Privacy notice
How Team Spark® collects, uses and protects personal information, and the rights you have over it.
Last updated [NEEDS: publication date].
Who we are
Team Spark is a trading name of UXclinician Ltd (“we”, “us”, “our”), a company registered in England and Wales.
- Registered company: UXclinician Ltd
- Company number: 11739483
- ICO registration: ZA512218
- Registered address: Courtenay House, Pynes Hill, Exeter EX2 5AZ
We are committed to protecting the privacy and security of your personal information. This notice describes how we collect and use personal information about you when you use Team Spark, in accordance with the UK GDPR and the Data Protection Act 2018.
For most of what happens in Team Spark, UXclinician Ltd is the data controller: we decide how and why personal information is used. Where your employer or another organisation has brought you onto Team Spark, that organisation is the controller for the information about its own staff, and we process it on its instructions under our data processing terms. This notice still tells you what we do with it.
This notice applies to people who visit the Team Spark website, contact us, create an account, or are invited to a team. Please read it alongside anything else we tell you when we collect information on a specific occasion.
The short version
- We hold your name, email address and a one-way hash of your password, plus which teams you belong to and which sessions you attended.
- We do not know what you wrote in a workshop. Your answers are stored with no name, no account identifier and no timestamp, so they cannot be traced back to you by anyone, including us. They are only shown, as themes, once enough people have answered for nobody to be identifiable.
- We use an automated language model to turn a team's anonymous, threshold-gated answers into a short insights and suggestions report. No names go to it.
- We do not sell data, run advertising, or track you across other sites.
- You can edit your details, export your insights and suggestions reports and delete your account yourself, at any time.
Data protection principles
We comply with data protection law, which requires that the personal information we hold about you is used lawfully, fairly and transparently; collected only for valid purposes we have explained; relevant and limited to those purposes; accurate and kept up to date; kept only as long as necessary; and kept securely.
What we hold about you
Personal data means any information about an individual from which that person can be identified. It does not include data that has been anonymised so that the individual can no longer be identified.
If you have an account
- Account details: your name, your email address, and your password stored as a one-way (bcrypt) hash. We never see or store the password itself.
- Team and role information: the teams you belong to, whether you are a facilitator, member or organisation admin, the organisation the team sits in, and the invitation sent to you (the email address it went to and whether it was accepted).
- Attendance: which workshop sessions you signed in to, and your progress through any catch-up session. Attendance is stored separately from answers and is never joined to them.
- Reports: a record of which reports have been sent to you by email, so that we do not send them twice. [NEEDS: confirm what the “report emails” table holds once email sending is wired up.]
If you contact us
- Contact-form submissions: your name, email address, organisation if you give it, and what you wrote. [NEEDS: confirm the exact contact-form fields.]
If you order printed copies
- Delivery details: the delivery name and postal address you give, and which account placed the order, used only to post and account for the order; kept after account deletion as an order record but no longer linked to your account.
Everyone
- Technical information handled by our hosting provider in the ordinary course of serving the site, including your IP address in server logs. [NEEDS: hosting provider and region.]
- A sign-in cookie when you are logged in, and one browser-storage entry that remembers your cookie choice. See our cookie policy.
What we deliberately do not hold
Your workshop answers are anonymous. When you answer a reflective exercise in a workshop, the answer is saved without your name, your account identifier or a timestamp. There is no field that links an answer to a person, so the link cannot be recreated later. Answers are held back until a minimum number of team members have responded, and are then shown only as collated themes. A facilitator, a manager, an organisation admin or a member of our team cannot see who wrote what, because that information does not exist.
The trade-off is that we cannot retrieve or delete “your” answers on request, because we cannot identify them. Deleting your account removes everything that is linked to you; anonymous answers stay part of the team's themes.
We do not collect special-category data (such as health information) deliberately. Please do not enter it in free-text fields. If a workshop exercise asks about how you feel about your work, it is because the theme is what the team is working on; the answer is anonymous.
How we collect it
We collect personal information when you create an account, when a facilitator invites you to a team, when you sign in to a session, when you use the contact form or email us, and in the course of providing the Service to you and your team.
The Team Spark website may link to other websites outside our control, which are not covered by this notice.
Why we use it, and the legal basis
We only use your personal information where the law allows. Most commonly:
To provide the Service (performance of a contract, or steps at your request before one). Creating and securing your account; adding you to a team and showing you its sessions; recording attendance so the team knows who has caught up; generating and sending reports; responding to support requests; telling you about changes to the Service or these terms.
Because it is in our legitimate interests, and yours do not override them. Keeping the Service secure and preventing abuse; understanding, in aggregate, how the Service is used so we can improve it; responding to enquiries; keeping our records accurate; managing our business, including planning and forecasting; and, where you have asked or it is reasonable to expect it, telling you about related services from UXclinician Ltd. You can object to any of this at any time.
Because you have consented. Optional analytics cookies, if we introduce them, run only if you say yes. You can withdraw consent at any time from Cookie settings in the footer.
