Privacy Policy

Privacy Policy

Privacy Policy

Privacy Policy — Intangia

Effective date: 1 January 2025
Last updated: 28 August 2026

Intangiable Ltd ("Intangia", "we", "us", or "our"), registered at 23 Godfrey St, London, SW3 3TA, UK, provides this Privacy Policy to explain how we collect, use, store, and share personal data across:

  • intangia.co — our public marketing website

  • app.intangia.co — our Scientific Opportunity Intelligence platform (the "Platform")

This Privacy Policy applies to processing of personal data under the UK GDPR and, where applicable, the EU General Data Protection Regulation ("EU GDPR").

It should be read alongside our Cookie Policy.

1. Personal Data We Collect

1.1 Marketing website — intangia.co

Because the marketing website does not require an account, most visitors can use it without directly identifying themselves.

We may collect:

  • Analytics data — information about website usage, including pages viewed, device and browser information, approximate location, referral source, and general usage behaviour. Framer's built-in analytics is designed not to use cookies or persistent identifiers and provides aggregated website analytics. We also use PostHog for analytics and product/website usage measurement.

  • Contact form submissions — when you submit our contact form, we collect the information you choose to provide, such as your name, work email address, company, and message. The form is provided by Fillout.

1.2 Platform — app.intangia.co

Because the Platform requires an account, we process:

  • Account and profile data — including your name, work email address, organisation/company, and role, collected during account creation and authentication.

  • Usage data — including searches, saved opportunities, workspaces created, analyses and other in-product activity. We use PostHog to help understand Platform usage and improve the service.

  • Authentication and session data — including OAuth tokens and session identifiers processed server-side to authenticate users and maintain secure sessions. We do not store users' raw passwords or other plaintext credentials.

The Platform is intended for professional use by organisations operating in the life sciences sector.

We do not intentionally collect special category personal data about users through the Platform.

The scientific and biomedical information analysed by the Platform — including information concerning targets, indications, diseases, trials, publications, patents, companies, deals and related research entities — is generally information about scientific or commercial entities rather than information about identifiable individuals. Where such information does contain personal data, we process it in accordance with applicable data protection law.

2. How We Use Personal Data

PurposeData usedLegal basisRespond to enquiriesContact form dataLegitimate interests and, where applicable, steps taken at your request before entering into a contractManage sales and customer relationshipsContact and lead dataLegitimate interestsProvide and secure the PlatformAccount, authentication and session dataPerformance of a contractOperate, maintain and improve the website and PlatformAnalytics, usage and technical dataLegitimate interests and, where required, consentProvide AI-assisted Platform functionality, including project configuration and report generationScientific/biomedical query and entity data and associated Platform inputsPerformance of a contract and legitimate interests, where applicableDiagnose and resolve technical errors and security issuesTechnical error, performance and diagnostic dataLegitimate interestsComply with legal obligations and protect our rightsRelevant personal dataLegal obligation and legitimate interests

We do not sell your personal data.

We do not share your personal data with third parties for those third parties' own direct marketing purposes.

3. Third-Party Service Providers

We use service providers to operate the website and Platform. These providers process information on our behalf or provide infrastructure and services necessary to operate Intangia.

ProviderUseData potentially involvedFramerWebsite hosting and website analyticsWebsite content, technical information and website usage dataFilloutContact form processingName, email address, company and message submitted through the formAttioCRM and lead managementContact and lead informationPostHogWebsite and Platform analytics and session recordingUsage events, device/browser information and, where session recording is enabled, masked interaction dataAWSPlatform cloud hosting and infrastructureAccount data, application data and Platform dataAWS BedrockAI-assisted Platform functionalityScientific/biomedical query content and associated application contextSentryApplication error monitoring, debugging and performance monitoringTechnical error, performance and diagnostic data

We use contractual and other appropriate safeguards with service providers where required by applicable data protection law.

3.1 Framer

Our marketing website is hosted using Framer.

Framer states that its services are hosted on Amazon Web Services facilities in the United States. Framer also states that personal data may be transferred outside the UK and EEA and that applicable transfer mechanisms are used for restricted transfers.

Framer's built-in analytics is designed not to use cookies or persistent identifiers and provides aggregated website analytics. Our separate use of PostHog is described below.

3.2 Fillout

We use Fillout to process submissions to our website contact form.

Fillout's default deployment region stores and processes form submission data in the United States. Fillout offers EU-based hosting as an alternative configuration on eligible plans.

Accordingly, contact-form submissions may be processed in the United States and other locations used by Fillout's infrastructure and subprocessors. Fillout documents the use of AWS/Render infrastructure and additional subprocessors, including US-based service providers.

3.3 Attio

We use Attio as our CRM and lead-management system.

Attio's platform is hosted on Google Cloud. Attio's current data processing documentation does not establish that customer data is restricted to a UK or EU hosting region; it expressly contemplates processing and transfers outside the UK and EEA and uses appropriate transfer mechanisms where required. Attio also states that backups may be maintained in a different geographical region.

Accordingly, we do not represent that contact or lead data stored in Attio remains exclusively within the UK or EEA.

3.4 PostHog and session recording

We use PostHog for website and Platform analytics.

Where session recording is enabled, it may capture information such as page content, clicks, scrolling and navigation behaviour.

