Privacy Notice

Intogreat Ltd (“Intogreat”, “Us”, “We”, or “Our”) understands the importance of your privacy and that you want to clearly understand how your Personal Data is used. We will only collect and use Personal Data in ways that are described here, and in a way that is consistent with our obligations and your rights under all relevant data privacy laws.

This Privacy Notice explains how we collect, use, store, protect and share personal data when you complete the Thrive 8 Index. This Privacy Notice is intended for individuals in the United Kingdom and is designed to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations.

Effective date:  27th January 2026

Who we are and how to contact us

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is Intogreat Ltd (company number 13734084)

Registered address: Suite 6a, 10 Duke Street, Liverpool L1 5AS, UK

Telephone: +44 (0) 7597 487 220

General and privacy enquiries email: hello@intogreat.net

This means Intogreat, not your employer, decides how and why your information is used,and is legally responsible for it. You can contact us about anything in this Privacy Notice using the details above.

Data protection officer (DPO)

We have assessed our obligations and, at present, a statutory Data Protection Officer is not required. If you have questions about this assessment or wish to contact the person responsible for privacy matters, please email hello@intogreat.net or write to the address above, marked “Privacy”.

The data we collect

When you complete the Thrive 8 Index, we collect:

•   Identifying details: your name, email address, the organisation you belong to, the country you work in, where relevant, details of the learning programme you attended, and any other demographic details that are relevant to the ongoing development of the Thrive 8 Index.

•   Your assessment responses: your answers to questions about how different parts of your life are feeling, including how you are coping under pressure, your energy, and how connected and supported you feel.

•   Your Thrive 8 Index results: the scores and personal report we generate from your responses.

Because the assessment asks about your well-being, your responses include information about your health. Health information is “special category data” under UK data protection law, which means it has extra legal protection and we may only use it with your explicit consent.

How we use your information, and our legal basis for processing

We use yourinformation for two purposes only:

•   To create your personal Thrive 8 Index report, which is provided to you and to no one else.

•   To produce anonymised, aggregated insights for your organisation, showing patterns across the whole group. Before any group results are shared, all identifying information is removed and responses are combined so that no individual can be identified. We never produce group results for fewer than 10 people, so results cannot be traced back to you even in small teams.

Our legal basis for collecting and using your information is your consent (Article6(1)(a) UK GDPR), and for your health information, your explicit consent (Article 9(2)(a) UK GDPR), which we ask for at the start of the assessment. We do not use your information for marketing, and we do not sell it or share it with anyone for their own purposes.

Only Intogreat; never your organisation, your manager, or anyone else sees your data. You, and only you, receive your report. Once group data has been fully anonymised it is no longer personal data, and we may retain anduse it, for example, to improve and validate the Thrive 8 Index. This never includes anything that could identify you.

Your report is generated by Intogreat using our own scoring tools within our secure Microsoft365 environment. No decisions are made about you by automated means, and your individual results are never used to evaluate you for employment purposes.

Taking part is voluntary

Completing the Thrive 8 Index is entirely your choice. Your organisation has commissioned the assessment, but it does not see who has or has not taken part in individual terms, and choosing not to participate, or withdrawing later, has no consequences for you. Consent given under pressure is not valid consent, and we have designed the assessment so that no such pressure can arise.

s

Who can see your information

Your individual answers, scores and report are seen only by Intogreat. They are never shared with your organisation, your manager, HR, or any other third party. You are the only person who receives your personal report.

We use Microsoft365 (including Microsoft Forms, Excel and OneDrive) to collect, store and process assessment data. Microsoft acts as our data processor under contract terms that require it to protect your data and use it only on our instructions. We do not use any other service providers to process your assessment data. Microsoft may store data in data centres outside the UK. Where this involves a transfer of your data internationally, it takes place under safeguards recognised by UK law, including UK adequacy regulations and the International Data Transfer Addendum to the EU Standard Contractual Clauses.

We would disclose personal data to other parties only if required to do so by law.

How long we keep your information

We keep your identifiable responses, scores and personal report for the duration of your organisation’s assessment cycle plus 12 months: an assessment cycle is usually 12 months, so in most cases your data is deleted within 24 months of completing the assessment. This allows us to support you and your organisation through the cycle, including any re-assessment, before your data is securely deleted.

