Data processing terms
How UXclinician Ltd processes personal data on behalf of an organisation that uses Team Spark® with its staff. Team Spark is a trading name of UXclinician Ltd. These terms form part of our terms of service and meet the requirements of Article 28 of the UK GDPR.
Last updated [NEEDS: publication date].
1. Who this is for
1.1 These terms apply where an organisation (the Customer, “you”) sets up teams on Team Spark for its own staff or associates, and in doing so decides why and how their personal data is used. In that relationship you are the controller and UXclinician Ltd (the Processor, “we”) is the processor.
1.2 They do not apply to data for which we are the controller in our own right: the account we hold for each individual user to secure and administer the Service, contact-form enquiries, and anonymous, aggregated information that identifies nobody. Our privacy notice covers that.
1.3 If there is a conflict between these terms and the terms of service, these terms win for anything about personal data.
2. Parties
- Processor: UXclinician Ltd, company number 11739483, registered at Courtenay House, Pynes Hill, Exeter EX2 5AZ, ICO registration ZA512218. Data Protection Officer: craignewman@uxcgroup.com.
- Customer: the organisation named on the Team Spark organisation account, acting through its organisation admin.
3. What is processed
3.1 Subject matter and purpose. Running a programme of team-development workshops for the Customer's teams through the Service: managing accounts and team membership, recording attendance and catch-up progress, collecting anonymous workshop answers, and generating and delivering reports.
3.2 Duration. For as long as the Customer has an organisation account, plus the deletion period in section 9.
3.3 Nature of the processing. Storage, retrieval, display to authorised users, email delivery, automated collation of anonymous answers by a language model, and deletion.
3.4 Data subjects. The Customer's employees, contractors and other people it invites to a team, and its facilitators and organisation admins.
3.5 Categories of personal data.
- Name and work email address.
- Password, held only as a one-way hash.
- Role (facilitator, member, organisation admin) and team memberships.
- Invitations: the email address invited and whether it was accepted.
- Attendance: which sessions a person signed in to, and catch-up progress.
- A record of reports emailed to a person.
- Technical data in server logs, including IP address.
3.6 What is not personal data. Workshop answers are stored with no name, account identifier or timestamp and cannot be linked to a person by any party. They are released only as collated themes once a minimum number of responses exists. Team and manager insights and suggestions reports are generated from those anonymous themes. We treat answers, themes and reports as anonymous information, not personal data, and they are outside the scope of sections 7 and 9 except as stated there.
3.7 Special-category data. None is intended. The Customer must not instruct its staff to enter health or other special-category data in free-text fields, and we do not process any as such.
4. Our obligations as processor
We will:
- Process personal data only on your documented instructions, which are these terms, the terms of service, and the configuration choices your admins and facilitators make in the Service, unless UK law requires otherwise, in which case we will tell you first where the law allows.
- Tell you immediately if we think an instruction breaches data protection law.
- Make sure everyone we authorise to access personal data is bound by confidentiality.
- Take the security measures in section 6.
- Only appoint sub-processors under section 5.
- Help you respond to data-subject rights requests (section 7) and with your security, breach-notification, impact-assessment and consultation obligations, taking into account the nature of the processing and the information available to us.
- Delete or return personal data at the end of the relationship (section 9).
- Make available the information needed to show we are meeting these obligations, and allow and contribute to audits (section 10).
5. Sub-processors
5.1 You authorise us to use the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| [NEEDS: hosting provider] | Hosting the application, its SQLite database and backups | [NEEDS: region] |
| [NEEDS: AI provider] | Collating anonymous, threshold-gated workshop answers into reports. Receives no personal data. | [NEEDS: region] |
| [NEEDS: email provider, not yet wired up] | Sending invitations, session reminders and reports | [NEEDS: region] |
| [NEEDS: payment provider, none yet] | Taking payments for one-off purchases and six-instalment plans; receives billing contact details, not staff data | [NEEDS] |
5.2 We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data-protection grounds and we cannot resolve it, you may end your organisation account. [NEEDS: refund policy]
5.3 Each sub-processor is bound by written terms that impose data-protection obligations equivalent to these, and we remain responsible to you for their performance.
6. Security
We implement appropriate technical and organisational measures, including:
- Answers anonymous by design: no field links a workshop answer to an account, so the most sensitive content cannot be attributed to anyone.
- Threshold gating: themes are not shown until enough responses exist for nobody to be identifiable.
- Attendance stored separately from answers and never joined to them.
- Passwords stored as bcrypt hashes; transport over HTTPS; HTTP-only session cookies.
- Role-based access in the Service: facilitators see only their teams; organisation admins see team lists, not member answers; members see only their own team's themes.
- Access to production systems limited to named individuals, under confidentiality.
- [NEEDS: backup schedule and retention; encryption at rest; logging and monitoring; vulnerability management; whether any certification (Cyber Essentials, ISO 27001) is held.]
7. Data-subject rights
7.1 Individuals can edit their own name and email, export their team's reports and delete their own account from within the Service. Deletion removes memberships, attendance, catch-up progress and the record of reports emailed to them.
7.2 If a data subject contacts us directly about data for which you are the controller, we will tell you within 5 working days and will not respond substantively unless you instruct us to or the law requires it.
7.3 Because workshop answers are anonymous, requests for access, correction, erasure or portability cannot be applied to them. We will explain this to you or the individual on request.
8. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, giving you what we know about its nature, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed. We will keep you updated as we learn more and cooperate with your own notifications to the ICO and to individuals.
9. Deletion and return at the end
9.1 When your organisation account ends, or earlier if you instruct us, we will delete the personal data we process for you within [NEEDS: period, e.g. 30 days], unless UK law requires us to keep it. Before that, your admins and facilitators can export team insights and suggestions reports from the Service.
9.2 Anonymous themes and reports are not personal data. We may keep them in anonymous, aggregated form to improve the programme and for research; on request we will delete a team's themes and reports along with the team [NEEDS: confirm this is operationally supported].
9.3 Backups containing deleted data are overwritten in the ordinary course of the backup cycle, within [NEEDS: backup retention period].
10. Audit
Once in any twelve-month period, or after a breach, you may ask us for the information reasonably necessary to demonstrate our compliance with these terms. If that is not enough, you may arrange an audit on at least 30 days' notice, during working hours, without disrupting the Service, by you or an independent auditor bound by confidentiality, at your cost. We will cooperate reasonably.
11. International transfers
We aim to keep personal data in the UK. We will not transfer it outside the UK, or permit a sub-processor to, without ensuring an adequacy decision, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard is in place. Current locations are listed in section 5. [NEEDS: confirm regions.]
12. Your obligations as controller
You confirm that you have a lawful basis for the processing you instruct, that you have told your staff what Team Spark is and how their data is used (you may point them to our privacy notice), that participation in workshops is voluntary for them, and that you will not use the Service to try to identify who wrote an anonymous answer or to take action against individuals on that basis.
13. Liability
Each party's liability under these terms is subject to the limits in the terms of service, except that nothing limits liability that cannot lawfully be limited, including under Article 82 of the UK GDPR.
14. General
These terms are governed by the law of England and Wales. We may update them to reflect changes in law, in the Service, or in our sub-processors, on at least 30 days' notice; if a change materially reduces your protection, you may end your organisation account under section 5.2.
Questions about these terms: support@uxcgroup.com.
Back to Team Spark home