1. Introduction
This Privacy Policy explains how Transformics, operated by Innovato Consultancy ("Transformics", "we", "us", or "our"), collects, uses, stores, and protects your personal data when you use our AI Transformation Operating Cockpit platform (the "Service"). The Service is a software-as-a-service (SaaS) platform that helps organizations assess their AI maturity, workforce readiness, and innovation climate through AI-powered diagnostics, survey distribution, cross-module intelligence, and automated reporting.
We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws. This policy applies to all users of our Service, including account holders, stakeholders invited to participate in interviews, and visitors to our website.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the Service.
2. Data Controller
The data controller responsible for your personal data is:
- •Transformics (operated by Innovato Consultancy)
- •Netherlands
- •Email: privacy@transformics.ai
If you have any questions about how we process your personal data, or if you wish to exercise your data protection rights, please contact us using the details above.
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
- •Email address (provided via Google OAuth, Microsoft OAuth, or magic link sign-in)
- •Display name (if provided by your OAuth provider)
- •Authentication provider identifier
3.2 Assessment Data
When you create and run an assessment, we collect:
- •Company name, sector, employee count, and geographic location
- •AI team information (whether an AI team exists, team size, decision-maker role)
- •Business unit descriptions
- •Stakeholder interview transcripts (conversations with our AI interviewer)
- •Documents you upload for analysis (processed for evidence extraction, then kept, encrypted, until you delete them or your organization is deleted)
- •Assessment scores, dimension analyses, and generated reports
3.3 Payment Data
Payment processing is handled entirely by Stripe, Inc. We do not collect, store, or have access to your credit card numbers, bank account details, or other payment instrument data. Stripe processes your payment data in accordance with its own privacy policy. We receive only a confirmation of payment status, subscription tier, and billing period from Stripe.
3.4 Technical Data
When you access our Service, we may automatically collect:
- •IP address
- •Browser type and version
- •Device type and operating system
- •Pages visited and time spent on the Service
- •Referral source
This data is collected through server logs and, where you have given consent, through analytics cookies. See our Cookie Policy for more details.
4. Legal Basis for Processing
Under Article 6(1) of the GDPR, we process your personal data on the following legal bases:
4.1 Performance of a Contract (Art. 6(1)(b))
We process your account data and assessment data as necessary to deliver the Service you have subscribed to. This includes creating your account, running AI-powered maturity assessments, generating reports, conducting stakeholder interviews, and managing your subscription.
4.2 Legitimate Interests (Art. 6(1)(f))
We process certain data based on our legitimate business interests, provided these interests are not overridden by your rights. This includes:
- •Improving and developing the Service (e.g., refining our scoring methodology)
- •Ensuring security and preventing fraud
- •Sending transactional emails related to your account and assessments
- •Company data enrichment via third-party services to improve assessment accuracy
4.3 Consent (Art. 6(1)(a))
Where required, we obtain your explicit consent before processing. This applies to:
- •Setting optional cookies (analytics, marketing, preferences)
- •Sending marketing communications (if applicable in the future)
You may withdraw your consent at any time by adjusting your cookie preferences or contacting us directly. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
4.4 Legal Obligation (Art. 6(1)(c))
We may process and retain certain data to comply with legal obligations, such as tax and financial record-keeping requirements under Dutch and EU law.
5. How We Use Your Data
We use your personal data to:
- •Create and manage your account
- •Deliver AI maturity assessments, including AI-powered scoring and analysis
- •Send document text and free-text survey answers to an AI model to extract evidence and themes, after replacing the names the platform knows about, your own sensitive terms and detected contact details with placeholders (this is pseudonymization, not anonymization)
- •Conduct stakeholder interviews using our AI interview agent
- •Generate board-ready executive reports
- •Enrich company profiles with publicly available business data to improve assessment accuracy
- •Process subscription payments through Stripe
- •Send transactional emails (welcome messages, subscription confirmations, report delivery, quota warnings, and stakeholder interview invitations)
- •Provide customer support
- •Improve and develop the Service
- •Comply with legal obligations
6. Third-Party Processors
We use the following third-party service providers to operate the Service. Each processor has been selected for its security practices and processes data only as instructed by us.
| Processor | Service | Location | Purpose |
|---|---|---|---|
| Supabase | Authentication & Database | European Union (Frankfurt, Germany; AWS eu-central-1) | User authentication, session management, and data storage |
| Stripe | Payment Processing | United States | Subscription billing and payment processing |
| Anthropic (Claude models) | AI model provider | Not called directly: the models are served through AWS Bedrock (see below) | Provider of the Claude models used for assessment analysis, scoring, interviews, and report generation |
| Resend | Email Delivery | United States | Transactional email delivery (welcome, reports, notifications) |
| Apollo.io | Data Enrichment | United States | Company profile enrichment with publicly available business data |
| Typeform | Surveys | European Union | Optional survey-import integration (organization-level survey content only; respondent personal data is not transmitted) |
| Vercel | Hosting | Hosting region not yet published | Frontend application hosting and delivery |
| AWS Bedrock | AI Inference | European Union (AWS EU Regions; requests from eu-west-1, Ireland) | LLM inference for all Customers (Anthropic Claude models through EU inference profiles) |
The authoritative, always-current list is published at /legal/subprocessors. We provide 30 days' notice before adding or replacing any sub-processor.
