Legal

GDPR Compliance

Last updated: 4 March 2026

TeamTreat is designed to support organizations operating under the UK GDPR and EU GDPR data protection frameworks.

This page outlines how TeamTreat processes personal data.

Section 1. Roles and Responsibilities

Organizations using TeamTreat are typically the data controllers.

They determine:

  • What employee data is uploaded
  • Why the data is processed
  • How long it should be retained

TeamTreat acts as a data processor, providing software infrastructure to manage this information.

Section 2. Personal Data Processed

Organizations may upload limited employee data such as:

  • Employee names
  • Work email addresses (optional)
  • Birthdates
  • Dietary requirements

This data is used only to support workplace celebrations managed through the platform.

Section 3. Processing Purpose

TeamTreat processes data for the following purposes:

  • Enabling organizations to track employee birthdays
  • Managing workplace celebrations
  • Coordinating associated orders
  • Maintaining system security
  • Providing customer support

Section 4. Data Minimization

TeamTreat is designed to store only the minimal information required to support celebration management workflows.

Organizations are responsible for ensuring they only upload necessary data.

Section 5. Subprocessors

TeamTreat may rely on trusted infrastructure providers to operate the service.

These providers process data only on our instructions and under strict security controls.

Examples include:

  • Cloud infrastructure providers
  • Authentication systems
  • Database hosting providers

Section 6. Data Retention

Data is retained only for as long as necessary to provide the service.

Organizations may remove employee data directly within the platform.

Section 7. Data Subject Rights

Individuals may have rights including:

  • Access
  • Correction
  • Deletion
  • Restriction of processing

Requests related to employee data should generally be directed to the organization that uploaded the information.

Section 8. Data Processing Agreements

Organizations requiring a Data Processing Agreement (DPA) may contact us to request one.

Section 9. Security

TeamTreat implements reasonable safeguards including:

  • Encrypted connections
  • Authentication controls
  • Infrastructure access restrictions

Section 10. Contact

For GDPR-related questions, contact:

[email protected]