Privacy Policy

Effective

This Privacy Policy explains how Indacas Ltd ("Indacas", "we", "us") handles personal data on the Indacas platform (the "Platform") — a service for creating and running research studies, surveys, and participant records.

If anything in this policy is unclear, contact us at [email protected].

1. Who we are

Indacas Ltd is a company registered in England and Wales (company number 17340475) with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

  • Data protection contact: [email protected]
  • Supervisory authority: the UK Information Commissioner's Office (ICO)

2. The two roles we play — controller and processor

Depending on the data, Indacas acts in one of two roles under UK GDPR:

Data Our role Who is the controller Examples
Account Data — data about your Indacas account, whether you are a Researcher or a Participant Controller Indacas Name, email, password hash, profile, organisation membership, notification preferences
Platform telemetry — data about how the Platform itself is used and kept secure Controller Indacas Server logs, security logs, session records
Research Data — the content of studies run on the Platform Processor The Researcher or their institution Study definitions, survey questions and responses, participant records, in-product consent records, study audit logs

In plain terms: if the data is about your relationship with Indacas (your account, your login, your subscription), we decide how and why it is processed and this policy governs it in full. If the data is research content — the answers you give in a study, the records a Researcher keeps about study participants — the Researcher (or their university, hospital, or company) is the controller, and we process that data only on their instructions under our Data Processing Agreement. Their own privacy notice (see our Participant Privacy Notice Template) tells you how they use it.

Defined terms used throughout our legal documents

  • "Researcher" — a person or organisation using the Platform to create and run studies.
  • "Participant" — a person who joins a study and submits data, with or without an Indacas account.
  • "Account Data" — personal data Indacas holds as controller about a Platform account.
  • "Research Data" — study content and participant data Indacas processes on a Researcher's behalf.

3. What we collect as controller (Account Data and telemetry)

3.1 When you create an account

  • Identity and contact: name, email address (verification required).
  • Credentials: a hash of your password (we never store the password itself), and — if you enable it — the secret for time-based two-factor authentication (TOTP). Authentication is handled by our self-hosted Ory Kratos identity service. Identity data is stored only on our infrastructure; like all traffic to the Platform, sign-in requests pass through Cloudflare's UK data centres in transit (see Section 6).
  • Profile: role (e.g. researcher, participant), institution, ORCID iD, and any public profile bio and links you choose to add.
  • Organisation membership: which organisations and studies your account belongs to, and your role in them.
  • Preferences: notification settings, interface preferences.

3.2 When you use the Platform

  • Session data: session cookies and tokens that keep you signed in (see the Cookie Policy).
  • Telemetry and logs: IP address, timestamps, requested pages, and errors, collected in server logs for security and reliability. Logging runs on our own self-hosted infrastructure (Grafana/Loki); it is not sent to a third-party analytics provider.
  • Billing data: subscription plan and billing status. Payment records are handled by our payment provider, Stripe, which is listed in our Subprocessor List. Card details are held by Stripe and never reach us.

3.3 Anonymous respondents

You can answer some surveys through a tokenised link without an account. In that case we set a token cookie on your browser so your in-progress response is not lost, and we store your answers as Research Data on the relevant Researcher's behalf. We do not require your name or email. If you later create an account, you can choose to "claim" such responses and attach them to your account — that link is only made when you ask for it.

3.4 When you contact us

If you send us a message through the contact form or by email, we keep your name, email address, any organisation and role you give, your answers to the enquiry questions, and the message itself, so that we can respond and follow up.

3.5 What we do not collect

We do not use advertising or third-party analytics trackers, we do not buy data about you, and we do not sell personal data.

4. Why we process Account Data, and our lawful bases

Purpose Lawful basis (UK GDPR Art 6)
Creating and operating your account; signing you in; delivering the Platform Contract (Art 6(1)(b))
Email verification, security emails, service notifications Contract (Art 6(1)(b))
Keeping the Platform secure (session management, abuse prevention, security logging) Legitimate interests (Art 6(1)(f)) — protecting the Platform and its users
Improving the Platform using aggregate, non-identifying usage information Legitimate interests (Art 6(1)(f))
Billing and subscription management Contract (Art 6(1)(b)); legal obligation (Art 6(1)(c)) for tax and accounting records
Responding to enquiries you send us, and following them up Legitimate interests (Art 6(1)(f)) — answering the people who contact us; or steps before entering a contract (Art 6(1)(b)) where you enquire about a plan
Responding to legal requests and complying with law Legal obligation (Art 6(1)(c))
Optional communications you opt into Consent (Art 6(1)(a)) — withdrawable at any time

Where we rely on legitimate interests, we have balanced our interest against your rights and use the least data necessary. You can object — see Section 9.

