FOURPLUS / PRIVACY
FourPlus Privacy Notice
XR services, HPIL and website engagement
This draft explains how FourPlus uses information from Eclipse Creator and Accelerate, the planned HPIL service, and our website quote and business case tools. HPIL is in development as a human process intelligence service for operational support, process knowledge and quality review; it is not training software. Collection depends on the features enabled for a deployment. Website engagement data has a separate sales purpose and is not combined with individual XR or HPIL execution records for sales profiling.
1 Who we are and who is responsible
FourPlus Immersive Ltd (company number 12558660), registered at Floor 16 (JQB), Centre City Tower, 7 Hill Street, Birmingham, B5 4UA, acts as controller where it determines the purposes and essential means of processing. This includes its website enquiries, permitted website engagement profiling, service security and its own approved product improvement and anonymisation activities. The role for an XR scoring service or HPIL deployment depends on the actual processing arrangements, not solely on who designs the software.
The employer, university, college, training provider, NHS trust or other organisation that gives you access (the Customer) is responsible for its user administration, training or operational programme and its own use of records. Where FourPlus processes operational information only on the Customer’s documented instructions, FourPlus acts as a processor under a data processing agreement. Where FourPlus and a Customer jointly determine a specific purpose and essential means, they will document their joint responsibilities and make the essence available to individuals. Each deployment will identify the relevant controllers, purposes and lawful bases; contract labels do not override the factual role.
Privacy contact: privacy@fourplus.co.uk. Data Protection Officer/privacy lead: Ivan Wall, ivan@fourplus.co.uk.
2 Information collected through XR and HPIL
- Identity and account data: name, username or user identifier, organisation, role/cohort, login and authorisation status, and identifiers needed to associate an authorised person with a defined execution session.
- Protocol and execution records: module or SOP and version; steps presented, started, completed, skipped, repeated or performed out of order; prompts, warnings, confirmations, process decisions, exceptions, adaptations, recovery actions and corrective actions, where the enabled service records them.
- Hand-tracking and spatial interaction data: positions and movements of hands within the XR environment and their interactions with virtual equipment, objects and controls. These data are used to understand task execution and are not used to identify you biometrically.
- Timing data: session date/time, start and finish, duration, per-step timing, pauses and retries.
- Voice assistance data: recordings made when you use enabled voice assistance, and resulting transcripts or commands. Recordings may support service delivery and speech-to-text validation, including accuracy across accents and dialects. The approved XR design retains recordings for up to 36 months. HPIL voice collection and retention must be confirmed for the deployment. Recordings are not used for speaker recognition, biometric identification, disciplinary action or covert monitoring.
- Point of view video: approved outward-facing video from a headset or wearable device showing the task, work area and equipment. It is intended to capture execution rather than the wearer’s face, but may incidentally include other people, voices, reflections, badges, screens or documents. Capture areas, recording indicators and minimisation controls must be defined before use. Permitted purposes may include execution review and, only after effective anonymisation and governance checks, computer-vision development. Facial recognition, biometric identification, disciplinary action and covert monitoring are not permitted.
- Assessment and support data: advisory training scores where relevant to XR training; HPIL process observations, guidance requests and responses, retrieved procedural context, exception/deviation flags, explanation or evidence references, confidence indicators and human-review annotations, where enabled.
- Technical and security data: headset/device and application identifiers, software/schema versions, synchronisation, diagnostics, security and audit events.
- Support and feedback: support tickets, user feedback and related communications.
- Customer knowledge and AI inputs: approved SOPs, process documents, structured execution evidence, questions and contextual material used for customer-specific retrieval and inference. These may include personal data if the Customer supplies it; access and minimisation requirements still apply. A customer-specific dataset is not automatically anonymous.
Eye tracking is outside the currently approved XR processing scope. It will not be enabled for XR or HPIL until the relevant notice, data protection impact assessment and other required assessments have been updated and the deployment has been approved.
We do not use hand, voice, video or other execution data to identify people biometrically or to infer health, emotions, protected characteristics or general employee productivity. The services are not intended to collect patient records or other special-category information. Incidental sensitive information must be minimised, restricted and, where unnecessary, removed. Any intended processing of special-category information requires a separate documented assessment, an applicable additional legal condition and an updated deployment notice.
3 How XR and HPIL information is collected
XR software records approved events during an enabled training or execution session. HPIL is intended to bring together structured evidence from process replication and enabled capture in a physical facility, potentially including wearable devices such as smart glasses. The deployment notice will describe the actual devices, sensors, recording scope, start and stop controls, information sources and responsible organisations before collection begins. A telemetry register will specify each field, purpose, access and retention period. A general privacy notice does not authorise continuous or covert recording.
