Skip to main content
Trust & data handling

Collect less by default. Separate participation from individual outcomes.

AILAT’s standard enterprise flow is designed around data minimization: no participant names or emails in the assessment, participant-only result access, aggregate organization reporting, and small-group privacy controls.

This page describes current product controls and is not a certification statement. Contact Founderly for procurement or security documentation.

Enterprise access model

Separate access for each purpose

01

Invitation

Distributed by the organization to start an assessment

02

Participant access

Resume the assessment and view a personal result

03

Organization report

View aggregate results as a designated recipient

Direct identity
Not requested by default
Group reporting
5+ completion floor
Personal results
Participant-only session
Organization results
Aggregate report link
Enterprise privacy model

Concrete controls instead of broad assurances.

AILAT uses the controls below in its standard enterprise assessment and reporting service.

No participant name or email by default

The standard enterprise assessment does not ask participants for direct identifiers. The client may keep its own employee-to-link mapping for distribution follow-up.

Access separated by purpose

Invitation, participant, and organization-report access are separated so each can be limited to its intended purpose.

Aggregate reporting only

Organization reports exclude individual rows and scores. Breakdowns appear only for groups of at least 5, with additional suppression where combined results could expose a smaller group.

Expiring, revocable report links

Named recipients receive report access that can expire or be revoked. Recipients must keep access links confidential.

Data inventory

What the standard enterprise flow stores—and why.

Avoiding direct participant identifiers is not the same as collecting no personal data. AILAT processes pseudonymous assessment and programme data to deliver scores, recommendations, coverage, and aggregate reporting.

Programme settings

Data
Organization context, approved reporting categories, recipients, and rollout settings.
Purpose
Configure the participant experience and aggregate report.

Participation records

Data
Pseudonymous invitation, activation, completion, and organization or programme information.
Purpose
Operate the rollout and calculate coverage without asking standard participants for names or email addresses.

Assessment data

Data
Setup information, answers, scores, feedback, and generated results.
Purpose
Deliver the assessment, personal result, recommendations, and aggregate analysis.

Organization reports

Data
Aggregate report content and records needed to manage access.
Purpose
Provide reports to designated recipients and protect access.

Contact inquiries

Data
Contact details, inquiry content, organization or rollout context, and limited source or campaign information.
Purpose
Route and answer questions and manage any resulting relationship.
Access controls

Access is separated and limited by purpose.

Invitation, participant, organization, and report access are protected separately for their intended audiences.

  • Participant access

    A protected session supports assessment resume and personal-result access. Recovery access is single-use.

  • Organization access

    Organization requests are authenticated and restricted to the relevant organization.

  • Report-page protections

    Report pages use controls designed to reduce unintended caching, indexing, and embedding.

Important access boundaries

  • Anyone who receives an active report link may be able to open or forward it, so recipients must keep it confidential.
  • Expiry or revocation prevents later hosted access but cannot retract a copy already saved or printed.
  • An organization may track invitation distribution, but the standard flow does not verify the identity of the employee who uses an invitation.
Retention

Current retention periods and limits.

Assessment sessions expire on defined schedules. Some completed result and report records do not yet have a fixed automatic deletion date.

Incomplete assessment

Assessment session data is scheduled for removal after 7 days of inactivity.

Completed assessment

Raw assessment session data is scheduled for removal after 90 days.

Completed result

No fixed automatic expiry currently applies; erasure may be requested where the law permits.

Organization report

Report-link expiry or revocation ends hosted access but does not itself delete the stored report, which currently has no fixed automatic expiry.

Service providers

Third parties that help deliver AILAT.

These are the main providers used for hosting, AI processing, payments, and email delivery. Contact Founderly for current procurement information.

Cloudflare

Cloud hosting, application delivery, security, and AI-processing infrastructure.

Google and Anthropic

AI services that may process open-text answers and limited assessment context for scoring, recommendations, or question selection.

Stripe

Payment processing for individually purchased assessments. Standard invoiced enterprise access does not require participant checkout.

Resend

Delivery of access, contact, and service emails. Message content may include assessment access, status, or result information where needed for the service.

Open-text answers and limited assessment context may be processed by an AI provider. AILAT does not promise EU-only processing. See the Privacy Notice for data categories, international processing, retention, and your rights. Last reviewed 20 July 2026.

Questions, rights, or procurement review

Ask for the specific detail your review requires.

For data requests, deletion, security questions, or enterprise due diligence, contact Founderly OÜ through the address below.

Enterprise review

Plan your rollout with clear data and reporting expectations.

Tell us the participant count, reporting categories, recipients, and any privacy or procurement requirements that need to be addressed before launch.