Privacy
Atlas Privacy Policy
Atlas is the app that shows you exactly what your marketing is doing, the moment you want to know. No waiting for a report. No booking a call. Open the app and see where you stand.
Atlas Privacy Policy
Last updated: 1 September 2026
1. Who we are
Quick by Design Ltd ("QBD", "we", "us", "our") is a marketing and digital agency registered in England and Wales (company number 5914521, VAT registration 991 9014 94), with its registered office at DeMontfort House, 7E Enterprise Way, Vale Park, Evesham, Worcestershire, WR11 1GS.
This policy explains how we collect, use, and protect personal data when you use Atlas, our client portal app for iOS and iPadOS. Atlas is also referred to as the "QBD App", including within the App Store listing and in some QBD materials; both names refer to the same app, and this policy applies equally whichever name you know it by. It applies to clients, Growth Specialists, and other QBD staff who sign in to Atlas, and to prospective clients who use Atlas's public content and enquiry features before becoming a client.
QBD is the controller of the personal data described in this policy, meaning we decide why and how it is collected and used through Atlas. Where Atlas displays data about your own contacts (for example, a client's own customer contacts synced from Brevo, or website visitor analytics from Google Analytics), QBD processes that data as a processor on the client's instructions; that relationship is governed separately by our Data Processing Agreement with each client company, not by this policy. Section 3.8 below explains what this means if your own data has reached us this way.
2. Scope of this policy
This policy covers Atlas only. It does not cover:
- the quickbydesign.co.uk website, which has its own privacy policy;
- the QBD Data Processing Agreement, which sets out QBD's obligations to client companies as a data processor; and
- third-party services accessed through Atlas (for example, if you follow a link out to a client's own website), which are governed by that third party's own privacy policy.
This policy is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and to meet Apple's App Store requirements for apps that collect personal data. QBD's clients and users are based in the United Kingdom; where any processing involves data being handled outside the UK, this is described in section 7 below.
3. The personal data we collect
What we collect depends on how you use Atlas, whether you're signed in as a client, a Growth Specialist, an admin, or browsing as a guest. The sections below group the data by feature.
3.1 Account and sign-in data
To sign you in, Atlas uses a passwordless one-time passcode (OTP) sent to your email address. We collect and process:
- your email address (used as your sign-in identifier and to send the OTP code);
- the 6-digit OTP code itself, held briefly while it's valid;
- your profile details as held in our systems: name, company, job role, Atlas permission level, company role (Owner, Finance or Sales), and which QBD services your company subscribes to;
- a session token, a random security credential (not a password) generated when you sign in, used to prove who you are on later requests without you having to enter your details again.
Your profile is stored securely on your device (in the iOS Keychain, which is encrypted by iOS itself) and is only otherwise held on QBD's systems (WordPress and ClickUp) where it already exists as part of our client records.
3.2 Location data
If you use the "Near Me" sort on the Events tab, Atlas requests one-off access to your device's location to work out which QBD events are nearest to you. This is a single location check each time you use the feature: Atlas does not track your location in the background, does not store a history of your location, and does not use it for any other purpose. You can decline this permission and still use the Events tab; you'll just need to sort events by date instead.
3.3 Financial data
If your company has QBD's billing feature enabled, Atlas displays your Xero invoices, payment history, and line items so you can review what you owe or have paid. This data is fetched from Xero via our Make automation platform each time you view it and is cached on your device only in encrypted form; it is deleted from your device automatically when you sign out. Only users with the Owner or Finance company role can see this section.
3.4 Your business's marketing and performance data
Much of Atlas shows you data about your own company's marketing performance, rather than data about you personally. Depending on which QBD services your company subscribes to, this can include:
- website analytics from Google Analytics 4 (accessed via Windsor.ai), covering sessions, engagement, and traffic sources;
- Google Search Console data, covering search clicks, impressions, rankings, and top queries/pages for your website;
- email marketing data from Brevo, covering your contacts, campaign performance, and Pulse Score engagement scoring;
- social media data from Buffer, covering your scheduled and published posts;
- monthly narrative Insights reports written by your Growth Specialist.
Where this data includes personal data about other individuals, for example the names, email addresses, or engagement scores of your own contacts held in Brevo, QBD processes that data as your processor, on your instructions, under our Data Processing Agreement with your company. It is not "your" personal data for the purposes of this policy, but we mention it here because it passes through Atlas. Section 3.8 below explains this arrangement in more detail.
Brevo access note: Atlas never holds or transmits a Brevo API key. All Brevo traffic is routed through a QBD-controlled proxy server, which resolves the correct key for your company on QBD's servers and enforces which operations are allowed. See section 5 for the full list of services this data passes through.
3.5 Support, feedback and content data
If you raise a support ticket, submit feedback or approval on a web/video project, request a website go-live, or send us a content brief or idea through Atlas, we collect the content of what you submit, together with your account details, so we can act on it. Support tickets and their comments are stored in ClickUp.
