Privacy Policy

Last Updated: September 20, 2025

1. Introduction

This Privacy Policy explains how Eteronas, UAB (operating the behav.ee platform, "we", "us", "our") collects, uses, and protects your personal data when you use our team assessment platform (the "Service").

We act as a data controller when managing platform accounts and technical operations. When providing assessments on behalf of client organizations, we may act as a data processor under their instructions.

2. Personal Data We Collect

We may collect the following categories of data:

  • Identity and Contact Data: name, email, job title, organization alalignment and/or hierarchy, employee ID (when provided by your organization).
  • Assessment Data: survey responses, feedback comments.
  • Account Data: usernames, encrypted passwords, roles, organization details.
  • Usage and Technical Data: login timestamps, browser/device type, IP address, server logs, error reports.
  • Communications Data: support requests, email correspondence.

If your organization provides your details to us (e.g., preloading participant lists), we process that data on their behalf.

3. Legal Basis for Processing

We process personal data under the following lawful bases (GDPR Article 6):

  • Contract performance: to provide assessments, generate reports, and manage accounts.
  • Legitimate interests: platform security, service improvement, fraud prevention.
  • Legal obligations: retention for audit, compliance with applicable law.
  • Consent: for optional analytics, non-essential cookies, and marketing communications (where applicable). You may withdraw your consent at any time.

4. How We Use Your Data

We use data to:

  • Deliver and manage assessments and reports.
  • Provide secure account access and cohort management.
  • Improve our platform and develop new features.
  • Monitor system performance and security.
  • Respond to support requests.

We do not sell or rent your personal data.

5. Data Sharing

  • Within your organization: authorized administrators.
  • Service providers (processors): hosting, storage, backup, analytics, and email delivery providers, under strict contracts.
  • Legal requirements: regulators, courts, or law enforcement if required by law.

6. International Transfers

If personal data is transferred outside the EEA, we use approved safeguards, such as EU Standard Contractual Clauses or adequacy decisions, depending on the destination.

7. Data Retention

  • Assessment data: retained for 3 years after completion (or as defined by your organization's policy).
  • Account data: retained while accounts are active; deleted 12 months after inactivity unless legally required.
  • Technical and log data: retained for up to 12–24 months for security and system improvement.
  • Communications data: retained for as long as necessary to handle requests and meet legal obligations.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, regular audits, and incident response procedures.

9. Your Rights

Under GDPR, you have the right to:

  • Access your data and receive a copy.
  • Request correction or deletion.
  • Restrict or object to processing.
  • Request data portability.
  • Withdraw consent (where processing is based on consent).
  • Lodge a complaint with a supervisory authority.

10. Exercising Your Rights

You can contact us at privacy@behav.ee.

We may request verification of your identity before acting on your request.

11. Cookies

  • Essential cookies: required for login and security.
  • Optional cookies: analytics and performance, only with your consent.
  • We do not use cookies for advertising.

12. Changes to This Policy

We may update this Privacy Policy. If we make significant changes, we will notify you via email or platform notice. The updated version will always be available on our website.

13. Supervisory Authority

If you believe your data has been processed unlawfully, you can lodge a complaint with the State Data Protection Inspectorate of Lithuania or your local supervisory authority.

14. Contact

Eteronas, UAB

Vilnius, Lithuania

Email: privacy@behav.ee