Who we are
Programme Insights Ltd is registered in England and Wales. We are the data controller for information processed through our platform and website. We are registered with the Information Commissioner's Office (ICO).
If you have questions about how we handle your data, contact us at james@programmeinsights.co.uk.
What data we collect
When you use the platform
- Documents you upload for assessment — programme documents, business cases, risk registers, benefits realisation plans, and similar project documentation
- Assessment results and scores — the findings, ratings, and evidence citations generated by our assessment pipeline
- Account information — your name, email address, and organisation
- Usage data — which modules you use, how often you run assessments, and how you interact with the platform
When you visit our website
- Standard analytics — pages visited, referral source, and device type
- No tracking cookies beyond essential session cookies for authentication and preferences
How we use your data
Documents: Your uploaded documents are processed through our assessment pipeline to generate findings, scores, and evidence citations. Document processing uses Azure OpenAI Service, hosted in UK data centres under Microsoft enterprise terms. Your data is not used to train AI models.
Account information: Used to provide the service, communicate about your account, and send service updates.
Usage data: Used to improve the platform and understand how modules are being used, so we can prioritise development.
We do not sell your data. We do not use your documents for marketing purposes. We do not share your data with third parties except as needed to provide the service through our Azure infrastructure.
Where your data is stored
All data is hosted in Azure UK South data centres. Your data remains within UK jurisdiction. No data is transferred outside the United Kingdom.
- Encryption at rest: AES-256
- Encryption in transit: TLS 1.2 or higher
Sub-processors
We use the following sub-processors to deliver the service:
- Microsoft Azure (UK South) — hosting, compute, and storage infrastructure
- Azure OpenAI Service (UK) — AI-powered document assessment and analysis
Both services operate under Microsoft enterprise terms. Under these terms, your data is explicitly excluded from model training. Microsoft does not access your data except as necessary to provide the service.
How long we keep your data
Documents and assessment results are retained for the duration of your subscription. When your subscription ends, all data is deleted within 30 days.
You can request deletion of your data at any time. We will confirm deletion in writing within 5 working days.
Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data
- Restriction — ask us to limit how we process your data
- Portability — receive your data in a structured, commonly used format
- Objection — object to specific types of processing
To exercise any of these rights, contact james@programmeinsights.co.uk. We respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Cookies
We use essential session cookies only. These handle authentication and remember your preferences. They are necessary for the platform to function.
We do not use third-party tracking cookies. We do not use advertising cookies. Our website analytics use privacy-respecting methods that do not require cookie consent.
SharePoint integration
When you connect your SharePoint document library, Programme Insights accesses your documents through the Microsoft Graph API using your organisation's OAuth consent.
- We read documents for assessment purposes only
- We do not modify, delete, or copy documents outside the assessment pipeline
- Access can be revoked at any time through your Azure AD / Entra ID admin portal
Changes to this policy
We will notify you of material changes to this policy by email. Minor clarifications or formatting changes may be made without notice.
Last updated: April 2026.
Contact
For any questions about this privacy policy or how we handle your data: