For HR Buyers · IT & Information Governance

The diligence pack, before the
procurement meeting — transparent by design.

NurtureArc is built to be assessed by HR, Information Governance, and DPO teams without a sales call. This page walks through five sections — GDPR posture, anonymous-first intake, accessibility, AI use, and retention / deletion — so your procurement, legal, and IT teams can sign off on what a deployment of NurtureArc would actually mean for your workforce.

✓ GDPR-aligned ✓ Anonymous by design ✓ WCAG 2.1 AA ✓ AI-transparent

What lawful basis we rely on, and who is the controller.

NurtureArc processes the data needed to deliver the 360° caregiver wellbeing assessment and the personalised 90-day transformation plan. For the platform itself, our lawful basis under UK / EU GDPR is legitimate interests — specifically, to provide the service the user has requested. For the sensitive wellness content captured in free-text answers, we rely on the user's explicit consent, surfaced the moment the assessment begins and recorded on the session record.

For the solo assessment, NurtureArc is the controller — we determine the means and purpose of processing for an anonymous individual user. For an employer-deployed team report, your organisation is the controller and NurtureArc acts as processor under a data processing agreement. Your DPO sets the lawful basis for inviting your workforce, defines what aggregate output you receive, and retains employee-facing transparency notices — we never see, surface, or transfer employee identity to your HR system.

Subprocessors are limited and disclosed: Render and Neon Postgres host the application and database in EU / UK regions, and the Polsia AI proxy routes our AI inference calls. Any cross-border transfer is governed by standard contractual clauses (SCCs). A current subprocessor list and the full processing-position summary are published at our /gdpr page; the canonical record of every data subject right available to your employees lives there too.

What an employee chooses to share, and what we never see.

📭
01

No identifiable contact required by default

On the solo flow, name and email are optional. A user can complete the 18-question assessment, receive a personalised transformation plan, and walk away without disclosing a single identifier to NurtureArc.

🆔
02

Answers are stored against an opaque session_id

Wellness answers, pillar scores, and the AI-generated plan are linked to a server-generated session_id. That session_id is the only key on the assessment record — it carries no semantic meaning, no employee number, no email hash, and no employer reference.

📊
03

Team reports aggregate pillar distributions only

The team-cohort report rolls responses up to pillar-level distributions and a single suggested employer-side intervention. No row-level employee data leaves the platform — the HR lead sees a workforce risk profile, not a list of individuals.

📤
04

The employee owns any onward export

If a user chooses to share their results with an employer or a line manager, they are the data exporter. NurtureArc does not email results to an employer address and does not proactively surface individual scores to an HR lead — consent, and the act of forwarding, rests entirely with the employee.

🧾
05

Funnel events carry zero PII columns

The assessment_events table holds funnel signals for the admin analytics dashboard. It records session_id, event type, question count, and referral source — never an email, an IP address, or any column that could be used to identify an individual visitor.

Designed for the assistive-tech users your workforce already includes.

NurtureArc targets full WCAG 2.1 Level AA conformance across the assessment flow and every employers/* public surface. The deep-navy + crisp-teal palette used on the assessment and employer pages is engineered to clear 4.5:1 contrast for body text and 3:1 for large text and UI components — so colour is never the only signal a user has to act on.

Keyboard navigation is end-to-end with visible focus rings, no keyboard traps, and a logical reading order through the 18-question flow. Screen-reader compatibility is checked via manual passes in NVDA and VoiceOver, alongside automated axe scans on every release candidate. Semantic landmarks are present on every page and the assessment flow exposes ARIA labels for question prompts and answer controls.

We deliberately avoid carousels, autoplaying motion, and parallax effects — none of which would trigger vestibular issues or surprise a screen-reader user mid-question. The full audit methodology, including the test set and the most recent conformance statement, is available on request from hello@nurturearc.polsia.app.

Audit methodology is provided on request, alongside a current statement of conformance, for inclusion in your equality impact assessment.

What the assessment model does, and what it deliberately does not.

⚙️
01

What the model does

Reads the user's pillar scores and free-text answers and produces a personalised set of action steps and a 90-day transformation prompt, via lib/polsia-ai.js. The output is a wellness coaching plan — reflective, specific, and grounded in the user's own response text — not a clinical recommendation.

🚫
02

What it does not infer

The model is not given, and does not infer, any of the following: medical history, current medication, clinical risk, protected characteristics, or the identity of an employer unless the user types one freely. Free-text answers used as model input are not associated with an identified individual at the point of inference.

⚖️
03

What it does not decide

NurtureArc does not use AI to make decisions that have legal or similarly significant effects on a user — the wellness score is informational only, and the 90-day plan is a personal prompt, not an instruction. This mirrors the canonical statement at /ai-transparency.

🛡️
04

How we mitigate

Prompt-level guardrails position the model as a wellness coach, not a clinician. Emergency signposting surfaces automatically on low mental-health scores regardless of model output. A persistent disclaimer sits on every results page, and the full mitigation summary is published at /ai-transparency.

The full AI statement — including the model provider, the system-prompt boundaries, and the user feedback path — lives at /ai-transparency and is updated alongside any change to the inference path. Still wondering whether anonymity holds? Read the FAQ →

How long we hold data, and how an employee asks for it to go.

🗓️

Assessment sessions

An anonymous assessment record sits in the assessments table for 12 months from completion. After 12 months the record is automatically purged by the nightly retention job — we don't keep shadow logs of completed sessions.

📩

Completed results

If a user opted in to receive their results by email, the assessment_results row is held until the user requests deletion or 12 months passes — whichever comes first. The 90-day check-in scheduling sits on the same row and is cleared at the same time.

📈

Team-cohort aggregates

Aggregate cohort outputs are retained for 24 months to support longitudinal reporting on the employer dashboard. Aggregates are stored without any per-employee join keys — by construction they cannot be reverse-engineered to a single respondent.

📬

Deletion on request

An employee can email hello@nurturearc.polsia.app to exercise any GDPR right. We acknowledge within five working days and complete the deletion within 30 days, escalating to the DPO contact if a request is unresolved at that point.

The full rights catalogue — access, rectification, erasure, restriction, portability, and objection — is published at /gdpr, with the privacy notice that accompanies every data capture at /privacy. Every transactional email we send has an unsubscribe link at /unsubscribe that takes a user off the relevant list with a single click.