Privacy Policy
Effective date: 1 November 2024
Last updated: 19 August 2026 · Next review: 19 August 2027
At Socialheads, we are committed to protecting your privacy and ensuring compliance with UK GDPR and other relevant data protection regulations. This policy explains how we collect, use, and protect your personal data.
What this policy covers
This policy covers the Socialheads website and our research: enquiries, bookings, interviews, focus groups and surveys. For all of that we are the data controller, which means we decide what is collected and why.
It does not cover the Socialheads app. When a care, youth, education or support service uses the app, that service is the data controller and we are their processor. What is collected there, who can see it and how long it is kept are set by that service and by our contract with them, not by this policy. The app privacy notice covers that side, and who can see my information is the plain-language version of it.
Who we are
Socialheads Limited, a private limited company registered in England and Wales, company number 16129065. Registered office: Canopi, 82 Tanner Street, London, SE1 3GN, United Kingdom.
We are registered with the Information Commissioner's Office, registration ZB957712. We have not appointed a statutory Data Protection Officer, which we are not required to do at our size and scope. Data protection questions come to the founder, at the address in section 14.
1. Data we collect
- Name, email address, and phone number (e.g. when you fill out a form or contact us).
- Job role and the organisation you work for (e.g. if you are a practitioner, manager, or work in youth care, health, or education).
- Your professional experience, if relevant to the research.
- Consent form information, including support or access needs you voluntarily share.
- IP address, browser type, device details, referrer URL, and interaction data from our website.
- Typeform survey responses.
- Research notes, transcripts, and (if applicable) interview recordings.
- Age and care status (if relevant to the research).
- Dates of contact, interview scheduling, consent status, and safeguarding checks (internal use).
- Confirmation of remuneration sent, and internal notes related to research logistics or insights.
Note: We only collect sensitive data (e.g. ethnicity, disability, or health information) when it is provided voluntarily or directly relevant to the research. We do not collect data for profiling or marketing.
2. How we collect data
- Website forms (e.g. contact or enquiry forms).
- Calendly bookings.
- Typeform surveys and consent forms.
- Research interviews and focus groups.
- Emails or direct communication.
- Cookies (see our Cookies Policy for details).
- In some cases, data may be temporarily stored on a researcher’s personal device (e.g. phone, laptop) when scheduling or recording. This is deleted within 14 days once uploaded to secure storage.
3. Why we collect data
- To respond to enquiries or service requests.
- To conduct ethical and participant-led research.
- To improve our platform, services, and user experience.
- To ensure accessibility and safeguarding during research.
- To understand how people interact with our website.
Note: We do not use your data for marketing or profiling unless you explicitly opt in.
4. Who else processes your data
These are the third parties who handle personal data on our behalf, what each one is for, and where the data sits.
- Google Analytics 4 and Google Tag Manager (United States) – website usage statistics: which pages are read, time on site, approximate location, browser and device. Loaded only if you accept analytics cookies, and never used for advertising. See our cookie policy for the cookies this sets.
- Google Workspace (European Union) – storing consent forms, research data and internal documentation.
- Google Meet (European Union) – conducting and recording interviews and focus groups, with consent.
- Google Calendar (European Union) – booking interviews, focus groups and meetings.
- Typeform (European Union) – collecting consent and survey responses.
- Fathom (United States) – recording and transcribing research sessions, with consent.
- Calendly (United States) – booking meetings.
- Notion (United States) – where an enquiry from a website form is recorded and followed up, including your name, email address, phone number and organisation.
- MailerSend (hosted in the European Union; the provider is US incorporated) – sending the emails that carry a form submission to us.
- Platform.sh (United Kingdom) – hosting the website, including the queued copy of a form submission until it is delivered to us.
- Cloudflare (United Kingdom and European Union) – Turnstile checks on forms to stop automated abuse. Cloudflare processes your IP address and browser information for security verification. See Cloudflare's privacy policy.
Note: We complete Data Protection Impact Assessments (DPIAs) and Transfer Risk Assessments (TRAs) for tools based outside the UK/EU. These platforms use Standard Contractual Clauses (SCCs) and the UK Addendum to ensure GDPR compliance. We keep DPIAs and TRAs in a dedicated compliance folder so they can be reviewed on request by regulators or partners. We do not sell or share your data for advertising purposes.
5. Your rights
- Access the data we hold about you.
- Request correction or deletion.
- Object to processing.
- Restrict how we use your data.
- Request a copy of your data (data portability).
- Withdraw consent at any time, where consent is what we relied on. Withdrawing it does not undo processing that already happened.
- Complain to the Information Commissioner's Office, free of charge, at any point.
Note: To exercise these rights, email [email protected]. We will respond within one month. We keep a log of all rights requests to ensure accountability.
Automated decisions: we do not make decisions about you by automated means, and we do not profile you.
6. Data retention and deletion
- Website enquiries and form submissions are retained for up to 12 months.
- Research participant data is retained for up to 2 years after the research project ends.
- Anonymised or aggregated data may be kept for longer for reporting or funding purposes.
- We log and review all deletions and maintain a clear audit trail.
Note: You may request earlier deletion unless we are legally required to retain your data.
7. Security measures
- Encrypted cloud storage (e.g. Google Workspace).
- Password protection and two-factor authentication.
- Restricted access to authorised team members.
- Secure deletion protocols and regular reviews of stored data.
- Where personal devices are used (e.g. phones, laptops), files are uploaded promptly to secure storage and deleted locally within 14 days.
- Spam prevention using Cloudflare Turnstile on form submissions to protect our services from automated abuse. Cloudflare may process your IP address and browser information solely for security verification. See Cloudflare's Privacy Policy for details.
8. Legal basis for processing
- Consent: when you choose to participate in research or complete a form.
- Legitimate interest: to improve our services and conduct ethical research.
- Contractual necessity: when we deliver something you've requested (e.g. a session booking).
Note: We record consent using Typeform, email, or signed forms.
9. Cookies
- We use cookies to understand site usage and improve functionality.
- You can choose to accept or reject cookies when visiting the site.
Note: See our Cookies Policy for details.
10. Children's privacy
- We do not knowingly collect data from anyone under 16 without verified parental consent.
- We follow safeguarding best practice, including age-appropriate explanations and DBS checks for relevant staff.
11. Media consent and story sharing
- We may ask for separate media consent to share quotes or stories publicly.
- You can say no or change your mind at any time.
- We never publish personal details without explicit permission.
12. Research ethics and safeguarding
- Informed consent is always required before participation.
- Safeguarding checks are completed for researchers working with young people.
- Data Protection Impact Assessments (DPIAs) and Transfer Risk Assessments (TRAs) are carried out for relevant tools.
- Participant tracking logs help manage consent, scheduling, and deletion timelines.
- We also maintain compliance logs (e.g. deletion log, breach log, access log) to evidence safe handling of data.
13. ICO and complaints
- We are registered with the Information Commissioner's Office (ICO), registration ZB957712.
- If you are concerned about your data, email [email protected].
- To make a complaint, use our complaints form, which goes to its own dedicated mailbox.
- If unresolved, contact the ICO at www.ico.org.uk. It is free.
14. Contact us
- If you have questions about this policy or your data, email [email protected].
- We are committed to transparency, respect, and safeguarding your privacy.