Privacy
Privacy Policy
How Best Place to Grow™ is designed to handle employee, alumni and organizational data - and what is not built yet.
Last updated: To be completed before publication
Current state
This site is a demonstration environment. No employee survey, alumni study or organizational data is currently collected, stored or processed through it. The sections below describe the privacy architecture the assessment platform is designed around, not an infrastructure already in operation.
Data minimisation
Only the data required to assess the Standard's indicators is collected. Demographic attributes are collected as bands, never as identifiers, and only where a population-level equity analysis requires them.
Purpose limitation
Assessment data is used to score an organization against the Employee Growth Standard, to produce its Growth Report™ and to publish aggregate research. It is never sold, never used for advertising and never used to profile an individual.
Aggregation and reporting thresholds
Results are only ever returned to an employer in aggregate, and only above a minimum group size. Below that threshold, no result is reported - not rounded, not approximated, not shown.
Employee anonymity
Surveys are administered by BPTG, never by the employer. Individual answers are never accessible to the employer: not aggregated late, not filtered, not exportable.
Open-text de-identification
Free-text answers are de-identified before any aggregation. Names, team references and identifying detail are removed, and verbatim quotation is only released where it cannot identify its author.
Employer access restrictions
An employer receives insight. It never receives people. Role-based access separates organization users, auditors and governance, and no role can reconstruct an individual response.
Retention and deletion
To be completed before publicationRetention periods per data category, and the deletion procedure at the end of each period.
Data subject rights
To be completed before publicationAccess, rectification, erasure, restriction, portability and objection, together with the contact route and response time, will be stated here with the identity of the data controller.
Subprocessors
To be completed before publicationThe list of subprocessors, their role and their location will be published here.
Security
To be completed before publicationTechnical and organizational security measures will be described here once the assessment platform infrastructure is implemented and reviewed. No security claim is made in advance of that review.
International transfers
To be completed before publicationTransfer mechanisms and safeguards for data leaving its region of collection.