Date of last update: 22/07/2026
General
This Privacy Policy (“Policy”) describes how we collect and use your personal data in connection with Strengthscope websites, portals, and services. The terms “Strengthscope”, “we”, “us”, or “our” refer to Strengthscope Limited, registered under the laws of England and Wales.
This Policy applies to:
The Services, together with our Websites and Portals, are referred to as the “Platform”.
This Privacy Policy does not constitute, create, or form part of any contract or warranty between you and Strengthscope. This Policy is provided for informational purposes under the applicable privacy laws and regulations.
Contents
Who is responsible for your data
For the purposes of applicable data protection laws (in particular, the General Data Protection Regulation (EU) 2016/679 (“GDPR“)), your data will be controlled by Strengthscope, which provides the Platform to you as a Controller and, where applicable, as the Processor of your personal data.
Strengthscope Limited provides a strengths-based assessment and development platform that operates via its websites and customer portals. It allows individuals and organisations to complete assessments, receive reports, participate in feedback, manage team and organisational analytics, and access development tools to improve personal and professional effectiveness.
Controllership details
Registered name: Strengthscope Limited
Registered address: 3rd Floor 86-90 Paul Street, London, England, EC2A 4NE
General contact address: hello@strengthscope.com
Privacy support: help@strengthscope.com
Data Protection Officer (DPO): dpo@strengthscope.com
Failure to provide personal data
Please read this Privacy Policy and our Terms and Conditions carefully before using the Services. If you do not agree with the Terms and Conditions, you should not use the Services. For information about how we process your personal data, please refer to this Privacy Policy.
If we are required by law to collect personal data, or if it is necessary to process your requests or fulfil a contract with you, and you do not provide the requested data, we may be unable to carry out your instructions or meet our contractual obligations. In such cases, we may need to terminate our engagement or the contract, but we will inform you of this decision at that time.
Key terms and definitions
Personal data: any information relating to an identified or identifiable natural person (“Data subject”). For the purposes of GDPR, personal data means any information relating to You such as a name, surname, gender, age, health information, preferences, etc.
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data processor: means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
You: means any individual accessing or using the Platform (“Visitor”), obtaining the Services (“Customer”), or otherwise interacting with us directly or indirectly, including as a prospective customer (“Lead”), a current or former customer, or an employee, representative, or associate of a customer.
Services: refers to all features, tools, content, and functionalities provided through the Platform. This includes but is not limited to produced assessments, online resources, licenses, services, or other collaterals purchased by the Customer under the Order.
Platform: refers to the Strengthscope websites and portals accessible from https://www.strengthscope.com, https://strengthscope.my.salesforce-sites.com, https://profile.strengthscope.com/Client/Account/Login, and https://profile.strengthscope.com.
Platform visitor: a person who visits Strengthscope’s websites.
Cookies: text files that are stored on a website visitor’s computer or mobile device by a website’s server.
Sources of personal data
We obtain personal data from the following sources:
Why we process your data
We process personal data for the following purposes:
No sale of personal data
We do not sell personal data under any circumstances. Personal information collected is used solely for the purposes described in this policy and in accordance with applicable data protection laws. Any sharing of personal data with third parties occurs only where necessary to provide our services, comply with legal obligations, or with your explicit consent.
Types of personal data & legal basis for processing
Below is a list of the categories of personal data we may collect and process about you:
Core personal data
Assessment & sensitive data
Financial & commercial data
Technical & behavioural data
Communications & content data
Operational/situational data
| Purpose of processing | Type of personal data processed | Data subjects | Legal basis | |
| 1
|
Account management & authentication
|
● Identity data ● Technical data ● Security data ● Usage data (limited to session activity) |
Customers
|
● Article 6 (1) (b) GDPR (contract performance)
● Article 6 (1) (f) GDPR (legitimate interests)
|
| 2
|
Billing & payment processing
|
● Identity data ● Billing & payment data ● Financial account data ● Document content ● Signature data ● Technical data ● Compliance data |
Customers
|
● Article 6 (1) (c) GDPR (legal obligation)
● Article 6 (1) (b) GDPR (contract performance)
|
| 3
|
Communication
|
● Identity data ● Professional data ● Appointment data ● Optional profile data ● Interaction data ● Communication data |
Leads
Customers
|
● Article 6 (1) (b) GDPR (contract performance)
