C
COBE Intelligence
Privacy Policy

Draft — pending legal review

This page is a working draft grounded in how the platform actually operates today. It has not yet been reviewed or approved by a qualified solicitor and should not be relied on as final legal terms until it has. Bracketed fields [like this] mark details COBE Research needs to confirm before publishing.

Last updated 07 October 2026

Privacy Policy

Who we are

About this policy

COBE Intelligence is operated by COBE Research CIC ("COBE Research", "we", "us"), a Community Interest Company registered in England and Wales (company number [registration number], registered office [registered address]). This policy explains what personal data we process, why, and what rights you have — whether you're an employee using the platform through your employer, an administrator managing your organisation's account, or a prospective customer.

If you're an employee, your own employer's workplace privacy notice (where they have one) sits alongside this policy — it explains what your employer specifically does with the results. This policy is COBE Research's own account of how the platform itself handles your data. See also our in-product Trust & Privacy page, which explains in plain terms how individual answers are protected before you're ever asked to take an assessment.

Data

What we collect

CategoryExamples
Account data Name, work email, role, organisation, login activity
Assessment and survey responses Answers to wellbeing, burnout, psychological safety, retention-risk and related questions, including open-text responses and, where an assessment asks for them, demographic details relevant to identifying workplace disparities. Some of this is "special category" data under UK GDPR (e.g. information relating to health or ethnicity) — see Legal basis below for how we handle it.
Technical data IP address, browser/device information, and security event logs (e.g. login and MFA activity)

Roles

How we use your data

We act in two different capacities, and it matters which one applies:

As a processor, on your employer's instructions. Your individual assessment answers are processed to generate your own results and, combined with your colleagues' answers, your employer's aggregate reporting. Your employer is the data controller for this data — they decide what it's used for and how long it's kept. We only ever show your employer aggregated, anonymised results, and never for a group smaller than the Rule of Ten minimum (see Trust & Privacy) — your individual answers are never visible to your employer.

As a controller, in our own right. We process account and billing contact details to run the service and manage the relationship with your organisation, and — only with your explicit, separately-given consent at the point you take an assessment, and only ever in de-identified, aggregated form meeting the same Rule of Ten protection — we may use response data for COBE Research's own published research into workplace equity. You can decline this and still use the platform.

Lawful basis

Legal basis for processing

  • Account and billing data: performance of our contract with your employer.
  • Standard assessment data processed on your employer's behalf: your employer's own lawful basis (typically legitimate interests in monitoring workplace wellbeing, or consent, depending on their policy).
  • Special category data (health-adjacent and demographic responses): your explicit consent, captured through the in-product Trust & Privacy consent step before you can take an assessment. You can withdraw this consent at any time by contacting us; withdrawing it does not affect data already processed.
  • Security and fraud prevention: our legitimate interest in keeping the platform and your account secure.

Protection

How we protect your data

  • Open-text and other sensitive response fields are encrypted at the application layer, not just at rest on disk.
  • Multi-factor authentication is mandatory for every administrator account, with optional SSO (OIDC/SAML) for organisations that centralise identity through their own provider.
  • Backups are encrypted and tested against a defined recovery point and recovery time objective.
  • Aggregate reporting to employers is suppressed automatically below the Rule of Ten minimum — a group too small to protect anonymity is never shown, no exceptions.
  • Error monitoring is configured to exclude personal and mental-health-adjacent request data by default, so it never leaves the platform for a third-party diagnostic tool.

Retention

How long we keep it

[COBE Research to confirm retention periods] — as a starting position: account data for the lifetime of your organisation's licence plus a limited period afterwards for legal and accounting purposes; assessment response data for as long as your employer's contract with us remains active, unless your employer instructs us to delete it sooner. Security logs are retained for a shorter, fixed period sufficient to investigate incidents.

Sharing

Sub-processors

We use a small number of specialist providers to run the service. Each is bound by its own data processing terms with us.

ProviderPurposeLocation
Sentry Error monitoring (personal and mental-health-adjacent data excluded by default) [region]
[hosting provider] Application hosting and database infrastructure [region]
[email provider] Transactional email (e.g. event reminders, notifications) [region]

We do not sell personal data, and we do not share assessment response data with any third party for their own marketing purposes.

Transfers

International data transfers

[COBE Research to confirm hosting region and, if any sub-processor is located outside the UK/EEA, the transfer mechanism used — e.g. the UK International Data Transfer Addendum to the EU Standard Contractual Clauses].

Rights

Your rights

Under UK GDPR you have the right to request access to, correction of, or erasure of your personal data, to restrict or object to certain processing, and to receive a copy of your data in a portable format.

To exercise any of these rights, contact us at hello@costofblackexcellence.com. Where the data in question was provided through your employer's use of the platform, we may need to direct your request to them as the data controller, and will tell you if that's the case.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.

Scope

Children's data

COBE Intelligence is a workplace platform intended for use by employees of our customer organisations. It is not directed at, and we do not knowingly collect data from, children.

Changes

Updates to this policy

We'll update the date at the top of this page whenever this policy changes, and will tell customer administrators directly of any material change. Contact hello@costofblackexcellence.com with any questions.

Privacy Policy · Terms of Service · DPA · Accessibility Statement