Who is responsible for your data
Chastre Consulting Unipessoal Lda (Portuguese company number 510564046), registered at Avenida da República n.º 1, 2.º D, 1495-110 Algés, Portugal, is the controller of the personal data described in this policy. It operates the IRT® Leadership Platform, which comprises the public IRT® site and the application where you take the Leadership Snapshot® and work through your Missions, the Toolkit and the Library.
For anything concerning this policy, or to exercise the rights set out under "Your rights", write to anabela.chastre@chastreconsulting.com. We answer within 30 days at the latest.
We have not appointed a Data Protection Officer, because we do not meet the criteria that make one mandatory: we carry out no large-scale systematic monitoring and we do not process special categories of data as a core activity. The address above is read by the company's principal.
What this covers, and what it does not
It covers the public IRT® site and the IRT® application you reach from the community.
It does not cover the Cobuntu platform, where your account lives. That distinction has practical consequences and is not a formality: Cobuntu is independently responsible for your account, your password, your community membership and any payment, and has its own policy. IRT® is responsible for what we describe here, which is the record of your work with the method.
The Cobuntu policy is at https://irt.cobuntu.com/privacy. You need both to have the full picture.
Your account is not ours
IRT® has no sign-up, no password and no user table. We do not store credentials because we never receive them.
When you open IRT® from the community, Cobuntu issues a short-lived, single-use code that our servers exchange for a session. From that exchange we receive a user identifier, and nothing else, unless the community has authorised more:
- your email address, so we can send you the checkpoints of your cycle;
- your name and profile photograph, so the application addresses you rather than a code;
- the language you chose on the platform, so IRT® speaks it too.
Where the community has not authorised one of these, the application still works, with less. We do not ask you for this data directly, nor obtain it any other way.
Internally, everything we hold is keyed to that identifier. No name and no address sit next to your answers: anyone opening our database would see results attached to a code, not to a person.
What we process, and on what basis
The table below is exhaustive as to personal data. Everything IRT® holds about you falls into one of these rows.
| Data | Purpose | Legal basis | How long |
|---|---|---|---|
| User and community identifier | Tie your journey to you and to nobody else | Performance of a contract | For as long as you have access to IRT® |
| Leadership Snapshot® answers (51 statements) and the computed result: State, Readiness, scores per dimension and per competency | Produce your report, select your Missions and let cycles be compared | Performance of a contract | For as long as you have access to IRT®. Comparability across cycles is the product: a deleted result makes the next one unreadable |
| Cycle, assigned Missions, the status of each and the dates | Run the six-month programme | Performance of a contract | For as long as you have access to IRT® |
| Your written reflections: Mission text, evidence, lever consolidation and cycle reflections | They are yours. They exist so you can reread them | Performance of a contract | For as long as you have access to IRT®. See the next section |
| Conversations with MIA, including whatever you write in them | Keep the conversation open between sessions | Performance of a contract | Until you delete them. There is no automatic sweep |
| Files you attach to a conversation | Explain a situation to MIA | Performance of a contract | 30 days, then deleted automatically |
| Email, name, photograph and language from the platform | Send you the checkpoints and render the application in your language | Performance of a contract | The email is deleted 90 days after your last sign-in, where no cycle is active |
| A record that someone opened an Action Plan, in the form of an irreversible code | Count how many distinct leaders looked for a theme, without knowing which ones | Legitimate interest in understanding which themes are sought | For as long as the Action Plan exists |
| Server logs (IP address, timestamp, errors) | Security and fault diagnosis | Legitimate interest in keeping the service running and secure | Held by our hosting providers for short periods, typically up to 30 days |
We process no special categories of data. The Leadership Snapshot® measures leadership behaviours you report about yourself, not health, beliefs, origin or orientation, and it is neither a clinical nor a psychometric instrument. We carry out no profiling with legal effects and no automated decision-making that significantly affects you: the algorithm computes a result and suggests Missions, and nothing in it decides anything about your employment.
