Built to be
checked
How information is held, who can look at it, and what is recorded when they do. Trust means different things to a data protection officer, a head of service and a young person, so this page is written to be checked by all three.
Your organisation stays in charge of the information. Socialheads holds it, keeps the record of what happens to it, and hands you the evidence when someone asks.
Choose the one that fits you:
On access, the whole posture is one sentence: reading a conversation is limited to the people in it, and any other access, ours included, needs a recorded reason your service can see.
Most services start with the staff team chat. The same governance covers messaging between staff and the people you support.
Who is responsible for what
When your service uses the Socialheads app, your organisation is the controller and Socialheads is the processor. That split decides who carries the legal duty, so it is worth being clear about from the start.
There is one carve out. For our own website, and for our own account, audit and security records, Socialheads is the controller, under our own lawful basis.
No supplier can make your service compliant. Socialheads is designed to support your UK GDPR responsibilities and built so you can evidence what happened.
How access to a conversation works
Encrypted on the way, and encrypted field by field in the database
Everything travels over an encrypted connection. In the database, personal data is encrypted field by field rather than sitting in readable columns, and backups are encrypted with their own key.
Someone is given access, by name
Being an administrator does not let someone read conversations. Your organisation gives that access to a named person, deliberately, and decides which roles should have it.
Encryption protects the data. Access rules decide who reads it
Those are two different jobs and we do them separately. Encryption keeps the information from being readable to anyone who should not have it at all. Who may read a conversation is a separate decision your organisation makes and we record, which is what lets a safeguarding lead review a concern when one is raised.
We do not look at your messages. The only exceptions are a legal obligation on us, or explicit permission from you or your organisation, and we put that standard in writing during procurement.
What is recorded
Every action that matters: what happened, when, who did it, who it was about, and which record it touched. A message flagged, a member archived, a consent captured, an export produced.
The names and the roles are written into the entry at the time, not looked up afterwards, so it still reads correctly once someone has changed their name, moved on, or had their account anonymised. That day is usually years later.
Entries cannot be edited or deleted from the product, and opening the log is itself recorded. What it shows by default is what happened and who was involved. Message content and contact details stay behind the step below.
What a break-glass access looks like
Sometimes a person with the right responsibility genuinely needs to read the content behind an entry: a safeguarding concern, a subject access request, an incident investigation. That is a real need, so it has a real route, and the route leaves a mark.
It is gated, it is short, and it is loud. So the question is never "did somebody read this". It is "here is who, here is when, and here in their own words is why".
If your security review wants this control by control, that is what the procurement pack is for.
How long records are kept
There is no single answer, because the period follows the record rather than the software. A looked after child's record runs to their 75th birthday. A contact register should go fairly quickly.
So the periods are yours to agree in your data processing agreement, and there is no global retention default wired into the software.
Safeguarding records are never deleted on a timer. Archiving locks access and keeps the record.
Erasure is deliberate, recorded, and conditional. Where a retention duty, a safeguarding need or a legal claim applies, the request is declined or deferred, and that decision is recorded with its reason. An unconditional wipe would hollow out a safeguarding timeline at the moment it matters most.
Where the data is held
Two different things live in two different places, and it is worth being exact.
United Kingdom
Identity is held in the United Kingdom. That is the account you sign in with, and the credentials behind it.
European Economic Area
Application data is held in the European Economic Area. That is your conversations, your records and your files.
Backups and uploaded files sit in EU jurisdiction storage, encrypted, with the backup key held separately from the database itself.
Application data sits in the EEA today, and identity data in the UK. If your procurement requires UK only residency for application data as well, tell us early: it is a real piece of work rather than a setting, and we would rather plan it with you than promise it.
Registration and how we are regulated
We are registered with the Information Commissioner's Office, registration ZB957712.
The ICO reaches both of us: your organisation as the controller, and Socialheads as your processor acting on your instruction. Your own inspectorate is a separate matter and it stays yours. Whichever one applies to your setting, an inspector asks what contact a person had, how the service responded, and how you know. The record described above is built to answer exactly that.
On security assurance, Cyber Essentials will be in place before your service goes live with us. If your procurement needs a particular standard, or an independent test, tell us as early as you can and we will tell you where it stands and when.
Does it tick the boxes?
