Privacy Notice

Privacy Notice – Onyx Data DataDNA Platform

Version: 1.0 Last updated: 13 March 2026 Effective date: 13 March 2026


1. Who We Are

This privacy notice explains how Onyx Data Ltd (“we”, “us”, “our”) collects and uses your personal information when you participate in the DataDNA Challenge platform.

Data Controller: Onyx Data Ltd Registered in England and Wales Company Number: 11795932 Registered Address: 16 Upper Woburn Place London WC1H 0AF

Contact us about your data: Email: contact@onyxdata.co.uk Subject line: “DataDNA Privacy Enquiry”

We will respond to privacy enquiries within 5 working days.


2. Data Protection Officer

Onyx Data Ltd is a small-to-medium enterprise (SME) and is not required to appoint a Data Protection Officer under UK GDPR Article 37. Our core activities do not involve large-scale systematic monitoring or processing of special category data.

For data protection queries, please contact us using the details in Section 1.


3. What Personal Data We Collect

When you submit to the DataDNA Challenge, we collect the following personal data:

Data Type Examples Source
Contact details Email address, name Your submission form
Professional information Company name (optional), role (optional) Your submission form
Submission content Your data visualisation files, technique descriptions Your submission
Technical information IP address, browser type Automatic collection
Generated data AI feedback scores, talent rankings Our analysis

We do not collect special category data (such as health, racial, or biometric data) through the DataDNA platform.


4. Why We Process Your Data (Purposes)

We process your personal data for four distinct purposes:

4.1 AI-Powered Submission Feedback

What we do: We use AI to analyse your submission and generate personalised feedback on storytelling, design, technical implementation, and insight quality.

Data used: Your email, name, submission content.

Lawful basis: Consent – you explicitly opt in by ticking the feedback consent checkbox on the submission form.

Benefit to you: You receive detailed, personalised feedback to help you improve your data visualisation skills.

4.2 Talent Pool Directory

What we do: We maintain a directory of talented data professionals, ranked by their submission quality, which we share with recruiters seeking skilled candidates.

Data used: Your email, name, submission scores, professional information.

Lawful basis: Consent – you explicitly opt in by ticking the talent pool consent checkbox on the submission form.

Benefit to you: Recruiters may contact you about job opportunities matching your demonstrated skills.

4.3 Feature Usage Tracking for Adoption Intelligence

What we do: We extract information about which data tools and techniques you used in your submission (for example, Power BI, Tableau, DAX measures) to create aggregated reports about tool adoption trends.

Data used: Tool usage data extracted from your submission.

Lawful basis: Consent – you explicitly opt in by ticking the feature tracking consent checkbox on the submission form.

Benefit to you: Your contribution helps inform community intelligence about data tool trends. These reports support our partnership with Microsoft and help shape the future of data tools.

4.4 Sponsor Outreach

What we do: We contact corporate sponsors about opportunities to support the DataDNA community through sponsorship, advertising, or partnership arrangements.

Data used: Business email addresses from corporate subscribers.

Lawful basis: Legitimate interests – we have a legitimate business interest in funding community initiatives through sponsor relationships. We have documented this in a Legitimate Interest Assessment, which balances our interests against your rights. You can request a copy of this assessment by contacting us.

Note: This applies only to business-to-business communications with corporate entities. We do not send unsolicited marketing emails to individuals without consent.


5. Who Receives Your Data

We share your personal data with the following categories of recipients:

Service Providers (Data Processors)

Processor Purpose Location Safeguards
Supabase Database hosting and storage EU/UK data centres Standard Contractual Clauses, Data Processing Agreement
Resend Transactional email delivery (feedback notifications) USA Standard Contractual Clauses, Data Processing Agreement
Anthropic AI processing for feedback generation USA Standard Contractual Clauses, Data Processing Agreement

Third Parties (If You Consent)

Recipient Purpose When Shared
Recruiters Talent pool directory access Only if you opted into talent pool
Microsoft Aggregated adoption intelligence only No personal data shared – only aggregate statistics

We never sell your personal data.


6. International Transfers

Some of our service providers process data outside the United Kingdom:

Provider Country Safeguard
Resend USA UK Standard Contractual Clauses (2022)
Anthropic USA UK Standard Contractual Clauses (2022)

These transfers are protected by Standard Contractual Clauses approved by the Information Commissioner’s Office, ensuring your data receives equivalent protection to UK law.

For Supabase, data is processed in EU/UK data centres covered by UK adequacy decisions.


7. How Long We Keep Your Data

We retain your data only as long as necessary for each purpose:

Data Category Retention Period Reason
Submission data Duration of your talent pool consent + 2 years To support talent pool functionality
AI feedback and scores 5 years Historical record for ranking and improvement tracking
Consent records 7 years Legal requirement for audit and compliance evidence
Tool usage data 3 years For aggregated intelligence reporting

When retention periods expire, we securely delete or anonymise your data.

If you withdraw consent, we will delete your data within 30 days, except where we are legally required to retain it (such as consent records for audit purposes).


8. Your Rights

Under UK GDPR, you have the following rights:

8.1 Right of Access

You can request a copy of the personal data we hold about you. We will respond within one month.

8.2 Right to Rectification

You can ask us to correct inaccurate personal data or complete incomplete data.

8.3 Right to Erasure (“Right to be Forgotten”)

You can ask us to delete your personal data. We will do so unless we have a legal obligation to keep it (such as consent records for audit purposes).

8.4 Right to Restriction

You can ask us to temporarily stop processing your data while we investigate a complaint or verify accuracy.

8.5 Right to Data Portability

You can request your data in a structured, commonly used format (such as CSV or JSON) to transfer to another service.

8.6 Right to Object

You can object to processing based on legitimate interests. We will stop processing unless we demonstrate compelling legitimate grounds.

8.7 Right to Withdraw Consent

You can withdraw consent at any time for any purpose. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to exercise your rights: Email: privacy@onyxdata.co.uk Subject line: “Data Rights Request – [Your Right]”

We will verify your identity before processing any request. We respond to all requests within one month, or inform you if we need an extension.


9. Automated Decision-Making

We use automated processing to generate feedback scores and talent rankings:

What happens

When you submit to the DataDNA Challenge:

  1. Our AI system (powered by Anthropic Claude) analyses your submission
  2. It generates scores across four categories: storytelling, design, technical implementation, and insight quality
  3. These scores contribute to your overall talent ranking if you opted into the talent pool

The logic involved

The AI evaluates your submission against established criteria for effective data visualisation, including clarity of narrative, visual design principles, appropriate use of data techniques, and quality of insights derived from the data.

Significance and consequences

  • Feedback: Your scores determine the personalised feedback you receive
  • Talent pool ranking: If opted in, your scores affect your visibility to recruiters
  • No negative consequences: Low scores do not exclude you from participation or result in penalties

Your right to human review

You have the right to:

  • Request an explanation of how your scores were calculated
  • Challenge the automated decision
  • Request human review of any automated decision that affects you

To request human review, email privacy@onyxdata.co.uk with subject line “Human Review Request”.


10. Complaints

If you are unhappy with how we handle your personal data, please contact us first so we can resolve your concern.

If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF

Telephone: 0303 123 1113 Website: https://ico.org.uk/make-a-complaint/


11. Changes to This Notice

We may update this privacy notice from time to time. We will notify you of significant changes by:

  • Posting the updated notice on our website
  • Emailing you if changes affect how we process your data

The “Last updated” date at the top of this notice shows when it was last revised.


12. Contact Us

For any questions about this privacy notice or how we use your data:

Email: contact@onyxdata.co.uk Response time: Within 5 working days