Legal
Privacy policy
Last updated 11 September 2026
This policy explains what personal data easyDSE collects when you use our website and complete a Display Screen Equipment (DSE) assessment, what we do with it, who we share it with, and the rights you have over it.
It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
1. Who we are
easyDSE (“easyDSE”, “we”, “us”) operates the easyDSE platform. For the purposes of data protection law we act in two different capacities, and which one applies to you matters:
- As a data controller. When you use easyDSE as an individual, on your own account, and when we handle account, billing and website data for business customers. We decide why and how your data is used.
- As a data processor. When your employer holds an easyDSE business subscription and invites you to complete an assessment. In that case your employer is the controller and decides why your data is used; we process it on their documented instructions under a data processing agreement.
If you are unsure which applies to you, your assessment invitation will say whether it came from an employer. You can also ask us at privacy@easydse.co.uk.
2. The data we collect
Account data
Your email address, and optionally your name and job title. We use magic-link sign-in, so we never ask for or store a password.
Assessment data
Your answers to the assessment questions. Depending on which questions apply to you, this may include:
- Details of your workstation, equipment, environment and working patterns.
- Free-text answers you type, and voice notes you choose to record. Voice recordings are converted to text automatically; we keep both the recording and the transcript.
- Photographs of your workspace, where you choose to upload them. These are optional and the assessment can be completed in full without them.
- Health data. Any aches, pains, symptoms, conditions, disabilities or pregnancy you tell us about. This is “special category” data under Article 9 UK GDPR and is treated with additional care (see section 4).
Report data
The risk rating, findings, recommended actions and product recommendations we generate from your answers, and the PDF report produced from them.
Business account data
For business customers: organisation name, billing contact, subscription and credit history. Card details are handled entirely by Stripe and never reach our servers.
Technical data
A strictly necessary session cookie to keep you signed in, plus server logs containing IP address, browser type and pages requested, kept for security and troubleshooting. We do not use advertising or cross-site tracking cookies. See our cookie policy.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Delivering the assessment and producing your report | Performance of a contract with you (Art. 6(1)(b)) |
| Emailing you your report and sign-in links | Performance of a contract (Art. 6(1)(b)) |
| Employer-commissioned assessments and reminders | Our client’s legitimate interests and legal obligation to assess DSE risk (Art. 6(1)(c)/(f)). We act on their instructions |
| Taking payment and keeping financial records | Contract, and legal obligation (Art. 6(1)(b)/(c)) |
| Keeping the service secure and preventing abuse | Legitimate interests (Art. 6(1)(f)) |
| Improving the questions and the quality of reports | Legitimate interests (Art. 6(1)(f)), using aggregated or de-identified data |
| Marketing emails to business contacts | Consent, or legitimate interests for existing customers (you can opt out in any email) |
4. Health data
Information about symptoms, conditions, disabilities or pregnancy is special category data. We rely on:
- Article 9(2)(b). Processing necessary for carrying out obligations in the field of employment and social protection law, which is what a DSE risk assessment is; and
- Article 9(2)(a). Your explicit consent, where you are using easyDSE as an individual rather than through an employer.
Every health question in the assessment is optional to elaborate on, and you can complete a valid assessment while sharing only what you are comfortable sharing.
What your employer sees. Where your employer commissioned the assessment, they receive your report, including the health information in it, because they need it to act on the risks identified. This is the point of the assessment. If there is something you do not want your employer to see, do not enter it; raise it instead with occupational health or your GP.
5. Automated analysis
We use a third-party large language model, accessed through OpenRouter, to help write the narrative in your report, to transcribe voice notes, and, where you upload them, to describe what is visible in your workspace photos.
The findings and risk rating in your report are produced by a fixed, auditable rule set, not by the model. The model shapes how the report reads and adds observations from photos; it does not decide your risk rating. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 UK GDPR.
Data sent to the model is used to generate your report only. We instruct our provider not to retain it for model training.
6. Who we share data with
- Your employer. Where they commissioned the assessment, as described above.
- Neon. Database hosting, in a United Kingdom region.
- Vercel. Application hosting, file storage and content delivery.
- Resend. Sending transactional email such as sign-in links and reports.
- Stripe. Payment processing for business subscriptions. Stripe is an independent controller for payment data.
- OpenRouter and the model providers it routes to. Automated report writing, transcription and photo analysis.
- Professional advisers, or authorities. Where we are legally required to disclose.
We do not sell personal data, and we do not share it with advertisers. Retailers we link to receive no personal data from us. An affiliate link carries only a referral code.
7. International transfers
We host data in the UK or EEA wherever we can. Some of our processors operate in the United States. Where personal data is transferred outside the UK, we rely on UK adequacy regulations, or on the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
8. How long we keep it
- Individual assessments. Kept while your account is active, and for 3 years after your last assessment so you have a record and a baseline to compare against. You can delete an assessment at any time.
- Employer-commissioned assessments. Kept for as long as your employer instructs, and deleted or returned when their subscription ends. Employers commonly keep DSE records for 6 years to cover the limitation period for personal injury claims.
- Voice recordings. The audio is deleted 90 days after the assessment is completed; the transcript stays in the report.
- Photographs. Deleted 12 months after the assessment is completed, or sooner on request.
- Billing records. Seven years, to meet HMRC requirements.
- Sign-in tokens and server logs. Thirty and 90 days respectively.
9. Your rights
Under the UK GDPR you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, where there is no overriding reason to keep it;
- restrict or object to how we use it, including objecting to our legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, where we rely on consent.
Where your employer is the controller, send your request to them; if you send it to us we will pass it on and help them answer it.
To exercise any of these rights, email privacy@easydse.co.uk. We will respond within one month.
You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.
10. Security
Data is encrypted in transit and at rest. Access is limited to the people who need it, protected by multi-factor authentication and logged. We use passwordless sign-in to remove the risks that come with stored passwords. Photographs and voice recordings are stored with unguessable URLs and served only to people authorised to view that assessment.
No system is perfectly secure. If a breach affects your rights and freedoms we will tell the ICO within 72 hours and let you know without undue delay.
11. Children
easyDSE is intended for people in work. We do not knowingly collect data from anyone under 16. Where an assessment indicates a user is under 18, we flag it for a supervised assessment rather than relying on self-assessment alone.
12. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use your data, we will email you before it takes effect.
13. Contact
Data protection enquiries: privacy@easydse.co.uk
General enquiries: hello@easydse.co.uk