DP DiasporaPulse™by Epicurean Digital Consultants Ltd TR · Türkçe ← Back to Platform

Privacy Policy

How we collect, use and protect personal data under UK GDPR · Last updated 19 September 2026 · Version 2.0

1. Who we are

Epicurean Digital Consultants Ltd (“we”), trading as DiasporaPulse™, is the data controller for personal data processed through this platform. We are registered in England and Wales (Company No. 16622200).

For any question about this policy or your rights, contact hello@epicureandigitalconsultants.com.

2. What we collect

CategoryExamplesWhy
Account dataEmail address, authentication identifiersTo create and secure your account
Verification dataPostcode district; a mobile number only once payouts are introducedTo reduce fraudulent and duplicate participation
Research profileDemographic and cultural profile answers you choose to giveTo match you to relevant studies
Study responsesAnswers you submit to a studyTo produce research findings for clients
Reward recordsPoints ledger, redemption and payout recordsTo pay you and meet accounting obligations
Technical dataSession identifiers, security and audit logsTo keep the platform secure and diagnose faults

3. Special category data

Some profile fields — for example ethnicity, national origin, language or religious observance where it affects consumer behaviour — are special category data under UK GDPR Article 9. We process these only where you have given explicit, separate, freely given consent, recorded against a versioned consent document. You may withdraw that consent at any time without affecting your account.

Sensitive profile values are never transmitted in email notifications.

4. Lawful bases

Consent (Art. 6(1)(a) and Art. 9(2)(a))
Panel participation, research profiling, and all special category data.
Contract (Art. 6(1)(b))
Operating your account and paying rewards you have earned.
Legal obligation (Art. 6(1)(c))
Financial and tax records relating to payouts.
Legitimate interests (Art. 6(1)(f))
Platform security, fraud and quality control. We balance these against your rights and do not use them for profiling that produces legal effects.

5. Who we share with

We do not sell personal data. We share it only with the processors needed to run the service, each under a written processing agreement and only on our instructions:

ProcessorWhat it doesWhere data is held
SupabaseDatabase, accounts and sign-inUnited Kingdom / European Economic Area
ResendSends our service and study emailsEuropean Economic Area, with UK transfer safeguards
HostingerHosts the websiteEuropean Economic Area
TwilioSends the one-time code that verifies your mobile numberUnited States, under the UK International Data Transfer Addendum

Reward vouchers are currently bought by us directly from the retailer (Amazon or Tesco) and the code is sent to you by us. The retailer does not receive your name, email address or any other detail about you.

We will publish any change to this list here before it takes effect.

Clients never receive your identity. Research findings are delivered aggregated or with direct identifiers removed.

6. International transfers

Our primary data storage is in the United Kingdom or European Economic Area. Where a processor transfers data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

7. How long we keep it

We keep personal data only as long as we need it, and no longer. These are the periods we work to. Where a period is set by law we say so; the others are our own defensible defaults, reviewed annually.

WhatHow longThen what
Your account and profileWhile your account is open, then 30 daysDeleted. The 30 days allow recovery from an accidental deletion or an account takeover
Special category answers (community, faith, diet)Deleted as soon as you withdraw that consentDeleted immediately, not at 30 days
Study answers12 months linked to youSeparated from you and kept only in aggregate
Consent records6 yearsKept as proof of consent, then the link to you is removed. UK GDPR requires us to be able to demonstrate consent
Points ledger and payment records6 years (required by tax law)Pseudonymised, then deleted
Quality review decisions6 yearsAnonymised after 12 months
Study invitations24 monthsAnonymised
Email delivery log12 monthsDeleted. The log holds a one-way hash, not your address
Security and access logs2 years, or 6 years where they evidence a paymentActor anonymised, then deleted
Deletion requests6 yearsKept as proof that we honoured your request, with your identity removed
Enquiries and panel-interest sign-ups24 months from last contactDeleted

If you delete your account we remove your personal data within one month. Financial and audit records in the table above are kept for the periods shown, with your identity removed. Research results already published to a client do not change, because they contain no identifiers.

8. Your rights

Under UK GDPR you have the right to access your data, correct it, erase it, restrict or object to processing, obtain portability, and withdraw consent at any time. You will never be penalised for exercising a right, and withdrawing consent does not affect rewards already earned.

To exercise a right, email hello@epicureandigitalconsultants.com. We respond within one month. You may also complain to the ICO at ico.org.uk, though we would prefer the chance to put things right first.

9. Security

Access to your data is enforced at the database level by row-level security, so one participant cannot read another’s records and one client cannot read another’s studies. Administrative access requires multi-factor authentication and is written to an append-only audit trail. Email notifications identify recipients by a one-way hash rather than storing the address in the log.

10. Decisions, and who can join

We make no decision about you by automated means alone that produces a legal or similarly significant effect. Quality checks flag a response for review; a person decides the outcome, and you can ask us to look again. The panel is for adults: you must be 18 or over to join, and we do not knowingly hold data about children.

11. Changes

If we change this policy materially we will tell you and, where the change affects a consent you have given, ask you to review it again.