Back to sign in

Privacy Policy

How Carrier collects, uses, stores, and protects personal data about researchers and authorised users of the platform.

1. About this Privacy Notice

This Privacy Notice explains how Carrier collects, uses, stores, shares, and protects personal data about researchers and authorised users of the platform.

This notice applies to:

  1. researchers;

  2. study owners;

  3. principal investigators;

  4. students using Carrier for research;

  5. administrators;

  6. collaborators;

  7. technical users;

  8. users who create, configure, test, manage, analyse, or administer studies on Carrier.

This notice does not replace the participant information sheet or privacy notice required for each individual study. Researchers remain responsible for preparing appropriate study-specific participant information and privacy materials.

2. Who is responsible for your personal data?

For general platform operation, researcher account management, authentication, security, technical support, audit logs, and platform administration, the controller is the University of Bath.

For individual studies created by researchers, the controller may be the researcher’s institution, the principal investigator’s institution, or multiple institutions acting as joint controllers.

Researchers are responsible for confirming the data protection role for each study they create or manage on Carrier.

3. Personal data we collect about researchers

Carrier may collect and process the following personal data about researchers and authorised users.

3.1 Account data

We may collect:

  1. name;

  2. email address;

  3. username or account ID;

  4. institution or organisation;

  5. department, research group, or project affiliation;

  6. role or permission level;

  7. supervisor, principal investigator, or project lead, where relevant;

  8. password authentication data;

  9. account status;

  10. account creation date;

  11. account update history.

3.2 Access and authentication data

We may collect:

  1. login timestamps;

  2. logout timestamps;

  3. failed login attempts;

  4. IP address;

  5. browser type and version;

  6. operating system;

  7. device information;

  8. session data;

  9. authentication logs;

  10. access-control records.

3.3 Terms acceptance records

Where researchers are required to accept the Carrier Researcher Terms of Use, we may record:

  1. name;

  2. email address;

  3. account ID;

  4. institution;

  5. date and time of acceptance;

  6. version of the Terms accepted;

  7. related technical metadata, such as session or IP information, where appropriate.

These records are used to evidence acceptance of the platform terms and manage authorised access.

3.4 Study setup and management data

When you create, configure, test, or manage a study, Carrier may process information linked to your account, including:

  1. study titles;

  2. study descriptions;

  3. study ownership records;

  4. collaborator lists;

  5. user permissions;

  6. study configuration;

  7. consent-flow configuration;

  8. survey and task configuration;

  9. prompts and AI instructions;

  10. randomisation settings;

  11. quota settings;

  12. screening settings;

  13. redirect and completion-code settings;

  14. study testing records;

  15. export activity;

  16. administrative notes or logs.

Some of this information may contain personal data if researchers include names, emails, identifiers, or other personal information in study materials or configuration fields.

3.5 API key and external provider configuration data

Carrier may allow researchers to configure external AI or LLM providers, such as OpenAI, Anthropic, or other providers.

Where this function is enabled, Carrier may process:

  1. provider name;

  2. model configuration;

  3. API-key configuration metadata;

  4. encrypted API-key records, where storage is required;

  5. study configuration linked to the provider;

  6. provider error logs;

  7. API request metadata;

  8. usage metadata needed for troubleshooting, monitoring, or audit.

Researchers are responsible for ensuring that any API keys they provide are authorised, properly restricted, monitored, and used in line with the relevant provider’s terms and institutional requirements.

Researchers should not include directly identifiable personal data or unnecessary participant information in API prompts or provider requests unless this is necessary, approved, and clearly explained in the relevant study documents.

3.6 Support and enquiry data

If you contact the Carrier team, we may collect:

  1. name;

  2. email address;

  3. institution;

  4. role or project affiliation;

  5. message content;

  6. support history;

  7. screenshots, logs, or files you provide;

  8. information needed to investigate and respond to your request.

3.7 Technical, security, and audit data

To operate and secure Carrier, we may collect:

  1. IP address;

  2. browser and device information;

  3. server logs;

  4. access logs;

  5. error logs;

  6. audit logs;

  7. security alerts;

  8. system performance records;

  9. records of changes made to studies, settings, permissions, or API configurations;

  10. information needed to investigate misuse, incidents, or technical problems.

4. How we use researcher personal data

We use researcher personal data to:

  1. create and manage researcher accounts;

  2. authenticate users;

  3. manage access permissions;

  4. allow researchers to create, test, run, and analyse studies;

  5. identify study owners and collaborators;

  6. record acceptance of the Carrier Researcher Terms of Use;

  7. provide technical support;

  8. troubleshoot errors;

  9. monitor platform performance;

  10. protect the security and integrity of Carrier;

  11. investigate suspected misuse, unauthorised access, data incidents, or API-key exposure;

  12. manage API-provider configuration where enabled;

  13. maintain audit records;

  14. comply with institutional, legal, research governance, contractual, and security obligations;

  15. administer, improve, and maintain the platform.

5. Lawful bases for processing

The lawful basis for processing researcher personal data may include:

  1. Public task — where processing is necessary for university research, education, infrastructure, or public-interest functions.

  2. Legitimate interests — where processing is necessary to operate, secure, maintain, and improve the platform, manage users, prevent misuse, and support research activity.

  3. Contract — where processing is necessary to provide access to Carrier under the Researcher Terms of Use.

  4. Legal obligation — where processing is required by law, audit duties, data protection obligations, or institutional governance requirements.

  5. Consent — where we ask for specific consent, for example for optional communications or non-essential cookies.

The appropriate lawful basis may vary depending on the activity and the institution responsible for the processing.

