BeyondTheChange — Privacy Policy
Version 1.0
What we collect
Your name, email address, and (optionally) phone number, to create and secure your account. If you are a staff user, we also hold your staff code. If you administer BeyondTheChange for your organisation, we hold your organisation's contact details. We keep a record of security-relevant actions on your account (e.g. logins, role or permission changes), including the IP address and browser/device information associated with them.
Why we collect it
To provide you with access to BeyondTheChange, to keep your account secure, and to maintain the audit trail your organisation requires for its own governance and security obligations.
How long we keep it
Your account details are kept for as long as your organisation's subscription is active. If your account is deactivated, your personal details are anonymised 90 days later. Security and login records are kept for 12 months, then deleted.
Where it is processed
Data is processed and stored within your deployment's hosting environment as agreed with Meliora — for an on-premise deployment, this means it stays on your organisation's own infrastructure. BeyondTheChange's AI-assisted features run on a locally hosted model; no assessment or account data is sent to an external AI/LLM service.
Your rights
You may ask to see, correct, or request deletion of your personal data, subject to our legal and contractual obligation to retain some records (for example, audit logs your organisation needs for its own compliance).
Questions
Contact your organisation's BeyondTheChange administrator, who will escalate to Meliora's Data Protection Officer, with any question about this policy or your personal data.
