Data practices
How Insightnix sources, prepares and maintains the data behind every dashboard, and how client data is handled within Data Services.
1. Overview
Insightnix has two distinct data activities. The public platform presents dashboards created from datasets made available under published licences, public-domain statements or reuse terms that permit the intended commercial reuse. Data Services provides managed dashboards, reporting, integration, migration, forecasting and support using a client’s own data and systems.
This document describes our operational principles for source selection, provenance, quality checks, transformation, licensing, updates, privacy, security and client-data handling. It is intended to promote transparency; it is not a guarantee that every source or dataset is free from error.
The binding commercial and data-processing obligations for a client engagement are in the accepted Order and our Data Services Terms. Personal information used for our own website and business purposes is covered by our Privacy Policy.
Purpose of this document
This document explains the operational principles we apply when selecting, preparing, presenting and maintaining data on the public Insightnix platform and when handling data for clients. It is intended to support transparency and informed use; it is not a guarantee that every dataset is complete, error-free or suitable for every decision.
Different data contexts
Public dashboard data is generally obtained from government, public-sector, research, intergovernmental or other institutional sources that publish the relevant dataset under terms permitting commercial reuse. Client Data Services may involve private files, databases, cloud services, APIs and business systems supplied or authorised by the client. The provenance, reuse terms, security and retention requirements therefore differ between the two contexts.
Core principles
- Provenance: preserve a clear record of where data originated and which version was used.
- Purpose limitation: process data for a defined dashboard, reporting, analytical or operational purpose.
- Minimisation: use only the fields, records and history reasonably needed.
- Reproducibility: document material transformations and calculations where proportionate.
- Proportionality: match controls and validation effort to the impact of likely errors or misuse.
- Transparency: identify important caveats, definitions, update dates and source restrictions.
2. Source selection
We favour authoritative, traceable sources such as national statistical agencies, government departments, regulators, central banks, international organisations, universities and established research programmes.
Before using a public dataset, we consider:
- the identity and credibility of the publisher;
- the original publication location and availability of methodology or metadata;
- coverage, definitions, units, geographic and time granularity;
- publication frequency, revision practices and known breaks in series;
- licence terms, attribution requirements and whether commercial reuse is permitted;
- whether the data can be reproduced or checked against the source; and
- privacy, disclosure and re-identification risks.
Each dashboard should identify the principal source and, where practicable, link to the original publication. We do not use, or may replace or remove, a source where its provenance, published reuse terms, reliability or privacy position cannot be established to a reasonable standard.
Commercially reusable public data
For the public platform, a dataset must carry a published licence, public-domain statement, statutory reuse notice or other published terms that permit the intended commercial reuse. Those published terms must cover the way we obtain, clean, combine, calculate, visualise and publish the data. Publication by a government body or availability without payment is not enough on its own.
We generally prefer official government, statistical, regulatory, intergovernmental and research sources because they often provide traceable provenance, stable definitions and explicit reuse notices. We still read the terms attached to each specific dataset. An institution may release some datasets under an open licence while reserving other content, so the publisher’s status does not replace the dataset-specific licence or reuse notice.
Where commercial reuse rights are unclear, absent or inconsistent, we do not use that dataset in a public dashboard. We may use an alternative source with clear published terms or link users to the original publication without republishing the underlying data.
Source-assessment factors
Before using a public source, we may consider the authority and reputation of the publisher, the collection method, geographic and temporal coverage, definitions, revision policy, machine-readability, licensing, citation requirements, known limitations and whether a more direct or primary source is available.
Primary and derived sources
Where practicable, we prefer the originating publisher or an official distribution channel. A reputable secondary source may be used where it provides a necessary harmonised dataset, archive or interface, but we aim to identify the underlying publisher and avoid implying that the secondary source created the original measurements.
