Data Processing Terms
These terms form part of your agreement with us and apply whenever we process personal data on your behalf. They exist because UK GDPR Article 28 requires them in writing. "You" means the business using Good Food Hygiene; "we" means Elearnment Ltd (company number 17458288, registered in England and Wales), trading as Good Food Hygiene.
1. Roles
You are the controller of the personal data you put into the app about your staff and about anyone recorded in your logs. We are your processor. We are the controller only of your own account and billing information, which is covered by our Privacy Notice rather than by these terms.
2. Subject matter and duration
We process that data to provide the app for as long as your account is open, and for up to thirty days afterwards to allow for accidental closure.
3. Nature and purpose
Storing, organising, backing up, displaying, exporting and deleting records you create, and making them available to the devices you have authorised and to anyone you share an Inspector Portal link with.
4. Types of data and categories of person
Names, job roles, working hours and training records of your staff; staff telephone numbers and emergency contacts where you record them, which includes the name and number of a third party who is not your employee; names and free-text descriptions of anyone recorded in your incident and accident logs; staff sickness records — the person's name, the kind of illness, and the dates they went home, were clear to return and came back; photographs you upload. This may include data concerning health where you record an injury or an illness exclusion.
5. Our obligations
We will:
- process that data only on your documented instructions, which for normal use means your use of the app;
- make sure anyone with access to it is under a duty of confidence;
- keep it secure, using encryption in transit and at rest, row-level access controls that stop one business seeing another's records, and access limited to those who need it;
- not appoint a new sub-processor without telling you first and giving you a chance to object;
- help you respond to a request from one of your staff, and to a security incident, an impact assessment or a consultation with the ICO;
- tell you without undue delay if we become aware of a personal data breach affecting your data;
- on closure of your account, delete the data, unless we are required by law to keep it;
- make available what you need to show we are meeting these obligations, and allow an audit on reasonable notice.
We will not use your data to train any machine learning model, sell it, or use it for our own purposes.
6. Sub-processors
We currently use:
- Supabase Inc. — database, authentication, file storage and server functions, in the London region.
- Krystal Hosting Ltd — serving the application files, in the UK.
- Groq, Inc. (United States) — the Basil assistant and voice transcription, only when a user uses Basil.
- ElevenLabs, Inc. (United States) — Basil's spoken replies, only when a user uses Basil's voice.
- Expo (650 Industries, Inc.), United States — delivering check reminders, only if you turn them on.
- Google LLC and Apple Inc., United States — the notification services that put a reminder on a device.
- OpenMeteo GmbH, Switzerland — the weather forecast, only at the moment you tap it.
- Stripe Payments Europe Ltd — payment processing, when charging begins.
If we add or replace one, we will tell you at least thirty days before it starts processing your data.
7. Transfers outside the UK
Data at rest stays in the UK. The two Basil features send data to the United States as described in the Privacy Notice, under the UK Extension to the EU-US Data Privacy Framework or the International Data Transfer Addendum to the standard contractual clauses. If you do not want any transfer, do not use Basil; nothing else in the app transfers data abroad.
8. Your obligations
You are responsible for having a lawful basis for the records you keep, for telling your staff that you keep them, and for the accuracy of what you enter. You must not put more personal data into the app than you need — in particular, the free-text fields in the incident log should describe what happened, not a person's race, religion, sexual life or disability unless that is genuinely relevant to the incident.
You are responsible for who you give an Inspector Portal link to, and for switching it off when it is no longer needed.