Privacy Policy
teique.com
Effective Date: 20 August 2026 | Version 2.0
teique.com
Effective Date: 20 August 2026 | Version 2.0
1. START HERE
1.1 This policy explains what London Psychometric Laboratory Ltd. does with personal data.
1.2 Find yourself below and read the parts listed.
I was asked to complete an assessment by a coach or my employer.
Read parts 2, 3, 4, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18 and 19.
I bought something for myself.
Read parts 2, 3, 5, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18 and 19.
I administer assessments to others.
Read parts 2, 3, 6, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18 and 19. Part 7 explains what we ask candidates; none of it reaches you.
Somebody has invited me to take a compatibility assessment with them.
Read 5.8.1 first, then parts 2, 3, 10, 11, 12, 13, 14, 15, 16, 17, 18 and 19. If you accept, read parts 5, 7, 8 and 9 as well.
I am just visiting the website.
Read parts 2, 3, 10, 11, 12, 13, 14, 15, 16, 17, 18 and 19.
1.3 This policy covers teique.com. Researcher Accounts on psychometriclab.com have that site's own privacy policy and Data Processing Schedule; you give your participants notice.
1.4 Part 3 is in every list: parts 10 and 16 turn on our role.
1.5 We are established in the United Kingdom and the UK GDPR and the Data Protection Act 2018 apply to everything in this policy. Where we offer the platform to people in the European Economic Area, the EU GDPR applies to that processing as well. The two are materially the same, and every reference in this policy to an Article of the UK GDPR is a reference to the corresponding Article of the EU GDPR where that Regulation applies. Wherever this policy names the Information Commissioner's Office, an EEA reader should read it as their own supervisory authority as well (10.8). We have not appointed a representative in the Union, Article 27(2) applying. Write to support@teique.com about anything in this policy and we will answer you.
2. WHO WE ARE
2.1 London Psychometric Laboratory Ltd. ("LPL", "we", "us") is registered in England and Wales.
| Company registration number | 07447169 |
|---|---|
| ICO registration reference | ZC211337 |
| Registered office | 27 Old Gloucester Street, Holborn, London WC1N 3AX, United Kingdom |
| support@teique.com | |
| Data Protection Contact | support@teique.com, marked for the Data Protection Contact |
2.2 We publish psychometric assessments, including the TEIQue, and operate the platform.
2.3 We have not appointed a Data Protection Officer. Our Data Protection Contact, above, answers data protection queries, and we keep the need for a Data Protection Officer under review.
3. THE DIFFERENT ROLES WE PLAY
3.1 A controller decides what happens to personal data. A processor acts on the controller's instruction.
3.2 Our role depends on how the data reached us.
| The data | Who decides what happens to it | Our role |
|---|---|---|
| Your answers and report, where a coach or organisation asked you to be assessed | That coach or organisation, the organisation whose account they work inside, or the organisation that engaged them (4.2) | Their processor, or their processor's processor |
| Your account, answers and reports, where you bought the assessment yourself | Us | Controller |
| Background information you give us, including sensitive information | Us | Controller |
| Answers you agree to contribute to our research | Us | Controller |
| Account and billing records for coaches and organisations | Us | Controller |
| Security, audit and licence compliance logs, including session and IP records | Us | Controller |
| The email address of a person you invite to a compatibility assessment, before they accept | Us | Controller |
3.3 Where a coach or employer asked you to complete an assessment, they decide how your results are used and for how long (part 4).
3.4 Background information and research contributions are asked for on our own behalf and not passed to whoever invited you (parts 7 and 8).
4. IF YOU WERE ASKED TO COMPLETE AN ASSESSMENT
4.1 This part applies if a coach, employer, or organisation invited you through a guest account.
##### Who is responsible for your data
4.2 The coach or organisation that invited you is the controller: they decide why you were assessed, on which instrument, what happens to your results, and for how long. Where the person who invited you works inside an organisation's account, or was engaged by an organisation that chose to assess you, that organisation is the controller (4.10).
4.3 We process your responses on their instruction, not for our own purposes, apart from parts 7 and 8.
##### What we hold
4.4 Your first name, last name and email address, supplied by whoever invited you; your answers and report; and session records: sign in and sign out times, actions taken, and your IP address.
##### What they can see
4.5 They can see your individual answers, not only your report, and can download them.
4.6 Background information under part 7 is not included; it is held by us alone.
##### Each questionnaire has its own guest account
4.6.1 Each questionnaire has its own sign in link and guest account. We hold no profile of you spanning them; their candidate profile is the record that does.
##### How long your guest account lasts
4.7 Your guest account runs on the schedule at part 12, extended while a research withdrawal window is open (8.9.2). It then closes: no sign in, no report, no support.
4.8 Closing your guest account does not delete their copy. An account unused for 60 months is deleted automatically unless they have agreed a longer period with us in writing (part 12). To remove your answers, ask them (4.10).
