Last updated: June 2026

Privacy Policy

This Privacy Policy explains how FrictionIndex collects, uses, stores, discloses and protects personal data in connection with the Platform. Please read it carefully. By accessing or using the Platform you acknowledge that you have read and understood this policy.

1. Data controller
FrictionIndex is the data controller in respect of personal data collected through the Platform. This means FrictionIndex determines the purposes and means of processing your personal data. This policy is governed by the laws of England and Wales and applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Personal data we collect
We collect the following categories of personal data: (a) Account and registration data — your name, work email address, organisation name, job title and any other information you provide when registering for or enquiring about the Platform. (b) Authentication data — your encrypted password credential and session tokens used to authenticate and maintain your logged-in session. Passwords are stored in hashed form and are not accessible to FrictionIndex personnel. (c) Usage and interaction data — information about how you interact with the Platform, including pages and features accessed, index readings viewed, sector pages visited, time spent on each area, navigation patterns, week navigation activity and feature toggle states. This data is collected automatically when you use the Platform. (d) Technical data — your IP address, approximate geographic location derived from IP address (country or region level only), browser type and version, device type and category, operating system and referral source. This data is collected automatically when you access the Platform. (e) Communications data — any correspondence, enquiries or feedback you submit to FrictionIndex via the Contact page, by email or by any other means. (f) Subscription and account management data — records of your subscription tier, access dates, account status changes and any tier updates made by administrators.
3. How we collect personal data
We collect personal data: (a) Directly from you — when you register for an account, submit an enquiry via the Contact page, communicate with us by email, or otherwise provide information to us. (b) Automatically — through session tokens, server logs and analytics tools when you access and interact with the Platform. Please see our Cookie Policy for further details on the technologies used to collect data automatically. (c) From our analytics provider — PostHog collects and processes usage and technical data on our behalf when you use the Platform. See section 6 for further details.
4. Purposes and legal bases for processing
We process your personal data for the following purposes and on the following legal bases: (a) Providing and managing the Platform — including authenticating your identity, maintaining your session, managing your account and subscription, and providing access to features appropriate to your subscription tier. Legal basis: performance of a contract. (b) Security and fraud prevention — monitoring access patterns to detect and prevent unauthorised access, credential sharing, fraudulent use or abuse of the Platform. Legal basis: legitimate interests (protecting the Platform, its infrastructure and other subscribers). (c) Platform analytics and improvement — collecting and analysing usage data to understand how the Platform is used, identify bugs or performance issues, and develop and improve features. Legal basis: legitimate interests (improving the Platform and service). (d) Communications — responding to enquiries, sending service-related notifications (such as account changes or subscription information) and communicating about material changes to the Platform or these policies. Legal basis: performance of a contract (for account-related communications); legitimate interests (for service communications). (e) Legal compliance — processing necessary to comply with applicable laws and regulations, to respond to regulatory enquiries or legal proceedings, or to enforce our rights under the Terms of Use. Legal basis: legal obligation; legitimate interests. We do not use your personal data for advertising purposes. We do not sell, rent or share your personal data with third parties for their own marketing purposes.
5. Automated decision-making
We do not make any decisions about you that produce legal or similarly significant effects solely by automated means. Subscription tier assignments are made by FrictionIndex administrators and are not automated decisions within the meaning of the UK GDPR.
6. Analytics — PostHog
We use PostHog, a product analytics platform, to help us understand how the Platform is used. PostHog processes usage and technical data on our behalf as a data processor acting under our instructions. We have configured PostHog to use its EU Cloud infrastructure, meaning data is processed on servers located within the European Economic Area. PostHog is subject to data processing agreements that require it to process data only in accordance with our instructions and in compliance with applicable data protection law. The data collected by PostHog on our behalf includes: pages visited and time spent; features and elements interacted with; session identifiers; browser and device information; and approximate geographic location derived from IP address. This data is used solely for the purpose of improving the Platform and is not shared with PostHog for its own commercial purposes. PostHog's own privacy policy is available at posthog.com/privacy. You can limit PostHog's data collection by managing your cookie preferences as described in the Cookie Policy.
7. Disclosure of personal data
