MaturityMap
Trust & data

Straight answers about your data.

Culture data is sensitive. This page sets out where it is stored, which services process it, and the controls every workspace has — in plain language, with nothing we can't stand behind.

Last reviewed: 12 August 2026

Where your data lives

MaturityMap stores customer data in a Neon PostgreSQL database hosted in AWS eu-west-2 (London, UK). Data is encrypted in transit and at rest by the database provider.

Report exports — Word, PDF and PPTX files — are stored as private files on Vercel's storage in London, United Kingdom, and are accessible only through authenticated download links.

Your data, your tenant

You own your data. Each workspace is a private tenant, and your programme data is exportable at any time — Word, PDF and PPTX reports plus the underlying data. When your subscription ends, your workspace becomes dormant: you can still sign in, see everything, and export everything, but nothing new can be collected or created until you resubscribe. We keep your data for 12 months from the day the workspace went dormant, then delete it. We email your lead consultants when the workspace goes dormant, 60 days before deletion and 14 days before deletion. You can ask us to delete sooner from Workspace settings, and resubscribing at any time reactivates the workspace and cancels the deletion.

AI processing

AI analysis is processed by Anthropic's Claude API. Inputs sent for analysis are not used to train Anthropic's models. Workspaces can optionally supply their own Anthropic API key under Admin → Tools → AI key.

Subprocessors

These are the services that process data on our behalf, and what each one does.

NamePurpose
VercelHosting, file storage (London), and Web Analytics (page views; no cookies)
NeonDatabase (London)
AnthropicAI processing
ResendTransactional email
StripePayments
SentryError monitoring
UpstashRate limiting
CloudflareBot protection

Your controls

Private tenancy

Each workspace is a private tenant. Your programme data is scoped to your workspace and is not visible to any other customer.

Full exports

Your programme data is exportable at any time — Word, PDF and PPTX reports plus the underlying data. Nothing is locked in.

12-month retention

When a subscription ends the workspace becomes dormant — you can still sign in, see and export everything, but nothing new is collected or created until you resubscribe. We keep your data for 12 months from the day it went dormant, then delete it. Lead consultants are emailed at dormancy, 60 days and 14 days before deletion. You can ask to delete sooner from Workspace settings; resubscribing reactivates the workspace and cancels the deletion.

Your own AI key

Workspaces can optionally supply their own Anthropic API key under Admin → Tools → AI key.

Questions

If you need more detail for a security or procurement review, email rob@peopleworklife.com and we'll answer directly — no ticket queue.

Last reviewed: 12 August 2026