Skip to content
Privacy commitments
How we hold it

You are handing us the most sensitive data in the company. We treat it that way.

Leadership assessment means personal, attributable data about named people. The standard we hold ourselves to is the one your own procurement team would set.

Data enters
01 · Residency

Your data stays in the EU.

Assessment responses and reports are stored and processed within the European Union.

02 · Encryption

Encrypted, end to end.

Data is encrypted in transit and at rest using industry-standard protocols.

03 · Access

Access is limited to named experts.

Only the named Atlas experts authoring your report can see raw responses. Access is role-based and logged.

04 · Retention

Kept only as long as needed.

We retain data for the life of the engagement and delete it on request.

Deleted on request
How data moves
A · Data in

Assessment responses, stored in the EU, encrypted

B · Governed access

Named experts only, role-based and logged

C · Human review

A named expert reviews and signs each report

D · Audit trail

Question, evidence, review and decision on record

The frame around it
05 · Legal basis

GDPR, by design.

Processing rests on a clear legal basis under the GDPR, governed by a signed data processing agreement.

06 · Sub-processors

Every sub-processor is named.

We work with a short list of sub-processors and share the full list on request.

07 · AI Act

Built towards the high-risk standard.

Leadership assessment is high-risk AI under Annex III of the EU AI Act. We do not argue our way out of that. We are building towards the standard it sets: documented processes, stated model limitations, and a human who can override every output. The remaining documentation is listed further down this page, under what we are building next.

08 · Human oversight

A human can always override the machine.

Article 14 of the AI Act requires a person with the authority to disregard or reverse the system's output. That is how Atlas was built, not a concession we made later. AI analyses, a named consultant authors and signs, and the decision stays yours.

09 · Isolation

Your data does not train our models.

Client data is never used to train models, and never shared across organisations. Evidence from one engagement is used for that engagement only.

10 · Auditability

Every conclusion has a paper trail.

We document the AI-assisted process, its limitations, and the human review behind each report, in line with the AI Act's transparency obligations. The documentation is available to enterprise clients and regulators on request.

Who sees what

Access is decided before analysis begins.

Before any analysis starts, we agree which sources may be used for which question, and who may see each one. Each source answers a different question, and none is treated as the whole truth.

11 · Separation

Separated by default.

Each customer's data is held apart, behind access control and tenant isolation. Zero leakage is the standard we hold ourselves to and test against.

12 · Permitted evidence

Permission is checked before evidence is used.

Atlas reads three kinds of evidence: assessment and survey responses, organisational context, and approved work evidence. A report draws only on evidence Atlas is permitted to use for that question, and the access rights are part of the record.

13 · Consent

Consent is never presumed freely given.

In an employment relationship, consent is not assumed to be freely given. Controller and processor roles follow what actually happens to the data, and the agreement has to reflect that.

14 · Participants

Participants are told, plainly.

Before anyone completes an assessment, they are told why Atlas is involved, what they will do, who can see what, where human review happens and what Atlas does not decide.

Where people stay in charge

Experts verify. Leaders decide.

AI helps Atlas read evidence at scale. It does not make decisions about people, and it does not publish unreviewed conclusions.

15 · Expert review

A named expert stands behind each report.

Material judgement stays with Atlas experts. Analysis is reviewed against its evidence before a client sees it, and the reviewer signs it by name.

16 · The decision

The decision remains with your leaders.

Atlas states what may help or hinder execution, with confidence and uncertainty. Your leaders take the decision, and the record shows what was decided and why.

17 · Disagreement

Review is part of the record.

The audit trail records the human review and the final client decision alongside the claim itself. A reviewer overriding the system is a legitimate outcome, and it is recorded.

From claim to evidence

Every material claim can be traced.

Atlas keeps an audit record for each report, so a recommendation can be explained, reproduced and challenged. We also say plainly which assurance exists today and which is still being built.

18 · The trail

What the record holds.

The record holds the question asked and the decision it served. It names the evidence each claim rests on, and the versions of assessment, survey and model that produced it. It states the confidence, the counter-evidence and the known gaps. It shows who reviewed the analysis, and what the client decided. That is what lets a recommendation be explained, reproduced and challenged.

19 · Independent review

Independently reviewed, honestly stated.

An independent security review covering both source code and the live platform closed in May 2026 with zero open findings. That is a point-in-time result, not a permanent guarantee, and it is not an ISO 27001 or SOC 2 certification.

20 · Being built

What we are building next.

Automatic logs for important system events. A DPIA and EU AI Act technical documentation for applicable use cases. Fairness, accuracy and access tests by system version. Incident, change and outcome evidence in one audit pack. We name these as in progress, not as things we already have.

The lines we hold

What Atlas does not do with your data.

A security reviewer needs the negative claims as much as the positive ones. These are the lines that do not move.

21 · No ranking

No ranking of people.

A leader is never reduced to a score, a type or a league-table position. Atlas assesses people in context; it does not rank them against each other.

22 · No pooling

No pooling across customers without an agreement.

Customer data stays separated by default. An aggregated benchmark is only ever built with a defined purpose, the necessary rights, a lawful basis, minimal data and aggregation that exposes no individual and no customer.

23 · No automation

No automated decisions about people.

No Atlas output decides anything about a person on its own. A human reviews the analysis, and your leaders take the decision.

24 · No overclaiming

No claims we cannot back.

No accuracy percentages before the recorded forecasts exist to support them. No certification claims we do not hold. No compliance claims before the assessment that would justify them. When we cannot show it, we do not say it.