Legal
Privacy.
A plain-language summary of how maturityOS handles data. The reviewed legal text supersedes this summary on launch.
Last updated: draft pre-launch.
Data we collect
Account information you provide (name, work email, company, role), respondent scores submitted into the diagnostic, and standard product telemetry (page views, feature usage, error logs). We do not collect special-category personal data.
How we use it
Solely to deliver the diagnostic, consensus review, roadmap, and scorecard outputs you've configured; to provide customer support; to improve the product; and to send service-related communications. We do not sell personal data.
Respondent confidentiality
Individual respondent scores are visible only inside aggregated views. Variance is surfaced at the attribute level, never tied back to a named respondent without explicit consent from that respondent.
Sub-processors
We rely on a small set of vetted sub-processors for hosting, analytics, email, and authentication. A current list is available on request and is reviewed annually.
Data retention
Account and diagnostic data are retained for the life of the subscription plus thirty days, after which they are permanently deleted. Customers may request earlier deletion at any time.
Your rights
You may access, correct, export, or delete your personal data by writing to privacy@maturityos.com. We respond within thirty days. EEA, UK, and California residents have additional rights under GDPR, UK GDPR, and CCPA respectively.
Security
Data is encrypted in transit and at rest. Access is least-privilege, audited, and reviewed quarterly. Incident response runs against a documented runbook with notification commitments per applicable law.
Changes
Material changes to this notice are communicated by email to account administrators at least thirty days before they take effect.
Questions? Write to privacy@maturityos.com.