Privacy Policy
Effective date: 6 April 2026 · Last updated: 4 October 2026
RotationGrid (“we”, “us”, “our”) provides a training capacity planning platform for UK postgraduate medical education programmes. This privacy policy explains how we collect, use, store, and protect personal data when you use RotationGrid.
1. Who we are
RotationGrid is a trading name of Ben Sharif Limited, a company registered in England and Wales (company number 17060795) with its registered office at 32 Denison Way, Cardiff, CF5 4SF. Ben Sharif Limited is registered with the Information Commissioner’s Office (registration reference ZC247448).
RotationGrid is operated as a data processor on behalf of NHS organisations (deaneries, Health Education England local offices, and equivalent bodies) who act as the data controller. When you create an account directly with RotationGrid (e.g. via self-serve signup), we also act as a controller for your account data.
For questions about this policy, contact us at: [email protected]
2. What data we process
Account data (we are controller)
- Email address and display name
- Password (hashed, never stored in plain text)
- Login timestamps and session data
- Role and permission assignments
Trainee data (NHS organisation is controller, we are processor)
- Trainee name, email, phone number
- GMC registration number
- Training grade, status, start/completion dates
- Placement records (site, dates, duration, working time equivalent)
- ARCP (Annual Review of Competency Progression) event outcomes
- Administrative notes entered by programme directors
- Audit trail of all data changes
3. Lawful basis for processing
Trainee data: Article 6(1)(e) UK GDPR — processing necessary for the performance of a task carried out in the public interest. NHS organisations have statutory functions under the National Health Service Act 2006 to manage postgraduate medical education and training.
Account data: Article 6(1)(b) UK GDPR — processing necessary for the performance of a contract (your service agreement with RotationGrid).
Where ARCP records contain information relating to health (e.g. outcome reasons), additional conditions under Article 9(2)(b) UK GDPR and Schedule 1, paragraph 1 of the Data Protection Act 2018 apply.
4. How we use your data
- To provide the RotationGrid platform and its features
- To authenticate users and enforce access controls
- To maintain audit trails for data integrity and accountability
- To generate reports and analytics for programme management
- To send essential service communications (e.g. password resets, invitations)
- To monitor system health and diagnose errors
We do not use your data for marketing, profiling, automated decision-making, or sale to third parties.
5. Data sharing and sub-processors
We share personal data only with the following sub-processors, each under a Data Processing Agreement:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and authentication | UK (London, eu-west-2) |
| Railway | Application hosting | EU |
| Amazon Web Services (S3) | Encrypted backup storage | UK (London, eu-west-2) |
| Amazon Web Services (SES) | Transactional email delivery to signed-in users (for example the optional weekly validation-breach digest, whose contents can name a trainee) | UK (London, eu-west-2) |
| Sentry | Error monitoring (technical error data and account identifiers only — no trainee personal data) | EU (Frankfurt, Sentry EU data region) |
All trainee data is stored in the UK or EEA. Sentry stores its data in its EU region and receives only technical error data (stack traces, request paths) plus the account identifier of the signed-in user — never trainee personal information. Sentry is a US-headquartered company, so limited support access from outside the UK/EEA may occur under its Data Processing Agreement and Standard Contractual Clauses. We do not use Sentry Session Replay.
6. Data retention
Trainee records are retained for 6 years after training completion, in line with the NHS Records Management Code of Practice 2021 and the Limitation Act 1980. Individual NHS organisations may configure longer retention periods where required (e.g. for GMC fitness-to-practise investigations).
After the retention period, trainee records are anonymised: personal identifiers are removed while preserving aggregate operational data (placement patterns, capacity statistics).
Account data is retained for the duration of your account. If your account is deactivated, we retain basic records for 12 months before deletion.
Automated backups are kept for no longer than 90 days: daily backups for 14 days, weekly backups for 76 days, and our database provider's own daily backups for 7 days. After that they are deleted automatically.
7. Your rights
Under UK GDPR, you have the following rights regarding your personal data:
| Right | Details |
|---|---|
| Access (DSAR) | Request a copy of all data we hold about you. We respond within 1 calendar month. |
| Rectification | Request correction of inaccurate data. Programme directors can update records directly in the platform. |
| Erasure | Request deletion of your data. This may be refused during the retention period due to legal obligations and public interest grounds. |
| Objection | Object to processing on public interest grounds. We will assess your objection against the compelling legitimate grounds for processing. |
| Restriction | Request restriction of processing while a complaint or objection is resolved. |
| Complaint | Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk. |
Note: The right to data portability does not apply when the lawful basis is public task (Article 6(1)(e)).
To exercise any of these rights, contact [email protected].
8. Security measures
- Encryption: All data is encrypted in transit (TLS) and at rest (AES-256)
- Access control: Role-based access control (RBAC) with row-level security policies on all database tables
- Multi-tenancy: Strict data isolation between organisations and programmes
- Audit trail: Every data change is logged with user, timestamp, and change details
- Rate limiting: Protection against brute-force and scraping attacks
- Security headers: Content Security Policy, HSTS, X-Frame-Options via Helmet
- Input validation: All user input validated server-side before processing
- Data residency: All primary data stored in the UK (London, eu-west-2)
9. Cookies and local storage
RotationGrid uses only strictly necessary storage for authentication (Supabase session tokens in browser localStorage). We do not use analytics cookies, tracking pixels, or third-party advertising scripts. Cookie consent is therefore not required under PECR 2003.
10. Data breach notification
In the event of a personal data breach, we will notify the relevant data controller (NHS organisation) within 24–48 hours. The controller is responsible for notifying the ICO within 72 hours where required under Article 33 UK GDPR, and affected individuals under Article 34 where the breach poses a high risk.
11. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via the platform and to registered administrators by email. The “last updated” date at the top of this page reflects the most recent revision.