Legal · Privacy

Privacy Policy

How Peoplethread collects, uses, and protects personal data — and the rights available to you under UK GDPR and the Data Protection Act 2018.

Version 1.0  ·  Effective date: 1 May 2026  ·  Last reviewed: June 2026

Contents

01

Who We Are

Peoplethread Technologies Limited ("Peoplethread", "we", "us", "our") operates the Peoplethread HR platform, accessible at peoplethread.app and associated subdomains.

Peoplethread is a Software-as-a-Service (SaaS) HR platform that enables organisations to record, manage, and analyse employee notes, follow-ups, and HR conversations. The platform also provides optional AI-powered features including sentiment analysis, automated summaries, and HR Insights dashboards.

For questions about this policy or how we handle your data, please contact us at [email protected].

02

Scope of This Policy

This Privacy Policy covers personal data processed in connection with:

It applies to all data subjects whose personal data Peoplethread processes, whether as a data controller or as a data processor acting on behalf of a client organisation.

Note for employees of Peoplethread client organisations: Your employer (the client organisation) is the data controller for personal data held about you in Peoplethread. This policy explains how Peoplethread processes that data as a data processor. For questions about what data your employer holds or to exercise your rights, please contact your employer's HR or data protection team in the first instance.

03

Controller & Processor Roles

Under UK GDPR, it is important to distinguish between the roles of data controller and data processor, as each carries distinct responsibilities.

Where Peoplethread is the Data Processor

When client organisations use the Peoplethread platform to store and manage employee records, notes, follow-ups, and related HR data, the client organisation is the data controller and Peoplethread acts as a data processor. We process that data only on the client's documented instructions, as set out in our Data Processing Agreement (DPA).

The client organisation is responsible for:

Where Peoplethread is the Data Controller

Peoplethread acts as a data controller in respect of personal data it collects independently, including:

04

Personal Data We Process

Data processed on behalf of client organisations (processor role)

The categories of personal data that client organisations may enter into the Peoplethread platform include:

Category Examples
Employee identifiers Full name, work email address, employee ID
Employment information Job title, team, management level, employment type, start date, office location, corporate title, peer group
HR notes content Free-text notes recording conversations, observations, and events relating to performance, conduct, attendance, development, check-ins, recognition, onboarding, and exit. Notes may contain personal information about employees as provided by the note author.
Follow-up records Descriptions of outstanding actions, due dates, completion status
User accounts Name, work email, hashed password, role, access profile settings for authorised platform users (managers, HR personnel, administrators)
Custom fields Additional employee data fields configured by the client organisation
Demographic data (special category) Gender identity, ethnicity, disability status, veteran status, and any other demographic types configured by the client organisation. See Section 7.
Audit records Records of administrative actions, data exports, and erasure operations, including the identity of the acting user

Data we collect as data controller

When individuals interact with Peoplethread directly — for example, by signing up for a trial, contacting our sales team, or visiting our website — we may collect:

05

Lawful Basis for Processing

As data processor

When processing personal data on behalf of client organisations, Peoplethread processes data only in accordance with the client's instructions as set out in the Data Processing Agreement. The lawful basis for processing is determined by the client organisation as data controller. The platform is designed to support the following lawful bases:

As data controller

For data we collect in our own right, we rely on the following lawful bases:

Processing activity Lawful basis
Providing the platform and managing customer accounts Article 6(1)(b) — contract performance
Billing and financial administration Article 6(1)(b) — contract performance; Article 6(1)(c) — legal obligation
Security, fraud prevention, and audit logging Article 6(1)(f) — legitimate interests (protecting the platform and our customers)
Product improvement and analytics Article 6(1)(f) — legitimate interests (developing and improving our services)
Marketing communications to existing customers Article 6(1)(f) — legitimate interests; opt-out provided in every communication
Marketing communications to prospects Article 6(1)(a) — consent, where required
Legal compliance and regulatory obligations Article 6(1)(c) — legal obligation

06

How We Use Personal Data

Service delivery

We use personal data to operate and provide the Peoplethread platform, including: authenticating users, displaying employee records and notes to authorised personnel, delivering notifications, generating exports and DSAR reports, and administering data retention and erasure workflows on the client's behalf.

