Portal Privacy Policy
Draft for legal review — not yet effective Prepared: 15 August 2026
This policy applies only to the B5.LY Business Portal (the Portal), not to the consumer service on bigfive.ly.
1. Who we are
GLORIAPR Ltd, trading as BigFive / B5.LY where applicable, operates the Portal.
- Company number: 16313878
- Address: Office 12012, 182–184 High Street North, East Ham, London E6 2JA, United Kingdom
- Privacy contact: Support@b5.ly
2. Our data-protection roles
We are a controller for account-owner and staff data used to create, secure, bill, support, and administer Portal accounts. For personal data about participants invited by a Portal client, the client generally acts as controller and we act as its processor, following documented instructions and the applicable Data Processing Agreement (DPA). We may act as controller for limited security, fraud-prevention, and service-integrity records.
Participants should normally direct privacy requests to the organisation or practitioner that invited them. We will redirect and assist where required.
3. Data we process
Account and business data
We may process names, business contact details, organisation and profile information, account roles, accepted-policy versions, authentication events, support messages, and security records.
Payment and credit data
We may process Stripe customer and payment references, order status, pack quantity, amount, tax, refund or dispute status, credit-lot dates, balances, and ledger history. Stripe receives payment-card details through its checkout. We do not need to store full card numbers.
Participant and assessment data
Depending on how the client uses the Portal, we may process participant names and emails, invitation and completion status, assessment responses, required scoring inputs, derived scores, generated reports, sharing settings, and relevant security and device records. API clients may choose not to send participant identifiers where the integration supports that choice.
4. Why we process data
We process data to create and secure accounts; verify email; prevent abuse; provide invitations, assessments, reports, templates, and Portal modules; process one-time credit purchases; maintain the credit ledger; send service and expiry notices; provide support; investigate incidents and payment disputes; comply with law; and improve reliability and usability.
For account data, our legal bases may include performance of a contract, legitimate interests in operating and protecting the Portal, legal obligations, and consent where required. For participant data processed on behalf of a client, the client is responsible for selecting and documenting the applicable legal basis.
5. Service communications
We send messages needed to operate an account, such as email verification, security notices, purchase confirmations, credit-expiry reminders, material service changes, and support replies. These are operational communications, not recurring-payment notices. Marketing messages, if introduced, will use the choices required by applicable law.
6. Payments
Stripe processes checkout and payment information for one-time credit purchases and may calculate tax from the billing information supplied at checkout. Stripe’s own privacy terms apply to processing it performs for its purposes. The Portal stores only the payment and order references needed to fulfil, reconcile, refund, dispute, and audit a purchase.
7. Sharing and subprocessors
We share personal data only as needed with authorised staff, the Portal client that controls participant data, professional advisers, authorities where legally required, and vetted providers that support hosting, databases, payments, email delivery, security, monitoring, and customer support. Current core providers include Vercel, our database hosting provider, Stripe, and Resend. Processors are subject to contractual and security requirements. Clients may request current subprocessor information and a DPA from Support@b5.ly.
We do not sell participant personal data.
8. International transfers
Some providers may process data outside the United Kingdom or European Economic Area. Where required, we use recognised transfer mechanisms and supplementary safeguards appropriate to the destination and service.
9. Retention and account closure
We keep account, order, credit-ledger, security, and audit records for as long as needed to provide the Portal, resolve disputes, prevent abuse, and meet legal obligations. A credit’s expiry does not itself delete a generated report. On account closure, we normally allow up to 30 days to export available data, unless law, security, or an active dispute requires a different period. We then delete or de-identify data according to the DPA, client instructions, legal requirements, and our retention schedule. Backups may persist for a limited controlled period.
10. Security
We use measures designed to protect personal data, including access controls, authentication, encryption in transit, provider-supported encryption at rest, logging, environment separation, and incident procedures. No system can guarantee absolute security. Portal client administrators must manage their users, devices, exports, and report links responsibly.
11. Cookies
The Portal uses essential cookies and similar storage for authentication, security, language, and core functions. We do not use third-party advertising cookies in the Portal. If optional analytics are introduced, we will provide the notices and controls required by law.
12. Adults only and high-impact use
The Portal is not intended for people under 18. Clients must not invite minors. Assessment reports must not be used as the sole basis for employment, clinical, legal, credit, relationship, or other high-impact decisions.
13. Your rights
Depending on applicable law, account users may have rights to access, correct, delete, restrict, object to, or receive copies of their personal data, and to complain to a regulator. Contact Support@b5.ly with the subject “Privacy Request.” Participants should first contact the client that invited them; we will assist that client as required. UK complaints may also be directed to the Information Commissioner’s Office.
14. Changes and contact
We will identify the effective date of each approved version and communicate material changes where appropriate.
Privacy questions or requests: Support@b5.ly