Legal
Platform Privacy Policy
How PerkIQ collects, uses and protects your personal data.
1 Who We Are
PerkIQ Ltd (company number 17102662, VAT number GB 516 4012 29, registered in England and Wales) operates the PerkIQ platform at www.perkiq.co.uk. We are the data controller for personal data processed through the platform. This policy is published at www.perkiq.co.uk/platform-privacy.
Registered address: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF
Contact: info@perkiq.co.uk
ICO registration number: ZC108098
VAT number: GB 516 4012 29
2 Who This Policy Applies To
This policy applies to:
- Employer users who register for and use the platform
- Colleagues invited to join a company account
- Employees who complete an anonymous benefit survey via a shared link
- Employees who access their employer's benefits portal using a personal sign-in. For those employees the employer is the data controller and PerkIQ is the data processor; a dedicated employee privacy notice is provided in the portal at perkiq.co.uk/portal/privacy.
- Individuals who contact us through the website contact form
This policy does not cover third-party websites linked from our platform.
3 Data We Collect and Why
3.1 Account holders
When you register, we collect your first name, work email address, and password (stored as a one-way hash). During onboarding we ask for your job title, company name, industry, and the number of people your organisation employs. You may optionally upload a company logo. We also store your in-app notification preferences.
Your employee headcount is additionally used to determine the price of a paid subscription. We keep a log of each change to it, showing the previous and new figures, the account holder who made the change, and when. We use this to explain how your price was calculated and to identify a change of price band. It is deleted when your account is closed, as described in section 9.
We use this data to create and manage your account and to deliver the platform. The lawful basis is contractual necessity (UK GDPR Article 6(1)(b)). Providing this information is a condition of using the platform. Without it, we cannot create or operate your account.
3.2 Invited team members
When an account admin invites a colleague, we collect the invitee's email address and their assigned role. The invitation link expires after 7 days. The lawful basis is contractual necessity (Article 6(1)(b)).
If you have been invited to join a company account, your email address was provided to us by the admin who invited you, not by you directly. We will send you an invitation email explaining this. If you did not expect to receive an invitation or wish to be removed, contact us at info@perkiq.co.uk and we will delete your details.
3.3 Business data you enter
Using the platform you may enter details about your organisation's benefits, including provider names, costs, renewal dates, and utilisation data, as well as action tracker entries and diagnostic questionnaire responses. This is organisational business data, not personal data relating to individual employees.
3.4 Employee survey respondents
Employees complete benefit surveys via a public link without creating an account. No personally identifiable information is collected. We record survey responses (ratings and multiple choice selections), a submission timestamp, and a salted, irreversible cryptographic hash used only to prevent duplicate submissions. The hash is keyed with a secret salt, meaning that knowledge of a respondent's IP address alone is insufficient to re-derive the stored hash.
Survey results are only visible to the employer once a minimum of five responses have been received. We have designed the survey system to minimise re-identification risk to the lowest practicable level. We process these responses on the basis that no individual is identifiable from them, and treat them as anonymous data within the meaning of UK GDPR Article 4. On that basis, individual data subject rights of access, rectification, and erasure do not apply to survey responses. We will notify you if this position changes or if we have reason to believe a response is attributable to an identifiable individual.
3.5 Contact form
We collect your name, email address, optional company details, and message content to respond to your enquiry. We also log the IP address of the request for rate limiting and security purposes. The lawful basis is legitimate interest (Article 6(1)(f)). Our legitimate interest is in being able to respond to enquiries received through our website. Providing your name and email is not a statutory requirement, but without them we cannot respond to you.
3.6 Benefits portal users
This section describes the employee benefits portal, for which PerkIQ acts as data processor on the employer's behalf. Employees are given a dedicated privacy notice in the portal at perkiq.co.uk/portal/privacy, which describes what is collected, the lawful bases, and how to exercise their rights.
Where an employer enables the benefits portal, their employees sign in with a personal link to view the benefits available to them. For this processing the employer is the data controller and PerkIQ is the data processor, acting under a Data Processing Agreement. We process:
- Identity and access: the employee's work email and display name, provided by the employer, used to sign them in. Processed on the employer's lawful basis (their legitimate interest in administering staff benefits).
- Security records: sign-in times and security events, kept to detect unusual access.