● Article 6 (1) (f) GDPR (legitimate interests)
|
| 4 | Compliance with legal & regulatory requirements | ● Identity data ● Professional data ● Billing & payment data ● Financial account data ● Document content ● Signature data ● Compliance data ● Security data |
Customers
|
● Article 6 (1) (c) GDPR (legal obligation)
|
| 5 | Cookies & tracking technologies implementation | ● Technical data ● Location data ● Consent data ● Usage data |
Visitors
Customers |
● Strictly necessary cookies: Article 6 (1) (b) GDPR (contract performance)
● Marketing or analytics cookies: Article 6 (1) (f) GDPR (legitimate interests); Article 6 (1) (a) GDPR (consent) |
| 6 | Customer relationship management & sales automation |
● Identity data ● Professional data ● Commercial data ● Appointment data ● Interaction data ● Usage data ● Communication content ● Consent data |
Leads
Customers |
● Article 6 (1) (b) GDPR (contract performance)
● Article 6 (1) (f) GDPR (legitimate interests) |
| 7 | Customer support | ● Identity data ● Assessment data ● Demographic data ● Billing & payment data ● Financial account data ● Commercial data ● Appointment data ● Optional profile data ● Usage data ● Communication content ● Meeting content ● Document content ● Interaction data ● Technical data ● Security data |
Visitors
Leads Customers |
● If processing special categories of data: Article 6 (1) (a) GDPR (consent); Article 9 (2) (a) GDPR (explicit consent)
● Article 6 (1) (b) GDPR (contract performance) ● Article 6 (1) (f) GDPR (legitimate interests) |
| 8
|
Defending or resolving legal claims
|
● Identity data ● Professional data ● Billing & payment data ● Financial account data ● Communication content ● Document content ● Signature data ● Compliance data ● Security data |
Visitors
Leads Customers
|
● Article 6 (1) (f) GDPR (legitimate interests)
|
| 9
|
Logistics & fulfilment of training materials
|
● Identity data ● Customs data ● Appointment data ● Optional profile data |
Customers
|
● Article 6 (1) (f) GDPR (legitimate interests)
|
| 10 | Marketing & advertising | ● Identity data ● Professional data ● Commercial data ● Usage data ● Location data ● Interaction data ● Consent data ● Technical data |
Leads
Customers |
● Article 6 (1) (f) GDPR (legitimate interests) |
| 11 | Platform analytics & development | ● Commercial data ● Technical data ● Usage data ● Interaction data ● Security data |
Customers | ● Article 6 (1) (f) GDPR (legitimate interests) |
| 12
|
Platform maintenance & performance
|
● Identity data ● Technical data ● Usage data ● Security data |
Customers
|
● Article 6 (1) (b) GDPR (contract performance)
● Article 6 (1) (f) GDPR (legitimate interests)
|
| 13
|
Security maintenance
|
● Identity data ● Technical data ● Compliance data ● Location data ● Security data ● Usage data |
Visitors
Customers
|
● Article 6 (1) (c) GDPR (legal obligation)
● Article 6 (1) (f) GDPR (legitimate interests)
|
| 14 | Service delivery | ● Identity data ● Assessment data ● Professional data ● Demographic data ● Technical data ● Appointment data ● Communication content ● Meeting content ● Document content ● Interaction data ● Usage data ● Security data |
Customers | ● If processing special categories of data: Article 6 (1) (a) GDPR (consent); Article 9 (2) (a) GDPR (explicit consent)● Article 6 (1) (b) GDPR (contract performance) |
| 15 | Social & community features | ● Identity data ● Optional profile data ● Interaction data ● Communication content |
Customers | ● Article 6 (1) (f) GDPR (legitimate interests) |
| 16 | Training delivery & facilitation | ● Meeting content ● Interaction data ● Usage data |
Customers | ● Article 6 (1) (f) GDPR (legitimate interests) |
The use of cookies & other tracking technologies
Strengthscope uses “cookies” – small text files stored on your computer or mobile device by our website’s server, and other limited tracking technologies to ensure smooth Platform functionality and enhance your user experience.
Certain cookies and similar technologies are essential to enable performance of the Platform and are processed on the legal basis of contract performance (Article 6 (1) (b) of the GDPR).
Other cookies and tracking tools are used to improve our website and tailor content, based on our legitimate interest in optimising functionality, performance, and security (Article. 6 (1) (f) of the GDPR).
Strengthscope does not use advertising identifiers (IDFA/AAID). All tracking technologies are implemented with data minimization, transparency, and respect for user privacy. For more details about our use of cookies, please visit our Cookie Policy.
Automated decisions
According to Article 22 of the GDPR, the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
The Company does NOT make any decisions based solely on automated processing, including profiling, which produces legal effects concerning data subjects.
How and when we share your information
Below are the circumstances under which personal data may be shared:
Corporate transaction: in the event of a potential or actual corporate transaction (e.g., a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding), we may transfer your personal data to relevant parties involved in the transaction. Such transfers will occur only to the extent necessary and subject to appropriate confidentiality and data protection safeguards, in compliance with Article 6 (1) (f) GDPR (legitimate interests) or other applicable lawful bases.