What you write is yours
The reflections you write in Missions, the evidence, the lever consolidation and the cycle reflections are treated differently from everything else, deliberately.
This text is never
- analysed, scored or used to change your result;
- sent to MIA or to any artificial-intelligence model;
- included in exports, including those the platform administrator runs;
- visible to your organisation, in any form.
It is stored so that you can reread it, and for no other reason. That separation is written into the code and not only into this policy: the function that assembles what MIA may know about you does not even select those columns, and the administrative export omits them.
The MIA assistant
MIA is a conversational assistant that matches the situation you describe to one of the method's Action Plans. It runs on a language model from Anthropic (Claude), which acts as a processor.
What MIA knows about you
Your State, your Levers, the titles and status of your Missions, and where you are in the cycle. Nothing more. That context is there to choose better, not to assess you.
What MIA never receives
Your written reflections, per the section above, and your Snapshot answers. It receives the computed result, not the 51 answers behind it.
Conversations are stored
A conversation stays available until you delete it. When you delete it, it is genuinely deleted: the messages are removed from the database, not flagged as hidden. We keep no copy.
Anthropic processes the messages to generate the reply and does not use them to train models. There is a limit of 40 messages per 24 hours per person, which exists to protect a shared balance and not to police you.
Your organisation does not see these conversations. There is no path in the product between what you write to MIA and anything a company can consult. See the section on organisations.
Files you attach, and the people in them
You can attach images, PDFs, Word and Excel files to a message for MIA. These are often 360-degree feedback reports, messages from colleagues or internal documents, which is to say data about other people who are not here and who agreed to nothing.
So this part has rules of its own:
- files are held in a private store in the European Union (Frankfurt region) and are not reachable by URL: every read is checked against the owner;
- they are deleted automatically 30 days after upload, by a daily process, whether the conversation continues or not;
- images and PDFs are sent to the model to answer the message you attached them to, and are not re-sent with later messages;
- Word and Excel files are never sent to the model. We extract the text on our own server and it is that text that travels, stored inside the message;
- reopening an older conversation shows an expired-file marker where the image was. That is correct behaviour, not a fault.
Please do not attach anything you would not show the person concerned, and remove names where the question does not need them. In attaching a document about third parties, you are the one deciding to share it with us, and that responsibility is yours. What we limit is what we do with it, and for how long.
If your employer enrolled you
When an organisation enrols a group of leaders, it buys a programme and receives a collective reading. What it can see is strictly this:
- how many people are enrolled and how many have taken the Snapshot;
- the distribution of States and the group's averages per dimension and per competency;
- which themes were most sought in the Toolkit, counted in distinct leaders.
What the organisation never sees
- any individual's result, State or scores;
- which Missions you were given, or anything you wrote in them;
- your conversations with MIA, what you asked, or which Action Plans you opened;
- a list of participants with results beside their names.
This is not filtering at the edge: the aggregate is computed without ever assembling a row per person. On top of that, statistics appear only from 5 assessed participants upwards. Below that, the organisation is told the group is too small and sees no figures, because in a group of three any average identifies the people in it.
Toolkit theme counts are computed over an irreversible code derived from your identifier with a secret key. It supports saying that ten distinct leaders sought the same theme; it does not support saying who, not even for someone holding the database without that key.
Emails we send you
Where we have your address, we send you the checkpoints of your cycle: the milestones at 30 and 90 days, the reassessment notice at 180, a reminder when a Mission has been idle for three weeks, and a nudge after two weeks of inactivity. They are part of the programme, not marketing, and IRT® sends you no promotions and no newsletters.
Delivery is through Resend, our transactional email provider.
The address is deleted from our database 90 days after your last sign-in, if no cycle is active at that point. We keep a copy of your email only while it is good for something. The rest of the record, which is anonymous, remains.
