@DearestWatson ("we", "us", or "our") is committed to protecting your personal data and ensuring transparency in how it is used. This policy explains what we collect, why we collect it, and the choices you have.
1. Data Roles
@DearestWatson
Contact: privacy@dearestwatson.com
When you use @DearestWatson directly, we act as controller for your account and service data. When your employer, client organization, or another customer invites you into the platform, that organization is usually the controller for the workspace purpose and @DearestWatson acts as processor under our agreement with them. For some operational data, such as security logs, abuse prevention, billing, and product reliability, @DearestWatson may act as an independent controller.
2. What Data We Collect
We collect and process the following types of personal data:
Account information
- Email address (used for login and identification)
- Name (used to personalize your experience)
- Company, team, role, level, and portal-access information where supplied by an organization or administrator
Assessment data
- Your responses to assessments
- Generated results, insights, and profiles
- Stakeholder Match, organizational-diagnosis, and development-pathway responses where you are invited into those modules
AI and meeting-analysis interactions
- Chat transcripts between you and Watson are stored on our infrastructure to provide continuity across sessions
- Behavioral signals derived from your interactions (e.g. recurring themes, blockers, completed actions) are synthesized into a coaching memory
- Meeting recordings, transcripts, and AI-assisted analyses where an authorised administrator records an engagement or internal meeting
- Raw behavioral event logs are retained for 30 days, after which only the synthesized memory is kept
Company Brain and purpose-bound professional context
- Up to four administrator-verified company documents may provide disclosed secondary context in Watson, Stakeholder Match, and meeting analysis
- Company context cannot determine development goals, change match scoring, become meeting evidence, or judge culture fit, alignment, performance, or potential
- Existing purpose-bound professional signals remain a separate data category where previously authorized and include neutral summaries, provenance, confidence, status, timestamps, and expiry—not raw assessment answers, Coach chats, or transcript passages
- Usage receipts retain bounded source identifiers and workflow metadata—not raw Coach chats, plaintext retrieval questions, or document passages
- Meeting analysis does not automatically create or retain professional-context observations about participants
- You may explicitly save a displayed meeting decision, meeting-theme title, or follow-up action into your own private development commitments and later remove it
- An authorised recorder may suggest a displayed decision or meeting-theme title for company-administrator review. It remains unavailable to Company Brain until approved, is limited to leaders, expires after 90 days, and excludes transcripts, quotations, interpretations, follow-ups, and person-pattern observations. Suggestions containing a known participant name are rejected.
Watson People Intelligence
- You may create, edit, publish, withdraw, or delete professional-experience records. Published records remain clearly labelled self-declared.
- Current team leaders may use interpreted assessment outcomes, published self-declared experience, and explicitly manager-visible development-goal title/status for people they currently lead. Company administrators may use the same eligible evidence across their company.
- Watson stores server-authorized query scope, confirmed criteria, candidate identifiers, evidence hashes, and mapping/prompt versions. Compliance telemetry does not store the raw question.
- Private Coach chats and memory, raw assessment answers, private development goals, reflection and check-in text, meeting recordings/transcripts, protected characteristics, and special-category data are excluded.
Usage data
- Interaction data used to improve the product, including analytics and search optimization
- Security, access, invitation, email-delivery, and audit logs used to protect the service and support customers
External invitation data
- Public invitation tokens and expiry information for assessment, onboarding, and client-match links
- Onboarding drafts that may include company, team, participant, and evaluation-context information before an account is created
- Transactional email delivery status for invitations, reminders, and access messages
Policy acceptance
- Timestamp and version of accepted policies
3. How We Use Your Data
We process your data to:
Provide the service
Deliver assessments, generate insights, and enable platform functionality.
Personalize your experience
Tailor insights and recommendations based on your inputs.
Improve the product
Analyze usage patterns to improve functionality, usability, and discoverability.
Ensure security and access control
Maintain secure login and protect your data.
Operate customer workspaces
Enable approved administrators to create participants, Stakeholder Match respondents, onboarding drafts, runs, reports, and module assignments.
Legal basis (GDPR):
- Contract performance (Article 6(1)(b))
- Legitimate interest (Article 6(1)(f))
- Consent where applicable (Article 6(1)(a))
Reading or acknowledging this policy records that the notice was delivered; it is not itself consent. For organization workspaces, the controller must identify and document the applicable lawful basis before enabling Company Brain.
4. Team, Leadership & Watson Usage
If you use the platform as part of a team or organization:
- Your assessment results, interpreted profiles, and generated insights may be visible to your designated leader or administrator
- Your raw assessment answers are not shared
- Leaders are provided with interpreted results only, not underlying inputs
- Access to results is defined by your organization (e.g. leader or administrator roles)
- Your Watson chat transcripts are private to you and are not shown to leaders or administrators as chat transcripts
- Private Coach conversations, blockers, resistance, and behavioral memory are not available to Stakeholder Match or meeting-analysis workflows
- Operational coaching telemetry, such as event delivery, notification status, and module activity, may be visible to authorised administrators where needed to run the service
- Stakeholder Match outputs are AI-assisted evidence for human review and are not standalone automated decisions
- “Joining a team” views describe possible working dynamics and onboarding questions only. They do not assess competence, performance potential, or employment suitability and must not be used as a hiring recommendation
- Where the governed Watson People Intelligence pilot is enabled, current leaders may receive named requirement-by-requirement staffing and team-composition decision support within their authorized scope. Staffing criteria must be confirmed before ranking.
Governed Company Brain
Where your organization enables Company Brain, the feature operates under this Privacy Policy rather than separate participant switches. Your organization remains responsible for establishing and documenting an appropriate lawful basis for workspace processing. You may access, correct, delete, restrict, or object to processing through your organization or by contacting us.
- Stakeholder Match may reuse explicitly approved professional evidence for deterministic comparison. Company Brain context may support briefing preparation, useful questions, collaboration guidance, and communication only; it does not determine ranking, hiring, eligibility, or suitability outcomes.
- Leader-facing meeting analysis and coaching may use relevant administrator-verified documents or active, human-approved meeting decisions and themes as secondary organizational context. That context is not evidence that something occurred in the current meeting and cannot become person evidence.
- Meeting analysis does not automatically create a durable professional-context claim from the transcript. Raw transcripts, quotations, interpretations, and person-pattern observations remain in the meeting workflow unless you make one of the explicit bounded choices described above.
- Administrators can see purpose and access metadata in the usage ledger, but cannot directly inspect your professional-context claims or private Coach memory.
- “Audit only” or implicit personalization means the main output does not repeat a profile; it does not mean the processing is undisclosed. Usage receipts and relevant professional-context records are included in your data export.
- Company Brain blocks special-category and sensitive inference, including health, diagnosis, political, religious, union, sexuality, and emotion-recognition categories.
- Company Brain is human decision support only. It must not make standalone decisions about employment, compensation, promotion, performance, or work allocation.
How Watson Uses Data
The platform uses your data to generate AI-powered coaching and insights. This includes:
- Individual leadership feedback
- Team-level patterns and dynamics
- Recommendations for leaders and organizations
These insights are generated based on:
- Your assessment results
- Your Watson chat history
- Aggregated team data
- Organizational context (where applicable)
To generate these insights, your prompts and relevant context are transmitted to third-party large language model (LLM) providers configured server-side — currently Mistral AI through its EU regional inference endpoint — which processes the data on our behalf under their respective enterprise terms. These providers do not use the data to train their public models. For Company Brain workflows, Mistral receives only the minimized, purpose-specific context lease and the task or transcript data genuinely required for that workflow.
Your data is used for the enabled development, insight, manager-support, and governed staffing purposes described in this notice.
Watson does not make solely automated employment, evaluation, compensation, staffing, promotion, or work-allocation decisions. It cannot assign a person or update a talent record. A responsible human must verify evidence, consider corrections and make any consequential decision.
