Privacy Policy
How we collect, use, and protect your personal data.
Humanity In Business Solutions Ltd
Effective: June 2026
Applies to: humanityinbusiness.com and intelligence.humanityinbusiness.com
Who this policy is for
This Privacy Policy applies to all visitors to humanityinbusiness.com and all registered users of the HIBS assessment platform at intelligence.humanityinbusiness.com. Where data processing differs between the two properties, this is clearly indicated. If you are completing a governance maturity assessment on the HIBS assessment platform, please read Section 5 carefully before you begin.
1. Who we are
Humanity In Business Solutions Ltd ("HIBS", "we", "us", "our") is a governance intelligence company incorporated in Bulgaria, operating from Sofia, Bulgaria. We are the data controller for personal data collected through our website and the HIBS assessment platform.
2. What data we collect and why
2.1 Marketing website (humanityinbusiness.com)
When you visit our marketing website we may collect:
- Usage and visitor-identification data via the Apollo tracker — pages visited, on-site activity, IP address, and the organisation associated with your IP address. Set only where you accept analytics cookies. Legal basis: consent.
- Aggregate, cookieless usage analytics via Vercel — page views and performance metrics, with no cookies, device storage, or persistent identifiers. Legal basis: legitimate interests (no device storage; consent not required under PECR).
- Contact form submissions — name, email address, organisation, role, and message content. Legal basis: legitimate interests (responding to enquiries) or pre-contractual steps.
- Cookie consent preference — your accept/decline decision, stored locally in your browser. Legal basis: legal obligation (PECR/ePrivacy compliance).
2.2 HIBS assessment platform (intelligence.humanityinbusiness.com)
When you register and use the assessment platform we collect:
- Account data — name, email address, organisation name, and job title provided at registration. Legal basis: contractual necessity.
- Assessment response data — your answers to governance maturity assessment questions across one or more of our nine assessment frameworks. Legal basis: contractual necessity (delivery of the service you have purchased or requested).
- Payment data — transaction records including amount, date, and Stripe payment reference. We do not store card numbers or payment instrument details. These are handled entirely by Stripe. Legal basis: contractual necessity and legal obligation.
- Report data — AI-generated maturity reports produced from your assessment responses, stored in our database and accessible through your account. Legal basis: contractual necessity.
- Usage and session data — authentication tokens, session activity, and platform usage patterns. Legal basis: legitimate interests (platform security and performance).
- Cookie consent preferences on the platform. Legal basis: legal obligation.
Assessment response data — important
Your assessment responses may contain commercially sensitive information about your organisation's governance posture. We treat this data with the same rigour we ask you to apply to your own governance. Assessment responses are stored in our Supabase database and are not shared with third parties except as described in Section 6, and are not used to train AI models. Authorised HIBS personnel may access your assessment responses and generated reports for the purposes of quality assurance, technical support, platform improvement, and service delivery. Such access is limited to what is necessary, is subject to internal confidentiality obligations, and does not constitute disclosure to third parties. Anonymised, aggregated score data may be used for industry benchmarking — see Section 5.
3. Lawful basis for processing
We process personal data only where we have a lawful basis to do so under UK GDPR and EU GDPR. The following bases apply to our processing activities:
4. Marketing communications
We will only send you marketing communications if you have explicitly opted in to receive them. You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@humanityinbusiness.com. Withdrawal of marketing consent does not affect your platform account or access to purchased reports.
5. AI processing and report generation
Read this before completing an assessment
When you generate a report on the HIBS assessment platform, your assessment responses are transmitted to the Anthropic API for AI-assisted report generation. By proceeding with report generation you acknowledge this transmission. This section explains what happens to your data during this process.
5.1 How AI report generation works
The HIBS assessment platform uses Claude, developed by Anthropic PBC, to generate governance maturity reports from your assessment responses. When you click to generate a report, the following data is transmitted to the Anthropic API:
- Your scored assessment responses including question text, domain, score band, and maturity level
- The assessment framework type (e.g. Internal Audit, Information Security)
- Your selected report tier (free summary, full paid, or ODD)
- Directional finding guidance drawn from our certified audit methodology framework
This data is transmitted securely over HTTPS. The generated report text is returned to our platform and stored in your account.
