Privacy Policy

How we protect your data at Emotional Piggy Ltd.

Privacy Policy

How we protect your data at Emotional Piggy Ltd.

Privacy Policy

How we protect your data at Emotional Piggy Ltd.

Last updated: 21/09/2025

Welcome to the privacy policy of Emotional Piggy Ltd (“we”, “us”, “our”). This page outlines how we collect, use, share, and safeguard your personal data in accordance with UK GDPR and the Data Protection Act 2018. For privacy matters, you can contact us at hi@emotionalpiggy.com. Company Number: 16344820. ICO Registration: CSN8100523.

Last updated: 21/09/2025

Welcome to the privacy policy of Emotional Piggy Ltd (“we”, “us”, “our”). This page outlines how we collect, use, share, and safeguard your personal data in accordance with UK GDPR and the Data Protection Act 2018. For privacy matters, you can contact us at hi@emotionalpiggy.com. Company Number: 16344820. ICO Registration: CSN8100523.

Last updated: 21/09/2025

Welcome to the privacy policy of Emotional Piggy Ltd (“we”, “us”, “our”). This page outlines how we collect, use, share, and safeguard your personal data in accordance with UK GDPR and the Data Protection Act 2018. For privacy matters, you can contact us at hi@emotionalpiggy.com. Company Number: 16344820. ICO Registration: CSN8100523.

1. Scope

This policy describes how we handle your personal data when you use our website, free screenings, paid assessments, enterprise programmes, and customer support. It applies to users in the UK and EEA under UK GDPR / Data Protection Act 2018 (and, where relevant, EU GDPR).

1. Scope

This policy describes how we handle your personal data when you use our website, free screenings, paid assessments, enterprise programmes, and customer support. It applies to users in the UK and EEA under UK GDPR / Data Protection Act 2018 (and, where relevant, EU GDPR).

1. Scope

This policy describes how we handle your personal data when you use our website, free screenings, paid assessments, enterprise programmes, and customer support. It applies to users in the UK and EEA under UK GDPR / Data Protection Act 2018 (and, where relevant, EU GDPR).

2. What data we collect

We collect account & contact data (name, email, password, organisation/school, role, country/region), screening & assessment data (your responses and notes, which may be health data), device and usage data (IP address, browser info, usage analytics, cookies), billing & payment information (limited to transaction data via our provider), support & feedback records, and enterprise admin/user details.

We do not intentionally collect data from children under 13. For school deployments, the controller (school/college) is responsible for the lawful basis and required consents.

2. What data we collect

We collect account & contact data (name, email, password, organisation/school, role, country/region), screening & assessment data (your responses and notes, which may be health data), device and usage data (IP address, browser info, usage analytics, cookies), billing & payment information (limited to transaction data via our provider), support & feedback records, and enterprise admin/user details.

We do not intentionally collect data from children under 13. For school deployments, the controller (school/college) is responsible for the lawful basis and required consents.

2. What data we collect

We collect account & contact data (name, email, password, organisation/school, role, country/region), screening & assessment data (your responses and notes, which may be health data), device and usage data (IP address, browser info, usage analytics, cookies), billing & payment information (limited to transaction data via our provider), support & feedback records, and enterprise admin/user details.

We do not intentionally collect data from children under 13. For school deployments, the controller (school/college) is responsible for the lawful basis and required consents.

3. Purposes and legal bases

We use your data to: (a) provide and operate our services (contractual necessity), (b) offer customer support and notifications (contract/legal interest), (c) improve security and performance (legit. interests), (d) manage billing and compliance (contract/legal obligation), (e) send marketing with your consent, (f) process health data with explicit consent.

You may withdraw marketing consent via unsubscribe link, and withdraw consent for health data by contacting us at hi@emotionalpiggy.com. These choices are always respected.

See our table below for more details on purpose and lawful basis. If you have questions, contact us any time.

3. Purposes and legal bases

We use your data to: (a) provide and operate our services (contractual necessity), (b) offer customer support and notifications (contract/legal interest), (c) improve security and performance (legit. interests), (d) manage billing and compliance (contract/legal obligation), (e) send marketing with your consent, (f) process health data with explicit consent.

You may withdraw marketing consent via unsubscribe link, and withdraw consent for health data by contacting us at hi@emotionalpiggy.com. These choices are always respected.