We do not sell or transfer personal data to third parties for their own purposes. We may disclose personal data in the following limited circumstances: (a) Service providers — we engage third-party service providers who process personal data on our behalf as data processors, including hosting providers, authentication services and analytics providers (including PostHog as described above). All processors are bound by data processing agreements requiring them to process data only on our instructions and in accordance with applicable law. (b) Legal requirements — we may disclose personal data where required to do so by law, court order, regulatory authority or other legal process. Where permitted by law, we will endeavour to notify the affected individual before making such disclosure. (c) Business transfers — in the event of a merger, acquisition, restructuring or sale of all or part of FrictionIndex's business or assets, personal data may be transferred to the relevant third party as part of that transaction, subject to appropriate confidentiality arrangements. (d) Protection of rights — we may disclose personal data where necessary to protect the rights, property or safety of FrictionIndex, its subscribers or others, or to detect and prevent fraud or security incidents.
8. International data transfers
We endeavour to store and process personal data within the United Kingdom or the European Economic Area. Our primary infrastructure is hosted within the EEA. Where any transfer of personal data to a country outside the UK or EEA is necessary — for example, in connection with a service provider — we ensure that appropriate safeguards are in place in accordance with UK GDPR transfer requirements, including the use of UK International Data Transfer Agreements, standard contractual clauses approved by the Information Commissioner's Office, or other applicable transfer mechanisms.
9. Data retention
We retain personal data only for as long as is necessary to fulfil the purposes set out in this policy and to comply with our legal, regulatory and contractual obligations. Our specific retention periods are as follows: (a) Account data — retained for the duration of your active subscription and for six years following termination or expiry of your subscription, to comply with legal and contractual obligations. (b) Authentication data — session tokens are deleted on logout or after a period of inactivity. Hashed password credentials are retained for the duration of your account. (c) Usage and technical data — retained in identifiable form for up to 24 months from collection. Aggregated or anonymised analytics data may be retained indefinitely. (d) Communications data — retained for six years from the date of the communication. You may request deletion of your personal data at any time by contacting us. We will process deletion requests in accordance with your rights under the UK GDPR, subject to our legal obligations to retain certain data.
10. Your rights
Under the UK GDPR you have the following rights in relation to your personal data processed by FrictionIndex: (a) Right of access — you may request a copy of the personal data we hold about you. (b) Right to rectification — you may request that we correct any inaccurate or incomplete personal data. (c) Right to erasure — you may request deletion of your personal data in certain circumstances, including where it is no longer necessary for the purposes for which it was collected. (d) Right to restriction of processing — you may request that we restrict processing of your personal data in certain circumstances, for example while a query about accuracy is being resolved. (e) Right to data portability — you may request that we provide your personal data in a structured, commonly used and machine-readable format in certain circumstances. (f) Right to object — you may object to processing of your personal data where we rely on legitimate interests, including objecting to use of your data for analytics purposes. (g) Right to withdraw consent — where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To exercise any of these rights, please contact us via the Contact page. We will acknowledge your request within five working days and respond substantively within one calendar month. We may need to verify your identity before processing certain requests. If you are dissatisfied with how we have handled your personal data or responded to your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
11. Security
FrictionIndex implements appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, disclosure, alteration or destruction. These measures include: encrypted storage of authentication credentials using industry-standard hashing algorithms; encrypted data transmission using HTTPS/TLS protocols; role-based access controls restricting internal access to personal data on a need-to-know basis; and regular review of security practices. Notwithstanding the above, no method of transmission over the internet or electronic storage system is completely secure. We cannot guarantee the absolute security of data transmitted to or stored on the Platform. You transmit data to us at your own risk. You should ensure that the device and network you use to access the Platform are appropriately secured.
12. Cookies and similar technologies
We use cookies, session tokens and similar technologies to operate the Platform and to collect analytics data. Please see our Cookie Policy for full details of the cookies and technologies we use, their purposes and how you can manage them.
13. Children
The Platform is designed for professional and institutional use only and is not directed at children under the age of 18. We do not knowingly collect personal data from children. If we become aware that personal data has been provided by a child without parental consent, we will take steps to delete such data promptly.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law or the technologies we use. The date of the most recent revision is shown at the top of this page. Where changes are material, we will use reasonable endeavours to notify registered subscribers by email or via the Platform. Continued use of the Platform following any update constitutes acceptance of the revised policy. You should review this policy periodically.
15. Contact and complaints
For any privacy-related queries, to exercise your rights or to raise a concern about how we handle your personal data, please contact us via the Contact page on the Platform. We take all privacy concerns seriously and will respond promptly. If you remain dissatisfied following our response, you may escalate your complaint to the Information Commissioner's Office at ico.org.uk.