LEGAL
Privacy Policy
How Congruo AI Ltd collects, uses, and protects your personal information
1. Who We Are
Congruo AI Ltd ("Congruo", "we", "us", "our") is a company registered in England and Wales.
Company Registration Number: 17175556
Registered address: 53 Fiador Apartments, 21 Telegraph Avenue, London, United Kingdom, SE10 0TH
We operate the platform available at congruo.io and app.congruo.io (the "Platform"), which provides AI-powered workplace culture intelligence services. For the purposes of UK data protection law, we are the data controller in respect of personal information we process about you.
Contact our Privacy team at: privacy@congruo.io
2. The Information We Collect
2.1 Information you give us directly
When you create an account or use our services, we collect:
- Your name and personal email address
- Your work email address — used to send you a verification code and never stored. Only your employer domain (e.g. @companyname.com) is written to your record.
- Your payment information (collected by Paddle — we do not store card details)
- Any communications you send us
2.2 Information we generate about you
- Your Personal Congruence Score and scores across the 13 culture dimensions
- Your employer domain, derived from your verified work email or verification method
- Assessment conversation transcripts
- Account preferences and settings
- Consent records — type of consent, verbatim wording shown, timestamp, IP address
- Distress flags where applicable — severity level and session reference only, no conversation content
2.3 Information we collect automatically
- Log data: IP address, browser type, pages visited
- Product analytics on congruo.io: anonymised page views via Plausible Analytics (no cookies, no personal identifiers)
- Product analytics on app.congruo.io: identified user behaviour via PostHog — users are identified by user ID after login, IP addresses are captured, session recordings are enabled on dashboard and non-assessment screens only. Assessment conversation screens are explicitly excluded from session recording.
- Technical monitoring: request logs and performance data via Azure Application Insights; error logs via Sentry. Both restricted to authorised development personnel. Neither captures assessment conversation content.
- Behavioural tracking on congruo.io: Brevo Tracker cookie (with your marketing consent) identifies returning visitors who have previously received and clicked a Congruo email, enabling personalised email automation.
- Behavioural tracking on app.congruo.io: Brevo Tracker (with your functional cookie consent on first login) tracks behaviour on dashboard and non-assessment screens to enable personalised product communications. Assessment screens are excluded.
- Advertising and analytics cookies on congruo.io: Google Ads conversion cookies and advertising platform cookies set only with your consent via the cookie banner. app.congruo.io carries no advertising tags.
2.4 Distress Protocol flagging
If your responses suggest you may be experiencing significant distress, the platform responds with supportive resource signposting. In the most serious cases, both founders are notified by email within 24 hours so that appropriate human oversight can take place. Distress flags are accessible to founders only and are never visible to employers.
2.5 Information from third parties
- Auth0: authentication status and account security information
- Paddle: subscription status, billing history, fraud prevention signals
- LinkedIn: where you use LinkedIn to verify employment, we receive your current employer name from your LinkedIn profile. No other LinkedIn data is stored.
3. How We Use Your Information
We use your personal information only for the purposes described below, each matched to a lawful basis under UK GDPR.
| Purpose | Lawful Basis | Details |
|---|---|---|
| Providing your culture assessment and Congruence Score | Performance of a contract | Core service delivery. We cannot provide the service without processing your assessment responses. |
| Processing Wellbeing and Mental Health dimension responses and Distress Protocol flagging | Explicit consent (Article 9(2)(a)) | Both explicitly named on the Assessment Start disclosure screen. Fresh consent obtained at each Check-in with Congruo session. |
| Check-in with Congruo reassessment sessions | Contract / Explicit consent | Each Check-in is a new session. Assessment Start disclosure shown again. Fresh explicit consent obtained before each Check-in begins. |
| Verifying your employment | Legitimate interest / consent | Work email or LinkedIn. The work email address is never stored — only your employer domain is retained. LinkedIn employer name extracted, no other LinkedIn data stored. SMS verification is planned but not currently offered. |
| Generating aggregate company culture profiles | Legitimate interest | Published only once minimum threshold of verified assessments reached. Individual results never identifiable. |
| Team and department level culture insights | Legitimate interest | Available where sufficient verified responses exist at team level. Same minimum threshold applies. |
| Transactional communications | Performance of a contract | Assessment completion notifications, verification codes, billing receipts, password resets, account deletion confirmation. Cannot be opted out of. |
| Product communications | Contract / legitimate interest | Personalised, data-driven communications that form part of the Congruo service: tailored culture insights, score change notifications, company assessment activity alerts, Congruence Score summaries. AI-generated personalised content uses your scores and employer domain. Frequency manageable via preference centre — cannot be fully opted out of as they form part of the service. |
