Glassbox · effective 2026-09-04

Privacy Notice

Version 1.0

This notice explains how [COMPANY LEGAL NAME] (company number [COMPANY NUMBER], registered office [REGISTERED OFFICE ADDRESS]) (the Company, we) processes personal data in connection with the Glassbox platform. The Company is the controller. Contact: nickyfventures@gmail.com.

1. What we collect

CategoryExamplesSource
Account dataname, email address, display name, password hashyou
Professional profilerole, employer or company name, years of experience, specialisms, controls platforms, certificationsyou
Legal acceptance recordstyped legal name, date and time, document version and hash, IP address, browser identifieryou and your browser
Contribution datafault cases, reasoning steps, hypotheses, confidence levels, reviews, scores, uploaded documents and imagesyou
Usage and security datasign-ins, page and record access, audit log entries, IP address, browser identifieryour browser
Access requestsname, email, company, role, experience, messageyou

Uploaded documents and images must not contain personal data of other people beyond a first name or role, and faces and identifiers must be removed. If we find such data we will remove or anonymise it.

2. Why we process it and on what basis

PurposeLawful basis (UK GDPR Article 6)
Operating your account and the platformperformance of a contract (the Confidentiality Agreement and Data Contribution Terms)
Evidencing your acceptance of legal documents and the rights you grantlegitimate interests (proof of contract and of rights in contributed material); legal obligation where applicable
Building datasets, benchmarks and machine-learning models from contributionslegitimate interests (developing the Company's products); contributions are attributed to you internally for quality, review and credit
Security, audit logging, preventing misuse and enforcing the Confidentiality Agreementlegitimate interests (protecting confidential information and the platform)
Assessing access requestslegitimate interests (deciding who to admit to a private platform)
Recording provisional contribution creditslegitimate interests and, once signed, performance of a separate written agreement

We do not use your data for marketing and we do not sell it.

3. Who receives it

  • Our infrastructure providers, acting as processors: Supabase (database, authentication and file storage) and Railway (application hosting). Data may be stored in the United Kingdom, the European Economic Area or the United States under appropriate safeguards (UK adequacy regulations or the International Data Transfer Agreement / EU standard contractual clauses with the UK addendum).
  • Other platform users see your display name and, where you author, solve or review a case, the content you contributed in that role. Reviewers see contributions; solvers do not see who authored a case.
  • Professional advisers, and authorities where the law requires.
  • A purchaser or successor of the Company's business, under confidentiality.

Datasets and models derived from contributions may be licensed to third parties. Before that, contributions are anonymised: your name and contact details are removed and free-text fields are checked for identifiers.

4. How long we keep it

DataRetention
Legal acceptance records and audit logsfor as long as the related contribution or agreement is in force, plus six years
Contributionsindefinitely, as part of the dataset; attribution to you is removed on request where it is not needed to evidence rights
Account and profile datawhile your account is active, then 12 months
Access requests12 months from decision

5. Your rights

You have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to complain to the Information Commissioner's Office (ico.org.uk). Erasure does not extend to contributions where we need them to evidence the rights granted, or to anonymised data. To exercise a right, email nickyfventures@gmail.com. We respond within one month.

6. Security

Access is invite-only. Data is encrypted in transit and at rest. Every read of confidential material is logged. Hidden case data is enforced at the database level, not only in the user interface.

7. Changes

We may update this notice. The version and date appear at the top; material changes are announced on the platform.