Existing XR production hosting is described in section 9. HPIL hosting, third-party AI access and the approved telemetry for each physical-facility deployment remain subject to confirmation. Staff, learners and relevant bystanders must receive appropriate information; workplace deployments must assess necessity, proportionality and whether consent would be freely given rather than assuming it.
4 Purposes and lawful bases
| Purpose | Information | FourPlus position / proposed basis |
|---|---|---|
| Operate, authenticate and secure the service | Account, ledger, technical/security | Controller for necessary operational purposes; contract and/or legitimate interests as applicable. |
| Create a session record and advisory training score | Identity, ledger, hand/spatial interaction, timing, assessment | Controller or processor allocation depends on the actual purpose and essential means. The deployment agreement and notice identify the parties and basis; software design alone does not settle the role. |
| Provide training feedback and identify SOP compliance and deviations | Ledger, interaction, timing, assessment | Legitimate interests in providing effective XR training and meaningful feedback, subject to necessity, fairness and human oversight. |
| Improve FourPlus content, usability, scoring and technical performance | Pseudonymised/minimised operational data where identity is unnecessary | Legitimate interests in R&D/product development, supported by a Product Improvement LIA. |
| Create anonymous datasets for AI development | Personal data when preparing anonymous information; effectively anonymous information thereafter | Legitimate interests for the personal-data processing needed to select, minimise and anonymise data, supported by a separate AI Development/Anonymisation LIA. The model-training dataset itself contains anonymous information, not personal data. |
| Meet legal, security and claims requirements | Relevant account, ledger, technical and support data | Legal obligation and/or legitimate interests. |
| Provide HPIL execution context and operational support | Approved execution evidence, procedures, questions, retrieved context and advisory outputs | Customer-determined operational use may be processing on instructions. Any FourPlus controller purpose requires its own identified basis and documented necessity. Deployment-specific assessment before collection. |
| Provide website quotes and requested business cases | Case inputs, submitted contact details and report records | Steps requested before a contract where applicable; otherwise legitimate interests in responding to organisational enquiries. Contact capture is separate from optional tracking. |
| Recognise website browsers and link engagement to contacts | Consented browser identifier, page events, approximate active time and submitted organisation details | Consent for engagement cookies and linked sales profiling. No tracking before opt-in; quote and report access remains available on rejection. |
| Send optional website email updates | Email address, preferences and consent record | Separate affirmative opt-in for this implementation. A quote or report request is not a marketing subscription. |
5 Advisory outputs and human review
XR training services may compare a session with an SOP and produce advisory scores or feedback. HPIL is intended to connect execution evidence with relevant procedures, support operators, provide missing context for quality review and inform process improvement and future automation. An HPIL observation, explanation or deviation flag is a review aid, not proof of error or misconduct. This design does not authorise solely automated decisions with legal or similarly significant effects.
- FourPlus does not permit the ledger, score or AI output to be used for disciplinary action.
- The services are not designed or authorised for covert employee surveillance, general productivity surveillance or monitoring outside the clearly defined training or operational session.
- A qualified human must interpret individual results and remain responsible for consequential training, competency, certification, progression, quality, employment or safety-related decisions. An organisation must not treat an automated result as a substitute for its professional or regulatory responsibilities.
- A reviewer must be able to inspect relevant execution evidence, the applicable procedure and available reason codes, consider missing context, challenge the model and change the proposed outcome. Where an output cannot be adequately supported, it must not be presented as a definitive finding.
- A user may challenge an inaccurate ledger entry or score and request human reconsideration.
- Where the data are incomplete or unreliable, the software should display an unscorable/low-confidence result rather than present a definitive conclusion.
6 Data protection and AI use
We protect personal and customer information through appropriate access controls and safeguards. Approved customer procedures, execution evidence, questions and related information may be used to provide authorised AI-assisted support. Where that information identifies a person, it remains subject to the purposes, access restrictions and retention arrangements described in this notice and the relevant deployment notice.
Under the approach described in this draft, only effectively anonymised information may be used to train, adapt or evaluate general or customer-specific AI models. Removing names or replacing identifiers alone does not make information anonymous. We assess whether a person could reasonably be identified and exclude information that does not meet the required standard.
Video and voice information requires particular care because people may be identifiable from their appearance, voice or the surrounding context. Any use for model development must meet the applicable anonymisation and governance requirements. Identifiable voice recordings used for speech-to-text validation remain protected personal data and are subject to the stated retention period.
Using customer information to provide an AI-assisted answer does not itself authorise its use for model training. Any proposed use of personal or pseudonymised information for model training requires a separate assessment of purpose, responsibility, lawful basis and safeguards, and an updated notice before that use begins.
7 Limits on use
- We do not sell personal data. Individual XR and HPIL operational records are not used for website advertising or sales profiling. Optional website engagement and email marketing are described separately in sections 15 and 16.
- We do not use the training ledger or score for disciplinary action.
