Legal

Privacy Policy

Effective date: 6 June 2026

1. What we collect

We collect only what is necessary to deliver the diagnostic experience and its outputs:

  • Identity data: name, work email, role, and organisation — collected at intake to issue credentials and coordinate team sessions.
  • Diagnostic responses: scenario choices, dimension scores, and written reflections — stored to generate your Coalition Map, Tension Map, and Strategist Brief.
  • Technical data: session codes, completion timestamps, and archetype classifications — used for session management and product improvement.

We do not collect IP addresses. We do not use third-party analytics that track individuals across sessions.

2. How we use it

  • To generate your personal or team diagnostic outputs.
  • To issue and verify credentials.
  • To coordinate multi-participant team sessions.
  • To notify you of session milestones (completions, brief readiness).
  • To improve the diagnostic instrument (only in aggregated, anonymised form).

Your individual responses are never shared with other participants. Your reflection text is never displayed in any team output.

3. Legal basis

POPIA (South Africa): Personal information is collected with your knowledge via the intake form, used only for the stated diagnostic purpose, and not shared with third parties beyond our email delivery service (Resend).

GDPR (EU/UK): Processing is based on contractual necessity (delivering the diagnostic you requested) and legitimate interest (session coordination and product improvement). You may withdraw consent or request deletion at any time.

4. Data retention

Diagnostic responses are retained for 24 months from the date of completion, after which they are automatically purged. Credentials and session metadata are retained indefinitely so that verification links remain valid.

You may request early deletion at any time by emailing info@usenorth.xyz. Deletion removes your responses from active tables and backups within 30 days.

5. Third parties

ProviderPurposeData
SupabaseDatabase hostingAll collected data
ResendEmail deliveryEmail address, name
AnthropicStrategist Brief generationAggregated session data (no PII)
PayFastPayment processingBilling details

6. Your rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (right to be forgotten).
  • Export your data in a portable format.
  • Object to processing for product improvement purposes.

To exercise any of these rights, email info@usenorth.xyz. We respond within 48 hours and resolve within 30 days.

7. Data residency

The Supabase project is hosted in Cape Town (af-south-1). Data does not leave this region for storage. Email delivery passes through Resend's infrastructure (US-based). Anthropic processes Strategist Brief inputs through their API (US-based). Participants in jurisdictions with strict data residency requirements should be advised of this before completing the diagnostic.

8. Changes to this policy

We review this policy with each significant change to data handling or infrastructure. Material changes will be notified by email to active users and posted on this page 30 days before taking effect.

Questions? Contact us at info@usenorth.xyz.