Privacy policy
Updated 11 September 2026
1. Who we are
MaturityMap is the organisational assessment and improvement service at maturitymap.ai, provided by PEOPLE WORK LIFE LIMITED (Companies House 16547876), 26 Cromwell Road, Ascot, England, SL5 9DG. Contact rob@peopleworklife.com about privacy or this notice.
2. Our role and your organisation’s role
We are the controller for account administration, our customer relationships, billing and service security. For assessment responses, participant records, uploaded evidence and programme content processed on a customer’s instructions, we act as processor. The organisation commissioning the programme determines its purposes and is responsible for its own privacy notice and lawful basis. Where a consultancy manages a programme for another organisation, their agreement determines their respective roles.
We receive information from you, the organisation or consultant administering your programme, documents they upload, and connected services you use. Participants may respond through invitation links or an account. Ask the inviting organisation about its use of your responses. We support it in responding to your requests.
3. Information we process
Account information includes name, email, workspace membership, role and access permissions, password hashes or passkey credentials, two-factor authentication records, billing references, support correspondence and security/audit events.
Programme information can include stakeholder and participant contact details, survey and assessment responses, organisational segments, interview and discussion notes, observations, uploaded documents and transcripts, scores, analysis, reports, action assignments, progress updates and internal notes. The organisation chooses what to collect and upload.
Connection and technical information includes session cookies, request and error information, and, for Teams, Microsoft tenant and user identifiers, conversation addressing, connection verification records, reminder preferences, delivery status and check-in receipts. Do not include unnecessary sensitive information in free text or files. Customers must have the additional lawful conditions required for any special-category information they submit.
4. Why we use information
We use account and contact information to provide access, manage subscriptions, respond to support requests and communicate about the service. Where you contract with us personally, this is necessary for our contract with you. For users acting for an organisation, our legitimate interest is administering and delivering that organisation’s service.
Our legitimate interests also include protecting accounts, preventing abuse, diagnosing errors and understanding product usage to improve the service. We use billing and other records where necessary to meet legal and accounting obligations. We process programme data only on the customer’s documented instructions; our customer must establish its own lawful basis for collecting and using it.
Account and security details are needed to provide secure access. Without them we may be unable to provide an account. Your organisation explains whether participation in its assessment is required. We do not sell personal data or use programme responses to market to participants.
5. Who can see programme data
Access depends on workspace roles, programme permissions and the sharing choices made by the customer. Consultants and authorised client users may view programme information, and customers may export reports or share portal links. Customers are responsible for recipients and copies they create outside MaturityMap.
Do not assume every response, report or Teams check-in is anonymous. Names, small groups and distinctive comments can identify people. The inviting organisation must explain the confidentiality arrangements for its programme. Teams action updates are linked to the connected account and form part of the programme record.
6. AI-assisted analysis
When an authorised user invokes AI features, relevant prompts, evidence or programme content may be sent to Anthropic to assist with analysis and drafting. Workspaces can supply an Anthropic API key for supported features; this does not guarantee that every AI operation uses that key.
AI-generated scores, summaries and recommendations need human review. MaturityMap is a decision-support tool, not a service for making solely automated employment decisions with legal or similarly significant effects. Customers remain responsible for decisions they make from its outputs.
7. Service providers and international processing
We use Vercel for application hosting, file storage and Web Analytics; Neon for PostgreSQL; Anthropic for AI; Resend for service email; Stripe for payments; Sentry for error monitoring; Upstash for rate limiting; and Cloudflare for bot protection. Microsoft processes Teams and identity information when the Teams connection is used. Only the providers relevant to a feature receive the information needed for that feature.
Our current primary database is in London. This does not mean all processing takes place in the UK: providers may process information in other countries, including the United States. Contact rob@peopleworklife.com for the arrangements and applicable transfer safeguards for your service.
8. Microsoft Teams
Where enabled, the private Teams bot links a Microsoft identity to an authenticated MaturityMap account and a selected programme. The user confirms that link in MaturityMap. Opted-in reminders contain action information; submitted status updates and internal notes are recorded against the linked account with an audit record and receipt.
You can turn off reminders or disconnect in Settings → Microsoft Teams. Disconnecting stops future use of that connection; it does not delete action history or messages already delivered. Microsoft and your organisation’s Teams retention settings govern copies held in Teams. The pilot does not read unrelated chats, channel history, files or meetings.
9. Cookies and service messages
MaturityMap uses the mm-session-token authentication cookie, authentication and security cookies, and temporary cookies to complete flows such as Teams linking. Browser storage supports preferences and recent items, and can hold assessment drafts and offline fieldwork responses. Local copies may remain after synchronisation until cleared. Use a trusted device for offline work and clear locally stored programme information before handing the device to someone else. Vercel Web Analytics measures page views, MaturityMap records product-use events to understand feature usage, and Sentry supports diagnostics. These services have their own technical processing; this notice does not claim that all telemetry remains in the UK.
Invitations, reminders and security messages support the service or the programme you were invited to. Teams reminders are optional. Ask the inviting organisation to stop programme invitations. Any marketing we send must use an applicable lawful route; you can ask us to stop marketing at any time.
10. Retention and deletion
We retain programme data while needed to deliver the customer’s programme and in accordance with its instructions. The workspace lifecycle provides a 365-day retention window after dormancy and a 14-day cooling-off period for an earlier workspace deletion request. Contact us to confirm or arrange deletion; disabling a connection or ending a subscription is not immediate erasure.
Account, billing, support and audit records may need separate retention for security, legal obligations or resolving disputes. We determine that period from the purpose of the record, applicable obligations and any ongoing claim. Backup and provider-held copies can have different deletion cycles; ask us for the arrangements applying to your data. We do not promise Pindrop’s deletion or backup deadlines for MaturityMap.
Disconnecting Teams retains completed programme updates and audit evidence. Customers control exported copies and their own Microsoft retention arrangements.
11. Your rights
Depending on the circumstances, you can request access, correction, erasure, restriction and portability of your personal data. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. Contact rob@peopleworklife.com; for programme data, contact the organisation that invited you first.
You have a right to object to processing based on legitimate interests, including our use of your account information to administer an organisational service. You can object to direct marketing at any time.
You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. You do not have to complain to us first.
12. Children and changes
MaturityMap is intended for organisational and workplace use, not services directed at children. Customers must not use it to collect children’s data without a separate agreed arrangement.
We will update this notice when the service or our practices change and date the new version. Contact rob@peopleworklife.com if you need an explanation or an accessible copy.