Privacy Policy
Effective date: May 20, 2025
1. Who We Are
TeamTorch Ltd ("TeamTorch", "we", "our", "us")
Company No. 14453517
Penhurst House, 352 Battersea Park Road, London, SW11 3BY, United Kingdom
Email: privacy@teamtorch.io
We comply with the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the Data Protection Act 2018.
2. How This Policy Applies
Data-subject group | Where the policy applies | Controller / processor role |
---|---|---|
Website & marketing visitors | www.teamtorch.io, landing pages, cookie banner | Controller |
Platform users / client employees | TeamTorch SaaS application and mobile app | Processor |
Prospects & demo requesters | Sales calls, web forms, email outreach | Controller |
TeamTorch employees & job candidates | Recruitment portal, HRIS, payroll | Controller |
Event / webinar / survey participants | Registration pages, attendee apps, feedback forms | Controller |
Vendors & contractors | Procurement, onboarding, payment systems | Controller |
If we process your data on behalf of your employer, they remain the primary data controller; this policy explains how we handle that data as their processor.
3. What Personal Data We Collect
The exact data we collect depends on your relationship with us:
- Identification & contact – name, work email, phone, employer, department, job title.
- Employment & professional – skills, career history, performance indicators, assessments, goals.
- Usage & device – IP address, browser type, device ID, time zone, click-stream, pages visited.
- Event & marketing – registration details, badge scans, dietary or accessibility requirements.
- Financial & contractual – invoicing details, bank info (vendors), compensation (employees).
- Special-category / sensitive – only with consent or legal requirement (e.g., disability, union membership).
4. How We Collect Data
- Directly from you (forms, profile updates, surveys, job applications).
- From your employer (HRIS integrations, CSV uploads).
- Automatically via cookies, SDKs, server logs, analytics tools.
- From third parties (LinkedIn, event co-sponsors).
5. Why We Process Your Data & Legal Bases
Purpose | Legal basis |
---|---|
Provide and secure the TeamTorch platform | Contract (Art 6(1)(b)) |
Analyse skills gaps, retention risk, dashboards | Legitimate interests (Art 6(1)(f)) |
Deliver consulting reports | Contract |
Send product updates & marketing | Consent / Legitimate interests |
Recruit & manage employees | Contract / Legal obligation |
Comply with laws | Legal obligation |
Develop AI/ML models (aggregated only) | Legitimate interests |
Automated Decision-Making & AI:
Insights are algorithmically generated, but not acted upon without human review. You can request human review by emailing privacy@teamtorch.io.
6. How We Protect & De-identify Data
- TLS and AES-256 encryption
- RBAC & MFA for internal access
- Penetration tests and vulnerability scans
- Tokenization and de-identification for ML
7. Data Sharing
We do not sell your data. We may share it with:
- Trusted subprocessors (e.g. AWS UK)
- Professional advisers and insurers
- Event partners (if opted-in)
- Authorities, as legally required
- M&A parties (with notice)
8. International Transfers
Primary hosting is in the UK (London). If accessed or backed up outside the UK/EEA, we use SCCs and perform transfer impact assessments.
We are not currently certified under the Data Privacy Framework.
9. Data Retention
Data Set | Retention Period | Rationale |
---|---|---|
Platform/HR records | Contract term + 12 months | Audits, disputes |
Log files | 12 months | Security |
De-identified analytics | Indefinite | Not personal data |
Marketing prospects | Until opt-out / 24 months inactive | Relevance |
Recruitment data | 12 months | Equality, future roles |
Employee files | 6 years after exit | Legal compliance |
10. Cookies, Tracking & "Do Not Track"
We use essential, analytics (GA4), and functional cookies (reCAPTCHA, Crisp Chat). You can manage cookies via our banner or browser. We do not respond to DNT signals.
Opt-out link: Google Analytics Opt-Out
11. Children
We do not knowingly collect data from anyone under 16. Contact us to delete any such data.
12. Your Rights
- Access, correct, delete data
- Object or restrict processing
- Receive portable copy
- Withdraw consent at any time
- Request human review of automated decisions
- Lodge a complaint with the ICO: ico.org.uk
13. Security Incidents
We maintain an incident response plan and notify affected parties without undue delay.
14. Changes to This Policy
We'll post updates 30 days in advance on our site and in the app if materially changed.
15. Contact Us
Email: privacy@teamtorch.io
Mail: Data Protection Officer
TeamTorch Ltd
Penhurst House
352 Battersea Park Road
London SW11 3BY
United Kingdom