5. Special-category data and Research Data (processor scope)

Studies run on the Platform may collect special-category data — most commonly health data. For that data:

  • The Researcher (or their institution) is the controller and is responsible for identifying an Article 6 lawful basis and an Article 9 condition (for example, explicit consent under Art 9(2)(a), or scientific research under Art 9(2)(j) with the UK research safeguards), obtaining any required ethics approval, and giving Participants a privacy notice.
  • Indacas is the processor. We process such data only on the Researcher's documented instructions, under the terms of our Data Processing Agreement. We do not use Research Data for our own purposes.
  • In-product, Researchers can flag fields as sensitive, and the Platform records in-product consent statements with acceptance timestamps and keeps audit logs of who viewed or changed Research Data (including timestamps and IP addresses). These features support the Researcher's compliance; they do not replace it.

If you are a Participant with questions about how a study uses your data, contact the Researcher named in that study's privacy notice first. We will assist Researchers in responding, and we will always tell you who the controller is if you are unsure.

6. Who we share personal data with

We share personal data only with:

  • Subprocessors and service providers listed in our Subprocessor List (DigitalOcean for hosting and database, Postmark for transactional email, Cloudflare for DNS and proxy, Stripe for payments). Each is bound by contract to process data only for us.
  • The relevant Researcher, where you participate in their study — your Research Data, and limited Account Data (such as your name and email) where the study design requires identified participation. Anonymous distributions do not share your identity.
  • Professional advisers, authorities, or successors where the law requires it or in a genuine corporate transaction, with safeguards.

We never share personal data with advertisers or data brokers.

7. International transfers

The Platform is hosted in London, UK, and traffic to it is handled by Cloudflare in UK data centres. Some service providers process data outside the UK: Postmark delivers email from the United States, and Stripe processes payments in Ireland and the United States. Where personal data leaves the UK, we rely on:

  • a UK adequacy regulation for the destination country, where one exists; or
  • the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), plus any needed supplementary measures.

Transfer details per provider are in the Subprocessor List.

8. How long we keep data

We keep Account Data for as long as your account is active, and then delete or anonymise it.

Server logs are kept for 90 days. Authentication, authorisation and API logs are kept for 12 months. Contact enquiries are kept for 12 months from our last exchange with you, and for the life of the contract where an enquiry leads to one.

When you make a deletion request, we will verify it is really you and then delete your Account Data within 30 days, except where we must keep specific records — for example billing records we are required to retain for tax purposes, or a minimal record of the deletion itself. Backups are overwritten on a rolling 7-day cycle, so data you have asked us to delete may persist in an encrypted backup for up to seven days after it is removed from our live systems.

Research Data retention is set by the controlling Researcher. On termination of a Researcher's use of the Platform, Research Data is returned or deleted as described in the Data Processing Agreement.

9. Your rights

Under UK GDPR you can ask us to:

  • Access the personal data we hold about you (a "DSAR");
  • Rectify inaccurate data (much of your Account Data you can edit yourself in your profile);
  • Erase your data;
  • Restrict or object to processing based on legitimate interests;
  • Port data you provided to us in a machine-readable format;
  • Withdraw consent where processing is based on consent, without affecting past processing.

To exercise a right, email [email protected] from your account email or contact us in-product. We will verify your identity, respond within one month (extendable by two months for complex requests, and we will tell you if so), and we will not charge unless a request is manifestly unfounded or excessive.

If your request concerns Research Data (e.g. "delete my survey answers in Study X"), the Researcher is the controller: we will pass your request to them without undue delay and assist them in responding, and we will tell you we have done so. Studies also include an in-product withdrawal route.

You can complain to the ICO at any time: ico.org.uk / 0303 123 1113.

10. Children

You must be 16 or older to create an Indacas account. We do not knowingly hold accounts for children under 16, and we will close any we discover.

Studies involving Participants under 16 are possible only under the governance of the controlling Researcher, who is responsible for lawful basis, parental/guardian consent where required, ethics approval, and appropriate safeguards. See the Acceptable Use Policy.

11. Security

We protect personal data with encryption in transit (TLS), role-based access control, audit logging of access to Research Data, optional two-factor authentication, and self-hosted identity infrastructure. A fuller description of technical and organisational measures is in Annex II of the Data Processing Agreement. No system is perfectly secure; if a breach affects your data and risks your rights, we will notify you and the ICO as the law requires.

12. Changes to this policy

We will post changes here with an updated date. For material changes we will give notice by email or in-product at least 30 days in advance before they take effect.

13. Contact

Indacas Ltd, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ Email: [email protected]