- We do not use the system for covert surveillance.
- Under the design retained in this draft, we do not train general or customer-specific AI models directly on named or pseudonymised personal execution records. Retrieval and inference do not remove the need to protect personal data.
- We do not use hand, voice or point of view video to identify people biometrically. Wearable recording must follow the disclosed capture scope and controls.
- We do not infer health conditions, emotions, protected characteristics or general employee productivity from XR or HPIL behaviour.
- We do not enable eye tracking under the current approved processing design.
8 Who receives information
- Authorised Customer trainers, operators, quality reviewers or administrators with a relevant training or operational need and permissions appropriate to their role. Access to an individual’s information must be limited to the stated purpose.
- Authorised FourPlus personnel and contractors for the relevant service, support, security, quality, product development and approved data engineering. Website sales personnel access website enquiry and consented engagement information through the separate private dashboard.
- Amazon Web Services for the existing XR hosting arrangement, and other approved service providers under written terms. Any HPIL model/inference provider, hosted website supplier, CRM or email service must be identified and assessed before it receives personal data; the local website preview has no third-party analytics or CRM integration.
- Professional advisers, regulators, courts or law-enforcement bodies where disclosure is necessary and lawful.
Only effectively anonymised information may enter the model-training pathway described here. Operational retrieval and inference access is separately controlled. Providers must not reuse personal customer inputs for their own model training unless a separately assessed and disclosed arrangement permits that use.
9 Hosting and international access
The existing XR service is described in version 1.2 as using AWS hosting in the United Kingdom, with no required transfer of UK personal data outside the UK in that production design. This draft does not extend that statement automatically to HPIL or the website dashboard. The website prototype currently stores data locally on its host computer. Production website/dashboard hosting, HPIL processing regions, remote support access and any model providers must be confirmed before launch.
This marketing website is hosted using Sites. Its owner editor requires sign-in. The marketing website does not implement the optional engagement cookies described in section 16. The local business-case builder and sales dashboard are separate. Hosting-provider processing, infrastructure access and any necessary international-transfer safeguards must be confirmed before this notice becomes effective for a public launch.
If personal data is made accessible to a separate organisation outside the UK, FourPlus will assess the applicable international-transfer requirements, including overseas support access and onward transfers. Where required, safeguards may include adequacy arrangements or appropriate contractual safeguards and the relevant data protection test or transfer risk assessment. The published notice and supplier information must identify the applicable arrangement. Effectively anonymous data is not personal data, but pseudonymised data remains subject to these requirements.
The service retention periods below are carried forward from the supplied XR draft, with new website periods matching the prototype. The longer XR periods, video retention and the HPIL schedule require documented necessity and approval; they are not new evidence that each period is proportionate.
10 Retention
| Record | Retention | End-of-period action |
|---|---|---|
| Identifiable session ledgers and scores | 36 months after the session, or Customer-documented shorter period | Delete or irreversibly anonymise. |
| Account/contract administration records | Customer relationship plus 6 years | Secure deletion subject to legal holds. |
| Security and diagnostic logs | 36 months | Secure deletion or aggregation. |
| Pseudonymised product-improvement data | Up to 10 years, reviewed annually | Delete, refresh or anonymise; retain only where continuing necessity is documented. |
| Anonymous AI-development datasets | Life of model plus 10 years | Retain while useful and governed; re-test assumptions if linkage environment or data availability materially changes. |
| Model artefacts and evaluation records | Life of model plus 10 years | Retain accountability evidence; do not intentionally retain personal training data in model artefacts. |
| XR voice recordings for speech-to-text validation | Up to 36 months from recording, as stated in the existing draft | Delete; validate necessity and shorter alternatives before approval. |
| POV video and HPIL retrieval stores and outputs | Deployment-specific period to be confirmed before collection | Document deletion, derived data and model/provider handling; no indefinite default. |
| Website visitor identifiers and engagement events | Up to 90 days; cookie duration also 90 days | Delete expired visitor activity. Withdrawal deletes activity for the affected browser in the prototype. |
| Website business cases and contact records | Cases: 12 months from submission. Contacts: 12 months after the last submission | Delete from the prototype. Separate contractual retention may apply if the person becomes a customer. |
| Website consent and administrator audit records | Up to 12 months in the prototype | Delete after the accountability period, subject to a documented legal hold. |
| Saved customer case on their device | Until the user starts a new case or clears browser storage | User-controlled local deletion; not a marketing identifier. |
11 Security and access
- The existing XR design specifies the controls below. HPIL and hosted website controls must be verified for their respective deployments before they are described as implemented.
- For the existing XR design, UK AWS hosting with encryption in transit and at rest.
- For production service administration, Customer/tenant segregation, role-based access, least privilege and multi-factor authentication for privileged access. The local website prototype currently uses a separate password-protected dashboard; production identity, MFA, backup and encryption arrangements must be completed before live lead capture.
