Privacy policy
Last updated: 9 September 2026
Who we are
CultureFitr is operated by MILAN DANILOVIĆ PR BYTESICHT NIŠ, registered in Serbia (tax identification number / PIB 114734080, registration number / matični broj 67813472), whose registered address is Radnička 2, 18000 Niš (Palilula), Serbia. Serbia is outside the European Economic Area. For a request about your own data, write to privacy@culturefitr.com.
Who is responsible for what
Two different relationships, and which one applies decides who to ask about your data. When an agency invites you to complete an assessment, that agency decides why it is collecting your answers and what it does with the result: it is the controller, and we act as its processor, on its instructions. For an agency’s own account — the names and email addresses of its team, its workspace settings and its subscription — we are the controller. So a candidate’s request about an assessment is normally one we pass to the agency that invited them, and we will tell you who that is if you ask us.
What we collect
Only what the service needs. There is no advertising, no analytics, no session recording and no tracking anywhere in the product.
- Agency account data: name, email address, workspace and client-company records, and subscription status.
- Respondent data: name, email address, the answers you give, the timing of the block you were on, and the culture scores computed from those answers.
- Technical logs necessary to run and secure the service, including IP addresses used for rate limiting and abuse prevention. These are held as short-lived counters — an IPv6 address is reduced to its network prefix — and discarded once the window they belong to has passed.
- If you create a workspace, the date you accepted these terms and this notice, and the IP address you accepted them from. That pair is kept for as long as the account exists, because it is how we can show the agreement was made — it is not used for anything else.
Why we process it, and our lawful basis
Each purpose has its own basis under Article 6. Where the basis is legitimate interests, you have the right to object — see “Your rights” below, and it is a real right rather than a formality.
- To provide assessments and reports to the agency that invited you — Art. 6(1)(f), the legitimate interests of that agency in evaluating culture fit for a role, and ours in providing the tool it uses. We are the processor here; the agency struck this balance and must be able to justify it.
- To run an agency’s account and charge for it — Art. 6(1)(b), performance of the contract with that agency.
- To keep the service secure, prevent abuse and enforce plan limits — Art. 6(1)(f), our legitimate interest in a service that stays available and is not used to send unsolicited mail at scale.
- To meet legal and accounting obligations — Art. 6(1)(c).
Automated processing and profiling
This one deserves to be read rather than skimmed, because the product’s output is a profile of you. Your ranked answers are scored by our own software using a fixed, published framework — the same arithmetic every time, with no model involved in the numbers. Those numbers place your preferences across four quadrants and produce a congruence score against an employer’s profile. A language model then writes prose describing the numbers; it receives the scores only, never your name or your email address, and it does not decide anything.
- It is profiling within the meaning of Art. 4(4): we evaluate personal aspects of you to produce an assessment of cultural preference.
- Nothing in the product accepts or rejects anyone. It has no reject button, no threshold and no ranking that decides an outcome. A person at the agency reads the report and decides, and our terms with that agency require that a result is never used as the sole basis for an employment decision.
- The instrument measures preference, not competence, suitability or performance. A low congruence score is not a judgement about your ability.
- Whether Art. 22 — the rule on decisions taken solely by automated means — applies to a score of this kind can depend on how much weight the recipient puts on it. The Court of Justice has held that producing such a value can itself be the decision, where whoever receives it relies on it decisively (SCHUFA, C-634/21). We are not able to promise you how a particular agency weighs a report. What we do is require human review contractually, keep the score explainable rather than a black box, and give you the rights below.
- So in every case you may object under Art. 21, ask us or the agency how a score was reached, contest a result you believe is wrong, and ask for a decision to be reviewed by a person. If you tell us an agency is using a report as an automatic filter, we want to know: that is a breach of our terms with them.
Special categories of data
Before launch, every question and answer option in the assessment was audited one category at a time against Article 9 of the GDPR — health including mental health, racial or ethnic origin, religious or philosophical beliefs, political opinions and trade union membership, sex life and sexual orientation, biometric and genetic data — and against Article 10, criminal convictions and offences. The audit concluded that the assessment does not collect or infer special-category data.
- Every item describes a situation at work and asks which of four professional responses you would choose. None asks about your health, your beliefs, your background, your personal life or your record.