Provenance records
Provenance may include the source organisation, dataset title, source page or endpoint, retrieval date, edition or release, file name, checksum, licence, geographic scope, units, relevant metadata and transformations applied. The level of detail presented publicly may vary, but internal records are maintained where proportionate to the dashboard.
Source withdrawal or correction
If a publisher withdraws, corrects or materially redefines a dataset, we may update, annotate, temporarily remove or discontinue the affected dashboard. We do not guarantee indefinite access to a source that is outside our control.
3. Preparation and structuring
Public and client data may require preparation before it can support reliable reporting. Depending on the dataset and agreed purpose, our process may include:
- checking file integrity, schemas, row counts, data types and required fields;
- standardising column names, date formats, units, currencies, country names and geographic codes;
- identifying duplicates, invalid values, missing values, outliers and inconsistent categories;
- documenting joins, filters, exclusions, mappings, assumptions and known limitations;
- reconciling important totals or samples against the authoritative source;
- creating calculated measures, rates, indices, aggregations, rolling values or derived fields where required for the dashboard;
- testing filters, relationships, refresh logic, row-level security and selected visual outputs; and
- retaining sufficient provenance or version information to reproduce material processing steps where reasonably practicable.
Transformations can change structure, level of aggregation or presentation, but should not intentionally misrepresent the source. Where a material calculation or methodological choice is not obvious, we aim to explain it in the dashboard, metadata or supporting documentation.
Automated checks reduce error but do not replace source expertise or human review. The depth of validation depends on the source, risk, scope and information available.
Typical preparation activities
Preparation may include file conversion, schema alignment, character and date normalisation, unit conversion, de-duplication, missing-value treatment, category mapping, geographic-code reconciliation, aggregation, reshaping, joins, calculated measures and the creation of display-friendly labels.
Quality checks
Depending on risk and feasibility, checks may include row and column counts, data types, uniqueness and key integrity, valid ranges, missingness, duplicate detection, reconciliation of totals, comparison with source summaries, outlier review, chronological continuity and spot checks against source records.
Transformations and assumptions
Material assumptions may be recorded in dashboard notes, metadata or internal transformation documentation. Some transformations are necessary to combine sources with different naming conventions, time periods or geographic classifications. Harmonisation improves usability but can introduce approximation and should not be interpreted as removing differences in the underlying methodologies.
Missing and suppressed values
A blank, zero, “not available”, “not applicable”, suppressed value and estimated value are not interchangeable. We aim to preserve these distinctions where the source permits. A visualisation may omit a missing point to avoid falsely presenting it as zero.
Automated pipelines
Where data preparation is automated, we may use validation rules, logging, exception reporting and staged processing. Automation reduces repetitive handling but does not eliminate the need for review, especially after a source changes structure or meaning.
4. Licensing and attribution
Our commercial-reuse rule
Insightnix uses public datasets only where the published licence, public-domain statement or stated reuse terms permit the intended commercial operation of the platform. A dataset being visible online, downloadable without payment or described informally as “public data” does not by itself permit copying, transformation, combination, republication or commercial use. Before using a dataset, we identify the applicable dataset-specific terms, the relevant version and the conditions attached to the intended use.
Our policy is to use public-domain information, openly licensed data or data covered by published dataset-specific reuse terms that allow commercial use. We do not knowingly publish datasets under terms limited to personal, educational, academic, research-only or non-commercial use. We also exclude sources whose terms prohibit the transformations, extraction, redistribution or public display needed for the dashboard.
A licence permitting commercial reuse may still impose conditions. Open licences commonly require attribution, preservation of notices, identification of changes, a link to the licence, share-alike treatment, database notices or compliance with acceptable-use and API requirements. We identify and apply the relevant conditions in the dashboard, dataset record or supporting page.
Examples of licence types that may permit commercial reuse
The following are examples of licence types that may permit commercial reuse when they apply to the specific dataset. This list is illustrative rather than exhaustive. A licence name alone does not replace reading the exact text, version, scope, exclusions and publisher notices attached to the dataset.
