Legal & ethics
Data processing
What we process, why, on what basis, and for how long. Identifying data is structurally separated from operational research records at the database level.
Categories processed
| Category | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Account and contact data | Authentication, role assignment, correspondence | Consent, and legitimate interest in operating the platform | Until account deletion, plus audit references |
| Application data | Screening mediums, sitters, researchers and reviewers | Consent | Two years from decision, then coded summary only |
| Target identity data | Verification of session material by authorized roles only | Explicit consent of the family representative | Until withdrawal or study closure, then deletion |
| Session recordings and transcripts | Blinded judging, transcript integrity, analysis | Explicit consent, per protocol version | Recordings deleted after transcription and verification unless consent extends |
| Judging and score data | Outcome measurement and reliability estimation | Consent; coded identifiers only | Retained with the study record |
| Audit and exposure logs | Accountability for access to sensitive records | Legal obligation and research-integrity requirement | Append-only, retained for the life of the programme |
Separation and minimisation
Identity lives in restricted tables that operational records never join by default. Every study record refers to participants and targets by opaque codes. Roles receive the minimum fields their protocol requires, and mediums and judges receive no identity fields at all.
Processors and transfers
The platform runs on managed cloud infrastructure for hosting, database, authentication and private file storage. Processors act only on instruction and have no research role. Sub-processors are listed on request; where processing occurs outside your jurisdiction, it is covered by standard contractual protections.
Security
Access is enforced at the database level by row-level policies rather than in the interface alone. Recordings, transcripts and consent documents are stored privately with per-role rules. Every sensitive read or write is logged append-only with user, role, action, resource and request metadata.
Your requests
Access, export, correction-by-amendment, restriction and erasure requests are handled under participant rights and the withdrawal policy. To make a request, contact the project.