See our table below for more details on purpose and lawful basis. If you have questions, contact us any time.

3. Purposes and legal bases

We use your data to: (a) provide and operate our services (contractual necessity), (b) offer customer support and notifications (contract/legal interest), (c) improve security and performance (legit. interests), (d) manage billing and compliance (contract/legal obligation), (e) send marketing with your consent, (f) process health data with explicit consent.

You may withdraw marketing consent via unsubscribe link, and withdraw consent for health data by contacting us at hi@emotionalpiggy.com. These choices are always respected.

See our table below for more details on purpose and lawful basis. If you have questions, contact us any time.

4. Controller vs Processor

If you use our service directly (B2C), Emotional Piggy Ltd is the data controller. For enterprise/school programmes, your institution is typically the controller and we act as a processor, under a Data Processing Addendum (DPA).

4. Controller vs Processor

If you use our service directly (B2C), Emotional Piggy Ltd is the data controller. For enterprise/school programmes, your institution is typically the controller and we act as a processor, under a Data Processing Addendum (DPA).

4. Controller vs Processor

If you use our service directly (B2C), Emotional Piggy Ltd is the data controller. For enterprise/school programmes, your institution is typically the controller and we act as a processor, under a Data Processing Addendum (DPA).

5. Automated analysis & human oversight

We use algorithmic and AI-assisted scoring to generate feedback. We do not make legally significant decisions solely by automated means. You may always request a human review or explanation of our logic.

Our team regularly reviews our automated systems and ensures meaningful human oversight is in place.

5. Automated analysis & human oversight

We use algorithmic and AI-assisted scoring to generate feedback. We do not make legally significant decisions solely by automated means. You may always request a human review or explanation of our logic.

Our team regularly reviews our automated systems and ensures meaningful human oversight is in place.

5. Automated analysis & human oversight

We use algorithmic and AI-assisted scoring to generate feedback. We do not make legally significant decisions solely by automated means. You may always request a human review or explanation of our logic.

Our team regularly reviews our automated systems and ensures meaningful human oversight is in place.

6. Sharing your data

We only share data as necessary with trusted service providers (hosting, analytics, payments, support, security). For enterprise use, client administrators may access relevant results.

We may share data where required by law, to protect rights and safety, or in connection with business reorganisations.

We do not sell your data.

6. Sharing your data

We only share data as necessary with trusted service providers (hosting, analytics, payments, support, security). For enterprise use, client administrators may access relevant results.

We may share data where required by law, to protect rights and safety, or in connection with business reorganisations.

We do not sell your data.

6. Sharing your data

We only share data as necessary with trusted service providers (hosting, analytics, payments, support, security). For enterprise use, client administrators may access relevant results.

We may share data where required by law, to protect rights and safety, or in connection with business reorganisations.

We do not sell your data.

7. International transfers

If your data is transferred outside the UK/EEA, we use appropriate safeguards (such as UK IDTA or EU Standard Contractual Clauses, plus any additional measures as needed). Details are available on request.

7. International transfers

If your data is transferred outside the UK/EEA, we use appropriate safeguards (such as UK IDTA or EU Standard Contractual Clauses, plus any additional measures as needed). Details are available on request.

7. International transfers

If your data is transferred outside the UK/EEA, we use appropriate safeguards (such as UK IDTA or EU Standard Contractual Clauses, plus any additional measures as needed). Details are available on request.

8. Retention

We keep data only as long as necessary. Account data is kept while your account is active and for 6 months after closure. Screening/assessment data is retained for 12 months.

Support records are held for 12 months after resolution. Billing information is kept as required by law (typically 6 years for tax).

Analytics data may be aggregated or anonymised for longer-term reporting.

8. Retention

We keep data only as long as necessary. Account data is kept while your account is active and for 6 months after closure. Screening/assessment data is retained for 12 months.

Support records are held for 12 months after resolution. Billing information is kept as required by law (typically 6 years for tax).

Analytics data may be aggregated or anonymised for longer-term reporting.

8. Retention

We keep data only as long as necessary. Account data is kept while your account is active and for 6 months after closure. Screening/assessment data is retained for 12 months.

Support records are held for 12 months after resolution. Billing information is kept as required by law (typically 6 years for tax).

Analytics data may be aggregated or anonymised for longer-term reporting.

