Culture data is sensitive. This page sets out where it is stored, which services process it, and the controls every workspace has — in plain language, with nothing we can't stand behind.
Last reviewed: 12 August 2026
MaturityMap stores customer data in a Neon PostgreSQL database hosted in AWS eu-west-2 (London, UK). Data is encrypted in transit and at rest by the database provider.
Report exports — Word, PDF and PPTX files — are stored as private files on Vercel's storage in London, United Kingdom, and are accessible only through authenticated download links.
You own your data. Each workspace is a private tenant, and your programme data is exportable at any time — Word, PDF and PPTX reports plus the underlying data. When your subscription ends, your workspace becomes dormant: you can still sign in, see everything, and export everything, but nothing new can be collected or created until you resubscribe. We keep your data for 12 months from the day the workspace went dormant, then delete it. We email your lead consultants when the workspace goes dormant, 60 days before deletion and 14 days before deletion. You can ask us to delete sooner from Workspace settings, and resubscribing at any time reactivates the workspace and cancels the deletion.
AI analysis is processed by Anthropic's Claude API. Inputs sent for analysis are not used to train Anthropic's models. Workspaces can optionally supply their own Anthropic API key under Admin → Tools → AI key.
These are the services that process data on our behalf, and what each one does.
| Name | Purpose |
|---|---|
| Vercel | Hosting, file storage (London), and Web Analytics (page views; no cookies) |
| Neon | Database (London) |
| Anthropic | AI processing |
| Resend | Transactional email |
| Stripe | Payments |
| Sentry | Error monitoring |
| Upstash | Rate limiting |
| Cloudflare | Bot protection |
Each workspace is a private tenant. Your programme data is scoped to your workspace and is not visible to any other customer.
Your programme data is exportable at any time — Word, PDF and PPTX reports plus the underlying data. Nothing is locked in.
When a subscription ends the workspace becomes dormant — you can still sign in, see and export everything, but nothing new is collected or created until you resubscribe. We keep your data for 12 months from the day it went dormant, then delete it. Lead consultants are emailed at dormancy, 60 days and 14 days before deletion. You can ask to delete sooner from Workspace settings; resubscribing reactivates the workspace and cancels the deletion.
Workspaces can optionally supply their own Anthropic API key under Admin → Tools → AI key.
If you need more detail for a security or procurement review, email rob@peopleworklife.com and we'll answer directly — no ticket queue.
Last reviewed: 12 August 2026