Wir verwenden Cookies

    Wir verwenden essentielle Cookies und, mit Ihrer Zustimmung, Analyse-Cookies zur Produktverbesserung. Mehr erfahren ·

    Privacy Policy

    1. Introduction

    Groundwell Labs ("Company", "we", "us") operates the PeopleSighted platform and is committed to protecting the personal data of its users. This Privacy Policy describes how we collect, use, store, and protect your information, in compliance with the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018).

    2. Data we collect

    We collect the following types of data: (a) Registration data: full name, email, password (cryptographic hash), language, and timezone; (b) Organizational data: company name, tax ID, departments, and job titles; (c) Employee data: information entered by the administrator such as name, job title, department, start date, manager, salary, and time-off data; (d) Usage data: access logs, IP address, browser type, and actions performed on the platform; (e) Payment data: processed directly by Stripe. We do not store credit card information.

    3. Legal basis for processing (GDPR/CCPA/LGPD)

    We process personal data based on the following legal bases: (a) Contract performance: to provide the contracted Service; (b) Consent: when you register and accept these terms; (c) Legitimate interest: to improve the Service, prevent fraud, and ensure security; (d) Legal obligation: to comply with tax and regulatory obligations. We do not sell personal data to third parties for commercial purposes, as required by the CCPA.

    4. How we use your data

    We use your data to: (a) provide, maintain, and improve the Service; (b) process payments and manage subscriptions; (c) send transactional communications (invitations, notifications, alerts); (d) provide technical support; (e) generate aggregate reports and analytics (without personal identification); (f) comply with legal obligations. We do not sell, rent, or share your personal data with third parties for marketing purposes.

    5. Data sharing

    We share data only with the following service providers: (a) Supabase: infrastructure and database, with US-based servers and encryption at rest and in transit; (b) Stripe: payment processing, PCI DSS certified; (c) Resend: transactional email delivery; (d) Vercel: application hosting; (e) PostHog: product usage analytics for improvements (aggregate data); (f) Sentry: technical error monitoring for platform stability; (g) Anthropic: supports the Luna assistant for theoretical people management questions (no access to the platform's database). All service providers are contractually required to protect your data to standards equivalent to this policy.

    6. Storage and security

    Your data is stored on secure servers with: (a) encryption in transit (TLS 1.2+); (b) encryption at rest (AES-256); (c) role-based access control (Row Level Security); (d) two-factor authentication available; (e) audit logs for sensitive actions. We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

    7. Artificial intelligence assistant (Luna)

    PeopleSighted includes an AI assistant called Luna, which helps users navigate the platform, generate reports, and get people management tips. Anthropic assists Luna with answers to theoretical and general knowledge questions about people management, but has no access to any data in your database. Information such as employee data, salaries, time off, and reviews is processed exclusively on our servers and is never shared with Anthropic. Luna also generates informational insights for administrators based on organizational data (such as attendance patterns and engagement). These insights are informational suggestions and do not replace human decisions. No automated actions are taken on employees based on Luna's insights.

    8. Data retention

    We retain your data for as long as your account is active. After organization account cancellation, your data is retained for 30 days for possible recovery. After this period, all data is permanently deleted, except where retention is required by law. For employee data managed by the organization, retention follows applicable labor and tax obligations. In Brazil, the labor statute of limitations is 5 years (limited to 2 years after termination for filing claims), and tax and social security obligations may require retention of up to 5 years. Accordingly, former employee data is retained for up to 5 years after the termination date, unless a longer period is required by specific legislation.

    9. Your rights (GDPR, CCPA and LGPD)

    You have the right to: (a) Access: request a copy of your personal data; (b) Rectification: correct incomplete or inaccurate data; (c) Erasure: request the deletion of your data; (d) Portability: receive your data in a structured format; (e) Objection: object to processing in certain circumstances; (f) Withdrawal of consent: withdraw your consent at any time; (g) Information: know with whom your data has been shared. California residents (CCPA): additionally have the right to know what personal data we collect, to request deletion, to opt out of the sale of personal data (we do not sell your data), and to not be discriminated against for exercising these rights. Note on employee data erasure: as PeopleSighted is a people management platform, the organization is the data controller for its employees' data. During the employment relationship and throughout the legal retention period (up to 5 years after termination), the employee cannot request erasure of their data. After the legal retention period has elapsed, former employees may request the deletion of their personal data by contacting: contact@groundwelllabs.com

    10. International data transfers

    Your data may be processed on servers located in the United States (Supabase, Vercel). These transfers are carried out based on standard contractual clauses and adequate safeguards as required by the LGPD and GDPR. We ensure that service providers maintain levels of protection equivalent to those required by applicable legislation.

    11. Cookies and similar technologies

    We use essential cookies for Service functionality (authentication and session preferences). We also use analytics cookies to measure campaign effectiveness and understand how users reach the platform, without creating individual browsing profiles. You can manage your cookie preferences at any time through the consent banner displayed on the platform.

    12. Children's data

    The Service is not intended for individuals under 18 years of age. We do not intentionally collect data from minors. If we become aware that data from a minor has been collected, we will proceed with its immediate deletion.

    13. Data protection officer (DPO)

    For questions related to personal data protection, contact our data protection officer: contact@groundwelllabs.com

    14. Changes to this policy

    We may update this policy periodically. Significant changes will be communicated via email or platform notification with at least 15 days' advance notice. The effective date at the top of this page indicates the current version.

    15. Contact

    For questions, requests, or complaints about this policy, contact: contact@groundwelllabs.com. You also have the right to file a complaint with the National Data Protection Authority (ANPD) in Brazil, the competent supervisory authority in the European Union, or the California Attorney General (for US residents).

    Last updated: 2026-05-21

    Terms of Service →