Privacy & Cookies
Website Privacy
The following statement explains how the AMRC Partner Portal handles your personal information and the cookies it uses. It applies whenever you visit the portal at this URL.
We never sell or rent your information. Where we share it (e.g. with the University of Sheffield as host institution, or with our processors listed below) we do so only for the purposes stated here and under written agreements that bind the recipient to comparable handling.
Information You Give Us
When you sign in, manage your team, or contact us by email, you provide information such as your name, email address, and the contents of any message. We use that information only to operate the service you asked for. We do not use it to send marketing unless you have separately opted in.
Information Collected Automatically
Like any web service, our server records standard request data — IP address, browser type, operating system, and access times — in short-lived logs used for security, troubleshooting, and capacity planning. These logs are not used to build a profile of you.
Feedback and Bug Reports
The portal has a Feedback button on every page, and our error page offers to report the problem. Both are entirely optional — nothing is sent unless you write a message and choose to send it.
When you do send something, we record:
- What you wrote.
- Who you are — your name, email address, and the partner organisation your account belongs to — so we can make sense of the report and follow it up.
- The page you were on when you opened the feedback box.
- Basic technical details to help us reproduce the problem: your browser window size, any error messages your browser had already produced during that visit, a reference code for the error if you were on the error page, and which release of the portal you were using.
- Whether you ticked the box to say we may contact you about it.
We do not capture what you have typed into other forms, your password, or a screenshot of your screen.
Feedback is read by the AMRC staff who administer the portal, and may be analysed alongside other portal data in AMRC's internal analytics environment so we can see which problems affect the most people. Ticking "you can contact me about this" tells us you are happy to be approached about your report; leaving it unticked means we will read it but not reply.
Lawful Basis for Processing
We process your personal data under the following UK GDPR Article 6 lawful bases, set out by purpose:
- Operating the portal and your account — providing sign-in, team management, and your organisation's project and funding information. This is necessary for the performance of the partnership arrangement between your organisation and AMRC, and for our legitimate interests in administering it (Article 6(1)(b) and 6(1)(f)).
- Security and audit logging — recording sign-ins, failed access attempts, permission changes, and administrative actions. This rests on our legitimate interests in keeping the service secure and on our legal obligations, including the logging commitments we make under ISO 27001 (Article 6(1)(f) and 6(1)(c)).
- Feedback and bug reports — reading, investigating and acting on what you choose to send us through the in-app feedback button or the error page. This rests on our legitimate interests in fixing faults and improving the portal for the partners who use it (Article 6(1)(f)). It does not rely on your consent, because you provide it by actively choosing to send us a message; if you would rather not, simply don't use the feedback button.
- Usage analytics (Microsoft Clarity) — relies entirely on your consent, which you give via the cookie banner and can withdraw at any time (Article 6(1)(a)).
Cookies and Similar Technologies
We use a small number of cookies and one localStorage entry. The table below lists each one, who sets it, what it does, how long it lives, and whether it requires your consent. Strictly-necessary entries are exempt from consent under UK PECR. Analytics entries require your affirmative opt-in via the cookie banner.
| Name | Set by | Purpose | Lifetime | Category |
|---|---|---|---|---|
better-auth.session_token |
Partner Portal | Keeps you signed in. | Session (max 12 hours) | Strictly necessary |
better-auth.state |
Partner Portal | Anti-CSRF state during sign-in. | A few minutes around sign-in | Strictly necessary |
amrc-portal-cookie-consent-v1 (localStorage) |
Partner Portal | Records your consent decision so we don't ask again. | Until you clear it via Cookie preferences | Strictly necessary |
_clck |
Microsoft Clarity | Persistent identifier for usage analytics. | 1 year | Analytics (opt-in) |
_clsk |
Microsoft Clarity | Session signal for usage analytics. | 1 day | Analytics (opt-in) |
For general background on cookies and how to control them in your browser, see aboutcookies.org.
Microsoft Clarity (Analytics)
If you accept analytics in the cookie banner, we load Microsoft Clarity to help us understand how the portal is used. Clarity is provided by Microsoft Corporation as a data processor on our behalf under the Microsoft Online Services Data Protection Addendum (DPA).
What Clarity records on our behalf:
- Approximate geolocation derived from IP address (the full IP is not stored).
- Browser type, device type, and operating system.
- Pages visited, time on page, and navigation paths.
- Mouse positions, click coordinates, and scroll depth.
- Session replays of the interaction — see the masking note below.
Mask-all recordings. Recordings are fully masked at our request: no on-screen text and no form input is captured in the replay. Clarity records the geometry of your interaction (where you clicked, how you scrolled, which page you navigated to) but never the underlying content of the pages you saw or the data you typed. This is enforced two ways: a data-clarity-mask attribute on every page, and the project-level masking setting in Clarity.
Microsoft retains Clarity data for up to 13 months and acts as a data processor under the DPA referenced above. For Microsoft's own statement, see the Microsoft Privacy Statement and the Clarity Terms of Service.
Changing or Withdrawing Your Consent
You can change your mind at any time. Click Cookie preferences in the footer of any page to re-open the consent banner — the new decision takes effect immediately for any future sessions. If you withdraw consent partway through a visit, Clarity will not start any new recording, but a recording already in progress for that page may continue until the page reloads.
If you want to remove every trace of Clarity, click Cookie preferences → Reject analytics, then clear your browser's site data for this portal — that wipes both the consent record and any Clarity cookies set during your previous opt-in.
Data Retention and Erasure
We keep your account data for as long as your organisation is an AMRC partner and you hold portal access. When your access is removed, or following a valid erasure request, we delete your user record and your sign-in credentials.
We retain a minimal entry in our security audit log recording that the deletion took place — including the email address held at the time of deletion — under UK GDPR Article 17(3)(b) and (e). This lets us evidence that the erasure was carried out and meets our legal obligations and our ISO 27001 logging commitments. Those audit entries are used for no other purpose and are themselves subject to retention limits.
Feedback and bug reports are kept for up to 24 months from the date you send them, whether or not we have resolved the issue, and are then deleted automatically. Deletion runs in periodic batches rather than continuously, so an individual report may persist for a short period beyond that before the next batch removes it. If your user record is deleted before then, the report is separated from your identity at that point and what remains cannot be traced back to you.
Your Data Protection Rights
Under the UK General Data Protection Regulation (UK GDPR) you have rights to access, correct, delete, restrict, port, and object to the processing of your personal data. To exercise any of those rights, or if you feel this site is not following its stated information policy, contact:
- University of Sheffield Data Protection Officer — University Data Protection Officer, Corporate Information & Computing Services, 10-12 Brunswick Street, Sheffield, S10 2FN. Email: dataprotection@sheffield.ac.uk.
For other portal enquiries or comments, email enquiries@amrc.co.uk.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk).