How We Protect Your Data
GDPR compliance and data security for your self-assessment
Minimal Data
We only collect what's needed
Encrypted
Your data is always encrypted
EU Stored
Data stays in the EU
Data Controller
The data controller responsible for your personal data is:
RSD-RS Initiative
Email: privacy@rsdrs.com
As data controller, we determine the purposes and means of processing your personal data and are responsible for compliance with data protection laws.
What Data We Store
For your self-assessment, we store:
- Email address – For sending your report and account identification
- Demographics – Age range, sex, country (for research)
- Purpose – Why you're taking the assessment
- Optional health data – ADHD subtype, co-occurring conditions (if provided)
- Assessment responses – Your answers and calculated scores
- Payment record – Transaction ID, amount, date (Stripe handles card details)
- Report token – A secure, unique link to access your report
- Timestamps – When you completed the assessment
What We Don't Store
We deliberately don't collect or store:
- Your name – We only need your email
- Your exact date of birth – Just an age range
- Your IP address – Not logged or stored
- Device fingerprints – No browser/device tracking
- Precise location – Only the country you select
- Browsing history – We don't track what you do elsewhere
- Credit card details – Stripe handles payments securely; we never see your card
- Social media data – No social logins or connections
- Third-party tracking cookies – No advertising or analytics trackers
Our philosophy is simple: we only collect what we need to deliver your report and contribute to research.
Security Measures
We implement comprehensive security measures:
- Encryption in transit: All connections use TLS 1.3 (HTTPS)
- Encryption at rest: Data encrypted with AES-256
- Secure payments: Stripe handles all payment processing (PCI DSS Level 1 compliant)
- Access controls: Only authorised systems can access your data
- Report security: Your report link uses a 64-character cryptographically secure token
- Database security: Row-level security policies, encrypted backups
- No shared hosting: Dedicated database instances
How Long We Keep Your Data
- Report access token: Expires after 90 days (for security)
- Assessment data: Retained for research purposes (anonymised after 2 years)
- Email address: Kept until you request deletion
- Payment records: 7 years (UK legal requirement for financial records)
You can request deletion of your data at any time. Note that anonymised research data cannot be deleted as it is no longer linked to you.
Your Rights Under GDPR
You have the following rights under the General Data Protection Regulation:
- Right of Access (Article 15) – Receive a copy of your personal data
- Right to Rectification (Article 16) – Correct inaccurate personal data
- Right to Erasure (Article 17) – Request deletion of your data
- Right to Restrict Processing (Article 18) – Limit how we use your data
- Right to Data Portability (Article 20) – Receive your data in a machine-readable format
- Right to Object (Article 21) – Object to processing based on legitimate interests
- Right to Withdraw Consent (Article 7) – Withdraw consent where processing is based on consent
To exercise any of these rights, email privacy@rsdrs.com
We will respond within 30 days. There is no fee for exercising your rights unless your request is manifestly unfounded or excessive.
Legal Basis for Processing
We process your data under the following legal bases:
| Data | Legal Basis |
|---|---|
| Email, assessment responses | Contract (Article 6(1)(b)) |
| Payment records | Legal obligation (Article 6(1)(c)) |
| Anonymised research data | Legitimate interest (Article 6(1)(f)) |
| ADHD status, health conditions | Explicit consent (Article 9(2)(a)) |
Third-Party Processors
We use trusted service providers who process data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting | EU (Frankfurt) |
| Stripe | Payment processing | US (EU-US DPF) |
| Resend | Email delivery | US (SCCs) |
| Vercel | Website hosting | Global (SCCs) |
All providers have Data Processing Agreements (DPAs) in place. For US providers, we rely on the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).
International Transfers
Your data is primarily stored in the European Union (Supabase EU servers in Frankfurt). Some processing occurs in the United States through our service providers.
For transfers to the US, we ensure adequate protection through:
- EU-US Data Privacy Framework – Providers certified under the DPF
- Standard Contractual Clauses – EU Commission-approved contracts
- Supplementary measures – Additional technical safeguards where needed
Data Breach Notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms:
- We will notify the ICO within 72 hours of becoming aware
- We will notify you directly if there is a high risk to your rights
- We will document all breaches and our response
Automated Decision-Making
Your assessment scores are calculated automatically based on your responses using a standardised scoring algorithm. This calculation:
- Is necessary to provide the service you requested
- Does not make decisions that legally or significantly affect you
- Is used for informational purposes only (not diagnosis)
You can request human review of your scores by contacting support@rsdrs.com.
Questions or Complaints
If you have questions about how we handle your data, contact us first:
Email: privacy@rsdrs.com
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
This data protection information applies specifically to the self-assessment service. For our full organisational policies, see our complete Privacy Policy.
Last updated: January 2025