ORG HEALTH CHECK - Privacy Policy & Cookie Notice

Org Health Check Ltd ("Org Health Check", "we", "us", "our"), company number 17381071, registered office Suite 5, 5th Floor, City Reach, 5 Greenwich View Place, London, United Kingdom, E14 9NN, provides the Org Health Platform to UK businesses. This Policy explains how we collect, use, and protect personal data, and sets out our use of cookies.

We act in different capacities depending on the context, which affects your rights and who to contact. This Policy is split into three parts accordingly:

Section A — where we act as Controller for our own website visitors, prospects, and named account administrators of client businesses.
Section B — where we act as Processor for employee data uploaded by our clients to the Platform.
Section C — cookies.

For any questions, contact us at info@orghealthcheck.co.uk.

Section A — Controller: Website Visitors, Prospects, and Account Administrators

1. What We Collect and Why

1.1 Account and billing data. When a business subscribes to the Platform, we collect the name, work email, and role of the individuals it nominates as account administrators, plus billing contact details and payment metadata (handled by Stripe; we do not store full card numbers).
Lawful basis: performance of a contract (Article 6(1)(b) UK GDPR) — necessary to set up and administer the subscription.

1.2 Enquiry and prospect data. Contact details submitted via forms, email, or calls (name, work email, phone, company) and related correspondence. Where a prospect shares sample workforce data during a scoping discussion, that exchange is generally governed by the Mutual NDA rather than this Policy, save that any personal data within it is still handled in accordance with the principles in this Section.
Lawful basis: legitimate interests (Article 6(1)(f)) — responding to enquiries and pursuing prospective business relationships, balanced against your interests and rights.

1.3 Website analytics and security data. Technical data such as IP address, browser type, device information, and pages visited.
Lawful basis: legitimate interests — for basic analytics and platform/website security. Where non-essential analytics cookies are used, we additionally rely on consent (see Section C).

1.4 Marketing communications. Where you opt in to receive product updates.
Lawful basis: consent (Article 6(1)(a)) — you may withdraw consent and unsubscribe at any time.

2. Retention

Account administrator and billing data: retained for the duration of the subscription, plus 6 years afterwards, to meet UK tax and company record-keeping obligations (Companies Act 2006 and HMRC requirements).

Enquiry and prospect data: retained for up to 24 months from last contact, then deleted or anonymised, unless the prospect becomes a client (in which case 1.1 applies going forward).

Website analytics data: retained per our analytics provider's standard retention window, typically no longer than 26 months.

Section B — Processor: Client Employee Data (Org Health Platform)

3. Our Role

When a client organisation uploads its workforce data to the Platform, Org Health Check acts as a data Processor. The client organisation is the Controller and is responsible for its lawful basis for processing its employees' data and for informing its employees accordingly. The detailed terms of this processing are set out in our Data Processing Agreement with each client.
If you are an employee of one of our clients and have questions about how your data is used, please contact your employer in the first instance, as they control that decision.

4. What Is Processed

Employee identifiers uploaded by the client via CSV: name, job title, department, manager/reporting line, salary band, tenure, and location. We do not collect special category data (e.g. health, ethnicity) as part of the standard Platform workflow, and instruct clients not to upload such data.

5. How AI Is Used

Raw, identifiable employee records are processed only within our secure database layer to calculate aggregated organisational metrics. Only aggregated, de-identified data is sent to Anthropic's Claude API to generate narrative insights and classify job titles. Job title classification may involve individual job titles but not names or other direct identifiers. We hold our own commercial API-tier agreement directly with Anthropic confirming they do not train their models on data submitted via their API (see clause 4.5 of the Data Processing Agreement).

6. Sub-processors

A current, versioned list of sub-processors is maintained in the Data Processing Agreement and at our designated Sub-processor Page, including Airtable, Make, Noloco, Anthropic, Vercel, and Tally.

7. International Transfers

Make (our automation layer) stores data within the EU; transfers from the UK to the EU are covered by the UK's own adequacy regulations, so no additional safeguard is required for that transfer specifically.
Airtable, our primary database provider, is US-hosted. We rely on Airtable's own standard Data Processing Addendum, which incorporates both the EU Standard Contractual Clauses and the UK Standard Contractual Clauses (UK Addendum), together with a Transfer Risk Assessment we maintain for this transfer.
Our other US-based sub-processors (Anthropic, Vercel) are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or, where applicable, the UK Extension to the EU-US Data Privacy Framework ("UK-US Data Bridge") which became fully operational under English law on 12 October 2023. We regularly monitor and verify the certification status of these US-based sub-processors under the Data Privacy Framework to ensure continuous compliance.

8. Retention and Deletion

Client employee data is retained for the duration of the client's active subscription. On cancellation or termination, it is retained for 30 days to allow export or reactivation, then permanently deleted from active systems, subject to standard backup rotation as described in the Data Processing Agreement.

9. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access controls, and per-client data isolation. Further detail is in the Data Processing Agreement.

Section C — Cookies

10.1 Essential cookies. Required for the website and Platform to function (e.g. session management, security). These do not require consent and cannot be disabled without affecting core functionality.

10.2 Analytics cookies. Used to understand website usage. [REVISED FOR UK GDPR & PECR COMPLIANCE] These cookies are strictly disabled by default. They are only deployed and set if the website visitor actively and explicitly consents (opts in) via our cookie banner.

10.3 You can manage or withdraw cookie consent at any time via our cookie banner or your browser settings. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

Section D — Your Rights

Under UK GDPR, individuals have the right to: access their data; rectify inaccuracies; request erasure; restrict or object to processing; and data portability, along with the right to withdraw consent where consent is the lawful basis. If you are an employee of a client organisation, these requests should generally be directed to your employer as Controller, who will coordinate with us as needed. If you are a website visitor, prospect, or account administrator, contact us directly at info@orghealthcheck.co.uk.
[REVISED FOR UK COMPLIANCE] Under UK GDPR, where we act as a Controller, we are legally obligated to respond to a valid rights request without undue delay and at the latest within one (1) calendar month of receipt, free of charge. In complex cases, we may extend this response period by up to two (2) further months, in which case we will notify the individual within the initial month and explain the reasons for the delay.

You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.

Section E — Changes to This Policy & Contact

We may update this Policy from time to time. Material changes will be notified via our website or, for active clients, by email. Continued use of our website or the Platform after changes take effect constitutes acceptance.

Questions about this Policy, or to exercise your data rights, can be sent to info@orghealthcheck.co.uk, or by post to Suite 5, 5th Floor, City Reach, 5 Greenwich View Place, London, United Kingdom, E14 9NN.