- UK Open Government Licence (OGL), including OGL v3.0: commonly used by UK government departments and public-sector bodies for Crown copyright and Crown database-right information. It generally permits copying, adaptation, publication, distribution and commercial exploitation, subject principally to attribution and the stated exclusions.
- Creative Commons CC0 1.0 Universal: a public-domain dedication that permits copying, modification and commercial use without seeking further permission, while good source acknowledgement may still be maintained as a matter of transparency and research practice.
- Creative Commons Attribution licences, including CC BY 4.0: permit sharing and adaptation for commercial purposes, subject to appropriate credit, a licence reference, indication of changes and the other applicable terms.
- Creative Commons Attribution-ShareAlike licences, including CC BY-SA 4.0: permit commercial reuse and adaptation but may require adapted material to be distributed under the same or a compatible licence. We assess whether the share-alike obligation is compatible with the intended dashboard and any downloadable output before use.
- Open Data Commons Public Domain Dedication and License (PDDL 1.0): intended to place a database in the public domain and permit unrestricted reuse, subject to the precise legal text and any separately applicable rights in individual contents.
- Open Data Commons Attribution License (ODC-By 1.0): permits use and redistribution of a database, including commercial use, subject to attribution and the licence conditions.
- Open Database License (ODbL 1.0): permits sharing, modification and commercial use of a database but includes attribution and share-alike obligations and may distinguish between the database, a derivative database, a produced work and individual database contents. We review those distinctions before publication or redistribution.
- Other national or regional open-government licences: datasets released by governments, statistical agencies, regulators, municipalities or public bodies may be used where their published terms expressly permit commercial reuse, transformation and republication for the proposed purpose.
- European Union institution reuse terms: material made available under an applicable EU reuse decision, data-portal notice, Creative Commons licence or equivalent published reuse terms may be used where the specific page and dataset permit the intended commercial reuse and all attribution, integrity and non-endorsement requirements can be met.
- Public-domain material: information may be used where it is clearly identified as being in the public domain or where a reliable legal basis establishes that no relevant exclusive right restricts the intended use. A lack of a copyright notice is not treated as proof of public-domain status.
- Publisher-specific open-data terms: some intergovernmental organisations, universities, research programmes, charities and public institutions publish datasets under bespoke reuse terms. We use them only where those published terms clearly cover commercial reuse, adaptation, combination, public display and any intended redistribution.
A licence may apply to the database but not to every item contained in it. Maps, photographs, logos, trademarks, narrative reports, third-party indicators, software, API documentation and embedded materials can be governed by different rights. We therefore consider the actual components used in the dashboard rather than assuming that one notice licenses an entire website or publication.
Licences and restrictions that are not normally suitable
We do not knowingly use a source for a commercial public dashboard where the applicable terms include any of the following restrictions:
- a Creative Commons NonCommercial condition, including CC BY-NC, CC BY-NC-SA or CC BY-NC-ND;
- the UK Non-Commercial Government Licence or another licence limited to non-commercial activity;
- “research only”, “academic use only”, “educational use only”, “personal use only” or comparable restrictions;
- a prohibition on republication, redistribution, data extraction, automated access, commercial use or creation of derivative works needed for the dashboard;
- a no-derivatives condition where cleaning, reformatting, calculation, translation, aggregation or visualisation would amount to an adaptation not permitted by the licence;
- confidential, leaked, unlawfully obtained, access-controlled or contractually restricted data;
- terms whose ownership, licence scope or authority cannot be established with reasonable confidence; or
- data containing personal information that cannot lawfully and appropriately be published, even if copyright reuse appears to be permitted.
Creative Commons Attribution-NoDerivatives licences may permit commercial distribution of an unadapted work, but they are not generally suitable where Insightnix needs to transform, combine, annotate or otherwise adapt the material. We therefore assess any no-derivatives source conservatively and ordinarily use it only as an unmodified reference or not at all.