6. API keys and provider-side responsibility

Where researchers provide or configure their own API keys, they are responsible for the relevant provider account, permissions, usage limits, spend caps, monitoring, and key management.

Carrier may process API-key-related information only as needed to provide the configured service, route requests, troubleshoot errors, maintain audit records, and secure the platform.

Researchers must not place API keys in participant-facing materials, public prompts, client-side code, exported datasets, shared documents, emails, or other insecure locations.

If an API key is suspected to have been exposed, misused, or compromised, the researcher should revoke or rotate the key immediately and notify the Carrier team where the issue may affect Carrier, study data, participants, other users, or the institution.

7. External AI and LLM providers

Carrier may support integration with external AI or LLM providers.

Depending on study configuration, prompts, study instructions, researcher-created materials, technical metadata, and study content may be sent to an external provider.

Researchers are responsible for ensuring that external provider use is:

  1. appropriate for the study;

  2. covered by ethics approval where required;

  3. compatible with institutional data protection requirements;

  4. explained in participant-facing materials where required;

  5. compliant with the provider’s terms, privacy terms, data processing terms, and usage policies.

External providers may process data under their own contractual terms, security arrangements, retention policies, and usage policies. These arrangements may depend on the provider, account type, API settings, contract, region, and model used.

8. Who we share researcher personal data with

Researcher personal data may be shared with:

  1. authorised Carrier platform administrators;

  2. authorised technical support staff;

  3. the researcher’s study collaborators, where necessary for study management;

  4. the institution responsible for the platform;

  5. institutional IT, information security, research governance, ethics, legal, audit, or data protection teams;

  6. hosting, database, infrastructure, security, backup, and support providers;

  7. external AI or LLM providers, where configured;

  8. regulators, courts, law enforcement, or public authorities, where required by law;

  9. other institutions involved in a study, where necessary and appropriate.

We do not sell researcher personal data.

9. International transfers

Carrier and its third-party providers may process data in the United Kingdom, the European Economic Area, or other countries.

Where personal data is transferred outside the United Kingdom or European Economic Area, appropriate safeguards should be used where required. These may include adequacy regulations, standard contractual clauses, the UK International Data Transfer Agreement, the UK Addendum, transfer risk assessments, or other approved transfer mechanisms.

The exact transfer arrangements may depend on the hosting provider, AI provider, infrastructure provider, API configuration, and institutional agreements.

10. Cookies and similar technologies

Carrier may use cookies or similar technologies.

Some cookies are necessary for Carrier to work, for example to:

  1. keep users logged in;

  2. maintain secure sessions;

  3. manage authentication;

  4. remember platform settings;

  5. protect against unauthorised access;

  6. support security and troubleshooting.

Carrier may also use optional analytics or performance technologies to understand platform usage and improve reliability. Where required, we will ask for consent before using non-essential cookies or similar technologies.

You can usually control cookies through your browser settings. Blocking essential cookies may prevent Carrier from working correctly.

11. How long we keep researcher personal data

We keep researcher personal data only for as long as necessary for the relevant purpose.

Indicative retention periods are:

Data type Indicative retention period
Researcher account data For as long as the account is active, then for a reasonable period for administration, audit, and security
Terms acceptance records For as long as needed to evidence acceptance and manage platform access
Study ownership and configuration records For as long as needed to operate the study, maintain research records, support audit, or meet institutional requirements
Technical and security logs For a limited period needed for security, debugging, audit, and platform operation
API configuration metadata For as long as needed to provide the configured service, unless removed earlier
Support enquiries For as long as needed to respond and maintain support records
Backups Retained for a limited backup cycle, then overwritten or deleted

Some records may be retained for longer where required for legal compliance, audit, research integrity, security investigation, dispute management, or institutional record-keeping.

12. How we protect researcher personal data

We use technical and organisational measures designed to protect researcher personal data.

These may include:

  1. access controls;

  2. role-based permissions;

  3. authentication;

  4. encrypted connections;

  5. secure password handling;

  6. secure API-key handling;

  7. server and database security controls;

  8. logging and monitoring;

  9. backup procedures;

  10. restricted administrator access;

  11. data minimisation;

  12. audit records;

  13. institutional information security procedures;

  14. incident reporting and response procedures.

No online platform can be guaranteed to be completely secure. Researchers must also protect their own accounts, devices, passwords, API keys, downloaded files, exported datasets, and local storage environments.

13. Your data protection rights

Depending on the circumstances and lawful basis, you may have rights to:

  1. access your personal data;

  2. correct inaccurate personal data;

  3. request deletion of personal data;

  4. restrict processing;

  5. object to processing;

  6. request transfer of your data;

  7. withdraw consent, where processing is based on consent;

  8. complain to the relevant supervisory authority.

Some rights may be limited where records are needed for security, audit, legal compliance, research governance, or institutional record-keeping.

To exercise your rights or ask a privacy question, contact the platform administrator.

For institutional data protection enquiries, contact your institution’s data protection officer.

14. Security incidents

If you become aware of suspected unauthorised access, account compromise, accidental disclosure, API-key exposure, data breach, or security vulnerability involving Carrier, you should report it immediately to the platform administrator.

If the incident relates to a specific study, you should also inform the principal investigator, study owner, relevant institution, and data protection contact as required by the study’s governance arrangements.

15. Changes to this Privacy Notice

This Privacy Notice may be updated from time to time.

The latest version is always available on this page.

Where changes materially affect how researcher personal data is used, additional notice may be provided where appropriate.

16. Complaints

If you have concerns about how your personal data is used, you can contact your institution’s data protection team.

You also have the right to complain to the UK Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Website: https://ico.org.uk/

17. Contact

For questions about this Privacy Notice, contact the platform administrator.