AI-powered features

Where a client organisation has enabled AI features (sentiment analysis, note summaries, HR Insights, employee timelines), we transmit relevant note content to our AI sub-processor (Anthropic) to generate AI outputs. See Section 8 for full details.

Security and platform integrity

We process personal data to protect the platform against unauthorised access, detect and prevent abuse, maintain audit logs, and investigate security incidents.

Support and communications

We may use contact information provided by authorised users to deliver support, respond to queries, and send service communications (such as notices of maintenance, updates, or changes to these terms).

Platform improvement

We may analyse aggregated or anonymised usage data to improve platform features and user experience. We do not use the content of HR notes or employee records for product development purposes.

Legal and compliance

We may process and retain personal data as required by applicable law, including employment law, financial regulations, and orders of courts or regulatory authorities.

07

Special Category Data

Certain categories of personal data are afforded additional protection under Article 9 UK GDPR because of their particular sensitivity. Peoplethread's platform may be used by client organisations to process the following special category data:

Demographic data

Gender identity, ethnicity, disability status, veteran status, and other characteristics configured by the client. Stored in an isolated database table, separate from the general employee record, and never included in standard API responses or exports.

Health information in notes

Notes may contain references to health conditions, mental health disclosures, or family circumstances if authored by HR or management staff. The platform provides an HR Only visibility tier specifically to restrict access to such sensitive content.

The following technical and organisational measures apply to all special category data processed through the platform:

Guidance for client organisations: Before collecting special category demographic data through the platform, ensure you have documented a valid condition under Article 9(2) UK GDPR — typically explicit consent under Article 9(2)(a) or a Schedule 1 condition under the Data Protection Act 2018. Update your employee privacy notice accordingly. We provide in-app template wording to assist with this.

08

AI-Powered Features

Peoplethread offers optional AI-powered features that use large language model technology to generate insights from HR note data. All AI features are an optional, separately enabled add-on. They are off by default and must be explicitly enabled by a client organisation.

Features and data involved

The features and data sent to AI is detailed in our help guides, which are accessible in the Help & Support section.

AI sub-processors

AI processing of HR note content is performed via the Anthropic Claude API. Anthropic processes note content solely to generate AI outputs and does not use it to train its models. Under Anthropic's standard commercial terms and Data Processing Addendum, input and output data may be retained by Anthropic for up to 30 days for trust-and-safety purposes and is then deleted.

Separately, the in-app help assistant ("PThelp") is powered by Microsoft Azure OpenAI Service. PThelp answers product questions from Peoplethread's own help guides; it does not have access to HR records. The question you type is sent to Azure OpenAI to generate the answer — known employee names are automatically removed from the question before it is sent, and the question text is not retained in Peoplethread's audit records. Please do not enter employee or case details into PThelp.

No employee identifiers (names, email addresses, employee IDs) or demographic data are included in AI prompts, with two qualifications: (a) note body text is sent as written, so any names a note author mentions within a note's body will be included in the data sent to Anthropic; and (b) the performance-review drafting feature includes the employee's first name (and only their first name) so the draft reads naturally — surnames, email addresses, employee numbers, and demographic data are never sent.

AI transparency and safeguards

09

Sub-processors & Third Parties

Peoplethread uses a small number of carefully selected sub-processors to deliver its services. We enter into Data Processing Agreements with all sub-processors and require them to meet the same standards of data protection that we apply ourselves.

