NIA.OS Privacy Notice
Last updated 27 September 2026
1. Who we are and what this notice covers
NIA.OS is the online platform of the NHS Innovation Accelerator (NIA), a programme run by UCLPartners. It allows innovators on the NIA programme to describe their innovations, allows NHS staff to find those innovations and get in touch, lets anyone browse the public catalogue, and allows confirmation of where an innovation is in use.
Data controller: UCLPartners is the data controller for the personal data processed on NIA.OS.
Data processor: UCLPartners runs the platform as a data processor.
Sub-processor: Amazon Web Services (AWS) hosts the platform and provides its sign-in, email and AI search services.
This notice explains what personal data NIA.OS holds, why, for how long, who can see it, and what you can ask us to do. It applies to everyone who interacts with the platform.
NIA.OS is a professional platform. It is not directed at children. UCLPartners does not knowingly collect personal data from anyone under the age of 18.
UCLPartners ICO Registration Number: ZA178403
UCLPartners Data Protection Officer:
UCLPartners, 76-78 Portland Place, London, W1B 1NT
gdpr@uclpartners.com
2. The people this notice is about
- Innovators and NIA Fellows, who hold an account and describe their innovation. "Innovators" includes NIA Fellows; the terms are used interchangeably in this notice.
- NHS staff: people at NHS organisations in the UK (including NHS Scotland, NHS Wales and Health and Social Care Northern Ireland) who hold an account, and NHS managers whose email address an innovator gives when asking them to confirm an adoption, before they have registered.
- NIA administrators, who run the programme on the platform.
- Enquirers without an account: people who browse or search the public catalogue and send an enquiry about a published innovation without signing in.
NIA.OS is intended for use in a professional capacity. NIA.OS is not for patients, asks for no patient data and has no place to record it.
3. What we collect, and why
3.1 Your account (innovators, NHS staff, administrators)
What: your full name, a preferred name if you give one, your email address, your role on the platform, your organisation, and a job title. For NHS staff, the organisation is identified by its ODS code and the email address must belong to an NHS domain. We also record when you last used the platform and, where it applies, why an account was made inactive, suspended or restored. NHS staff who create their own account with an NHS email address are held as a pending registration until they finish creating their account. If your email domain is not yet on our NHS list and you ask to be told when it is added, we keep that email address for that purpose. For innovators we also record your programme cohort.
Why: to give you an account and let you use the platform. The lawful basis for account data is Article 6(1)(b) UK GDPR: processing necessary for the performance of a contract to which the data subject is party, namely the Terms of Use accepted on account creation.
Sign-in: NIA.OS has no passwords. Each sign-in records the browser family it came from, so we can email you when your account is used from a new browser.
Invitations: when an administrator invites you, we hold your name, email address, intended role and who invited you.
3.2 Your innovation (innovators)
What: everything you enter about your innovation, as well as any documents uploaded and a copy of each version you publish, with the date it was published.
Why: so NHS staff can find your innovation, and the NIA programme can support and measure. The lawful basis for account data and all innovation content submitted by innovators is Article 6(1)(b) UK GDPR: processing necessary for the performance of a contract to which the data subject is party.
Publication: when you publish, a frozen copy of your innovation is taken at that moment. Only its public parts are shown to NHS staff and in the public catalogue. Editing your draft afterwards does not change the published copy until you publish again. Parts of your innovation that are not published (your About you details, private evidence notes, self-assessment scores and adoption contacts) are never shown in the catalogue; your name and job title from About you appear in the Adoption Pack. Contract values are never shown publicly. They are seen only by you, the NHS managers of the organisation concerned, and the NIA team. When you publish, the text of your innovation is processed by the AI embedding model (section 3.3) so it can be found; a numeric representation of it is stored with the innovation.
A purpose declared in advance: UCLPartners may in future use innovation content, in aggregated or otherwise minimised form and never as raw personal data, to train or improve models that help match innovations to NHS needs. We state this purpose now because a new purpose cannot be added after collection. Before this is done, a separate Data Protection Impact Assessment will be completed and, where required, a fresh mechanism will be put in place. We will notify innovators before any such use begins.
Please do not enter personal information about other people beyond what a question asks for, or health information about anyone, in free-text answers. Those fields are for describing your innovation.
3.3 Finding innovations, connecting and messaging
What: when you choose to connect with an innovation we record that you did, your organisation, the reason you gave, and each stage the connection reaches and when. Messages between an innovator and the NIA team are stored with both accounts. Questions you ask an NHS organisation that has adopted an innovation are stored with your account, and your email address is passed to that organisation's contact so they can reply. If you send an enquiry without signing in, we hold the name, email address and organisation you type, and the reason you chose, so the innovator can reply. If you share an innovation with a colleague by email, we hold the address you typed for that one email. An enquiry that looks automated is held for the NIA team to check and is not passed on to the innovator; held enquiries are kept for 24 months. When signed-in NHS staff download an Adoption Pack, their name and organisation are printed on it.