If you use the business card scanner, Atlas uses your device's camera to capture an image of a card so the details can be transcribed; the photo itself is processed for this purpose and is not retained by QBD after the contact details have been extracted and confirmed by you.
3.6 Device, technical and diagnostic data
- a push notification token, if you allow notifications, so we can deliver alerts to your device (for example, a new Insights report or approval request);
- standard technical data collected automatically by Apple as part of operating the App Store and app crash diagnostics (governed by Apple's own privacy policy, not this one);
- basic usage information needed to make API calls to our backend function correctly (for example, which endpoint was called and when).
3.7 Data that stays on your device or in your own iCloud account
Some features are deliberately designed to never reach QBD's servers at all:
- QBD Ping: your private notes and logged interactions with contacts, and any Pulse Score contact notes, are stored using Apple's SwiftData framework and, if you have iCloud enabled, sync privately across your own devices via your personal iCloud account. QBD cannot see this data;
- bookmarks, event bookings, contact tags, favourites, hidden contacts, and achievement unlocks are stored locally on your device using iOS's standard app storage;
- Face ID / Touch ID app-lock: if you enable Atlas's biometric lock, the check itself is performed entirely by iOS using your device's Secure Enclave. QBD never receives, sees, or stores any biometric data; we only receive a yes/no result from iOS confirming the device owner unlocked Atlas.
3.8 If your data has reached us through one of our clients
You might never have signed in to Atlas yourself, but still have personal data that reaches QBD through it, for example because you're a customer, subscriber, or website visitor of a QBD client, and your details sit in that client's Brevo account, appear in their Google Analytics or Search Console data, or are part of a Buffer post they've scheduled.
In that situation, QBD is not the controller of your data. Your data is being processed by us strictly as a data processor, acting only on the documented instructions of that client, under a Data Processing Agreement (DPA) we sign with every client whose services involve personal data. The client remains fully responsible, as controller, for deciding why and how your data is used, and for meeting its own obligations to you under UK GDPR.
A few protections the DPA gives you, even though you're not a party to it:
- we only process your data on our client's documented instructions, never for our own separate purposes;
- we don't bring in a new sub-processor to handle your data without the client's authorisation;
- if we become aware of a personal data breach affecting your data, we must notify the client without undue delay so they can meet their own reporting duties to you and, where required, the ICO;
- when our services to that client end, we must delete or return all of that client's data, including yours, within 10 business days;
- we support the client in responding to any request you make to exercise your data protection rights, but we don't respond to you directly unless the client instructs us to or we're legally required to.
If you want to exercise your rights over data held about you in this way, such as asking what's held or asking for it to be deleted, the right first step is to contact the relevant QBD client directly, since they hold the primary relationship with you and the legal responsibility as controller. If you're not sure which of our clients holds your data, or can't get a response from them, you can still contact us using the details in section 11 and we'll help direct your request appropriately.
4. How we use your data, and our legal basis for doing so
Under UK GDPR, we must have a lawful basis for each way we use personal data. The table below sets out our main purposes.
| Purpose | What this covers | Lawful basis |
|---|---|---|
| Signing you in and keeping your account secure | OTP delivery, session tokens, biometric app-lock, forced logout on a revoked session | Contract (providing the service you've signed up for) and our legitimate interest in keeping accounts secure |
| Providing the core Atlas features you request | Dashboards, Insights, Pulse Score, Content Mode, Projects, Support, Billing | Contract |
| Responding to support requests, feedback and content briefs | Support tickets, project approvals, content briefs | Contract, and legitimate interest in resolving issues promptly |
| Location-based event sorting | One-off use of device location for "Near Me" | Consent (iOS location permission, which you can withdraw at any time) |
| Sending push notifications | Alerts about reports, approvals or account activity | Consent (iOS notification permission) |
| Improving and securing Atlas | Diagnosing faults, preventing abuse, session validation | Legitimate interest |
| Meeting our legal and accounting obligations | Financial records shown via Xero, retaining records as required by law | Legal obligation |
4.1 Automated processing and profiling
Pulse Score is a numeric engagement score calculated automatically from how your contacts interact with emails and your website (opens, clicks, visits). It is used to help you and your Growth Specialist identify engaged contacts; it does not have any legal or similarly significant effect on any individual, and no automated decision is made about a person without a human being involved. If you have questions about how a particular score was calculated, contact us using the details in section 11.
5. Who we share your data with
We don't sell your personal data. We share it only with the service providers who help us run Atlas, each acting under a contract that requires them to protect your data and use it only for the purpose we've instructed. As of the date of this policy, these are:
| Provider | What it's used for |
|---|---|
| WordPress (self-hosted) | Public content (blog, podcast, events, resources) and client profile records |
| Make (Integromat) | Automation platform connecting Atlas to our other systems: authentication, contact and project data, support tickets |
| Brevo | Email marketing and contact/Pulse Score data, accessed only via our proxy server |
| Windsor.ai | Aggregating Google Analytics 4 data for display in Atlas |
| Google (Analytics 4 and Search Console) | Source of website analytics and search performance data shown in Atlas |
| ClickUp | Client profile metadata, project tracking, and support ticket storage |
| Buffer | Scheduled and published social media posts, accessed via a Make proxy |
| Xero | Invoices and payment records for clients with billing enabled |
| Cloudflare | Hosts the Worker proxy that mediates access to Brevo without exposing an API key to Atlas |
| Apple | App Store distribution, push notifications (APNs), iCloud/CloudKit sync of your own on-device data, and Sign in with Apple where used |
We may also share personal data where we're required to by law, to protect QBD's rights, or as part of a business transfer (for example, a merger or acquisition), in which case we'll make sure your data continues to be protected.