4.8.1 If they close their account, the candidate profiles, answers and reports in it are deleted, including yours. What remains is the security and audit logs at part 11, any anonymised research record you contributed under part 8, which no longer identifies you, the separated copy of the date of birth at 7.14, which identifies nobody, a copy in our offline archives on the schedule at 12.1 to 12.4.3, and anything the law requires us to keep.
##### Getting a copy, or asking questions
4.9 Where they allow it, we email your report on completion and you can re-send it while your guest account is open (4.7).
4.10 To see, correct or delete your data, contact whoever invited you, or the organisation whose account they work inside. If you do not know who, ask us; we will not make the request for you. If you contact us instead, we tell them that you asked and when, so that they can answer you. We do not do that for the background information at part 7, your research contribution at part 8, or the logs at part 11: on those we answer you ourselves and do not tell them you asked.
5. IF YOU BOUGHT SOMETHING FOR YOURSELF
5.1 This part applies if you hold a Personal Account and bought for your own use.
##### Who is responsible for your data
5.2 We are, unless you involve a coach or organisation.
##### What we hold and why
| What | Why | Our lawful basis |
|---|---|---|
| Name, email address, account details | To create and run your account | Our contract with you |
| Your answers and reports | To produce what you bought | Our contract with you |
| Billing details: name or organisation name, billing address, VAT number | To take payment and issue a valid invoice. UK law requires it to show your name and address | Our contract with you, and legal obligation |
| Invoice and purchase records: what you bought, when, amount, VAT | Proper accounting records | Legal obligation |
| A payment reference from our provider, and usually the card brand and last four digits | To match payments, refund, and investigate disputes | Our contract with you |
| Support correspondence and call recordings | To answer you, keep a record, and train staff | Our contract, and our legitimate interest in a support service |
| Session records, sign in events and IP address | Platform security and investigating problems | Our legitimate interest in platform security |
| Marketing emails, if you ask for them | To send what you asked for | Your consent, withdrawable at any time |
| A record that you asked for marketing and that you stopped | To honour your withdrawal and show what you asked for | Our legitimate interest in not contacting you again |
5.2.1 Do you have to give us this? Your name and email address are required by our contract with you: we cannot open an account or deliver what you buy without them. Your billing details are required by UK invoicing and tax law: we cannot issue a valid invoice, and so cannot sell to you, without them. Nothing else in the table above is required. Part 7 states which background fields are required and which are optional. Marketing emails come only if you ask. The session records, invoice records and payment reference above are created by your use of the platform and by your payment, and are not asked for. Part 7 covers the background information and what happens if you decline it.
5.3 Calls may be recorded where we call you or you call a number we gave you. We say so at the start and you can decline. Recordings answer your query, keep a record, and train staff.
##### Your reports
5.4 Reports stay in your account while it is active and are deleted with it.
5.4.1 Some reports are made from a background questionnaire and cannot be produced without the required fields in it (7.9.1). We tell you before you pay.
5.5 You may share your own report with any adviser. This policy does not restrict that.
##### If you buy a compatibility assessment
5.6 You and one other person each complete an assessment and receive your own report, not the other's.
5.7 You both also receive a compatibility report. It tells each of you something about the other, so both must agree before release. Our basis is the contract each enters with us.
5.8 We hold the other person's email address to deliver your invitation, on our legitimate interest in delivering it. If they decline or do not respond within the period in the Personal Account Terms, nothing is released.
5.8.1 If you received an invitation to a compatibility assessment, this paragraph is for you. The email inviting you links to it. If you accept, a compatibility report is placed in both accounts. Deleting your account later removes your own report and your own data, but does not remove the compatibility report from the other person's account: 5.9 explains why, and you should read it before you accept. We hold your email address only because the person named in the invitation gave it to us in order to invite you. Our basis is our legitimate interest in delivering the invitation. If you decline, or do not respond within the period at clause 6.7 of the Personal Account Terms, we delete it on the schedule at part 12. Your rights are at part 10, and you can write to support@teique.com at any time.
5.9 The compatibility report stays in your account if the other person deletes theirs. Once their contract has ended, our basis is our legitimate interest in a complete record of your purchase. Their report and data go with their account.
6. IF YOU ADMINISTER ASSESSMENTS TO OTHERS
6.1 This part applies to Coach, Business and Enterprise Accounts and Coach Sub-Accounts. Under an Enterprise Account the Enterprise controls your candidates' data and you act on its instruction: 6.2 does not apply; 6.3 applies; 6.4 and 6.5 apply except as to billing, of which you have none.
##### Two different sets of data
6.2 Your candidates' data. You are the controller, we are your processor. You decide who is assessed, why, and what happens to the results. The terms are in our Data Processing Agreement, required by Article 28 of the UK GDPR.
6.3 Your own account data. We are the controller: name, email, organisation name, accreditation status, correspondence, technical logs, billing details.
6.4 Billing details means your name or organisation name, billing address, VAT number, invoice and purchase records, and a payment reference, held to take payment, invoice, and keep accounting records.
6.5 Our basis is our contract with you, our legal obligations in tax and company law, and our legitimate interest in operating securely.
