Company & Controller

Who Is Responsible for Your Data

This site and platform are operated by SEE Change Happen Ltd, a company registered in England and Wales, Company No. 13138905, registered address1 The Briars, Waterberry Drive, Waterlooville, PO7 7YH. SEE Change Happen Ltd is the data controller for personal data collected through this site and the platform atapp.thetransinclusiontoolkit.co.uk.

Source: Privacy Policy, §1 "Who We Are".

Encryption & Application Security

How Data Is Protected in Transit and at Rest

  • Encryption in transit — the site and platform use HTTPS (TLS) encryption for all connections.
  • Credential handling — API keys and service credentials used by the platform are held in the platform's managed secret stores, encrypted at rest by the provider, accessible only to server-side functions and never exposed to the browser.
  • Private document storage — files you upload to the DocuVault™ are held in a private, access-controlled storage bucket in the United Kingdom, reachable only by the account that owns them and only through expiring links. They are never served from a public URL.
  • Access controls — access to personal data is restricted to authorised personnel on a need-to-know basis.
  • Bot and abuse protection — Cloudflare bot management, and Turnstile on forms, protect the site from automated abuse.

Source: Privacy Policy, §8 "Data Security", andAnnex B of the draft Data Processing Agreement.

Access & Authentication

How Sign-In and Licensing Work

  • Per-user licensing — Practitioner and Professional access levels are licensed per user.
  • Passwordless sign-in — you sign in with your personal email address and a 6-digit one-time code sent by email. There are no passwords to set, store, or forget.
  • Devices — each licence is for one named person, used across that person's own devices, licensed for two concurrent devices. You can retire a device yourself from your account settings at any time to free up a slot.

Sub-processors

Who Else Processes Your Data

  • Stripe — payment processing for paid subscriptions; PCI DSS Level 1 certified. Card data is entered on Stripe's own hosted checkout page and never passes through our servers.
  • HubSpot — CRM, form processing, and email communications; maintains SOC 2 Type II certification.
  • Cloudflare — hosting, content delivery, and security, including bot management and Turnstile on forms.
  • Amazon CloudFront — content delivery for video and podcast media on the marketing website only. No account or user data is held there.
  • Supabase — the application platform: database, authentication, file storage (including DocuVault™ documents), and server-side functions. It is the primary store for your data, and the project region is London, United Kingdom.
  • OpenAI — powers the Quinn AI inclusion assistant and the guided pathway's AI-powered tools.
  • Pinecone — vector database used by Quinn to search the Toolkit knowledge base; no personal data is stored, only a temporary query embedding.
  • Resend — transactional and support email: the 6-digit sign-in codes, account and lifecycle messages, and support correspondence.

This is our complete list of sub-processors, current as at 13 August 2026, and it matchesAnnex C of the draft Data Processing Agreement. Under clause 4.4 of that agreement, publication of an updated list on this page — together with notice to the email address on the account — is how we give notice of a change of sub-processor. Source: Privacy Policy, §6 "Third-Party Services".

AI Data Handling

No AI Training on Your Data

Commitment

OpenAI's API data usage policy states that API inputs and outputs are not used to train their models. Where Quinn or the guided pathway's AI tools analyse your questions or uploaded policies, we use OpenAI's API under a data processing agreement that prohibits training on customer content. Pinecone, the vector database behind Quinn's knowledge-base search, stores no personal data — only a temporary mathematical representation (embedding) of your query is sent to find relevant content.

What Quinn keeps depends on your access level. On pilot and superuser accounts the questions asked and the answers given are stored, so that the assistant can be reviewed and improved. On every other account they are not: we record only the topic tags and the length of each message.

Source: Privacy Policy, "Quinn AI Inclusion Assistant" and "AI Processing" sections.

AI Architecture

How the Toolkit Uses AI

You interact with the Toolkit application — never directly with an AI provider. The Toolkit is an application whose services make their own API calls to AI models where a task needs one, through a deliberately platform- and model-agnostic layer.

  • Our AI sub-processors are named in the list above. We do not pin this page to particular model names, because the models in use are superseded and replaced as the field moves.
  • Prompts come from a tested library. Calls are built from a predetermined, multi-layered prompt library that injects steering as needed (for example, UK English) — not free-form pass-through of your input.
  • It is not purely AI. Deterministic code performs look-ups and cross-referencing, and output is cross-checked against tables of predetermined citations — code is reliable and repeatable where AI, by its nature, varies.

Data Residency

Where Your Data Is Processed

Your application data — your account, organisation profile, pathway progress, diagnostic results, and DocuVault™ documents — is held and processed by Supabase inLondon, United Kingdom. That data therefore stays in the UK, and no restricted transfer arises for it. This website and the platform are served by Cloudflare.

We do not, however, claim UK-only data residency across every sub-processor. HubSpot, OpenAI, Pinecone, and Resend process some data in the United States under Standard Contractual Clauses and the UK International Data Transfer Agreement (the UK Addendum); Stripe processes payment data in the United States and other jurisdictions under Standard Contractual Clauses and its certification under the EU-US Data Privacy Framework; and Cloudflare processes data across its global network under its own Data Processing Addendum, which incorporates the Standard Contractual Clauses and the UK Addendum.

Source: Privacy Policy, §6 "Third-Party Services" and §11 "International Data Transfers"; Annex C of the draft Data Processing Agreement.

Your Rights

Access, Export, Deletion & Cancellation

Under UK GDPR you can request access to your data (within 30 days), rectification, erasure, restriction of processing, data portability, and can object to processing or withdraw consent at any time. We do not use automated decision-making that produces legal or similarly significant effects.

There is a single retention timer, and it runs on free accounts. It is keyed to the date you last signed in, and we send reminder emails, asking you to sign in or to export what you want to keep. We do not operate an automatic deletion process, so nothing is removed on the timer alone. A paid subscription suspends the timer entirely. If a subscription ends, the account returns to the free access level and the timer applies again from your last sign-in.

Deletion on request is separate from that timer, is immediate, and is available at any time: you can ask us to delete your account and its data from your account settings in the app or by contacting us, whatever your access level and whether or not you are paying.

Paid subscriptions can be cancelled at any time from the Account area of the app, using Manage subscription to open the Stripe billing portal, with no cancellation fees. On cancellation the account returns to the free access level and the inactivity timer above applies again — export what you need via each tool's export function.

Source: Privacy Policy §10 "Your Rights" and§9 "Data Retention";Subscription Terms §4 "Cancellation" and §9 "Your Content and Data".

Service Availability

Uptime & Support Commitments

We do not offer a formal Service Level Agreement (SLA) or uptime guarantee. If your organisation requires guaranteed uptime or dedicated support, contact us to discuss a bespoke enterprise arrangement.

Source: Subscription Terms, §7 "Service Availability".

Contact

Questions or a Security Concern?

Our Data Processing Agreement — the UK GDPR Article 28 terms on which we process personal data on a customer's behalf — is published for review. It is adraft awaiting our solicitor's sign-off: it is not yet in force and forms no part of any current agreement. The sub-processor list on this page is the one its Annex C records.

A due-diligence pack for procurement and legal teams — including our consulting practice's data-handling and privilege architecture note and retention and secure deletion policy — is available on request. For questions about this page, our data handling, or to report a security or data protection concern, email[email protected] or use our contact page. If you're not satisfied with our response, you have the right to lodge a complaint with theInformation Commissioner's Office (ICO).

Source: Privacy Policy, §13 "Contact Us".