FrictionIQ Privacy Policy
Last updated: 13 June 2026 Version: 1.0 (Beta)
This Privacy Policy explains how FrictionIQ (“we”, “us”, “our”) collects, uses, stores, and protects personal information when you use the FrictionIQ platform at frictioniq.io and related services (the “Service”).
This policy is written for all user types on the platform. Some features are available only to certain roles.
Important: FrictionIQ is a workforce and team management tool for healthcare and clinical organisations. It is not intended for storing patient-identifiable information. Do not enter patient names, NHS numbers, dates of birth, addresses, photographs of patients, or other information that could identify a patient in any free-text field, message, or upload.
Legal note: This document is a product-aligned draft for beta use. It does not constitute legal advice. Organisations using FrictionIQ should review this policy with their own legal and information governance advisers before wider rollout.
1. Who we are and how to contact us
Service operator: FrictionIQ Website: https://frictioniq.io Privacy contact: privacy@frictioniq.io
If you use FrictionIQ through your employer or contracting organisation, that organisation may also hold privacy information about you. See Section 3 for how responsibilities are divided.
2. Scope — who this policy applies to
This policy applies if you access FrictionIQ as any of the following:
| User type | How you typically access the Service |
|---|---|
| Organisation administrator | You register an organisation and manage teams, managers, and settings |
| Manager | You are invited by an organisation admin to manage one or more teams |
| Staff member | You are invited to join a team and use the staff portal (including mobile/PWA) |
| Platform administrator | You operate or support the FrictionIQ platform itself |
| Anonymous feedback submitter | You submit post-shift feedback via a team QR/link without signing in |
If you do not agree with this policy, you should not use the Service.
3. Roles and responsibilities (controller vs processor)
FrictionIQ is used by organisations to support team feedback, reporting, communication, and staff wellbeing tools. Privacy law responsibilities depend on the type of data and context:
3.1 Organisation-controlled data
For most workplace data processed on behalf of an organisation — including team feedback visible to managers, concern/incident reports, team membership, and organisation messaging — your organisation is generally the data controller and FrictionIQ acts as a data processor, processing data on the organisation’s instructions through the Service.
Organisation administrators and managers should ensure they have a lawful basis to use the Service and should provide their own workforce privacy information where required (for example, an employee privacy notice).
3.2 FrictionIQ-controlled data
FrictionIQ is generally the data controller for:
- Organisation administrator account registration details
- Platform help & support tickets you send to FrictionIQ
- Platform announcements and operational emails from FrictionIQ
- Platform administrator access and audit activities
- Service security, abuse prevention, and product improvement data that is not organisation content
3.3 Staff-only private features
Certain staff features are designed so that organisation administrators and managers cannot access your individual content through the Service, including:
- Private wellbeing check-in history (exhaustion trends)
- Private diary entries
- Knowledge tracker entries (learnings and knowledge gaps)
This data is linked to your user account and protected by access controls in the Service. It is processed to provide personal reflection and wellbeing tools as part of the Service. Your organisation does not receive the content of these private entries through normal platform access.
4. Information we collect
We collect different information depending on how you use the Service.
4.1 Account and identity information (all signed-in users)
- Email address
- Password (stored in hashed form by our authentication provider; we do not store plain-text passwords)
- Authentication session data
- Name (where provided, for example on manager or staff profiles)
- Role and organisation/team membership context
4.2 Organisation administrator registration
When an organisation admin creates an account, we collect:
- Organisation name
- Organisation type (for example hospital, GP practice, clinic)
- City and country
- Admin email address and password
4.3 Manager and staff invitation data
When an organisation admin or manager invites users, we collect and store:
- First name and last name
- Email address
- Staff role category (for staff: doctor, nurse, healthcare assistant, receptionist)
- Team and organisation association
- Invitation and acceptance status
Invitation emails may be sent through our email provider and may include onboarding instructions or mobile setup information.
4.4 Post-shift team feedback
When feedback is submitted — via the staff portal or a team feedback link/QR code — we collect the responses you enter, which may include:
- Role and shift details (shift type, shift date)
- Shift ratings and workload/exhaustion ratings
- Answers about difficult encounters, team cohesion, IT issues, breaks, near misses, equipment issues
- Selected constraint categories and patient care impact selections
- Optional service improvement category and free-text suggestion
Anonymity to your organisation: Team feedback submissions are stored without your user identity attached in the feedback record visible to organisation administrators and managers. They see the feedback content and aggregated trends, not which individual submitted a given response.
Signed-in staff and wellbeing: If you submit feedback while signed in to the staff portal as an accepted team member, a separate private wellbeing check-in record may be created for you containing exhaustion-related fields from that submission. This private wellbeing history is visible only to you, not to your organisation’s admins or managers through the Service.