##### What you are responsible for
6.6 As controller you must inform candidates, have a lawful basis, and answer their requests. That Schedule sets out how those sit with our processor role.
6.6.1 Do you have to give us this? Your name, email address and organisation are required by our contract with you: we cannot open or run an account without them. Your billing details are required by UK invoicing and tax law. Your accreditation status is a condition of the access we grant. Nothing else we ask for is required.
6.7 If a candidate contacts us about their answers or their report, we tell them who the controller is and that the request goes to them, we do not forward or answer it, and we tell you that the request was made, when, and which candidate made it. In a sub-account the controller is the organisation. This does not apply to the data we hold as controller under parts 7, 8 and 11, on which we answer the candidate directly and do not tell you they asked.
##### What we do not give you
6.8 Background information we ask a candidate for, optional or required, is asked on our own behalf. None of it is shown to you: held on our servers only, not stated, itemised, or otherwise made identifiable in anything you receive, and not available on request. It may inform which norm group a Candidate's scores are read against and how the report is written, and clause 5.4 of the Assessment Participant Terms applies.
6.9 We ask every candidate and never tell you what they said or whether they agreed; nothing appears in your account, any report, or any export.
##### Sub-processors and security
6.10 We use a small number of service providers, by function at part 13; a list naming each is available from support@teique.com.
6.11 Our technical and organisational security measures are described on request.
7. BACKGROUND INFORMATION
7.1 Some assessments ask for background information. It is asked separately and never shared with a coach or organisation. Every sensitive question offers "prefer not to say". What stops a report is at 7.9.1.
##### What we ask, and when
7.2 Background information is asked for in two places.
A career and development report asks two different things, for two different reasons.
The three required fields are your date of birth, your highest level of education completed, and what you want the assessment for. We use these to produce your report, and it cannot be produced without them (7.9.2).
Everything else is optional. We ask about your gender identity, your ethnicity, your nationality, the languages you speak, your disability status, your employment type and management level, your field of study, and your industry, organisation size, years of experience and number of direct reports. We use these to tailor your report to you, including by comparing your scores against the norm group most relevant to you, so that the feedback you get is about people in your situation. Where you separately agree to contribute to our research programme, part 8 also applies to them. Skipping any of them affects only how closely the report is tailored.
7.2.1 Our basis for every optional field at 7.2 is your consent, under Article 6(1)(a), and for those at 7.4 and 7.4.1 your explicit consent, under Article 9(2)(a) as well. Withdrawing it is at 7.13.
7.2.2 Answering these questions does not build our comparison norms; it selects which of them your scores are read against. Norms are built from research contributions only. Where you agree at part 8 to contribute, your answers in this part form part of that contribution, on the separate consent at 8.3, and are then used as part 8 describes.
Our research questionnaire is described at part 8.
##### Sensitive information
7.3 Some of what we ask is sensitive under data protection law and needs your explicit permission.
7.4 The sensitive categories asked about in this part are health, including disability status and ethnic or racial origin. Our research questionnaire may also ask about religious or philosophical beliefs and political opinions; part 8 governs that, and this part does not ask about either.
7.4.1 We also ask about your gender identity and the languages you speak. Data protection law lists neither as a sensitive category. We treat both as sensitive: asked behind the permission screen at 7.6, each with a "prefer not to say", and held on the basis at 7.2.1; 7.7 covers the case where a question is not special category data in your case. Clause 7.9 applies to them.
7.5 We do not ask about or hold sexual orientation, sexual life, genetic data, biometric data, trade union membership, or criminal records.
##### How we ask
7.6 Before any sensitive information is collected, a separate screen names the categories, explains why, asks your explicit permission, and tells you how to withdraw it, unbundled from other consent. The optional questions outside 7.4 and 7.4.1 are asked on a screen that states that answering one is your consent, that you may leave any of them blank, and how to withdraw at 7.13. The required non-sensitive fields at 7.9.2 are asked on their own screen, on the basis at 7.9.2 and not on your permission. They are put to you whether you give that permission or refuse it, so refusing never costs you your report.
7.7 Where a question at 7.4.1 turns out not to be special category data in your case, Article 6(1)(a) alone is our basis for it and we treat it the same way regardless.
##### You can say no
7.8 Every sensitive question is optional. Each offers "prefer not to say", and we never ask for a reason.
7.9 Saying "prefer not to say" still gets you your report. The parts designed to use that information are written without it, so the report is less tailored. Nothing is withheld or charged.
7.9.1 What stops a report is our not receiving the required fields at 7.9.2: not opening that screen, not submitting it, or leaving them blank. Nothing you decide at the consent screen affects it.
7.9.2 Three background fields are required, and no others: your date of birth, your highest level of education completed, and what you want the assessment for. They are ordinary details, are not sensitive, and are not among 7.4 or 7.4.1. We hold them to produce your report. Where you agree at part 8 to contribute, they form part of that contribution on the consent at 8.3. Clause 12.4 states the one further purpose for which a copy remains in the archive, and clause 7.14 the one copy of the date of birth that outlives deletion. Everything else the questionnaire asks is optional, and skipping any of it changes nothing about your report except how closely it is tailored to you. They are asked on their own screen, before or after the consent screen at 7.6 and independently of it. The report cannot be produced without them, and you do not consent to them. Where you bought the report our basis is our contract, Article 6(1)(b); where somebody else ordered it, our legitimate interest in an accurate report, Article 6(1)(f).
