AuthenticTeamz
Sign In

Privacy policy

Privacy Policy — AuthenticTeamz

Last updated: June 2026

This Privacy Policy explains how AuthenticTeamz ("we", "us", "our") collects, uses, stores, and protects personal data when you use our platform and services (the "Service"). By using the Service, you acknowledge this policy.

If you do not agree with this policy, please discontinue use of the Service.


1. Data Controller and Processor

AuthenticTeamz operates as a data processor in the context of B2B deployments. The organisation that provides you with access to the Service (your employer or contracting entity) is the data controller responsible for determining the purposes and means of processing your personal data.

If you have questions about how your data is used within your organisation, contact your account administrator. For questions about this policy or AuthenticTeamz's role as processor, contact us at team@authenticteamz.com.


2. Information We Collect

We collect the following categories of personal data:

  • Account data: name, email address, authentication credentials, role, team assignment, and profile details you or your administrator provide.
  • Assessment data: responses you submit to questionnaires, derived personality and behavioural scores, consent records, and completion metadata (e.g. timestamps).
  • 360 peer evaluation data: peer ratings submitted about you or by you as part of 360-degree assessments. Individual peer responses are never disclosed to the person being rated; only aggregated results from a minimum of three respondents are shown.
  • Manager notes: optional notes added by authorised administrators about your profile or development.
  • Skills data: hard skills extracted from CVs you choose to upload. The PDF file itself is processed in memory and is not stored; only the extracted skill list is retained.
  • AI assistant data (opt-in only): conversation history with the AI chat assistant, where your organisation has enabled this feature. This feature is not active by default.
  • Operational data: error logs and performance traces collected via our monitoring tools to maintain and improve the Service.

We do not intentionally collect special categories of personal data (such as health data, political opinions, or biometric data) unless explicitly required for a specific assessment and supported by a clear legal basis.


3. Legal Bases for Processing (GDPR Article 6)

We process personal data only where we have a valid legal basis. The table below sets out the primary legal basis for each category of processing activity.

Processing ActivityLegal Basis (GDPR Art. 6)Notes
User authentication and account managementArt. 6(1)(b) — Performance of a contractNecessary to provide access to the Service
Delivery of assessments and generation of reportsArt. 6(1)(b) — Performance of a contractCore service functionality
Sending transactional communications (invitations, notifications)Art. 6(1)(b) — Performance of a contractRequired to operate the Service
Access control and role-based data visibilityArt. 6(1)(f) — Legitimate interestsProtecting data subjects and service integrity
Security monitoring and error loggingArt. 6(1)(f) — Legitimate interestsEnsuring platform security and stability
Compliance with legal obligationsArt. 6(1)(c) — Legal obligationWhere required by EU or Portuguese law
AI-assisted features (opt-in only)Art. 6(1)(a) — ConsentEnabled only where the organisation has obtained appropriate consent

Where we rely on legitimate interests (Art. 6(1)(f)), we have assessed that our interests do not override the fundamental rights and freedoms of data subjects. If you wish to understand more about this assessment, contact us at team@authenticteamz.com.


4. How We Use Your Information

We use personal data to:

  • Deliver the Service, including generating individual reports and team insights.
  • Authenticate users and maintain account security.
  • Send transactional communications such as invitations and system notifications.
  • Monitor and resolve technical errors and performance issues.
  • Comply with legal obligations and enforce our contractual terms.

Access within the platform is role-based. Managers and administrators see derived scores and insights — not individual raw questionnaire answers. Raw answers are accessible only to the person who submitted them.


5. Sharing of Information

We share personal data with the following categories of third parties:

  • Infrastructure and service providers (sub-processors) who help us deliver the Service, under contractual data protection obligations. Our current sub-processors include:
    • Supabase — database and authentication (Frankfurt, Germany)
    • Vercel — application hosting and compute (Frankfurt, Germany)
    • Resend — transactional email delivery
    • Sentry — error monitoring and performance tracking
    • Google (Gemini API) — AI inference, used only where AI features are enabled for your account
  • Your organisation — account administrators and team managers can access derived scores and insights as configured in the product.
  • Competent authorities — where required by law, court order, or to protect the safety and rights of individuals.

A full sub-processor list is maintained and available on request at team@authenticteamz.com.

We do not sell your personal data.