Unsigned feedback: If you submit feedback without signing in, no account-linked wellbeing record is created.
4.5 Concern, incident, and issue reports (staff)
When staff submit a team report, we collect:
- Report type (concern, incident, or issue)
- Subject and details (free text)
- Whether you choose anonymous or identified submission
- Your user identity is stored internally to operate the Service
Anonymous reports: If you choose anonymity, organisation administrators and managers see the report content and status but not your name, email, or role in the management view. Anonymous reports cannot receive a direct response through the Service.
Identified reports: If you choose not to be anonymous, managers/admins can see your name, email, and staff role, and you may receive a response through the Service.
4.6 Private staff diary
If you use the private diary, we store:
- Encounter type (patient encounter, colleague encounter, or other)
- What happened, how it felt, and optional learnings (free text, length limited)
Diary entries are visible only to you.
4.7 Knowledge tracker (staff)
If you use the knowledge tracker, we store:
- Learning entries (free text)
- Knowledge gaps, optional plans, closure method, target dates, reminders, and open/closed status
These entries are visible only to you.
4.8 Organisation messaging
The Service supports messaging between:
- Staff and team managers (per team)
- Organisation administrators and managers
We store conversation metadata, message body text, timestamps, and read/unread state for participants. Staff cannot message other staff through the Service.
4.9 Help & support tickets
If you contact FrictionIQ support through the in-app help feature, we collect:
- Your user identity and email
- Your role context
- Ticket category, subject, and message content
- Optional page context
- Support conversation history
Platform administrators can access support tickets to resolve requests.
4.10 Platform announcements and notifications
FrictionIQ may send in-app notifications and/or emails to organisation administrators and managers about product updates or service announcements. We store delivery and read status where applicable.
4.11 Technical and device information
When you use the Service, we and our infrastructure providers may automatically process:
- Browser type and device information
- IP address and approximate location derived from IP
- Log files, error reports, and security events
- PWA/install prompt dismissal preferences (stored locally in your browser)
- Last selected team preference for staff quick actions (stored locally in your browser)
- Session/portal role context (stored locally in your browser)
Our staff mobile experience may use a service worker and local browser storage to support installation and basic offline behaviour.
We do not use third-party advertising cookies or sell personal information.
5. How we use information
We use personal information to:
| Purpose | Examples |
|---|---|
| Provide the Service | Authentication, team membership, feedback capture, reports, messaging, dashboards, exports |
| Operate staff private tools | Wellbeing trends, diary, knowledge tracker |
| Send service communications | Invitation emails, password reset, confirmation emails, support replies, announcements |
| Support organisations | Team management, aggregated feedback analytics, report handling |
| Keep the Service secure | Fraud/abuse prevention, access control, audit logging |
| Improve and maintain the platform | Bug fixing, performance monitoring, beta development |
| Comply with law | Respond to lawful requests, enforce terms, protect rights and safety |
Lawful bases (UK GDPR)
Depending on context, we rely on one or more of:
- Contract — to provide the Service to you or your organisation
- Legitimate interests — to operate, secure, and improve the platform in a way that respects your rights
- Legal obligation — where we must retain or disclose information
- Consent — where required for optional communications (you may withdraw consent where applicable)
Organisations using FrictionIQ are responsible for identifying and documenting their own lawful basis for workforce processing.
6. Who can see your information
Access is controlled by role and by product design.
| Data type | Staff member | Manager | Org admin | Platform admin |
|---|---|---|---|---|
| Team feedback content (individual submission) | Can submit | Can view without submitter identity | Can view without submitter identity | Infrastructure access only for operations/support* |
| Private wellbeing history | Yes (self only) | No | No | Infrastructure access only* |
| Private diary & knowledge tracker | Yes (self only) | No | No | Infrastructure access only* |
| Team reports (anonymous) | Can submit/view own | Content only, no identity | Content only, no identity | Infrastructure access only* |
| Team reports (identified) | Can submit/view own | Yes | Yes | Infrastructure access only* |
| Org messaging (participant) | Yes (own threads) | Yes (own threads) | Yes (own threads) | No routine access |
| Team membership roster | Own memberships | Team roster | Organisation roster | Support/suspension operations* |
\*Platform administrators and hosting providers may technically access systems for security, support, and maintenance. We limit access to what is necessary and do not use organisation feedback content for unrelated purposes.
