The Jam Jar ← Back to the site

Security & Data Protection

Answers to the questions organisations ask before buying seats · The Jam Jar, run by The Human-Centric Workplace Ltd

If you are considering corporate membership, your IT, procurement or data protection team will want to know what we hold, where it lives and how it is looked after. This page answers that up front, in plain English, so nobody has to chase a questionnaire round by email.

We would rather tell you what we are than describe what we are not. The Jam Jar is a small, focused community platform run by a two-person business. Our controls are built to match what we actually hold, and we say clearly below where a larger supplier would offer more.

At a glance

Certification and assurance

Are you ISO 27001 certified?

No. The Human-Centric Workplace Ltd does not hold ISO 27001 certification, and we will not imply otherwise to win business.

ISO 27001 certifies that an organisation runs a formal, independently audited information security management system. For a two-person business running one community platform, the certification cost would land on membership prices without meaningfully changing how safe your people's data is.

What we do instead is described throughout this page, and it is specific rather than aspirational. If your procurement process requires certification from all suppliers without exception, we would rather you know that now than three meetings in.

Are you SOC 2 or Cyber Essentials certified?

No. The same answer applies. If Cyber Essentials would unblock a purchase for you, tell us — it is a proportionate scheme for a business our size and we would consider it.

Are your suppliers certified?

Yes, and this is where most of the meaningful assurance sits, because the infrastructure your data actually lives on is run by companies considerably larger than us. Supabase, Netlify, Stripe, Resend and Anthropic each maintain their own security certifications and publish them on their trust pages. We are happy to point you to the current ones.

Do you carry out penetration testing?

We do not commission third-party penetration tests. We do run a scripted security test against the live platform that attempts, as an outsider would, to read every database table, list the photo storage, and call our private server functions without a login. It runs after every significant change. We are happy to share the results.

Do you hold cyber liability insurance?

Not at present. If cover is a requirement of your procurement process, say so early — for a business our size it is a proportionate and obtainable step, and we would rather arrange it than lose the conversation over it.

Roles and responsibilities

Are you a data controller or a data processor?

For the running of The Jam Jar, we are the data controller. We decide what is collected and why, and we are accountable for it. Your people join as individual members of our community, rather than us processing your data on your instructions.

There is one exception. If you supply us with a list of employees so we can set up their seats, you are the controller for that list and we act as your processor for the narrow purpose of creating those accounts. From the point someone becomes a member, we are controller again.

This matters for your records of processing, and we are happy to put it in writing in whatever form your team needs.

Who is accountable for data protection at your end?

Simone Fenton-Jarvis, co-founder, is our named privacy contact and is accountable for data protection. We have not appointed a statutory Data Protection Officer, as we do not meet the UK GDPR criteria requiring one: we do not carry out large-scale systematic monitoring, and we do not process special category data on a large scale.

Will you sign our Data Processing Agreement?

We will review any DPA you send. Where we act as controller rather than processor, some standard processor clauses will not apply, and we will say so rather than signing something that misdescribes the relationship. For the seat-setup processing described above, a processor DPA is appropriate and we will sign one.

What you are actually trusting us with

What data do you hold about our employees?

CategoryWhat it is
AccountWork email address, membership status, plan, and a Stripe reference. Nothing more is required to hold an account.
ProfileWhatever the member chooses to add: name, photo, job title, country, a short bio, a LinkedIn link.
ContributionsDiscussion threads, replies, feed posts and comments, reactions, ratings, questions to our experts, and feature requests.
PaymentHandled entirely by Stripe. We never see or store card details.

We do not ask for special category data, and we do not profile members.

Can we see what our employees post?

Not as their employer — but read the next paragraph, because the honest answer has a caveat and we would rather you heard it from us.

We give organisations no visibility of individuals. No dashboard, no reporting on who posted what, no engagement statistics by name, no export of anyone's contributions. We will tell you how many of your seats are in use and nothing more, and we would push back if asked for more.

The caveat: The Jam Jar is a single shared community, not a private space per organisation. Anyone holding an active membership sees what everyone posts — and that includes anyone from your own organisation who holds one of your seats. If your HR director takes a seat, they read the community like any other member, colleagues included.

We tell members this plainly, so nobody is posting under a false assumption. Where someone wants to raise something without their name attached, Ask an Expert takes anonymous questions.

So the promise we make is precise: we will not become a channel for reporting on your people. We cannot make colleagues invisible to each other inside a shared community, and we will not pretend otherwise.

If you need to identify an individual member's activity for a genuine legal reason — a regulatory investigation, litigation, or a lawful request — contact us and we will handle it properly, considering our obligations to both you and the member.

What can other members see?

Members of the community see each other's name, photo, job title and country in the member directory, and everything anyone posts in the shared spaces. Nothing is visible to the public, and the community is closed to non-members. Members can contact each other through the platform; the recipient receives the sender's email address so they can reply directly.

Where the data lives

Is our data stored in the UK?