6. How long we keep your data
| Data | Retention |
|---|---|
| OTP codes | Deleted after use or after the 10-minute validity window expires |
| Session tokens | Expire automatically after 30 days, or immediately on sign-out or revocation |
| Cached analytics, Xero, and Buffer data on your device | Held only for the cache period stated for that feature (typically 30 minutes to 24 hours), and wiped entirely from your device when you sign out |
| Financial (Xero) data | Cached on-device only while signed in; the record of truth remains in Xero, retained per QBD's accounting obligations |
| Support tickets and project records | Retained for the duration of our relationship with your company and for a reasonable period afterwards for record-keeping |
| Account and profile data | Retained for as long as you have an active account, and for a limited period afterwards in case you return, unless you ask us to delete it sooner |
| On-device / iCloud data (Ping notes, bookmarks, tags, achievements) | Stays under your control: deleted if you delete the data in-app, uninstall Atlas, or turn off iCloud sync for it |
When we no longer need personal data for the purposes described in this policy, we delete it or anonymise it.
7. International data transfers
QBD and its client companies are based in the United Kingdom, and wherever possible your data is processed in the UK. Some of the service providers listed in section 5 may store or process data outside the UK (for example, on servers in the EEA or the United States) as part of their own global infrastructure. Where this happens, we make sure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the provider's own UK/EU adequacy arrangements, before any transfer takes place.
8. How we protect your data
We use a combination of technical and organisational measures appropriate to the sensitivity of each type of data:
- Personal and financial data cached on your device (contacts, analytics, Xero invoices, company members, admin data) is stored using iOS's encrypted, backup-excluded file protection, never in plain, unencrypted storage.
- Your account profile is stored in the iOS Keychain, which is encrypted by the operating system.
- Every request to our backend is authenticated using a session token that is validated server-side against your stored identity, role, and permissions, never trusted from the request alone.
- All traffic between Atlas and our servers is encrypted in transit (HTTPS/TLS).
- Access to Brevo data is mediated by a proxy that only allows specific, pre-approved operations and never exposes an API key to Atlas.
- All cached personal data is wiped from your device automatically when you sign out.
- Optional biometric app-lock adds a device-level barrier to opening Atlas, on top of your account sign-in.
No method of storage or transmission is completely secure, but we keep these measures under review as Atlas evolves.
9. Your rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete your data, in certain circumstances, including deleting your account and its associated data entirely;
- restrict or object to certain processing, including processing based on legitimate interest;
- receive a copy of your data in a portable format, where technically feasible;
- withdraw consent at any time for anything we do on the basis of consent (for example, location access or push notifications), without affecting the lawfulness of processing before you withdrew it;
- not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you, and to request human review of any such decision.
To exercise any of these rights, contact us using the details in section 11, or delete your account directly within Atlas at Settings > Account > Delete Account. We'll respond within one month; if your request is broad or unclear, we may pause that one-month clock while we ask you to clarify what you need, and restart it once you reply.
9.1 How to complain
If you're unhappy with how we've handled your personal data, tell us first, using the details in section 11, so we have a chance to put it right. We'll acknowledge your complaint within 30 days and investigate it properly.
If you're not satisfied with our response, you have the right to complain to the UK's independent data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113. The ICO is being restructured into a new body, the Information Commission, under the Data (Use and Access) Act 2025; until that transition completes, the ICO remains the correct point of contact.
10. Children's privacy
Atlas is business software intended for use by adults working with or for QBD's client companies. It is not directed at, and we do not knowingly collect personal data from, children under 13. If you believe a child has provided us with personal data, please contact us and we'll delete it.
11. How to contact us
If you have any questions about this policy or how we handle your data, or want to exercise any of the rights listed in section 9, contact us at:
- Email: enquiries@quickbydesign.co.uk
- Phone: 0845 413 9800
- Post: Quick by Design Ltd, DeMontfort House, 7E Enterprise Way, Vale Park, Evesham, Worcestershire, WR11 1GS
12. Changes to this policy
We may update this policy from time to time, for example when we add a new feature to Atlas. If we make a material change, we'll update the "Last updated" date at the top of this policy and, where appropriate, notify you in Atlas. We encourage you to review this policy periodically.
This is the current version of the Atlas Privacy Policy, published at qbd.co.uk/atlas/atlas-privacy-policy, and linked from within Atlas and from the App Store listing.