Skip to main content
Privacy notice

Your assessment data, explained plainly.

This notice explains what AILAT processes, how AI-assisted scoring works, what an inviting organization can see, how long current records remain, and how to exercise your rights.

Version 2.0 · Last updated

On this page

The short version

Responsible parties
Founderly is responsible for direct assessments and its own billing, security, and compliance uses. An inviting organization normally determines its workforce-assessment purpose.
Automated evaluation
Open-text answers are scored automatically, and limited assessment context can be used for learning recommendations and adaptive question selection.
Organization reporting
The standard organization report contains aggregate results, not individual answers or scores, and uses small-group suppression controls.
Retention
Raw sessions expire on schedule; some completed results and reports do not yet have a fixed automatic deletion date.
01

Who is responsible, and when this notice applies

The responsible party depends on whether you take AILAT directly or through an organization.

This notice applies when you visit AILAT, purchase or take an assessment, activate an organization invitation, receive or access an organization report, contact us, or exercise a privacy right.

If you purchase or take AILAT independently, Founderly OÜ determines why and how the assessment service processes your personal data and acts as controller.

If an organization invites you, that organization normally decides why the assessment is offered and how it uses programme reporting. Founderly handles the data needed to provide AILAT under the applicable customer arrangement and follows the organization's instructions where it acts as processor. The organization's participant notice also applies. Founderly acts separately as controller only for purposes it determines itself, such as direct billing, legal compliance, security, or fraud prevention.

Founderly OÜ

Estonian Commercial Register code 14704762
Pärnu mnt. 12, 10148 Tallinn, Estonia
mail@founderly.com
02

What personal data we process

AILAT avoids asking standard enterprise participants for names or email addresses, but pseudonymous assessment and programme records remain personal data.

Assessment setup

Industry, professional role, motivation, and, for an organization-sponsored assessment, the role or department category selected from the organization’s configured list.

Source: You, or your organization for organization and programme context.

Responses and activity

Multiple-choice and open-text answers, response time, answer timestamps, completion state, and assessment duration.

Source: You and the assessment service while you participate.

Scores and recommendations

Correctness, automated open-answer score and feedback, proficiency estimates, overall and dimension scores, literacy level, strengths, growth areas, and learning recommendations.

Source: Generated from your responses and assessment context.

Identifiers and access records

Pseudonymous assessment and participation identifiers, organization or programme references, access status, completion status, and security records needed to protect access.

Source: Generated by AILAT; organization or programme context may come from the customer.

Payments and recovery

Transaction and payment-status information, purchaser email, and records needed to provide or recover paid assessment access.

Source: You, Stripe, and AILAT when it records the transaction and provides access information.

Organization administration

Organization and programme settings, approved reporting categories, report-recipient contact details, participation status, and report-access records.

Source: The organizational customer and AILAT.

Contact inquiries

Name, email address, inquiry details, organization or rollout context where relevant, and limited source or campaign information supplied with the inquiry.

Source: You when you use the contact form or email Founderly directly.

Communications

Support messages, privacy requests, and the limited contact or verification information needed to answer them.

Source: You, an organizational customer, or another person contacting Founderly.

Technical and security data

IP address and limited operational or security metadata needed to protect and run the service.

Source: Your device, network, AILAT, and its infrastructure providers.

AILAT is not designed to collect special-category data. Please do not put names, health or disability information, racial or ethnic origin, political or religious views, trade-union information, sex-life or sexual-orientation information, confidential business information, or unrelated information about another person in an open-text answer.

03

Why we process it and the legal basis

We do not rely on consent for the core assessment. The applicable basis follows the purpose and Founderly’s role in that activity.

  • Provide a directly purchased assessment, adapt delivery, produce results and recommendations, and support paid-access recovery.

    Role
    Founderly as controller.
    Legal basis
    Performance of the service contract — GDPR Article 6(1)(b).
  • Provide an organization-sponsored assessment and aggregate programme reporting.

    Role
    The organization normally acts as controller for its workforce purpose. Founderly acts as processor where it handles data under the organization’s instructions and as controller for separate purposes it determines itself.
    Legal basis
    The organization must identify and explain its lawful basis. Founderly follows documented instructions where it acts as processor and identifies a separate basis for purposes it determines itself.
  • Manage enterprise accounts, coordinator access, transactional service notices, contract acceptance, and delivery evidence.

    Role
    Founderly as controller for business-account administration and its contract, security, compliance, and claims records.
    Legal basis
    Legitimate interests in administering and securing the enterprise service — Article 6(1)(f); and legal obligation where applicable — Article 6(1)(c).
  • Protect assessment access, prevent abuse and fraud, troubleshoot failures, monitor service operation, and maintain reliability.