Yes. The database and file storage holding profiles, posts and photos are hosted in Supabase's London region (eu-west-2). Member content does not leave the UK at rest.

Who else processes the data, and are there international transfers?

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageData at rest in London, UK. US-incorporated company.
NetlifyWebsite hosting and server-side functionsUSA
StripePayments and subscription managementIreland and USA
ResendTransactional email (login codes, notifications, digest)USA
AnthropicThe AI behind our BEAM feedback toolUSA

Where personal data reaches a US provider, the transfer is covered by either the UK–US Data Bridge, for providers certified under it, or the ICO's International Data Transfer Agreement or Addendum. We will notify members through our privacy notice before adding a sub-processor.

Do you use our data to train AI models?

No. Our BEAM feedback tool sends what a member types to Anthropic's API to generate coaching feedback. Under Anthropic's commercial terms that content is not used to train their models and is retained only for a limited period. We keep no copy of it ourselves.

We also ask members directly, in the tool and in our privacy notice, not to enter real names of colleagues when describing a situation.

Security controls

How do members sign in?

With a six-digit code sent to their email address. There are no passwords, which removes an entire category of risk: nothing to reuse across sites, nothing to phish in the usual way, and nothing for us to store or leak. Codes are short-lived and single-use.

How do you control access to data?

Access rules are enforced by the database itself, through row-level security on every table, rather than only by the website. A member's session determines what they can read or change at the data layer, so a flaw in the front end cannot be used to reach data that member is not entitled to. Uploaded photos are protected the same way. Lapsed members lose access automatically.

How are administrative privileges handled?

Two people — the company's co-founders — hold administrative access. Administrative actions are verified on the server against the signed-in identity, not asserted by the browser. Credentials for our infrastructure providers are held server-side only and are never sent to a member's browser.

Every account with administrative access to our infrastructure — database, hosting, source control and payments — is protected by multi-factor authentication. Administrative access is limited to the smallest number of people who can run the business, and is reviewed whenever that changes.

Is data encrypted?

Yes. All traffic to and from the platform uses HTTPS, and data is encrypted at rest by our infrastructure providers as standard.

How are payments secured?

Stripe handles the entire payment flow. Card details never touch our systems. Payment events reaching our platform are cryptographically verified as genuinely from Stripe before anything is acted on.

Incidents, retention and rights

What happens if there is a data breach?

We will investigate immediately and contain the issue. Where a personal data breach is likely to result in a risk to people's rights and freedoms, we will report it to the ICO within 72 hours of becoming aware, as UK GDPR requires. We will inform affected members directly where the risk to them is high.

For corporate customers, we will notify your named contact within 72 hours of becoming aware of any breach affecting your people, whether or not it meets the threshold for regulatory reporting.

How long do you keep the data?

DataRetention
Account and profileDeleted automatically 90 days after the membership ends. The delay exists so a member who rejoins is not starting from nothing.
ContributionsRetained so remaining members' conversations still make sense, but detached from the person: the account is deleted and posts appear as "Former member" with the email address removed from our records.
Reactions, votes, ratings, saved itemsDeleted with the account.
Payment and transaction recordsSix years, as UK tax law requires.

Deletion is automated and runs daily. It is not a manual promise someone has to remember to keep.

How do our employees exercise their data protection rights?

By emailing simone@thehuman-centricworkplace.com. Rights of access, rectification, erasure, restriction, portability and objection all apply. We respond within one month, free of charge. Members can edit most of their own profile themselves, and can ask for their contributions to be deleted as well as their account.

What happens when we stop buying seats?

Your people's accounts lapse and their access ends immediately. Their data follows the retention schedule above. Individual members may choose to continue with a personal membership, which is their decision rather than yours or ours. We do not hold your data hostage and there is no exit fee.

Business continuity

What happens if The Jam Jar goes down?

Realistic answer: The Jam Jar is a professional community, not a system your business depends on to operate. An outage is an inconvenience rather than a business continuity event, and we do not offer a contractual uptime guarantee. Our hosting and database providers publish their own status pages and availability records.

Is the data backed up?

Yes. Our database is backed up automatically every day and retained for seven days, and can be restored by our infrastructure provider. Uploaded files are held on redundant storage infrastructure.

What if the business is sold or closes?

If the business changes hands, our privacy notice continues to apply and members would be informed. If The Jam Jar were to close, we would give members reasonable notice, an opportunity to export their own contributions, and would delete the data afterwards.

Anything else

Can we run our own security review?

Yes. Send your questionnaire and we will complete it. We will answer "no" where the answer is no, rather than leaving it blank or writing something that sounds like a yes.

Who do we contact?

Simone Fenton-Jarvis — simone@thehuman-centricworkplace.com

The Human-Centric Workplace Ltd, registered in England and Wales, company number 16215745. Registered office: 102 Lees Hall Road, Sheffield, England, S8 9JN. ICO registration ZC205952.

Our privacy notice sets out in full what we collect and why.