The questions a data protection review and a procurement panel ask, with where Socialheads stands on each. Where something lands before your service goes live rather than today, it says so.
| The question | Where Socialheads stands | See |
|---|---|---|
| Who is the controller and who is the processor? | Your organisation is the controller. Socialheads is the processor, acting on your documented instructions. | Above |
| Is there a data processing agreement? | Yes. We sign Article 28 terms with every service before it goes live, and the same terms flow down to every sub-processor. | Sub-processors |
| Who else handles the data, and where? | Six companies, published by purpose, data and region, with the named list sent to your review on request. Identity is held in the UK; application data in the EEA. | Sub-processors |
| Is it registered with the ICO? | Yes. Registration ZB957712. | Privacy policy |
| Is the data encrypted? | In transit everywhere. Personal data, including message content, is encrypted field by field in the database. | Above |
| Can your staff read our conversations? | Reading is limited to the people in a conversation. Any other access, ours included, needs a recorded reason your service can see. | Above |
| Is there an audit trail? | Yes. Every access and every change is recorded, and the trail can only be added to from the app. | Above |
| How long is data kept? | To the periods your service sets in the agreement, by record class. Safeguarding records are never deleted on a timer. | Above |
| Can a young person exercise their rights? | Yes. A copy of their Socialheads messages and a deletion request are one tap in the app, routed to your DPO and never through their worker. Records you hold elsewhere stay your process. | Their page |
| Does it meet the Children's Code? | Built to it: no profiling, no advertising, no behavioural tracking, and the young person's own page explains who sees what. | App privacy |
| Does it support our safeguarding duties? | Yes. Flagging by anyone in a conversation, named-person access with a written reason, and administrators told at the time. | How safeguarding works |
| Can we configure it to our policies? | Yes. File sharing, who can talk to whom, permissions and vocabulary are per-service settings that start closed. | Setting up |
| What about the Online Safety Act? | A written risk assessment is in place before your service goes live, and the product enables your reporting duties rather than replacing them. | How safeguarding works |
| Is there a security certification? | Cyber Essentials is in place before your service goes live with us. Ask early if your procurement needs a different standard. | Below |
| What happens if there is a breach? | We tell your service without undue delay, with what we know, so you can meet your own 72 hour clock. | Ask us |
| Can we see your assessments? | Yes. Our DPIAs, including one per sub-processor, go to whoever is running your review. | The pack |
What we can send you
This page is the shape of it. If you are preparing a data protection review, or putting a paper in front of a panel, ask for the pack and you get the detail behind every line of it.
The procurement pack
- The data processing agreement, including the retention periods you set.
- Our data protection impact assessment, the supplier half of the one your organisation carries out.
- A security overview, set out the way a security review asks for it.
- A subprocessor list, with the region of each one, so you can check residency line by line.
Get in touch and name the procurement pack in your message. How safeguarding works is the same model from your safeguarding lead's side.
Straight answers
Who is the data controller?
Your organisation is the controller and the legal duty sits with you. Socialheads is the processor and acts on your instruction. For our own website, and our own account and security records, Socialheads is the controller.
Is Socialheads encrypted?
Yes. Connections are encrypted, and personal data is encrypted field by field in the database: message content, names, contact details, attachment filenames and captions, the reason on a safeguarding flag, and the identity held in the audit record. Backups carry their own key, held separately. Who can read a conversation is controlled separately from that: only the people in it, and any other access needs a recorded reason your service can see. If your review has a question about a specific encryption model, ask and we will answer it directly.
Can Socialheads staff read our conversations?
Reading your conversations is not part of any Socialheads job, and the product has no Socialheads staff screen that opens them. We build the software and run the infrastructure, so the capability exists, as it does with every supplier who hosts your data. It is never used routinely, and for an exceptional case we hold ourselves to authorisation by more than one person, telling you, and recording it in your own audit log. Ask for that in writing.
Who in our organisation can see the audit log?
The org level roles that carry the duty: your administrators, your data protection officer, your safeguarding lead, and your Caldicott Guardian where you have one. Each sees their own organisation and nothing else, and opening the log is itself recorded.
Do you delete records after a set time?
Each class of record carries its own clock, and the period is yours to set in your data processing agreement. Safeguarding records are never deleted on a timer, and erasure is a deliberate, recorded act.
Where is our data held?
Identity, meaning the account you sign in with, is held in the United Kingdom. Application data, meaning your conversations, records and files, is held in the European Economic Area, and so are backups and uploaded files.
Is our data encrypted at rest?
Personal data is, encrypted field by field, so what reaches the disk is ciphertext rather than readable columns. Full-disk encryption of the server itself is deliberately not in place, so if your review needs it specifically, say so early and we will talk it through.
What about security certification?
Cyber Essentials will be in place before your service goes live with us. If your procurement needs a particular standard, or an independent test, tell us early and we will tell you where it stands and when.
Can you send us a DPA, a DPIA and a subprocessor list?
Yes. Ask for the procurement pack through the get started form. Saying what your review needs helps the right level of detail arrive first time.
Ask us to show you the audit trail on real screens, with your service in mind. Tell us the timescale you are working to and we will work it out with you.