    Role
    Founderly as controller for independently determined security purposes, or as processor where the activity forms part of the instructed service.
    Legal basis
    Legitimate interests in a secure and reliable service — Article 6(1)(f), where Founderly is controller.
  • Process payments, maintain transaction evidence, handle disputes, and meet accounting or other legal duties.

    Role
    Founderly is controller for its payment, access, accounting, and dispute records. Stripe describes its own checkout processing in its privacy notice.
    Legal basis
    Contract — Article 6(1)(b); legal obligation — Article 6(1)(c); and legitimate interests for fraud or claims where applicable.
  • Answer enterprise, API, research, procurement, privacy, and general inquiries and manage necessary follow-up.

    Role
    Founderly as controller.
    Legal basis
    Steps requested before entering a contract — Article 6(1)(b); legitimate interests in responding and operating the service — Article 6(1)(f); or legal obligation for rights requests — Article 6(1)(c), as applicable.
  • Answer privacy requests, cooperate with regulators, and establish, exercise, or defend legal claims.

    Role
    Founderly as controller for its obligations and claims; Founderly also assists organizational controllers.
    Legal basis
    Legal obligation — Article 6(1)(c); legitimate interests in legal claims — Article 6(1)(f), where applicable.

Required information: Industry, role, motivation, answers, and any department required by the assessment configuration are needed to complete the assessment and generate a result. Direct purchasers must provide Stripe with the information needed for checkout and an email used for access or recovery. Without required information, AILAT cannot provide the relevant assessment, result, or paid access. Support and privacy-request contact information is otherwise optional, although enough information may be needed to locate and verify the relevant data.

04

AI-assisted scoring and profiling

AILAT automatically adapts the assessment, evaluates open-text responses, and may use limited assessment context for learning recommendations or question selection.

Open-answer scoring: AILAT sends the relevant question, your complete answer, and the grading criteria through Cloudflare to one or more AI providers (Google, Anthropic, or Cloudflare) to produce a score and feedback.

Learning recommendations: AILAT may use your industry, role, literacy level, and weakest assessment dimensions to generate a personalized learning path.

Adaptive question selection: Earlier answers and estimated proficiency can influence the next question. Limited assessment context may be used to select or generate that question; this context does not include your open-text answer.

Automated scores affect proficiency, dimension scores, your result, and learning path. A human does not routinely review every answer. This automated evaluation is profiling because it evaluates knowledge or performance.

Founderly does not use this profiling to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. AILAT is not intended for individual hiring, promotion, pay, discipline, termination, credit, eligibility, or similar decisions, and the standard organization report does not expose your individual answer or score. An organization planning a consequential use must separately assess its lawfulness, implement required safeguards, and tell affected people.

Founderly does not use assessment answers to train its own models. Third-party handling of prompts depends on the provider terms and settings applicable to AILAT; current providers are listed on the Trust and data-handling page.

05

Organization reporting, recipients, and transfers

AILAT does not sell personal data or use assessment data for advertising. Data is disclosed only for the service, payment, security, legal, and organization-reporting activities described here.

What an inviting organization can see

The standard organization report contains aggregate results, never your individual answer, score, name, or email. Aggregate breakdowns require at least five completed assessments and apply group and complementary suppression designed to reduce re-identification risk. These controls do not by themselves prove legal anonymization.

The organization may receive activation or completion status for an invitation it issued and may separately track which employee received that invitation. AILAT does not receive the organization's employee-to-invitation mapping in the standard flow.

Service providers and other recipients

Cloudflare

Cloud hosting, application delivery, security, AI-processing infrastructure, and fallback AI processing.

Data: Service, assessment, access, and request data as required to run the service.

Google and Anthropic

AI-model providers used to score open-text answers and support learning recommendations.

Data: Your open-text answers with the related question and grading criteria, and limited assessment context for recommendations.

Resend

Delivery of access, contact-form, and service emails.

Data: Recipient email and message content, which may include assessment access, status, or result information where needed for the service.

Stripe

Checkout, payment confirmation, fraud/compliance activity, and payment-event delivery.

Data: Payment and customer information supplied at checkout, plus checkout/session and status data returned to AILAT.

Founderly personnel

Service administration, support, security, and privacy requests.

Data: Authorized personnel access only the information needed for the task.

You enter card details directly in Stripe's hosted checkout. AILAT receives transaction and payment-status information but does not receive or store full card details. Stripe processes checkout data under its own privacy information.

We may also disclose information where required by law, to protect legal rights or security, or in a corporate transaction subject to appropriate confidentiality and legal requirements.