Input masking is enabled for relevant form fields and other user inputs so that information entered into those fields is obscured before being captured by session recording. We configure PostHog to minimise the collection of personal data through analytics and session recording.

PostHog analytics data is processed using the PostHog EU Cloud configuration used by Intangia.

3.5 Sentry

We use Sentry for application error monitoring, debugging and performance monitoring across the Platform's backend and frontend.

Sentry is configured to use its EU data region in Germany for Intangia's Sentry organisation.

The information sent to Sentry is intended to consist primarily of technical diagnostic information, such as application errors, stack traces, performance information, browser and device information, and related debugging context.

We configure our applications to minimise the transmission of personal data to Sentry and use available data-scrubbing and privacy controls where appropriate. We do not intentionally send account credentials, passwords or other unnecessary personal information to Sentry.

Sentry provides an EU data region hosted in Germany and supports European data-residency requirements.

3.6 AWS and AWS Bedrock

Our Platform infrastructure is hosted on Amazon Web Services in the eu-west-2 (London) region.

We use AWS Bedrock for certain AI-assisted features, including project configuration and report generation.

We design these features so that personal account information is not intentionally sent to the underlying AI models. Scientific and biomedical information used to generate Platform outputs may be processed by Bedrock as part of providing the requested functionality.

Users should not intentionally enter unnecessary personal or sensitive information into scientific query fields or other free-text Platform inputs.

4. International Data Transfers

Intangia's core Platform infrastructure is hosted in AWS's eu-west-2 (London) region.

However, not all personal data processed by Intangia is necessarily stored or processed in the UK. Our third-party service providers may process data outside the UK or EEA.

In particular:

  • Framer states that its services are hosted in AWS facilities in the United States.

  • Fillout's default deployment region for form submissions is the United States.

  • Attio uses Google Cloud and permits international transfers subject to applicable safeguards.

  • Sentry provides an EU data region hosted in Germany, which is the region used by Intangia for Sentry data.

Where personal data is transferred outside the UK or EEA and applicable law requires a transfer mechanism, we rely on an applicable adequacy decision or appropriate safeguards, such as the UK International Data Transfer Addendum, UK International Data Transfer Agreement, or EU Standard Contractual Clauses.

5. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide our services, maintain business and accounting records, resolve disputes, enforce agreements, comply with legal obligations, and establish or defend legal claims.

Our current retention practices include:

  • Contact form and lead data: retained for up to 2 years after our last substantive contact, after which inactive records are reviewed and deleted where there is no continuing business or legal reason to retain them.

  • General correspondence: ordinarily retained for 12 months, unless a longer period is necessary for a legitimate business, contractual or legal purpose.

  • Platform account data: retained while your account remains active and, after termination, for as long as reasonably necessary for account administration, contractual records, security, dispute resolution, legal claims and compliance with legal obligations.

  • Platform application and project data: retained for as long as necessary to provide the Platform and associated services and, after termination, for as long as reasonably necessary for contractual, operational, legal, security or dispute-resolution purposes.

  • Analytics and usage data: retained according to the retention settings applicable to the relevant analytics service and for no longer than reasonably necessary for the purposes for which the information was collected.

  • Sentry diagnostic data: retained according to the retention settings applicable to our Sentry organisation and for no longer than reasonably necessary for debugging, security and service improvement.

  • Backups: may retain information for a limited additional period where necessary for security, disaster recovery and business continuity. Backup copies are deleted or overwritten in accordance with the applicable backup lifecycle.

Where data is no longer required, we will delete it, anonymise it, or securely dispose of it, subject to applicable legal or regulatory retention requirements.

6. Data Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

Platform authentication is handled server-side using OAuth and session-based authentication. We do not store users' plaintext passwords.

Our Platform infrastructure uses AWS. Data transmitted between users and our services is protected using encrypted connections, and AWS storage and infrastructure controls are used to protect data at rest.

Access to production systems and personal data is restricted to authorised personnel on a need-to-know basis.

Our service providers maintain their own technical and organisational security measures. We select providers that maintain security controls appropriate to the services they provide.

No internet-based service can be guaranteed to be completely secure, but we maintain security controls appropriate to the nature and risks of the processing we undertake.

7. Your Rights

Depending on the circumstances and applicable law, you may have the right to:

  • access the personal data we hold about you;

  • request correction of inaccurate or incomplete personal data;

  • request deletion of your personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • request portability of personal data processed by automated means where the relevant legal requirements are met;

  • withdraw consent where processing is based on consent; and

  • lodge a complaint with a supervisory authority.

If you are in the UK, you can lodge a complaint with the Information Commissioner's Office (ICO).

You can exercise your rights by contacting us at privacy@intangia.co.

We may need to verify your identity before completing a request. We will respond within the period required by applicable data protection law.

8. Children's Data

The website and Platform are intended for business use by professionals and organisations in the life sciences industry and are not directed at children.

We do not knowingly collect personal data from children under 16.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our services, technology, legal requirements or data-processing practices.

When we make material changes, we will update the "Last updated" date at the top of this policy and, where appropriate, provide additional notice.

10. Contact Us

Intangiable Ltd
23 Godfrey St
London
SW3 3TA
United Kingdom

Email: privacy@intangia.co