Privacy Notice
Last updated
Specify is a founder-stage company. This notice describes what we actually collect today, not what we might collect later.
- Before you send us anything
- Remove names, personal data, prices and confidential project details from any enquiry text you paste. The preliminary audit is not the place for material you would not want leaving your organisation.
Who is responsible for this data
Specify decides what is collected here and why, which makes Specify the controller of it under the GDPR. Specify is a trading name. The business is not yet incorporated, so there is no registered company name, company number or registered office to publish, and inventing one would be worse than saying so. This section will name the entity as soon as one exists.
Write to tpg@specify.digital about anything in this notice, including a request to see, correct or delete what we hold. Two founders read that address and one of them answers.
What is collected
- Contact details you supply when you write to us or apply to the founding-partner programme: name, work email, company, optional website and role.
- The enquiry text you submit, exactly as you wrote it.
- Your consent selections.
- If you join the founding-partner list: your work email and how you describe what you sell.
- If you apply to be a founding partner: your company, the request you describe, your answers about how enquiries reach you, why you would be a valuable partner, and what you would use the credit for.
- The name and role of the person you nominate as able to approve what your business can deliver. If that is not you, they have not visited this site, so tell them their details were shared and that they can ask us to remove them.
- If you write to us as an investor: your name, work email, firm, role and location, the type of investor you are, the stage and cheque size you work at, the sectors you cover, a profile link, how you came across us, and what you tell us about your interest, what you could contribute and what you want to ask.
- If you create a store: the store's name and web address, the country and currency it trades in, a contact email we send a code to and ask you to enter back, your acceptance of the terms, and the identifier of the store that was created.
- If you send an unsolicited application: your name, email, where you are, your current education or role, any links you supply, and your written answers about what you would add, one piece of your work, and whether you can work on site.
- Standard technical logs produced by hosting.
We do not ask for special category data, meaning health, racial or ethnic origin, religion, political opinion, trade union membership, sex life, sexual orientation, genetic or biometric information. Do not put any of it in free text. If it arrives anyway we delete it rather than keep it.
Why it is collected, and on what legal basis
Each purpose names the lawful basis it relies on. Where the basis is consent you can withdraw it, and where the basis is our legitimate interest you can object.
- To assess a consulting brief or a founding-partner application, and to reply to you. Basis: taking steps at your request before entering a contract.
- To tell you when we open your sector, if you joined the founding-partner list. Basis: your consent. Withdraw it by replying to any message from us, or by writing to the address above.
- To consider an application for work and reply to it, including the ones we decline. Basis: taking steps at your request before entering a contract. Applications are not used for anything else and are not shared outside the two founders.
- To understand where Catalogue Blind Spots and Capability Gaps are commercially significant across early enquiries. Basis: our legitimate interest in learning which problems are worth building for. This is done on aggregated and redacted material, and it does not require knowing who anyone is.
- To consider an approach from an investor and reply to it. Basis: our legitimate interest in raising investment for the business.
- To create and run the store you asked us to create, and to contact you about it. Basis: performance of the terms you accepted when you signed up.
- To operate, secure and debug the service, and to keep a record of what we sent you. Basis: our legitimate interest in running a service that works and is not abused.
Withdrawing consent, or objecting to a legitimate interest, does not undo anything done lawfully before you did so. There is no automated decision-making that produces a legal or similarly significant effect on anyone.
Who can access it
Submissions are visible to the two founders. They are not shared with other companies, and they are not published or used publicly without separate written permission.
Three categories of provider process data on our behalf, under each provider's written data processing terms:
- OpenAI, for the preliminary analysis. The enquiry text you submit is sent to OpenAI to produce the preliminary result. If you do not want text leaving our systems, do not use the paste or describe options; the worked locker example runs entirely in your browser.
- Resend, for notification email. Resend receives the message and the address it goes to.
- Microsoft Azure, for hosting, the database, file storage and the site measurement described under Cookies below. Everything else sits here.
These terms commit each provider to process the material only on our instructions and to keep it secure. There is no fourth category. Nothing is sold, nothing is shared with advertisers, nothing is used for advertising and nothing is passed to a data broker.
Where it is processed
Hosting, the database and file storage are in the European Union. The specific regions, resource configuration and network detail are shared under a technical review rather than published, which is the same position taken on the Technical page and is about not handing an attacker a map.
Two of the three providers process some data outside the European Economic Area. OpenAI processes API requests in the United States. Resend delivers email from the United States. Both transfers rely on the Standard Contractual Clauses approved by the European Commission, incorporated into the data processing terms we have accepted with each of them. Ask and we will send you the relevant terms.
