Legal/Compliance asks: How does Empatyzer ensure it is not used for employee evaluations and how is that written in the terms/contract?

TL;DR:

  • Empatyzer does not expose raw individual scores or allow employers to identify employees.
  • Data is aggregated and anonymized; product features and permissions prevent use for evaluations.
  • Contract terms, DPA/DPIA templates, EU hosting, auditable admin access and account deletion options are provided.

How does Empatyzer reduce the risk of employee evaluation?

Empatyzer maintains the developmental nature of the system: the profile describes the mechanisms, advice supports cooperation, and comparison explains differences between people without creating employee rankings.

Features that can help:

  • Traits: Shows your own features and mechanisms along with their strengths and possible costs, giving you specific context for further work.
  • Tips: Offer practical guidance for cooperation with the selected person: what may suit them, what is worth doing and what can be the basis for a common course of action.
  • Comparison: Describes the difference between two people in a relational way, so that the result is used to understand cooperation rather than to rank people.

Empatyzer is built to prevent use as an employee assessment tool. The platform never shares raw individual results with employers or managers. Client-facing reports are aggregated and anonymized so you can track trends without identifying people. Product controls block exporting individual profiles and limit visibility to collective culture and motivator metrics. Users control their profile visibility and can delete their account anytime; deletion also removes them from aggregate statistics. The terms of service and client agreements explicitly prohibit using data for employee evaluation and define processing purposes. We provide DPA and DPIA templates and technical details about EU hosting and customer data separation. Conversation content is not passed to HR or third parties and remains in the system under a "Las Vegas" policy. We do not train models on company data or use raw client data to improve our general models. Provider admin access is logged, restricted and audited, and any security incidents are reported to clients per contract. The agreement also specifies retention rules and the deletion procedure after contract termination.

In practice, product safeguards, contractual clauses and technical procedures together limit the risk of using Empatyzer for employee evaluations; enforcement measures and remediation paths follow from the contract and the client's policies.

Sources and research

  1. European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. Source
  2. European Data Protection Board. (2020). Guidelines 4/2019 on Article 25 Data Protection by Design and by Default (Version 2.0). Source
  3. National Institute of Standards and Technology. (2020). Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5 DOI: 10.6028/NIST.SP.800-53r5
  4. American Educational Research Association, American Psychological Association, & National Council on Measurement in Education. (2014). Standards for Educational and Psychological Testing. American Educational Research Association. Source

Author: Empatyzer

Published:

Updated:

 

""