Draft for legal and operational completion

Do not publish this as the final policy until the bracketed company details, providers, hosting locations, lawful bases and retention decisions have been completed and approved.

Privacy and trust

Culturevating OS privacy policy

Draft dated 6 August 2026 · Version 0.1

1. Who we are

Culturevating OS is operated by Not Usual Ltd (“Not Usual”, “we”, “us”). Our registered office is [insert registered address], company number [insert company number]. Contact our privacy lead at [insert privacy email].

For account administration, billing, platform security and our own website, Not Usual will normally act as a controller. When a client organisation uses Culturevating OS to process information about its workers, customers or partners, that client will normally determine the purposes and act as controller, while Not Usual acts as its processor. The relevant contract and data processing agreement must confirm these roles for each deployment.

2. What this policy covers

This policy covers the Culturevating website, administration areas, Bridgit conversations, Microsoft 365 connections, uploaded evidence, organisational diagnostics and related support. A client organisation must also provide its own privacy information where it decides how Culturevating is used with its people or customers.

Data control and deployment choices

A subscription level does not determine whether a client can access or control its organisational data. Clients should be able to obtain usable exports and follow documented offboarding and deletion processes at every service level. An upgrade changes where information is hosted and who operates the technical environment; it does not sell ownership or data-subject rights back to the client.

Culturevating Cloud

Not Usual operates the SaaS and structured data environment under the agreed controller/processor terms.

Connected Garden

Culturevating provides intelligence while approved documents can remain in the client’s SharePoint tenant.

Tenant-Owned Garden

Dataverse, SharePoint and Garden records operate in the client’s approved Power Platform environment, with restricted support access for Not Usual.

The Account data-location map should identify the active model, storage locations, relevant controller, permitted access and available export format for each data category. Final contracts must define data return, migration assistance, deletion, backup expiry and any charges for technical migration services.

3. Information, purposes and lawful bases

CategoryExamplesPurposePotential basis
Account and identityName, work email, Microsoft identifiers, role, organisation and sign-in eventsProvide and secure accounts; administer accessContract, legitimate interests and security obligations, depending on context
Organisation directoryMicrosoft 365 teams, direct memberships, job title, department and office locationScope access and provide team or specialist insightThe client organisation must identify and document its lawful basis
Culturevating activityGoals, ideas, diagnostic answers, plans, documents, conversations, evidence and outcomesProvide requested diagnostics, collaboration and organisational intelligenceUsually contract for service delivery; the client determines its basis for workforce processing
Derived intelligenceThemes, summaries, competency signals, connections and recommendationsHelp users and organisations understand patterns and opportunitiesDepends on the underlying purpose and lawful basis; outputs require human review
BillingBilling contacts, subscription, invoices, payment references and limited card descriptorsManage subscriptions, payments, accounting and disputesContract and legal obligations
Technical and securityIP address, device/browser information, timestamps, logs and audit eventsOperate, protect and troubleshoot the serviceLegitimate interests and legal/security obligations
Website choicesCookie consent, language and interface preferencesRemember choices and control optional technologyLegal exemption where strictly necessary; consent for non-essential purposes

Launch decision required: complete a processing record and confirm the lawful basis for every enabled purpose. Consent should not automatically be assumed appropriate in an employment relationship.

4. Microsoft 365

Where an authorised organisation connects Microsoft 365, Culturevating can read approved directory information through Microsoft Graph, including teams, direct memberships and limited user profile information. We use stable Microsoft identifiers to maintain scope. Culturevating does not change Microsoft team membership through the current integration.

Future access to meetings, messages, email or documents must not be enabled merely because directory access exists. Each additional source needs a documented purpose, minimum permission, transparency information, retention rule and—where required—a data protection impact assessment.

5. Bridgit and artificial intelligence

Bridgit is intended to help organise information, support reflection, identify patterns and suggest questions or connections. AI output may be incomplete or wrong and should be reviewed by an appropriate person before decisions are made.

  • We do not intend Bridgit to make solely automated decisions producing legal or similarly significant effects.
  • Private personal conversations should not be visible to organisation administrators unless the individual deliberately shares them or a clearly documented exceptional legal process applies.
  • Client content must not be used to train a provider’s general models unless the controller has expressly approved this and the legal, contractual and transparency requirements are satisfied.
  • We must publish the AI and hosting providers, processing locations, retention settings and contractual safeguards before live AI processing begins: [insert approved provider register].

6. Teams, specialisms and workplace insight

Access is intended to follow role and scope. Members see their own information; Insight Leads see aggregated information for assigned teams or specialisms; Organisation Administrators see approved organisation-level aggregates. Platform Administrators should not have routine access to client content.

Team and specialism reporting should use a minimum cohort of five contributing people. Culturevating must not infer sensitive characteristics such as health, ethnicity, beliefs, sexual orientation or trade-union membership. Information collected to support learning and innovation must not quietly be reused for individual performance management.

7. Sharing and processors

We may use carefully selected providers for hosting, authentication, AI, communications, billing and support. We will require appropriate contracts, confidentiality, security and deletion commitments. The final policy must name or link to the current subprocessors: [insert subprocessor register and notification process].

We may disclose information where required by law, to protect rights or security, or as part of a properly managed corporate transaction. We do not sell personal information.

8. International transfers

The final hosting and provider architecture will determine whether information leaves the UK. Before an international transfer is enabled, we will identify the transfer mechanism, assess relevant risks and apply supplementary safeguards where necessary. [insert hosting regions and transfer safeguards].

9. Retention

We keep identifiable information only for as long as needed for the documented purpose, contractual obligations, legal requirements and dispute handling. The production service will enforce an approved retention schedule covering personal reflections, organisational seasons, source documents, derived insight, audit logs, support records and billing information.

Launch decision required: agree exact periods, deletion workflows, client-configurable rules, backup expiry and what happens when an organisation or individual leaves. Cookie preferences currently expire after approximately six months.

10. Security and access

We use measures intended to protect confidentiality, integrity and availability, including Microsoft authentication, server-side role checks, tenant-scoped access, minimum permissions and audit requirements. Production readiness additionally requires database row-level controls, encryption, secrets management, tested backups, vulnerability management, incident response and periodic access reviews.

Not Usual support access to client content should be time-limited, purpose-bound, approved and audited rather than permanently available.

11. Your rights

Depending on the circumstances, you may have rights to be informed, access information, correct it, have it erased, restrict or object to processing, receive portable information, and raise concerns about automated decision-making. Where a client organisation controls the information, we may direct your request to that organisation and assist it as processor.

Contact [insert privacy email]. We may need to verify identity and clarify the information involved. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.

12. Cookies, changes and contact

Our cookie information explains browser storage and how to change choices. We will review this policy when purposes, providers or technology change and show the effective date and material updates.