7.10 Where we do not receive the required fields at 7.9.2 and a coach or organisation sent the assessment, the assignment stays pending fourteen days then expires; they can cancel or resend, and you can complete the required fields while your guest account is open. Where you bought it yourself it stays on your account while that account is open. Leaving those fields blank is not a ground for refund: clauses 3.5, 3.5.1 and 10.4.1.1 of the Personal Account Terms.
7.10.1 We do not tell them what you answered or what you decided at the consent screen. Our terms with them state that where an assessment was completed and no report was produced, the cause is the required fields at 7.9.2 not being received, so the absence of a report tells them that and nothing more.
7.11 Your standard assessment and its report are unaffected (4.9).
##### Who sees it
7.12 We do. It is never disclosed to a coach, organisation or partner, is never stated, itemised, or otherwise made identifiable in anything a coach or organisation receives, and sits on the infrastructure at part 13 (13.5). It may inform which norm group your scores are read against and how your report is written (7.2), and clause 5.4 of the Assessment Participant Terms applies.
##### Withdrawing
7.13 Withdraw at any time while we hold the information. If you have a personal account, use the withdrawal control in your account settings: withdrawing is as easy as giving permission was. If you took the assessment as a guest, write to support@teique.com and we withdraw it for you; a guest account has no withdrawal control. Withdrawing removes your answers to the questions at 7.4 and 7.4.1 and nothing else: the required fields at 7.9.2 are not held on your permission and are unaffected, and your other answers, your other reports and your account are untouched. Where your report is designed to take account of that information, it is produced, or produced again, without the benefit of what you withdrew (7.9), at no charge, and you do not lose it. You can withdraw until it is destroyed on the schedule at part 12; for a research contribution, part 8 governs. Withdrawal reaches everything on the live platform at once. One copy may remain in the offline archive at 12.1 to 12.4.3. We do not use that copy to recover your background information, and we keep it only where we need it to establish, exercise or defend a legal claim, which is the condition in Article 9(2)(f) of the UK GDPR and, where the data is not special category, our legitimate interest under Article 6(1)(f). If we ever restore from an archive, the restore brings the whole copy back, and a withdrawal is not repeated by itself: nothing in the restored data records that you withdrew, so the answers may come back. A restore happens only in a disaster recovery, we explain what it involved at the time, and you can withdraw again at any point and we will carry it out (12.4.3). It is destroyed on the schedule at 12.3.
##### One thing we keep permanently
7.14 This applies to reports made from the background questionnaire, and only to those. They are the only reports we ask a date of birth for. When we issue one, we keep the date of birth given for it, permanently. Nothing goes with it. Not your name, not your email address, not your account, not the report, not your answers, not your scores, and nothing recording which report it came from. What we hold is a list of dates.
7.14.1 Before we issue a report of that kind we check the date given for it against the list. If it is one we already hold, the report is paused and checked before it goes out, so that the same report is not issued twice. Reports of any other kind are not checked, because no date of birth is given for them and there is nothing to check. That check is the only thing the list is used for. It is internal. We do not publish it, it is not part of the research programme at part 8, it is not used for statistics or research of any kind, and it goes to nobody outside LPL Ltd.: not to a coach, an organisation, a partner or an outside researcher.
7.14.2 The copy is separated when the report is issued and is held apart from the platform. No process links it to a platform record, and we hold no key and no mapping back to one. It is ordered by the date itself, not by when reports were issued, and it carries no timestamp. The check at 7.14.1 is automatic and matches a date against dates: it tells us that a date has been seen before, and nothing about whose it was. Once separated, no row in it is yours: it is a date, and nothing in it says whose. So a request to see, correct, export or delete your data finds nothing in it to act on. Separating and keeping the date is still something we do with your date of birth: 7.14.3 states our basis and 7.14.3.1 your right to object to it.
7.14.3 Checking and keeping are two things, and they rest on different parts of the law. Checking the date given for your report against the list, where your report is one of that kind, is necessary in order to provide that report, because the check is what stops the same report being issued twice: Article 6(1)(b) of the UK GDPR. Keeping the list, so that later reports can be checked against it, is our legitimate interest in issuing reports correctly: Article 6(1)(f), and 10.4.1.1 lists it. Neither rests on your consent. You are not asked to agree to it, and withdrawing a consent does not reach it.
7.14.3.1 You can object to our keeping the list, and we tell you now that we will refuse. The right to object at 10.4.1 applies, because keeping the list rests on legitimate interests. We consider every objection and answer it in writing with our reasons. But the reason we would give is the same in every case and has nothing to do with you: the list is the only thing that stops a duplicate report going out, it protects everyone's reports and not only yours, and taking one date out of it defeats the check for everybody. We say this here rather than let you find it out by writing in and being turned down.