Anonymised, aggregated group results contain nothing that identifies you and may be kept for longer.

How we protect your information

Your data is held in Intogreat’s secure Microsoft 365 environment, protected by access controls, encryption in transit and at rest, and multi-factor authentication. Access is restricted to the Intogreat team members who need it to run the assessment and produce reports.

We maintain procedures to identify, investigate, and remediate personal data breaches. Where required, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable personal data breach. Where a breach is likely to result in a high risk to your rights and freedoms, we will also inform you without undue delay, providing information about the nature of the breach, likely consequences, and measures taken.

Your rights

Under UK data protection law you have the right to:

•   Withdraw your consent at any time. Email hello@intogreat.net marked "Privacy" and we will stop processing your data and delete your responses and report. Withdrawing is as easy as consenting, and does not affect anything done before you withdrew. Where your responses have already been included in fully anonymised group results, those results cannot be unpicked, but they contain nothing that identifies you.

•   Access a copy of the personal information we hold about you.

•   Correct information that is inaccurate or incomplete.

•   Have your information erased, restrict how we use it, or object to its use.

•   Data portability: receive the information you gave us in a usable electronic format.

To exercise any of these rights, contact hello@intogreat.net. We will respond within one month. There is no charge.

You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO): ico.org.uk • 0303 123 1113 • Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would welcome the chance to address any concern first, but you may contactthe ICO at any time.

International users

If you access the Thrive 8 Index from outside the UK, please note that your data may be processed in the UK or other countries where our providers operate. We will implement appropriate safeguards for any transfers as described above.

Provision of the website and creation of log files

Each time you access our website, our system automatically collects data and information from the computer system of the accessing computer.

The following data is collected:

  1. Information about the browser type and the version used.
  2. The operating system of the user.
  3. The Internet service provider of the user.
  4. The IP address of the user.
  5. Date and time of access.
  6. Websites from which the user’s system accesses our website.
  7. Websites that are accessed by the user’s system via our website.

This data is stored in the log files of our system. This data is not stored together with other personal data of the user.

The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user’s computer. For this purpose, the user’s IP address must remain stored for the duration of the session.

The storage in log files is done to ensure the functionality of the website. An evaluation of the data for marketing purposes does not take place in this context.

These purposes are also our legitimate interest in data processing according to Art. 6 (1) sentence 1 lit. f GDPR. The legal basis for the temporary storage of the data and the log files is Art. 6 (1) sentence 1 lit. f GDPR.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.

If the data is stored in log files, this shall be the case after seven days at the latest. Storage beyond this, e.g., for fraud prevention, is possible. In this case, the IP addresses of the users are deleted or alienated so that an assignment of the calling client is no longer possible.

The collection of data for the provision of the website and the storage of the data in log files is necessary for the operation of the website. Consequently, there is no possibility for the user to object.

Use of cookies

Our website uses cookies. Cookies are text files that are stored in the internet browser or by the internet browser on the user’s computer system. When a user calls up a website, a cookie may be stored on the user’s operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again.

We use cookies to make our website more user-friendly. Some elements of our website require that the calling browser can be identified even after a page change.

The following data is stored and transmitted in the cookies:


  1. Accessibility settings.
  2. Frequency of page views.
  3. Use of website functions.

The user data collected in this way is pseudonymized by technical precautions. Therefore, it is no longer possible to assign the data to the calling user. The data is not stored together with other personal data of the user.

When calling up our website, the user is informed about the use of cookies for analysis and other than technically necessary purposes and his or her consent to the use of such cookies and the processing of personal data used in this context is obtained. In this context, a reference to this data protection declaration is also made.

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognised even after a page change.

The legal basis for the processing of personal data using technically necessary cookies is Art. 6 (1) sentence 1 lit. f GDPR.

Cookies are stored on the user’s computer and transmitted to our site by the user. Therefore, you as a user also have full control over the use of cookies. By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been saved can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all the functions of the website to their full extent.

If you use a Safari browser from version 12.1, cookies are automatically deleted after seven days. This also applies to opt-out cookies, which are set to prevent tracking measures.

Newsletter

On our website, you have the option of subscribing to a free newsletter. When registering for the newsletter, the data from the input mask is transmitted to us.