| Marketing communications | Consent | Product updates, new features, upgrade prompts, broadcast newsletter. Asked conversationally at end of assessment — marketing emails only, not product communications. Manageable via preference centre or from the chat. Withdraw consent at any time. |
| Qualitative employer intelligence (paid employer tiers) | Legitimate interest | If your employer holds any paid subscription, your conversation content may be analysed alongside other employees for themes and patterns. Pre-processed and anonymised before Claude receives it. Individual responses never quoted, attributed, or identifiable in employer-facing output. |
| AI-generated personalised product email content | Contract / legitimate interest | Claude generates personalised narrative insights for product emails using your dimension scores, Congruence Score, and employer domain. Stateless processing — Anthropic does not retain this data. |
| Advertising measurement and retargeting on congruo.io | Consent (cookie consent) | Google Ads conversion tracking, Meta, LinkedIn, StackAdapt. congruo.io only. app.congruo.io carries no advertising tags. |
| Company profile claiming and management | Contract / legitimate interest | Where an employer claims their company profile, we process the claimant name, job title, work email address, phone number (if given), and authority declaration. The work email address used to claim a page is retained for as long as the claim stands — it is where the record of the authority declaration is sent, and how we contact the page owner. This is different from the work email used to verify employment for an assessment, which is never stored. A phone number, if given, is used only to verify the claim and to reach the claimant where email fails. |
| Responding to contact enquiries | Legitimate interest | Where you submit the contact form we process the reason for your enquiry, your name, email address, and — where relevant — your company, job title and the details you write. The form saves as you complete it, so a partly-finished enquiry may be held briefly before you submit it. |
| Newsletter — confirming your subscription | Legitimate interest | When you ask to subscribe we email you a confirmation link, and one reminder if you have not used it after seven days. These two messages complete the request you made and contain no marketing. |
| Newsletter — sending it | Consent | Sent only after you confirm, and only until you unsubscribe. We never send it to an address that has not confirmed. |
| Platform improvement | Legitimate interest | Anonymised and aggregated data only. |
| Legal obligations | Legal obligation | Compliance with applicable laws. |
| Fraud prevention and security | Legitimate interest / legal obligation | Platform integrity monitoring. |
4. How We Share Your Information
4.1 Our service providers
We share information with the following trusted providers, each bound by appropriate data protection agreements:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure and data hosting | All platform data | UK South (GDPR) |
| Auth0 | User authentication | Email address, account status | EU (SCCs) |
| Anthropic | AI assessment processing — direct API, stateless, no data retained | Conversation context (current turn only) | US (DPA + SCCs) |
| Paddle | Payment processing | Billing and subscription data | EU/UK (MoR) |
| Resend | Transactional email delivery | Email address, message content | EU (GDPR) |
| Brevo | Product and marketing email; behavioural tracking (with consent) | Email, name, preferences, site behaviour | EU (GDPR) |
| PostHog | Product analytics — identified users in authenticated app | User ID, behaviour events, session recordings (dashboard only) | EU |
| Plausible | Traffic analytics — public site only | Anonymised page views only | EU |
| Azure Application Insights | Technical monitoring and performance | Request logs, IP addresses, performance data | UK South |
| Sentry | Error tracking | Error logs, session references | EU (GDPR) |
| Employment verification (OAuth) | Employer name only — no other LinkedIn data retained | US (SCCs) | |
| Twilio | SMS verification — planned, not currently in use | No data is shared with Twilio today | US (SCCs) |
| Google Ads conversion tracking only (cookie consent required) | Ad click data, conversion events | US (SCCs + Consent Mode v2) | |
| Meta | Advertising (cookie consent required) | Ad click data, PageView events | US (SCCs) |
| LinkedIn Ads | Advertising (cookie consent required — separate from LinkedIn verification) | Site visit data, ad click data | US (SCCs) |
| StackAdapt | Programmatic display advertising (cookie consent required) | Site visit data | US (SCCs) |
4.2 What employers can and cannot see
4.3 Score Cards
When you choose to share your Score Card, it contains your dimension scores and overall Congruence Score only. Your employer name does not appear on your Score Card. You can revoke individual shared Score Card links at any time from your account settings. All shared links are automatically deactivated when your account is deleted.
4.4 Company profiles
Company culture profiles are publicly visible on congruo.io once a minimum threshold of verified employee assessments has been received. Individual contributions cannot be identified within a profile. Profiles are permanent once published. Suppression is available only in exceptional circumstances — see the Employer Terms for details.
4.5 Other disclosures
We may share information where required by law or in connection with a business sale or merger, subject to equivalent privacy protections.
5. International Transfers
Where service providers process data outside the UK or EEA, we ensure appropriate safeguards including ICO-approved standard contractual clauses (SCCs). Anthropic (US) processes data under a signed DPA and SCCs with no retention. LinkedIn employer verification data is extracted in the UK before any transfer occurs. All personal and assessment data is stored exclusively in Azure UK South.
