Legal
GDPR Compliance
Last updated: 4 March 2026
TeamTreat is designed to support organizations operating under the UK GDPR and EU GDPR data protection frameworks.
This page outlines how TeamTreat processes personal data.
Section 1. Roles and Responsibilities
Organizations using TeamTreat are typically the data controllers.
They determine:
- What employee data is uploaded
- Why the data is processed
- How long it should be retained
TeamTreat acts as a data processor, providing software infrastructure to manage this information.
Section 2. Personal Data Processed
Organizations may upload limited employee data such as:
- Employee names
- Work email addresses (optional)
- Birthdates
- Dietary requirements
This data is used only to support workplace celebrations managed through the platform.
Section 3. Processing Purpose
TeamTreat processes data for the following purposes:
- Enabling organizations to track employee birthdays
- Managing workplace celebrations
- Coordinating associated orders
- Maintaining system security
- Providing customer support
Section 4. Data Minimization
TeamTreat is designed to store only the minimal information required to support celebration management workflows.
Organizations are responsible for ensuring they only upload necessary data.
Section 5. Subprocessors
TeamTreat may rely on trusted infrastructure providers to operate the service.
These providers process data only on our instructions and under strict security controls.
Examples include:
- Cloud infrastructure providers
- Authentication systems
- Database hosting providers
Section 6. Data Retention
Data is retained only for as long as necessary to provide the service.
Organizations may remove employee data directly within the platform.
Section 7. Data Subject Rights
Individuals may have rights including:
- Access
- Correction
- Deletion
- Restriction of processing
Requests related to employee data should generally be directed to the organization that uploaded the information.
Section 8. Data Processing Agreements
Organizations requiring a Data Processing Agreement (DPA) may contact us to request one.
Section 9. Security
TeamTreat implements reasonable safeguards including:
- Encrypted connections
- Authentication controls
- Infrastructure access restrictions
Section 10. Contact
For GDPR-related questions, contact: