Data & Privacy Policy
How WhichAudit collects, stores, and protects your information
Last updated: March 2026 · Version 1.2
Who we are and what this covers
WhichAudit is an independent clinical audit repository operated by an NHS clinician. This policy explains what personal data we collect when you use the site, how it is used, and your rights under UK GDPR and the Data Protection Act 2018.
This policy applies to all users of whichaudit.co.uk, including visitors who browse projects and individuals who submit audit records.
What information we process
When you browse the site
Browsing WhichAudit does not require an account and we do not use tracking cookies. Standard web server logs may temporarily record your IP address and the pages you visit as part of normal server operation. These logs are not linked to any identity and are not retained beyond 30 days.
When you submit an audit
We collect:
- Project content — project name, type, NHS trust, specialty, year, guidelines referenced, background, aims, objectives, and keywords. This is public-facing content.
- Email address — collected at submission to prevent spam and duplicate entries. Your email address is immediately and irreversibly hashed using PBKDF2-SHA256 before storage. The original address is never retained and cannot be recovered.
- Submission metadata — timestamp and data classification tag. No IP address is logged against submissions.
When you leave a comment
Comments are stored against the project they relate to. No name or identifying information is required. All comments are moderated before publication.
Our strict no-patient-data policy
WhichAudit does not accept, store, or display any patient-identifiable information under any circumstances. Submitters are explicitly required to confirm compliance before submission can be completed.
The submission form captures audit methodology only — background, aims, and objectives — not patient outcomes, results, or any data that could be used to identify individuals. If a submission is found to contain patient-identifiable data, it will be immediately deleted and the submitter notified.
Every submission is manually reviewed before approval, providing an additional safeguard against inadvertent disclosure.
Purposes and legal basis
Publishing audit content
Consent (submission)By submitting a project, you consent to the content being published publicly on WhichAudit under open access terms.
Preventing duplicate submissions
Legitimate interestThe hashed email is used to detect and prevent the same audit being submitted multiple times.
Moderating comments
Legitimate interestWe review comments before publishing to prevent spam and ensure quality.
Platform analytics
Legitimate interestAggregated, non-personal view counts are tracked per project to show popularity. No individual tracking.
Who can see your data
We do not sell, rent, or share personal data with third parties.
Submitted project content (project name, trust, specialty, etc.) is publicly visible on the site — this is the purpose of submission. Hashed email addresses are never exposed externally.
We use infrastructure providers (hosting, database) that may process data on our behalf under GDPR-compliant Data Processing Agreements. All services are operated within the UK or EU.
How long we keep data
| Data type | Retention |
|---|---|
| Published project content | Indefinitely (open archive) |
| Hashed email addresses | Until project is deleted |
| Unapproved/rejected submissions | 30 days, then deleted |
| Comments (approved) | Indefinitely with the project |
| Comments (rejected) | Deleted immediately |
| Server access logs | Maximum 30 days |
| Admin session tokens | Session duration only |
Your rights under UK GDPR
Under UK GDPR and the Data Protection Act 2018, you have the right to:
Note: Because email addresses are stored only as irreversible hashes, we cannot verify the identity of an erasure request by email match alone. Please provide the project title and approximate submission date to help us locate the relevant record.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.
Cookie usage
WhichAudit uses a minimal set of cookies. We do not use third-party advertising or tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| session | CSRF protection for forms (essential) | Session |
| access_token | Admin authentication (admin users only) | Session |
Questions about this policy?
If you have questions about how your data is handled, would like to exercise any of your rights, or wish to report a concern, please contact us. We aim to respond to all data-related requests within 30 days.
If you are unsatisfied with our response, you may escalate to the Information Commissioner's Office (ICO) — the UK's independent data protection authority.