6. How Long We Keep Your Information
| Data type | Retention period |
|---|---|
| Account information | Duration of account. Deleted within 30 days of voluntary account deletion. |
| Work email address (assessment verification) | Never stored. Employer domain retained for duration of account. |
| LinkedIn employer data | Employer name extracted and stored as employer domain only. No other LinkedIn data retained. |
| SMS phone number | Not collected — SMS verification is not currently offered. |
| Assessment responses and transcripts | Duration of account. Deleted within 30 days of account deletion. |
| Congruence Scores | Anonymised and aggregated on account deletion. Personal identifiers purged. |
| Distress flags | Severity level and session reference retained for 12 months then deleted. No conversation content stored. |
| Consent records | Duration of account plus 2 years after deletion. |
| Incomplete assessments | Retained for the duration of your account, so you can return and finish. We do not delete an unfinished assessment on a timer, and we do not send a reminder sequence. You can delete your account at any time. |
| Unvalidated completed assessments | Score viewable; all other features gated after 30 days without verification. If employment is still unverified 90 days after you complete the assessment, we erase the conversation transcript. Your dimension scores are kept. |
| Score Card shared URLs | Active for lifetime of account. Deactivated on account deletion or manual revocation via account settings. |
| Product email content (AI-generated) | Stateless — not retained by Anthropic. Generated content stored as sent email record in Brevo. |
| Advertising cookie data | Per platform — typically 30 days (StackAdapt) to 2 years (Meta). See Cookie Policy. |
| Brevo Tracker behavioural data | 180 days per Brevo retention policy. |
| Azure Application Insights logs | 90 days. |
| Sentry error logs | 90 days. |
| Billing and payment records | 7 years (held by Paddle as Merchant of Record). |
| Marketing consent records | Duration of active consent plus 2 years after withdrawal. |
| Support communications | 2 years from resolution. |
| Employer portal access logs | 90 days. |
| Company page claim records | Duration of the claimed page, plus 30 days after a subscription ends. Claims that are refused or closed are kept no longer than 12 months from the decision. |
| Contact enquiries | 24 months after your last contact. An unfinished enquiry with no email address is deleted after 7 days. |
| Newsletter subscriptions | Unconfirmed requests are deleted after 30 days. If you unsubscribe we keep a record of your address and your consent and withdrawal dates for 6 years, as evidence that you consented and withdrew — nothing further is sent to you. |
| Individual Premium features (TBC) | To be confirmed before Premium launches — August 2026. |
| Referral programme data (TBC) | To be confirmed before referral programme launches — August 2026. |
7. Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights:
Right of access
Request a copy of the personal information we hold about you. We respond within one calendar month.
Right to rectification
Ask us to correct inaccurate or incomplete information.
Right to erasure
Request deletion of your account by contacting privacy@congruo.io. We complete deletion within 30 days of your request. All scores, transcripts, and history are permanently deleted and cannot be recovered.
Right to data portability
Request a copy of your data in machine-readable format (JSON) by contacting privacy@congruo.io. We respond within one calendar month.
Right to restriction
Ask us to restrict processing in certain circumstances, for example while a complaint is investigated.
Right to object
Object to processing based on legitimate interest, including direct marketing.
Right to withdraw consent
Where we rely on consent (Wellbeing dimension and Distress Protocol processing; marketing emails; advertising cookies; Brevo Tracker), withdraw consent at any time without affecting the lawfulness of prior processing. Marketing preferences manageable via preference centre or from the chat.
Rights related to automated processing
Your Congruence Score is generated through an automated process. You have the right to request human review of any significant decision made on the basis of your score.
Distress flag deletion
Request deletion of any distress flag associated with your account by contacting privacy@congruo.io. This does not affect the underlying transcript or any welfare notification already sent.
To exercise any right contact privacy@congruo.io. You may also complain to the ICO at ico.org.uk or call 0303 123 1113.
8. Cookies
We use cookies in three contexts:
- congruo.io (public site): Strictly Necessary cookies (Auth0 session, CSRF), Marketing and Behavioural cookies (Google Ads, Meta, LinkedIn, StackAdapt, Brevo Tracker — all with your consent via the cookie banner), and Functional cookies (Crisp live chat when activated).
- app.congruo.io (authenticated app): Strictly Necessary cookies (Auth0 session, CSRF) plus Functional cookies including the Brevo Tracker (with your consent via the first-login functional cookie notice). No advertising cookies.
- No Google Analytics (GA4) — analytics are handled by PostHog (authenticated app, identified) and Plausible (public site, anonymised).
Full details of every cookie, its purpose, provider, and duration are in our Cookie Policy at congruo.io/cookies. You can change your congruo.io cookie preferences at any time via "Cookie Settings" in the site footer. You can manage your app.congruo.io functional cookie preferences via account settings.
9. Security
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Assessment transcripts encrypted separately from scores. Distress flags stored in a restricted database collection accessible to founders only. Technical monitoring tools (Azure Application Insights and Sentry) are accessible to authorised development personnel only and are configured to exclude assessment conversation content. All data stored in Azure UK South.
10. Children
Our Platform is not directed at individuals under 18. Contact privacy@congruo.io if you believe a child has provided us with personal information.
11. Changes to This Policy
We will notify you of material changes by email or via a prominent notice on the Platform before the change takes effect.