Security and data protection

What we store, where it lives, and who can see it.

Every note you write about a team member is personal data about a real person, and often about their performance. That is sensitive. This page explains in plain English what happens to it, then sets out the full technical detail for anyone whose job it is to check.

In plain English What we store Where it lives Who can see it Your rights Technical measures Sub-processors Contact

Four things worth knowing.

Your data stays in Europe
Stored and processed in Stockholm. It does not travel to a server outside the European Economic Area, including when the AI generates your output.
Your records are yours alone
Every record is owned by the account that created it. The database enforces this at row level, so a defect in the application cannot expose one manager's records to another.
Administrators cannot read your notes
If your organisation buys seats, the administrator sees who has a seat and whether it is being used. They cannot read your notes, your people records, or anything you have written about your team.
Export or delete, any time
One action exports a person and everything attached to them. One action deletes them. Deletion is permanent and takes everything attached to them with it.

Why the administrator point matters. Managers write honestly when they know their notes will not be read by someone else and used against them, or against the person they are writing about. A tool that lets an administrator read a manager's private assessment of a colleague is a tool managers will not use honestly. We built it the other way round on purpose.

What we store

Management Ignition stores two kinds of information: the account of the manager using the service, and the records that manager creates about the people they manage.

About you, the account holder

About the people you manage

We do not ask for and do not want special category data as defined by UK GDPR Article 9. That includes health information, trade union membership, and anything about race, religion, sexual orientation or political opinion. If a manager types something in that category into a free-text field it will be stored as entered, which is why the notes fields carry guidance on what to write.

The people you write about have not signed up. They are data subjects and you are recording personal data about them. If you are using this at work, your employer is the controller of that data and you should check your organisation's policy on manager records. If you are using it privately, you are the controller. Either way, write what you would be comfortable defending if the person asked to see it.

Where it lives

ComponentLocation and provider
Database and authenticationSupabase, hosted on AWS in Stockholm (eu-north-1)
Application and API functionsVercel, pinned to Stockholm (arn1)
AI generationAnthropic, EU processing
PaymentsStripe, an EU-US Data Privacy Framework participant
Email deliveryTransactional email for sign-in links only

Generation is pinned to Stockholm rather than left to default. This was a deliberate architectural decision, taken when we moved the generation layer, so that the free text a manager writes about a colleague is processed in Europe rather than travelling to a US region.

Your prompts and the outputs generated from them are not used to train any AI model.

Who can see it

You

You can see everything you have created. Your people, your notes, your sessions, your actions, your history.

Other managers in your organisation

Nothing. Row level security in the database scopes every record to the account that created it. A manager cannot query another manager's records even if the application had a defect that tried to.

Your organisation's administrator

If your organisation has bought seats, the administrator can see how many seats are in use, who holds them, and whether a seat is active. They cannot see your people, your notes, your sessions, or anything you have written. This is enforced in the database, not just hidden in the interface.

Us

Access to production data is restricted to named individuals who need it to operate the service, and is used only to investigate a fault or respond to a request from you. We do not read manager notes as a matter of course, and we do not analyse their content.

To be completed before launch: the number of personnel with production access, and the process by which that access is reviewed.

Your rights, and the rights of the people you write about

Under UK GDPR and the EU GDPR, the people whose data is held have rights of access, rectification, erasure, restriction, portability and objection. Management Ignition is built so that a manager can satisfy most of those requests directly, without contacting us.

RightHow it works in the app
Access and portabilityExport a person and everything attached to them in one action. The export includes every session, output and action.
ErasureDelete a person in one action. Deletion is permanent and cascades: sessions, outputs and actions attached to that person are removed with them.
RectificationEdit any person record or note directly.
Your own accountDelete your account and everything in it. Contact us and we will action it.

If you are a data subject and you believe a manager holds records about you in this service, contact that manager or your employer in the first instance. They control the record. We can help them respond but we cannot disclose records to a third party without the controller's instruction.

Technical and organisational measures

These are the measures referred to in Article 32 of UK GDPR and set out in Annex 3 of our data processing agreement. The DPA is available on request.

Encryption

Access control

Segregation

Resilience and recovery

To be completed before launch: backup frequency and retention period, restoration testing schedule, and business continuity arrangements.

Monitoring and incident response

To be completed before launch: breach detection and alerting arrangements, and the tested incident response timeline.

Data minimisation and retention

Sub-processors

We use the following sub-processors to deliver the service. Each is engaged under a written contract containing data protection terms.

Sub-processorPurposeLocation
SupabaseDatabase and authenticationAWS Stockholm, eu-north-1
VercelApplication hosting and API functionsStockholm, arn1
AnthropicAI generationEU processing
StripePayment processingEU and US, Data Privacy Framework

We will give reasonable notice of any intended change to this list. If you object to a new sub-processor on reasonable data protection grounds, you may terminate without penalty.

Questions, requests, or a security concern

Management Ignition is operated by Allcow Trading Co. Ltd., trading as The Message Business, registered in England and Wales.

For data protection questions, subject access requests, or to request a copy of the data processing agreement, email team@management-ignition.com.

If you believe you have found a security vulnerability, please email us before disclosing it publicly. We will acknowledge within two working days.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

To be completed before launch: ICO registration number.

Email us →

This page was last updated in August 2026. We update it whenever the underlying arrangements change.