You're browsing as a guest. Log in or create an account to save your history, write journal entries, and earn milestones.
How we protect your data.
This page summarises how My Impact protects organisation and member data, from where it's stored, to who can see it, to how we'd handle an incident. If you need a full DPA or our response to a security questionnaire, just get in touch.
Last updated: 9 May 2026
Data handling & storage
Where is our data stored?
All personal data is currently hosted on US-based cloud infrastructure. Transfers from the UK are covered by appropriate safeguards under UK GDPR. We are planning a migration to UK/EEA-based hosting in a future release.
Is data encrypted in transit and at rest?
Yes. All connections use HTTPS/TLS, and stored data, including database contents and file attachments, is encrypted at rest using industry-standard ciphers.
What kinds of data does My Impact hold about our organisation and members?
We hold the minimum needed to run the service: account details (email, optional display name), the activities and contributions members log, optional journal entries and attachments, and your organisation's name, type and contact email.
For a full list, see our Privacy Policy.
Access control & authentication
How do members and admins sign in?
We use passwordless one-time magic links sent to your verified email, optionally combined with single sign-on through Google or Microsoft. We never store passwords.
Who on the My Impact team can access our data?
Access to production systems is restricted to a small number of named engineers on a least-privilege basis. Access is logged, reviewed periodically, and revoked promptly when no longer needed.
Are there role-based permissions inside an organisation account?
Yes. Organisation accounts distinguish between admins (who can manage settings, members and exports) and members (who can only see their own data). Admins choose who has elevated rights.
Tenant isolation & confidentiality
Is one organisation's data ever visible to another?
No. Every record is scoped to its owning organisation and member. Database queries enforce these scopes at the application layer, and admins of one organisation cannot see records belonging to another.
Can a member's individual records be seen by their organisation's admins?
Members control what they share. Aggregated, anonymised totals are visible to admins by default; identifiable individual records are only visible where the member has explicitly opted in (for example, by submitting an entry to a shared challenge).
Will My Impact use our data to benchmark against other customers?
We may publish anonymised, aggregated statistics about overall service usage. We do not name or identify customers in benchmarks without written permission.
Sub-processors & third parties
Who are your sub-processors?
We use a small set of named, trusted processors, each bound by a data processing agreement:
- Managed cloud hosting (USA): application hosting and managed PostgreSQL database.
- Resend: transactional email delivery (magic links, notifications).
- Stripe: payment processing for paid plans (we never see card details).
- OpenAI: powers the optional Sidekick AI assistant via enterprise endpoints.
- Sentry: anonymised error monitoring with sensitive values scrubbed before sending.
The full list with locations and safeguards is on our Privacy Policy.
Will you tell us before adding a new sub-processor?
Yes. We maintain a current list of sub-processors and notify organisation admins by email before adding new ones, giving you a reasonable window to object.
Do you sell or share data for marketing?
No. We do not sell personal data, and we do not share it with advertising networks or data brokers.
Backups, resilience & continuity
How often is data backed up?
The production database is backed up at least daily, with point-in-time recovery available for recent windows. Backups are encrypted and stored in the same region as the primary database.
What is the recovery objective if something goes wrong?
We target a recovery point objective (RPO) of under 24 hours and a recovery time objective (RTO) of under 24 hours for full service restoration. Most disruptions resolve far faster.
Do you have a business continuity plan?
Yes. We maintain a documented continuity plan covering hosting failure, key-personnel loss, and supplier outage, and we review it at least annually.
Incident response & breach notification
What happens if you discover a security incident?
We follow a documented incident-response runbook: contain, investigate, remediate, and learn. Affected systems are isolated immediately, the root cause is identified, and changes are made to prevent recurrence.
How quickly will you notify us of a personal data breach?
Where a breach is likely to affect your organisation or its members, we will notify the relevant admin contact without undue delay and in any event within 72 hours of becoming aware, in line with UK GDPR.
Do you run security testing?
Yes. We run automated dependency scanning and static analysis on every change, and review our security posture regularly. Penetration test summaries are available under NDA on request.
Compliance & legal
Are you UK GDPR compliant?
Yes. My Impact CIC is the data controller for personal data you and your members submit, and we operate in line with the UK GDPR and Data Protection Act 2018.
Will you sign a Data Processing Agreement (DPA)?
Yes. We have a standard DPA covering controller-to-processor obligations where applicable. Contact us at hello@myimpact.uk for a copy.
Can you complete a security questionnaire for our procurement team?
Yes. We're happy to complete reasonable due-diligence questionnaires (SIG-lite, supplier security reviews, etc.). Email us with the document and your timeline.
Data subject rights, retention & exit
How can a member exercise their data rights (access, correction, deletion)?
Members can download a complete export of their own data, and can permanently delete their account, directly from Settings. We respond to any other UK GDPR request within 30 days.
How long do you keep our data?
We keep personal data for as long as the related account is active. When an account is deleted, personal data is erased within 30 days, except where we are required to retain limited records for legal or accounting reasons.
What happens to our data if we leave My Impact?
You can export your organisation's data on request before closing the account. Once closed, all personal data is deleted in line with the retention policy above.
AI features (Sidekick)
Is anything someone types into Sidekick shared with the AI provider for training?
No. Sidekick uses enterprise endpoints with zero data retention agreements in place. Inputs and outputs are not used to train the underlying model, and the provider does not retain prompt content beyond what is needed to return a response.
Can we disable AI features entirely for our organisation?
Yes. Organisation admins can switch Sidekick off across the account, and individual members can choose not to use it. With AI features disabled, no prompts or context are ever sent to the AI provider.
Could AI output expose sensitive information?
Sidekick responses are generated from the prompt and the limited context the user explicitly chooses to include (such as their own recent activity totals). It cannot read other members' records, your private settings, or anything outside the user's own scope. We treat AI replies as best-effort guidance, not as authoritative or specialist advice.
Need more detail?
Ask us anything.
Need our DPA, a completed security questionnaire, or a deeper conversation with our team? We're happy to help, most requests get a response within a couple of working days.