Why: to make the introduction you asked for. The lawful basis for this processing is Article 6(1)(f) UK GDPR: processing necessary for the purposes of the legitimate interests pursued by UCLPartners.
Search: the words you search are used to find matching innovations. Part of that matching uses two AI models through AWS Bedrock: an Amazon text-embedding model (Amazon Titan), run in the AWS London region, and an AI language model provided by Anthropic (Claude Haiku), run through AWS's EU cross-region inference profile. Your search text, with an expanded form of it, is sent to the models, together with the text of published innovations. The model provider does not retain your search text. NIA.OS keeps a copy of the search text, with no account attached, to check the quality of results: it is kept indefinitely, and email addresses, phone numbers and NHS numbers are removed before it is stored (see section 7). See section 6 for where this runs.
3.4 Confirming adoptions
What: when an innovator says an innovation is in use at an NHS organisation, we record the organisation, the type of adoption, the dates, and the email address of the NHS manager asked to confirm it. We also record the contract value (kept private), the number of people benefiting if given, the manager's answer and when it was given, and any reason given for withdrawing the record.
Why: so an NHS buyer can rely on where an innovation is genuinely in use. The lawful basis for this processing is Article 6(1)(e) UK GDPR: processing necessary for the performance of a task carried out in the public interest.
3.5 Understanding demand and how the platform is used
What: the platform records product events and demand signals. Product events carry a pseudonymous key, your role and your organisation; demand signals carry only your role. Neither carries your name or email address. Text you type into the 'tell us what you could not find' form is stored as you typed it. Aggregate counts are kept separately with no person reference at all.
Why: to see where NHS demand is unmet, to steer the programme, and to improve the platform. The lawful basis for this processing is Article 6(1)(e) UK GDPR: processing necessary for the performance of a task carried out in the public interest.
What we do not do: there is no session recording or screen replay on NIA.OS. Anonymous page-speed measurements are sent to our monitoring infrastructure and contain no personal data.
3.6 Emails we send
The platform sends transactional emails. Most emails are queued with your address and the details it needs and the address and personal details in the queued record are deleted 30 days after the email is sent or finally fails; a record that the email was sent is kept. Sign-in code emails are sent straight away and are not queued. If an address permanently bounces or generates a complaint, it is added to a do-not-send list. That list is kept so we never email the address again, including after an erasure request.
The lawful basis for this processing is Article 6(1)(f) UK GDPR: processing necessary for the purposes of the legitimate interests pursued by UCLPartners.
3.7 Security, audit and infrastructure records
To keep the platform secure and accountable we keep:
- an audit log
- sign-in session records
- application logs
- network flow records
- web application firewall logs
- AWS account activity logs
- error reports, with names and email addresses removed
These records include IP addresses.
The lawful basis for security, audit and infrastructure records is Article 6(1)(c) UK GDPR: processing necessary for compliance with a legal obligation.
3.8 Handling your requests
When you exercise a data right we record the request, when it arrived, its statutory deadline and its outcome, so we can demonstrate we handled it correctly and within time.
4. Where your data comes from
Almost everything comes from you. The exceptions:
- your NHS organisation's details come from the NHS ODS register;
- an administrator may enter your name and email address to invite you; a colleague may enter your email address to share an innovation with you;
- an innovator may enter an NHS manager's email address when requesting an adoption confirmation; and
- an enquirer may enter their own details without an account.
- an innovator's company details come from Companies House, which receives the company name you type to search.
5. Who can see your data
- Other users, according to role.
- Anyone visiting the public catalogue, for the information you chose to publish.
- Amazon Web Services
- NHS England
- Health Innovation Networks
NIA.OS does not share or sell your data to non-relevant third parties.
6. Where your data is held
All personal data is stored and processed in the AWS London (eu-west-2) region.
One exception: the AI model that ranks search results (Anthropic's Claude Haiku) is not available in London, so that step runs through AWS's EU cross-region inference profile, which may process it in Ireland, France, Germany, Italy, Spain, Sweden or the UK. Only your search text and a shortlist of published innovations are sent; nothing is stored there. The lawful basis for this transfer is the UK's adequacy regulations for EEA countries under Section 17A of the Data Protection Act 2018, which recognise EEA countries as providing an equivalent level of data protection to the UK.
