Skip to content
Raise Lens
LEGAL

Privacy

Effective 2026-10-05. Questions: [email protected].

Who we are

Raise Lens is operated by Greystones Advisory Ltd, a company registered in England and Wales (company number 15880604). Its registered office is Greystones, Waterhouses, Stoke-on-Trent, England, ST10 3HZ.

The data controller for personal data collected through Raise Lens is Andrew Holden. For any privacy question, or to exercise a right set out below, email [email protected].

Summary

Raise Lens collects the minimum personal data needed to run an account-based discovery tool. We don't sell data, don't run advertising trackers, and don't profile you beyond what your eligibility profile tells our matcher. The full details follow.

What we collect

  • Account: email address and password hash. You can optionally fill in eligibility-profile fields, sectors, country, stage, organisation type, to enable match scoring and saved-search alerts.
  • Billing: handled by Stripe. We store the Stripe customer ID and subscription state; card details never reach our servers.
  • Product analytics: server-side request logs (path, referrer, status code, user agent) retained 30 days for debugging and abuse triage.
  • Google Analytics: only if you allow optional cookies, page views, referrer and device details are sent to Google Analytics 4 so we can see which pages help. Advertising signals are off. See the cookie notice.
  • Microsoft Clarity: only if you allow optional cookies, clicks, scrolls, page views and device details are sent to Microsoft Clarity so we can see where pages confuse people. Form inputs are masked and account, dashboard and sign-in pages are never recorded. See the cookie notice.
  • Feedback: when you click Report bad data, or the thumbs-up / thumbs-down control on an auto-generated summary, we store the row ID, your reason, and a hashed IP for spam triage.
  • Website analysis: if you paste a website into the box on the homepage, we read that site's public pages, send their text to our text-analysis processor (Anthropic) to produce a short summary and a suggested profile, and keep the result for 30 days; if you then create an account, the summary, the website address and the profile are stored with your account to pre-fill your eligibility profile. We count analyses per day against a hashed IP and a cookie, never the IP itself.
  • Saved items + watchlists: the opportunity IDs you save and the filter sets you bookmark. Used only to render those lists back to you.
  • Newsletter: if you subscribe to the weekly briefing, your email address, the sectors/stage/country you optionally tell us (to tailor picks), and the IP address used at sign-up (kept up to 90 days as an anti-abuse signal).
  • Usage events: first-party product analytics, covering which pages and opportunities are viewed, saved or dismissed, tied to an anonymous session (and to your account only while you're signed in). De-identified after 90 days. No cross-site tracking.

What we don't do

  • No sale of personal data to third parties.
  • No advertising trackers, behavioural retargeting, or fingerprinting scripts.
  • No profiling beyond what your eligibility profile tells our matcher.
  • No selling, renting, or transferring your contact list.

Contact data in our funder & opportunity directory

To run a funding-discovery tool we index publicly available funder, grant and tender pages. That content can include personal data about professional contacts: the name, role, work email, phone number or LinkedIn profile of a programme officer or grants contact, and the names of past grant recipients. We collect this from public sources, not from those individuals directly.

Our basis is legitimate interest in providing a research and discovery service over business-context professional data (we don't process special-category data this way, and we don't use it for marketing). If you are an individual whose details appear and you want them corrected or removed, email [email protected] and we'll action it within 30 days.

Lawful basis (UK / EU)

  • Contract: running your account, processing your subscription, delivering the product you signed up for.
  • Legitimate interest: server logs and the honeypot/feedback anti-abuse signals (security, abuse triage, debugging); first-party usage analytics to improve relevance; the funder & opportunity directory described above; transactional email about your account.
  • Consent: the weekly newsletter, where you opt in explicitly (double opt-in) and can one-click unsubscribe from every email; and optional cookies (sign-up attribution, Google Analytics and Microsoft Clarity), which load only after you click “Allow”.

Processors

We use a small set of third-party processors to operate the service. Each is bound by a data-processing agreement and processes data only on our instructions:

  • Supabase: application database hosted in the EU (eu-west-1).
  • Railway: application hosting.
  • Cloudflare: DNS, CDN, and bot protection in front of the site.
  • Stripe: subscription billing and payment processing.
  • Resend: transactional email (signup, password reset, digest).
  • Anthropic: auto-generated summaries of publicly available funder content. Your eligibility-profile fields are never sent to Anthropic.
  • ScrapingAnt: renders public funder, grant and tender pages so we can index them. It sees the public page URLs and content, not your account data.
  • Google: Google Analytics 4 website analytics, only for visitors who allow optional cookies; no account or eligibility data is sent.
  • Microsoft: Microsoft Clarity session analytics, only for visitors who allow optional cookies; no account or eligibility data is sent.
  • Voyage AI (with OpenAI as a fallback): text embeddings that power search over public funding-intelligence content; no account or eligibility data is sent.

We also use Slack to receive internal operational alerts (e.g. “N new opportunities today”); these contain operational counts, not your personal data.

An up-to-date list is available on request at [email protected].

International transfers

Our application database is in the EU. Some processors (Stripe, Anthropic, Resend, Cloudflare, and our embeddings/scraping providers) operate from the US under Standard Contractual Clauses (or the UK / EU adequacy decisions where applicable).

Retention

  • Account data: kept while your account is active; deleted (subject to the tax-record exception below) within 30 days of you closing your account. We retain billing records for the period required by tax law (typically 6 years in the UK) after account closure — these are held by our payment processor.
  • Server logs: 30 days (managed by our hosting provider).
  • Usage events: de-identified after 90 days (the anonymous event is kept for relevance tuning; the link to your account is removed).
  • Newsletter sign-up IP: deleted after 90 days. The subscription itself lasts until you unsubscribe.
  • Feedback signals: retained in aggregate (so we can measure data quality over time); the linked IP hash and user-agent are deleted after 90 days.
  • Security (honeypot) logs: 180 days.

These periods are enforced by an automated daily job, not just policy.

Your rights

Under UK GDPR / EU GDPR you can:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data (subject to legal retention requirements above).
  • Export your account + saved-items data in a portable format.
  • Object to processing or withdraw consent for the newsletter at any time.
  • Lodge a complaint with the UK ICO (or your local supervisory authority).

You can download all your data and delete your account yourself from your account settings with no email needed. For anything else, email [email protected] and we'll action requests within 30 days.

US privacy (California / CCPA & CPRA)

If you are a California resident, you have the right to know what personal information we collect (see “What we collect” and the directory section above), to access and delete it, and not to be discriminated against for exercising those rights.

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of.
  • Exercise your access/delete rights via your account settings or by emailing [email protected].

Changes to this notice

Material changes will be announced in-product and via email to registered users at least 14 days before they take effect. The “Effective” date at the top of this page reflects the current version.