iProtocol Impact

GOALS FRAMEWORK

Legal

Privacy Policy

Last updated: June 2026 · Version 2.0

This policy explains how iProtocol Impact Ltd collects, uses, stores, and protects your personal data. We are committed to full compliance with UK GDPR, the Data Protection Act 2018, the Children's Code (Age Appropriate Design Code), and all applicable UK data protection legislation. If you do not agree to this policy, please do not use our platform.

1. Who we are

iProtocol Impact Ltd ("iProtocol Impact", "we", "us", "our") is the data controller responsible for your personal data. We are registered in England and Wales and operate from the United Kingdom.

Data Controller contact: privacy@iprotocolimpact.com
ICO registration: Pending registration with the Information Commissioner's Office
Data Protection Officer: privacy@iprotocolimpact.com

For all data protection enquiries, requests to exercise your rights, or complaints, contact us in writing at the above address. We will respond within 30 days of receiving your request.

2. Definitions

In this policy: "Platform" means the iProtocol Impact web application and all associated services. "User" means any individual who creates an account on the Platform. "Participant" means an individual whose development data is tracked through the Platform. "Organisation" means a school, charity, workplace, community group, or other entity using the Platform to manage participants. "Mentor" means an individual who provides development support to participants through the Platform. "Special category data" means data revealing racial or ethnic origin, health data, data concerning a natural person's sex life or sexual orientation, and any data relating to children.

3. Data we collect

3.1 Account and identity data

3.2 Development and goal data

3.3 Financial data

3.4 Communications data

3.5 Technical and usage data

4. Special category and sensitive data

Some features of the Platform may involve the collection of data that falls within special category classifications under UK GDPR, including:

We process special category data only where we have a valid lawful basis, including explicit consent or where processing is necessary for the provision of social protection services. We apply enhanced security measures to all special category data. We conduct Data Protection Impact Assessments (DPIAs) before introducing new features that process special category data.

5. Legal basis for processing

We process your personal data on the following legal bases:

6. How we use your data

We use your data strictly for the following purposes:

We will never use your data for advertising purposes or sell it to third parties. We will never use your development data to make automated decisions that have a significant effect on you without human review.

7. Data sharing and third parties

We do not sell, rent, or trade your personal data. We share data only with the following categories of trusted processors, each bound by data processing agreements (DPAs) that require them to process data only as instructed and in compliance with UK GDPR:

We may disclose your data to law enforcement, regulators, or statutory authorities where required by law, where necessary to protect the safety of a child or vulnerable person, or where necessary to protect our legal rights in legal proceedings. We will notify you of any such disclosure where we are legally permitted to do so.

In the event of a merger, acquisition, or sale of assets, your data may be transferred to a successor entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.

8. International data transfers

Some of our third-party processors are based outside the UK. Where we transfer data internationally, we ensure appropriate safeguards are in place, including UK International Data Transfer Agreements (IDTAs), Standard Contractual Clauses (SCCs), or transfers to countries with UK adequacy decisions. Our primary database is hosted in the EU West region (Ireland), which benefits from a UK adequacy decision.

9. Children and under-18 users

We take our obligations under the Children's Code (Age Appropriate Design Code) and UK GDPR Article 8 seriously. The following additional protections apply to users under 18:

10. Data retention

We retain your personal data for the following periods:

When you request account deletion, all personal data that is not subject to a legal retention requirement is anonymised immediately and permanently deleted within 30 days.

11. Cookies

We use strictly necessary cookies only. These are required for the Platform to function and cannot be disabled. They include:

We do not use tracking cookies, advertising cookies, analytics cookies that identify you personally, or any third-party cookies for marketing purposes. We do not use Google Analytics or any similar behavioural tracking service.

12. Security

We implement industry-standard technical and organisational security measures including:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware and will notify affected individuals without undue delay.

13. Your rights under UK GDPR

You have the following rights. To exercise any of them, contact us at privacy@iprotocolimpact.com. We will respond within 30 days and will not charge a fee for reasonable requests:

If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

14. Limitation of liability

To the fullest extent permitted by applicable law, iProtocol Impact Ltd shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of data, loss of profits, or loss of business, arising out of or in connection with your use of the Platform, even if we have been advised of the possibility of such damages.

Our total aggregate liability to you for any claims arising under or in connection with this policy or the Platform shall not exceed the greater of (a) the total fees paid by you to iProtocol Impact in the 12 months preceding the event giving rise to the claim, or (b) £100.

Nothing in this policy limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded by law.

15. Indemnity

You agree to indemnify, defend, and hold harmless iProtocol Impact Ltd and its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or in connection with: (a) your use of the Platform in violation of our Terms of Service or Acceptable Use Policy; (b) your violation of any applicable law or regulation; (c) any data you submit to the Platform that infringes the rights of any third party; or (d) your provision of inaccurate or misleading information in connection with parental consent for under-18 participants.

16. Governing law and jurisdiction

This policy and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. You agree that the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this policy or the Platform.

17. Acceptable use and prohibited conduct

You must not use the Platform to process personal data in a way that is unlawful, discriminatory, or in breach of any applicable data protection legislation. You must not upload to the Platform any data relating to another individual without that individual's knowledge and consent. You must not use the Platform to process data relating to children without first obtaining verified parental consent. Breach of these obligations may result in immediate suspension of your account and may be reported to the relevant authorities.

18. Changes to this policy

We reserve the right to update this policy at any time. Where changes are material, we will notify you by email at least 30 days before the changes take effect and will display a prominent notice on the Platform. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you must stop using the Platform and may request deletion of your account.

19. Contact

For all privacy-related enquiries, data subject requests, or complaints:

iProtocol Impact Ltd

Email: privacy@iprotocolimpact.com

Response time: Within 30 calendar days

This privacy policy does not constitute legal advice. iProtocol Impact recommends that organisations using the Platform for the processing of special category data or children's data seek independent legal advice to ensure their own compliance obligations are met.

Back to homeTerms of Service