5. Your Rights & Control
You have full control over your data:
- Access — You can request a paginated machine-readable export and readable summary in the product; shared and unstructured records are reviewed before the response is marked complete
- Correction — You can update inaccurate information
- Deletion — You can submit an erasure request in the product; deletion is verified and shared records, legal holds, and lawful exclusions are reviewed before completion
- External respondent requests — If you were invited as a Stakeholder Match respondent or onboarding contact, contact us or the inviting organization and we will coordinate the request
- Portability — You can request your data in a structured format
- Restriction & objection — You can limit or object to certain processing
- Withdraw consent — Where processing is based on consent, you may withdraw it at any time
- Company Brain rights — You can request usage receipts and relevant professional-context records, and ask to correct, delete, restrict, or object to their use
We respond to requests within one month.
6. Data Retention
- Account, profile, assessment, and Watson conversation data is stored as long as your account is active
- Raw behavioral event logs are retained for 30 days; only the synthesized coaching memory is kept beyond that
- Meeting audio defaults to 90 days (company setting 30–365 days); transcripts and analysis default to 365 days (company setting 90–1,095 days), subject to audited legal holds
- Superseded or archived Company Brain versions default to 90 days (company setting 30–365 days); shared content and usage receipts may require privacy review
- Transactional email logs keep delivery status for operational support, and personal email-log fields are redacted after 180 days
- Public invitation tokens expire automatically and can be revoked by authorised administrators
- Private GDPR export artifacts expire after 24 hours
- Inactive-account cleanup begins after three years measured across relevant product activity. A warning is sent 30 days before eligibility, subject to legal holds and review
7. Data Security
We implement appropriate technical and organizational measures, including:
- Encrypted data transmission (HTTPS/TLS)
- Secure authentication systems
- Row-level access controls ensuring users only access their own data
- Regular security reviews
8. Data Sharing & Sub-processors
We do not sell your data.
We rely on the following trusted third-party providers to operate the platform:
- Vercel — static application hosting, deployment infrastructure, and global content delivery
- Supabase — EU production database, authentication, storage, EU-routed edge functions, and platform infrastructure
- Mistral AI SAS — EU regional AI inference and audio transcription (AI Coach, insights, profile extraction, and meeting analysis)
- LetterMint — transactional email (login credentials, invitations)
- Google — Google Workspace SAML sign-in where enabled
- Microsoft — Microsoft Teams integration and Microsoft Entra sign-in where enabled
These providers process data on our behalf under strict confidentiality and in accordance with a Data Processing Agreement (GDPR Article 28). LLM providers process prompts on a zero-retention or no-training basis under their enterprise terms.
9. EU Data Residency & Processing
Our production architecture keeps the customer content used by the core platform in Europe:
- Data — EU: Production customer content—including account and profile data, assessment data, Coach content, meeting recordings and transcripts, generated analyses, and Company Brain records—is stored in our Supabase production project in Stockholm, Sweden.
- Functions — EU: The application and its internal workflows route Supabase Edge Function requests that process customer content to an EU execution region in Frankfurt, Germany.
- AI processing — EU: AI chat, analysis, and audio-transcription requests are sent to Mistral's EU regional inference endpoint. Only the information needed for the requested feature is sent.
Our development environment is separated from production and is not a production customer-content store.
This EU commitment applies to production customer content and the core application processing described above. Limited operational metadata may be handled globally where necessary for content delivery, security, account administration, billing, transactional email, support, or integrations requested by a customer (such as Microsoft Teams or SAML sign-in). Where a provider processes that limited data outside the EU/EEA, we use an applicable adequacy decision or safeguards such as the European Commission's Standard Contractual Clauses. We do not treat global delivery or control-plane metadata as customer assessment, Coach, meeting, or Company Brain content.
10. Complaints
If you believe your data rights have been violated, you have the right to lodge a complaint with a supervisory authority.
In Denmark:
Datatilsynet
www.datatilsynet.dk
11. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are significant, you will be asked to review and re-accept the updated policy before continuing to use the platform.
12. Contact
If you have any questions about this policy or your data: privacy@dearestwatson.com
