Pocket PMO

1. Data Controller

Pocket PMO Ltd ("we", "us", "our") is the data controller responsible for your personal data. This privacy policy explains how we collect, use, and protect your information in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Contact: For data protection inquiries, please contact us through our Support page.

2. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to provide our services to you
  • Legitimate Interests (Art. 6(1)(f) GDPR): Analytics, security, and service improvement
  • Consent (Art. 6(1)(a) GDPR): Marketing communications and optional cookies
  • Legal Obligation (Art. 6(1)(c) GDPR): Compliance with applicable laws

3. Information We Collect

We collect and process the following categories of personal data:

  • Account Information: Email address, name, and authentication credentials
  • Project Data: Projects, risks, issues, actions, dependencies, tasks, milestones, documents, decisions, lessons, change requests, and reports you create
  • Profile Photo and Avatar: If you choose to create an avatar, the photo you upload and the stylised portrait generated from it. This is optional, and the stylised portrait is shown on reports you choose to publish
  • Team Member Data: Names and email addresses of team members you add to projects
  • Financial Data: Budget information and ROI calculations you enter
  • Usage Data: How you interact with the Service, features used, preferences, and locally stored filter/view settings
  • Technical Data: IP address, browser type, device information
  • Communications: Support requests and feedback you submit

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process and store your project management data
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and requests
  • Analyze usage patterns to improve user experience
  • Power AI features including the AI project team (planning, RAID, reporting and quality assistants), with your explicit consent
  • Send transactional emails produced by AI workflows (meeting invites, task notifications) to active registered users, only after PM approval
  • Generate and email scheduled reports and snapshot links to the recipients and on the cadence you configure
  • Send occasional product guidance emails to registered users (for example, help getting started if your account is set up but unused). These are sent on the basis of legitimate interest (Art. 6(1)(f) GDPR) and every message includes an unsubscribe link
  • Create an optional stylised avatar from a photo you upload, and display your name and that avatar on snapshot reports you publish, so recipients can see who shared the report
  • Enable data portability through JSON and CSV export formats
  • Detect, prevent, and address technical issues and security threats

4a. Free Sandbox and Demo

Our public sandbox and interactive demo require no account. Any plan you build there is stored only in your own browser's local storage — it is never sent to or stored on our servers, and it is cleared when you reset the sandbox, clear browser data, or after a period of inactivity. We collect no personal data from you to use the sandbox beyond the standard, privacy-friendly page analytics described in our Cookie Policy.

5. Data Hosting & Storage Location

Your data is stored on enterprise-grade cloud infrastructure:

  • Primary Data Centre: European Union (EU) region
  • Database: PostgreSQL with AES-256 encryption at rest
  • Backups: Daily automated backups retained for up to 90 days
  • Encryption in Transit: TLS 1.3 for all connections

For enterprise customers requiring specific data residency (e.g., UK-only, specific country), please contact us through our Support page.

6. Data Recipients and Third Parties

We share your data with the following categories of recipients:

  • Cloud Infrastructure: EU-based hosting provider for data storage and processing
  • AI Service Providers: For AI-powered features (data processed in accordance with Data Processing Agreements)
  • Email Delivery Service (Resend): For transactional and product emails including AI-initiated meeting invites, task assignment notifications, RAID item updates, scheduled reports and getting-started guidance, sent from our notification domain to active platform users
  • Authentication Services: For secure login functionality
  • Microsoft 365 (optional, opt-in): When you connect your tenant via Settings → Integrations, we call Microsoft Graph on your behalf to sync milestones to Outlook calendar, send report emails from your Outlook mailbox, post to Microsoft Teams, and upload files to SharePoint. OAuth tokens are AES-GCM encrypted at rest and only used for actions you trigger or explicitly enable. Disconnecting performs a soft-revoke and retains audit history.
  • Error Monitoring (Sentry): Receives stack traces, browser/device metadata and minimal user identifiers when the app encounters an unexpected error, so we can detect and fix bugs. Sentry does not receive your project content, RAID items, documents, or AI conversations.
  • Recipients of snapshot links you create: When you generate a shareable snapshot (project, portfolio, status or budget, the last of which contains financial figures), we store a point-in-time copy of the selected data and make it available at a unique unguessable link that requires no login. Anyone you send that link to can view the snapshot until it is revoked. You control whether a snapshot is created and who receives the link; the snapshot never updates after generation.
  • Questions asked of a published snapshot (optional): If you switch on questions for a snapshot, viewers can ask questions about it. The question text and the frozen snapshot data are sent to our AI provider to produce an answer, and questions are logged (with a count) so you can see what was asked. Viewers are not asked to identify themselves; we record only the question, the time and rate-limiting metadata. Turning questions off stops this immediately.
  • Private briefing notes on a report (optional): If you add a briefing note to a snapshot, it is stored with that snapshot and sent to our AI provider alongside the frozen data when a viewer asks a question, so the answer can reflect the context you gave. The note itself is never displayed on the report or returned verbatim; deleting the note or turning questions off stops it being used.
  • Guided setup session requests: If you request a free guided setup session, we store the contact details and context you submit and raise it as a support request so we can arrange the session with you by email.

