storming.team

How Storming handles personal data

Teams answer candidly when they know who gets to see their answers. This page therefore describes, for HR, data protection and IT, who sees which data in Storming, how long it is kept and where it is processed. Documents still being written are marked as such and will be ready before the first use with real employee data.

Roles and visibility

Team members see their whole profile. Leads see what a person has explicitly shared with them. Administrators manage teams and invitations but have no access to answers or profiles; this is blocked in the access control layer itself.

Consent scopes

Taking part is voluntary. Anyone who takes part decides separately what to share: the five main dimensions, the facets, participation in pair views, the shared development plan and the anonymous contribution to the culture map. Only the anonymous contribution is on by default. A share lasts until it is ended, or until an end date the person chose.

Legal framing

Art. 328b of the Swiss Code of Obligations and the revised Federal Act on Data Protection shaped the design from the start. Art. 328b is semi-mandatory: an employee’s consent cannot make lawful any processing that goes beyond it.

Retention

Change pulse answers are deleted 90 days after the pulse closes. Pair analyses are deleted as soon as either person withdraws their consent. Agreements are anonymised 30 days after a person leaves. Individual questionnaire answers are subject to a 24-month limit, after which only the computed scores remain; the automatic deletion for this is not in place yet.

Data subject rights

Team members can export their data as a JSON file and delete their account for good at any time, without the lead’s approval. Agreements with other people are anonymised in the process, and the access log is kept.

Tenant isolation

Each customer has its own database file with its own key. When a customer leaves, the key is destroyed. Because different customers’ data never shares a database, there is no query across customers, and so no comparisons between companies.

Traceability

Every statement about a person comes from a versioned rule and a fixed text template, both published on the method page. There is no automated decision about people.

Hosting

The application and databases run at Infomaniak; we send email through Hostpoint and receive it at Proton. All three are Swiss companies processing the data in Switzerland. None belongs to a US group subject to foreign disclosure orders.

Subprocessors

CompanyFunctionProcessing locationPersonal data
Infomaniak Network SAApplication and database hostingSwitzerlandyes
Hostpoint AGTransactional outbound mailSwitzerlandname, email address
Proton AGInbound mail (mailboxes)Switzerlandemail content sent to us

We run the website’s visitor statistics (Umami) ourselves, so it is not on the list. Changes to the list are announced 30 days in advance, and customers can object.

Documents

Penetration test

A penetration test has not been scheduled yet. It will take place before the first use with real employee data. Once a date is set it will appear here, and after the test a summary with the date and the testing firm.