Who we are. WhichAudit ("we", "us") operates whichaudit.com, a repository of anonymised NHS clinical audit and quality improvement project summaries. For any privacy query, contact us via the contact form.

What we collect.

Account data — if you register: username, email address, and any optional profile details you choose to add (job title, trust, specialty, bio).
Submission data — project summaries you submit, and the email address provided with a submission (used only to notify you about approval).
Newsletter signups — your email address, if you subscribe.
Usage data — pages visited, referrer, device type and browser, collected via our own privacy-light analytics. We do not use third-party advertising trackers. A session cookie distinguishes visits; it does not identify you personally.
Comments and suggestions — content you submit through comment forms or the suggest-a-topic feature.

What we never collect. Patient-identifiable data has no place on this platform. All published project summaries are anonymised, aggregate-level descriptions. Submissions containing patient-identifiable information are rejected.

How we use your data. To operate the site, review and publish submissions, notify you about your submissions, send the newsletter you asked for, generate contributor certificates on request, and understand aggregate site usage. We do not sell or share your data with third parties for marketing.

Legal bases (UK GDPR). Consent (newsletter, optional profile fields), contract (operating your account), and legitimate interests (site analytics, security, spam prevention).

Email. Transactional and newsletter email is delivered via SendGrid (Twilio Inc.), acting as our processor. Newsletter emails always include an unsubscribe link, and you can unsubscribe at any time.

Retention. Account data is kept while your account is active; delete your account and it is removed. Newsletter emails are kept until you unsubscribe. Page-view analytics are aggregate and retained for service improvement. Published project summaries are retained as a permanent public archive (they contain no personal data beyond optional submitter attribution).

Your rights. You may request access, correction, deletion, or portability of your personal data, object to processing, or withdraw consent at any time — use the contact form. You may also complain to the ICO (ico.org.uk) if you believe we have mishandled your data.

Cookies. We use strictly-necessary cookies (session management, CSRF protection, dark-mode preference stored locally on your device). No advertising cookies.

Security. The site is served over HTTPS with modern security headers, passwords are hashed with PBKDF2, and authentication endpoints are rate-limited.

Changes. We will update this page when our practices change and adjust the date above.