Privacy Policy
Last updated: 2026-05-13
1. Who we are
Assessifier ("Assessifier," "we," "us," or "our") operates the Assessifier platform, a system for organizations ("Subscribers") to build, deploy, and analyze diagnostic assessments. Participants complete assessments through links shared by Subscribers.
For the purposes of the EU/UK General Data Protection Regulation (GDPR/UK GDPR), Assessifier is the data controller with respect to information about Subscriber accounts, and a data processoracting on the Subscriber’s instructions with respect to participant responses captured through the Subscriber’s assessments. Data controller / processor responsibilities are described in our Data Processing Addendum, available on request.
2. Information we collect
Subscriber account data. Organization name, contact name, work email, optional phone number, plan tier, and billing information when applicable.
Subscriber configuration. Branding (logos, colors, fonts, sender display name), authored assessments, questions, scoring rubrics, and recommendation text.
Participant data.Answers selected, category scores, the run timestamp, and source IP address. Participants may optionally provide a name and email to receive their results by email; otherwise participation is anonymous from the Subscriber’s and our perspective.
Technical data. Server logs, error reports, and basic device/browser information used to operate and secure the Service.
Cookies and similar technologies. A first-party authentication cookie set by our identity provider during sign-in, and a small set of localStorage values for user preferences (e.g. light/dark theme). We do not currently use third-party advertising or cross-site tracking technologies.
3. How we use information
We use information to:
- Provide, operate, secure, and improve the Service.
- Send transactional emails (account verification, password resets, assessment results, billing notices).
- Respond to support inquiries and communicate about service updates.
- Detect, investigate, and prevent abuse.
- Comply with legal obligations and enforce our Terms.
We do not sell personal information, and we do not share personal information with third parties for their own marketing.
4. Legal bases (EU/UK GDPR)
Where GDPR or UK GDPR applies, we rely on the following bases:
- Contract. To provide the Service that you signed up for.
- Legitimate interests. Securing the Service, preventing fraud, debugging, and improving product quality. We balance these against your interests and rights.
- Consent. Where required for optional features (e.g. providing your name and email to receive results).
- Legal obligation. Where we must keep records or respond to lawful requests.
5. Sharing
We share personal information only with:
- Service providers acting on our behalf and under contract — currently Microsoft Azure (hosting, database, email delivery, identity) and any future payment processor for subscription billing. Service providers process personal information only as needed to perform their services.
- The Subscriber whose assessment a participant completed. Subscribers see the responses and any identifying information the participant elected to provide.
- Authorities when required by law, court order, or in response to a lawful request, after taking reasonable steps to challenge overbroad requests.
- A successor in connection with a merger, acquisition, or sale of assets, subject to confidentiality commitments.
6. International transfers
We host data on Microsoft Azure infrastructure in the United States. If you access the Service from the EU, UK, or Canada, your personal information may be transferred to and processed in the United States.
Where we transfer personal data out of the EEA / UK, we rely on appropriate safeguards — typically the European Commission’s Standard Contractual Clauses and the UK Addendum — along with supplementary measures as required.
7. Data retention
We retain Subscriber account data for as long as the account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. Participant responses are retained as part of the Subscriber’s account; Subscribers may delete individual assessments or runs at any time. After account closure we delete or anonymize personal information within 90 days, except where law requires longer retention.
8. Security
We use industry-standard administrative, technical, and physical safeguards to protect personal information: HTTPS in transit, encryption at rest, role-based access controls, identity provider-managed authentication for both subscribers and operators, and regular security review of the platform. No system is perfectly secure; in the event of a breach we will notify affected parties as required by law.
9. Your rights
Depending on where you live, you may have the following rights regarding personal information about you:
EU / UK (GDPR / UK GDPR): access, rectification, erasure, restriction of processing, portability, objection (including to processing based on our legitimate interests), withdrawal of consent where we rely on consent, and the right to lodge a complaint with your supervisory authority.
California (CCPA/CPRA) and other US states: the right to know what categories and specific pieces of personal information we have collected; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising); and the right not to be discriminated against for exercising these rights.
Canada (PIPEDA): the right to access personal information we hold about you, to challenge its accuracy, and to withdraw consent (subject to legal and contractual restrictions). You may also contact the Office of the Privacy Commissioner of Canada.
To exercise any of these rights, email privacy@assessifier.com. We respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request.
Authorized agents may submit requests on your behalf with written authorization. Participants who completed an assessment for a particular Subscriber may also direct requests to that Subscriber, who is responsible for fulfilling rights in respect of their participants.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact privacy@assessifier.com and we will take steps to delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated by email or in-app notice in advance of taking effect where required by law.
12. Contact us
Privacy questions, rights requests, and complaints can be sent to privacy@assessifier.com.
EU and UK residents may also contact our representative for GDPR / UK GDPR matters at the same address until a local representative is appointed; we will update this section if and when one is.