Built on a
short list

Your organisation is the controller and Socialheads is your processor. Six companies handle personal data on our behalf. Here is what each is for, what it sees and where it runs, and the named list goes to your review on request.

Who handles what

Nothing about a young person rests outside the UK or the European Economic Area, and each one is bound to the same Article 28 terms we sign with your service.

Hosting

For: The servers running the application, its database and background work.

Sees: All application data at rest, encrypted field by field where it is personal.

Where: Germany. European Economic Area.

Live chat transport

For: Carries messages in real time. Our own encrypted copy is the record.

Sees: Conversation participants and message text. Never a file, a filename or a caption.

Where: European Union.

Sign-in

For: Passwordless sign-in for everyone who uses the app.

Sees: Email, mobile number, name, role and organisation. Never a message.

Where: United Kingdom.

Edge, files and backups

For: Serves the app securely, stores shared files and encrypted backups.

Sees: Files under random keys; filenames and captions stay encrypted in our database. Backups are encrypted before they leave our servers.

Where: UK and EU. File and backup storage bound to EU jurisdiction.

Email

For: Invitations, notifications and system messages.

Sees: Email address, name, and a body carrying no case detail.

Where: European Union.

Text messages

For: The invitation text that brings someone into the app.

Sees: Mobile number, a body carrying no case detail, delivery status.

Where: European Union.

What each one is held to

  • Article 28 terms. Every sub-processor works under a data processing agreement, so the duties your service places on us flow down to them.
  • Assessed before use. Each has its own data protection impact assessment, with a transfer risk assessment where a US parent company is involved, and we share them with your review.
  • Deletion follows the person. When a membership ends, the record at the chat provider goes with it, and a full erasure anonymises the account there. If a deletion doesn't reach them, that is recorded and followed up.
  • Least data by design. The chat provider never receives a file, a filename or a caption. Email and text never carry case detail. Sign-in never receives a message.
  • Anything assistive runs on our own infrastructure. Messages are never sent to a third-party model and never used to train one, so no AI company appears on this list.
  • You hear before anything changes. We tell your service before a sub-processor is added or replaced, with time to raise an objection.

Ask for the named list

Running a data protection review or a procurement assessment? Tell us and we will send the full list of named providers, with the assessments behind each one.

For the website and our research, Socialheads is the controller and a different set of tools is involved. Those are named in full in the privacy policy.

Ask for the list
Top