Legal & ethics

Data processing

What we process, why, on what basis, and for how long. Identifying data is structurally separated from operational research records at the database level.

Categories processed

Categories of personal data processed, with purpose, lawful basis and retention.
CategoryPurposeLawful basisRetention
Account and contact dataAuthentication, role assignment, correspondenceConsent, and legitimate interest in operating the platformUntil account deletion, plus audit references
Application dataScreening mediums, sitters, researchers and reviewersConsentTwo years from decision, then coded summary only
Target identity dataVerification of session material by authorized roles onlyExplicit consent of the family representativeUntil withdrawal or study closure, then deletion
Session recordings and transcriptsBlinded judging, transcript integrity, analysisExplicit consent, per protocol versionRecordings deleted after transcription and verification unless consent extends
Judging and score dataOutcome measurement and reliability estimationConsent; coded identifiers onlyRetained with the study record
Audit and exposure logsAccountability for access to sensitive recordsLegal obligation and research-integrity requirementAppend-only, retained for the life of the programme

Separation and minimisation

Identity lives in restricted tables that operational records never join by default. Every study record refers to participants and targets by opaque codes. Roles receive the minimum fields their protocol requires, and mediums and judges receive no identity fields at all.

Processors and transfers

The platform runs on managed cloud infrastructure for hosting, database, authentication and private file storage. Processors act only on instruction and have no research role. Sub-processors are listed on request; where processing occurs outside your jurisdiction, it is covered by standard contractual protections.

Security

Access is enforced at the database level by row-level policies rather than in the interface alone. Recordings, transcripts and consent documents are stored privately with per-role rules. Every sensitive read or write is logged append-only with user, role, action, resource and request metadata.

Your requests

Access, export, correction-by-amendment, restriction and erasure requests are handled under participant rights and the withdrawal policy. To make a request, contact the project.