This notice explains what personal data the Trustworthy and Ethical Assurance (TEA) Platform ("we", "us") collects, why, how long we keep it, and how you can remove it. The Platform is provided by The Alan Turing Institute, which is the data controller for the personal data described here. This notice summarises what the Platform does with your data; the Institute's full privacy notice has the legal and contact details, including how to contact the Institute's Data Protection Officer. Contact for the Platform: tea@turing.ac.uk.
We use only essential cookies, for signing you in and keeping your session. See the Cookie Notice.
To run your account, to let you build and share assurance cases, to send the account emails above, and to keep the Platform secure. We do not sell personal data, use it for advertising, or share it with third parties except the providers that host and deliver the service (Microsoft Azure for hosting, storage and email; GitHub and Google when you choose to sign in or connect with them).
We process your account details and your contributions to the Platform because it is necessary for the legitimate interests of The Alan Turing Institute: to provide and run the Platform, to conduct research and further the work of the Institute, and to evaluate and improve the service. The Platform uses only essential cookies, which do not require your consent (see the Cookie Notice). We do not run a mailing list or newsletter from the Platform.
When you connect Google, we ask for the drive.file permission. This lets the Platform see, create and change only the files it creates in your Drive, or that you open with it. It does not give us access to the rest of your Drive. We use it to create a TEA folder in your Drive and to save exports of your cases there when you ask, and to read back files you have chosen to link to a case.
The tokens are stored in our database and sent only over encrypted connections. We use them only to make the Drive requests you trigger. We do not use Google user data for advertising, do not sell it, and do not let humans read it except with your permission, for security purposes, or to comply with the law. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google at any time from Settings → Connected accounts, which deletes the stored tokens, or by revoking the Platform's access from your Google account permissions.
We keep your account and content while you use the Platform. If you do not log in for two years we warn you by email 30 days and 7 days before deleting the account, and then delete it. The full rules are in the Data Retention Policy.
You can delete your account from Settings. When an account is deleted: cases you own that have another Admin are kept under that Admin; cases with no other Admin are deleted; your name is removed from comments on cases that are kept; your account details, sign-in identifiers and tokens are deleted. If you own any integrations you must remove them first.
The Platform runs on Microsoft Azure in the United Kingdom: the application, database and file storage are in the UK South region, and account emails are sent through Azure Communication Services with its data location set to the UK.
We will update this notice when the Platform's data handling changes and show the date of the last change here. Questions: tea@turing.ac.uk.
Last updated: September 2026
This site uses essential cookies to support authentication of registered users only.