---
title: "App privacy notice | Socialheads"
url: https://socialheads.co.uk/app-privacy/
---
**Effective date:** 19 August 2026 · **Next review:** 19 August 2027

## Who this is for

This covers the Socialheads app: the messaging service a care, youth, education or support service uses to talk with the people it supports. It is written for anyone who wants the detail, including young people, parents and carers, and data protection officers assessing us.

If you want the plain-language version first, read [who can see my information](/who-can-see-my-information/). Both say the same thing. This one just says more.

The [website privacy policy](/privacy/) is a different document covering our website and our research.

## Who is responsible for your information

**Your service is the data controller. Socialheads is their processor.** That distinction decides almost everything on this page.

Your service decides who is invited, what is collected, who can see it and how long records are kept. We build and run the software and hold the information on their behalf, under a contract that only lets us act on their instructions.

So questions about why you were invited, who is in your conversations, or how long your records are kept are answered by your service. Questions about how the software itself works are answered by us. Both routes are at the bottom of this page.

There is one exception. We are the controller for our own security and audit logs, which we keep under our own responsibility so that we can account for how the system was used.

## What is held

- **Who you are:** name, email address, mobile number, pronouns, age category, and your role at the service.
- **Your conversations:** the messages you send and receive, and who is in each conversation.
- **Anything shared in a conversation:** images and documents.
- **A record of what happened:** when an account was created, when someone was added to a conversation, when information was accessed and by whom.
- **Agreements:** what has been agreed and when.

**What is never collected:** your location. Your contacts. Any advertising identifier. There is no analytics package in the app measuring how you use it, and no advertising anywhere in the product.

## Why it is held, and on what legal basis

Your service sets this, and for most services it is one of two things: a legal duty they have to keep records and to safeguard the people they support, or a task they carry out in the public interest. Where information in a conversation is sensitive, which for these purposes includes anything about health, ethnicity, religion, sexuality or the criminal law, the condition they rely on is safeguarding children and individuals at risk.

Consent is deliberately not the basis for the core service. A safeguarding record that disappeared the moment someone withdrew consent would not be a safeguarding record, and services could not rely on it. Consent does cover the optional parts, like which notifications you choose to receive.

## Who can see your conversations

The people in a conversation read it. That is you, whoever is supporting you, and anyone else who has been added.

Someone running the service works with numbers rather than conversations, so they can see the service is running properly.

For safeguarding, or where the law asks it, the person at your service whose job that is can ask for what they need. It is switched on for one named person, not granted by a job title and not by being someone's manager. They write their reason first, in their own words, and every administrator at the service is told at the time and pointed to where that reason is kept. Their name, their reason and the time are recorded.

You can ask your service whether that has happened to your conversations. It is a fair question and it has an answer.

## Socialheads and your messages

We do not look at your messages. The only exceptions are where we are legally obliged to, or where you or your service has given us explicit permission.

That rule is built into the system, not just written down. Personal information is encrypted field by field in the database, so it is not readable by browsing the data. Any authorised decryption is recorded. When something goes wrong we work from timings and error reports, and we ask whoever saw the problem.

## Where your information is held

- **Your conversations, files and records:** Germany, on servers in Falkenstein. Inside the European Economic Area.
- **Your sign-in details:** the United Kingdom.
- **The live chat service:** the European Union, in the Netherlands.
- **Files you share, and backups:** the European Union, in storage bound to the EU when it was created.

Nothing about you rests outside the UK or the EEA. Some of the companies we use have US parents, so their staff may need administrative access for support, which is covered by the contracts we hold with them. Every one of those arrangements is assessed and written down before it is used.

## How it is protected

- Encrypted in transit, everywhere, all the time.
- Personal information encrypted field by field where it rests, including message content.
- Every service's data is separated from every other service's.
- Reading a conversation you are not part of requires a named grant and leaves a record.
- Backups are separately encrypted, held away from the main system, and restoring them is tested.

Socialheads is not end-to-end encrypted, and that is a decision rather than a gap. Your service has to be able to produce a record for a safeguarding investigation, a subject access request or an inspection, and end-to-end encryption would put that out of reach. So information is strongly protected, and every access is accountable.

## How long it is kept

Your service decides, and the period is set in our contract with them rather than by us. It is not one length for everyone, because the law sets different periods for different kinds of record. Some run a long time: records about a child who has been looked after are generally kept until their 75th birthday, and adoption records for at least 100 years.

This is why a deletion request is considered rather than automatic. Where a record has to be kept, we tell you that, and why.

## What you can ask for

From the **My data** screen in the app, for each organisation you are part of, you can do both of the following. Both cover what Socialheads holds, which is your messages and the files shared with them. Records your service keeps elsewhere, such as case notes, are requested from the service directly.

- **Ask for a copy of your messages** and the files shared with them. It goes straight to that organisation's data protection officer and does not pass through whoever supports you. The screen tells you where the request has got to, and when your copy is ready you can download it.
- **Ask for your Socialheads data to be deleted.** It goes to the same person. What can be agreed depends on your service, since some records have to be kept by law, and the screen says so up front.

You can also ask your service to correct something that is wrong, to restrict how your information is used, to object to it being used, and to withdraw consent where consent is what they relied on.

If you are 13 or older you can make these requests yourself. Under 13, a parent or guardian does it with you.

## Is any of this automated?

No decision about you is made by a computer, and nothing profiles you or scores you. Your messages are never sent to an AI company, and they are never used to train anything.

If we add it, it will help practitioners with their own work, like drafting the write-up they have to produce anyway for them to check and correct. It will run on our own computers rather than another company's, it will never be trained on your conversations, and we will never put it between you and the person supporting you.

## Who else is involved

These companies help run the app. Each one is assessed before it is used, and none of them may use your information for anything except providing their part of the service.

- **Hetzner** (Germany): the servers holding the application and its database.
- **TalkJS** (Netherlands): the live chat service that carries messages.
- **Auth0** (United Kingdom): signing in.
- **Cloudflare** (UK and EU): serving the app securely, and storing shared files and backups in EU-bound storage.
- **Postmark** (European Union, Frankfurt): sending emails from the app.
- **Twilio**: sending invitation text messages.

## If something isn't right

- **Your service first.** Ask whoever supports you, or the service's data protection officer, whose job this is.
- **Us,** if it is about the software rather than your service. Email <hello@socialheads.co.uk>, or use our [complaints form](/complaints/).
- **The Information Commissioner's Office,** if your service does not put it right. They take complaints at [ico.org.uk](https://ico.org.uk), free of charge. That is your right.

## Who we are

Socialheads Limited, a private limited company registered in England and Wales, company number [16129065](https://find-and-update.company-information.service.gov.uk/company/16129065). Registered office: Canopi, 82 Tanner Street, London, SE1 3GN, United Kingdom. Registered with the Information Commissioner's Office, registration ZB957712.

Questions about this notice go to <hello@socialheads.co.uk>.
