Privacy Policy
Last updated: 16 September 2026
1. Who we are
This policy describes how Whole Elephant Research Company Limited (trading as The WERC App) uses personal data on thewerc.app. We are a UK company. For the purposes of UK GDPR we are a controller of Platform Data. Where you belong to a university or other institution tenant, that institution is typically a joint controller with us for that tenant's Platform Data. Roles for optional hosted research modules are explained in section 5 and in the institution's DPA.
General: hello@werc.uk · Privacy contact: dpo@werc.uk · Support: support@werc.uk
Registered office and Companies House number are stated on the signed Data Processing Addendum with your institution, and will be added here once confirmed.
2. What we collect
Account and platform data
- Name, email address, hashed password, optional two-factor authentication details
- Institution membership, role (participant, researcher, technician), department
- Confirmation that you are 18 or over
- Optional demographic answers used to match you with studies
- Study sign-ups, bookings, attendance, completion status, in-platform messages
- Points, reward claims, and related integrity or reliability records
- Technical data needed to run the service (for example IP address and browser on security events)
Special category data
Some demographic fields are special category data under UK GDPR (for example ethnicity, sexual orientation, or disability/health-related answers). Those fields are optional. We only store them if you provide them and confirm an extra in-product acknowledgement. We do not use them for advertising.
What we do not collect by default
- The contents of tasks on external tools such as Gorilla, Qualtrics, or Pavlovia. Those stay with the researcher or institution. We store completion and points, not the survey or experiment payload.
- Payment card details. Rewards are points and campus fulfilment, not card checkout on this platform.
- Medical records or clinical diagnoses as a healthcare provider. We are not a medical device or a care service.
Optional hosted modules: if your institution enables WE Wearables, WE Psychometrics, WE Neuro, or WE Biospecimens for a study you join, we will store the related research files or metrics as described in that study's materials and in section 5. Those modules are off unless the institution turns them on.
3. How we use data
- Create and secure your account
- Match you with studies and manage bookings, messages, and completions
- Operate points and rewards
- Protect the service (abuse, fraud, integrity reviews)
- Provide support and meet legal duties
- Improve the product using aggregated or non-identifying operational metrics we generate ourselves — we do not currently use third-party advertising or analytics cookies
4. Lawful bases
Under UK GDPR Article 6 we typically rely on:
- Contract — providing the account and platform features you asked for
- Legitimate interests — securing the service, preventing abuse, operating a multi-tenant campus product (balanced against your rights)
- Consent — optional demographics (especially special category fields) and any optional modules you opt into (for example Data Bank)
- Legal obligation — where we must keep records or respond to a competent authority
For special category data we rely on your explicit consent (Article 9), unless your institution's notice states another research condition that applies to hosted research data they control.
5. Who owns what
Platform data
Your profile, demographics, participation history, messages, and points are hosted by WE Research to run the service. With your institution we treat this as a joint-controller arrangement: they decide campus use and ethics; we decide how the product is built and hosted.
External study data
If a study sends you to Gorilla, Qualtrics, Pavlovia, or a similar tool, that researcher or institution owns the data they collect there under their own participant information sheet. Contact them about that data.
Hosted Data (only if enabled)
If a study uses WE Wearables, psychometrics, neuro files, or biospecimen results on this platform, we store those payloads under the study and participation record. Access is limited to authorised study staff and our processors. Neuro and biospecimen access is audited. Controller/processor roles are in the institution DPA and the study materials.
WERC Data Bank (only if you enrol)
If you opt into the WERC Data Bank, you may allow secondary licensing of eligible hosted data for WERC points (not cash). Buyers receive pseudonymised packages. They must not re-identify you. Leaving the Data Bank stops new licences; already fulfilled licences follow their terms.
6. Your rights
You can ask us to:
- Access a copy of your Platform Data
- Correct inaccurate data
- Erase data (subject to limited exceptions)
- Restrict or object to certain processing
- Receive data in a machine-readable form (portability)
Many of these are available in your account (export and delete). You can also email dpo@werc.uk. We will respond within 30 days. We may need to verify it is you.
Deleting your account removes platform profile data we hold. If you are in an active study, tell the research team as well — they may still hold external study data. If you own live studies or labs, you may need to transfer them before deletion can complete. We may retain security audit records as described in section 8.
You can complain to the Information Commissioner's Office. See also our Complaints Procedure.
7. Sharing and processors
We share data with:
- Your institution's authorised staff (technicians and, where the product allows, researchers on studies you join)
- Infrastructure processors: Supabase (database and files, EEA), Vercel (application hosting), Upstash (rate limiting), Resend (email), Cloudflare (Turnstile bot protection)
- Wearable providers (Garmin / Fitbit) only if you connect those accounts
Some processors may handle data in the United States. Where a UK restricted transfer occurs we rely on the provider's UK-approved transfer terms (adequacy, IDTA, or UK Addendum).
We do not sell your personal data.
8. Retention
We keep account and platform records while your account is active. If you delete your account we erase operational personal data, except where we must keep something for legal claims, security audit, or backup expiry. We do not keep a full copy of a deleted profile for a fixed two-year archive.
Hosted Data, if enabled, follows the study's retention setting and automated purge jobs. Data Bank inventory follows the enrolment choices you made (including any five-year policy).
9. Security
We use measures including:
- HTTPS (TLS) in transit and infrastructure encryption at rest
- Hashed passwords, optional authenticator two-factor authentication
- Institution isolation (application checks and database row-level security)
- Rate limiting and bot protection on signup
Special category answers are protected by access control and provider encryption at rest. They are not stored in a separate encrypted vault. No internet service is perfectly secure.
10. Children
The service is for people aged 18 or over.
11. Cookies
We use strictly necessary cookies and similar storage to sign you in and protect the service. See the Cookie Policy.
12. Breach notification
If a personal data breach is likely to result in a high risk to you, we will tell you without undue delay. We will notify the ICO where UK GDPR requires it (generally within 72 hours of becoming aware). Institutions are notified under their DPA, typically within 24 hours of us becoming aware.
13. Changes
We will post updates on this page and change the "Last updated" date. Material changes may also be notified in-product or by email where appropriate.
14. Contact
Whole Elephant Research Company Limited (The WERC App)
General: hello@werc.uk
Data protection: dpo@werc.uk
Support: support@werc.uk