Privacy Notice

Last updated: July 2026

1. Who we are

UHB Research Hub is an internal knowledge-sharing platform for staff of University Hospitals Birmingham NHS Foundation Trust (UHB). It is maintained by UHB staff and hosted on secure UK/EU infrastructure.

2. What personal data we collect

  • Account details: name, UHB ID, work email address, hashed password.
  • Content you submit: research titles, authors, descriptions, uploaded documents, DOIs and external links, comments, ratings, suggestions.
  • Technical data: sign-in timestamps, browser type, IP address (used only for security and abuse prevention).

3. Lawful basis

Processing is carried out under UK GDPR Article 6(1)(e) — public task — and Article 9(2)(h) where relevant to the provision of health services. We do not process patient-identifiable data in this system; uploads containing such data are blocked automatically and any that slip through will be removed and reported.

4. How we use your data

  • To operate the site and let colleagues discover approved research.
  • To administer accounts, uploads, comments, notifications and suggestions.
  • To maintain an immutable audit trail of admin actions (approvals, rejections, role changes) for governance purposes.

5. Sharing

Your name, work email and submitted content are visible to other signed-in UHB colleagues so that they can contact you about your work. Nothing on the platform is public to the internet unless you provide an external DOI/URL.

6. Retention

Accounts and content are retained while the platform is in use. You may request deletion of your account or any specific upload at any time; admin approval is required before removal (in line with records-management requirements).

7. Your rights

You have the usual UK GDPR rights: access, rectification, erasure, restriction, portability and objection. To exercise them, contact the site administrator using the Suggestions tab or email the UHB Information Governance team.

8. Security

  • All traffic is encrypted (HTTPS/TLS).
  • Passwords are hashed and checked against the Have I Been Pwned breach database.
  • Row-level security policies ensure users can only edit their own content.
  • Admin actions are recorded in a tamper-evident audit log.
  • Free-text fields are scanned for patterns resembling NHS numbers and hospital IDs.

9. Contact

For privacy questions, contact the site administrator via the Suggestions tab or the UHB Information Governance team via the trust intranet.