How we check licence terms before use
Our review is proportionate to the source and proposed use. It may include:
- identifying the publisher or licensor stated in the dataset record and locating the original publication channel;
- locating the licence statement on the dataset page, metadata record, download page, API documentation or accompanying file;
- recording the licence name, version, source location and date checked;
- checking that commercial use is expressly permitted and is not contradicted elsewhere in the publisher’s terms;
- checking whether copying, extraction, adaptation, combination, visualisation, publication and redistribution are permitted;
- reviewing attribution wording, licence-link, change-notice, share-alike, database-right and disclaimer requirements;
- checking exclusions relating to logos, trademarks, images, personal data, confidential information, third-party content or sensitive datasets;
- checking API registration, rate-limit, caching, technical-security and acceptable-use requirements separately from the data licence;
- considering whether the source requires users to access the original publisher rather than a republished copy;
- considering whether data protection, statistical-disclosure, national-security, export-control or sector-specific restrictions apply independently of copyright licensing; and
- retaining proportionate evidence of the licence or terms relied on, because online notices can later change.
Our decision to use a source is limited to the particular dataset, edition, access route and intended use reviewed. It does not automatically extend to a later release, a different API, another dataset from the same institution or third-party content linked from the same page.
Attribution and source narratives
For each public dashboard, we provide a source narrative in the dashboard, dataset panel, methodology note or linked supporting page. Depending on the source and licence, this may include:
- the publisher or responsible institution;
- the dataset, table, series, indicator or API name;
- a link or reference to the original source location;
- the applicable licence and, where appropriate, its version or licence link;
- the source publication date, edition, release, data vintage or retrieval date;
- the geographic and temporal coverage;
- units, definitions and important methodological notes;
- a description of material cleaning, aggregation, conversion, joining, calculation or modelling performed by Insightnix;
- an indication that changes have been made where the licence requires it;
- publisher disclaimers or mandatory attribution wording;
- limitations, breaks in series, suppressed values, estimates, revisions or comparability warnings; and
- a statement that the publisher does not endorse Insightnix, our processing, dashboard design or conclusions, where appropriate.
Attribution is intended both to comply with legal conditions and to enable users to investigate the original evidence. It does not imply that the source organisation has reviewed, endorsed, sponsored or certified an Insightnix dashboard. Unless expressly stated otherwise, responsibility for the transformations, presentation and commentary added by Insightnix rests with Insightnix, while responsibility for the original data collection, definitions and publication remains with the source publisher.
Where multiple datasets are combined, we may provide a separate attribution for each material source. Where a dashboard uses many series from a single catalogue, attribution may be consolidated in a source table or methodology page rather than repeated beside every visual.
Transformations and derivative outputs
Public dashboards commonly require us to clean, rename, filter, harmonise, join, aggregate, normalise, calculate, convert, model or visualise source data. We carry out those steps only where the applicable rights permit them. We distinguish between values published directly by a source and values calculated or modelled by Insightnix.
Where a licence requires adaptations or derivative databases to be made available under specified terms, we assess whether the output falls within that requirement and what notices, downloadable files or licensing statements are needed. The fact that a visual dashboard can be viewed without charge does not by itself satisfy every share-alike or redistribution obligation.
Nothing in a source licence automatically grants rights in the Insightnix name, trademarks, website software, code, user interface, original explanatory writing, graphic design or other original material. Conversely, Insightnix Terms of Use do not remove any rights that a user may receive directly under the applicable source licence in the underlying data.
Government and institutional sources
Many Insightnix dashboards use data from government departments, national statistical offices, regulators, central banks, local authorities, intergovernmental organisations, universities and established research programmes. Their public status and authority are relevant to provenance, but they do not replace a licence check. Different departments within the same government, or different datasets on the same institutional portal, may apply different reuse terms.
Some government publications contain material supplied by commercial partners, mapping providers, photographers or other third parties that is excluded from the general government licence. Some statistical data may also be subject to disclosure controls, access conditions or limitations on the use of logos and official emblems. We exclude such material unless separate published terms clearly permit the intended reuse.
