Your assessment data, explained plainly.
This notice explains what AILAT processes, how AI-assisted scoring works, what an inviting organization can see, how long current records remain, and how to exercise your rights.
Version 2.0 · Last updated
On this page
The short version
- Responsible parties
- Founderly is responsible for direct assessments and its own billing, security, and compliance uses. An inviting organization normally determines its workforce-assessment purpose.
- Automated evaluation
- Open-text answers are scored automatically, and limited assessment context can be used for learning recommendations and adaptive question selection.
- Organization reporting
- The standard organization report contains aggregate results, not individual answers or scores, and uses small-group suppression controls.
- Retention
- Raw sessions expire on schedule; some completed results and reports do not yet have a fixed automatic deletion date.
Who is responsible, and when this notice applies
The responsible party depends on whether you take AILAT directly or through an organization.
This notice applies when you visit AILAT, purchase or take an assessment, activate an organization invitation, receive or access an organization report, contact us, or exercise a privacy right.
If you purchase or take AILAT independently, Founderly OÜ determines why and how the assessment service processes your personal data and acts as controller.
If an organization invites you, that organization normally decides why the assessment is offered and how it uses programme reporting. Founderly handles the data needed to provide AILAT under the applicable customer arrangement and follows the organization's instructions where it acts as processor. The organization's participant notice also applies. Founderly acts separately as controller only for purposes it determines itself, such as direct billing, legal compliance, security, or fraud prevention.
Founderly OÜ
Estonian Commercial Register code 14704762Pärnu mnt. 12, 10148 Tallinn, Estonia
mail@founderly.com
What personal data we process
AILAT avoids asking standard enterprise participants for names or email addresses, but pseudonymous assessment and programme records remain personal data.
Assessment setup
Industry, professional role, motivation, and, for an organization-sponsored assessment, the role or department category selected from the organization’s configured list.
Source: You, or your organization for organization and programme context.
Responses and activity
Multiple-choice and open-text answers, response time, answer timestamps, completion state, and assessment duration.
Source: You and the assessment service while you participate.
Scores and recommendations
Correctness, automated open-answer score and feedback, proficiency estimates, overall and dimension scores, literacy level, strengths, growth areas, and learning recommendations.
Source: Generated from your responses and assessment context.
Identifiers and access records
Pseudonymous assessment and participation identifiers, organization or programme references, access status, completion status, and security records needed to protect access.
Source: Generated by AILAT; organization or programme context may come from the customer.
Payments and recovery
Transaction and payment-status information, purchaser email, and records needed to provide or recover paid assessment access.
Source: You, Stripe, and AILAT when it records the transaction and provides access information.
Organization administration
Organization and programme settings, approved reporting categories, report-recipient contact details, participation status, and report-access records.
Source: The organizational customer and AILAT.
Contact inquiries
Name, email address, inquiry details, organization or rollout context where relevant, and limited source or campaign information supplied with the inquiry.
Source: You when you use the contact form or email Founderly directly.
Communications
Support messages, privacy requests, and the limited contact or verification information needed to answer them.
Source: You, an organizational customer, or another person contacting Founderly.
Technical and security data
IP address and limited operational or security metadata needed to protect and run the service.
Source: Your device, network, AILAT, and its infrastructure providers.
AILAT is not designed to collect special-category data. Please do not put names, health or disability information, racial or ethnic origin, political or religious views, trade-union information, sex-life or sexual-orientation information, confidential business information, or unrelated information about another person in an open-text answer.
Why we process it and the legal basis
We do not rely on consent for the core assessment. The applicable basis follows the purpose and Founderly’s role in that activity.
Provide a directly purchased assessment, adapt delivery, produce results and recommendations, and support paid-access recovery.
- Role
- Founderly as controller.
- Legal basis
- Performance of the service contract — GDPR Article 6(1)(b).
Provide an organization-sponsored assessment and aggregate programme reporting.
- Role
- The organization normally acts as controller for its workforce purpose. Founderly acts as processor where it handles data under the organization’s instructions and as controller for separate purposes it determines itself.
- Legal basis
- The organization must identify and explain its lawful basis. Founderly follows documented instructions where it acts as processor and identifies a separate basis for purposes it determines itself.
Manage enterprise accounts, coordinator access, transactional service notices, contract acceptance, and delivery evidence.
- Role
- Founderly as controller for business-account administration and its contract, security, compliance, and claims records.
- Legal basis
- Legitimate interests in administering and securing the enterprise service — Article 6(1)(f); and legal obligation where applicable — Article 6(1)(c).
