Skip to content

Privacy Policy

How we collect, use and protect your data.

Last updated: August 2026

1. Introduction

AllocBoard ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our staff allocation management platform.

AllocBoard is operated by AllocBoard Ltd, based in the United Kingdom. Our role depends on whose data is involved. For the account data of the people who sign up, and for our own billing and support records, we are the data controller. For the data an organisation puts into its own workspace, including staff records, allocations and expenses, that organisation is the controller and we act as its data processor, on its instructions. Our DPA sets those terms out in full, and the Expense estimates section at the end of this policy explains the same split in plain terms for staff who were asked for estimates but have no account.

We comply with the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR) where applicable.

2. Information We Collect

Account Information

When you create an account, we collect your email address, full name, and optionally your profile picture. Account authentication is handled by our trusted partner, Clerk.

Staff Records

Administrators enter and manage staff member names, staff type (research or admin), allocation data (person-month values per project), and expense records including amounts, dates, and descriptions. Staff members recorded in the system do not have login credentials; their information is managed entirely by administrators.

Project Data

We store information about your projects including names, descriptions, start and end dates, work package details, budgets, allocation history, reporting periods, and expense types (salary, travel, operating costs).

Payment Information

Payment processing is handled entirely by Stripe. We store your subscription status and plan type, but we never store credit card numbers, bank details, or other sensitive payment information.

3. How We Use Your Information

  • Provide and maintain our service
  • Process your subscription and payments
  • Send important service updates and notifications
  • Respond to your enquiries and support requests
  • Improve our platform and develop new features
  • Ensure the security of our service

5. Data Sharing and Third Parties

We share your data with trusted service providers who help us operate our platform. We do not sell your personal data to third parties.

ServicePurposeData SharedLocation
ClerkAuthenticationEmail, name, profile pictureUnited States
StripePayment processingEmail, payment detailsUnited States
NeonDatabase hostingAll application dataLondon, UK
Fly.ioApplication server hostingAll application dataLondon, UK
ResendTransactional emailRecipient name and email address, and the content of the message sentUnited States
CloudflareWebsite hosting, CDN and reverse proxyIP address, request metadataGlobal (edge network)

For organisations requiring a signed Data Processing Agreement, please see our DPA.

6. Data Retention

We retain your account data for as long as your account is active. When a staff record is deleted, it is immediately removed from the application and its personal data is permanently anonymised within 30 days. Database backups are retained for up to 7 days for disaster recovery. Audit logs are retained for the period set by your plan tier, which is the life of the account on a paid plan and 1 year on the free trial, or for 90 days where no plan is in place, and are permanently deleted 90 days after that period ends. Payment and billing records are retained for 6 years after the end of the financial year in which the transaction took place, as required by HMRC.

7. Data Security

We implement robust technical and organisational measures to protect your personal data, including:

AES-256-GCM field-level encryption for sensitive data (names, emails, salaries) with per-tenant encryption keys

Row-Level Security (RLS) on all tenant data tables ensuring strict database-level isolation

Blind indexes (HMAC-based) for searching encrypted data without decryption

Removal from the application on deletion, with permanent anonymisation of personal data within 30 days

Core application data hosted in the UK (London) with TLS encryption in transit

Secure authentication via Clerk with session management

For full details, see our Security page at /security.

8. Your Rights

Under UK and EU GDPR, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your personal data
  • Restriction: Restrict processing of your personal data
  • Portability: Receive your data in a portable format
  • Objection: Object to processing based on legitimate interests

These rights apply to the personal data we hold as the controller, which is your account information and our own billing and support records. To exercise them, contact us at [email protected].

For the records your organisation keeps in its workspace, including staff details, allocations and expenses, that organisation is the controller and not us. Exercise these rights with them, normally through your project administrator. If you contact us instead we will pass your request on, because we are not permitted to act on their data ourselves.

9. Cookies

We use a minimal number of essential cookies for authentication and payment processing. We do not use marketing or advertising cookies. For full details, see our Cookie Policy at /cookies.

10. International Data Transfers

Some of our sub-processors, specifically Clerk (authentication), Stripe (payments), Resend (transactional email) and Cloudflare (CDN and reverse proxy), are based in the United States. Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including the UK International Data Transfer Agreement (IDTA) and EU Standard Contractual Clauses (SCCs) as applicable. The database (Neon) and the application servers (Fly.io) are both hosted in London, so no international transfer applies to core application data.

11. Children's Privacy

Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: [email protected]

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.

Expense estimates

If you received an email asking you to submit upcoming expense estimates, this section explains how your information is handled. It applies to you even though you do not have an AllocBoard account.

Who is responsible for your information

The organisation that asked you for estimates, normally your employer or the institution running your project, decides why and how your information is used. Under UK GDPR they are the data controller, and they are who you should contact about your data.

AllocBoard provides the software they use to collect it. We act only on their instructions, as their data processor. We do not decide what is collected, who reviews it, or how long it is kept, and we do not use it for our own purposes.

What is collected, and why

When you open your personal link you are asked for expected future costs: which project the cost belongs to, the type of expense, a date or date range, an amount, and an optional description. You may add a breakdown of an expense into separate lines.

This is used for project budgeting and financial planning by the organisation running your projects. Estimates are forecasts of intended spending, not claims for reimbursement.

Your name and work email address are already held by that organisation. They are used here to address the request to you and to send your personal link.

Who sees it

Your estimates are visible to the administrators and managers of the projects you selected, within your own organisation. A reviewer may approve or reject each item, or send it back with a comment asking for more detail.

Your estimates are not shared with other organisations using AllocBoard, and we do not sell or share them with third parties. The sub-processors listed in section 5 above, which are the hosting, database and email providers that run the service, process the data only to deliver it, under contract.

How long it is kept

Your organisation sets the retention period, between 3 and 60 months. The exact figure for your organisation is stated in the email you received.

Estimates that a reviewer approves may become part of the organisation's project financial records, which their own record-keeping rules govern.

Whether you have to use the link

You do not. The link is offered for convenience. You can give your estimates to your project administrator directly instead, by replying to the email or contacting them another way.

Your personal link

The link in your email is personal to you. It opens your own estimates and nothing else: it does not show other people's expenses, salaries or project budgets.

Please do not forward it. Anyone holding the link can see and change your estimates until it expires.

The link expires after a period set by your organisation. It may be replaced during the process. If a reviewer asks you for more information, or if you request a new one, the previous link stops working and the newest email carries the current one.

Your rights over this information

Under UK GDPR you may ask to see the information held about you, have it corrected, have it deleted, object to how it is used, or receive a copy in a portable form. You can also withdraw agreement where your organisation relies on it.

Because your organisation is the controller, exercise these rights with them. Contact your project administrator, or the reply-to address on the email you received. They may have their own privacy notice covering staff data more broadly.

If you contact AllocBoard directly we will pass your request to the relevant organisation, as we are not permitted to act on their data ourselves.

You may also complain to the Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority.

Automated decisions

There are none. Every estimate is reviewed by a person at your organisation.

Back to contents