We do not sell your personal data to third parties. We may disclose information to comply with legal obligations or to protect rights, privacy, safety, or property.

6a. Authorised Support & Administrator Access

A small number of named PocketPMO staff hold an internal administrator or support role that allows them to access account and project data when strictly necessary to operate, maintain or troubleshoot the Service, investigate security incidents, or fulfil a support request you have raised. Specifically:

  • Administrator and support actions are gated by role checks and require two-factor authentication.
  • Every administrative action, including viewing user details, changing a subscription, issuing a refund, granting credits, suspending an account, or generating a one-time impersonation link, is written to an immutable audit log with the actor, target, reason and timestamp.
  • "View as user" impersonation issues a single-use, short-lived sign-in link; the impersonating session shows a persistent red banner and is logged from start to finish.
  • Administrators cannot retrieve your password and cannot disable the audit log.
  • Webhook signing secrets and end-user secrets are never displayed to staff.

You can request a copy of audit entries that relate to your account via our Data & Privacy page.

7. International Data Transfers

Your data may be processed in countries outside the European Economic Area (EEA). Where we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules where applicable

8. Data Retention

We retain your personal data for as long as necessary to:

  • Active accounts: For the duration of your account plus 30 days after deletion request
  • Avatars: Uploaded photos are processed to produce the stylised portrait and are not retained; the portrait is stored privately until you remove it or delete your account. Published snapshot reports keep a frozen copy of the publisher name and avatar until the link is deactivated
  • Backup data: Up to 90 days in encrypted backups
  • Legal compliance: As required by applicable laws (e.g., billing and financial records typically retained for 6 years in line with HMRC guidance)
  • Dispute resolution: As needed to resolve any disputes

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Request correction of inaccurate data
  • Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
  • Right to Data Portability (Art. 20): Receive your data in machine-readable formats (JSON full export, CSV portfolio exports)
  • Right to Object (Art. 21): Object to processing based on legitimate interests
  • Right to Restrict Processing (Art. 18): Request restriction of processing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, visit our Data & Privacy page or contact us through the Support page.

10. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (TLS 1.3) and at rest
  • Row-level security policies for data access control
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Audit logging of data access and modifications

11. AI Features and Automated Processing

Our AI-powered features (document generation, risk analysis, meeting summaries) process your project data to provide insights and generate content. Key points:

  • AI processing is performed securely with appropriate safeguards
  • Your data is not used to train general AI models
  • You can opt out of AI features while retaining core functionality
  • No fully automated decision-making with legal or significant effects is performed
  • AI workflows may draft emails (meeting invites, notifications), which, once approved by you, are sent only to users with active accounts who have accepted the Terms of Service
  • Calendar invites (.ics files) are generated and sent as interactive meeting requests
  • Our proactive delivery watcher runs scheduled scans over project data you have already provided (tasks, RAID items, milestones and owners). It creates no new categories of personal data, and its findings and drafted fixes are advisory only until you approve them

12. Cookies and Tracking

We use cookies and similar technologies. For detailed information about our cookie usage and how to manage preferences, see our Cookie Policy.

13. Children's Privacy

The Service is not intended for users under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware of such collection, we will take steps to delete the data promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. Continued use of the Service after changes constitutes acceptance.

15. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in your country of residence. We encourage you to contact us first so we can address your concerns directly.

16. Contact

For privacy-related questions, requests, or to exercise your data rights:

This policy was last updated on 26 August 2026. See also our Terms of Service and Cookie Policy.