P
PeopleOS

Privacy Notice

This notice explains how PeopleOS collects, uses, and protects your personal data. It applies to all users of the PeopleOS platform and to candidates who complete assessments.

GDPR Art.13 compliantEU AI Act Art.13 compliantLast updated: June 2026

1. Who we are (Data Controller)

PeopleOS is operated by MBU Intelligence. We are the data controller for personal data collected through this platform.

Contact: privacy@peopleos.health

For EU AI Act and GDPR enquiries, our Data Protection contact is available at the address above.

2. What data we collect

Data categoryExamplesLegal basisRetention
Account dataName, email address, Clerk user IDContractDuration of account + 3 years
Assessment responsesAnswers to OCEAN, EQ, Bias, Johari, Values, Leadership questionsContract / Consent (Art. 9 GDPR for psychometric data)3 years from completion
Psychometric profilesOCEAN scores, EQ scores, bias tendency scores, leadership style classificationContract / Consent3 years from completion
AI conversation logsMessages sent to and received from the AI Assistant when learning mode is enabledExplicit consent (opt-in)12 months or until consent is withdrawn
Usage dataAI model used, token counts, cost, plan ID, request timestampsLegitimate interest (service improvement, billing)24 months
Billing dataStripe customer ID, subscription plan, billing cycleContract / Legal obligationDuration of contract + 7 years (tax)
Notification logsRecord of notifications sent, event type, timestampLegitimate interest6 months
EU AI Act consentTimestamp of Article 13 disclosure acknowledgement, assessment token, articles acknowledgedLegal obligation (EU AI Act Art.12)3 years

3. Special-category data

Psychometric assessment results (OCEAN scores, personality profiles, EQ scores) constitute special-category personal data under GDPR Article 9 — specifically data revealing mental health or psychological characteristics.

We process this data under Article 9(2)(b) — processing necessary for employment-related obligations with appropriate safeguards — and/or Article 9(2)(a) — explicit consent.

You always have the right to withdraw consent and request deletion of psychometric data. Withdrawal does not affect the lawfulness of prior processing.

4. Automated processing and the EU AI Act

PeopleOS uses AI systems for psychometric assessments and an AI assistant. These systems are classified as high-risk AI under EU AI Act Annex III §4 (AI in employment decisions).

We comply with EU AI Act Chapter 2 obligations:

Article 9 — Risk management: we operate a risk management programme covering bias detection, accuracy monitoring, and residual risk documentation.

Article 10 — Data governance: assessment scoring is based on validated psychometric models. Your responses are never used to train AI models without explicit, separate consent.

Article 12 — Logging: each assessment session is automatically logged with model version, consent timestamp, and completion status.

Article 13 — Transparency: you receive a clear disclosure of AI use, data processing, and your rights before every assessment begins.

Article 14 — Human oversight: all assessment results are reviewed by HR professionals before being used in any employment decision. No decision is made solely on the basis of automated output.

Article 15 — Accuracy: scoring models are reviewed quarterly for accuracy and demographic fairness.

You have the right to request a human explanation of any automated result and the right to object to automated processing under GDPR Article 22.

5. Who we share data with (Sub-processors)

Sub-processorCountryPurposeSafeguard
Vercel Inc.USAApplication hosting and serverless computeStandard Contractual Clauses (SCCs)
Supabase Inc.USADatabase storage and real-time servicesSCCs / Data Processing Agreement
Clerk Inc.USAAuthentication and user identity managementSCCs / DPA
Stripe Inc.USAPayment processing and subscription managementSCCs / DPA
Anthropic PBCUSAAI language model inference (AI Assistant)SCCs / Usage Policy

6. Your rights

To exercise any of these rights, use the Privacy Centre in your dashboard or email privacy@peopleos.health. We will respond within 30 days as required by GDPR Article 12.

If you believe we have handled your data unlawfully, you have the right to lodge a complaint with your national data protection authority.

Right
Right of access (Art.15)

Request a copy of all personal data we hold about you.

Right
Right to erasure (Art.17)

Request deletion of your personal data ('right to be forgotten'). Exceptions apply where we have a legal obligation to retain data.

Right
Right to portability (Art.20)

Receive your data in a structured, machine-readable format (JSON/CSV).

Right
Right to restriction (Art.18)

Request that we temporarily stop processing your data while a dispute is resolved.

Right
Right to rectification (Art.16)

Request correction of inaccurate or incomplete data.

Right
Right to object (Art.21)

Object to processing based on legitimate interest. You also have the right to object to automated decision-making under Art.22.

Right
Right to withdraw consent

Withdraw any consent you have given at any time without affecting prior lawful processing.

7. International transfers

PeopleOS is hosted in the European Union where possible. Some sub-processors operate in the United States. All international transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c).

A list of sub-processors and their transfer mechanisms is maintained at /dpa.

8. Cookies and tracking

PeopleOS uses essential cookies only: session authentication cookies set by Clerk (HttpOnly, SameSite=Lax, Secure). We do not use advertising, analytics, or tracking cookies.

No third-party tracking scripts are loaded. No cross-site user profiling is performed.

9. Changes to this notice

We may update this privacy notice to reflect changes in our processing activities or legal requirements. Material changes will be communicated via email to account holders.

This notice was last updated: June 2026. Version: 1.0.

Submit a data request →View DPA template