Protect assessment access, prevent abuse and fraud, troubleshoot failures, monitor service operation, and maintain reliability.
- Role
- Founderly as controller for independently determined security purposes, or as processor where the activity forms part of the instructed service.
- Legal basis
- Legitimate interests in a secure and reliable service — Article 6(1)(f), where Founderly is controller.
Process payments, maintain transaction evidence, handle disputes, and meet accounting or other legal duties.
- Role
- Founderly is controller for its payment, access, accounting, and dispute records. Stripe describes its own checkout processing in its privacy notice.
- Legal basis
- Contract — Article 6(1)(b); legal obligation — Article 6(1)(c); and legitimate interests for fraud or claims where applicable.
Answer enterprise, API, research, procurement, privacy, and general inquiries and manage necessary follow-up.
- Role
- Founderly as controller.
- Legal basis
- Steps requested before entering a contract — Article 6(1)(b); legitimate interests in responding and operating the service — Article 6(1)(f); or legal obligation for rights requests — Article 6(1)(c), as applicable.
Answer privacy requests, cooperate with regulators, and establish, exercise, or defend legal claims.
- Role
- Founderly as controller for its obligations and claims; Founderly also assists organizational controllers.
- Legal basis
- Legal obligation — Article 6(1)(c); legitimate interests in legal claims — Article 6(1)(f), where applicable.
| Purpose | Role | Legal basis |
|---|---|---|
| Provide a directly purchased assessment, adapt delivery, produce results and recommendations, and support paid-access recovery. | Founderly as controller. | Performance of the service contract — GDPR Article 6(1)(b). |
| Provide an organization-sponsored assessment and aggregate programme reporting. | The organization normally acts as controller for its workforce purpose. Founderly acts as processor where it handles data under the organization’s instructions and as controller for separate purposes it determines itself. | The organization must identify and explain its lawful basis. Founderly follows documented instructions where it acts as processor and identifies a separate basis for purposes it determines itself. |
| Manage enterprise accounts, coordinator access, transactional service notices, contract acceptance, and delivery evidence. | Founderly as controller for business-account administration and its contract, security, compliance, and claims records. | Legitimate interests in administering and securing the enterprise service — Article 6(1)(f); and legal obligation where applicable — Article 6(1)(c). |
| Protect assessment access, prevent abuse and fraud, troubleshoot failures, monitor service operation, and maintain reliability. | Founderly as controller for independently determined security purposes, or as processor where the activity forms part of the instructed service. | Legitimate interests in a secure and reliable service — Article 6(1)(f), where Founderly is controller. |
| Process payments, maintain transaction evidence, handle disputes, and meet accounting or other legal duties. | Founderly is controller for its payment, access, accounting, and dispute records. Stripe describes its own checkout processing in its privacy notice. | Contract — Article 6(1)(b); legal obligation — Article 6(1)(c); and legitimate interests for fraud or claims where applicable. |
| Answer enterprise, API, research, procurement, privacy, and general inquiries and manage necessary follow-up. | Founderly as controller. | Steps requested before entering a contract — Article 6(1)(b); legitimate interests in responding and operating the service — Article 6(1)(f); or legal obligation for rights requests — Article 6(1)(c), as applicable. |
| Answer privacy requests, cooperate with regulators, and establish, exercise, or defend legal claims. | Founderly as controller for its obligations and claims; Founderly also assists organizational controllers. | Legal obligation — Article 6(1)(c); legitimate interests in legal claims — Article 6(1)(f), where applicable. |
Required information: Industry, role, motivation, answers, and any department required by the assessment configuration are needed to complete the assessment and generate a result. Direct purchasers must provide Stripe with the information needed for checkout and an email used for access or recovery. Without required information, AILAT cannot provide the relevant assessment, result, or paid access. Support and privacy-request contact information is otherwise optional, although enough information may be needed to locate and verify the relevant data.
AI-assisted scoring and profiling
AILAT automatically adapts the assessment, evaluates open-text responses, and may use limited assessment context for learning recommendations or question selection.
Open-answer scoring: AILAT sends the relevant question, your complete answer, and the grading criteria through Cloudflare to one or more AI providers (Google, Anthropic, or Cloudflare) to produce a score and feedback.
Learning recommendations: AILAT may use your industry, role, literacy level, and weakest assessment dimensions to generate a personalized learning path.
Adaptive question selection: Earlier answers and estimated proficiency can influence the next question. Limited assessment context may be used to select or generate that question; this context does not include your open-text answer.
Automated scores affect proficiency, dimension scores, your result, and learning path. A human does not routinely review every answer. This automated evaluation is profiling because it evaluates knowledge or performance.