A second exception: the web application firewall in front of the platform is a global AWS service, and its log of requests it flagged or blocked (your IP address, the page address and request type, not your sign-in details) is held in the AWS US East (N. Virginia) region for 30 days.
Application logs and the AWS account activity log are kept in London for 12 months and copied to a central archive, also in London, for 12 months.
7. How long we keep your data
How long we keep each kind of data is set out below. The full technical inventory behind these periods is held by UCLPartners and available on request.
| Data | Retention period |
|---|---|
| Your account and profile | While your account is active, then 6 years. If you ask us to erase your account, it is deleted at that point. |
| Your innovation: published versions and uploaded documents | 6 years after your account ends; unpublished drafts are anonymised when your account is erased |
| A rendered copy of an innovation's Adoption Pack, made when the innovator publishes so NHS staff can download it | The current copy for as long as the innovation is published; each new publish replaces the previous copy; deleted when the innovator's account is erased |
| Connections, enquiries, questions, messages and adoption records | 6 years |
| The emails we send you | Personal details removed 30 days after sending; an address on our do-not-send list is kept so we never email it again |
| Search text | Kept with identifiers removed and no account attached |
| Usage analytics (pseudonymous) | 2 years |
| Records of the actions you take (security, firewall and infrastructure logs) | 12 months; the audit log 6 years |
| Backups | 35 days |
| Data rights requests | 3 years |
| Invitations you have not accepted | They expire after 30 days and are removed by an administrator |
8. Your rights, and how to use them
Under UK GDPR you can ask to:
- see the personal data we hold about you (subject access request);
- correct inaccurate data;
- erase your data ("right to be forgotten");
- restrict how we use your data while a dispute is resolved;
- object to processing based on legitimate interests or public task; and
- receive a copy of the data you gave us in a portable, machine-readable form.
How to ask: email nia@uclpartners.com. To erase your account you can also use the delete control in your settings. We will respond within one month. Erasure is scheduled 30 days after your request, or sooner where the statutory deadline requires; until then you can restore your account by signing in. Erasure removes your account and your name from the platform; some records stay without your name, as section 7 and the paragraphs below explain.
Adoption records. If you ask us to erase your data, your name is removed from any adoption record or confirmation, but the record that the innovation was in use, and the NHS organisation, stay. If you are an innovator, your published innovation is taken off the catalogue.
Messages you have sent to others stay in their conversations with your name removed. After erasure we keep a small number of records without which the platform cannot be audited or cannot stop emailing you: the audit log of actions you took, your email address on our do-not-send list if it is there, uploaded evidence files, which are made unreachable rather than deleted, and backups, which are overwritten within 35 days.
You also have the right to complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113.
9. Automated decisions
NIA.OS makes no decision about you that has a legal or similarly significant effect. No profiling with legal or significant effects takes place on NIA.OS.
10. Cookies
NIA.OS sets only the cookies it needs to keep you signed in, to link the steps of creating an account, and to return what you typed to a form that could not accept it. These are strictly necessary, so no cookie consent banner is shown. NIA.OS sets no advertising cookies and no third-party analytics cookies.
| Cookie | Set when | Kept for | Removed when |
|---|---|---|---|
| __Host-niaos_session | You log in, or you finish creating your account | Up to 90 days | You sign out, or your browser deletes it after 90 days |
| __Host-niaos_registration | You ask for a registration code, and again when it is accepted, or you log in before you have finished creating your account | 3 minutes, then 10 minutes once the code is accepted | You finish creating your account, or your browser deletes it when that time runs out |
| niaos_cant_find_retry | The "tell us what you could not find" form is refused (JavaScript off only) | 10 minutes | You send that form again, or your browser deletes it after 10 minutes |
NIA.OS also stores two small items in your browser, both needed for something you asked to do and neither sent to us: which button you pressed before signing in (kept for 15 minutes), and which message an innovator's home page last showed (until you close the tab).
11. Security
Data is encrypted in transit (TLS) and at rest. Access is restricted by role. Personal data in analytics is pseudonymised, except the words people type into search and the 'tell us what you could not find' form, which are stored as typed. Sign-in tokens are held server-side only. The platform sits behind a web application firewall that blocks abusive traffic and applies rate limits, with alarms on unusual sign-in and account activity.
A Data Protection Impact Assessment (DPIA) for NIA.OS will be completed by 31 March 2027 covering the platform's data flows, the AI search component, and the pseudonymous analytics store. The DPIA will be held internally by UCLPartners. NHS DPOs or information governance leads who need to review it may request a copy via nia@uclpartners.com after this date.
12. Changes to this notice
We will publish any change to this notice on the platform. This notice is effective from 01 October 2026.