Version: 2.1 Effective date: 8 July 2026
Replaces: Version 2.0, effective 26 June 2026
1. Who We Are and How to Reach Us
The Innovators Team platform (innovators.team) is operated by Proportion Enterprise BV, trading as Proportion Global, registered in the Netherlands (KVK number available on request).
For the purposes of the UK GDPR and EU GDPR, Proportion Global is the data controller for all personal data collected on this platform, except where noted otherwise in Section 3.4.
Data protection contact: su*****@***************rs.team
If you have a complaint or question about how your data is handled, please contact us at the address above. You also have the right to lodge a complaint with your national data protection authority (see Section 7).
2. What This Policy Covers
This policy describes how we collect, use, store, and share personal data when you use the Innovators Team platform, including:
- Community features powered by BuddyBoss (profiles, groups, activity feeds, messaging)
- Co-Innovation Journey features (HCD challenges, submissions, dialogues, events)
- AI Assistant features (AI-powered chat, Google Drive document integration)
- Learning features powered by LearnDash
It does not cover third-party websites linked from the platform. Those sites have their own privacy policies.
3. Data We Collect and Why
We only collect personal data that is necessary for the purpose stated. Below we describe each category, the data involved, and the legal basis under Article 6 of the GDPR.
3.1 Account and Profile Data
What we collect: Name, email address, password (stored as a cryptographic hash, never in plain text), profile photograph, biography, professional background, location, languages, social media links, and any other fields you complete in your profile (xProfile fields).
Why: To create and manage your account and provide you with access to the platform.
Legal basis: Performance of a contract (Article 6(1)(b)). Your account is the contract.
Retention: Your account data is retained for the duration of your membership and deleted within 30 days of a verified deletion request. Some anonymised metadata (e.g. contribution counts) may be retained in aggregate form.
3.2 Community Activity Data (BuddyBoss)
What we collect: Posts, comments, and replies in the activity feed and group feeds; group membership and roles (member, moderator, administrator); private messages between members; media and file uploads; friendship connections; notification preferences and read status.
Why: To operate the social community features of the platform, facilitate collaboration between members, and send you notifications you have opted into.
Legal basis: Performance of a contract (Article 6(1)(b)) for core community features. Legitimate interests (Article 6(1)(f)) for security monitoring and fraud prevention.
Retention: Community content (posts, comments) is retained for the duration of your membership. Private messages are deleted within 30 days of a verified deletion request. Media and file uploads are deleted on request or on account deletion.
Note on public content: Content you post in public or open groups may be visible to non-members and search engines. If you delete your account, we will remove your name and profile but some content (e.g. discussion threads others have replied to) may be retained in anonymised form to preserve conversation integrity.
3.3 Co-Innovation Journey Data
What we collect:
- Challenge submissions — your written responses and file attachments for challenge activities
- Peer comments and votes — comments you leave on others’ submissions and votes cast
- Sub-team membership — which sub-teams you belong to within a challenge
- Workshop attendance — RSVP and attendance records for challenge-linked events
- Dialogue responses and replies — responses you submit to public or group dialogues, and replies to those responses
- Dialogue subscriptions — if you subscribe to a dialogue as a non-member, your email address
- Join requests — your request to join a facilitator-moderated group
- Audit events — a log of key actions (e.g. phase changes, submission reviews) for challenge integrity
Why: To operate the Co-Innovation Journey: managing challenge phases, enabling peer collaboration and feedback, running public dialogues to gather community input, and ensuring facilitators can moderate and review work.
Legal basis: Performance of a contract (Article 6(1)(b)) for registered members. Consent (Article 6(1)(a)) for dialogue subscriptions by non-members (opt-in email subscription).
Retention: Challenge data is retained for the duration of the challenge and your membership. Dialogue subscriptions for non-members are retained until you unsubscribe (HMAC-secured unsubscribe link in every notification email). Audit logs are retained for 12 months.
Note on dialogue visibility: Public dialogues may be visible to visitors who are not members of the platform. Responses you submit to a public dialogue may be seen by the dialogue host and other respondents, depending on the moderation settings applied.
3.4 AI Assistant Data
The AI Assistant is a feature a group’s own administrator or moderator can turn on for their group. It lets members have a conversation with an AI assistant, optionally grounded in documents from a Google Drive folder the group has connected.