7. International Data Transfers
As indicated above, several of our processors are based in the United States. When your personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through:
- •Standard Contractual Clauses (SCCs) approved by the European Commission
- •The EU-U.S. Data Privacy Framework, where the processor is certified
- •Additional technical and organizational measures as appropriate
You may request a copy of the applicable transfer safeguards by contacting us at the address provided in Section 13.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period |
|---|---|
| Account data | Until you request deletion or 2 years after last login |
| Assessment data & reports | Duration of your subscription plus 2 years |
| Uploaded documents | Kept, encrypted with your organization's key, so the evidence stays traceable, until you delete the document or your organization is deleted |
| Free trial workspaces that never become a subscription | Deleted 90 days after the trial ends |
| Stakeholder interview transcripts | Duration of your subscription plus 2 years |
| Payment records | 7 years (Dutch tax law requirement) |
| Server logs (technical data) | 90 days |
When data is no longer needed, it is securely deleted or anonymized.
7a. Where Data Is Stored and Processed
The production database (Supabase/Postgres), which holds account and assessment data, is hosted in eu-central-1 (Frankfurt, Germany) for every Customer. LLM inference uses Anthropic Claude through Amazon Bedrock EU inference routing (requests from eu-west-1, Ireland, routed only to AWS Regions in EU member states) for every Customer. Neither requires an election.
These two facts do not cover every service. The hosting region of the application tier has not been published yet, and several processors listed in Section 6 are located outside the EU. A per-account residency election cannot currently move data to a different region. For requirements beyond this setup, contact your account manager or privacy@transformics.ai for a customer-specific assessment.
7b. Aggregation & k-Anonymity
When we produce cross-customer benchmarks (sector medians, percentiles, distributions) from anonymized aggregate data, we contractually commit to the following safeguards, enforced in code:
- k-anonymity threshold: benchmark outputs are surfaced only when at least 10 distinct contributing Customer organizations are represented in the underlying cohort.
- Stricter threshold for percentile rankings: at least 20 contributing Customers to prevent outlier re-identification.
- Exclude-from-aggregates: Customers who opt out (or Financial Entities who do not opt in) have their data excluded from all current and future benchmark computations.
- No model training: we do not use Customer Data, aggregated or otherwise, to train, tune, or modify general-purpose AI models.
- Trade-secret carve-out: free-text responses, bespoke tailored-survey variants, and qualitative feedback are never included in cross-customer aggregates.
The full commitment is in Exhibit A of the Master Service Agreement and Annex B of the Data Processing Agreement.
7c. DORA (Financial Entities)
Customers that are Financial Entities within the meaning of Regulation (EU) 2022/2554 (DORA) receive a DORA Financial-Sector Rider implementing the Article 30 mandatory contractual provisions, including ICT-incident reporting timelines (4-hour classification, 24-hour initial notification), a 6-month exit-assistance window with certified deletion, competent-authority access rights, and aggregation-off-by-default. See the DPA page to request the rider.
9. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- •Right of access (Art. 15), You may request a copy of the personal data we hold about you.
- •Right to rectification (Art. 16), You may request correction of inaccurate or incomplete personal data.
- •Right to erasure (Art. 17), You may request deletion of your personal data, subject to legal retention obligations.
- •Right to restriction (Art. 18), You may request that we restrict processing of your data in certain circumstances.
- •Right to data portability (Art. 20), You may request your data in a structured, commonly used, machine-readable format.
- •Right to object (Art. 21), You may object to processing based on legitimate interests.
- •Rights related to automated decision-making (Art. 22), Our AI-powered assessments involve automated processing. You have the right to request human review of any automated decision that significantly affects you.
When we erase data on request, erasure also covers free-text answers (encrypted answers are overwritten without being decrypted), stored quotes and survey links. Interview transcripts record a stakeholder by name rather than by email address, so please tell us which interview to remove.
To exercise any of these rights, contact us at privacy@transformics.ai. We will respond within 30 days as required by the GDPR.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl if you believe your data protection rights have been violated.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- •Encryption in transit using TLS (Transport Layer Security) for all data communications
- •Encryption at rest for stored data in our database
- •Encryption of survey free-text answers, uploaded evidence files and your sensitive-terms list with a key unique to your organization, destroyed when the organization is deleted
- •Placeholders instead of known names and contact details in requests to AI models, and administrator switches to turn off AI reading of documents and of survey free text
- •Survey results for a department, level or function of fewer than five people are not shown separately, and a survey answer is saved only after the respondent's consent is recorded
- •Role-based access controls limiting data access to authorized personnel
- •Secure authentication via industry-standard OAuth 2.0 protocols
- •Regular security reviews of our infrastructure and third-party processors
- •Service role key separation between frontend and backend access
While we strive to protect your personal data, no method of transmission or storage is 100% secure. If you become aware of any security breach, please notify us immediately.
11. Children's Privacy
Our Service is designed for business professionals and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- •Update the "Last updated" date at the top of this page
- •Notify you via email if the changes materially affect how we process your data
- •Where required by law, obtain your renewed consent
We encourage you to review this policy periodically.
13. Contact Information
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your data, please contact us:
- •Transformics (operated by Innovato Consultancy)
- •Netherlands
- •Email: privacy@transformics.ai