Compliance with the laws: we may disclose your personal data to third parties where necessary to comply with legal obligations under Article 6 (1) (c) GDPR, including to:
Protection and safety: we may disclose your personal data to third parties where necessary to protect vital interests including to:
Service providers and professional advisors: we may share your personal data with carefully selected providers and professional advisors, such as:
We do not sell user data to any third parties. All service providers engaged by us operate under standard Data Processing Addendums (DPAs) and are compliant in accordance with Article 28 of the GDPR. We adhere to the principle of data minimisation, sharing only the information necessary to deliver each specific service. Additionally, third-party integrations are user-controlled and require explicit consent before any data is shared.
International data transfers
The Company has affiliates and service providers in the United States and in other countries. Your personal information may be transferred to other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.
Under data protection laws, we can only transfer your personal data to a country outside the UK/EEA where:
protection of personal data (known as an ‘adequacy decision’) further to Article 45 of the EU GDPR. A list of countries the European Commission has currently made adequacy decisions in relation to is available here:
Where we transfer your personal data outside the UK we do so on the basis of an adequacy regulation or where this is not available, we will do so under a transfer mechanism such as legally-approved standard data protection clauses recognised or issued further to Article 46 (2) of the UK GDPR. In the event we cannot or choose not to continue to rely on either of those mechanisms at any time we will not transfer your personal data outside the UK unless we can do so based on an alternative mechanism or exception provided by UK data protection law and reflected in an update to this Policy. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Data retention practices
Strengthscope implements comprehensive data deletion and retention procedures to respect user privacy and comply with applicable data protection regulations, including the right to erasure. This involves a) user-requested deletion and b) automatic data retention and deletion.
Customer-requested deletion
Customers may delete their accounts at any time. Strengthscope may retain personal data for as long as necessary to fulfil the purposes outlined in this Privacy Policy, for example, comply with legal obligations, resolve disputes, and enforce our agreements and policies.
Automatic data retention and deletion
Strengthscope retains personal data only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements and policies. Once data reaches the end of its retention period, Strengthscope either securely deletes it or anonymises it to ensure that it can no longer be used to identify any individual.
Inactive users:
General data retention practices
We will retain and use Your personal data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Please, see the table below:
| Data categories based on the purpose of personal data processing | Retention period | |
| 1 | Account management & authentication | Retained for the duration of the Customer’s account activity plus 2 (two) years after the account deletion based on our legitimate interest (6 (1) (f) of the GDPR) |
| 2 | Billing and payment processing | Retained for the duration of the purpose, for which processing is needed and 6 (six) years to comply with financial regulations and auditing requirements (6 (1) (c) of the GDPR) |
| 3 | Communication | Retained for the duration of the Customer’s account activity plus 2 (two) years after the account deactivation |
| 4 | Compliance with legal and regulatory requirements | Retained for the duration of the purpose, for which processing is needed and 6 (six) years to comply with legal obligations (6 (1) (c) of the GDPR) |
| 5 | Cookies & other tracking technologies implementation | Depending on the type of cookies, retention periods may very – see our Cookie Policy |
| 6 | Customer relationship management and sales automation | Retained for the duration of interaction with the Customer data collected under other purposes |
| 7 | Customer support | Retained for the duration of Customer support interaction and 2 (two) years to defend against legal claims based on our legitimate interest (6 (1) (f) of the GDPR) |
| 8 | Defending or resolving legal claims | Retained for the duration of the purpose, for which processing is needed and 6 (six) years to comply with legal obligation |
| 9 | Logistics and fulfilment of training materials | Retained for the period of service completion plus 2 (two) years |
| 10 | Marketing & advertising | Retained for the duration of the purpose, for which processing is needed plus 2 years after the last meaningful activity (defines as a reply, meeting booked/held, form submission, webinar attendance, sales call, proposal sent, contract discussion) or until the data subject requests the opt-out (details added to suppression list and kept indefinitely to comply with opt-out request) |
| 11 | Platform analytics and development | Retained for up to 7 (seven) years for performance monitoring and improvement |
| 12 | Platform maintenance & performance | Retained for up to 7 (seven) years to ensure optimal operation and troubleshooting |
| 13 | Security maintenance | Retained for 2 (two) years to support incident management and security auditing |
| 14 | Service delivery | Retained for the period of service provision plus 2 (two) years |
| 15 | Social and community features | Retained for the duration of the purpose, for which processing is needed or until the data subjects removes or requests deletion of personal data |
| 16 | Training delivery & facilitation | Retained for the period of service provision plus 2 (two) years |
Information security
We employ industry standard security measures designed to protect the security of all information submitted through the Services.