Sub-processor Purpose Data location
Microsoft Azure Cloud infrastructure, hosting, database, and storage. All application services, the PostgreSQL database, backups, and network infrastructure run on Azure. United Kingdom
Anthropic (Claude API) AI processing for optional AI features (sentiment analysis, summaries, HR Insights). Note content is transmitted only when AI features are enabled by the client organisation. Processed outside the UK; retained by Anthropic for up to 30 days for trust-and-safety purposes, then deleted, and not used to train Anthropic's models. See Section 10 for transfer details.
Microsoft Azure OpenAI Service AI processing for the optional in-app help assistant (PThelp). Processes the help question typed by the user (with known employee names automatically removed) together with Peoplethread's own help-guide content; has no access to HR records. Processed within Microsoft's Azure OpenAI service under Microsoft's data-processing terms; not used to train models. Prompts may be processed outside the UK under Microsoft's global capacity arrangements.
Cloudflare Content delivery, DNS, and bot / DDoS protection in front of the Peoplethread application. Processes network request metadata (including IP addresses) to route and filter traffic; does not store customer records. Global edge network; UK requests are served from UK/EU edge locations. Transfers under appropriate UK GDPR safeguards.
Resend Transactional email delivery (password resets, security notifications, and account communications). Processes recipient name, email address, and email content. Not used for marketing. European Union (eu-west-1); operated by a US-headquartered provider under appropriate UK GDPR transfer safeguards.

We do not sell or rent personal data to third parties. We do not share personal data with any third party for advertising, profiling, or marketing purposes.

We may disclose personal data to law enforcement, regulatory bodies, or courts where we are legally required to do so, or where necessary to protect our legal rights or the safety of individuals.

We will notify client organisations of any changes to our sub-processor list in advance, in accordance with our Data Processing Agreement, so they have the opportunity to object.

10

Data Transfers

UK-resident database

Your core records — employee records, notes, follow-ups, audit logs, and user accounts — are stored in our United Kingdom database. Azure United Kingdom is the sole deployment region for our application services and the PostgreSQL database, and we do not replicate or back up that database to any region outside the UK. Where limited personal data is processed outside the UK by our sub-processors (see Section 9), those transfers are subject to the safeguards described below.

AI processing via Anthropic and Azure OpenAI

When AI features are enabled, note content is transmitted to Anthropic's API infrastructure for processing. Anthropic may process this data outside the United Kingdom. Anthropic's international data transfers are conducted under appropriate legal mechanisms as set out in their Data Processing Addendum. Anthropic retains input and output data for up to 30 days for trust-and-safety purposes and then deletes it; it is not used to train Anthropic's models.

The in-app help assistant (PThelp) is processed by Microsoft Azure OpenAI Service. PThelp handles product help questions and help-guide content only — it has no access to HR records — and prompts may be processed outside the UK under Microsoft's global capacity arrangements.

Client organisations that require HR note content to remain within the United Kingdom may disable AI features entirely, in which case no note content is transmitted to Anthropic. Limited network and email metadata is still processed by Cloudflare and Resend as described in Section 9.

UK GDPR transfer safeguards

Any transfers of personal data outside the UK are conducted only where appropriate safeguards are in place under Chapter V UK GDPR, such as the UK International Data Transfer Agreement (IDTA) or an adequacy decision by the UK Secretary of State.

11

Data Retention & Erasure

Retention of client data (processor role)

Peoplethread retains employee data held within the platform in accordance with the client organisation's configured retention policy. The platform default is 7 years after an employee profile is deactivated, aligning with UK HMRC record-keeping requirements for employment records. Client organisations (Super Admins) can configure a different threshold — from 1 to 99 years after deactivation — within their platform settings.

Upon expiry of the applicable retention period, data is permanently deleted. The platform has multiple deletion and erasure options. The full details can be found in our Help and Support section.

Every erasure operation is atomic (either fully completes or fully rolls back), password-protected, and permanently recorded in the platform's append-only audit log.

Retention holds

Any employee record may be placed on a retention hold by an authorised administrator. Held records are excluded from all erasure modes — including auto-erasure — until the hold is explicitly lifted. Retention holds are used for situations such as ongoing Employment Tribunal proceedings, HMRC investigations, or other legal or regulatory requirements requiring data preservation.

