No participant name or email by default
The standard enterprise assessment does not ask participants for direct identifiers. The client may keep its own employee-to-link mapping for distribution follow-up.
AILAT’s standard enterprise flow is designed around data minimization: no participant names or emails in the assessment, participant-only result access, aggregate organization reporting, and small-group privacy controls.
This page describes current product controls and is not a certification statement. Contact Founderly for procurement or security documentation.
Enterprise access model
Separate access for each purpose
Invitation
Distributed by the organization to start an assessment
Participant access
Resume the assessment and view a personal result
Organization report
View aggregate results as a designated recipient
AILAT uses the controls below in its standard enterprise assessment and reporting service.
The standard enterprise assessment does not ask participants for direct identifiers. The client may keep its own employee-to-link mapping for distribution follow-up.
Invitation, participant, and organization-report access are separated so each can be limited to its intended purpose.
Organization reports exclude individual rows and scores. Breakdowns appear only for groups of at least 5, with additional suppression where combined results could expose a smaller group.
Named recipients receive report access that can expire or be revoked. Recipients must keep access links confidential.
Avoiding direct participant identifiers is not the same as collecting no personal data. AILAT processes pseudonymous assessment and programme data to deliver scores, recommendations, coverage, and aggregate reporting.
Invitation, participant, organization, and report access are protected separately for their intended audiences.
A protected session supports assessment resume and personal-result access. Recovery access is single-use.
Organization requests are authenticated and restricted to the relevant organization.
Report pages use controls designed to reduce unintended caching, indexing, and embedding.
Assessment sessions expire on defined schedules. Some completed result and report records do not yet have a fixed automatic deletion date.
Incomplete assessment
Assessment session data is scheduled for removal after 7 days of inactivity.
Completed assessment
Raw assessment session data is scheduled for removal after 90 days.
Completed result
No fixed automatic expiry currently applies; erasure may be requested where the law permits.
Organization report
Report-link expiry or revocation ends hosted access but does not itself delete the stored report, which currently has no fixed automatic expiry.
These are the main providers used for hosting, AI processing, payments, and email delivery. Contact Founderly for current procurement information.
Cloud hosting, application delivery, security, and AI-processing infrastructure.
AI services that may process open-text answers and limited assessment context for scoring, recommendations, or question selection.
Payment processing for individually purchased assessments. Standard invoiced enterprise access does not require participant checkout.
Delivery of access, contact, and service emails. Message content may include assessment access, status, or result information where needed for the service.
Open-text answers and limited assessment context may be processed by an AI provider. AILAT does not promise EU-only processing. See the Privacy Notice for data categories, international processing, retention, and your rights. Last reviewed 20 July 2026.
Questions, rights, or procurement review
For data requests, deletion, security questions, or enterprise due diligence, contact Founderly OÜ through the address below.
Tell us the participant count, reporting categories, recipients, and any privacy or procurement requirements that need to be addressed before launch.