- Usage analytics: which benefits are viewed, searched and saved, recorded against a temporary session identifier, not the employee's identity. Employers see only aggregated results, never an individual's activity, and the text typed into search is never recorded. We respect Do Not Track and Global Privacy Control signals. PerkIQ is the controller for this aggregated product-improvement analytics only.
- Saved benefits: benefits an employee stars to save to their own list, visible only to them.
- Notifications: if an employee turns on notifications, we store a notification subscription for their device so we can alert them to portal updates. Notifications are off by default and can be turned off at any time. Lawful basis: the employee's consent. When the portal is installed as an app, alerts are routed through the employee's device or browser maker's notification service (for example Apple, Google or Mozilla); the alert does not carry benefit details.
- Messages and feedback: questions an employee sends to their benefits contact include their name and email; the anonymous feedback form attaches no identity.
The portal does not process special category data, does not profile employees, and makes no automated decisions about them.
4 Automated Decision-Making
PerkIQ does not carry out automated decision-making or profiling that produces legal or similarly significant effects on any individual, as described in UK GDPR Article 22. Our Snapshot scoring engine produces a diagnostic score for your organisation based on the information you provide. This score is generated deterministically from your inputs and relates to your organisation as a whole, not to any individual. It has no legal or similarly significant effect on any person.
5 Special Category Data
PerkIQ is not designed to collect or process special category data as defined in UK GDPR Article 9, and does not ask for it anywhere in the platform.
Employee survey questions relate to benefits satisfaction and do not ask about health conditions, disability, or any other special category. The benefits information held in the platform describes the schemes an employer offers and their cost, not any individual's health, treatment or claims history. Benefits portal records show which benefits an employer makes available to an employee, not any medical or personal information about that employee.
Employer users are asked not to enter special category data into free text fields. If you believe special category data has been entered in error, contact us at info@perkiq.co.uk and we will remove it.
If we introduce a feature that would involve processing special category data, we will update this policy and identify an appropriate Article 9 condition before that feature is made available.
6 Who We Share Your Data With
We do not sell or share your personal data with third parties for marketing purposes. We use the following service providers to operate the platform:
| Provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, user authentication, and file storage | EU (Ireland) |
| Vercel Inc. | Application hosting. Serverless functions execute in Ireland (dub1); static content is served from a global edge network. | EU (Ireland) for function execution; US-incorporated provider |
| Google LLC | Social login (Google OAuth) and optional website analytics | US |
| Resend Inc. | Transactional emails (account confirmation, password reset, invitations) | US |
| Upstash Inc. | Request rate limiting. Upstash Inc. is US-incorporated; data is hosted on EU infrastructure. No personal data stored. | EU (Ireland, eu-west-1) |
| Functional Software, Inc. (Sentry) | Error tracking and performance monitoring. Error logs may incidentally contain personal data such as user IDs. Log retention capped at 12 months. | EU (Germany) |
| Stripe Payments UK Ltd | Payment processing and billing. PerkIQ does not store card data. | UK/US |
| HubSpot, Inc. | Customer relationship management and account tier synchronisation | US |
| PostHog, Inc. | Product analytics. Browser events are consent-gated via the cookie banner and are not active on the employee portal. | EU (Frankfurt) |
| Slack Technologies, LLC | Internal operational notifications to PerkIQ staff. Not a customer-facing data path. | US |
| Apple Inc., Google LLC, Mozilla Corporation | Push notification delivery for the employee benefits portal, where an employee turns notifications on. See section 3.6. | US; EU edge |
We may also disclose your data where required by law, regulation, or court order.
A complete and current list of our sub-processors, including transfer mechanisms, is published at perkiq.co.uk/sub-processors.
7 International Data Transfers
Our primary database (Supabase, Ireland), our rate limiting service (Upstash, Ireland), our error monitoring (Sentry, Germany) and our product analytics (PostHog, Frankfurt) all hold data in the EU, an adequate jurisdiction under UK GDPR. Vercel executes serverless functions in Ireland. No additional transfer mechanism is required for data at rest with those providers, and Standard Contractual Clauses with the UK IDTA apply as a back-stop to the US incorporation of Upstash, Sentry, PostHog and Vercel.
Stripe Payments UK Ltd is a UK entity and no transfer mechanism is required for it. Onward transfers within the Stripe group are covered by Stripe's own Data Processing Agreement.