Retention of our own data (controller role)

For personal data we hold as data controller — including customer account information, billing records, and support communications — we retain data for as long as necessary for the purpose for which it was collected and as required by law. In general:

Upon termination of a client's subscription, we will delete or return all client data in accordance with the terms of the Data Processing Agreement.

12

Your Rights

Under UK GDPR and the Data Protection Act 2018, individuals have the following rights in relation to their personal data. These rights apply where Peoplethread acts as data controller. Where Peoplethread acts as data processor, requests should in the first instance be directed to the client organisation that is the data controller.

Right What it means
Right of access (DSAR) You may request a copy of all personal data held about you and information about how it is used.
Right to rectification You may ask us to correct inaccurate data or complete incomplete data.
Right to erasure In certain circumstances you may ask us to delete your personal data.
Right to restriction In certain circumstances you may ask us to restrict processing of your data.
Right to data portability You may request a copy of data you provided to us in a structured, machine-readable format.
Right to object You may object to processing based on legitimate interests or for direct marketing purposes.
Rights related to automated decision-making You have the right not to be subject to solely automated decisions that produce significant legal effects.
Right to withdraw consent Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

We will respond to all rights requests within one calendar month of receipt. If a request is complex or we receive a large number of requests, we may extend this period by a further two months, in which case we will notify you within the first month.

We will not charge a fee for handling rights requests unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

13

Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. Key security controls include:

Peoplethread's security controls are designed in alignment with the ISO/IEC 27001 information-security framework, and the platform is hosted on Microsoft Azure infrastructure that is itself ISO/IEC 27001 certified. A comprehensive description of Peoplethread's security architecture is available in our Enterprise Security Overview, available on request.

In the event of a personal data breach affecting client HR data (which we process on behalf of client organisations), we will notify the affected client organisation without undue delay after becoming aware of the breach, providing the information the client needs to meet its own obligations as data controller — including any notification it must make to the supervisory authority within 72 hours. For personal data that Peoplethread holds as a data controller in its own right, we will notify the supervisory authority within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, and affected data subjects without undue delay where the risk is high.

14

Cookies & Tracking

Peoplethread's web application uses a small number of cookies that are strictly necessary for the service to function. We do not use tracking cookies, advertising cookies, or third-party analytics cookies without your consent.

Cookie Purpose Lifetime
Refresh token cookie Stores the digitally signed session refresh token to maintain your login. Set as httpOnly, Secure, and SameSite=Strict to prevent cross-site access. 1 hour (rotated and extended on each use while you remain active)

If you visit our marketing website at peoplethread.com, we may use analytics tools to understand how visitors interact with the site. Where consent is required for such cookies, we will ask for it via a cookie consent mechanism.

15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. When we make changes, we will update the "Last reviewed" date at the top of this page.

Where changes are material — for example, where we introduce a new purpose for processing or a new category of data — we will notify affected users and client organisations by email or via a notice within the platform before the changes take effect, giving reasonable notice to raise any objections.

We encourage you to review this policy periodically. Your continued use of the platform after changes take effect constitutes acceptance of the updated policy, subject to any rights you have to object to specific processing activities.

16

Contact & Complaints

Data protection enquiries

For any questions, concerns, or rights requests relating to personal data processed by Peoplethread, please contact our data protection team:

Email: [email protected]
Post: Data Protection, Peoplethread Technologies Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Response time: We aim to acknowledge all enquiries within 5 working days and resolve them within one calendar month.

For employees of Peoplethread client organisations

If you are an employee of an organisation that uses Peoplethread and you wish to exercise your data subject rights or have concerns about how your data is being used, please contact your employer's HR or data protection team in the first instance. Your employer is the data controller for your data held in Peoplethread. Peoplethread will cooperate with your employer in responding to your request.

Right to complain to the supervisory authority

You have the right to lodge a complaint with the UK data protection supervisory authority, the Information Commissioner's Office (ICO), if you believe your personal data has been processed unlawfully or that your rights have not been respected.

Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113
Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would always appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first if possible.