International processing

AILAT does not promise EU-only processing. Some service providers may process personal data outside the European Economic Area. Founderly is confirming and documenting the relevant provider locations and transfer safeguards and will update this notice as those details are finalized. Contact Founderly for the current available information.

06

Current retention and browser storage

The rows below state the current periods or retention criteria. Some completed results, reports, and provider records do not yet have a fixed automatic expiry.

Incomplete assessment session
Raw session state, including answers, is scheduled for removal after 7 days without activity.
Completed assessment session
Raw session state, including answers, is scheduled for removal 90 days after completion.
Completed result record
Retained to provide result access while a fixed automatic deletion period is being finalized.
Organization report
The hosted access link normally expires after 30 days unless configured otherwise; a fixed deletion period for the stored report is being finalized.
Payment, access, and event records
Accounting records are retained for 7 years from the end of the financial year, as required by Estonian law. Non-accounting fields are kept only as long as needed and not for that period.
Contact inquiries
Kept only as long as needed to respond, manage any resulting relationship, and meet legal or claims-related needs.
Provider and operational logs
Retained per provider configuration and only as long as needed for operations and security.
Browser storage
Temporary transition and paused-state values normally end with the browser session or when AILAT clears them. The necessary enterprise participant cookie lasts up to 30 days unless cleared earlier.

Records without automatic expiry

Some completed results, reports, and provider records do not yet expire automatically. Founderly is implementing category-specific schedules and coordinated deletion. If you request erasure, we will identify the relevant records, apply any legal-retention duties, and explain what can be deleted.

Cookies, browser storage, and security

AILAT uses storage necessary to activate, resume, and protect the assessment: a participant cookie lasting up to 30 days and short-lived browser-session storage. Disabling necessary storage may stop resume or access functions from working. Stripe may separately use storage on its hosted checkout under Stripe's own notice.

AILAT does not use advertising cookies or session-replay tools. Infrastructure providers may create operational and security logs. AILAT uses proportionate technical and organizational measures designed to protect personal data, but no service can guarantee absolute security.

07

Your data-protection rights

Your rights depend on the processing activity and legal basis. They are not absolute, but we will explain if a request cannot be fulfilled.

  • Access

    Ask whether personal data is processed and request a copy.

  • Correction

    Ask us or the relevant organization to correct inaccurate data.

  • Erasure

    Request deletion where the applicable legal conditions are met.

  • Restriction

    Ask for processing to be limited in the circumstances provided by law.

  • Portability

    Receive eligible data in a structured, commonly used format where the right applies.

  • Objection

    Object to processing based on legitimate interests, including the stated security or operational interest where applicable.

  • Withdrawal

    Withdraw consent for a separate optional use if we ask for consent; the core assessment does not currently rely on consent.

  • Complaint

    Complain to the Estonian Data Protection Inspectorate or another competent EU supervisory authority.

You may request available information about how the automated result was generated or report an association or processing error. This is not a promise of routine human re-scoring.

Email mail@founderly.com. If available, include your assessment reference. An individual purchaser may instead provide the purchaser email and approximate transaction date; an organization participant may provide the organization name and invitation reference. Do not email payment-card details, access links or credentials, or your assessment answers. We may request proportionate information to verify that the request relates to you.

For an organization-sponsored assessment, contact the organization about its workforce purpose and use. When Founderly is controller, the GDPR ordinarily requires a response without undue delay and within one month, subject to a lawful extension. Where Founderly acts as processor, the organization is responsible for deciding the request and Founderly must forward it and assist as required by law and the applicable agreement.

Age eligibility

The AI-scored AILAT service is intended for users aged 18 or over and is not directed to children. If you are under 18, do not use the service. If you believe a child has submitted personal data, contact us so we can investigate and delete it where appropriate. This product rule is separate from Estonia's age threshold for consent-based online services.

08

Contact, complaints, and changes

You can contact Founderly directly, and you may also complain to a competent supervisory authority without contacting us first.

Founderly privacy contact

Founderly OÜ
Pärnu mnt. 12
10148 Tallinn, Estonia

mail@founderly.com

Supervisory authority

Andmekaitse Inspektsioon
Estonian Data Protection Inspectorate
Tatari 39, 10134 Tallinn, Estonia

Visit AKIinfo@aki.ee

You may complain to AKI or another competent EU supervisory authority, particularly in the country of your habitual residence, workplace, or the alleged infringement.

We may update this notice when the product, providers, contracts, retention controls, or law changes. We will update the date above and, where required or reasonably practicable, provide an additional prominent notice.