Legal
Privacy policy
In effect from 18 August 2026.
1. Who we are
fractionalsmatch is provided by Fractionals Match and runs at fractionalsmatch.com. For questions about this policy or to exercise any right in section 11, write to hello@fractionalsmatch.com.
2. Our role
We are the controller for the personal data described in this policy: your account, your assessment and profile, your capability record and evidence, your briefs and messages, your use of the Service, and the details you leave when you download our research. You put data in; we decide how the Service processes it to do its job; this policy is the account of that.
3. What we collect
- Account data — name, email address and a hashed password; or your Google identity if you sign in with Google.
- Assessment and profile — your answers to the behavioural diagnostic and the operating profile derived from them: scores, archetypes and consistency signals about how you work. This is the heart of the Service and it is data about you.
- Capability record and evidence — for operators: the stages, industries, problems and capabilities you claim, and the evidence you attach to them. Earlier versions of your capability record are kept so your profile’s history is honest.
- Briefs — for founders: the problems, stage and context you describe.
- Introductions and messages — who you asked to meet, who asked to meet you, and what you wrote.
- Report leads— if you download our research (for example, the UK & EMEA Fractional Work Report), the name, email, role and optional company you give us, the campaign parameters on the link you followed, and whether you opened the file.
- Operational data — sign-in sessions, security logs, and metering of the AI features your account uses.
- Analytics — how the interface is used, and only if you consent. See section 12.
There is no billing data: the Service is currently free and we hold no payment details. We do not ask for special category data and the Service is not designed to hold it.
4. Why we process it, and on what basis
- To provide the Service — building your profile, ranking matches, delivering introductions and messages: performance of our contract with you.
- To show your profile to potential matches — the point of the product: performance of our contract.
- To secure it — detecting abuse, keeping logs: legitimate interests in running a service users can rely on.
- To deliver research you ask for — providing the report you requested and understanding which channels our research reaches: taking steps at your request, and our legitimate interest in measuring our own marketing.
- Marketing email — only if you ticked the box, and separately withdrawable at any time.
- To improve the Service through analytics — your consent, withdrawable at any time.
- Service messages you need in order to use the Service — performance of our contract.
5. Matching and automated processing
Matching is algorithmic: the Service scores fit between profiles and ranks the result. Nothing is decided about anyone automatically — a Match is a suggestion, and an introduction only happens when a person chooses to send one and a person chooses to answer. There is no automated decision-making producing legal or similarly significant effects.
Some features send text to our AI sub-processor: generating a narrative reading of a profile, the reflective companion, and checking evidence text for consistency. Your content is not used to train AI models. AI output is interpretation, and it is shown to you as such.
6. Who processes it
We keep the list of third parties deliberately short. Each is bound by data protection terms no less protective than our own, and we remain responsible for them.
- Amazon Web Services — hosting and database. Processes in the United Kingdom (London).
- Anthropic — the AI features in section 5. Processes in the United States.
- Google — sign-in with Google, only if you use it; Google Analytics, only if you consent.
- Resend — delivers the emails the Service sends. Processes in the European Union and the United States.
- Amplitude — product analytics, only if you consent. Processes in the European Union.
- Sentry — error reporting, so we learn when the Service breaks. Reports carry technical details (the page, the stack trace), not your identity or IP address, and it sets no cookies. Processes in the European Union.
We do not sell personal data, and we do not share it for advertising. We may disclose data where the law requires it; where we are lawfully able, we will tell you first.
7. Where it is held
Your data is stored in the United Kingdom, encrypted in transit and at rest. Where a sub-processor in section 6 processes it elsewhere, that transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or under UK adequacy regulations where they apply.
8. How long we keep it
- While your account is open — account, profile, capability history, briefs and messages are kept so the Service works.
- Operational logs — up to 12 months.
- Report leads — for as long as the research programme runs, and removed on request at any time.
- Deletion is immediate — when we delete data it is removed from the live database at once; we do not currently retain automated backups.
9. Closing your account
Write to us and we will close your account and delete your personal details, your profile, your assessment, your capability record and your briefs. Messages you exchanged with another user are part of their record of the conversation as well as yours; we remove your name from them rather than deleting the other person’s copy of what was said. We may retain the minimum needed to establish, exercise or defend legal claims — a legitimate interest you can object to.
10. Security
Encryption in transit and at rest; passwords hashed and never readable by the application; the database unreachable from the public internet; every read and write scoped to the signed-in user’s own session; and administrative access limited to a short, named allowlist that can only change through a reviewed code change.
If a personal data breach affects your data, we will tell you without undue delay and within 72 hours of becoming aware, with what we know and what we are doing — and notify the ICO where the law requires.
11. Your rights
You may ask for access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. Where consent is the basis, you may withdraw it at any time without affecting what was done beforehand.
Write to hello@fractionalsmatch.com. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
12. Complaints
Raise it with us first at hello@fractionalsmatch.com. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk), the UK supervisory authority.
13. Cookies and analytics
The Service sets a session cookie to keep you signed in, and stores your analytics choice on your device. Both are strictly necessary and need no consent.
Analytics (Google Analytics and Amplitude) is optional and off until you accept it. We ask once, declining is one click, and nothing analytics-related loads unless you accept. To change your mind, use “Cookie settings” in the footer of any page. The full list of cookies and storage we set is in the cookie policy.
A report download link contains a token identifying your request. It is a link, not a cookie, and it does nothing but serve you the file and count that it was opened.
14. Children
fractionalsmatch is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
15. Changes
We may update this policy. Material changes are notified by email or in the Service at least 30 days before they take effect. The date at the top of this page always states the version in force. The terms of service sit alongside this policy.

