Skip to main content
Account help

Data and privacy during the pilot

Current product information · 2 October 2026. This page explains the prototype’s behaviour. It does not replace an approved privacy notice or venue data-processing agreement.

What the application records

Do not put passwords, customer identity documents, health information or unnecessary personal details in uploads or feedback. Fictional demo exercises need no real venue records.

Access and retained records

Restricted intake is active: only validated UTF-8 CSV data can be uploaded. PDF, Excel, image and archive attachments are blocked. Formula-like cells and binary content are rejected. This is not malware scanning. Remove guest names, contact details and other unnecessary personal information before importing.

Application access is checked against active user and company permissions. Source documents use controlled download routes. Some financial and audit history is append-only to preserve decision evidence. Suspension removes application access; it does not erase retained records or downloaded copies.

There is no self-service account deletion or document purge. Ask the pilot lead about an access, correction or deletion request. Do not assume files are automatically deleted after the pilot.

Confirm before confidential live use

The pilot operator must provide the responsible organisation and privacy contact, approved purposes and processing terms, hosting and service-provider information, retention periods, a rights-request process and incident contacts. Hosted recovery still requires verification. The venue must agree to the restricted CSV intake; accepting other attachments will require a separate scanning and quarantine service. These items are not established merely by signing in or submitting an application.

Until those arrangements are confirmed, use fictional or appropriately minimised test data. Ask the person who invited you for the approved pilot documentation.