Legal

Privacy.

A plain-language summary of how maturityOS handles data. The reviewed legal text supersedes this summary on launch.

Last updated: draft pre-launch.

Data we collect

Account information you provide (name, work email, company, role), respondent scores submitted into the diagnostic, and standard product telemetry (page views, feature usage, error logs). We do not collect special-category personal data.

How we use it

Solely to deliver the diagnostic, consensus review, roadmap, and scorecard outputs you've configured; to provide customer support; to improve the product; and to send service-related communications. We do not sell personal data.

Respondent confidentiality

Individual respondent scores are visible only inside aggregated views. Variance is surfaced at the attribute level, never tied back to a named respondent without explicit consent from that respondent.

Sub-processors

We rely on a small set of vetted sub-processors for hosting, analytics, email, and authentication. A current list is available on request and is reviewed annually.

Data retention

Account and diagnostic data are retained for the life of the subscription plus thirty days, after which they are permanently deleted. Customers may request earlier deletion at any time.

Your rights

You may access, correct, export, or delete your personal data by writing to privacy@maturityos.com. We respond within thirty days. EEA, UK, and California residents have additional rights under GDPR, UK GDPR, and CCPA respectively.

Security

Data is encrypted in transit and at rest. Access is least-privilege, audited, and reviewed quarterly. Incident response runs against a documented runbook with notification commitments per applicable law.

Changes

Material changes to this notice are communicated by email to account administrators at least thirty days before they take effect.

Questions? Write to privacy@maturityos.com.