How Storming handles personal data
Teams answer candidly when they know who gets to see their answers. This page therefore describes, for HR, data protection and IT, who sees which data in Storming, how long it is kept and where it is processed. Documents still being written are marked as such and will be ready before the first use with real employee data.
Roles and visibility
Team members see their whole profile. Leads see what a person has explicitly shared with them. Administrators manage teams and invitations but have no access to answers or profiles; this is blocked in the access control layer itself.
Consent scopes
Taking part is voluntary. Anyone who takes part decides separately what to share: the five main dimensions, the facets, participation in pair views, the shared development plan and the anonymous contribution to the culture map. Only the anonymous contribution is on by default. A share lasts until it is ended, or until an end date the person chose.
Legal framing
Art. 328b of the Swiss Code of Obligations and the revised Federal Act on Data Protection shaped the design from the start. Art. 328b is semi-mandatory: an employee’s consent cannot make lawful any processing that goes beyond it.
Retention
Change pulse answers are deleted 90 days after the pulse closes. Pair analyses are deleted as soon as either person withdraws their consent. Agreements are anonymised 30 days after a person leaves. Individual questionnaire answers are subject to a 24-month limit, after which only the computed scores remain; the automatic deletion for this is not in place yet.
Data subject rights
Team members can export their data as a JSON file and delete their account for good at any time, without the lead’s approval. Agreements with other people are anonymised in the process, and the access log is kept.
Tenant isolation
Each customer has its own database file with its own key. When a customer leaves, the key is destroyed. Because different customers’ data never shares a database, there is no query across customers, and so no comparisons between companies.
Traceability
Every statement about a person comes from a versioned rule and a fixed text template, both published on the method page. There is no automated decision about people.
Hosting
The application and databases run at Infomaniak; we send email through Hostpoint and receive it at Proton. All three are Swiss companies processing the data in Switzerland. None belongs to a US group subject to foreign disclosure orders.
Subprocessors
| Company | Function | Processing location | Personal data |
|---|---|---|---|
| Infomaniak Network SA | Application and database hosting | Switzerland | yes |
| Hostpoint AG | Transactional outbound mail | Switzerland | name, email address |
| Proton AG | Inbound mail (mailboxes) | Switzerland | email content sent to us |
We run the website’s visitor statistics (Umami) ourselves, so it is not on the list. Changes to the list are announced 30 days in advance, and customers can object.
Documents
- Subprocessor listv1.0 · above on this page
- Data processing agreement (DPA)in progress
- Technical and organisational measuresin progress
- Deletion conceptin progress
- DPIA input (template)in progress
Penetration test
A penetration test has not been scheduled yet. It will take place before the first use with real employee data. Once a date is set it will appear here, and after the test a summary with the date and the testing firm.