Two ways a group can connect Google Drive. A group’s moderator chooses one when setting the assistant up:
- Connect your own Google account (preferred). The moderator signs in with their organisation’s own Google account and picks one folder using Google’s folder picker. The platform only ever requests Google’s
drive.filepermission scope — this is Google’s most limited Drive scope: it grants access solely to the one folder explicitly selected, and nothing else in that Google account’s Drive. The connection (a Google refresh token) is stored encrypted in our database, scoped to that one group. A group’s own moderator or administrator can disconnect it at any time from their group’s Manage → AI Assistant screen, which also revokes the token with Google immediately — no need to email support.
In this case, the folder itself always remains in your organisation’s own Google Drive — it is never copied or transferred into Innovators Team’s own storage.
What we collect:
- Chat messages — every message you send to the AI assistant, and the assistant’s responses. Saved as a Google Document in your group’s connected Drive folder (in a “Chat Logs” subfolder). Not stored on Innovators Team servers.
- Uploaded files — files you share directly in the AI chat interface. Saved to your group’s connected Drive folder. Not stored on Innovators Team servers.
- Google Drive document content — text extracted from files in your group’s connected Drive folder, read temporarily into memory as AI context. Read-only, in memory during the request. Never duplicated or stored on Innovators Team servers.
- Usage metadata — timestamp, group ID, and approximate token count, used to enforce a daily fair-use allowance per person. Stored briefly in the platform’s own database (cleared automatically each day) and also logged for operator reporting. Retained for up to 12 months.
- Connection metadata (OAuth path only) — the Google account email of whoever connected Drive for the group, shown to that group’s moderators so they know which account is linked. The underlying access token is never visible to anyone, including platform administrators, other than in encrypted form.
Why: To generate AI-assisted responses tailored to your project context, to save conversation logs for your own reference within your group’s Drive, and to monitor platform usage for capacity management.
Legal basis: Performance of a contract (Article 6(1)(b)) for providing the AI feature. Legitimate interests (Article 6(1)(f)) for usage monitoring and capacity management.
How the AI works:
- When you send a message, your message and any relevant document excerpts from your group’s connected Drive folder are sent securely to Anthropic’s Claude API.
- Anthropic processes the input and returns a response. Anthropic does not use data submitted via its API to train its AI models. Your conversations are not used to improve Claude or any other AI model. Anthropic may, however, retain inputs and outputs for up to 30 days for safety and security monitoring purposes, after which they are deleted.
- The conversation is saved as a Google Document in a “Chat Logs” subfolder within your group’s connected Google Drive folder. This document is accessible to group administrators and anyone with access to that Drive folder.
- The platform does not make any automated decisions with legal or similarly significant effects based on your AI conversations.
What the AI does not do:
- The AI does not browse the internet or access any systems beyond the single Drive folder your group has connected.
- The AI does not have access to other groups’ data, other groups’ Drive connections, or other users’ private messages.
- The AI does not score, rank, or make decisions about you as a person.
- The platform does not retain copies of your group’s documents on its own servers.
Who controls this data: Because the documents remain in your organisation’s own Google Drive under either connection method, your organisation acts as the data controller for the content of those documents. Proportion Global acts as a processor when it accesses that content to provide the AI feature, under the terms of this policy.
Retention: Chat logs and uploaded files are retained within your group’s Google Drive folder, under your organisation’s own retention policy. Innovators Team does not hold independent copies. Usage metadata is retained for up to 12 months. If a group disconnects Google Drive, we delete the stored connection token immediately; documents already saved in your Drive are unaffected and remain yours.
3.5 Learning Data (LearnDash)
What we collect: Course enrolment, lesson completion, quiz responses, and course progress.
Why: To track your learning progress, issue completion certificates, and enable facilitators to monitor cohort progress.
Legal basis: Performance of a contract (Article 6(1)(b)).
Retention: Retained for the duration of your membership, or for up to 3 years after course completion if required for accreditation purposes.
3.6 Technical and Analytics Data
What we collect: IP address, browser type and version, device type and operating system, pages visited, time spent on pages, referring URL, and session cookies.
Why: To keep the platform secure, diagnose technical issues, and understand how the platform is used in aggregate.
Legal basis: Legitimate interests (Article 6(1)(f)) for security and platform stability. Consent (Article 6(1)(a)) for analytics cookies (Google Analytics): you are asked for consent on first visit via our cookie banner.
Retention: Google Analytics data is retained for 14 months. Server logs are retained for 90 days. Session cookies expire at the end of your browser session.
4. Who We Share Your Data With
We do not sell your personal data. We do not share your data with third parties for advertising or marketing purposes.
