Privacy Notice – Onyx Data DataDNA Platform
Version: 1.0 Last updated: 13 March 2026 Effective date: 13 March 2026
1. Who We Are
This privacy notice explains how Onyx Data Ltd (“we”, “us”, “our”) collects and uses your personal information when you participate in the DataDNA Challenge platform.
Data Controller: Onyx Data Ltd Registered in England and Wales Company Number: 11795932 Registered Address: 16 Upper Woburn Place London WC1H 0AF
Contact us about your data: Email: contact@onyxdata.co.uk Subject line: “DataDNA Privacy Enquiry”
We will respond to privacy enquiries within 5 working days.
2. Data Protection Officer
Onyx Data Ltd is a small-to-medium enterprise (SME) and is not required to appoint a Data Protection Officer under UK GDPR Article 37. Our core activities do not involve large-scale systematic monitoring or processing of special category data.
For data protection queries, please contact us using the details in Section 1.
3. What Personal Data We Collect
When you submit to the DataDNA Challenge, we collect the following personal data:
| Data Type | Examples | Source |
|---|---|---|
| Contact details | Email address, name | Your submission form |
| Professional information | Company name (optional), role (optional) | Your submission form |
| Submission content | Your data visualisation files, technique descriptions | Your submission |
| Technical information | IP address, browser type | Automatic collection |
| Generated data | AI feedback scores, talent rankings | Our analysis |
We do not collect special category data (such as health, racial, or biometric data) through the DataDNA platform.
4. Why We Process Your Data (Purposes)
We process your personal data for four distinct purposes:
4.1 AI-Powered Submission Feedback
What we do: We use AI to analyse your submission and generate personalised feedback on storytelling, design, technical implementation, and insight quality.
Data used: Your email, name, submission content.
Lawful basis: Consent – you explicitly opt in by ticking the feedback consent checkbox on the submission form.
Benefit to you: You receive detailed, personalised feedback to help you improve your data visualisation skills.
4.2 Talent Pool Directory
What we do: We maintain a directory of talented data professionals, ranked by their submission quality, which we share with recruiters seeking skilled candidates.
Data used: Your email, name, submission scores, professional information.
Lawful basis: Consent – you explicitly opt in by ticking the talent pool consent checkbox on the submission form.
Benefit to you: Recruiters may contact you about job opportunities matching your demonstrated skills.
4.3 Feature Usage Tracking for Adoption Intelligence
What we do: We extract information about which data tools and techniques you used in your submission (for example, Power BI, Tableau, DAX measures) to create aggregated reports about tool adoption trends.
Data used: Tool usage data extracted from your submission.
Lawful basis: Consent – you explicitly opt in by ticking the feature tracking consent checkbox on the submission form.
Benefit to you: Your contribution helps inform community intelligence about data tool trends. These reports support our partnership with Microsoft and help shape the future of data tools.
4.4 Sponsor Outreach
What we do: We contact corporate sponsors about opportunities to support the DataDNA community through sponsorship, advertising, or partnership arrangements.
Data used: Business email addresses from corporate subscribers.
Lawful basis: Legitimate interests – we have a legitimate business interest in funding community initiatives through sponsor relationships. We have documented this in a Legitimate Interest Assessment, which balances our interests against your rights. You can request a copy of this assessment by contacting us.
Note: This applies only to business-to-business communications with corporate entities. We do not send unsolicited marketing emails to individuals without consent.
5. Who Receives Your Data
We share your personal data with the following categories of recipients:
Service Providers (Data Processors)
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Database hosting and storage | EU/UK data centres | Standard Contractual Clauses, Data Processing Agreement |
| Resend | Transactional email delivery (feedback notifications) | USA | Standard Contractual Clauses, Data Processing Agreement |
| Anthropic | AI processing for feedback generation | USA | Standard Contractual Clauses, Data Processing Agreement |
Third Parties (If You Consent)
| Recipient | Purpose | When Shared |
|---|---|---|
| Recruiters | Talent pool directory access | Only if you opted into talent pool |
| Microsoft | Aggregated adoption intelligence only | No personal data shared – only aggregate statistics |
We never sell your personal data.
