Decision Atlas Legal

Privacy Policy

Decision Atlas is designed around data minimisation. The platform does not require client names, addresses, phone numbers, emails, or direct identifiers to generate a report.

Plain-English summary

  • We collect practitioner account data such as email address for authentication and service access.
  • Payments are handled by Stripe. We do not store card numbers.
  • Report inputs should be anonymised and must not contain direct client identifiers.
  • Report PDFs may be generated through PDFShift from report content.
  • Transactional and follow-up emails may be sent through Resend.
  • AI-assisted processing may be used to classify anonymised contexts, support matching, and generate report language.
  • Outcome submissions may be used to improve the evidence vault when submitted with authority.
  • Contact us at info@decisionatlas.co.uk for privacy questions.

1. Who this policy applies to

This policy applies to practitioners, account holders, and people who use or access Decision Atlas.

2. Data we process

Account data: email address and authentication data needed to create and manage your account.

Report context: anonymised decision domain, age band, country context, decision type, situation summary, and report metadata used to generate reports.

Generated reports: report content, report identifiers, download status, report tier, generated PDF files, and report-session metadata may be processed to deliver the service, provide downloads, support billing records, and operate follow-up outcome workflows.

Payment data: Stripe handles payment processing. We may receive payment confirmation, customer email, product, subscription, invoice, and transaction metadata from Stripe. We do not store card numbers.

Stripe webhooks: Stripe webhook payloads may be received by our server to confirm payments and subscriptions. These payloads may contain personal data such as email address. They are used for billing/account operation and should not be logged or stored beyond what is necessary for service operation and accounting.

Email and follow-up data: where follow-up reminders or transactional emails are enabled, we may process email address, report reference, reminder status, email delivery metadata, and follow-up link metadata.

Outcome submissions: if you submit an outcome, we process the anonymised outcome information and associated report/session metadata to improve the evidence vault.

Technical data: server logs, IP address, browser/device information, and security events may be processed to operate and protect the platform.

3. Data we do not need

Decision Atlas does not need client names, client email addresses, client phone numbers, client addresses, medical records, safeguarding details, or other direct identifiers. Practitioners must not enter these details.

4. Why we process data

  • to create and manage practitioner accounts;
  • to authenticate users through Supabase;
  • to process payments and subscriptions through Stripe;
  • to generate reports from anonymised decision contexts;
  • to convert report content into downloadable PDFs;
  • to send transactional emails, report links, and follow-up reminders where enabled;
  • to process anonymised outcome submissions and improve report reliability;
  • to protect the platform from misuse, fraud, and security risk;
  • to improve aggregate matching quality and evidence-vault performance.

5. Service providers

We use third-party providers to operate the platform. These may include Supabase for authentication and database infrastructure, Vercel for hosting, Stripe for payments and subscriptions, PDFShift for PDF generation, Resend for transactional and follow-up email delivery, and OpenAI or another AI processing provider where AI-assisted processing is used.

These providers process data only as necessary to deliver, secure, bill, monitor, and improve the service. Depending on the provider and processing context, a provider may act as a processor, subprocessor, or independent controller for limited service purposes such as payment processing.

Decision Atlas does not sell personal data and does not use report inputs for advertising targeting.

6. AI-assisted processing

Decision Atlas may use AI-assisted processing to classify anonymised decision contexts, support evidence matching, generate report language, summarise matched evidence, and improve internal quality checks. AI-assisted processing is used as part of the report generation workflow and does not create medical, legal, financial, therapeutic, safeguarding, employment, or crisis advice.

Decision Atlas does not make automated decisions that produce legal or similarly significant effects about a client. Practitioners remain responsible for their own professional judgement and for deciding whether a report is appropriate to use in their own practice.

7. Cookies

Decision Atlas uses strictly necessary cookies or similar technologies for login, authentication, security, and session operation. We do not currently use advertising cookies or behavioural tracking cookies. See our Cookie Policy for more detail.

8. Retention

Account and billing records are kept for as long as necessary to provide the service, meet legal/accounting duties, resolve disputes, and maintain security.

Generated reports are intended to remain available for a limited operational period, currently 30 days unless a different retention period is stated in the product, dashboard, or report flow. Report files, session records, and download links may be deleted or disabled after that period.

Anonymised decision metadata, pattern classifications, report metadata, and outcome records may be retained for evidence-vault improvement where they no longer identify a person. Where data remains personal data, deletion or restriction requests will be considered under applicable data-protection law.

Security logs, backups, webhook records, and transactional email metadata may persist for a limited operational period where necessary for security, audit, dispute handling, or legal/accounting reasons.

9. Your rights

You may request access, correction, deletion, restriction, objection, or portability of your personal data where those rights apply. To exercise your rights, contact info@decisionatlas.co.uk. You may also complain to the UK Information Commissioner's Office.

10. Practitioner responsibility

Practitioners are responsible for ensuring that any decision context submitted to Decision Atlas is anonymised and does not contain direct client-identifying information. If you submit information on behalf of a client, you are responsible for your own professional, consent, confidentiality, and data-protection obligations.

11. International processing

Some service providers may process data outside the United Kingdom or European Economic Area. Where this occurs, Decision Atlas expects providers to use appropriate contractual, technical, and organisational safeguards for the processing they perform.

12. Contact

For privacy queries, data-rights requests, DPA requests, or concerns about report data, contact: info@decisionatlas.co.uk

Last updated: 20 June 2026.