Back to Home
Data Protection & AnonymityPOPIA • GDPR • CCPA CompliantLast Updated: August 13, 2026 • v2.6

Privacy Policy & Signal Governance

RateTheLeader® is engineered around zero-knowledge anonymous evaluation. Discover how we protect your identity, safeguard your corporate feedback, and handle platform telemetry.

1. Zero-Knowledge Anonymity & Decoupled Signal Architecture

100% Decoupled

The foundational principle of RateTheLeader® is uncompromised psychological safety for corporate evaluators. While account authentication requires a verified business email address to prevent automated spam and protect corporate reputation, your identity, email address, IP address hash, and user ID are strictly decoupled from your submitted evaluations.

Irreversible Anonymization Protocol

Ratings submitted across the 20 Core Leadership Pillars (scores 1–5 and qualitative notes) are ingested into an isolated score repository. Neither the rated executive, the company management, nor external auditors can view or reverse-engineer which employee provided a specific review.

2. Information We Collect & Minimum Data Principles

Data Minimization

In compliance with international data minimization standards, we collect only data strictly necessary to operate and secure the platform:

  • Account Credentials: Full name, verified business email address, company affiliation, and one-way cryptographic salted password hashes (never stored in plain text).
  • Colleague Circles: Optional peer contact vectors provided voluntarily by the user for leadership feedback invitations.
  • User-Provided AI API Keys (BYOK): Custom API keys for Google Gemini, OpenAI, Groq, or OpenRouter provided to access high-volume reporting are stored with AES-256 encryption.
  • Transactional Metadata: Purchase records, invoice identifiers, and access entitlement status (no raw payment card numbers are ever stored on our servers).

3. AI Processing, Foundation Models & Zero Data Mining

No AI Training

RateTheLeader utilizes state-of-the-art generative language intelligence (Google Gemini 3.7 Flash, OpenAI, Groq, and OpenRouter) to produce structured executive synthesis reports, blind-spot matrix indicators, and strategic roadmaps.

Enterprise AI Privacy Protections

All synthesis prompts send anonymized numeric metrics and stripped evaluation excerpts over encrypted TLS connections. We enforce API zero-data retention and zero-training policies: your corporate commentary is never used to train public foundation models.

4. Payment Security & Yoco Multi-Currency Gateway

PCI-DSS Compliant

All financial transactions for Executive Intelligence Report unlocks ($19 USD), Semi-Annual Platform Access ($30 USD), and Pro AI Upgrades ($40 USD) are handled via PCI-DSS Level 1 certified payment processors (Yoco Online Checkouts and Stripe).

When payments are converted to South African Rand (ZAR), dynamic conversion occurs over secure HTTPS connections. RateTheLeader never captures, stores, or processes sensitive credit card primary account numbers (PANs) or CVVs on our application databases.

5. Data Retention, Account Deletion & Right to be Forgotten

90-Day Audit Buffer

We retain account data for as long as your account remains active. Users can request account deletion at any time via the User Profile portal or by contacting our data protection officer.

Upon receipt of a deletion request, personal identifying information is placed into a secure 90-day retention audit escrow to mitigate fraudulent activities and fulfill corporate governance obligations. After 90 days, all personal identifiers, email addresses, and passwords are permanently expunged. Anonymized statistical averages remain preserved within the global aggregate index.

6. Global Regulatory Compliance (POPIA, GDPR, CCPA)

Global Governance

RateTheLeader operates with global data privacy compliance in mind:

POPIA (South Africa)

Compliant with lawful condition processing, data subject participation, and direct marketing boundaries.

GDPR (European Union)

Full support for rights of access, rectification, erasure (Right to be Forgotten), and data portability.

CCPA / CPRA (California)

Strict "Do Not Sell My Personal Information" enforcement — personal data is never sold or rented.

7. Security Safeguards, Encryption & Access Controls

AES-256 & TLS 1.3

We implement industry-grade technical and organizational safeguards:

  • TLS 1.3 encryption for all data in transit across public networks.
  • Encrypted cloud databases with automated daily backups and least-privilege administrative access policies.
  • Zero plain-text logging of authentication tokens or user API keys.
  • Regular security auditing, rate limiting, and DDoS mitigation.

8. Data Protection Officer & Privacy Inquiries

Privacy Support

For privacy inquiries, data access requests, or to exercise your statutory data subject rights, contact our Data Protection and Compliance Office:

RateTheLeader Privacy & Compliance Team
NorthBright Digital U.S. • Data Protection Office
privacy@ratetheleader.com
© 2026 RateTheLeader® • NorthBright Digital U.S. All rights reserved.