7. Sharing and subprocessors
We use trusted service providers to run the Service. These providers process data on our instructions and under appropriate safeguards.
| Provider type | Purpose |
|---|---|
| Supabase | Database, authentication, and backend infrastructure |
| Vercel | Application hosting and content delivery |
| Resend (or equivalent email API) | Transactional email (invites, notifications, support) |
We may also share information:
- With your organisation’s authorised users (managers/admins) as part of normal Service operation
- With professional advisers (legal, security) under confidentiality
- When required by law or to protect rights, safety, and integrity of users and the Service
- In connection with a business transfer (merger, acquisition, or asset sale), with appropriate notice where required
We do not sell personal information.
A current subprocessor list is available on request at privacy@frictioniq.io.
8. International transfers
Our infrastructure providers may process data in the United Kingdom, European Economic Area, United States, or other countries where they operate data centres.
Where personal data is transferred outside the UK, we rely on appropriate safeguards such as UK adequacy regulations, Standard Contractual Clauses, or equivalent mechanisms, as applicable.
9. Data retention
We keep information only as long as necessary for the purposes described in this policy, unless a longer period is required by law.
In general:
- Organisation and team data is retained while the organisation account is active
- Organisation deletion by an admin triggers deletion of associated organisation data through database cascade rules
- Staff private diary, knowledge, and wellbeing records are retained while your user account exists and you have not deleted the content, subject to organisation/account lifecycle events
- Support tickets are retained as needed to resolve issues and maintain support history
- Security and server logs are retained for a limited operational period
Retention periods may be refined as the Service moves from beta to general availability.
10. Security
We implement technical and organisational measures designed to protect personal information, including:
- Authenticated access controls and row-level security in the database
- Role-based permissions for organisation, manager, staff, and platform admin areas
- Encryption in transit (HTTPS)
- Hashed password storage through our authentication provider
- Separation of anonymous feedback from identifiable manager/admin views
No method of transmission or storage is completely secure. Please use a strong password and keep your login credentials confidential.
11. Your rights
If UK GDPR / UK data protection law applies to you, you may have rights including:
- Access — request a copy of personal information we hold about you
- Rectification — ask us to correct inaccurate information
- Erasure — ask us to delete information in certain circumstances
- Restriction — ask us to limit processing in certain circumstances
- Objection — object to processing based on legitimate interests
- Data portability — receive certain information in a portable format where applicable
- Withdraw consent — where processing is based on consent
How to exercise your rights
- Staff private content (diary, knowledge, wellbeing): you can access, edit, and delete much of this directly in the staff portal
- Account and organisation matters: contact your organisation administrator first if your employer controls the processing
- FrictionIQ platform matters: email privacy@frictioniq.io
We respond within one month in most cases, subject to legal exceptions.
You may also complain to the Information Commissioner’s Office (ICO) in the UK: https://ico.org.uk
12. Organisation account deletion
Organisation administrators can permanently delete their organisation account from settings. Deletion removes organisation-controlled data from the Service, including teams, feedback submissions, reports, and related organisation records, subject to technical deletion processes and legal retention obligations.
Deletion of an organisation may affect staff access to organisation-linked features. Private staff records may be deleted or orphaned depending on account relationships and deletion scope at the time of deletion.
13. Children
The Service is intended for adult workforce users in professional healthcare and clinical settings. It is not directed at children under 18, and we do not knowingly collect information from children.
14. Acceptable use and sensitive information
You must not use the Service to store or transmit:
- Patient-identifiable information
- Special category health data about identifiable patients
- Information you are not authorised to share
Free-text fields (feedback suggestions, reports, diary entries, messages) should describe workplace issues in a general way. If you include identifiable third-party information against this guidance, your organisation and/or FrictionIQ may need to handle that information under broader legal duties.
15. Beta service notice
FrictionIQ is currently offered as a beta service. Features, data locations, retention practices, and subprocessors may change as the product develops. We will update this policy when material changes occur.
16. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do.
If changes are material, we will provide additional notice where appropriate (for example in the Service or by email to organisation administrators).
17. Summary by user type
### Organisation administrators You provide organisation and account details; you manage teams, managers, and staff invitations; you can view aggregated/anonymous team feedback and manage reports/messaging for your organisation.
### Managers You receive manager access by invitation; you can view team feedback without submitter identity, manage team reports (with anonymity respected), message staff and admins, and view team roster information.
### Staff members You receive staff access by invitation; you can submit anonymous team feedback, optionally build a private wellbeing trend when signed in, use private diary/knowledge tools, submit anonymous or identified reports, and message your team manager or org admin.
### Platform administrators You support platform operation, organisation suspension, support tickets, and service announcements under separate internal access rules.
18. Contact
Privacy questions: privacy@frictioniq.io Support (in-app): Help & Support within your portal Website: https://frictioniq.io
*End of Privacy Policy v1.0 (Beta)*