APIs and technical access
The right to reuse data and the conditions for accessing an API are related but separate matters. A dataset may be openly licensed while its API is subject to registration, authentication, request limits, caching restrictions, security requirements or service-specific terms. We follow both the data licence and the technical access conditions that apply to the access route used.
We do not treat the absence of an effective technical barrier as permission to scrape or extract data. Where a publisher provides an official bulk download or API, we generally prefer that route. We may cache permitted data to support performance and continuity, but we do not guarantee that an API or source will remain available.
Licence changes, withdrawals and disputes
Publishers may change licences, remove files, alter API terms, add restrictions or clarify that material was incorrectly labelled. We may periodically recheck high-value or actively maintained sources, particularly when updating a dashboard or changing the way data is used.
If a licence is changed or withdrawn, we may preserve uses already authorised where legally permitted, revise attribution, stop refreshing the dataset, restrict downloads, replace the source, archive the dashboard or remove affected material. We are not obliged to continue publishing a dashboard where the legal basis for reuse becomes uncertain or operationally disproportionate.
A rights holder or publisher who believes that material has been used outside the applicable permission should contact us with the affected page, dataset, claimed right, relevant licence or terms and supporting evidence. We will assess sufficiently detailed notices in good faith and may temporarily restrict access while the matter is reviewed. Removal during a review does not constitute an admission of infringement or liability.
User reuse of dashboard material
Users should not assume that all elements visible on a dashboard share one licence. The underlying data, Insightnix visualisation, source logos, map layers, fonts, explanatory text and third-party materials may have different owners and conditions. A source licence may permit users to obtain and reuse the underlying data directly from the publisher, but that does not necessarily permit wholesale copying of the Insightnix website or proprietary presentation.
Anyone wishing to reproduce, redistribute or commercially exploit dashboard material should review the source-specific notices and our Terms of Use. Where uncertainty remains, users should obtain permission from the relevant rights holder or use the original source data under its own licence rather than copying the compiled Insightnix presentation.
No exhaustive licence guarantee
Open-data licensing is fact-specific, and terminology varies between publishers and jurisdictions. The examples above are not legal advice, an exhaustive catalogue of commercially reusable licences or a guarantee that a particular dataset can be used merely because it references one of them. Our policy is to assess each source individually and to refrain from publication where commercial reuse, transformation or attribution requirements cannot be established to a reasonable standard.
5. Updates and corrections
Public dashboards are updated according to source availability and our maintenance schedule. A source may publish monthly, quarterly, annually, irregularly or with a delay. A dashboard’s latest displayed period is therefore not necessarily the current calendar period.
Where available, dashboards show a source date, publication date, last-refresh date or similar indicator. Source publishers may revise historical figures, definitions or methodologies. We may reprocess affected periods, and values displayed at different times can therefore change.
If we identify a material processing or presentation error, we aim to correct it promptly, re-run relevant checks and update the affected output. Minor formatting changes may be made without a separate notice. For a significant correction, we may add a note where this is useful to users.
To report a suspected issue, provide the dashboard name, figure, period, source you are comparing and a brief explanation. We will assess the report but cannot guarantee a particular outcome or response time for every public-dashboard query.
Update schedules
An update frequency shown on a dashboard is an intended cadence, not a guarantee that the publisher will release new information or that an update will complete on a particular date. Delays may result from source publication, schema changes, validation issues, outages, licensing questions or resource constraints.
Revisions and vintages
Official statistics are often revised after initial publication. A dashboard may therefore change even for historical periods. Where meaningful, we may record the data vintage or retrieval date, but we do not promise to retain every historical version.
Corrections
When a material error is identified, we may correct the data, transformation, label or explanatory note; republish the dashboard; and record an update notice where proportionate. Minor typographical or presentational corrections may be made without a formal notice.
