Draft for legal and operational completion
Do not publish this as the final policy until the bracketed company details, providers, hosting locations, lawful bases and retention decisions have been completed and approved.
Privacy and trust
Culturevating OS privacy policy
Draft dated 6 August 2026 · Version 0.1
1. Who we are
Culturevating OS is operated by Not Usual Ltd (“Not Usual”, “we”, “us”). Our registered office is [insert registered address], company number [insert company number]. Contact our privacy lead at [insert privacy email].
For account administration, billing, platform security and our own website, Not Usual will normally act as a controller. When a client organisation uses Culturevating OS to process information about its workers, customers or partners, that client will normally determine the purposes and act as controller, while Not Usual acts as its processor. The relevant contract and data processing agreement must confirm these roles for each deployment.
2. What this policy covers
This policy covers the Culturevating website, administration areas, Bridgit conversations, Microsoft 365 connections, uploaded evidence, organisational diagnostics and related support. A client organisation must also provide its own privacy information where it decides how Culturevating is used with its people or customers.
Data control and deployment choices
A subscription level does not determine whether a client can access or control its organisational data. Clients should be able to obtain usable exports and follow documented offboarding and deletion processes at every service level. An upgrade changes where information is hosted and who operates the technical environment; it does not sell ownership or data-subject rights back to the client.
Culturevating Cloud
Not Usual operates the SaaS and structured data environment under the agreed controller/processor terms.
Connected Garden
Culturevating provides intelligence while approved documents can remain in the client’s SharePoint tenant.
Tenant-Owned Garden
Dataverse, SharePoint and Garden records operate in the client’s approved Power Platform environment, with restricted support access for Not Usual.
The Account data-location map should identify the active model, storage locations, relevant controller, permitted access and available export format for each data category. Final contracts must define data return, migration assistance, deletion, backup expiry and any charges for technical migration services.
3. Information, purposes and lawful bases
| Category | Examples | Purpose | Potential basis |
|---|---|---|---|
| Account and identity | Name, work email, Microsoft identifiers, role, organisation and sign-in events | Provide and secure accounts; administer access | Contract, legitimate interests and security obligations, depending on context |
| Organisation directory | Microsoft 365 teams, direct memberships, job title, department and office location | Scope access and provide team or specialist insight | The client organisation must identify and document its lawful basis |
| Culturevating activity | Goals, ideas, diagnostic answers, plans, documents, conversations, evidence and outcomes | Provide requested diagnostics, collaboration and organisational intelligence | Usually contract for service delivery; the client determines its basis for workforce processing |
| Derived intelligence | Themes, summaries, competency signals, connections and recommendations | Help users and organisations understand patterns and opportunities | Depends on the underlying purpose and lawful basis; outputs require human review |
| Billing | Billing contacts, subscription, invoices, payment references and limited card descriptors | Manage subscriptions, payments, accounting and disputes | Contract and legal obligations |
| Technical and security | IP address, device/browser information, timestamps, logs and audit events | Operate, protect and troubleshoot the service | Legitimate interests and legal/security obligations |
| Website choices | Cookie consent, language and interface preferences | Remember choices and control optional technology | Legal exemption where strictly necessary; consent for non-essential purposes |
Launch decision required: complete a processing record and confirm the lawful basis for every enabled purpose. Consent should not automatically be assumed appropriate in an employment relationship.
4. Microsoft 365
Where an authorised organisation connects Microsoft 365, Culturevating can read approved directory information through Microsoft Graph, including teams, direct memberships and limited user profile information. We use stable Microsoft identifiers to maintain scope. Culturevating does not change Microsoft team membership through the current integration.
Future access to meetings, messages, email or documents must not be enabled merely because directory access exists. Each additional source needs a documented purpose, minimum permission, transparency information, retention rule and—where required—a data protection impact assessment.
5. Bridgit and artificial intelligence
Bridgit is intended to help organise information, support reflection, identify patterns and suggest questions or connections. AI output may be incomplete or wrong and should be reviewed by an appropriate person before decisions are made.
- We do not intend Bridgit to make solely automated decisions producing legal or similarly significant effects.
- Private personal conversations should not be visible to organisation administrators unless the individual deliberately shares them or a clearly documented exceptional legal process applies.
- Client content must not be used to train a provider’s general models unless the controller has expressly approved this and the legal, contractual and transparency requirements are satisfied.
- We must publish the AI and hosting providers, processing locations, retention settings and contractual safeguards before live AI processing begins: [insert approved provider register].
6. Teams, specialisms and workplace insight
Access is intended to follow role and scope. Members see their own information; Insight Leads see aggregated information for assigned teams or specialisms; Organisation Administrators see approved organisation-level aggregates. Platform Administrators should not have routine access to client content.
Team and specialism reporting should use a minimum cohort of five contributing people. Culturevating must not infer sensitive characteristics such as health, ethnicity, beliefs, sexual orientation or trade-union membership. Information collected to support learning and innovation must not quietly be reused for individual performance management.
7. Sharing and processors
We may use carefully selected providers for hosting, authentication, AI, communications, billing and support. We will require appropriate contracts, confidentiality, security and deletion commitments. The final policy must name or link to the current subprocessors: [insert subprocessor register and notification process].
We may disclose information where required by law, to protect rights or security, or as part of a properly managed corporate transaction. We do not sell personal information.
8. International transfers
The final hosting and provider architecture will determine whether information leaves the UK. Before an international transfer is enabled, we will identify the transfer mechanism, assess relevant risks and apply supplementary safeguards where necessary. [insert hosting regions and transfer safeguards].
9. Retention
We keep identifiable information only for as long as needed for the documented purpose, contractual obligations, legal requirements and dispute handling. The production service will enforce an approved retention schedule covering personal reflections, organisational seasons, source documents, derived insight, audit logs, support records and billing information.
Launch decision required: agree exact periods, deletion workflows, client-configurable rules, backup expiry and what happens when an organisation or individual leaves. Cookie preferences currently expire after approximately six months.
10. Security and access
We use measures intended to protect confidentiality, integrity and availability, including Microsoft authentication, server-side role checks, tenant-scoped access, minimum permissions and audit requirements. Production readiness additionally requires database row-level controls, encryption, secrets management, tested backups, vulnerability management, incident response and periodic access reviews.
Not Usual support access to client content should be time-limited, purpose-bound, approved and audited rather than permanently available.
11. Your rights
Depending on the circumstances, you may have rights to be informed, access information, correct it, have it erased, restrict or object to processing, receive portable information, and raise concerns about automated decision-making. Where a client organisation controls the information, we may direct your request to that organisation and assist it as processor.
Contact [insert privacy email]. We may need to verify identity and clarify the information involved. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.
12. Cookies, changes and contact
Our cookie information explains browser storage and how to change choices. We will review this policy when purposes, providers or technology change and show the effective date and material updates.