Privacy notice
This notice covers portal.fractionalteams.com only — the client report portal. For the main website and Fractional Teams’ services generally, see fractionalteams.com.
Who is responsible
The data controller is Next Generation ICT Ltd, trading as Fractional Teams, 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. Contact: help@fractionalteams.com.
What we process, and why
| Data | Why | Basis |
|---|---|---|
| Your name, work email address, password (stored only as a salted hash), and optional two-factor secret (stored encrypted) and backup codes (hashed) | To give you a login and keep your account secure | Contract with your organisation; legitimate interest in security |
| Session cookie (signed, HTTP-only) and CSRF token | To keep you signed in and protect forms; strictly necessary, no consent banner needed | Legitimate interest |
| API keys you create (stored only as a hash, with a short prefix and last-used time) | To authenticate your software and let you see which keys are in use | Contract |
| Report content and lead data supplied by or gathered for your organisation — including the names, LinkedIn profiles and message summaries of people your organisation has contacted through its outreach campaigns | To deliver the audit and outreach reporting your organisation has engaged us for | Contract with your organisation (your organisation is the controller of its outreach data; we process it on its instructions) |
| Lead-status changes (who marked which lead, when) | Audit trail shown to your organisation’s users and to the Fractional Teams team, who are notified of each change | Contract |
| Chat messages you send from a report, and the resulting transcript | To answer your question; the team reads chats in its internal Slack workspace, an unanswered chat is emailed to the support inbox and continued by email, and the transcript stays in the portal so you can reopen it | Contract |
| Server and error logs (IP address, requested path, time) and in-memory rate-limit counters | Security monitoring, rate limiting and fault finding | Legitimate interest |
| Analytics on the public pages only (the landing, about, contact, pricing and privacy pages, the sign-in and forgot-password pages, the demo and the documentation) and only for visitors who are not signed in, if enabled: Google Analytics 4 with IP anonymisation and advertising signals off, and Ahrefs Web Analytics | To see how the public pages are used. Never on signed-in pages, reports, or pages carrying a one-time link | Legitimate interest |
Emails we send
Account emails only: invitations, password resets, two-factor changes, “a new report is ready”, and chat transcripts or missed-reply notices. Lead-status changes you make are notified to the Fractional Teams team, not emailed to you. No marketing email is sent from the portal.
Who else sees it
- The other users on your organisation’s account, and the Fractional Teams team, who can view your organisation’s reports, users and lead statuses.
- Processors we use to run the service: a UK/EU hosting provider for the server, a transactional email provider for account emails, Slack for the team side of the in-report chat, and the analytics providers above on public pages only. Each processes data on our instructions under a contract.
- Nobody else. Data is never sold, and one client’s data is never visible to another client.
How long we keep it
- Account data: for the life of your organisation’s engagement, then deleted on request or within 12 months of the engagement ending.
- Reports and lead history: kept as your organisation’s record while it is a client; deleted with the account.
- Chat transcripts: kept in the portal (so a conversation can be reopened) and with the support email thread; deleted with the account.
- Server logs: rolling, typically under 90 days. Database backups: rolling, deleted on the same cycle.
- Demo workspace data: fictional, reset nightly.
Your rights
You can ask for access to, correction of, or deletion of your personal data, object to processing based on legitimate interest, and ask for a copy in a portable format. Email help@fractionalteams.com; we answer within one month. If you are unhappy with our response you can complain to the UK Information Commissioner’s Office (ico.org.uk). If your organisation is the controller of the data in question (for example outreach lead data), we will pass your request to them.
Security
All traffic is encrypted in transit. Passwords are hashed, two-factor secrets are encrypted at rest, API keys are stored hashed and shown once. Access to a client’s data is scoped per user and enforced on every request, on the web, the API and the MCP server alike. The service is reviewed for security before each significant change.
Changes
This notice was last updated on 2026-09-08. Material changes are announced to signed-in users.