7.14.4 Your date of birth on the platform is unaffected by this. It is still a required field at 7.9.2, held for the purposes stated there, covered by everything part 10 gives you, and deleted with your account or your candidate profile on the schedule at part 12. The separated list is the only thing that outlives that deletion, and it outlives it because there is nothing in it to delete on anybody's behalf.
7.14.5 This applies to reports issued on or after the Effective Date of this policy. We do not go back over reports issued before it.
8. OUR RESEARCH PROGRAMME
8.1 We run the research programme behind our instruments: validity checking, the comparison norms your results are scored against, including country and regional norms, and published research.
8.1.1 Findings are published in academic journals and other scholarly outlets at group level, and never identify anyone.
##### We ask separately, after you finish
8.2 We ask about contributing only after you complete an assessment, so it cannot affect your answers.
8.3 The request has two steps: whether to take part at all, and, only if you say yes, explicit permission for the sensitive categories. You can accept the first and decline the second. The sensitive categories in the research questionnaire are health including disability status, ethnic or racial origin, religious or philosophical beliefs, and political opinions, together with the questions at 7.4.1. We also ask about your marital status. Data protection law does not list it as a sensitive category. We treat it as one, so it is asked behind the same permission and never outside it.
8.3.1 We ask again each time and keep no record of your saying no: no preference or flag, on our servers or in your browser, and nothing reads our security logs.
8.3.2 With a Personal Account, once you have agreed we do not ask again about taking part (8.7, 8.7.1).
8.4 Our basis is your consent, and for the sensitive categories your explicit consent, under Article 6(1)(a) and Article 9(2)(a).
8.4.1 Consent is given by agreeing and then completing the research questionnaire. Agreeing alone contributes nothing, so there is then nothing to withdraw.
##### What we keep
8.5 The research record is a copy of your assessment responses, together with your answers to the questions at part 7 reduced to broad categories rather than as you gave them, held as one record. Your name and email are not part of it. Until it is anonymised it carries a withdrawal reference, so that we can find it, show it to you and destroy it if you withdraw (8.9). That reference is destroyed at anonymisation. After anonymisation no identifying field remains in it and the creation date is scrambled.
8.6 The record is then irreversibly anonymised. We hold no key and no mapping back to you. The corpus is held separately from the live platform and no process links a research record to a platform record. The corpus as a whole runs to thousands of cases. The comparison norms derived from the corpus are used on the platform to score reports (7.2, 8.1); they are group level and contain no individual record.
8.6.1 Nobody outside LPL Ltd. and the hosting provider engaged under part 13 can reach the corpus. The comparison norms derived from it are unpublished and are our property; published findings are group level and contain no individual record.
8.6.2 Inside LPL Ltd., research roles hold no access to the live platform and no route to it. Staff who operate the live platform hold no credential for the corpus and cannot retrieve an individual record from it. Access to each is logged.
8.6.3 We do not attempt to match a research record to an account, and doing so would be a breach of our own rules rather than a use the data permits.
8.6.4 We have assessed identifiability against the standard the Information Commissioner applies, and on the measures and controls at 8.5 to 8.6.3 taken together the record is not personal data. The assessment is written up and available from support@teique.com. Part 12 states that the record is kept indefinitely.
8.6.5 Anonymisation happens fourteen days after you contribute; that window is what a withdrawal under 8.9.1 reaches. A button after you submit anonymises your contribution straight away instead, and there is then nothing to withdraw.
##### If you have a Personal Account
8.7 If you agree, your account is marked as contributing and future assessments contributed without our asking. You can switch it off in settings at any time (8.9).
8.7.1 The mark covers your assessment answers and your answers to the questions at part 7 outside 7.4 and 7.4.1. Every time an assessment asks the questions at 7.4 or 7.4.1 we ask your explicit permission again, for that assessment (8.3).
8.8 Switching it off is a withdrawal, not a setting for future assessments only (8.9.1), and cannot reach anonymised records.
##### Withdrawing
8.9 Withdraw by the link we email after a contribution, the button in your guest account while open, or, with a Personal Account, the switch in settings. A contribution anonymised straight away under 8.6.5 cannot be withdrawn.
8.9.1 Withdrawing revokes your consent. Anything waiting to be anonymised is discarded and nothing further is contributed. A withdrawal covers whatever your consent covered: one questionnaire, or, with standing consent, every assessment you take.
8.9.2 Otherwise you have fourteen days from contributing, and the email gives the end date. Your guest account and withdrawal link each run fourteen days and each holds the other open.
8.9.3 Before removing anything, we show you what the withdrawal covers and ask you to confirm.
8.9.4 Once anonymised, neither you nor we can find or remove a contribution (8.6).
8.9.4.1 A withdrawal is a deletion you asked for, so 12.4.3 applies to it: if we restore from an archive taken before you withdrew, the contribution may come back, because nothing in the restored data records the withdrawal. Withdraw again and we carry it out.