6. International Transfers

Our primary data infrastructure is hosted in Frankfurt, Germany (EU). Certain sub-processors (Resend, Sentry, and Google Gemini) may process data in the United States or other regions outside the European Economic Area (EEA). Where such transfers occur, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) as required under GDPR Chapter V (European Commission Decision 2021/914/EU). Transfer Impact Assessments have been completed for US-based sub-processors where required.


7. Retention

We retain personal data for the duration of your organisation's active contract with AuthenticTeamz, plus a post-termination period as specified in the Data Processing Agreement (DPA). Operational logs are retained for up to 90 days. Database backups are managed by Supabase in accordance with the applicable plan.

Upon contract termination or a verified erasure request, we delete account data, assessment responses, derived scores, notes, skill profiles, and AI conversations within 30 days (standard clients) or 7 business days (enterprise clients).


8. Security

We implement technical and organisational measures to protect personal data, including:

  • Encryption in transit: TLS 1.2+ for all connections between users, our application, and the database.
  • Encryption at rest: AES-256 encryption managed by Supabase's infrastructure.
  • Database access controls: Row Level Security (RLS) is enabled on all tables. The browser never connects directly to the database; all reads and writes go through the application server.
  • Role-based access: data visibility is enforced at account, team, and user levels.
  • Authentication controls: invitation-only onboarding; session cookies are httpOnly, Secure, and SameSite=Lax.

No method of transmission over the internet is completely secure. In the event of a personal data breach, we will notify the relevant controller in accordance with our obligations under GDPR Article 33 (within 72 hours of becoming aware). Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with GDPR Article 34, unless an exception applies (e.g. the data was encrypted).


9. Your Rights

Depending on your jurisdiction and circumstances, you may have the following rights under the GDPR and applicable Portuguese law:

RightDescription
AccessRequest a copy of the personal data we hold about you (Art. 15)
RectificationRequest correction of inaccurate or incomplete data (Art. 16)
ErasureRequest deletion of your data ("right to be forgotten") (Art. 17)
RestrictionRequest that we restrict processing of your data (Art. 18)
Data portabilityReceive your data in a structured, machine-readable format (Art. 20)
ObjectionObject to processing based on legitimate interests (Art. 21)
Withdraw consentWhere processing is based on consent, withdraw it at any time (Art. 7(3))

Because AuthenticTeamz operates as a data processor in B2B contexts, some rights should be directed to your organisation (the data controller) in the first instance. Where AuthenticTeamz can assist directly, contact us at team@authenticteamz.com. We target a response within 30 days (extendable by a further 60 days for complex requests, with notice).

Right to lodge a complaint: If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Portuguese Data Protection Authority:

Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal Website: www.cnpd.pt Email: geral@cnpd.pt

You also have the right to lodge a complaint with the supervisory authority in your country of habitual residence or place of work within the EU/EEA.


10. Automated Decision-Making

AuthenticTeamz does not make solely automated decisions that produce legal or similarly significant effects about you, as defined by GDPR Article 22.

All assessments, scores, and reports generated by the Platform are provided as decision-support tools only. They are intended to supplement — not replace — human judgment. Final decisions about individuals (including employment, promotion, or team composition) must always be made by a human reviewer.

If your organisation uses Platform outputs in a way that you believe constitutes solely automated decision-making, please raise this with your account administrator or contact us at team@authenticteamz.com.


11. Cookies and Session Management

The Service uses session cookies to authenticate and maintain your login session. These cookies are:

  • httpOnly — not accessible by client-side scripts.
  • SameSite=Lax — protected against cross-site request forgery.
  • Secure — transmitted only over HTTPS in production.
  • Valid for a maximum of 30 days, and invalidated immediately upon logout.

We do not use third-party advertising or tracking cookies.


12. Children's Privacy

The Service is intended for use in professional B2B contexts and is not directed at individuals under 16 years of age (or the applicable minimum age under local law). We do not knowingly collect personal data from minors.


13. Changes to This Policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date and, where changes are material, notify affected parties in accordance with our contractual obligations. Continued use of the Service after such changes constitutes acceptance where permitted by law.


14. Contact

For all privacy-related enquiries, requests, or complaints, please contact us:

PurposeContact
General enquiries & privacy requeststeam@authenticteamz.com
Data breach notifications (to AuthenticTeamz)team@authenticteamz.com
Sub-processor list requeststeam@authenticteamz.com
Supervisory authority (CNPD)geral@cnpd.pt / www.cnpd.pt