9. Your rights

You may have rights to access, correct, erase, restrict or object to our use of your data, request data portability, and to object to certain automated decisions. You can withdraw consent for health data or marketing at any time.

To exercise your rights, contact: hi@emotionalpiggy.com. If we cannot resolve your issue, you may contact the UK ICO at ico.org.uk or call 0303 123 1113.

These rights apply as required by law and may be subject to exceptions.

9. Your rights

You may have rights to access, correct, erase, restrict or object to our use of your data, request data portability, and to object to certain automated decisions. You can withdraw consent for health data or marketing at any time.

To exercise your rights, contact: hi@emotionalpiggy.com. If we cannot resolve your issue, you may contact the UK ICO at ico.org.uk or call 0303 123 1113.

These rights apply as required by law and may be subject to exceptions.

9. Your rights

You may have rights to access, correct, erase, restrict or object to our use of your data, request data portability, and to object to certain automated decisions. You can withdraw consent for health data or marketing at any time.

To exercise your rights, contact: hi@emotionalpiggy.com. If we cannot resolve your issue, you may contact the UK ICO at ico.org.uk or call 0303 123 1113.

These rights apply as required by law and may be subject to exceptions.

10. Security

We use technical and organisational safeguards such as encryption in transit, access controls, logging, staff training, vendor checks, and least-privilege policies.

While no method is 100% secure, we continually review our practices to protect your information.

10. Security

We use technical and organisational safeguards such as encryption in transit, access controls, logging, staff training, vendor checks, and least-privilege policies.

While no method is 100% secure, we continually review our practices to protect your information.

10. Security

We use technical and organisational safeguards such as encryption in transit, access controls, logging, staff training, vendor checks, and least-privilege policies.

While no method is 100% secure, we continually review our practices to protect your information.

11. Cookies and similar technologies

Our website uses cookies to operate, remember your preferences, and (with consent) for analytics and marketing. Non-essential cookies are disabled until you consent.

See our Cookie Policy and Cookie Settings for more information and controls.

11. Cookies and similar technologies

Our website uses cookies to operate, remember your preferences, and (with consent) for analytics and marketing. Non-essential cookies are disabled until you consent.

See our Cookie Policy and Cookie Settings for more information and controls.

11. Cookies and similar technologies

Our website uses cookies to operate, remember your preferences, and (with consent) for analytics and marketing. Non-essential cookies are disabled until you consent.

See our Cookie Policy and Cookie Settings for more information and controls.

12. Children & students

Direct-to-consumer services are not for children under 13. In education settings, we follow the controller’s instructions and applicable laws/consent frameworks.

If you believe a child has provided us data without proper authority, contact us and we will promptly address any issues.

12. Children & students

Direct-to-consumer services are not for children under 13. In education settings, we follow the controller’s instructions and applicable laws/consent frameworks.

If you believe a child has provided us data without proper authority, contact us and we will promptly address any issues.

12. Children & students

Direct-to-consumer services are not for children under 13. In education settings, we follow the controller’s instructions and applicable laws/consent frameworks.

If you believe a child has provided us data without proper authority, contact us and we will promptly address any issues.

13. Third-party links

Our site may link to other websites with their own privacy policies, which we do not control.

You should review those policies before providing personal data to third parties.

13. Third-party links

Our site may link to other websites with their own privacy policies, which we do not control.

You should review those policies before providing personal data to third parties.

13. Third-party links

Our site may link to other websites with their own privacy policies, which we do not control.

You should review those policies before providing personal data to third parties.

14. Changes to this policy

We may update this policy periodically. Any material changes will be communicated via this page and, if significant, also by email or in-app notice.

14. Changes to this policy

We may update this policy periodically. Any material changes will be communicated via this page and, if significant, also by email or in-app notice.

14. Changes to this policy

We may update this policy periodically. Any material changes will be communicated via this page and, if significant, also by email or in-app notice.

15. Contact us

Data Protection Lead: JIALIN ZHANG . If you have any questions or would like to make a privacy request, email us at hi@emotionalpiggy.com.

15. Contact us

Data Protection Lead: JIALIN ZHANG . If you have any questions or would like to make a privacy request, email us at hi@emotionalpiggy.com.

15. Contact us

Data Protection Lead: JIALIN ZHANG . If you have any questions or would like to make a privacy request, email us at hi@emotionalpiggy.com.