We share data only in the following circumstances:
4.1 Sub-processors (technical service providers)
These providers process data on our behalf under Data Processing Agreements (DPAs) that require them to maintain the same level of data protection.
| Provider | Purpose | Location |
|---|---|---|
| Anthropic PBC | AI language model API (Claude) for AI Assistant feature | USA |
| Google LLC | Google Drive (document storage, chat logs, OAuth sign-in), Google Analytics, Gmail | USA |
| Rapyd.cloud | Platform hosting and database | EU |
| Modal Labs Inc. | Backend API services for AI Assistant | USA |
| Mailchimp (Intuit Inc.) | Email newsletters and marketing communications | USA |
| WP Engine / applicable host | WordPress hosting infrastructure | USA/EU |
| LearnDash (StellarWP) | Learning management system | USA |
4.2 Partner organisations
The Global Alliance for Improved Nutrition (GAIN) is a strategic partner of the Innovators Team platform. As a partner, GAIN may have access to aggregate platform usage data (e.g. number of active groups, challenge completion rates) for programme reporting purposes. GAIN does not have routine access to individual member profiles, private messages, or AI chat logs, and does not act as a data controller for data collected on this platform.
4.3 Legal requirements
We may disclose personal data if required by law, court order, or if we believe disclosure is necessary to protect the rights, property, or safety of our users or the public.
5. International Data Transfers
The platform is hosted in the EU (Rapyd.cloud). However, some of our sub-processors are located in the United States. When we transfer personal data outside the European Economic Area (EEA), we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
- Adequacy decisions where applicable.
Data may also flow to countries where our community members are based, including Ghana, Kenya, India, and other countries in Africa, Latin America, and South Asia, for the purpose of delivering our community and challenge features to local members.
6. Cookies
We use cookies for the following purposes:
| Category | Purpose | Consent required? |
|---|---|---|
| Strictly necessary | Login sessions, security, CSRF protection | No |
| Functional | Your language and display preferences | No |
| Analytics | Google Analytics: aggregate usage statistics | Yes |
| Marketing | Meta Pixel (only if enabled) | Yes |
You can withdraw consent for non-essential cookies at any time using the cookie settings link in the footer of the platform.
7. Your Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Access (Art. 15) — request a copy of the personal data we hold about you
- Rectification (Art. 16) — ask us to correct inaccurate or incomplete data
- Erasure (Art. 17) — ask us to delete your data (“right to be forgotten”)
- Restriction (Art. 18) — ask us to pause processing while a dispute is resolved
- Portability (Art. 20) — receive your data in a structured, machine-readable format
- Objection (Art. 21) — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing
- Automated decisions (Art. 22) — not be subject to decisions made solely by automated means that significantly affect you
How to exercise your rights: Email su*****@***************rs.team with your request. We will respond within 30 days. We may ask for proof of identity before processing your request.
Right to complain: You can also lodge a complaint with the data protection authority in your country. In the Netherlands (where Proportion Global is registered): Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl, +31 7*******00).
8. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- TLS/SSL encryption for all data in transit
- Cryptographic password hashing (never stored in plain text)
- Encryption at rest for stored Google Drive connection tokens
- Role-based access controls limiting who can access what data
- HMAC-secured tokens for sensitive operations (e.g. dialogue unsubscribe links)
- Regular security monitoring and server logging
- Access to personal data limited to authorised platform administrators
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
9. Children
The platform is intended for users aged 16 and above. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, please contact us at su*****@***************rs.team and we will delete the account.
10. Changes to This Policy
We may update this policy from time to time to reflect changes in how we use data, our sub-processors, or applicable law. When we make material changes, we will:
- Post the updated policy on this page with a new effective date
- Send a notification to registered members by email
Continued use of the platform after the effective date of a revised policy constitutes acceptance of the new policy.
11. Glossary
- Data controller — the organisation that determines why and how personal data is processed
- Data processor — an organisation that processes data on behalf of the controller
- Personal data — any information that can identify a natural person, directly or indirectly
- Processing — any operation performed on personal data (collection, storage, use, sharing, deletion)
- OAuth — an industry-standard protocol that lets you grant a limited, revocable connection to another service (here, your Google Drive) without ever sharing your password
- Scope — in OAuth, the specific, limited set of permissions being granted (e.g.
drive.filegrants access only to files you explicitly select, never your whole Drive) - GDPR — General Data Protection Regulation (EU) 2016/679
- EEA — European Economic Area
- SCC — Standard Contractual Clauses: legal mechanism for cross-border data transfers
- LIA — Legitimate Interests Assessment: balancing test required when relying on Art. 6(1)(f)
Last updated: 8 July 2026 | Questions: su*****@***************rs.team
