GDPR Policy

Effective Date: 12 June 2025

Inspired Cloud Solutions Ltd (trading as EthosHub, "we", "our", "us") is committed to protecting and respecting your privacy. This GDPR Policy explains how we collect, use, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

EthosHub is a digital platform that enables employees to report workplace incidents securely and anonymously. Our goal is to help organisations foster safe, respectful work environments.

We act as a Data Processor for our client organisations (the Data Controllers) in respect of employee report data, and as a Data Controller in our own right for data such as user accounts, billing information, and platform communications.

2. What Personal Data We Collect

Depending on how you interact with our service, we may collect:

  • Account information: name, email address, job title, organisation
  • Incident report details: free-text descriptions, categories, timestamps, file attachments
  • Communication data: messages exchanged with caseworkers
  • Usage data: device type, browser, operating system, timestamps
  • Anonymous session tokens: a hashed token only — the raw token is never stored, and no IP address is logged for anonymous reporters

3. Legal Basis for Processing

We process your data on the following legal bases under UK GDPR Article 6:

  • Contractual necessity — to provide the services you or your employer have requested
  • Legitimate interests — for improving service functionality, usability, and security
  • Legal obligation — where required by law, such as data retention or regulatory disclosures
  • Consent — for optional communications such as marketing emails, which you may withdraw at any time

Where incident reports contain Special Category Data (such as information about racial discrimination, harassment, or health matters), we process this under Article 9(2)(b) of UK GDPR (processing necessary for employment law obligations) and, where applicable, Article 9(2)(g) (substantial public interest).

4. How We Use Your Data

We use your personal data to:

  • Facilitate the secure reporting and resolution of incidents
  • Enable communication between reporters and caseworkers
  • Provide analytics to help organisations improve workplace safety
  • Monitor and improve platform performance and user experience
  • Maintain security and prevent misuse

We do not sell your personal data or use it for advertising.

5. Data Retention

We retain personal data only as long as necessary to fulfil the purposes for which it was collected. Case and incident data is retained in accordance with the subscribing organisation's retention settings and applicable employment law. Anonymous session tokens are stored in hashed form only and expire after 90 days by default. Payment records are retained as required by HMRC regulations.

6. Data Sharing and Transfers

We may share your data with:

  • Your employer or organisation (authorised caseworkers and administrators only)
  • Service providers (data processors) who help us deliver the platform, including AWS, Neon, Stripe, and Resend — all bound by strict data processing agreements
  • Legal authorities where required by law

Our primary infrastructure is hosted within the UK (AWS eu-west-2). Where data is transferred outside the UK, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses or UK adequacy decisions — in accordance with UK GDPR Chapter V.

7. Your Rights Under UK GDPR

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data in certain circumstances ("right to be forgotten")
  • Restrict or object to our processing
  • Port your data to another service in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent
  • Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113

To exercise any of these rights, contact us at: gdpr@ethoshub.io. We will respond within one month.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data at rest and in transit (TLS)
  • Role-based access controls — caseworkers can only access cases within their organisation
  • Hashed storage of passwords and anonymous session tokens (raw values are never stored)
  • No IP address logging for anonymous reporters

No method of internet transmission or electronic storage is completely secure. We will notify you and the relevant authorities of any breach as required by law.

9. Contact Us

If you have any questions or concerns about this policy or your data, please contact us at:

Inspired Cloud Solutions Ltd (trading as EthosHub)
Email: gdpr@ethoshub.io
Website: www.ethoshub.io

10. Updates to This Policy

We may update this policy from time to time. Any changes will be posted on this page with a revised "Effective Date". Material changes will be communicated by email or via the platform.

Who we are

EthosHub is a secure, anonymous workplace incident reporting platform designed to help organisations address and prevent bullying, harassment, discrimination and more.

Subscribe to our Newsletter

We deliver high quality blog posts written by professionals. No spam, just good content.

© 2026 EthosHub.io | All Rights Reserved.