Model training
Submitted customer and company information is not used to train general-purpose models.
OpenAI does not use material submitted through its API to train its models. It holds API content for a limited period for abuse monitoring and then deletes it. We train no model of our own, on your submissions or on anything else.
How long it is kept
Nothing is kept indefinitely. At the end of a period below the record is deleted, not archived under a different name.
- Enquiry submissions to the retired Enquiry Audit, including the preliminary analysis shown to you at the time: 24 months from submission. Nothing new is collected this way.
- Contact details from a consulting brief or any other enquiry to us: 24 months from our last exchange with you.
- Founding-partner applications: 24 months from the decision on them.
- The founding-partner list: until you ask to come off it, or until we stop running the programme, whichever is first.
- The details of a person nominated as able to approve capability: deleted with the submission they arrived on, or sooner if they ask us directly.
- Unsolicited applications for work where we do not proceed: 6 months from our decision. Longer only if you tell us in writing that we may keep yours on file, and then for a further 12 months.
- Standard technical logs produced by hosting: 90 days.
- Correspondence with a customer or a partner: for the length of the relationship and 24 months after it ends.
Ask us to delete something earlier and we will, unless we are required to keep it. Once there is a company with accounting obligations, invoices and the records attached to them will be kept for the period the law requires, and that period will be named here rather than left to inference.
Job applications
An unsolicited application is read by the two founders and nobody else. It is not shared with other companies, it is not used to train anything, and it is not used for any purpose other than considering you.
There is no automated screening and no scoring model. Two people read each application. If we do not proceed, the retention period above applies and you can ask us to delete it sooner.
Cookies, analytics and browser storage
This site measures how many people read it, which pages they read and roughly where in the world they are. That runs on Azure Application Insights, a Microsoft service already used for the platform itself. It runs no advertising, no profiling and no third-party tracking scripts. Nothing collected here is shared with advertisers, sold, or used to build a profile of you, and none of it is joined to anything you submit through a form.
Page views are counted whether or not you agree to anything, because counting a page needs no identifier and records nothing about the reader. Recognising your browser across pages and visits does need one, and that is what the banner asks about. Agreeing sets two cookies that hold a random identifier and nothing else, so several visits can be counted as one reader rather than several. Declining sets no cookie, keeps the page counts, and is remembered so you are not asked again. Ignoring the banner is the same as declining until you answer it.
Your IP address reaches Microsoft as part of making the request at all. It is used to work out an approximate city and country and is then discarded rather than stored, which is Application Insights' default behaviour and is not changed here. Approximate location, browser and device type are kept; the address itself is not. Measurement data is stored in the European Union and kept for 90 days.
A partly completed form is saved in your own browser's storage so that you can leave and come back without retyping it. That stays on your device and reaches us only when you press submit. Clearing site data for this domain removes it. Card details entered during signup are validated in your browser and discarded, and no card number, expiry, security code or cardholder name is stored anywhere.
Signing in to the Specify platform sets a session cookie, which is strictly necessary to keep you signed in. It does no tracking and is used for nothing else.
Your rights
The GDPR gives you the following rights over what we hold about you. They are not conditional on having bought anything.
- Access: a copy of what we hold, and what it is used for.
- Rectification: correction of anything inaccurate or incomplete.
- Erasure: deletion of what we hold, unless we are required to keep it.
- Restriction: a pause on our use of it while a question about accuracy or basis is resolved.
- Portability: the data you gave us, in a machine-readable form, for you or for another provider.
- Objection: to anything we do on the basis of legitimate interests, including the aggregated learning described above.
- Withdrawal of consent: at any time, for anything we do on the basis of consent.
Write to tpg@specify.digital. We answer within one month. There is no charge and we will not ask you why.
We may ask for enough information to be confident it is your data we are about to hand over or delete. That is the only reason we would ask, and we will not use anything you send for it beyond answering the request.
Complaints
If you think we have handled your data badly, tell us and we will try to put it right. You do not have to come to us first. You can complain to the data protection authority in the country where you live, where you work, or where you think the problem happened, and you can do that whatever we say about it.
Specify is not yet incorporated and therefore has no established lead supervisory authority. This section will name it once there is one.
Changes to this notice
The date at the top of this page is when it last changed. If we change something that affects data already collected, we will say so here, and where the change is significant we will tell the people affected directly rather than relying on them rereading the page.