1. Two different roles
As a controller, we handle a small amount of data about the people who run and use the platform: account details, contact details, billing details and usage logs.
As a processor, we handle the records your organisation enters about children and other individuals — dietary requirements, healthcare plan documents, medication registers and related notes. Your organisation decides what goes in; we act only on its instructions under the Data Processing Agreement.
2. What we collect as a controller
- Identity and contact data: name, work email, job role, organisation.
- Account data: hashed credentials, role assignments, acceptance of legal documents with version and timestamp.
- Technical data: IP address, device and browser type, and security event logs.
- Usage data: which features were used and when, for support and service improvement.
- Correspondence: the content of messages you send us.
We do not use tracking or advertising cookies, we do not sell personal data, and we do not use customer records to train AI models.
3. Special category health data
Allergy, intolerance and dietary records are health data, and therefore special category data under UK GDPR. We only ever process it as a processor, on your organisation's documented instructions. Your organisation is responsible for identifying its lawful basis (Article 6) and condition for processing special category data (Article 9) — commonly explicit consent, or a substantial public interest condition where applicable.
Because much of this data concerns children, we apply additional safeguards: no direct child accounts, least-privilege access, mandatory audit logging, and restricted internal access limited to named staff acting on a documented support request.
4. Why we process controller data
- To provide, secure and support the platform (contract).
- To keep the service safe and prevent abuse (legitimate interests).
- To keep records of legal document acceptance and comply with our own obligations (legal obligation).
- To send service notices. Marketing email is only sent with consent and can be withdrawn at any time.
5. Sharing
We share data only with sub-processors that host or support the platform, with professional advisers where necessary, and where required by law. Every sub-processor is bound by written terms at least as protective as ours. We maintain a current sub-processor list and notify customers before adding one.
6. International transfers
We aim to keep customer records in the UK or European Economic Area. Where any transfer outside those regions is necessary, it is made under an adequacy decision or the UK International Data Transfer Addendum with appropriate supplementary measures.
7. Retention
Customer records are retained for as long as the organisation instructs, and are deleted on termination in line with the Data Processing Agreement. Account and security logs are retained for up to 12 months. Records of legal document acceptance are retained for the life of the account plus six years, because they evidence a contractual agreement.
8. Your rights
You have the right to access, correct, erase, restrict, object to and port your personal data, and to withdraw consent where processing relies on it.
If your data is in a customer organisation's records, please contact that organisation first — it is the controller. If you contact us instead, we will pass the request on and support them in responding.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
9. Security
We use TLS in transit, encryption at rest, row-level access control tied to organisation and role, audit logging of access to personal records, and least privilege for our own staff. No system is perfectly secure; we operate an incident response process and will notify affected controllers without undue delay, and in any event within 24 hours of becoming aware of a personal data breach.
10. Contact
Privacy questions and data protection requests: privacy@saphetech.com.
