NoOneToTalk Corporate
Privacy Policy
Governing Law: England and Wales
Version 1.0 · Last updated: 1 October 2026
1. Who we are
| Company | NO ONE TO TALK LTD |
|---|---|
| Company number | 15474380 |
| Registered office | 20 Wenlock Road, London, N1 7GU, England |
| Support and abuse reports | support@noonetotalk.com |
| Data protection | privacy@noonetotalk.com · dpo@noonetotalk.com |
This Policy explains how we process personal data when you use NoOneToTalk Corporate (the "Service") as an employee or collaborator of a company that contracted it (the "Company"). Read it together with the Corporate Terms of Use.
2. Controller and processor roles
2.1. For HR data your Company manages through the Service (profile, contracts, time records, requests, payslips, documents), the Company is the controller and we act as its processor under a data processing agreement (Art. 28 UK GDPR / GDPR / LGPD).
2.2. For platform security, content moderation, abuse prevention and the operation of Rooms and Kibo, we act as controller.
2.3. Each Company is an isolated tenant. Data from one Company is not shared with another.
3. Data we process
- Account data: name, work email, nickname, role, department, language, photo if provided.
- HR data: time punches (and location if your Company enables it), requests, documents, payslips, calendar.
- Wellbeing data: mood check-ins, fitness and nutrition preferences, Kibo conversations. Some of this may be health-related.
- User Content: messages, comments, reactions and feedback you post, including in Rooms.
- Moderation data: results of automated checks, reports you submit or receive, blocks, and moderation actions.
- Technical data: device, app version, IP address, logs and push notification tokens.
4. Rooms: pseudonymity and moderation
4.1. Rooms are pseudonymous, not fully anonymous. When you post as "Anonymous", other employees and your Company's administrators do not see your name or photo. Your Company only receives aggregated, de-identified insights.
4.2. We always store the link between each post and your account. Authorised No One To Talk staff can see the author to review reports, remove content, and remove abusive users.
4.3. AI-assisted moderation. Before a message or comment is published, its text is checked by automated filters and an AI moderation model (currently provided by OpenAI). The model only receives the text needed for the check, not your name. Content is not used by the provider to train its models.
4.4. If you block a user, we store the block so we can hide their content from you. If you report content, we store the report, the content and the reporter so we can act within 24 hours.
4.5. Deleted messages are removed from the feed immediately and kept in restricted storage only for as long as needed to handle open reports or legal claims.
5. Lawful bases
- Contract / Company's legitimate interest in providing HR and workplace tools.
- Legitimate interests (Art. 6(1)(f)) in keeping the Service safe: moderation, abuse prevention and security.
- Legal obligation where we must retain or disclose data.
- Explicit consent (Art. 9(2)(a)) for optional wellbeing features that involve health-related data. You can withdraw consent at any time.
- Vital interests where there is a credible risk to life.
6. Sharing
- With your Company: HR data, and only aggregated or de-identified Room insights. We do not reveal the authors of pseudonymous posts to your Company unless required by law or where there is a credible risk of serious harm.
- With sub-processors: hosting, email, push notifications, AI providers (moderation, translation, Kibo), under written agreements with appropriate transfer safeguards.
- With authorities: when required by law, court order, or to protect someone's life. Content that sexualises minors is reported to the competent authorities.
We never sell personal data or use it for behavioural advertising.
7. International transfers
Some providers process data outside the UK/EEA. We use adequacy decisions or Standard Contractual Clauses (with the UK Addendum where relevant).
8. Retention
- HR data: as instructed by your Company and required by law.
- Room content: while the Room exists or until you delete it; moderation records up to 24 months after the case is closed.
- Account data: until your Company deactivates your account, then deleted or anonymised within 90 days, unless a legal hold applies.
9. Your rights
You have rights of access, rectification, erasure, restriction, objection and portability, and to withdraw consent. For HR data, we will forward your request to your Company as controller. Write to privacy@noonetotalk.com. You can also complain to the UK Information Commissioner's Office (ICO), your local EU authority, or the ANPD in Brazil.
10. Security
We use encryption in transit, access control by role, tenant isolation, audit logs and restricted access to author identity in Rooms.
11. Age
The Service is only for users aged 18 or over.
12. Changes
We will notify you in the app of material changes to this Policy.
Version 1.0 · 1 October 2026