  1. Email address.
  2. Name.
  3. First name.
  4. IP address of the accessing computer.
  5. Date and time of registration.

No data will be passed on to third parties in connection with the processing of data for the dispatch of newsletters. The data is used exclusively for sending the newsletter.

The collection of the user’s email address serves to deliver the newsletter. The collection of other personal data during the registration process serves to prevent misuse of the services or the email address used.

The legal basis for the processing of data after registration for the newsletter by the user is Art. 6 (1) sentence 1 lit. a GDPR if the user has given his or her consent.

The data processed in connection with the so-called double opt-in procedure (IP address, time stamp) is based on Art. 6 (1) lit. f GDPR. In cases of doubt, being able to prove that you have consented to receive our newsletter is considered a legitimate interest.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. The user’s email address is therefore stored if the subscription to the newsletter is active. The other personal data collected during the registration process is usually deleted after a period of seven days.

E-mail contact

On our website, it is possible to contact us via the email address provided. In this case, the user’s personal data transmitted with the email will be stored. The data is used exclusively for processing the conversation.

In the case of contact by email, this also constitutes the necessary legitimate interest in processing the data. The legal basis for the processing of the data is Art. 6 (1) lit. a GDPR if the user has given his or her consent.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation is terminated when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

The additional personal data collected during the sending process will be deleted after a period of seven days at the latest.

The user has the possibility to revoke his consent to the processing of personal data at any time. If the user contacts us by email, he or she can object to the storage of his or her personal data at any time. In such a case, the conversation cannot be continued.

The data will be used exclusively for the processing of the conversation and will be deleted afterwards.

Contact form

Our website contains a contact form that can be used for electronic contact. If a user uses this option, the data entered in the input mask is transmitted to us and stored.

At the time the message is sent, the following data is stored:

  1. Email address.
  2. Name.
  3. First name.
  4. IP address of the calling computer.
  5. Date and time of contact.
  6. Reason for contacting us.

For the processing of the data, your consent is obtained during the sending process and reference is made to this data protection declaration. Alternatively, it is possible to contact us via the email address provided. In this case, the user’s personal data transmitted with the email will be stored. The data is used exclusively for processing the conversation.

The processing of the personal data from the input mask serves us solely to process the contact. In the case of contact by email, this also constitutes the necessary legitimate interest in processing the data. The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.

The legal basis for the processing of the data is Art. 6 (1) sentence 1 lit. a GDPR if the user has given his or her consent. If the email contact aims at the conclusion of a contract, the additional legal basis for the processing is Art. 6 (1) sentence 1 lit. b GDPR.


The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and those sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when the circumstances indicate that the matter in question has been conclusively clarified. The additional personal data collected during the sending process is deleted after a period of seven days at the latest.

The user has the possibility to revoke his consent to the processing of personal data at any time. If the user contacts the controller by email, he or she can object to the storage of his or her personal data at any time. In such a case, the conversation cannot be continued. The data will be used exclusively for the processing of the conversation and will be deleted afterwards.

Hosting

The website is hosted on servers provided by our service provider. Our service provider is: Webflow Rank, 398 11th Street, San Francisco, United States.

The servers automatically collect and store information in so-called server log files, which your browser automatically transmits when you visit the website. The information stored is:

  • Browser type and browser version.
  • Operating system used.
  • Referrer URL.
  • Host name of the accessing computer.
  • Date and time of the server request.
  • IP address.

This data is not merged with other data sources. The collection of this data is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, the server log files must be collected.

The location of the server of the website is geographically in Ireland.

Disclosure to third parties

We do not sell, trade, or otherwise transfer to outside parties your personal data. This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our website policies, or protect ours or others’ rights. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.

Your consent

By using our website, you consent to this Privacy Notice.

Changes to this notice

We may update this Privacy Notice from time to time. We will post any changes on this page and, where appropriate, notify you by email. Please review this Privacy Notice regularly.

Contact

For privacy questions, to exercise your rights, or to make a complaint, please contact:

Data Controller: intogreat Ltd

Address: Suite 6A, 10 Duke Street, Liverpool, L1 5AS, UK

Email: hello@intogreat.net

Telephone: +44 (0)7597 487 220

We will respond as soon as reasonably practicable and within the timeframes required by UK data protection law.