Privacy policy
This policy sets out which personal data the platform processes, for what purpose, who it is disclosed to, and how you can exercise your rights. It refers to the Swiss Federal Act on Data Protection (FADP) and, where applicable, to the General Data Protection Regulation of the European Union (GDPR).
Controller
The controller for the processing described here is B Lab (Switzerland), a Swiss charitable foundation.
Rue de Lyon 77, 1203 Geneva · Rue de Bourg 43, 1003 Lausanne · Hohlstrasse 418, 8048 ZurichFor any question about this policy, or to exercise your rights, write to support@leadership-compass.net.
What this policy covers
It covers the platform served on this site: opening an account, the questionnaires, the reflective journal, commitments, third-party assessments, donations, and the e-mails that accompany those uses.
Other sites run by the foundation publish their own policy; this one does not apply to them.
Categories of data processed
Depending on what you use, the platform processes the following categories:
- Account and identity: name, e-mail address, language, role and organisation, as you state them.
- Postal code, when you choose to provide it.
- Moral ambition: free text of at most 500 characters, written at the start of the journey.
- Questionnaire answers, and the leadership profile computed from them — kept so that comparison over time remains possible.
- Reflective journal: personal free-text notes, encrypted in the database.
- Commitments: what you decide to undertake, including the names of anyone you mention in them.
- Third-party assessments: the e-mail address of everyone you invite, and the answers they give on the seven dimensions of the method.
- Donations: amount, date, and what a tax receipt requires — name, e-mail address, canton.
- Technical traces: IP address and timestamp of sensitive actions, logged for security purposes.
Purposes
This data is used to:
- Open your account, authenticate you and maintain your journey.
- Run the instrument: questionnaires, results, comparison over time.
- Collect third-party assessments and return them to you in aggregated form.
- Draft your personal plan and suggest rewordings of your commitments, using a language model.
- Send you the messages the service requires: sign-in link, invitations, reminders.
- Process donations and issue tax receipts.
- Keep the platform secure, diagnose failures, and measure traffic in aggregate.
- Meet the legal obligations that apply to the foundation.
Legal bases
The FADP does not make processing conditional on a listed legal basis: it requires processing to be lawful, carried out in good faith, proportionate, and to have a purpose that is evident. Where the GDPR applies, we rely on the following bases:
- Performance of the contract for using the platform (Art. 6(1)(b) GDPR) — account, questionnaires, results.
- Your consent (Art. 6(1)(a) GDPR) — for whatever you add freely: moral ambition, reflective journal, invitations to third parties, listing on the donor wall. You may withdraw it at any time; withdrawal does not affect processing already carried out.
- Our legitimate interest (Art. 6(1)(f) GDPR) — platform security and aggregate traffic measurement.
- Compliance with legal obligations (Art. 6(1)(c) GDPR) — accounting duties in particular, for donations.
Third-party assessments
You may invite anyone of your choosing to answer about you on the seven dimensions of the method. For that we keep the e-mail address the invitation is sent to, along with the answers submitted.
Thirty days after an answer, the respondent's identity is destroyed: the e-mail address and the invitation token are erased, and the answers remain with no link to an individual. This is the only automatic erasure the platform performs today.
Answers are returned to you in aggregated form only, above a minimum number of respondents; below that threshold, nothing is shown.
Use of a language model
To draft your personal plan and suggest rewordings of your commitments, the platform calls on Anthropic, a provider established in the United States.
The only personal data disclosed to it is the free text of your commitments. Your first name is not disclosed: a placeholder is sent instead and replaced on receipt. The reflective journal, third-party answers and your e-mail address are not disclosed.
No decision producing legal effects concerning you is taken by automated means.
Recipients
We sell no data and disclose none for advertising purposes. The following providers act as processors, each for the single service entrusted to it:
- Anthropic (United States) — text generation: first name and the free text of commitments.
- Google Workspace (United States) — delivery of service e-mails: the recipient address and the message body.
- Google and Microsoft (United States) — sign-in with an external account, if you choose that route: the authentication data you entrust to them.
- Stripe — card payment for donations: the donor's e-mail address.
- Datatrans and TWINT (Switzerland) — payment by TWINT: the platform discloses no personal data to them.
- Infomaniak (Switzerland) — storage of donation receipts, which carry the name, e-mail address, amount and canton.
- Sentry and Plausible — error logging and traffic measurement, on self-hosted instances: this data does not leave the foundation's infrastructure.
Two surfaces expose data to other users. A cohort dashboard shows aggregated results only, and only above a minimum number of participants. The donor wall shows the name you give when donating, unless you ask not to be listed.
Transfers abroad
Several of the providers above are established in the United States. That country's law does not offer a level of protection recognised as equivalent to Swiss or European law.
These transfers rest on the processing agreements the foundation has concluded with each of its providers.
Retention
We would rather describe what the platform does today than announce retention periods it would not apply:
- The identity of anyone who answered an assessment is erased automatically thirty days after their answer.
- A journal entry you delete is removed from the database immediately: no bin, no grace period.
- All other data — account, answers, results, commitments, donations, technical traces — is kept for as long as your account exists. No automatic deletion is scheduled to date.
- Records relating to donations are kept for as long as accounting obligations require.
Export and deletion of your account are available self-service from your profile. Deletion erases your journal, then replaces your name, address, moral ambition, postal code, role and organisation with anonymous values; it cannot be undone. Cohort aggregates already frozen are anonymous and remain, as do tax receipts, whose retention is an accounting obligation.
Security
Traffic to and from the platform is encrypted in transit. The reflective journal is further encrypted at field level in the database, with a key specific to each client workspace, held outside that database.
Each client workspace is partitioned from the others, and sensitive actions leave a timestamped trace. No measure makes a system impregnable: tell us without delay about any suspicious access to your account.
Cookies and traffic measurement
The platform sets a session cookie, strictly necessary to keep you signed in. It serves no advertising purpose.
Traffic measurement runs on a self-hosted Plausible instance, designed to work without cookies and without individual profiles. There is no advertising tracker and no social network button.
Your rights
Within the limits set by law, you have the following rights:
- Access to your data (Art. 8 FADP; Art. 15 GDPR).
- Rectification of inaccurate data (Art. 5 FADP; Art. 16 GDPR).
- Erasure of your data (Art. 5 FADP; Art. 17 GDPR).
- Restriction of processing (Art. 12, 13 and 15 FADP; Art. 18 GDPR).
- Objection to processing (Art. 4 FADP; Art. 21 GDPR).
- Portability: obtaining your data in a commonly readable format (Art. 20 GDPR).
- Withdrawal of consent at any time, without affecting processing already carried out.
- Complaint to a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner; in the European Union, the authority where you reside (Art. 77 GDPR).
Send your request to the contact address given above. We may ask you to establish your identity before acting on it, and we answer within the time limits set by law.
Changes to this policy
This policy follows the platform as it evolves. The applicable version is the one published on this page; the date it was last updated appears at the top of the document.