Privacy · GDPR
Your data remains yours.
This notice explains what personal data Constrive PDI processes, why we process it, how long we retain it, and how you can exercise your rights.
- Version
- 1.0
- Effective
- Last updated
Introduction
Constrive B.V. is the controller responsible for the personal data processed through Constrive PDI.
For privacy questions or requests, contact privacy@constrive.com. Constrive B.V. has not appointed a Data Protection Officer; privacy enquiries are handled through this address.
This privacy notice is intended to provide the information required by Articles 13 and 14 of the General Data Protection Regulation (GDPR).
- Privacy contact privacy@constrive.com
Data we collect
We collect only the information needed to provide, secure, and improve the PDI service.
- Personal data
- Email address, survey responses, computed scores, developmental dimensions, and archetype assignments.
- Technical data
- IP address (logged temporarily), user agent, authentication and session identifiers.
- Usage data
- Survey completion times, page views, report generation, and feature usage recorded in operational and audit logs.
- Data we do not collect
- We do not ask for health data, religion, ethnicity, sexual orientation, political opinions, genetic data, or biometric data.
How we use your data
We use personal data to provide and operate the PDI service, compute developmental scores and archetypes, produce and communicate reports, and maintain service quality and reliability.
We use data for research and development only where explicit consent has been obtained. Where possible, research data is anonymized before use.
Back to topLegal basis for processing
- Legitimate interests — Article 6(1)(f)
- Operating and securing the main PDI service and providing developmental feedback, balanced against your rights and interests.
- Contract performance — Article 6(1)(b)
- Providing the service where processing is necessary for Constrive employees or another contractual relationship.
- Consent — Article 6(1)(a)
- Using data for research purposes where you have explicitly agreed. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligation — Article 6(1)(c)
- Retaining records where tax, employment, or another applicable law requires it.
Data retention
- Personal data
- Until an erasure request is completed or seven years after your last interaction, unless a shorter or longer legally required period applies.
- Session data
- Authentication sessions expire after 24 hours of inactivity.
- Audit logs
- Seven years. User identifiers and direct request fingerprints are anonymized when an erasure request is completed.
- Anonymized research data
- May be retained indefinitely because it can no longer be linked to an identifiable person.
Your rights
Subject to the conditions in the GDPR, you have the right to information (Articles 13–14), access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), and safeguards concerning automated decision-making (Article 22).
You may contact privacy@constrive.com to exercise a right or raise a concern. You also have the right to lodge a complaint with the Dutch Data Protection Authority or the supervisory authority in your country.
-
Access and portability
Request a machine-readable export:
/gdpr/export -
Erasure
Request deletion of your data:
/gdpr/erase - Contact privacy@constrive.com
Automated decision-making
PDI scores and archetypes are not used to make decisions that produce legal or similarly significant effects without human review. The PDI is a developmental aid, not a ranking or automated selection tool.
Every report includes an Article 22 notice. You may request human intervention, an explanation of a result, and an opportunity to express your point of view or challenge its interpretation.
Back to topData security
We use technical and organizational safeguards appropriate to the risk, including encrypted PostgreSQL storage, TLS 1.3 connections, access controls, passwordless authentication, security logging, regular security audits, and an incident-response procedure.
No internet service can guarantee absolute security. We review and improve these controls as the service evolves.
Back to topInternational transfers
PDI data is stored and processed within the European Union or European Economic Area. We do not transfer PDI personal data to third countries.
Back to topUpdates to this notice
We version this notice and show its effective date and last-updated date. Material changes will be communicated through the service or by email where appropriate.
Version 1.0 is the first comprehensive Article 13/14 privacy notice for Constrive PDI and is effective from 12 August 2026.
Back to top