hyf.idSetup and support

Consumer Privacy Notice

Last updated: 15 September 2026 (Version 1.5)

This notice covers the hyf.id sign-in service for invited organisations during private development.

It also covers our Test signing in with your organisation account study for participants arriving through Prolific. The Prolific study section explains the information and retention rules for that study. Ordinary invited sign-in has its own session rules below.

This is the Consumer Privacy Notice for this limited service. Our Website Privacy Notice separately covers our business website, enquiries and contact records managed in HubSpot. Using an organisation email address to sign in is covered here; giving it to us to discuss our services is covered by the Website notice.

Who we are

hyf.id Ltd is the controller for this service, registered in England and Wales, company number 17276154. Our address is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. Our ICO registration number is ZC239188.

Contact privacy@hyf.id, or write to our address marked "Data Protection". For service help, contact support@hyf.id.

Authentication information

When you authenticate using Microsoft or Google, hyf.id may receive your name, email address, unique account identifier and other basic profile information provided by your identity provider, including your managed organisation identifier. We also receive the organisation email address you enter.

We use the required information to validate the sign-in, check that the returned managed account matches the organisation email address you entered and maintain the security of the service. For ordinary invited sign-in, we also check access for your organisation and associate your identity with a temporary session. The study does not create an ordinary signed-in account session.

hyf.id does not request access to the contents of your email, files, calendar, contacts or messages through Microsoft or Google authentication. Authentication through Microsoft or Google does not give hyf.id access to your Microsoft or Google password.

For ordinary invited sign-in, we process authentication information to provide the service you request under our terms. We use connection information, such as IP addresses and request details, for our legitimate interests in security and reliable operation. We use support correspondence to answer requests, and may process information to meet legal obligations. The study's purposes and basis are described below.

Ordinary invited sign-in: storage and retention

Sign-in attempts last up to 10 minutes. Session information is held in memory for up to one hour; restarts may end it earlier. We retain a Google access token during the session to enable disconnection, but do not retain raw identity tokens or refresh tokens. Session records are not written to a database or backed up. Essential browser cookies support sign-in and the session; the cookie notice explains them.

Application diagnostic logs are retained for 14 days. Infrastructure logs may include IP addresses and request URLs, including short-lived sign-in callback parameters. Their retention depends on the hosting and security archive in use. Support and incident records are kept for as long as needed to resolve the matter and meet applicable legal obligations.

Prolific organisation-account study

If you enter through the Prolific study link, we measure whether you can complete sign-in with your organisation’s existing Microsoft or Google account. Your organisation does not need to register for the study. Success, refusal, administrator approval requirements, organisation blocks and other failures are all valid study outcomes. Some attempts do not return an identifiable result; we record those as unknown. Signing in confirms access to a managed account at that time, not employment status.

Information we receive and use

We receive the organisation email address you enter and the Prolific participant, study and submission identifiers supplied with your study link. Microsoft or Google may return your name, email address, account and organisation identifiers and other basic profile information. We process the required claims to validate the sign-in and discard unused profile information. We do not ask for your organisation's name.

We retain only the domain part of your email, such as acme.com from member@acme.com, together with your Prolific identifiers, internal attempt references, selected provider, timestamps and limited sign-in stage, validation and outcome records. We record which version of the study information you were shown. We do not retain the part of the email before @ or a hash of your full email address.

We use these records to group results by domain and provider, match attempts to Prolific submissions and understand where sign-in succeeds or stops. We keep a record of each sign-in attempt. We may match domains to public organisational infrastructure information for sampling and analysis. A domain can identify an organisation; records linked to your Prolific ID remain personal data. Public findings are aggregated, with small groups suppressed to protect participants. We do not use your organisation email address for contact or marketing, reconstruct full email addresses, or use sign-in failure to decide whether you should be paid.

Our lawful basis for this limited study processing is our legitimate interests in evaluating and improving organisation-account sign-in and administering the study. Taking part is voluntary, and you can object to this use of your data using the contact options below. Permission granted on a Microsoft or Google consent screen is separate from participation in this study.

Study storage and deletion

Your full email and pending sign-in details are held only in server memory for up to 10 minutes. They are removed when sign-in succeeds, fails, you choose to finish, or the attempt expires. Your email is not written to research storage or logs. OAuth tokens and raw returned identity details are processed only in memory for validation, never written to storage or logs, and not retained after OAuth processing. We do not keep a Google access token for later disconnection in the study.

Email domains, Prolific linkage and limited research results are stored in a dedicated, encrypted study store in AWS in the United Kingdom, separate from ordinary hyf.id application data. Prolific linkage is kept separately from analysis records within that study store. This allows us to export and delete study records independently of ordinary application data. Access is limited to authorized research and operations staff using restricted access controls. Infrastructure administration uses individual accounts, restricted permissions and multi-factor authentication. Linked research records and exports are deleted 90 days after the study closes; only aggregate results that have been checked for disclosure risks remain.

Necessary study connection and security information, including IP addresses, is processed separately to protect the service. Retained study security and connection logs are kept for up to 14 days. They exclude full email addresses, raw tokens, authorization codes and identifying URL parameters. Essential browser cookies support sign-in and return to your study result. The study cookie lasts up to 24 hours and contains an opaque reference, not your email or tokens.

Finishing and requesting deletion

You can stop sign-in and choose Finish and return to Prolific at any time, including if access is blocked. You do not need administrator approval to complete your participation. Finishing removes pending sign-in details and ends further authentication processing; the limited research result is kept for the period above unless you request deletion. A browser that is closed or offline may not return a result to us.

To request deletion of a linked study record or object to its use, message the study researcher through Prolific with your Prolific ID, or contact privacy@hyf.id. You do not need to send your organisation email address, password or a token. Once results have been irreversibly aggregated, we cannot identify and remove your contribution from those aggregate figures.

Prolific manages recruitment, submissions and payment under its own privacy notice. We return you using a study completion link and do not send your organisation email address, email domain or provider tokens to Prolific. Microsoft, Google or your organisation may keep their own sign-in and consent records. Provider permissions can remain after you finish; you can review or remove them through your provider's account controls.

Sharing and protection

We use AWS infrastructure in the United Kingdom. Authorized providers and personnel may access limited information to operate and support the service. International transfers are subject to safeguards required by applicable law. Google or Microsoft handles sign-in under its own privacy terms, and your organisation may control account permissions.

We do not sell personal data or use it for advertising. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Your choices and rights

For ordinary invited sign-in, you can disconnect and sign out. For Google, this also revokes the retained access token; for Microsoft, remove app permissions through My Apps or your administrator. Study participants can finish and request deletion as described above. Permissions may remain with the provider after a hyf.id session ends.

Contact privacy@hyf.id to request access, correction, erasure, restriction or portability, or to object to processing based on legitimate interests. Rights depend on applicable law and may have exceptions. You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint/ or your local supervisory authority, without contacting us first.

Google API Services User Data Policy · Information Commissioner's Office