This Privacy Policy describes how Leading srl STP ("we", "us", "our"), operating the Calibrate service at calibrateapp.net, collects, uses, and protects information about you when you use our platform.
1. Who we are
The data controller is: Leading srl STP
Via Lazzaretto 1, 20060 Gessate (MI), Italy
Email: [email protected]
2. Data we collect
We collect the following categories of personal data:
Account data — your email address, hashed password, and professional role (coach, mentor coach, or school/organisation). Collected when you register.
Billing data — name, company, VAT number, and address, collected only if you purchase a paid plan and request invoicing.
Usage data — number of evaluations run, AI model used, token counts, and associated cost. Used for internal analytics and plan management.
Evaluation reports — the structured ICF competency reports generated by the AI. Stored so you can access your history.
Session transcripts — text or audio you submit for evaluation. These are sent to our AI providers for processing but are not permanently stored in our database.
Feedback — optional ratings and notes you submit via the in-app feedback form.
3. How we use your data
To provide, operate, and improve the Calibrate service.
To manage your account and credits.
To process payments and generate invoices.
To send transactional emails (account verification, password reset, receipts).
To respond to feedback and support requests.
To comply with legal obligations.
We do not sell your personal data. We do not use your data for advertising purposes.
4. Legal basis for processing (GDPR)
Contract performance — processing necessary to provide the service you signed up for (Art. 6(1)(b) GDPR).
Legitimate interests — internal analytics and service improvement (Art. 6(1)(f) GDPR).
Legal obligation — invoicing and tax records (Art. 6(1)(c) GDPR).
5. Third-party processors
We share data with the following sub-processors, each bound by their own data processing agreements:
Passwords are stored as bcrypt hashes and are never readable by us. All data in transit is encrypted via HTTPS/TLS. Access to the database is restricted to our Cloudflare Worker infrastructure.
9. Cookies
Calibrate does not use tracking or advertising cookies. We use browser localStorage to store your authentication token and session preferences. No third-party analytics scripts are loaded.
10. Children
Calibrate is intended for professional use and is not directed at children under 16. We do not knowingly collect data from minors.
11. Changes to this policy
We may update this policy from time to time. We will notify registered users by email for material changes. The "Last updated" date at the top of this page reflects the most recent revision.