8.9.5 You can also write to support@teique.com.
##### Nobody is told what you decided
8.10 We do not tell a coach or organisation whether you agreed or declined; it changes nothing in your report.
##### It survives account deletion
8.11 Anonymised research records survive deletion of your account: they no longer identify you.
9. HOW REPORTS ARE PRODUCED
9.1 Reports are generated automatically: answers scored by software, report assembled from that scoring. No person reads them.
9.2 Scoring your answers and assembling your report is profiling: automated processing that evaluates personal characteristics. It is not automated decision making producing legal or similarly significant effects about you.
9.3 Our terms forbid account holders to use a report, or let it be used, as the sole basis for a recruitment, selection, promotion, disciplinary or termination decision, as a mechanical cut off, or as an input to automated decision making without meaningful review by a suitably qualified person, and require them to bind anyone they share it with to the same restriction. Send your own report to someone yourself and that restriction does not travel with it.
9.4 If you believe a decision breached that, tell us and the organisation concerned.
10. YOUR RIGHTS
10.1 Where we are the controller (part 3), you have the following rights.
| Right | What it means |
|---|---|
| Access | To be told whether we hold data about you, and to receive a copy |
| Rectification | To have inaccurate data corrected |
| Erasure | To have your data deleted, in the circumstances the law allows |
| Restriction | To have us stop using your data while a question about it is resolved |
| Portability | To receive data you gave us in a structured, commonly used, machine readable format, and have it sent to another organisation where feasible |
| Objection | To object to processing carried out on the basis of legitimate interests |
| Withdraw consent | Where we rely on your consent, to withdraw it at any time. This does not affect processing already carried out |
10.2 To exercise them, write to support@teique.com. There is no charge.
10.3 We respond within one month, extended by up to two months for complex requests, and tell you if so.
10.4 We may ask you to confirm your identity before we act.
10.4.1 Your right to object. Where we process your data on the basis of our legitimate interests, you have the right to object at any time, on grounds relating to your particular situation. Write to support@teique.com. If you object we stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend a legal claim. We tell you which.
10.4.1.1 We rely on legitimate interests for: platform security; the logs at part 11; operating securely (6.5); delivering a compatibility invitation; running our support service; holding the required background fields at 7.9.2 where somebody else ordered your report; keeping a complete record of your purchase (5.9); showing what we told someone (19.4); keeping archived background information to establish, exercise or defend a legal claim (7.13, 12.4); keeping the separated list of dates of birth, so that a report made from the background questionnaire and given a date already on it is paused and checked before it goes out (7.14, and 7.14.3.1 on objecting); transferring the business as a going concern (13.6); and keeping a record that you asked for marketing and stopped (part 12).
##### Where we are not the controller
10.5 Where a coach or organisation asked you to complete an assessment, they are the controller of your answers and your report, and rights over those you exercise against them, not us (4.2, 4.10). We remain the controller of the background information you gave us (part 7), of any research contribution you made (part 8), of the security, audit and licence compliance logs we hold about your use of the platform (part 11), and of an invitation email address held under 5.8.1. For those, write to support@teique.com and we answer you ourselves.
##### Complaining
10.6 If you are unhappy with how we handled your data, tell us first.
10.7 You can also complain to the Information Commissioner's Office, the UK supervisory authority for data protection.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113
ico.org.uk
10.8 If you are outside the United Kingdom you may complain to the supervisory authority of the country you live or work in, or where the matter arose, instead of or as well as to the Information Commissioner's Office. In Rwanda that is the National Cyber Security Authority.
11. WHAT WE COLLECT AUTOMATICALLY
11.1 Our servers record the following whenever anyone uses the platform.
| What | Why |
|---|---|
| The IP address your device connects from | Security, fraud prevention, investigating problems, evidence of your country for VAT, evidence of who accepted our terms and from where, and checking a coach or organisation administers assessments inside its licensed territory |
| Sign in and sign out events, and actions taken in an account | Security and audit trail |
| Browser and device type | Making the platform work on your device |
| Timestamps | Security and audit |
11.2 Our basis is our legitimate interest in security, preventing misuse, and investigating problems. Where an IP address is evidence of your country for VAT, our basis is legal obligation.
11.2.1 We license by territory, so we record the country a connection came from to check a coach or organisation works inside it, on our legitimate interest in enforcing that licence.
11.2.2 We record your IP address and time whenever an account holder accepts our terms, or confirms at sign in that they have read this policy, as evidence of who accepted or confirmed which version and from where, on our legitimate interest in showing agreement.
11.2.3 We derive the country of a connection from the DB-IP Lite database, made available by DB-IP under the Creative Commons Attribution 4.0 International Licence (CC BY 4.0), and hold no other location data.
11.3 An IP address places a connection no more precisely than a city. We collect no precise or device level location data, and do not track you.
11.4 Session records are held separately from your name and email but are linked to the account that invited you and to your candidate profile. We cannot promise that link is broken until they delete that profile.