Because the law requires it. Keeping the records that accounting and tax law require once billing exists; responding to lawful requests from authorities.
Some grounds overlap. If we need to use your information for a purpose that is not compatible with the one we collected it for, we will tell you and explain the legal basis.
Automated processing and AI
We use an automated language model to collate a team's answers into a short insights and suggestions report, in a version for the team and a version for the manager. What is sent to the model is the set of anonymous, threshold-gated answers for that module and the team's name [NEEDS: confirm whether the team name or organisation name is included in the prompt]. No member names, email addresses, attendance records or account identifiers are sent.
The model is provided by [NEEDS: AI provider and product, e.g. Anthropic Claude via API], which processes the text on our behalf as a processor. [NEEDS: confirm the provider's data-use terms, in particular that inputs are not used to train models, and the region where they are processed.]
Reports are drafted by the model and are not reviewed by a person before the team sees them. [NEEDS: confirm.] They are not used to make any decision that has a legal or similarly significant effect on you; they are prompts for a team conversation. No profiling of individuals takes place, because the input contains nothing about individuals.
Sharing your information
We share personal information only where necessary to run the Service, where the law requires it, where you ask us to, or where we have another legitimate interest.
- Your team. Your name and attendance are visible to your facilitator and, in summary, to your organisation's admin. Your answers are visible to nobody, only the anonymous themes.
- Hosting. The Service and its database run on [NEEDS: hosting provider], in [NEEDS: region]. [NEEDS: confirm the database is a single SQLite file on that host and where backups are kept.]
- AI provider. See above. [NEEDS: provider.]
- Email. [NEEDS: email-sending provider. Email sending is not yet wired up; add when it is.]
- Payments. There is no payment integration yet. [NEEDS: when billing is added, name the provider and note that card details go directly to it.]
- Professional advisers and authorities. Our auditors and professional advisers; and a court, regulator, law-enforcement agency or other authority where we are required to disclose.
We require third parties to keep your data secure and to process it only on our instructions and for the purposes we specify.
We do not sell personal information and we do not share it with advertisers.
International transfers
We aim to keep your data in the UK. Where a provider we use processes data outside the UK, we make sure it is protected by safeguards that data protection law recognises, such as an adequacy decision or the UK International Data Transfer Agreement. [NEEDS: confirm the regions of the hosting and AI providers.]
Security
We take reasonable technical and organisational measures to protect your data: passwords are stored only as bcrypt hashes; the Service is served over HTTPS; access to production data is limited to the people who need it and is subject to a duty of confidentiality; and workshop answers are anonymous by design, so the most sensitive data we hold cannot be attributed to anyone even if it were disclosed. [NEEDS: confirm backup, encryption-at-rest and access-control arrangements with the hosting provider.]
We have procedures for dealing with a suspected data breach and will notify you and the ICO where the law requires it.
How long we keep it
- Account and team data: for as long as you have an account. When you delete your account, or when your organisation ends its use of Team Spark and asks us to, we delete it [NEEDS: any grace period, e.g. 30 days].
- Attendance and catch-up progress: deleted with your account.
- Anonymous workshop answers and themes: these are not personal data and are kept as part of the team's programme record. They are deleted when the team is deleted [NEEDS: confirm].
- Contact-form submissions: [NEEDS: retention period, e.g. 12 months after the enquiry is closed].
- Server logs: as set by our hosting provider, [NEEDS: period].
- Billing records, once billing exists: as long as accounting and tax law requires, currently up to six years from the end of the financial year concerned.
We may anonymise information so that it can no longer be associated with you, and use it without further notice, for example for statistics or research into how teams develop.
Your rights
Under data protection law you have the right to:
- Access the personal information we hold about you.
- Correct anything that is inaccurate or incomplete. You can edit your name and email yourself in the Service.
- Erase your information where there is no good reason for us to keep it. You can delete your account yourself in the Service.
- Port your information: you can export your team's reports from the Service. For anything else, ask us.
- Object to processing based on our legitimate interests, and at any time to direct marketing.
- Restrict processing while a question about it is resolved.
- Withdraw consent where consent is the basis, for example for analytics cookies.
These rights are not absolute and a request may be refused where an exception applies. Because workshop answers are anonymous, rights of access, correction, erasure and portability cannot apply to them: we cannot identify which answers are yours.
To exercise a right, or if you are a member of staff whose organisation is the controller, contact us at craignewman@uxcgroup.com and we will help, or direct you to the organisation where appropriate. You can find out more about your rights at ico.org.uk.
Contact and complaints
UXclinician Ltd has appointed a Data Protection Officer. Contact them at craignewman@uxcgroup.com with any question about this notice or how we handle your personal information.
You have the right to complain at any time to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint. Our ICO registration number is ZA512218. The ICO asks that you try to resolve the issue with us first, so we would appreciate the chance to put things right before you approach them.
Changes to this notice
We may update this notice. If we make a substantial change we will tell you in the Service or by email. The date at the top shows when it was last changed.
See also our terms of service, cookie policy and data processing terms.
Back to Team Spark home