Data Use
How Yurify handles organisational data
This page describes what Yurify collects during diagnostics, scans and programmes, how it is stored, and how organisations can request changes or deletion.
Information collected
During a diagnostic, scan or programme, participants provide responses to structured assessments covering communication, alignment, decision-making, ownership and workplace friction. Sponsors provide organisational context such as team size, role structure and priority areas.
Why information is collected
Responses are the raw inputs to the friction profile and the executive report. Sponsor context is used to interpret findings and to scope the appropriate intervention.
How responses are analysed
Individual responses are aggregated into team- and organisation-level reports. Analysis focuses on patterns and perception differences across roles, not on individual scores.
Who can access results
Access is limited to the Yurify team assigned to the engagement. Individual responses are not shown to the employer. Sponsors receive aggregated results and thematic analysis only.
Data hosting
Managed cloud infrastructure operated by vetted providers. Primary regions: Singapore and European regions, depending on the engagement. Database: Managed database service with role-based access controls.
Data processors
Yurify engages a limited set of vetted subprocessors for hosting, database, email delivery and assessment infrastructure. Each subprocessor operates under its own confidentiality and security terms.
Data retention
Retained for the duration of the engagement and up to 12 months afterwards for optional follow-up. Encrypted backups retained on a rolling 30-day window. Retention periods can be shortened on request as part of an engagement agreement.
Data deletion
Participants can request deletion of their personal data by writing to info@yurify.co. Organisations can request deletion of engagement data at the end of the programme. Deletion requests are actioned within 30 days of receipt.
Security measures
AES-256 encryption at rest via the managed database provider. TLS 1.2 or higher for all data in transit. Access is restricted to named Yurify personnel through role-based controls. No system is perfectly secure; Yurify applies reasonable technical and organisational measures but cannot guarantee absolute security.
Enterprise client options
A Data Processing Agreement and additional data-handling information can be provided for qualifying organisational engagements.
AI use
Where Yurify uses AI tools to accelerate analysis or content preparation, the same confidentiality standards apply as for any other processor. Client data is not used to train external AI models.
Minimum group size for aggregated reporting
Team-level and organisational reporting is only produced where there are enough responses to prevent individual identification. Yurify applies a minimum group size of 5 respondents per reported segment. Where a segment falls below that threshold, results are merged into a larger group or withheld.
AI training
Client and participant data is not used to train Yurify's or any third party's AI models. AI tools, where used, process data only to produce the outputs for that engagement.
Contact for data requests
Data questions and requests: info@yurify.co. Security contact: info@yurify.co.
Yurify does not claim ISO 27001, SOC 2 or HIPAA certification. Where a specific compliance requirement applies to your organisation, please raise it during the fit call so it can be addressed in the engagement agreement.