Data Protection Impact Assessment
Where handling personal information is likely to be high risk to people, the law requires an assessment of that risk and of what reduces it. This page summarises ours, for the research Vellinx carries out on organisations and the roles in them. It sits beside our privacy notice, which says what we do; this page says what could go wrong for the people concerned, and what we do about it.
The full assessment is a working document that we keep up to date. This summary is of version 2, dated 29 September 2026, which replaced version 1 of 14 June 2026. We have left out detail that is commercially sensitive or could weaken our security. If you would like to know more, contact us at privacy@vellinx.com.
What the assessment covers
It covers the research described in our privacy notice under "People at the organisations we research": researching an organisation, and the roles in it, for a user with a genuine business reason to approach that organisation. Our own marketing, running the service for the people who use it, this website's logs and the handling of complaints are described in the notice too; none of them is high risk on its own, and the assessment refers to them only where they meet the research.
Why we carried out an assessment
The research meets more than one of the conditions that the Information Commissioner's Office (ICO), the UK's data protection regulator, lists as needing an assessment:
- It combines information from several sources: an organisation's own website, news and trade press, and public registers such as Companies House.
- It uses AI to do so, to read those sources and write the briefing.
- The information does not come from the people it is about, and most of them are not told about the research directly.
- It evaluates: it describes what the holder of a role is likely to care about, and a role at a named organisation is usually one person.
Describing roles rather than naming people reduces what we hold. It does not take the research outside data protection law, and it does not remove the need for this assessment.
How the research works
- A user chooses an organisation. The research reads public pages about it and writes a briefing that describes people by their role, such as "the chief commercial officer", not by name.
- We keep a copy of each page the research reads, so that every claim can be checked against the page it came from. Before a page is kept, email addresses, telephone numbers and the name of anyone who has objected are taken out of it, and so is any line our screen flags as being about someone's health, genetic or biometric data, religion or beliefs, political opinions, trade union membership, racial or ethnic origin, sex life or sexual orientation, or criminal convictions or offences.
- The same is done to what the research writes, before anything is stored or shown, so that a page written to steer the research into saying such things cannot get them stored.
- Every claim in a briefing links to the pages it came from and is marked with how confident it is and how current its sources are.
- Everything a research run produces is deleted six months after the run. Only figures that name no one, such as how long a run took, are kept after that.
- A person reads the briefing and decides whether and how to approach. Nothing about anyone is decided automatically.
Is it necessary and proportionate?
Our lawful basis is legitimate interests, which we have weighed against the interests and rights of the people concerned in a separate assessment. The research exists to make an approach relevant to what an organisation is dealing with and to the right role, and it reads the same public, professional sources a person preparing the approach would read. What we hold is kept to what that needs: roles rather than names, no contact details for the people researched, no research into anyone's private life, and one six-month limit on everything a run produces. An objection to the research is final: we stop, and delete what names the person.
On that basis, and with the measures below, the assessment concludes that the research is necessary and proportionate.
The risks, and what reduces them
Each risk is rated as it stands after the measures that reduce it, on a scale of low, medium and high.
- A briefing gets something wrong about a role. Every claim is marked with how it stands and linked to its pages; a check reads each verified claim against its own pages and marks down what they do not carry; any figure used in a suggested approach must rest on a verified claim or on evidence the user supplied; and a person reviews everything. Medium, falling to low to medium once we have a written accuracy standard that logged research runs meet.
- People do not know the research happens. Our privacy notice describes it, and anyone can object. Low.
- The research goes further than people would expect. It is limited to a role at that organisation, from business sources, and never looks at private life or personal social media. Low.
- Sensitive or discriminatory inferences. The research is instructed not to write about health, beliefs and the other sensitive kinds of information, and a screen withholds any line it flags, from what is kept and from every briefing. A screen of words cannot see such matter conveyed by suggestion, which is why the instruction and the screen are separate measures. Low, subject to the live test listed below; the general bias of an AI model is monitored rather than removed.
- Information is transferred outside the UK. Our AI provider's safeguards include the UK International Data Transfer Addendum. Medium until our assessment of the onward transfer to the United States is complete and reviewed.
- A security breach. Security measures across every place research is kept, the six-month deletion, and a written breach procedure. Medium, falling to low once the copies we keep for our own working are also held to the six-month limit.
- A page written to manipulate the research. Pages reach the AI model as material to read, not as instructions, and whatever the research is led to write, contact details, the names of people who have objected and sensitive lines are taken out before anything is stored. We test this against a hostile page. Low to medium.
- The research quietly widens over time. Every change that touches the research's instructions, what we store or what we fetch is checked against this assessment, the privacy notice and our terms before it is closed. Low, now that this check is part of closing every such change.
- The AI model changes. Automated tests run on every change, the checks on each claim do not assume the model is right, and each logged test is run again when the model changes. Low to medium.
- A customer misuses a briefing. Our terms of use limit briefings to the customer's own organisation, forbid decisions about anyone's job, credit, insurance, housing, education or access to a service, and require a customer to delete its copy when we pass on an objection. Low to medium.
Our conclusion
With these measures, no risk to the people we research is rated high, and once the open measures below are complete the overall risk is low to medium. The assessment therefore concludes that consulting the ICO before processing is not required. If a test shows a high risk that we cannot reduce, we will consult the ICO first.
Some of these conclusions, this one among them, are of a kind that only a qualified lawyer can confirm. That review has not yet taken place.
What is still open
- A written standard for the accuracy of a briefing, met on logged research runs.
- A logged test, on a real research run, that a role whose holder has objected is left out and that the screen works.
- A logged check, with the first objection we receive, that it reaches every place research is kept.
- Our assessment of the onward transfer to the United States, and its legal review.
- A control that holds the copies we keep for our own working to the same six-month limit, by 21 December 2026, and one that deletes database safety copies after seven days without our having to run it.
- Confirming the terms of the AI assistant we use in our own work, and that it does not train on what it is shown.
Each test is recorded, with its date and result, in a verification log that forms part of the assessment, and is run again when something it depends on changes.
How we keep it up to date
We review the assessment at least once a year, when the law changes, and whenever the research gains a capability that affects personal information. We update this summary when the assessment's conclusions change.
Summary of version 2 of the assessment, dated 29 September 2026 · Published 29 September 2026.