Privacy commitments
How we hold it

You are handing us the most sensitive data in the company. We treat it that way.

Leadership assessment means personal, attributable data about named people. The standard we hold ourselves to is the one your own procurement team would set.

Data enters
01 · Residency

Your data stays in the EU.

Assessment responses and reports are stored and processed within the European Union.

02 · Encryption

Encrypted, end to end.

Data is encrypted in transit and at rest using industry-standard protocols.

03 · Access

A short list of named eyes.

Only the named Atlas experts authoring your report can see raw responses. Access is role-based and logged.

04 · Retention

Kept only as long as needed.

We retain data for the life of the engagement and delete it on request.

Deleted on request
The frame around it
05 · Legal basis

GDPR, by design.

Processing rests on a clear legal basis under the GDPR, governed by a signed data processing agreement.

06 · Sub-processors

Named, and few.

We work with a short, named list of sub-processors, available on request.

07 · AI Act

Built to the high-risk standard.

Leadership assessment is high-risk AI under Annex III of the EU AI Act. We do not argue our way out of that. We build to the standard it sets: documented processes, stated model limitations, and a human who can override every output.

08 · Human oversight

A human can always override the machine.

Article 14 of the AI Act requires a person with the authority to disregard or reverse the system's output. That is how Atlas was built, not a concession we made later. AI analyses, a named consultant authors and signs, and the decision stays yours.

09 · Isolation

Your data trains nothing.

Client data is never used to train models, and never shared across organisations. Each engagement is sealed to itself.

10 · Auditability

Every conclusion has a paper trail.

We document the AI-assisted process, its limitations, and the human review behind each report, in line with the AI Act's transparency obligations. Available to enterprise clients and regulators on request.