Data Protection
How we protect your health data under UK GDPR Article 9.
Our lawful basis
We process special category health data under Article 9(2)(a) — explicit consent. You must actively opt in by checking the consent box before submitting any outcome or creating a stack. We never bundle this consent with other terms.
For standard personal data (email, display name), our lawful basis is Article 6(1)(b) — contract (providing the service you requested) and Article 6(1)(f) — legitimate interests (preventing abuse, maintaining service security).
Technical security measures
- Row-Level Security (RLS): Database-level policies ensure users can only read/write their own data. Even if an API bug exposed a query, RLS prevents cross-user data leakage.
- Aggregation threshold: We never display outcomes for a compound × condition pair with fewer than 3 data points. This prevents reverse-engineering individual identities from small samples.
- Encryption in transit: All traffic uses TLS 1.3.
- Encryption at rest: Database encrypted with AES-256.
- No third-party trackers on any page that displays or collects health data.
- Pseudonymous by default: Display names only. Real names are never required or displayed.
- Session-scoped consent: Article 9 consent is re-asked each session, not stored indefinitely.
Data minimisation
We collect the minimum data needed to provide the service:
- We DO collect: Display name, email (for login), compounds, conditions, outcomes, doses, duration, side effects
- We DON'T collect: Real name (optional), precise location, IP addresses (not stored), browsing history, advertising identifiers
Your rights
Request all data we hold about you
Correct inaccurate data
Delete your account and all data
Export your data in JSON
Stop specific processing
Revoke consent at any time
To exercise any right, email privacy@works-for-us.app. We respond within 30 days.
DPIA (Data Protection Impact Assessment)
Because we process special category health data at scale, a DPIA is required under UK GDPR Article 35. Our DPIA documents the processing, assesses risks, and records mitigations. It is reviewed annually or whenever processing changes materially.
Status: DPIA to be completed before public launch. Current draft available on request.
Data retention
| Data type | Retention period |
|---|---|
| Individual outcomes + stack data | Until account deletion (max 30 days after request) |
| Account (email + display name) | Until account deletion |
| Aggregated, de-identified data | Permanent (can no longer be linked to you) |
| Consent logs | 6 years (Article 7(1) evidence) |
International transfers
Our infrastructure (Vercel + Supabase) may process data in the US. We rely on the UK-US Data Bridge (UK GDPR Art 46) for lawful transfers. All data is encrypted in transit and at rest regardless of location.