Privacy & data

What we keep, and what we don’t.

This describes what the product actually does. We audit other people’s security for a living, so the bar for our own handling is the one we would hold a service provider to.

What we record about a visitor

Only what you type and what your own browser sends. There are no third-party trackers, no advertising pixels, and no fingerprinting.

  • Email address, first and last name — supplied by you at signup or when a service provider unlocks their score
  • Whether that email has been verified
  • The page you first landed on, the referring site, and any utm_ tags already in the link you followed
  • A dated trail of what you did: signed up, verified, started or submitted an assessment, viewed a study guide, invited a service provider
  • A record of each page you view on this site, kept without your name or address — see “Counting visits to this site” below

Counting visits to this site

The site counts its own page views, so we can see how many people use it and roughly where from. It does this itself: no analytics company, advertising network or other third party is involved, and nothing is stored in your browser — no cookie, no identifier.

For each page view we keep the page, the name of the site you came from, any utm_ tags in the link, the kind of device, browser and operating system, whether you were signed in (never which account), and a rough location — country, region and town — that our hosting platform works out from your connection when the request arrives. We do not keep your IP address.

Whether two page views came from the same person is decided by an anonymous code made from your connection and browser together with a secret that stays on our server. The code changes every day, so we can count visitors within a day but cannot follow anyone from one day to the next, and the code cannot be turned back into your address.

  • Not counted: browsers that send Do Not Track or Global Privacy Control, automated visitors such as search crawlers and uptime monitors, and Paladin staff working in the operator console
  • The address of a private page (an invitation link, for example) is never kept: the secret part of it is replaced before the view is stored
  • Page views are deleted after 90 days

What a service provider gives us

A service provider completing a tokenized assessment link is asked, after submitting, for their name, work email, and which approved pension fund the assessment is for. That is what unlocks their own score.

The pension fund is chosen from a fixed list — a service provider cannot direct their submission at an arbitrary organization.

What a new client gives us when starting an agreement

A client who has agreed a proposal fills in an onboarding form before any account exists, so we can prepare their Master Services Agreement. It asks for more about other people than anywhere else on this site, so here is exactly what it takes:

  • The contracting organization: legal entity name and entity type
  • Each plan the agreement covers: plan name, and the plan number and EIN if you have them
  • Who signs, and any additional signers: name, title, work email and phone
  • The legal reviewer, if legal reviews before signature: name, work email and phone
  • Anyone else in the review chain: name, work email, phone, their role, where they sit in the order, and any note you add about that step
  • When you would like to take the assessment
  • The network address and browser details of the submission, and the moment you confirmed you are authorized to share these people’s details. We keep them with the record of exactly what you submitted, and use the network address to limit how many submissions one location can make in an hour

We use it to prepare the agreement, to route it for signature in the order you set, and to set up access to Paladin for those people once the agreement is signed. Names and email addresses go into the signature request itself, which is sent through DocuSign.

Please list only people you are authorized to share. Everyone you name will receive email about this agreement, so add them only if passing on their work contact details is yours to do.

The signer’s email address is also kept in our contact register, with a note that an agreement is in progress, so we can see where things stand and connect it to their account once it exists. The other people you name are used only to route the agreement; they are not added to that register.

While you fill the form in, what you have typed is kept in your own browser, on your own device — not on our servers — so a closed tab does not lose it. It is removed when you submit, when you choose to start fresh, or after a week. Nothing reaches us until you confirm on the review screen.

When you hand an engagement to someone else

If you delegate management of a service provider’s assessment to another organization — a law firm or an IT company, say — you enter the person’s name and work email. We keep those, what you allowed them to do, and when they accepted or you withdrew it. They are shown to you so you can see and cancel the delegation.

The invitation is a link you send them yourself; we do not email it. The delegate sees only the engagement you handed them, and only what you allowed.

Who can see an assessment

An assessment is scoped to the organization that requested it. Another organization assessing the same service provider sees its own result and never yours.

The service provider who filled it in sees their own headline score, risk band and per-domain percentages — not the answer-level detail, and never another provider's results.

Where AI is used, and where it is not

The score is computed entirely in deterministic code. No model sets an answer, moves the score, or cancels a red flag — the same inputs always produce the same number, and the formula is published on the Services page.

AI reads the free-text comment behind a “Yes” and grades how well it substantiates the claim. That produces a second, clearly-labelled evidence-adjusted score shown beside the official one. If the AI is unavailable, the assessment still scores normally.

We keep a copy of what is sent to the AI and what it answers, so our staff can check its work. Those copies include the comments and answers you typed, are visible only to Paladin staff, and are deleted after 180 days — or after 2 years if a person reviewed that call. An uploaded document is never copied into them: only its name and size are.

What we never do

  • Sell or rent personal data
  • Buy data about you from a broker, or combine your record with purchased data
  • Track you across other websites
  • Infer anything about you beyond what you told us or your browser sent
  • Show your results to anyone other than the organization that requested them

Your data, on request

You can ask for a copy of everything held about you, ask for it to be corrected, or ask for it to be deleted. Use the address below and we will confirm in writing when it is done.

Deleting an account does not retract an assessment already delivered to a plan sponsor — that is their fiduciary record, not ours to remove. We will say so plainly rather than quietly leaving it in place.

Contact

Data questions, access requests and deletion requests: privacy@paladinassurance.com