Legal
Privacy, Confidentiality and Reporting
Non-attribution in standard reports
Individual diagnostic survey answers are not shown attributably in standard sponsor or facilitator reports. Access to team reports is company- and role-scoped, and platform operations access for support is role-restricted and logged. That access is not used to produce attributed reporting for employers or sponsors. Aggregate reporting and unattributed comments can still carry re-identification risk in small leadership teams; Steradian applies reporting floors and screening controls described below and does not promise absolute anonymity.
How your information is handled
Steradian handles different kinds of content differently. In plain language:
- Diagnostic survey responses — Stored linked to your account for operations (scoring, support, and service delivery). Reported only in aggregate and not attributed in standard sponsor or facilitator reports. Platform operations staff can access individual records for support; that access is role-restricted and logged, and is not used for attributed reporting.
- Session and decision-workspace contributions — Attributable by design (for example, decision perspectives captured under your login) and disclosed as such before participation.
- Written rationales — Displayed without attribution on team surfaces. Identifiability screening withholds recognizable wording in small groups; originals remain sealed from standard team views.
What your sponsor can see
- That you completed the survey (completion status — needed for campaign management)
- When you completed it (timestamp — for tracking progress)
- Team aggregate metrics (when the minimum reporting floor of 3 respondents is met)
- Organizational trends and insights (averages, alignment scores, domain summaries, and — where group size permits — response distributions)
- Respondent count on closed reports (how many leaders contributed to the cohort)
What standard sponsor and facilitator reports do not show
- Your individual answers attributed to you in those report flows
- Your personal Steradian Score as a named individual result for sponsors
- Side-by-side “you vs. teammate” answer attribution
Minimum reporting floor and related thresholds
Organizational analytics and leadership reports use a minimum reporting floor of 3 respondents before aggregate results are shown. Item-level response distributions are withheld below n = 5. Reports display respondent counts so readers can judge sample size; they do not currently display role-coverage breakdowns in standard report templates.
Example: With only 2 responses, a sponsor could deduce "If team average is 80 and I scored 85, the other person must have scored 75." Individual responses are not shown attributably in standard sponsor or facilitator reports. Aggregate reporting and unattributed comments can still carry re-identification risk in small leadership teams. Steradian applies minimum-count reporting rules, distribution thresholds, identifiability screening for written comments, and role-scoped access controls to reduce that risk — and does not promise absolute anonymity.
Data quality assurance
Steradian employs statistical quality controls to support accurate organizational insights, including:
- Detection of response patterns that may indicate survey fatigue or rushed completion
- Statistical weighting to improve aggregate metric accuracy
- Confidence intervals and reliability indicators
These quality indicators are used to improve the accuracy of aggregate metrics and are not used to judge individual respondents or shared with employers as individual scores.
Information We Collect
Steradian collects the following types of information:
Account Information:
- Name and email address (required for account creation)
- Company name and title (optional, for organizational context)
- Phone number (optional, for account recovery)
- Password (hashed with bcrypt; not stored in plain text)
Survey Responses:
- Your responses to organizational alignment assessment questions
- Perceptions of current and future organizational capabilities
- Response timestamps and completion status
Usage Data:
- Login timestamps and session information
- Page views and feature usage (for platform improvement)
- IP address and browser information (for security and analytics)
How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide organizational alignment assessment services and generate insights
- Account Management: To create and manage your account, authenticate logins, and provide customer support
- Aggregate Analytics: To calculate organizational insights, alignment scores, and trends (subject to the minimum reporting floor of 3 respondents)
- Platform Improvement: To improve our services, fix bugs, and enhance user experience
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
Data Sharing and Disclosure
We do not sell your information. We share it only with service providers that operate the platform, under contractual confidentiality, and in the limited circumstances below:
- With Your Organization: Aggregated insights (subject to the minimum reporting floor) are shared with your organization's sponsor or administrator
- Service Providers: We may share data with trusted third-party service providers who assist in operating our platform (e.g., cloud hosting providers, email service providers, database hosting services), subject to contractual confidentiality and data processing agreements that comply with applicable data protection laws
- Legal Requirements: We may disclose information if required by law, court order, government regulation, or to protect the rights, property, or safety of Steradian, our users, or others
- Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction, subject to the same privacy protections set forth in this policy
- With Your Consent: We may share information when you have explicitly consented to such sharing
Individual diagnostic answers are not attributed in standard sponsor or facilitator reports. Platform operations personnel retain role-restricted, logged access to systems for support and service operation; that access is not used to produce attributed reporting for employers or sponsors.
Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Investigate the breach promptly and take steps to contain and remediate it
- Notify affected users within 72 hours of becoming aware of the breach (as required by applicable law)
- Notify relevant regulatory authorities as required by applicable data protection laws
- Provide clear information about what information was affected and what steps we are taking
- Provide guidance on steps you can take to protect yourself
Notifications will be sent to the email address associated with your account. If you have concerns about a potential data breach, please contact us immediately at security@steradiansurvey.com.
Your Rights and Choices
You have the following rights regarding your personal information:
- Access: You can access and review your account information at any time through your profile settings
- Correction: You can update or correct your account information through your profile settings
- Deletion: Account and data deletion requests are fulfilled manually. Email privacy@steradianinsights.com (same mailto as Settings → Request account deletion). There is no automated self-serve deletion in the product today.
- Data Portability: You can request a copy of your data in a machine-readable format
- Opt-Out: You can opt out of non-essential communications (marketing emails) while still receiving important service notifications
Note: If you request account deletion, we will process removal of your personal information manually. Aggregate organizational insights that have already been shared with your organization may remain in aggregated form.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Automated retention enforcement is not yet in place (see also our Security page). Deletion requests are fulfilled manually via the privacy contact above.
For Module 2 sealed comment originals, records become purge-eligible 30 days after pulse close under current retention configuration; eligibility is defined in product policy, and automated purge is not yet running. Aggregated organizational insights may be retained longer for research and analytical purposes.
Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit: Data transmitted between your browser and our servers is protected using HTTPS/TLS
- Access controls: Company- and role-scoped permissions limit who can administer accounts and view team reports
- Password security: Passwords are hashed using bcrypt and not stored in plain text
- Audit logging: Authentication and administrative actions are logged for investigation and review
- Account protection: Account lockout after failed login attempts; password practices for administrators
- No data sales: We do not sell your personal data. We share it only with service providers that operate the platform, under contractual confidentiality, and as described above
Research Foundation:
Our aggregation / non-attribution practices follow academic research standards:
- Tourangeau & Yan (2007) - Survey anonymity and response honesty (citation title; Steradian gloss: unattributed response conditions)
- Podsakoff et al. (2003) - Common method biases in organizational research
- American Association for Public Opinion Research (AAPOR) - Survey research guidelines
Our commitment to you
Steradian designs standard sponsor and facilitator reports so individual diagnostic answers are not attributed. We display aggregate, unattributed insights subject to a minimum reporting floor of 3 respondents, withhold item distributions below n = 5, and apply identifiability screening for written rationales in small groups. Platform operations access for support is role-restricted and logged, and is not used to produce attributed reporting. This commitment is described in our Terms of Service and implemented through the technical controls above. We do not promise absolute anonymity.
International Data Transfers
Steradian is operated from the United States. If you are located outside the United States, please be aware that information we collect may be transferred to, stored, and processed in the United States. By using our services, you consent to the transfer of your information to the United States. We take appropriate measures to ensure your information receives an adequate level of protection.
Children's Privacy
Steradian is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@steradianinsights.com and we will take steps to delete such information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our Service. These technologies help us:
- Maintain your session and authenticate your identity
- Remember your preferences and settings
- Analyze Service usage and performance
- Provide security features
You can control cookies through your browser settings. However, disabling cookies may affect the functionality of the Service. For more information about our use of cookies, please contact us at privacy@steradianinsights.com.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy: privacy@steradianinsights.com
Security Concerns: security@steradiansurvey.com
Data Protection Officer (if applicable): dpo@steradiansurvey.com
Mailing Address: [Company Name], [Street Address], [City, State ZIP Code], United States
Note: If you are located in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection authority if you believe we have violated applicable data protection laws.