User reports
Reports of possible errors should identify the dashboard, metric, period, geography, suspected issue and supporting source. We assess reports but cannot guarantee that every suggested change is accepted or implemented.
Archiving and discontinuation
A dashboard may be archived or discontinued where its source is no longer maintained, the licence changes, quality becomes insufficient, the subject is superseded or ongoing maintenance is disproportionate. Archived content may remain available with a clear status notice or may be removed.
6. Accuracy and limitations
We take reasonable care when preparing dashboards, but we do not independently audit every publisher’s collection process or certify the underlying data. Public figures remain subject to the source’s definitions, sampling, modelling, estimation, coverage, revision and disclosure-control practices.
Apparent comparisons may be affected by differences in definitions, currencies, population denominators, reporting periods, geography, missing observations, inflation treatment, methodology changes or breaks in series. Visual scale, rounding and aggregation can also affect interpretation.
Forecasts, scenarios, machine-learning results and trend extrapolations are inherently uncertain and depend on assumptions and historical data. They should not be treated as guarantees.
Public dashboards are provided for general information and exploration. They are not a substitute for the original publication or for legal, financial, medical, investment, safety, policy or other professional advice. Important decisions should be checked against authoritative sources and reviewed by appropriately qualified people.
Comparability
Values with the same label may have different definitions across countries, organisations, periods or publications. Changes in collection methods, boundaries, classifications, price bases, population denominators, reporting completeness or seasonal adjustment can affect comparisons.
Uncertainty and estimation
Some datasets include estimates, modelled values, samples, confidence intervals, imputation, rounding or suppressed observations. A precise-looking chart does not remove the uncertainty inherent in the source. Users should consult source methodology before drawing high-impact conclusions.
Correlation and causation
A visual relationship between variables does not by itself establish that one caused the other. Confounding, selection effects, measurement error and temporal trends may explain an apparent association.
Aggregation
National, regional, annual or category-level summaries can conceal variation within groups. Rankings can be sensitive to missing data, normalisation, tie handling, denominator choices and time periods. Dashboard order or colour should not be interpreted as an evaluative judgement unless expressly stated.
Decision use
Public dashboards are for general informational and analytical use. They are not professional, legal, medical, investment, safety-critical or regulatory advice. Users remain responsible for verifying current primary sources and assessing fitness for their particular purpose.
7. Privacy on the platform
Public dashboards are designed to use aggregate, statistical, anonymised or otherwise lawfully publishable information rather than information intended to identify individual people.
- We assess whether fields, combinations, small counts, free text or geographic detail could create an unreasonable identification risk.
- Where appropriate, we may aggregate, suppress, remove, generalise or decline to publish information.
- We do not intentionally attempt to re-identify individuals from anonymised public datasets or encourage users to do so.
- If a public source lawfully publishes identifiable information, we assess necessity, proportionality, licence terms and privacy impact before considering its use.
Viewing dashboards does generate limited technical and cookie-related information needed to deliver and secure the website. Enquiries, suggestions and newsletter subscriptions also involve personal information. Those activities are described in our Privacy Policy and Cookie Policy.
Preference for aggregate information
Public dashboards are designed primarily around aggregated, statistical, anonymised or non-personal information. We avoid publishing direct identifiers and do not intentionally create public tools for identifying, tracking or scoring individual people.
Anonymisation and disclosure risk
Removing names alone may not make information anonymous. Where a dataset could create a meaningful re-identification or singling-out risk, we may aggregate categories, suppress small counts, reduce granularity, remove fields, use broader periods or decline publication.
Public information about individuals
The fact that information is publicly accessible does not remove data-protection obligations. Before publishing personal information, we consider the source, purpose, reasonable expectations, sensitivity, possible harm, legal basis and whether a less intrusive presentation can achieve the same purpose.
Re-identification
Users must not attempt to re-identify individuals from anonymised, aggregated or pseudonymised dashboard data, combine it with other information for that purpose, or use Insightnix to facilitate harassment, discrimination or unauthorised profiling.
