Privacy and data protection
How BriefCycle handles data.
Last updated 10 September 2026 · Otherworld Dev Ltd, company number 17175223, ICO registration C2001194
BriefCycle is assessment moderation software for universities, made by Otherworld Dev Ltd, a company registered in England and Wales. This page explains what data the software processes, where it lives, and who to contact. It is written for the people at a university who have to decide whether to use it, so it is specific rather than generic. A fuller data protection pack and security summary are available on request for procurement and DPIA purposes.
Two kinds of deployment, two sets of responsibilities
Universities can run BriefCycle on their own infrastructure or have us host it.
- Self-hosted. The university installs and operates the software itself and holds all the data. Otherworld Dev Ltd is a software supplier only and does not process personal data on the university's behalf, other than support access the university explicitly grants for a specific purpose.
- Hosted by us. We operate a dedicated, single-tenant instance for the university on UK infrastructure. The university is the controller; Otherworld Dev Ltd is its processor under Article 28 of the UK GDPR, on the terms of a written data processing agreement.
What the software processes
BriefCycle manages the review and approval of assessment materials — coursework briefs, exam papers, marking criteria — as they move between the people who set, review, approve and sign them off. The personal data involved is about staff and external examiners:
- name, university email address and username of each participant;
- who is assigned to which role on which assessment;
- review comments and decisions, and the record of who did what and when — this audit trail is the point of the product;
- a log of which participant opened which document, and the IP address in web-server logs;
- notification emails, which contain the recipient's name, the assessment reference and a link — never document content.
BriefCycle does not process student personal data. There are no fields for student names, numbers, work or marks, and no upload path that expects them. It uses no artificial intelligence and makes no automated decisions: every decision in the workflow is made by a named person.
The assessment documents themselves — unreleased exam papers in particular — are confidential university material rather than personal data, and are protected accordingly: served only to the participants of that assessment through a permission-checked viewer, with every open logged.
Where data is stored (hosted deployments)
Hosted instances run in the United Kingdom and personal data is not transferred outside the UK.
| Sub-processor | Purpose | Location |
|---|---|---|
| Civo Limited | Virtual server, storage and backups for the dedicated instance. London region; data is not replicated to other regions. ISO/IEC 27001:2022 certified. | United Kingdom |
| Mythic Beasts Ltd | Sending notification and reminder emails. Sees recipient name, address and assessment reference only. | United Kingdom |
| Otherworld Dev Ltd (own infrastructure) | Encrypted off-site backup copies; the decryption key is held separately from the hosting provider. | United Kingdom |
TLS certificates are issued by Let's Encrypt, which receives domain names only. No analytics, advertising, tracking or error-reporting services are used, in the software or on this website. We give customers 30 days' notice of any change to this list.
Security
One isolated deployment per institution; TLS for all traffic; single sign-on with the university's own Microsoft Entra ID tenant and no self-registration; documents never served from a public path; a read-only in-browser document viewer with short-lived signed access; full version history so nothing is overwritten; encrypted nightly backups mirrored off-site with tested restores; key-only administrative access limited to named personnel; dependency vulnerability scanning before each release. A written security summary is available on request.
Retention and deletion
Workflow records and documents are retained for as long as the university's instance exists, because the audit trail is the institution's quality record; retention policy is the university's to set and we apply it on instruction. When a hosted agreement ends, we provide a complete export of the university's data and then delete all data, including backups and off-site copies, within 30 days, and confirm deletion in writing.
Your rights
If you are a member of staff or an external examiner and your details are in a BriefCycle instance, the university that runs it is the controller: requests to access, correct or erase your data go to it, and we will assist it within five working days. Contact details for the ICO, the UK supervisory authority, are at ico.org.uk.
This website
briefcycle.com is a static site. It sets no cookies, runs no analytics and loads nothing from third parties. If you email us to book a demo, we keep your message and reply for as long as the conversation is live and for up to 12 months afterwards, on the basis of our legitimate interest in responding to enquiries.
Contact
Data protection queries, requests for the data protection pack, and notification of any concern: privacy@briefcycle.com. Otherworld Dev Ltd, 4th Floor, 14 Museum Place, Cardiff CF10 3BH.