Information Security Policy
This is a draft prepared for review by qualified counsel and should be reviewed before publication.
Our Commitment
[LEGAL ENTITY NAME] (“we”, “us”, or “our”) is committed to respecting your privacy and protecting the personal information you share with us through Illumetis — The Leadership Blind Spot Diagnostic. This policy describes the safeguards we apply to keep that information secure and to protect it against loss, misuse, and unauthorised access, disclosure, or alteration.
Scope & Data We Handle
This policy applies to the personal information we collect when you use the Illumetis diagnostic. That information is limited to:
- your first name and last name;
- your email address;
- your approximate location (city, region, and country), derived from your IP address using a third-party IP-geolocation service; and
- your diagnostic responses, including your multiple-choice answers and any text you choose to enter in the optional free-text field describing the decision in front of you.
We do not collect, process, or store payment-card or cardholder data, financial-account details, or any special-category or health data. Please avoid entering any sensitive personal information into the optional free-text field, as it is not required and is not intended for such content.
Data Protection Safeguards
We apply technical and organisational measures appropriate to the nature of the information we hold, including:
- Encryption in transit: information submitted through the diagnostic is transmitted over encrypted connections using current TLS standards.
- Access control and least privilege: access to personal information is restricted to authorised personnel who need it to perform their role, on a least-privilege basis.
- Unique credentials and strong authentication: administrative users are assigned unique credentials and are required to use strong passwords (a minimum length with a mix of character types, kept confidential and changed periodically). Multi-factor authentication is required for administrative access.
- Secure hosting: where personal information is stored on a backend service, we use reputable hosting providers that maintain appropriate physical and environmental security controls.
Data Minimisation & Retention
We collect only the information needed to deliver your diagnostic result and to send the correspondence you have agreed to receive. We do not sell your personal information, and we do not send unsolicited marketing (“spam”). We retain your information only for as long as necessary for the purposes for which it was collected, or as required to meet legal, accounting, or regulatory obligations, after which it is securely deleted.
Secure Disposal
When personal information is no longer required, we dispose of it securely. Electronic records are deleted using methods designed to render the data unrecoverable, and any physical records are destroyed beyond reconstruction. We periodically review our holdings to confirm that information past its retention period has been disposed of.
Third-Party Processors
We use a limited number of trusted third-party service providers to operate the diagnostic, including an IP-geolocation provider (to derive approximate location) and email and hosting providers (to store leads and deliver correspondence). These providers are permitted to process personal information only on our instructions and are bound by confidentiality obligations and, where applicable, a data-processing agreement requiring them to maintain appropriate security measures.
Incident Response & Breach Notification
We maintain procedures to identify, manage, and respond to information-security incidents. Suspected incidents must be reported internally without delay to our designated privacy/security contact, who is responsible for assessing the incident, containing it, and documenting the response. Where a personal-data breach is likely to result in a risk to affected individuals, we will notify the affected users and the relevant supervisory authority within the timeframes required by applicable law.
Personnel & Training
Personnel and contractors with access to personal information are subject to confidentiality obligations and are made aware of their responsibilities under this policy. We require periodic acknowledgement of our information-security and privacy policies and provide guidance appropriate to each role.
Your Rights & Contact
Subject to applicable law, you may request access to the personal information we hold about you, ask us to correct or update it, or request its deletion. You may also unsubscribe from correspondence at any time. To exercise these rights, or if you have any questions about this policy or our handling of your information, please contact:
- Privacy contact: [DPO / PRIVACY CONTACT]
- Email: [CONTACT EMAIL]
- Postal address: [REGISTERED ADDRESS]
This policy is governed by [GOVERNING LAW / JURISDICTION] and should be read together with our Privacy Policy and Legal Disclaimer.
Effective date: [EFFECTIVE DATE] · © [YEAR] [LEGAL ENTITY NAME]. All rights reserved.