Cookies
IRT® uses no analytics cookies, no advertising cookies and no third-party cookies. There is no Google Analytics, no social pixel and nothing that follows you between sites. We use two cookies, both strictly necessary, which is why we do not ask you to consent to them:
| Cookie | Where | Purpose | Lifetime |
|---|---|---|---|
| irt_session | Application | Keep you signed in. Not readable by JavaScript, and holds nothing about you beyond the identifier | 11 hours |
| NEXT_LOCALE | Public site | Remember the language you picked, so it does not revert on each visit | 1 year |
The Cobuntu community, being a different service, has its own cookies and its own preferences control, described in its policy.
Who we share with
We do not sell personal data, we do not pass it to advertising intermediaries, and we do not share it with anyone outside this list. The providers below process data on our behalf under processing agreements:
| Provider | Purpose | Where |
|---|---|---|
| Vercel | Hosting the applications and the private attachment store | European Union (Frankfurt) for attachments; United States for platform operations |
| PostgreSQL database provider | Storing everything in the table above | European Union |
| Anthropic | Generating MIA's replies | United States |
| Resend | Sending the cycle emails | United States |
| Cobuntu | Identity and community membership, as an independent controller and not as our processor | European Union |
We may also disclose data where the law requires it, on a reasoned request from a competent authority.
Transfers outside the European Union
Anthropic, Resend and part of Vercel's operations are in the United States. Those transfers rely on the Standard Contractual Clauses approved by the European Commission, together with the technical measures those providers document. Attachments, the most sensitive category, were deliberately placed in a European region.
How long we keep things
The periods are in the data table above. In summary, soonest to expire first:
| What | Period | How |
|---|---|---|
| Signed-in session | 11 hours | The cookie expires |
| Files attached to MIA | 30 days | Deleted by an automatic daily process |
| The copy of your email | 90 days without signing in, no active cycle | Deleted by the daily sweep |
| Conversations with MIA | Until you delete them | Your call. There is no deadline |
| Results, cycles, Missions and your reflections | For as long as you have access to IRT® | Deleted on request, or when you lose access and ask |
Leaving the community does not by itself delete your IRT® history, because someone who comes back expects to find their journey where they left it. If you want it deleted, just ask, and we do not have to ask why.
Your rights
Under the General Data Protection Regulation you have the right to:
- know what data we hold about you and obtain a copy;
- have inaccurate data corrected;
- ask for erasure;
- receive your data in a machine-readable format, or have us send it to another organisation;
- restrict processing while a challenge of yours is being considered;
- object to processing based on our legitimate interest, which in this policy is only the theme counts and the server logs.
Write to anabela.chastre@chastreconsulting.com. We answer within 30 days and charge nothing, except for manifestly repetitive requests. We may ask you to confirm your identity before handing data over, which is there to protect you rather than to delay you.
Some things need no request: deleting a conversation with MIA is done in the application itself, and takes effect immediately.
If you believe we have not handled a matter properly, you may complain to the Comissão Nacional de Proteção de Dados (CNPD), Portugal's supervisory authority, at https://www.cnpd.pt. If you live in another European Union country you may go to your own country's authority.
Your account, password and membership data belong to Cobuntu, and rights over those are exercised with them, at https://irt.cobuntu.com/privacy.
Security
The measures that matter, concretely:
- all traffic is encrypted in transit, and the database and file store are encrypted at rest by the providers;
- the session cookie is not readable by JavaScript, so an injected script cannot take it;
- your standing in the community is checked on every request rather than cached in the session, so a removal takes effect on the next page load and not hours later;
- attachments live in a private store and every read verifies ownership, rather than relying on an address being hard to guess;
- the platform API key exists in a single service, and the applications you use do not hold it.
No system is impregnable. If a data breach occurs that is likely to result in a high risk to you, we will tell you and the authority within the statutory deadlines.
Minors
IRT® is intended for professionals in leadership roles and is not directed at anyone under 18. We do not knowingly collect data from minors. If we learn that we have, we delete it.
Changes to this policy
When this policy changes, the date at the top changes with it. Where a change is substantial, a new processor or a new purpose for instance, we will say so in the application or by email before it takes effect.
The Portuguese version is the authoritative one. This English version is provided for convenience and, where the two diverge, the Portuguese prevails.