Legal

Privacy, Confidentiality and Reporting

How your information is handled

Steradian handles different kinds of content differently. In plain language:

What your sponsor can see

What standard sponsor and facilitator reports do not show

Minimum reporting floor and related thresholds

Organizational analytics and leadership reports use a minimum reporting floor of 3 respondents before aggregate results are shown. Item-level response distributions are withheld below n = 5. Reports display respondent counts so readers can judge sample size; they do not currently display role-coverage breakdowns in standard report templates.

Example: With only 2 responses, a sponsor could deduce "If team average is 80 and I scored 85, the other person must have scored 75." Individual responses are not shown attributably in standard sponsor or facilitator reports. Aggregate reporting and unattributed comments can still carry re-identification risk in small leadership teams. Steradian applies minimum-count reporting rules, distribution thresholds, identifiability screening for written comments, and role-scoped access controls to reduce that risk — and does not promise absolute anonymity.

Data quality assurance

Steradian employs statistical quality controls to support accurate organizational insights, including:

These quality indicators are used to improve the accuracy of aggregate metrics and are not used to judge individual respondents or shared with employers as individual scores.

Information We Collect

Steradian collects the following types of information:

Account Information:

Survey Responses:

Usage Data:

How We Use Your Information

We use the information we collect for the following purposes:

Data Sharing and Disclosure

We do not sell your information. We share it only with service providers that operate the platform, under contractual confidentiality, and in the limited circumstances below:

Individual diagnostic answers are not attributed in standard sponsor or facilitator reports. Platform operations personnel retain role-restricted, logged access to systems for support and service operation; that access is not used to produce attributed reporting for employers or sponsors.

Data Breach Notification

In the event of a data breach that compromises your personal information, we will:

Notifications will be sent to the email address associated with your account. If you have concerns about a potential data breach, please contact us immediately at security@steradiansurvey.com.

Your Rights and Choices

You have the following rights regarding your personal information:

Note: If you request account deletion, we will process removal of your personal information manually. Aggregate organizational insights that have already been shared with your organization may remain in aggregated form.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Automated retention enforcement is not yet in place (see also our Security page). Deletion requests are fulfilled manually via the privacy contact above.

For Module 2 sealed comment originals, records become purge-eligible 30 days after pulse close under current retention configuration; eligibility is defined in product policy, and automated purge is not yet running. Aggregated organizational insights may be retained longer for research and analytical purposes.

Data Security

We implement industry-standard security measures to protect your information:

Research Foundation:

Our aggregation / non-attribution practices follow academic research standards:

Our commitment to you

Steradian designs standard sponsor and facilitator reports so individual diagnostic answers are not attributed. We display aggregate, unattributed insights subject to a minimum reporting floor of 3 respondents, withhold item distributions below n = 5, and apply identifiability screening for written rationales in small groups. Platform operations access for support is role-restricted and logged, and is not used to produce attributed reporting. This commitment is described in our Terms of Service and implemented through the technical controls above. We do not promise absolute anonymity.

International Data Transfers

Steradian is operated from the United States. If you are located outside the United States, please be aware that information we collect may be transferred to, stored, and processed in the United States. By using our services, you consent to the transfer of your information to the United States. We take appropriate measures to ensure your information receives an adequate level of protection.

Children's Privacy

Steradian is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@steradianinsights.com and we will take steps to delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate and improve our Service. These technologies help us:

You can control cookies through your browser settings. However, disabling cookies may affect the functionality of the Service. For more information about our use of cookies, please contact us at privacy@steradianinsights.com.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Mailing Address: [Company Name], [Street Address], [City, State ZIP Code], United States

Note: If you are located in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection authority if you believe we have violated applicable data protection laws.