Skip to content

Privacy Policy

Effective date: 23 June 2026·Version: 3.0

← All policies

Draft for review — not yet legally verified.

1. Who we are

The ExQlo service is operated by TrustedPsych Ltd (company no. 15705041), registered office 71–75 Shelton Street, Covent Garden, London, England, WC2H 9JQ ("we", "us", "our"). We are the data controller for the personal data described in this policy.

Data Protection Lead: tom@exqlo.com · +44 (0)7525 475 964.

2. Where your data lives

By design, your core personal data is stored and processed within the UK and EEA. Our database, authentication and file storage run on Supabase in its EU region, and our application is hosted on Vercel in London. A small number of functional providers process limited data outside the UK/EEA under appropriate safeguards (see section 8).

3. What data we collect

  • Identity — name, job title, organisation.
  • Contact — email, phone, address.
  • Professional credentials — qualifications, regulatory numbers, CVs, references.
  • Profile content — biography, rates, expertise, availability, non-identifying case-history summaries.
  • Media — photographs, introduction videos, slides.
  • Usage and technical — IP address, device and browser information, logs.
  • Payment — billing details and the last four digits of a card; full card payments are handled by Stripe.
  • Communications — case-room messages (delivered in real time via Ably), documents shared in the Case Room (stored encrypted; see section 10), emails (sent via Postmark), SMS notifications (sent via Twilio), and support correspondence.
  • Safeguard records — where the Case Room chat detects that a message may contain identifying information and you choose to send it anyway, we record that a warning was shown and acknowledged, the categories detected (for example, an NHS number or a date of birth), and the time. We do not record the message content or the matched values.

Please do not upload patient or special-category data unless it is strictly necessary and you have a lawful basis and appropriate safeguards.

4. How we obtain data

We obtain data directly from you (registration, profile completion, uploads), automatically (cookies and similar technologies — see our Cookie Policy), and from third parties (payment confirmations, public professional registers and the open web, as described in section 5).

5. How we source experts (Talent Pool)

To build our directory we identify UK expert witnesses and interpreters from public professional registers and the open web, using automated search, and store this information securely in our database in the EU region. Where we hold information about you that you did not give us directly, this section is your notice under Article 14 of the UK GDPR.

  • What we hold — typically name, professional field, public contact details, and publicly available descriptions of expertise.
  • Why — to maintain a professional directory and, where our directory does not return enough matches for a Case Request, to suggest relevant experts as a fallback. We mark such suggestions clearly as inferred and unverified.
  • Lawful basis — our legitimate interests in operating a professional B2B directory (Article 6(1)(f)). We have balanced these against your interests and rights.
  • Your choices — you can object to this processing or ask us to erase your information at any time by emailing tom@exqlo.com; we will honour your request promptly.
  • Retention — we keep a sourced record for up to 24 months from the last meaningful activity, after which we review and delete it.

6. AI-assisted matching and enrichment

We use Anthropic's Claude models, via Anthropic's commercial API, to assess how suitable an Expert is for a Case Request and to help enrich directory information. The case summary and the relevant Expert profile are sent to this API to generate a suitability score and short rationale.

  • Data submitted to Anthropic's commercial API is not used to train any AI model.
  • A ExQlo administrator reviews every result, so this is not a solely-automated decision and it does not produce a legal or similarly significant effect on you (Article 22 UK GDPR).
  • If you have any concerns about this processing, contact tom@exqlo.com.

7. Lawful bases

We rely on: performance of a contract (providing the Service); legitimate interests (operating and securing the directory, sourcing experts, product improvement); legal obligation (accounting, tax and compliance); and consent where required (for example, certain marketing). You may withdraw consent at any time.

8. Sharing, processors and international transfers

We use a small number of service providers (processors). We do not sell personal data.

ProviderPurposeData location
SupabaseDatabase, authentication and file storage (EU region)UK/EEA
VercelApplication hosting and compute (London)UK/EEA
StripePayments, Connect accounts and payoutsUS (SCCs/IDTA)
AnthropicAI suitability matching and enrichment via its commercial API; inputs and outputs are not used to train any AI modelUS (SCCs/IDTA)
TwilioSMS notificationsUS (SCCs/IDTA)
PostmarkTransactional emailUS (SCCs/IDTA)
SlackInternal operational notificationsUS (SCCs/IDTA)

Where a provider processes data outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards such as the UK IDTA or EU Standard Contractual Clauses. As noted above, our core storage and hosting are within the UK/EEA.

9. Retention

  • Account data — for the life of the account plus 6 years.
  • Payment records7 years (tax and financial rules).
  • Usage and logs — up to 24 months.
  • Sourced directory records — up to 24 months from last meaningful activity (see section 5).

We may retain data longer where necessary to establish, exercise or defend legal claims, or to meet a legal obligation.

10. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, encryption of case-room messages at rest, end-to-end encryption of documents shared in the Case Room (encrypted on the sender's device, such that we cannot access their contents), access controls, and two-factor authentication for administrator accounts. We review and update these measures as our systems evolve.

11. Your rights

Subject to the UK GDPR, you may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent where consent is the basis. You may also complain to the Information Commissioner's Office (ICO). We aim to respond within one month of verifying your identity.

12. Children

The Service is for professionals aged 18 and over. We do not knowingly collect data from children.

13. Changes

We may update this policy and will highlight material changes by email or on our website. The effective date shows the current version.