6. International Transfers
Some of our service providers process data outside the United Kingdom:
| Provider | Country | Safeguard |
|---|---|---|
| Resend | USA | UK Standard Contractual Clauses (2022) |
| Anthropic | USA | UK Standard Contractual Clauses (2022) |
These transfers are protected by Standard Contractual Clauses approved by the Information Commissioner’s Office, ensuring your data receives equivalent protection to UK law.
For Supabase, data is processed in EU/UK data centres covered by UK adequacy decisions.
7. How Long We Keep Your Data
We retain your data only as long as necessary for each purpose:
| Data Category | Retention Period | Reason |
|---|---|---|
| Submission data | Duration of your talent pool consent + 2 years | To support talent pool functionality |
| AI feedback and scores | 5 years | Historical record for ranking and improvement tracking |
| Consent records | 7 years | Legal requirement for audit and compliance evidence |
| Tool usage data | 3 years | For aggregated intelligence reporting |
When retention periods expire, we securely delete or anonymise your data.
If you withdraw consent, we will delete your data within 30 days, except where we are legally required to retain it (such as consent records for audit purposes).
8. Your Rights
Under UK GDPR, you have the following rights:
8.1 Right of Access
You can request a copy of the personal data we hold about you. We will respond within one month.
8.2 Right to Rectification
You can ask us to correct inaccurate personal data or complete incomplete data.
8.3 Right to Erasure (“Right to be Forgotten”)
You can ask us to delete your personal data. We will do so unless we have a legal obligation to keep it (such as consent records for audit purposes).
8.4 Right to Restriction
You can ask us to temporarily stop processing your data while we investigate a complaint or verify accuracy.
8.5 Right to Data Portability
You can request your data in a structured, commonly used format (such as CSV or JSON) to transfer to another service.
8.6 Right to Object
You can object to processing based on legitimate interests. We will stop processing unless we demonstrate compelling legitimate grounds.
8.7 Right to Withdraw Consent
You can withdraw consent at any time for any purpose. Withdrawal does not affect the lawfulness of processing before withdrawal.
How to exercise your rights: Email: privacy@onyxdata.co.uk Subject line: “Data Rights Request – [Your Right]”
We will verify your identity before processing any request. We respond to all requests within one month, or inform you if we need an extension.
9. Automated Decision-Making
We use automated processing to generate feedback scores and talent rankings:
What happens
When you submit to the DataDNA Challenge:
- Our AI system (powered by Anthropic Claude) analyses your submission
- It generates scores across four categories: storytelling, design, technical implementation, and insight quality
- These scores contribute to your overall talent ranking if you opted into the talent pool
The logic involved
The AI evaluates your submission against established criteria for effective data visualisation, including clarity of narrative, visual design principles, appropriate use of data techniques, and quality of insights derived from the data.
Significance and consequences
- Feedback: Your scores determine the personalised feedback you receive
- Talent pool ranking: If opted in, your scores affect your visibility to recruiters
- No negative consequences: Low scores do not exclude you from participation or result in penalties
Your right to human review
You have the right to:
- Request an explanation of how your scores were calculated
- Challenge the automated decision
- Request human review of any automated decision that affects you
To request human review, email privacy@onyxdata.co.uk with subject line “Human Review Request”.
10. Complaints
If you are unhappy with how we handle your personal data, please contact us first so we can resolve your concern.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF
Telephone: 0303 123 1113 Website: https://ico.org.uk/make-a-complaint/
11. Changes to This Notice
We may update this privacy notice from time to time. We will notify you of significant changes by:
- Posting the updated notice on our website
- Emailing you if changes affect how we process your data
The “Last updated” date at the top of this notice shows when it was last revised.
12. Contact Us
For any questions about this privacy notice or how we use your data:
Email: contact@onyxdata.co.uk Response time: Within 5 working days