Privacy Policy

Last updated: September 27, 2026

MaturityHR is a product of evaluoi.ai Oy Ltd (Business ID: 3582911-8). This Privacy Policy describes how personal data is processed in the MaturityHR service available at maturityhr.com.

1. Controller

Company: evaluoi.ai Oy Ltd
Business ID: 3582911-8
Email: hello@evaluoi.ai

2. Data We Collect

We collect the following categories of personal data when you use our Service:

Account Information

  • Email address
  • Display name
  • Password (hashed)

Assessment Data

  • Maturity assessments and signals your organization creates
  • Responses submitted by you or assessment participants
  • Development initiatives logged at measurement points

Assessment and pulse answers are collected through role-specific links. The organization's administrators see summaries by role, not individual answers. A role summary is shown only when the number of respondents in that role reaches the product's minimum threshold.

Usage Data

  • Login timestamps
  • Device and browser metadata
  • Security log entries, such as sign-in attempts, including IP address and browser metadata
  • Aggregated page view statistics collected through Vercel's cookieless web analytics (no cookies, no cross-site tracking)

Payment Information

  • Processed securely by Stripe
  • We do not store credit card numbers or full payment details

Data We Do Not Process

MaturityHR is not designed to process special category data as defined in GDPR Article 9, including health data, biometric data, genetic data, or data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation.

Assessments concern organizational processes and practices, not individual performance evaluation.

3. Legal Bases for Processing

We process personal data under the following GDPR legal bases:

  • Consent (Article 6(1)(a)): You provide explicit consent during signup and when granting specific permissions.
  • Contract Performance (Article 6(1)(b)): Processing is necessary to provide the MaturityHR Service.
  • Legitimate Interest (Article 6(1)(f)): For security, fraud prevention, and improving the reliability and performance of the Service.

4. Your Rights

Under GDPR, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Update your profile information at any time.
  • Right to Erasure: Request account and data deletion by contacting hello@evaluoi.ai. We confirm the request, carry out the deletion and complete it within 30 days of the request.
  • Right to Data Portability: Request your data in a machine-readable format; we deliver the export within 30 days of the request.
  • Right to Withdraw Consent: Withdraw consent at any time.
  • Right to Object: Object to processing based on legitimate interest.

To exercise these rights, contact: hello@evaluoi.ai

5. Security

We implement strict security standards to protect your data:

  • Encryption at rest (AES-256)
  • Encryption in transit (TLS 1.3)
  • Database Row Level Security (RLS) for tenant isolation
  • Access controls based on roles and permissions
  • Audit logging of security events; log entries containing IP addresses and device metadata are anonymized when the related account is deleted
  • Passwords hashed using industry-standard algorithms

6. Third-Party Processors

Data processing locations:

  • Primary data storage: EU (AWS eu-west-1, Ireland) via Supabase
  • Application hosting and cookieless web analytics: Vercel
  • AI features: Google Cloud Vertex AI, EU (europe-west1, Belgium)

We work with the following GDPR-compliant processors:

Supabase

  • Services: Database, authentication, storage, authentication emails
  • Location: EU (AWS eu-west-1, Ireland)
  • Compliance: GDPR, ISO-certified infrastructure

Vercel

  • Services: Application hosting, cookieless web analytics
  • Compliance: GDPR

Stripe

  • Services: Payment processing
  • Compliance: PCI DSS Level 1 certified

Sentry (Functional Software, Inc.)

  • Services: Error monitoring; error events may include IP address, browser metadata and request URLs
  • Transfers: Safeguarded by EU Standard Contractual Clauses under Sentry's Data Processing Addendum
  • Compliance: GDPR

Resend

  • Services: Transactional email delivery (member invitations); processes recipient email addresses and message content
  • Transfers: Safeguarded by EU Standard Contractual Clauses under Resend's Data Processing Agreement
  • Compliance: GDPR

Google Cloud (Vertex AI)

  • Services: AI-assisted features, i.e. generating the organizational values reflection and the mapping of named values to framework sub-areas (organization name, named values and their descriptions, aggregated maturity scores, framework area and sub-area labels), suggesting and translating pulse survey questions (sub-area names, the selected initiative's name and description, the question texts), and the in-app help assistant (the user's question, recent conversation turns, plan and role). No stored individual respondent answers are sent; text that users type into these features is sent as written
  • Location: EU (Vertex AI, europe-west1, Belgium)
  • Vertex AI data caching is disabled for the service's project
  • Customer data is not used to train models (Google Cloud Vertex AI terms); processing safeguarded by the Google Cloud Data Processing Addendum
  • Compliance: GDPR

All processors operate under Data Processing Agreements (DPAs) compliant with GDPR Article 28.

We do not sell, rent, or trade your personal data to third parties, and we do not use it for marketing or advertising. The processors listed above act only on our instructions to provide the Service.

7. Data Retention

  • Active accounts: Retained until deletion
  • Deleted accounts: Deletion is completed within 30 days of a verified deletion request
  • Audit logs: Retained while the customer relationship is active; entries containing IP addresses and device metadata are anonymized upon account deletion
  • Anonymous security log entries (entries with no linked account, such as failed sign-in attempts): retained for a maximum of 90 days and then deleted automatically by a daily purge. These entries contain an IP address and browser metadata; they do not contain email addresses
  • Backups: Encrypted daily backups with a rolling retention window; expired backups are purged automatically

8. Cookies and Local Storage

We use only strictly necessary and functional first-party storage:

  • Authentication session (stored in localStorage)
  • Language preference (localStorage and a functional first-party cookie)
  • Interface state, such as the sidebar position (first-party cookie)

We do not use advertising, tracking, or analytics cookies. Our web analytics (Vercel Analytics) is cookieless. For details, see our Cookie Policy.

9. Contact