Privacy
Privacy Policy
Last updated 17 July 2026 · Version 2026-07-17
Insights Research Ltd ("Insights", "we") provides a research and market-intelligence platform to UK mortgage and property firms. This policy explains what personal data we handle, why, for how long, and how you can exercise your rights under the UK GDPR and the Data Protection Act 2018.
Who is the controller?
For the Insights platform itself (accounts, billing, product usage), Insights Research Ltd is the data controller. For research content that customers upload or collect via surveys, the customer's organisation is the controller and Insights is the processor acting on their instructions.
Privacy contact: privacy@insights.co. Postal address is available on request.
What personal data we hold
The categories below are the complete list — if it is not here, we do not collect it.
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Registration email + hashed password | Create and secure the user account. | Performance of a contract | For the life of the account. 30 days after deletion. |
| Session tokens (JWT / refresh) | Keep the user signed in securely. | Performance of a contract | Rotated by Supabase Auth; invalidated on sign-out or deletion. |
| Password reset tokens | Allow the user to reset a forgotten password. | Performance of a contract | Single-use, expires within 1 hour. |
| Profile (full name, avatar) | Personalise the interface and identify the user to colleagues. | Performance of a contract | For the life of the account. |
| Organisation name, controller, DPO, contact details | Attribute research to the correct legal controller. | Performance of a contract | For the life of the organisation. |
| Invitation email address and token | Invite a colleague to an organisation. | Legitimate interests | Invitations expire after 7 days and are purged after 30 days. |
| Survey responses (answers, respondent email, consent) | Deliver research results to the survey owner. | Performance of a contract | Set by the organisation's retention policy; default 24 months. |
| Personalised respondent invitation tokens | Route respondents to the correct survey without collecting extra data. | Legitimate interests | Until the survey closes or is deleted. |
| Imported CSV / XLSX files | Analyse the organisation's own data alongside survey results. | Performance of a contract | Until deleted by the organisation. |
| AI analysis prompts and outputs | Summarise research findings. | Performance of a contract | For the life of the parent survey/dataset. |
| Reports, comments, share links | Publish findings to authorised clients. | Performance of a contract | For the life of the organisation. |
| In-app notifications | Alert users to comments, approvals and shared reports. | Legitimate interests | 12 months from creation. |
| Organisation activity log | Provide an audit trail for security and accountability. | Legal obligation | 24 months. |
| Report share view records | Confirm a client viewed a shared report. | Legitimate interests | 24 months. |
| Transactional email (invitations, alerts) | Deliver essential service communications. | Performance of a contract | Delivery logs held by the provider per their policy. |
| User consent records (cookies, marketing, AI improvements) | Prove valid consent for optional processing. | Legal obligation | Retained for the life of the account plus 24 months as evidence. |
| Subscription plan and status | Provide the paid product; recover subscription fees. | Performance of a contract | 7 years from last transaction (statutory). |
| IP address and user-agent (edge logs) | Protect the service against abuse and detect security incidents. | Legitimate interests | 30 days at the edge. |
| Cookies and browser storage | Sign-in, preferences and (with consent) analytics. | Consent | See Cookie Policy. |
| Contact form messages | Respond to sales and support enquiries. | Legitimate interests | 24 months from last contact. |
Automated processing and AI
Some features use AI models via the Lovable AI Gateway (Google Gemini) to summarise research content. Where free-text respondent answers are analysed we apply basic PII masking beforehand. AI outputs are always clearly labelled and never used to make legally significant decisions about a person. You may request human review of any AI output through the Privacy Centre once signed in.
International transfers
Application data is stored on servers in the European Union. Some sub-processors (notably the AI Gateway and edge network) may transfer data outside the UK/EEA under Standard Contractual Clauses and, where required, the UK International Data Transfer Addendum.
Your rights
You have the right to access, correct, erase, restrict, port, and object to processing of your personal data, and to withdraw any consent you have given. You can exercise these rights from the Privacy Centre inside the app (once signed in) or by emailing us. We aim to respond within 30 days.
If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk.
Security
All data is encrypted in transit and at rest. Access is scoped by row-level security policies keyed to your organisation and role. We keep an immutable audit log of privileged actions.
Changes to this policy
We will notify signed-in users of material changes at least 14 days before they take effect. Historic versions are available on request.