We implement a comprehensive set of technical and organisational security measures to ensure the confidentiality, integrity, and availability of personal data, in accordance with the General Data Protection Regulation (GDPR). These measures include, but are not limited to:
Account and authentication security: customer accounts are protected by secure authentication processes, are stored and managed safely.
Annual penetration testing: regular penetration tests through independent third parties to identify and remediate vulnerabilities in our systems.
Data encryption and secure transmission: all data is encrypted in transit and at rest, ensuring that information is protected when transmitted over networks and when stored.
Data loss prevention (DLP): DLP tools are deployed to monitor and prevent unauthorised sharing or leakage of personal data.
Database and file storage protection: databases and file storage systems are secured with encryption, network safeguards, and routine backups to prevent data loss.
Employee security awareness training: all employees undergo mandatory annual training on data protection, phishing awareness, and secure handling of personal information.
Incident response plan: we maintain a documented and regularly tested incident response plan to ensure swift and effective action in the event of a data breach or security incident.
ISO 27001 certification: our information security management system is certified to ISO 27001, demonstrating our commitment to internationally recognised standards for data protection and risk management.
Monitoring and incident detection: systems are continuously monitored to detect and respond to potential security incidents promptly.
Multi-factor authentication (MFA) & single sign-on (SSO): additional layers of identity verification or streamlined secure access where possible to reduce password fatigue and improve security.
Role-based access control (RBAC): access to personal data is restricted on a need-to-know basis. Only authorised personnel can access customer data according to their role and responsibilities.
Secure development practices: our development teams follow secure coding standards, including OWASP guidelines, and conduct code peer reviews for applications that handle personal data.
Vendor risk management: we assess and monitor third-party vendors to ensure they meet our data protection and security requirements.
While we take reasonable steps to protect your personal data, no system can be completely secure. Therefore, we encourage you to take precautions to protect your own information, including maintaining the confidentiality of login credentials.
To protect you and your data, we may suspend your use of any of the Services, without notice, pending an investigation, if any breach of security is suspected.
Updating personal data
If any of the personal data that you have provided to us changes, for example if you change your email address or if you wish to cancel any request you have made of us, or if you become aware we have any inaccurate personal data about you, please let us know by sending an email to dpo@strengthscope.com We will not be responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.
Children’s privacy
Strengthscope does not knowingly collect any personal data from children under the age of 16 (sixteen). If you think that your child provided this kind of information on our Platform, we strongly encourage you to contact us immediately and we will do our best to promptly remove such information from our records.
Our priority is to add protection for children while using the Internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.
Consistent with the requirements of the GDPR, if we learn that we have received any information directly from a child under the age of 16 without first receiving his or her parent’s verified consent, we will use that information only to respond directly to that child (his or her parent or legal guardian) to inform the child that he or she cannot use the Sites and subsequently we will delete that information.
Your rights and choices
Under the General Data Protection Regulation (GDPR), you have certain rights concerning your personal information. You may request that we take the following actions in relation to the personal data we hold about you:
Opt-out: opt-out from the processing of personal data based on your consent.
Access: provide details about how we process your personal information and give you access to it.
Request: You have the right to receive your personal data in a structured, commonly used, and machine-readable format. If you wish, you can also request that we transfer this data directly to another data controller, where technically feasible.
Correct: update or correct any inaccuracies in your personal data.
Delete: remove your personal information from our records. In certain circumstances, you have the right to request the deletion of your personal data. This may apply if:
*Please note that this right is not absolute and may be subject to exceptions, such as compliance with legal obligations or the establishment, exercise, or defence of legal claims.
Transfer: send you or a third party a machine-readable copy of your personal data.
Restrict: You have the right to request the restriction of processing of your personal data in certain situations, such as:
While the processing is restricted, we will only store your personal data and will not process it further unless specific conditions apply.
Object: You have the right to object to the processing of your personal data based on our legitimate interests (Article 6(1)(f) of the GDPR), unless we can demonstrate compelling legitimate grounds for the processing that override your rights and freedoms.
To further exercise any of these rights, you may contact us at dpo@strengthscope.com. We may need to request specific information from you to verify your identity and process your request. In some cases, applicable laws may require or allow us to decline your request. If we are unable to comply, we will explain the reason, subject to any legal restrictions.
If you have concerns about how we handle your personal information or our response to your requests, you may contact us at dpo@strengthscope.com or file a complaint with the data protection authority in your jurisdiction.
Updates to this Privacy Policy
Contact information
We welcome your comments or questions about this Policy, and you may contact us at the following address: dpo@strengthscope.com.