Fractional Teams

Privacy notice

This notice covers portal.fractionalteams.com only — the client report portal. For the main website and Fractional Teams’ services generally, see fractionalteams.com.

Who is responsible

The data controller is Next Generation ICT Ltd, trading as Fractional Teams, 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. Contact: help@fractionalteams.com.

What we process, and why

DataWhyBasis
Your name, work email address, password (stored only as a salted hash), and optional two-factor secret (stored encrypted) and backup codes (hashed)To give you a login and keep your account secureContract with your organisation; legitimate interest in security
Session cookie (signed, HTTP-only) and CSRF tokenTo keep you signed in and protect forms; strictly necessary, no consent banner neededLegitimate interest
API keys you create (stored only as a hash, with a short prefix and last-used time)To authenticate your software and let you see which keys are in useContract
Report content and lead data supplied by or gathered for your organisation — including the names, LinkedIn profiles and message summaries of people your organisation has contacted through its outreach campaignsTo deliver the audit and outreach reporting your organisation has engaged us forContract with your organisation (your organisation is the controller of its outreach data; we process it on its instructions)
Lead-status changes (who marked which lead, when)Audit trail shown to your organisation’s users and to the Fractional Teams team, who are notified of each changeContract
Chat messages you send from a report, and the resulting transcriptTo answer your question; the team reads chats in its internal Slack workspace, an unanswered chat is emailed to the support inbox and continued by email, and the transcript stays in the portal so you can reopen itContract
Server and error logs (IP address, requested path, time) and in-memory rate-limit countersSecurity monitoring, rate limiting and fault findingLegitimate interest
Analytics on the public pages only (the landing, about, contact, pricing and privacy pages, the sign-in and forgot-password pages, the demo and the documentation) and only for visitors who are not signed in, if enabled: Google Analytics 4 with IP anonymisation and advertising signals off, and Ahrefs Web AnalyticsTo see how the public pages are used. Never on signed-in pages, reports, or pages carrying a one-time linkLegitimate interest

Emails we send

Account emails only: invitations, password resets, two-factor changes, “a new report is ready”, and chat transcripts or missed-reply notices. Lead-status changes you make are notified to the Fractional Teams team, not emailed to you. No marketing email is sent from the portal.

Who else sees it

How long we keep it

Your rights

You can ask for access to, correction of, or deletion of your personal data, object to processing based on legitimate interest, and ask for a copy in a portable format. Email help@fractionalteams.com; we answer within one month. If you are unhappy with our response you can complain to the UK Information Commissioner’s Office (ico.org.uk). If your organisation is the controller of the data in question (for example outreach lead data), we will pass your request to them.

Security

All traffic is encrypted in transit. Passwords are hashed, two-factor secrets are encrypted at rest, API keys are stored hashed and shown once. Access to a client’s data is scoped per user and enforced on every request, on the web, the API and the MCP server alike. The service is reviewed for security before each significant change.

Changes

This notice was last updated on 2026-09-08. Material changes are announced to signed-in users.