EU GDPR

Privacy policy

Updated: demo version v0.1

1. Data controller

StigomBoard is a service shared by many customers. For the personal data stored in the service for each customer company, that company is itself the data controller. StigomBoard acts as a data processor on the company's behalf.

2. Data processed

  • Administrators' identifying data: name, email, role, last login.
  • Board members' data: name, email (if chair/secretary or report recipient), role.
  • Survey participants' data: name and email (for sending invitations).
  • Answers: anonymous – cannot be linked to the respondent in the database.
  • Audit log: logins, survey lifecycle events.

3. Purpose and basis of processing

The purpose of processing the data is to organize the board's self-assessment. Processing is based either on the controller company's legitimate interest (evaluation per the governance code) or on the data subject's consent (voluntary respondents).

4. Anonymity

Answers cannot be linked to the respondent at the database level. Only the information about who has responded is kept (to calculate the response rate) – not what each person answered. Per-member NPS results are subject to k-anonymity protection (default n < 3 → the result is not shown).

5. Retention period

The active phase of the survey (invitations, response window): until the response time ends. Response data: a retention period set by the controller company, by default 7 years from the end of the evaluation year. Participants' personal data can be requested for deletion at any time.

6. Data transfers and sub-processors

  • Anthropic (Claude API): PDF extraction and generation of AI report text. Per the agreement, data is not used to train the model. Submitted data is processed for the task.
  • Email service: sending invitations and reports (e.g. AWS SES, Postmark).
  • Hosting: EU-region cloud.

7. Rights of the data subject

  • The right to be informed about the processing (this policy).
  • The right to access one's own data.
  • The right to rectify incorrect data.
  • The right to erase data (the right to be forgotten).
  • The right to restrict and object to processing.
  • The right to lodge a complaint with the supervisory authority (Data Protection Ombudsman, tietosuoja.fi).

Requests go to the controller company's contact person. The StigomBoard owner can, on request, export the company's data out of the system (GDPR export) or delete it entirely.

8. Cookies

We use only necessary session cookies. More information on the cookie page.

This is the demo version's policy. In production, a customer-specific privacy policy and DPA are drawn up for each customer.

Privacy policy – StigomBoard · StigomBoard