- There are no free-text answers anywhere. You rank four fixed options, so there is no box in which anything else could be volunteered.
- We repeat the audit whenever items are added or changed, because that is the only thing that keeps the conclusion true.
Who can see your results
The agency workspace that created your assessment link, and the employer that agency is recruiting for. That second recipient is the point of the product: its main output is a report placing your culture profile beside that employer’s, and the report carries your name. The agency decides when to share it and can revoke it. Whether you can view your own report is also controlled by that agency. Public report links use long random tokens, are stored only as a one-way hash, and can be revoked at any time.
Payments and billing
This section concerns agency account holders only. A respondent completing an assessment never enters payment details and is never charged. Paid plans are sold through Paddle, which acts as the merchant of record: Paddle is the seller on your invoice, takes the payment on its own checkout, and issues the receipt. Card and bank details are entered on Paddle’s pages and are never sent to us, never pass through our servers and are never stored by us. What we receive and store is a subscription identifier, a customer identifier, the plan, its status and the date the current period ends. That is enough to know what your workspace is entitled to, and not enough to charge anyone. Paddle processes your billing details as its own controller for that purpose and under its own privacy notice, and it registers for and remits the applicable VAT or sales tax itself.
Who else processes your data
A small number of service providers, and only for the purposes described above: a hosting provider, a transactional email provider (for verification, invitations, password resets and notifications), a language-model provider, and Paddle for payments. The model provider receives assessment scores only — never a name or an email address. Their identities and locations, the safeguards for any transfer outside your jurisdiction, and their contractual commitments are set out in our data processing agreement, which we provide on request. We do not sell personal data.
Where your data is processed
The service is hosted in the European Union. MILAN DANILOVIĆ PR BYTESICHT NIŠ is registered in Serbia, which is outside the European Economic Area, so our own access to the data as processor is a transfer to a third country. Where an agency in the EEA instructs us, that transfer is governed by the standard contractual clauses adopted by the European Commission, which form part of our data processing agreement. If you want the detail of which provider is where, and which safeguard applies to each, ask us and we will send it.
Retention and deletion
Results are kept for as long as the owning agency keeps them, because the agency decides that as controller. Agencies can delete individual results at any time, and doing so also deletes the written insights and any comparison derived from them. Assessment links expire on a date the agency sets, and expired and revoked link records are removed on a rolling basis. Abuse-prevention counters are discarded as soon as their window has passed. To request deletion of your own data, contact the agency that invited you, or write to us and we will identify them for you and pass the request on.
Your rights
Under the GDPR you have the rights below, and you can exercise them by writing to privacy@culturefitr.com. We will respond within one month. Where the agency that invited you is the controller, we will pass your request to it and tell you who it is; we will not go quiet on you.
- Access — a copy of the personal data we hold about you, and confirmation of whether we hold any (Art. 15).
- Rectification — correction of anything inaccurate (Art. 16).
- Erasure (Art. 17), and restriction of processing while a dispute is resolved (Art. 18).
- Portability — the data you provided, in a machine-readable form (Art. 20).
- Objection — you may object at any time to processing based on legitimate interests, which covers the assessment itself. This right was missing from an earlier version of this notice; it is the one that matters most here (Art. 21).
- To lodge a complaint with a data protection supervisory authority — in the EEA, the authority in your country of residence or work. You do not have to come to us first, though we would rather you did (Art. 77).
- And, independently, with the Serbian authority: Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade, Serbia — office@poverenik.rs, +381 11 3408 900. Serbian data protection law applies to us in parallel with the GDPR because we are established there, and it gives you that route regardless of where you live.
Security
Data is encrypted in transit. Authentication uses httpOnly cookies with short-lived tokens, and every query is scoped to a single agency workspace. Assessment share links are stored as a one-way hash alongside a copy encrypted with a key held outside the database, so a copy of the database alone does not yield a working link. Secrets are never stored in plain text, and tokens are removed from logs and traces structurally rather than by pattern-matching. Our /security page describes the controls in more detail.
Changes to this notice
We will update the date below when this notice changes, and will tell workspace owners directly about any change that affects how we use data they are responsible for. The current version is always the one on this page.