Data Collection Purpose Justification


FieldValue
Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II — Security, Availability, Confidentiality

1. Purpose and Scope

This document records the specific purposes for which QA Touch collects personal information and the justification demonstrating that each collection is necessary to meet the entity’s service delivery and privacy objectives. It supports SOC 2 Privacy criterion P3.1 (Collection Limited to Identified Purposes) and demonstrates data minimisation compliance under GDPR Article 5(1)(b) and equivalent regulations.

2. Data Collection Purpose Register

Personal Data ElementCollection PurposeLegal BasisNecessity JustificationMinimisation Applied
Full NameAccount identification; attribution of test actions in audit log; display within team workspace.Contract performance (GDPR Art. 6(1)(b))Required to identify individual users within collaborative team environments and accurately attribute all actions in the audit trail.First and last name only; no government ID or other identity documents collected.
Email AddressPrimary login credential; notification delivery; workspace invitations; support communication.Contract performanceNecessary for account authentication, security alerts, password reset, and team collaboration.One email per account; no secondary email unless provided by user.
Password (hashed)Verifying user identity on login.Contract performanceRequired to authenticate users and prevent unauthorised access to customer workspaces.Stored as Argon2id one-way hash; plaintext never stored, transmitted, or retrievable.
Phone Number (optional)MFA delivery via SMS or call if selected by user; account recovery option.Legitimate interests (security hardening)Collected only when user voluntarily enables phone-based MFA; not required for any other function.Optional; collected only on user election; deletable when user switches MFA method.
IP Address (login/session)Security event logging; brute-force detection; geographic anomaly alerting.Legitimate interests (security)Necessary to detect account takeover attempts, credential stuffing, and geographic anomalies.Retained in security logs per defined retention schedule; not used for profiling or marketing.
SSO / OAuth Identity TokensFederated authentication via third-party identity provider (Google Workspace, Okta, etc.).Contract performanceRequired when user authenticates via SSO; allows login without QA Touch storing a password.Tokens valid only for session duration; not retained after logout or expiry.
Profile Photo (optional)Personalisation; display within team workspace.Consent / Legitimate interestsOptional avatar that improves team identification in collaborative UX; not required for any function.Optional; user may upload or skip; deletable at any time from User Settings.
Role and Permission AssignmentsEnforcing RBAC; ensuring users access only authorised resources.Contract performanceNecessary to implement data access controls that protect customer test assets.Only role and permission data needed for access decisions stored; no sensitive personal attributes.
Billing Contact InformationProcessing subscription payments; invoicing; subscription lifecycle management.Contract performanceRequired to manage the commercial relationship and ensure service continuity.Limited to billing contact name, email, address; payment card data tokenised by PCI-compliant processor.
AI Prompt ContentProcessing user’s natural language input or uploaded files to generate test cases via LLM provider.Contract performance / ConsentCollected only when user actively submits a prompt; necessary to provide the AI generation service.Transmitted to LLM provider; QA Touch storage minimised [VERIFY retention with engineering].
Support Ticket ContentInvestigating and resolving customer support requests.Legitimate interests / Contract performanceNecessary to diagnose technical issues and maintain service quality.Limited to what user chooses to share; only relevant support agents access specific tickets.
Anonymised Usage AnalyticsProduct improvement; identifying usability issues; feature prioritisation.Legitimate interestsImproves platform for all users; no individual profiling.Anonymised before processing; no personal re-identification possible [VERIFY anonymisation method].
Integration Event LogsDebugging integration failures; audit trail of integration activity.Legitimate interests / Contract performanceNecessary to diagnose sync errors and maintain reliable integration behaviour.Logs contain event type, timestamp, and outcome; personally identifiable content of synced records minimised.

3. Purpose Limitation Controls

  • Personal data is collected only for the purposes listed in this register and the Privacy Policy.
  • Any new data collection or new use of existing data requires: reassessment of legal basis, update to this register, DPIA if high-risk, Privacy Policy update, and user notification before processing begins.
  • Employee access to personal data is restricted to the scope of their documented business role.
  • Data is never shared with third parties outside the documented Sub-Processor Register.
  • Annual data minimisation review: each element evaluated to confirm continued necessity.

4. New Data Collection Approval Process

  • Product Manager or Engineering Lead identifies new data collection requirement and submits a Data Collection Request.
  • Privacy/Compliance Officer reviews necessity, proportionality, and legal basis; conducts DPIA if high-risk (AI features, new sensitive categories).
  • CISO reviews security implications of the proposed new data element.
  • CISO and Privacy Officer jointly approve or reject; decision documented with rationale.
  • Privacy Policy and this register updated before feature launch; customers notified of material changes.