5.2 What Anthropic does not do with your data
Anthropic does not use data submitted via the API to train its AI models. API data is subject to Anthropic's data processing terms, which are separate from Anthropic's consumer product terms. For details see Anthropic's privacy policy at anthropic.com/privacy.
5.3 Benchmarking and aggregated data
Domain-level scores from completed assessments may be anonymised and aggregated to produce industry benchmark data. This aggregated data cannot be attributed to any individual or organisation. If you do not wish your anonymised scores to contribute to benchmarking, contact us at privacy@humanityinbusiness.com and we will exclude your data from aggregation.
5.4 Automated decision-making (GDPR Article 22)
The HIBS assessment platform uses automated processing (AI report generation) to produce governance maturity reports from your assessment responses. This processing produces outputs that may inform organisational decisions but does not produce legal effects or similarly significant effects concerning you as an individual.
Reports are advisory tools based on self-assessment data and are not used to make automated decisions about individuals' access to services, credit, employment, or any other matter with legal or similarly significant effect. If you believe automated processing has affected you in a way that engages Article 22 of UK GDPR or EU GDPR, contact us at privacy@humanityinbusiness.com to request human review.
6. Third-party data processors
We share personal data with the following third-party processors where necessary to deliver our services. All processors are subject to data processing agreements and are required to handle personal data in accordance with applicable law.
All processors listed above are located outside the UK/EEA. Transfers to the USA are made under Standard Contractual Clauses or equivalent transfer mechanisms where applicable. Supabase offers EU data residency for platform data — we have configured the HIBS assessment platform to use EU-region storage where available.
7. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. The following retention schedule applies:
When data reaches the end of its retention period it is securely deleted from our systems. Where data is stored with third-party processors, deletion requests are passed to those processors in accordance with our data processing agreements.
7A. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/HTTPS) and at rest where supported by our infrastructure providers.
- Access controls limiting personnel access to personal data on a need-to-know basis, subject to internal confidentiality obligations.
- Authentication mechanisms including password hashing and session management via Supabase Auth.
- Regular review of third-party processor security postures and data processing agreements.
- Row-level security policies on database tables to ensure users can only access their own data.
No system is completely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
7B. Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of UK GDPR / EU GDPR.
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 of UK GDPR / EU GDPR.
- Document the breach, its effects, and the remedial action taken, and make this documentation available to the supervisory authority on request.
If you believe your account or data has been compromised, contact us immediately at privacy@humanityinbusiness.com.
7C. Children's data
Our services are designed for business professionals and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, please contact us at privacy@humanityinbusiness.com.
8. Your rights
Under UK GDPR and EU GDPR you have the following rights in relation to your personal data. To exercise any of these rights contact us at privacy@humanityinbusiness.com. We will respond within one calendar month.
9. Complaints and supervisory authorities
If you have a concern about how we handle your personal data, please contact us in the first instance at privacy@humanityinbusiness.com. We will acknowledge your complaint within 5 working days and aim to resolve it within 30 days.
If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with your supervisory authority:
10. Governing law and jurisdiction
This Privacy Policy is governed by UK GDPR and, where applicable to EEA residents, EU GDPR as implemented in Bulgaria. For the avoidance of doubt, users located in the European Economic Area benefit from the full protections afforded by EU GDPR regardless of the governing law of any commercial agreement.
Disputes relating to this Privacy Policy that cannot be resolved through our complaints process may be referred to the courts of England and Wales (for UK matters) or the competent courts of Bulgaria (for EU/EEA matters), without prejudice to your right to bring proceedings before your local supervisory authority.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, applicable law, or platform features. The current version of this policy is always available at humanityinbusiness.com/privacy.
Where changes are material — for example, changes to the categories of data collected, the purposes of processing, or the third-party processors used — we will notify registered users by email at least 14 days before the changes take effect. Non-material changes (such as clarifications or formatting) may be made without prior notice.
Your continued use of our services after a policy update constitutes acceptance of the updated terms. If you do not accept a material change, you may close your account before the effective date.
12. Contact us
For all privacy-related enquiries, Subject Access Requests, or to exercise any of your rights under this policy:
This Privacy Policy was last updated in June 2026 and supersedes all previous versions. It applies to humanityinbusiness.com and intelligence.humanityinbusiness.com. Registered users will be notified of material changes by email.