Privacy Notice
Last updated: September 2026
1. Who we are
UHB Research Hub is an internal knowledge-sharing platform for staff of University Hospitals Birmingham NHS Foundation Trust (UHB). It is maintained by UHB staff and hosted on secure UK/EU infrastructure.
2. What personal data we collect
- Account details: name, UHB ID, work email address, hashed password.
- Content you submit: research titles, authors, descriptions, uploaded documents, DOIs and external links, comments, ratings, suggestions.
- Technical data: sign-in timestamps, browser type, IP address (used only for security and abuse prevention).
3. Lawful basis
Processing is carried out under UK GDPR Article 6(1)(e) — public task — and Article 9(2)(h) where relevant to the provision of health services. We do not process patient-identifiable data in this system; uploads containing such data are blocked automatically and any that slip through will be removed and reported.
4. How we use your data
- To operate the site and let colleagues discover approved research.
- To administer accounts, uploads, comments, notifications and suggestions.
- To maintain an immutable audit trail of admin actions (approvals, rejections, role changes) for governance purposes.
5. Sharing
Your name, work email and submitted content are visible to other signed-in UHB colleagues so that they can contact you about your work. Nothing on the platform is public to the internet unless you provide an external DOI/URL.
6. Retention & deletion schedule
We keep personal data only as long as it is needed (UK GDPR storage limitation). The following periods are applied automatically:
- Opportunity applications (including any CV link): deleted 6 months after the opportunity's closing date.
- Closed or filled opportunities: deleted 24 months after they were last updated.
- In-app notifications: deleted after 12 months.
- Admin audit log: retained 2 years, then deleted.
- Completed data protection requests: retained 12 months as evidence of compliance, then deleted.
- Accounts and submitted research: retained while the account is active; you may request deletion at any time.
You may request deletion of your account or any specific upload at any time; admin approval is required before removal (in line with records-management requirements).
7. Your rights
You have the usual UK GDPR rights: access, rectification, erasure, restriction, portability and objection. Signed-in users can download a full copy of their data, delete their account, or raise a formal data protection request from Settings → Your data. Every request is logged with a 30-day response deadline and tracked by an administrator. You may also contact the UHB Information Governance team, or complain to the Information Commissioner's Office.
8. Records of processing (ROPA) & data protection impact
A summary Record of Processing Activities and a Data Protection Impact Assessment for this platform are maintained by the site owner and available to the UHB Information Governance team on request. In outline:
- Processing activities: staff account management; publication of staff-authored academic outputs; research/audit collaboration advertising and applications; site feedback messaging; administrative audit logging.
- Data subjects: UHB staff and trainees only. No patient data is processed — free-text and uploaded documents are automatically screened for patient identifiers and blocked.
- Categories of data: name, UHB ID, work email, career grade and specialty, submitted academic content, application messages and optional CV links.
- Recipients / processors: the hosting and database provider and the email delivery provider, under contract, within the UK/EEA or equivalent safeguards.
- Risks and mitigations: inadvertent disclosure of patient data (mitigated by automated identifier screening, mandatory declarations and admin approval); unauthorised access (mitigated by UHB-domain-restricted sign-up, row-level security, audit logging and 30-minute idle sign-out); excessive retention (mitigated by the schedule in section 6).
9. Security
- All traffic is encrypted (HTTPS/TLS).
- Passwords are hashed and checked against the Have I Been Pwned breach database.
- Row-level security policies ensure users can only edit their own content.
- Admin actions are recorded in a tamper-evident audit log.
- Free-text fields are scanned for patterns resembling NHS numbers and hospital IDs.
10. Contact
For privacy questions, contact the site administrator via the Suggestions tab or the UHB Information Governance team via the trust intranet.