12. HOW LONG WE KEEP THINGS
| What | How long |
|---|---|
| Guest accounts | 14 days from issue, restarting on each sign in, never more than 30 days from issue before completion; then 14 days from completion, extended while a research contribution is within its withdrawal window (4.7, 8.9.2) |
| Archived reports left after a candidate profile is deleted | Until the coach or organisation deletes them, and automatically with their account after 60 months of inactivity |
| Account data, assessment responses and reports | 60 months from the last sign in, then deleted automatically. We email at least 30 days before; signing in restarts the 60 months. Account holders can set a shorter period, and a commercial account holder can agree a longer one with us in writing |
| Deleted candidate profiles | Your reports and identifying data are deleted, your reports regenerated from your answers with nothing identifying you, and your answers then deleted. What is left is an archived report naming nobody, which we cannot connect to you. The coach or organisation keeps it and can delete it, and may recognise it from their records (4.10) |
| Cookies and similar technologies | Essential cookies last for your session or up to 12 months. Analytics and marketing cookies last no more than 12 months from being set, and are deleted if you withdraw your agreement |
| Marketing subscription records, including your consent and any withdrawal of it | Until you withdraw, then 24 months as evidence of what you asked for and when you stopped |
| Billing and accounting records | As long as tax and company law require, and as long as we may need them to establish, exercise, or defend a legal claim. These records survive deletion of your account |
| Invitation records where a compatibility invitee declines or does not respond | Within 30 days of the invitation being declined or lapsing |
| Support correspondence and call recordings | 60 months from the last message or call |
| Security, audit and licence compliance logs, including session and IP records | 12 months from the date recorded, on their own schedule, and not deleted when a guest account closes. Separately from these logs, your account records the date you last signed in, from which the 60 month period above runs |
| Background information, including sensitive information, where a coach or organisation invited you | Held with your assessment responses for as long as they keep your candidate record, and destroyed with them. You can withdraw your permission for the sensitive information until then (7.13). The required fields at 7.9.2 are not held on your permission and cannot be withdrawn; 10.4.1 states your right to object to them; if an objection succeeds no report can be produced from them. Where you contribute under part 8, an anonymised copy is kept as the row for anonymised research records states |
| Background information, including sensitive information, where you bought the report yourself | Held with your assessment responses while your personal account is open, and deleted with it. You can withdraw your permission for the sensitive information until then (7.13). The required fields at 7.9.2 are held to perform our contract with you: they cannot be withdrawn and no right to object arises. Where you contribute under part 8, an anonymised copy is kept as the row for anonymised research records states |
| The separated list of dates of birth, kept so a repeat can be caught when a report made from the background questionnaire is issued (7.14) | Permanently. It is a list of dates held apart from the platform, with nothing beside it and no link back to a platform record. No row in it is anybody's, so a request to see, correct, export or delete finds nothing in it to act on. It is internal: never published and never disclosed to anyone outside LPL Ltd. Clause 7.14.3 states the basis for keeping it and 7.14.3.1 the position on objecting. |
| Anonymised research records | Indefinitely. They are not personal data |
| Backups and archives | See below |
##### Backups and archives
12.1 Copies of deleted data may remain in our offline archives after deletion from the platform.
12.2 We do not routinely search archives. If that is the only way to answer your request, and is proportionate, we will, and tell you either way.
12.3 Archives older than five years are destroyed. Data may persist in archive form for up to ten years from creation.
12.4 We keep archives to recover from a disaster and to establish, exercise, or defend a legal claim. Background information within an archive is kept for the second of those purposes only, on Article 9(2)(f) where it is special category and Article 6(1)(f) where it is not. A restore returns the whole archive, and what happens to background information within the restored copy is at 12.4.3: our own rules run again on it, but a deletion you asked for is not repeated by itself. Nothing here involves opening the archive.
12.4.1 An archive is a sealed copy of the whole system on the day it was taken and cannot be opened to remove one person. Anything deleted afterwards stays there until destroyed under 12.3.
12.4.2 Archived data is beyond use: offline, not processed, never used to make or inform a decision about anyone, and not searched except in the one case at 12.2 and where we become subject to a legal obligation to preserve part of it, in which case we process that part for that purpose alone and destroy it as soon as the obligation ends.
12.4.3 A restore returns the platform to the state it was in when the archive was taken. Deletions that follow from our own rules re-apply by themselves, because the rule runs again on the restored data: the retention periods do it, and so does guest account expiry. A deletion you asked for does not: nothing in the restored data records that you asked. If you deleted your account, deleted a candidate record, or withdrew a permission between the archive being taken and the restore, the restore may undo it. A restore happens only where we are recovering from a disaster, and we explain what that recovery involved and what it affected at the time. You can ask us at any point to carry out a deletion again, and we will.
##### If we have to keep something longer
12.5 We may keep records longer where the law requires it, or to establish, exercise, or defend a legal claim.
13. WHO ELSE HANDLES YOUR DATA
13.1 Each provider is bound by contract to protect your data, use it only for the purpose we engaged it for, and meet obligations equivalent to ours. We stay responsible.
