Privacy Policy for Advisers

Last Updated: 18/10/2025

This privacy policy applies to advisers and staff who use the PalmFlow dashboard. If you are a client completing a PIP form through PalmFlow, a separate privacy notice will be shown to you before you begin.

PalmFlow provides a secure platform for advisory organisations to assist clients with Personal Independence Payment (PIP) applications. This policy explains how we handle information about advisers who use our service.

1. Who We Are

PalmFlow is operated by Digital Palm Ltd.

For adviser accounts: PalmFlow acts as Data Controller for information about advisers (your account, login details, usage).

For client data: Your organisation (Citizens Advice bureau, local council, NHS body, or other advisory service) is the Data Controller. PalmFlow acts only as Data Processor, providing the technical platform on your organisation's behalf.

2. Information We Collect About Advisers

Account Information

Authentication Data

Usage Data

Technical Data

What We Do NOT Collect

We do not collect or store the actual health information that clients provide in their PIP forms when viewing it through the dashboard. Client health data is stored separately and controlled by your organisation.

3. How We Use Adviser Information

Legal Basis

We process adviser information under GDPR Article 6(1)(b) - Contract (necessary to provide the service to your organisation) and Article 6(1)(f) - Legitimate Interests (maintaining system security and improving our service).

Purposes

4. Information Sharing

Within Your Organisation

Your organisation's administrators can view:

Sub-Processors (Third Parties)

We use the following sub-processors to deliver our service:

Supabase (Database & Authentication)

Vercel (Application Hosting)

Azure OpenAI (Primary AI Processor)

OpenAI (Fallback AI Processor)

Legal Obligations

We may disclose information if required by law, court order, or regulatory authority, including:

Business Transfers

If PalmFlow is acquired or merged with another company, adviser information may be transferred to the new entity. We will notify you at least 30 days in advance and provide options to delete your account if you object.

What We Never Do

We do not and will never:

5. Data Security

We implement comprehensive security measures to protect adviser accounts and client data:

Technical Controls

Organisational Controls

Data Segregation

6. Data Retention

Adviser Accounts

Active accounts: Retained while you remain employed at your organisation and use the service.

Deactivated accounts: When you leave your organisation, your account is deactivated. Your historical records (session creation history, audit logs) are retained for 2 years for accountability purposes, then permanently deleted.

Organisation cancellation: If your organisation cancels PalmFlow service, all adviser accounts are deactivated immediately. Data is retained for 30 days to allow data export, then permanently deleted.

Client Health Data

Your organisation controls retention of client PIP form data based on their regulatory requirements and internal policies:

Deletion is automated and includes:

7. Your Rights as an Adviser

Under UK GDPR, you have the following rights regarding your adviser account information:

Right of Access

Request a copy of all information we hold about you as an adviser (Subject Access Request).

Right to Rectification

Correct inaccurate or incomplete account information (name, email, role).

Right to Erasure

Request deletion of your account when you leave your organisation. Note: Some records may be retained for legal compliance (e.g., audit logs for accountability).

Right to Restrict Processing

Request we limit how we use your information while a dispute is resolved.

Right to Data Portability

Receive your account information in a machine-readable format (JSON export).

Right to Object

Object to processing based on legitimate interests (e.g., analytics). We will stop unless we have compelling legal grounds.

How to Exercise Your Rights

Contact your organisation's PalmFlow administrator, or email us directly at policy@digitalpalm.co.uk. We will respond within 30 days (1 month).

Right to Complain

If you're unhappy with how we handle your information, you can complain to:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113

8. Client Data (Brief Summary)

This section is a brief summary only. Clients see a separate, detailed privacy notice before providing health information.

Your organisation is the Data Controller for all client PIP form data. PalmFlow acts only as Data Processor, providing the technical platform.

What clients provide: Health condition information, daily living limitations, mobility restrictions (no names, addresses, or contact details by design).

How it's processed:

Legal basis: GDPR Article 9(2)(h) - provision of health and social care services (PIP assistance constitutes social care).

Client rights: Clients exercise data subject rights (access, deletion, rectification) through your organisation as Data Controller.

9. International Data Transfers

Default: UK Processing Only

Adviser account information and client health data are processed and stored in the United Kingdom by default:

Exception: OpenAI US (Fallback for Client Data Only)

When Azure OpenAI UK is unavailable, client health information (not adviser accounts) may be processed via OpenAI's US servers. This constitutes an international transfer to a third country.

Safeguards:

Your adviser account information never leaves the UK.

10. Cookies and Tracking

We use essential cookies only:

Strictly Necessary Cookies

We do not use:

You can disable cookies in your browser, but this will prevent you from logging in to PalmFlow.

11. Automated Decision-Making

PalmFlow does not make automated decisions about advisers or clients.

AI is used to generate draft summaries of client responses, but:

12. Children's Privacy

PalmFlow is not intended for use by children under 16. Adviser accounts should only be created for employed or contracted staff members. If we become aware that an account was created for a child under 16, we will delete it immediately.

Clients completing PIP forms may be under 16 (accompanied by a parent/guardian). The client privacy notice addresses this scenario separately.

13. Changes to This Privacy Policy

We may update this policy to reflect changes in our practices, legal requirements, or service features.

How we notify you:

Material changes (affecting your rights or how we use data) will be notified at least 30 days in advance. Your continued use of PalmFlow after the effective date constitutes acceptance of the updated policy.

If you disagree with changes, you may request account deletion by contacting your organisation administrator or emailing us directly.

14. Data Protection Officer

For organisations processing large volumes of sensitive data, we recommend appointing a Data Protection Officer (DPO). If your organisation has a DPO, please inform us so we can coordinate on data protection matters.

PalmFlow does not currently have a formal DPO as we process data solely on behalf of Controller organisations. However, data protection queries should be directed to the contact details below.

Contact Information

For Advisers (Your Account)

Questions about your adviser account, privacy rights, or this policy:

Email: policy@digitalpalm.co.uk
Address: Digital Palm Ltd, 5 Brunswick Avenue, London, N11 1HP
Response time: 5 business days

For Client Data Protection Queries

Clients should contact the organisation that provided their PalmFlow access (Citizens Advice, council, NHS body, etc.). That organisation is the Data Controller for client information.

Organisations acting as Data Controllers can contact us for technical assistance with data subject requests at the email above.

Regulatory Authority

Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF