Legal and compliance
Privacy Policy
What personal data this service holds, why, for how long, and who else sees it.
Who this applies to
This notice covers Infin8 Digital Limited and the Highways Transparency Reporter service. It is written for two audiences at once: the officer using the service, and the information governance team deciding whether their authority may.
There are two distinct roles, and the distinction matters because it decides who answers a subject access request.
- For account data we are the controller. The name, work email address and job title of the people who sign in are ours to hold and ours to answer for.
- For report content we are the processor. Everything an authority enters, uploads or generates in a transparency report belongs to that authority. We hold it on their instructions and do nothing else with it. The terms of that arrangement are the Data Processing Agreement.
What is held
Account data
- Name, work email address and job title, as entered.
- The organisation an account belongs to and its role in it.
- Sign-in times, and a truncated IP address against security-relevant events. Truncated because the last octet answers no question this service needs to ask.
Report content
Answers to the Department for Transport's transparency report questions, the documents an authority uploads as supporting evidence, and the text extracted from them. This is authority information — spend figures, road condition statistics, maintenance policy — not personal data, with one exception: the sign-off block records the name and job title of the head of service and the section 151 officer, because the Department's own template requires it.
What is not held
- No passwords. Sign-in is a one-time code to a work address, so there is no password on this service to steal or reuse.
- No payment card details, ever. Publication licences are bought by purchase order and invoice; no card is taken through this service.
- No analytics, no advertising identifiers, no tracking pixels, no third-party scripts, no external fonts. See the Cookie Policy.
- No special category data is asked for, and none should be entered.
Why, and on what legal basis
| Purpose | Lawful basis |
|---|---|
| Signing you in and keeping the session secure | Contract — you cannot use the service without it |
| Attributing changes to whoever made them | Legitimate interests — an authority has to be able to evidence its own report to the Department |
| Keeping a security audit log | Legitimate interests — detecting and investigating misuse |
| Recording publication licence orders and raising invoices | Contract, and legal obligation for the accounting records |
| Fingerprinting exported documents (below) | Legitimate interests — protecting copyright in the generated work |
Document fingerprinting
This is disclosed rather than buried, because it identifies a person and you are entitled to know.
Every report exported from this service carries an identifying code. It is written into the document's properties, and also as characters that are invisible on the page but survive text being copied out of the document. The code is a one-way cryptographic value: it cannot be decoded, and by itself it says nothing about anybody. What it does is let us look up, in our own records, which report it came from, which account exported it and at what moment.
It exists for one purpose: to establish where a copy came from if a report licensed for internal evaluation only is published or distributed. It is not used to monitor how anyone works, and it never leaves this service unless a document does.
The invisible characters change nothing a reader sees. They sit only at the end of a paragraph, never inside a word, so screen readers read the text exactly as written and searching still finds every word.
How long it is kept
| What | Kept for |
|---|---|
| Sign-in codes | Minutes. Deleted once used or expired. |
| Sessions | Until sign-out or expiry, then purged automatically. |
| Invitations | Until accepted or expired, then purged. |
| Email delivery log | Purged on the retention schedule below. |
| Usage events | Purged on the schedule an administrator sets, 400 days by default. |
| Reports and uploaded documents | Until the authority deletes them. Deleting a report deletes its answers, its documents and its trace records with it. |
| Account records | While the account exists. |
| Security audit log | Not purged. It is append-only by design — a log that can be trimmed is not evidence of anything. It holds the actor, the action, a truncated IP address and a timestamp. |
| Licence and invoice records | Six years, as the accounting rules require. |
Where it is processed
In United Kingdom, on infrastructure provided by Akamai Technologies (Linode). There is no international transfer of report content or account data outside the UK and the EEA.
Who else sees it
- Akamai Technologies (Linode) — hosting. Holds the data at rest in the region named above.
- Google Workspace — transactional email only: sign-in codes, invitations, licence confirmations. It receives an email address and the text of that message, nothing else.
- An AI provider — only where an administrator has switched the assistant on, and only then. When it is on, the text of documents an authority has chosen to include is sent to the configured endpoint so that answers can be drafted and figures extracted. Which provider that is, is the administrator's choice and is recorded in the configuration. When it is off, nothing is sent anywhere.
- GOV.UK — read from, never written to. The service fetches published statistical tables. No personal data is sent in doing so.
Nobody else. Data is not sold, not shared for marketing, and not used to train anyone's model by us.
Your rights
You may ask for a copy of the personal data held about you, ask for it to be corrected, ask for it to be deleted, object to processing based on legitimate interests, or ask for it in a portable form. Requests are answered within one month.
For report content, ask your own authority first: they are the controller and we act on their instructions.
Our data protection contact is not published on this installation.
If you are not satisfied with our response you may complain to the Information Commissioner's Office, the UK supervisory authority.
If something goes wrong
A personal data breach affecting an authority's data is reported to that authority without undue delay and in any event within 24 hours of us becoming aware of it, with what we know at the time and what we are doing about it. See the Data Processing Agreement for the full undertaking.
Changes
Material changes are announced in the service before they take effect. The date at the top of this page is when it last changed.
Contact
Questions about this document go to contact@infin8.digital.
A registered address has not been published on this installation.