Privacy Policy
How we collect, use and protect your data.
Last updated: August 2026
1. Introduction
AllocBoard ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our staff allocation management platform.
AllocBoard is operated by AllocBoard Ltd, based in the United Kingdom. Our role depends on whose data is involved. For the account data of the people who sign up, and for our own billing and support records, we are the data controller. For the data an organisation puts into its own workspace, including staff records, allocations and expenses, that organisation is the controller and we act as its data processor, on its instructions. Our DPA sets those terms out in full, and the Expense estimates section at the end of this policy explains the same split in plain terms for staff who were asked for estimates but have no account.
We comply with the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR) where applicable.
2. Information We Collect
Account Information
When you create an account, we collect your email address, full name, and optionally your profile picture. Account authentication is handled by our trusted partner, Clerk.
Staff Records
Administrators enter and manage staff member names, staff type (research or admin), allocation data (person-month values per project), and expense records including amounts, dates, and descriptions. Staff members recorded in the system do not have login credentials; their information is managed entirely by administrators.
Project Data
We store information about your projects including names, descriptions, start and end dates, work package details, budgets, allocation history, reporting periods, and expense types (salary, travel, operating costs).
Payment Information
Payment processing is handled entirely by Stripe. We store your subscription status and plan type, but we never store credit card numbers, bank details, or other sensitive payment information.
3. How We Use Your Information
- Provide and maintain our service
- Process your subscription and payments
- Send important service updates and notifications
- Respond to your enquiries and support requests
- Improve our platform and develop new features
- Ensure the security of our service
4. Legal Basis for Processing
- Contract: Processing necessary to provide our service to you
- Legitimate interests: Improving our service and ensuring security
- Legal obligation: Compliance with applicable laws
- Consent: Where you have given explicit consent
5. Data Sharing and Third Parties
We share your data with trusted service providers who help us operate our platform. We do not sell your personal data to third parties.
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Clerk | Authentication | Email, name, profile picture | United States |
| Stripe | Payment processing | Email, payment details | United States |
| Neon | Database hosting | All application data | London, UK |
| Fly.io | Application server hosting | All application data | London, UK |
| Resend | Transactional email | Recipient name and email address, and the content of the message sent | United States |
| Cloudflare | Website hosting, CDN and reverse proxy | IP address, request metadata | Global (edge network) |
For organisations requiring a signed Data Processing Agreement, please see our DPA.
6. Data Retention
We retain your account data for as long as your account is active. When a staff record is deleted, it is immediately removed from the application and its personal data is permanently anonymised within 30 days. Database backups are retained for up to 7 days for disaster recovery. Audit logs are retained for the period set by your plan tier, which is the life of the account on a paid plan and 1 year on the free trial, or for 90 days where no plan is in place, and are permanently deleted 90 days after that period ends. Payment and billing records are retained for 6 years after the end of the financial year in which the transaction took place, as required by HMRC.
7. Data Security
We implement robust technical and organisational measures to protect your personal data, including:
• AES-256-GCM field-level encryption for sensitive data (names, emails, salaries) with per-tenant encryption keys
• Row-Level Security (RLS) on all tenant data tables ensuring strict database-level isolation
• Blind indexes (HMAC-based) for searching encrypted data without decryption
• Removal from the application on deletion, with permanent anonymisation of personal data within 30 days
• Core application data hosted in the UK (London) with TLS encryption in transit
• Secure authentication via Clerk with session management
For full details, see our Security page at /security.
8. Your Rights
Under UK and EU GDPR, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Restriction: Restrict processing of your personal data
- Portability: Receive your data in a portable format
- Objection: Object to processing based on legitimate interests
These rights apply to the personal data we hold as the controller, which is your account information and our own billing and support records. To exercise them, contact us at [email protected].
For the records your organisation keeps in its workspace, including staff details, allocations and expenses, that organisation is the controller and not us. Exercise these rights with them, normally through your project administrator. If you contact us instead we will pass your request on, because we are not permitted to act on their data ourselves.
10. International Data Transfers
Some of our sub-processors, specifically Clerk (authentication), Stripe (payments), Resend (transactional email) and Cloudflare (CDN and reverse proxy), are based in the United States. Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including the UK International Data Transfer Agreement (IDTA) and EU Standard Contractual Clauses (SCCs) as applicable. The database (Neon) and the application servers (Fly.io) are both hosted in London, so no international transfer applies to core application data.
11. Children's Privacy
Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: [email protected]
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.
Expense estimates
If you received an email asking you to submit upcoming expense estimates, this section explains how your information is handled. It applies to you even though you do not have an AllocBoard account.
Who is responsible for your information
The organisation that asked you for estimates, normally your employer or the institution running your project, decides why and how your information is used. Under UK GDPR they are the data controller, and they are who you should contact about your data.
AllocBoard provides the software they use to collect it. We act only on their instructions, as their data processor. We do not decide what is collected, who reviews it, or how long it is kept, and we do not use it for our own purposes.
What is collected, and why
When you open your personal link you are asked for expected future costs: which project the cost belongs to, the type of expense, a date or date range, an amount, and an optional description. You may add a breakdown of an expense into separate lines.
This is used for project budgeting and financial planning by the organisation running your projects. Estimates are forecasts of intended spending, not claims for reimbursement.
Your name and work email address are already held by that organisation. They are used here to address the request to you and to send your personal link.
Who sees it
Your estimates are visible to the administrators and managers of the projects you selected, within your own organisation. A reviewer may approve or reject each item, or send it back with a comment asking for more detail.
Your estimates are not shared with other organisations using AllocBoard, and we do not sell or share them with third parties. The sub-processors listed in section 5 above, which are the hosting, database and email providers that run the service, process the data only to deliver it, under contract.
How long it is kept
Your organisation sets the retention period, between 3 and 60 months. The exact figure for your organisation is stated in the email you received.
Estimates that a reviewer approves may become part of the organisation's project financial records, which their own record-keeping rules govern.
Whether you have to use the link
You do not. The link is offered for convenience. You can give your estimates to your project administrator directly instead, by replying to the email or contacting them another way.
Your personal link
The link in your email is personal to you. It opens your own estimates and nothing else: it does not show other people's expenses, salaries or project budgets.
Please do not forward it. Anyone holding the link can see and change your estimates until it expires.
The link expires after a period set by your organisation. It may be replaced during the process. If a reviewer asks you for more information, or if you request a new one, the previous link stops working and the newest email carries the current one.
Your rights over this information
Under UK GDPR you may ask to see the information held about you, have it corrected, have it deleted, object to how it is used, or receive a copy in a portable form. You can also withdraw agreement where your organisation relies on it.
Because your organisation is the controller, exercise these rights with them. Contact your project administrator, or the reply-to address on the email you received. They may have their own privacy notice covering staff data more broadly.
If you contact AllocBoard directly we will pass your request to the relevant organisation, as we are not permitted to act on their data ourselves.
You may also complain to the Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority.
Automated decisions
There are none. Every estimate is reviewed by a person at your organisation.