13.2 We engage providers for these functions:
| Function | What they handle |
|---|---|
| Hosting and infrastructure | The servers on which the platform runs, and the servers on which the research corpus is held |
| Payment processing | Card details go directly to the provider. We never receive or store a full card number, expiry date, or security code, only a payment reference and usually the card brand and last four digits |
| Protection against automated abuse | Checks that assessment pages are used by a person, not a script |
| Analytics and marketing on our public web pages | Usage data, aggregated for reporting, not assessment data |
13.3 A current list naming each provider, its function and location is available from support@teique.com. Changing a provider never widens what it may do (13.1).
13.3.1 Abuse protection runs on assessment pages and needs no consent (15.2). Analytics and marketing run on public web pages only, and only if you agree (15.3).
13.4 We do not sell personal data or share it with advertisers, investors, or data brokers.
13.5 We may disclose personal data where legally required, for example a court order or lawful request from a regulator or law enforcement, having checked it is valid.
13.6 If our business is sold or reorganised, personal data may transfer to the acquirer, on our legitimate interest in transferring the business as a going concern, handled under this policy until it publishes its own; we tell account holders, and we publish the change here before it takes effect.
14. WHERE YOUR DATA IS HELD
14.1 The platform runs on UK infrastructure, where assessment responses, reports and account data are held.
14.2 Some providers at part 13 operate outside the United Kingdom, so limited data, mostly technical and payment information, is handled outside the UK.
14.3 Where that happens we rely on an adequacy decision, the UK Extension to the EU-US Data Privacy Framework, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, checked before we engage a provider. For a copy of the safeguards in place for a particular provider, write to support@teique.com. We send it free of charge, redacted only for commercial terms.
14.4 If we ever propose to process assessment data outside the United Kingdom, we tell affected account holders in advance.
14.5 A coach or organisation outside the United Kingdom may have its own obligations under local law.
15. COOKIES AND ANALYTICS
15.1 We use cookies and similar technologies on our public web pages.
15.2 Essential cookies keep you signed in, keep your session secure, and make the platform work. Necessary for a service you asked for, they need no consent.
15.3 Analytics and marketing cookies show us how the site is used. We set them only if you agree, through the cookie banner; you can change your mind.
15.4 Assessment pages carry no advertising, and no advertising cookie is set while you complete one.
15.5 Most browsers let you block or delete cookies; blocking essential cookies stops parts of the platform working.
15.6 Some browsers send a "do not track" signal. There is no agreed standard, so we do not act on it; our cookie banner gives you the choice.
16. HOW WE PROTECT YOUR DATA
16.1 Data is held on UK infrastructure, encrypted in transit and at rest, with access restricted by role.
16.2 We log access, monitor for intrusion, and scan for vulnerabilities. Staff access is restricted, logged, attributable, and subject to confidentiality obligations.
16.3 Sign in is by email link, not password, so an account is only as secure as its registered email account.
16.4 A fuller description of our technical and organisational measures is available on request.
16.5 Where we are the controller and a breach is likely to risk your rights, we report it to the Information Commissioner's Office within 72 hours of becoming aware, and tell you where the risk is high.
16.5.1 Where a coach or organisation is the controller the duty is theirs: we tell them without undue delay and give them what they need, and they decide whether the Commissioner and you are told (4.10).
17. CHILDREN
17.1 You must be eighteen or over to hold an account or complete an assessment.
17.2 Our instruments for adolescents and children are not on the platform and are not offered commercially.
17.3 If we learn that we hold data about someone under eighteen, we delete it. Tell us at support@teique.com.
18. CHANGES TO THIS POLICY
18.1 We may update this policy. The version and effective date are at the top.
18.2 On a new version we email account holders and ask you to confirm at your next sign in that you have read it. This policy is a notice, not a term of our General Terms of Service. Where a change is to a term of those Terms rather than to this notice, clause 15 of the General Terms of Service applies, including clause 15.1.1 of those Terms if you are a consumer. We do not pause your access to anything you have already paid for. Nothing in this part is, or operates as, your consent to any processing: where we rely on consent we ask for it separately, at 7.6 and 8.3, and you can withdraw it without affecting your account.
18.3 Continued use of the platform is not, and is not treated as, agreement to a changed policy. We do not ask you to agree to this policy; we ask you to confirm that you have read it, as 18.2 describes.
18.4 If you were invited to complete an assessment, this policy is given to you as a notice at your first sign in, in the version then published, and that version applies for the life of the invitation. You are not asked to agree to it, and 18.3 applies to you as it applies to everyone else.
18.5 For visitors without an account, the version published at the time of the visit applies.
18.6 Previous versions are available from support@teique.com.
19. CONTACT US
19.1 For anything in this policy, including a request about your data:
support@teique.com
19.2 Or write to:
London Psychometric Laboratory Ltd.
27 Old Gloucester Street
Holborn
London WC1N 3AX
United Kingdom
19.3 Requests are answered within the timescales at part 10.
19.4 We keep correspondence from anyone who contacts us: your message, our reply, any recording. Our basis is our legitimate interest in running a support service and showing what we told someone, and for account holders our contract (part 12).