Founderly does not use this profiling to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. AILAT is not intended for individual hiring, promotion, pay, discipline, termination, credit, eligibility, or similar decisions, and the standard organization report does not expose your individual answer or score. An organization planning a consequential use must separately assess its lawfulness, implement required safeguards, and tell affected people.
Founderly does not use assessment answers to train its own models. Third-party handling of prompts depends on the provider terms and settings applicable to AILAT; current providers are listed on the Trust and data-handling page.
Current retention and browser storage
The rows below state the current periods or retention criteria. Some completed results, reports, and provider records do not yet have a fixed automatic expiry.
- Incomplete assessment session
- Raw session state, including answers, is scheduled for removal after 7 days without activity.
- Completed assessment session
- Raw session state, including answers, is scheduled for removal 90 days after completion.
- Completed result record
- Retained to provide result access while a fixed automatic deletion period is being finalized.
- Organization report
- The hosted access link normally expires after 30 days unless configured otherwise; a fixed deletion period for the stored report is being finalized.
- Payment, access, and event records
- Accounting records are retained for 7 years from the end of the financial year, as required by Estonian law. Non-accounting fields are kept only as long as needed and not for that period.
- Contact inquiries
- Kept only as long as needed to respond, manage any resulting relationship, and meet legal or claims-related needs.
- Provider and operational logs
- Retained per provider configuration and only as long as needed for operations and security.
- Browser storage
- Temporary transition and paused-state values normally end with the browser session or when AILAT clears them. The necessary enterprise participant cookie lasts up to 30 days unless cleared earlier.
Records without automatic expiry
Some completed results, reports, and provider records do not yet expire automatically. Founderly is implementing category-specific schedules and coordinated deletion. If you request erasure, we will identify the relevant records, apply any legal-retention duties, and explain what can be deleted.
Cookies, browser storage, and security
AILAT uses storage necessary to activate, resume, and protect the assessment: a participant cookie lasting up to 30 days and short-lived browser-session storage. Disabling necessary storage may stop resume or access functions from working. Stripe may separately use storage on its hosted checkout under Stripe's own notice.
AILAT does not use advertising cookies or session-replay tools. Infrastructure providers may create operational and security logs. AILAT uses proportionate technical and organizational measures designed to protect personal data, but no service can guarantee absolute security.
Your data-protection rights
Your rights depend on the processing activity and legal basis. They are not absolute, but we will explain if a request cannot be fulfilled.
Access
Ask whether personal data is processed and request a copy.
Correction
Ask us or the relevant organization to correct inaccurate data.
Erasure
Request deletion where the applicable legal conditions are met.
Restriction
Ask for processing to be limited in the circumstances provided by law.
Portability
Receive eligible data in a structured, commonly used format where the right applies.
Objection
Object to processing based on legitimate interests, including the stated security or operational interest where applicable.
Withdrawal
Withdraw consent for a separate optional use if we ask for consent; the core assessment does not currently rely on consent.
Complaint
Complain to the Estonian Data Protection Inspectorate or another competent EU supervisory authority.
You may request available information about how the automated result was generated or report an association or processing error. This is not a promise of routine human re-scoring.
Email mail@founderly.com. If available, include your assessment reference. An individual purchaser may instead provide the purchaser email and approximate transaction date; an organization participant may provide the organization name and invitation reference. Do not email payment-card details, access links or credentials, or your assessment answers. We may request proportionate information to verify that the request relates to you.
For an organization-sponsored assessment, contact the organization about its workforce purpose and use. When Founderly is controller, the GDPR ordinarily requires a response without undue delay and within one month, subject to a lawful extension. Where Founderly acts as processor, the organization is responsible for deciding the request and Founderly must forward it and assist as required by law and the applicable agreement.
Age eligibility
The AI-scored AILAT service is intended for users aged 18 or over and is not directed to children. If you are under 18, do not use the service. If you believe a child has submitted personal data, contact us so we can investigate and delete it where appropriate. This product rule is separate from Estonia's age threshold for consent-based online services.
Contact, complaints, and changes
You can contact Founderly directly, and you may also complain to a competent supervisory authority without contacting us first.
Supervisory authority
Andmekaitse Inspektsioon
Estonian Data Protection Inspectorate
Tatari 39, 10134 Tallinn, Estonia
You may complain to AKI or another competent EU supervisory authority, particularly in the country of your habitual residence, workplace, or the alleged infringement.
We may update this notice when the product, providers, contracts, retention controls, or law changes. We will update the date above and, where required or reasonably practicable, provide an additional prominent notice.