Security and data protection
Peer feedback, review results and employee goals are sensitive data. Here is how we protect them.
Where data is stored
Customer data is stored on servers in Europe. All connections to the service are encrypted with TLS (HTTPS).
Enterprise customers can have their company data stored in isolation from other customers.
Access to the service
- Corporate single sign-on via SAML 2.0 and OpenID Connect.
- Two-factor authentication with an authenticator app.
- Account provisioning via SCIM 2.0 and HR system integrations.
- Roles and permissions: employees see their own results, managers and HR see only what their role allows. Access to individual campaigns can be granted one by one.
Reviewer anonymity
- In anonymous reviews, reviewer names are never shown in reports.
- When a reviewer group is too small, groups can be merged so that no answer can be traced back to a specific person.
- An AI summary is only generated when there are enough reviewers to keep them anonymous.
Artificial intelligence
- The AI model runs on infrastructure operated by our team. Feedback texts are not sent to third-party AI services.
- People's names are removed from comments before analysis.
Personal data
We process personal data in accordance with the General Data Protection Regulation (GDPR). At the customer's request, we delete or anonymize employee data. See our Privacy Policy for details and our Data Processing Agreement.
Report a security issue
If you have found a vulnerability or suspect a data leak, please email us at [email protected].