Google, Resend, HubSpot, Slack, Apple and Mozilla operate in or transfer data to the United States. For those transfers we rely, in order of preference, on the EU-US Data Privacy Framework (DPF) with UK Extension where the provider holds a valid DPF certification, and on Standard Contractual Clauses (SCCs) supplemented by the UK International Data Transfer Addendum (IDTA) issued by the ICO as a back-stop where DPF is unavailable or certification lapses. These mechanisms are incorporated in each provider's Data Processing Agreement. If the hosting region of any provider changes, this policy will be updated accordingly.
8 Cookies
Strictly necessary (no consent required)
We use a session cookie to keep you logged in, and a short-lived cookie used during the sign-up flow. These are required for the platform to function and cannot be disabled.
Analytics (requires your consent)
With your consent, we use Google Analytics to understand how visitors use our website, and PostHog to understand how the platform itself is used. You can accept or decline analytics cookies via the cookie banner when you first visit. You can change your preference at any time using the cookie settings link in the footer. Neither is active on the employee benefits portal.
We also collect basic web performance data through our hosting provider. No personal data is attached to these measurements.
We do not use advertising, marketing, or third-party tracking cookies.
Local storage
We use browser local storage to save your in-progress diagnostic answers and provider comparison shortlist on your device. This data is not transmitted to our servers.
9 How Long We Keep Your Data
| Data | Retention period |
|---|---|
| Account data | Retained while your account is active. Deleted immediately and in full if you close your account, subject to the payment records note below. |
| Headcount change records | Retained while your account is active, to explain how your price was calculated. If the account holder who made a change is removed from the account, the reference to them is deleted and the figures remain against the organisation. The whole log is deleted when the account is closed. The record of what you were invoiced is held separately by Stripe, our payment processor. |
| Anonymous survey responses | Retained indefinitely. These are anonymous data to which UK GDPR does not apply. |
| Invitation records | Invitation links expire after 7 days. The invitation record is retained for audit purposes for 24 months from the date of invitation. |
| Benefits portal access records (employee email, name, sign-in times) | Kept while the employer grants the employee portal access; removed on the employer's instruction when access ends, and in any event deleted when the employer's account is closed. |
| Benefits portal usage analytics | 365 days, then deleted automatically |
| Push notification registrations | Deleted when the employee turns notifications off, when the app is removed, or when the notification service reports the registration as no longer valid. |
| Error logs | 12 months |
| Contact form submissions | 24 months |
| Google Analytics data | Per Google Analytics retention settings (default: 14 months) |
| PostHog product analytics | Per the retention configured in PostHog; pseudonymous event data only |
Account deletion is permanent. Within PerkIQ it is a hard delete, not an archive: deletion cascades to all associated company data, diagnostic history, action items, benefits portal records, push notification registrations and the headcount change log.
We are required by law to keep records of the payments we receive, and those records are held by Stripe, our payment processor, rather than in the platform. Stripe retains them for the period required by UK tax and accounting law, generally six years from the end of the accounting period they relate to. Closing your PerkIQ account does not delete them, because we are not permitted to delete them. The lawful basis for keeping them is compliance with a legal obligation (UK GDPR Article 6(1)(c)).
10 Your Rights
Under UK GDPR you have the following rights in relation to your personal data: the right to access a copy of your data, the right to correct inaccurate data, the right to request deletion, the right to data portability, the right to restrict or object to processing, and the right to withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at info@perkiq.co.uk. We will respond within 30 days of receiving your request. Where a request is complex or we receive a large number of requests simultaneously, we may extend this period by a further two months. We will notify you of any extension within the initial 30-day period and explain the reason for the delay.
You can also:
- Export your data at any time using the data export feature in your account Settings
- Edit your profile, company details, and entered data directly in the platform
- Delete your account and all associated data via Settings
- Manage notification preferences and cookie consent via Settings and the cookie banner
11 Children
PerkIQ is a business platform intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. Contact us at info@perkiq.co.uk if you believe we have inadvertently collected data from a minor and we will delete it promptly.
12 Changes to This Policy
We will notify you of material changes to this policy by email or in-app notification not less than 14 days before they take effect. The current version is always available at www.perkiq.co.uk/platform-privacy.
13 Contact
PerkIQ Ltd
167-169 Great Portland Street, 5th Floor, London, W1W 5PF
Company number: 17102662 · VAT: GB 516 4012 29
ICO registration: ZC108098
Email: info@perkiq.co.uk