8. Client data (Data Services)
Client engagements are scoped separately from the public platform. Our normal principles are:
- the client retains ownership and control of its data;
- we request access only to data and systems reasonably required for the agreed work;
- access methods, environments, credentials, outputs and responsibilities are agreed before or during mobilisation;
- where practicable, production dashboards, gateways, workspaces and data connections are built in or transferred to client-controlled environments;
- we document material transformations, metric logic, assumptions and known quality issues according to the scope;
- client data is not used to build public Insightnix dashboards, another client’s work, advertising profiles or general-purpose model training; and
- the client remains responsible for lawful collection, source-system accuracy, business definitions, user authorisation and decisions made from the outputs.
Credentials should be individually assigned, least-privileged, time-limited where possible and revoked when no longer needed. Clients should not send passwords or high-risk information through ordinary email or general website forms where a safer agreed method is available.
Data intake
Before or at the start of an engagement, we may seek information about the source, purpose, fields, data subjects, special categories, retention needs, access method, geographic location, existing permissions and intended dashboard users. A sample or data dictionary may be requested to support scoping.
Secure transfer and access
Transfer methods are selected according to the sensitivity and volume of data. Where possible, we prefer controlled access, encrypted transfer, least-privilege service accounts and revocable credentials over sending unrestricted copies by ordinary email.
Client responsibility
The client is responsible for the lawfulness, accuracy and completeness of Client Data, the instructions it gives, the rights of authorised users and the decisions made using outputs. We may identify apparent quality issues, but our work does not constitute a comprehensive audit unless expressly included in the Order.
Test and development data
Synthetic, masked or reduced test data should be used where reasonably practicable. Where production data is necessary for development or testing, access and retention should be limited to what is required for the agreed purpose.
Return and deletion
At the end of a project or applicable retention period, Client Data is returned, deleted, anonymised or retained as agreed and subject to legal obligations, unresolved disputes and protected backup cycles.
9. Storage, retention and deletion
Security measures are selected according to the nature, volume and sensitivity of the data, the delivery platform and the risks agreed for the engagement. Measures may include:
- access controls, least-privilege permissions and authentication requirements;
- encrypted connections and secure transfer methods where supported;
- segregated project locations, protected working copies and restrictions on local storage;
- security updates, malware protection, logging, backup and recovery controls appropriate to the environment;
- confidentiality obligations and controlled subprocessor access; and
- incident identification, escalation, containment and client notification procedures.
Client data is retained only for the engagement, support, legal obligations and agreed handover or deletion period. At the end of processor services, personal information is returned or deleted as directed by the client and subject to the Data Services Terms. Protected backup copies may remain until overwritten in the normal cycle, but are kept beyond ordinary use.
No system is completely secure. Clients should maintain authoritative backups and should promptly revoke access or tell us about suspected compromise, incorrect permissions or changed personnel.
Environment and access controls
Depending on the engagement, controls may include role-based access, multi-factor authentication, environment separation, network restrictions, encrypted transfer, secrets management, logging, backup, patching and periodic review of authorised users. The exact controls depend on the client platform, architecture and agreed responsibility model.
Retention design
Retention is considered at intake and may differ between raw extracts, transformed tables, published models, logs, backups and project documentation. Temporary working files should not become indefinite archives merely because they are technically easy to retain.
Deletion limitations
Immediate deletion may not be possible from immutable logs or rotating backups. In those cases, information is placed beyond ordinary use and expires through the established cycle, unless restoration is required for continuity, security or law.
Incidents
Suspected loss, unauthorised access, corruption or disclosure is investigated under our incident procedures. Where we act as processor, the client is notified in accordance with the applicable contractual data-protection terms.
10. Confidentiality
- Client data, non-public requirements, credentials, Deliverables and findings are treated as confidential unless the client authorises disclosure or the information is already lawfully public.
