Policies
Data Protection
How we handle research data, commercial data and personal data supplied as part of a project.
Last updated 11 September 2026
Project data is different from account data
Our Privacy Policy covers the personal data you give us about yourself. This page covers the data you send us to work on — survey responses, interview transcripts, commercial records, research datasets.
We act on your instructions
For project data you remain the controller and we act as processor. We use that data only to carry out the work you asked for, and for nothing else.
We do not use client data to train models, build products, or as example material.
Practical measures
- Access is limited to the specialists working on your project.
- Every expert partner signs a confidentiality agreement before receiving material.
- Files are stored outside the public web directory under randomised names.
- Transfers happen over HTTPS; we do not ask you to email sensitive datasets.
- Data is deleted at the end of the retention period, or earlier on request.
Sensitive and special-category data
Health, biometric, criminal-justice and other special-category data needs extra care. Tell us before you send it.
Wherever possible we work on de-identified extracts. Where data genuinely cannot leave your environment, we can supply analysis scripts for your own team to run instead, and support them remotely.
Ethics approval
If your research requires ethics approval, that approval is yours to obtain and must be in place before data is collected. We can help you articulate the research components of an application, but we cannot obtain approval for you and will not analyse data collected without it.
Data processing agreements
For institutional and commercial clients we are happy to sign a data processing agreement setting out these commitments formally. Send yours, or ask us for ours.
Something here unclear, or does not cover your situation? Email scholarcraft.consultancy.service@gmail.com or message us on WhatsApp and we will answer plainly.