- Separate customer login/device allocation, identity mapping and access-control services.
- Access to personal information is restricted to authorised purposes. Only effectively anonymised information is permitted for model development under the approach described in this notice.
- Audit logging, vulnerability management, backups, recovery testing and incident procedures.
- Documented checks and approval before information is used for a new purpose.
12 Your rights
Depending on the processing and your circumstances, you may have rights to access, correct, erase or restrict personal data, object to processing based on legitimate interests, receive portable data where applicable, and obtain information about and human review of qualifying automated decisions. You may withdraw consent at any time; withdrawal does not affect the lawfulness of earlier processing. You may object to direct marketing and related profiling. Rights apply to identifiable and pseudonymised operational information, including relevant retrieval stores and website records. After effective anonymisation, information can no longer be retrieved as your personal data from an anonymous dataset.
Contact privacy@fourplus.co.uk, giving your organisation and enough context to locate the relevant session, enquiry or website visit. We will verify identity where needed and coordinate with the Customer where responsibility sits with them. For website tracking, Cookie settings lets you change your choice without contacting us. Email marketing choices are separate from tracking choices.
13 Complaints and changes
Contact FourPlus at privacy@fourplus.co.uk. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. We will update the relevant notice before materially changing collection, wearable capture, eye tracking, permitted AI uses, sales-tracking purposes, recipients or international access. Where a change requires new consent, a notice update alone is not sufficient.
14 Children and vulnerable learners
Where software is used by children or vulnerable learners, FourPlus and the Customer will complete deployment-specific safeguarding, transparency and data-minimisation checks. Data from children is excluded from anonymous AI-development datasets by default unless a separately approved assessment supports the use and effective anonymisation is demonstrated. The website business-case tools are intended for organisational purchasing and project planning; any use aimed at children requires a separate review, including whether engagement tracking should be disabled.
15 Website enquiries and engagement
You can calculate a quote and potential savings without supplying contact details or accepting engagement tracking. Calculator inputs are processed to return your results and are not stored as a lead merely because you use the calculator. Avoid entering patient information or unnecessary personal information about staff or learners in free-text fields.
When you generate a business case, we ask for your name, email and organisation. Role and organisation website are optional. We record the submitted case, quote, request time and your choices about project follow-up and email updates. The prototype generates the report on screen or as a download; it does not send emails. We use the submission to fulfil your request and manage the enquiry, on the basis described in section 4.
If you separately allow engagement cookies, we recognise this browser using a random identifier and record visits, pages or sections viewed, approximate active time, referral website hostname and quote/report events. We do not use keystroke capture, session replay, screenshots, fingerprinting, reverse-IP company identification or cross-site advertising in this implementation. Active time excludes hidden or idle periods where detectable and remains an estimate, not proof of attention.
If you submit contact details after allowing tracking, we link consenting activity from this browser to the contact record, including earlier consenting visits within the retention period. We use this profile to understand product interest and inform sales follow-up. The same browser can be shared by different people; cookie records do not verify who was using it.
The dashboard may group contacts using their declared organisation website or email domain. We label this as an unverified association. Shared or personal domains, including nhs.net, are not treated as one employer. We cannot reliably identify every visitor, colleague or device, and do not claim an unknown visitor belongs to a company solely because another contact from that organisation has visited.
Website sales profiles remain separate from individual XR and HPIL execution records. Optional email updates require a separate unticked opt-in in this implementation. You may stop those messages independently of your cookie choice. We do not use the website profile for solely automated decisions with legal or similarly significant effects.
16 Website cookies and your choices
The first visit presents equally prominent options to allow or reject engagement cookies. No engagement identifier or tracking event is created until you opt in. The quote, savings calculator and report remain available if you reject tracking. Cookie settings remains available so you can change your choice.
The fp_choice cookie remembers your choice for 90 days. The optional fp_visitor cookie recognises a consenting browser for up to 90 days. The fp_admin cookie supports authorised FourPlus dashboard sign-in for 8 hours and is not a sales-tracking cookie. When you explicitly choose Save on this device, browser storage retains your case until you clear it or start a new case.
Withdrawing engagement consent stops further recording, clears the optional identifier and deletes the activity linked to that browser in this implementation. It does not automatically delete a separately submitted enquiry or undo lawful earlier processing. A limited consent record is retained for accountability. Contact privacy@fourplus.co.uk to request deletion or exercise other rights for submitted information.
The current local prototype has no external analytics, CRM or advertising recipient. Before hosted launch, we will identify the actual website and dashboard providers, relevant locations and transfer safeguards. Visitor profiling for sales is not treated as aggregate statistical analytics exempt from consent.
For privacy enquiries, contact privacy@fourplus.co.uk. You can also contact the ICO.