- Access is limited to personnel and engaged service providers who need the information to deliver or protect the service and are subject to appropriate obligations.
- Information from one client is not disclosed to another client and is not intentionally incorporated into another client’s Deliverable.
- We do not identify a client, use its logo or publish a case study without written permission.
- Disclosure required by law, court or regulator is limited to what is required, with prior notice where legally permitted.
Generic skills, experience, ideas and know-how retained by our personnel are not treated as client data, provided they do not reveal confidential information or reproduce a client-specific Deliverable.
Need-to-know access
Confidential information is made available only to personnel and engaged service providers who require it for the relevant purpose and are subject to contractual, professional or statutory duties of confidence.
Client separation
We use logical, organisational or platform-native controls intended to prevent one client from accessing another client’s information. The precise separation model may depend on whether the solution is hosted in the client’s environment, our controlled environment or a third-party platform.
Permitted disclosures
Confidential information may be disclosed where required by law, court order or a competent authority. Where legally permitted, we will seek to notify the affected client before disclosure and limit the disclosure to what is required.
Residual knowledge
General professional skill, experience and unaided knowledge retained by personnel may be used in other work, provided that this does not involve disclosing Client Data, client-specific confidential information or protected intellectual property.
11. UK GDPR and data protection
Insightnix is operated in accordance with the UK GDPR, Data Protection Act 2018, relevant Data (Use and Access) Act 2025 provisions and PECR where those laws apply.
- For website enquiries, business contacts, contracts, invoicing, security and our own compliance records, Insightnix normally acts as controller.
- For personal information in a client dataset processed solely on the client’s instructions, the client normally acts as controller and Insightnix acts as processor.
- The controller is responsible for lawful basis, transparency, data minimisation, data-subject rights, accuracy and the decision to use the data.
- As processor, we follow documented instructions, maintain confidentiality and appropriate security, control subprocessors, assist with rights and breach obligations, and return or delete information as agreed.
- Special-category, criminal-offence, children’s or other high-risk information must be identified and expressly agreed before access so that necessity, legal conditions and safeguards can be assessed.
The complete Article 28 terms are in section 12 of the Data Services Terms or a client-specific Data Processing Agreement.
Controller activities
We act as controller for our website, enquiry, contract, invoice, security and compliance information. Our Privacy Policy explains the purposes, lawful bases, sharing, retention and rights that apply to those activities.
Processor activities
Where we process personal data on a client’s documented instructions, the accepted Order and Data Services Terms contain the required subject matter, duration, purpose, data types, data-subject categories and processor obligations. A separate Data Processing Agreement may be used where the project requires more specific terms.
High-risk processing
Projects involving special-category data, criminal-offence data, systematic monitoring, vulnerable individuals, large-scale profiling or other high-risk processing require express assessment and may require a data protection impact assessment, additional security or revised scope before work begins.
International transfers and subprocessors
Where a service requires international access or a subprocessor authorised under the relevant agreement, the applicable contractual and legal safeguards must be in place. The client remains responsible for confirming the architecture and subprocessor arrangements where the agreement requires its authorisation.
Individual rights
Where we act as processor, we assist the client as required by contract and do not independently determine the outcome of rights requests concerning Client Data. Where we act as controller, requests are handled under our Privacy Policy.
12. Contact
For source, methodology, correction, licensing or client-data questions, contact [email protected].
When reporting a public-data issue, include the dashboard name, figure, period and original source. Do not email confidential client data or credentials unless an appropriate transfer method has been agreed.
Reporting a data issue
For a public dashboard issue, identify the dashboard, source, metric, date or geography and the reason you believe the information is incorrect or misleading. For a client project, use the agreed support or project channel and avoid including sensitive data in the initial message.
Data-protection rights and complaints should be submitted through the contact route in our Privacy Policy. Contractual questions about a Data Services engagement should be sent to the contact stated in the relevant Order or to [email protected]