, fulfilment, and any individually approved buyer-proof messages.
- Self-hosted Umami processes privacy-minimized page and allowlisted funnel events when enabled.
- Sentry-compatible error tracking and OpenTelemetry/Grafana infrastructure process bounded reliability and incident metadata when enabled.
5. International transfers
Public research and business contacts may concern organisations or people outside the United Kingdom. Some processors may also store or access information outside the United Kingdom. We record the source and jurisdiction used for an approved business-contact route and, where required, rely on the processor’s lawful transfer mechanism and contractual safeguards. You may ask for the source categories or safeguard relevant to your data.
6. Retention
We keep information only for a justified purpose and review it when that purpose ends. Our current schedule keeps abandoned intake for 90 days; support correspondence for two years; contracts, orders and accounting evidence for six years; and operational logs for 30 to 90 days according to the production backend. Buyer report artifacts remain available while the account is active, subject to necessary accounting, dispute, security, and source-audit retention.
For an approved buyer-proof email route, the sendable contact address is encrypted and scheduled for deletion 30 days after the run’s evaluation cutoff. The minimum source, classification, message-integrity, and compliance audit is scheduled for deletion two years after that cutoff. If someone objects or opts out, Reacham deletes the sendable locator and retains only a one-way suppression fingerprint needed to prevent another unsolicited message across runs. That suppression record is retained while Reacham conducts direct outreach and reviewed at least annually.
Automated account export and erasure are not yet self-serve. Requests are handled through the support address. The contact-locator retention and suppression controls described above are enforced in the buyer-proof workflow; other applicable requests are handled manually where technically and legally possible. Expiring backups may retain protected copies until their normal rotation completes.
7. Your rights and direct-marketing objections
Depending on the circumstances, you may request access, the source and categories of your data, correction of inaccurate data, erasure, restriction or objection to processing, or portable data. Email reacham@froggyhub.com. We may need to verify your identity and may retain information where the law or an overriding legitimate need requires it.
You have an absolute right to object to the use of your personal data for direct marketing. You may reply “opt out” to a buyer-proof message or email the address above; Reacham will stop direct marketing to that recipient and apply the cross-run suppression control. Withdrawing consent is as easy as giving it and does not affect earlier lawful processing.
You may complain to the UK Information Commissioner’s Office. We would appreciate the opportunity to address the concern first, but that does not limit your right to contact the regulator.
8. Security, changes, and version
We use access controls, encryption in transit, encryption at rest for sendable buyer-proof contact addresses, one-way suppression identifiers, verified payment webhooks, restricted provider credentials, and operational monitoring appropriate to a small online service. No system is perfectly secure. We version material changes and do not silently rewrite the Terms or Privacy Notice attached to existing evidence. This notice is version reacham-commercial-b2b-2026-07-15, effective 15 July 2026.