Data security and GDPR · Esperto assessment platform

Assessment Data Security

Assessment data is stored on servers in the Netherlands and is seen only by the people the commissioning organization authorizes, plus the Esperto and hosting staff who need access to run the platform.

This page is written for the people who have to check us before an assessment can run: procurement teams, information security officers and data protection officers at the organizations our partners work with, and those partners themselves. It summarizes what Esperto B.V. does with assessment data, which measures are in place, who our sub-processors are and what happens when something goes wrong.

Everything here follows the wording of our standard data processing agreement. Where this page and that agreement differ, the agreement prevails. If a question in your questionnaire is not answered here, we make no statement about it, and privacy@esperto.one will tell you what applies.

Version 1.0 · Last reviewed 16 September 2026 · Based on the Esperto Data Processing Agreement, standard version 2.2 (6 September 2026)

Hosted in the NetherlandsAssessment data, including backups, stays in Dutch data centers.
No transfer outside the EEARespondent data, answers, scores and reports are not transferred outside the European Economic Area.
Breach notice within 48 hoursCustomers are notified within 48 hours after Esperto becomes aware of a breach.
One DPA for both chain positionsOur standard data processing agreement covers Esperto as processor and as sub-processor.
Roles in the chain

Esperto is a processor or a sub-processor. Never the owner of your data.

Under the GDPR, the organization that decides why an assessment runs is the controller. Esperto only processes data on that organization's documented instructions. Depending on who commissions the assessment, Esperto sits in one of two positions. Our data processing agreement covers both without amendment.

Situation 1

Esperto as processor

You run assessments with your own employees, clients or coachees, for your own purposes. You are the controller and Esperto is your processor.

  • Youcontroller
  • Espertoprocessor
  • ACC ICTsub-processor, hosting
Situation 2

Esperto as sub-processor

You are a consultancy, coach or assessment provider delivering a program to a client, for example a bank or a corporate. Your client is the controller, you are the processor and Esperto is your sub-processor within the meaning of Article 28(4) GDPR.

  • Your clientcontroller
  • Youprocessor
  • Espertosub-processor
  • ACC ICTsub-processor, hosting

One set of obligations for both situations

Every obligation Esperto accepts in the data processing agreement applies towards our customer and, in the second situation, for the benefit of the end client as well. The customer passes on the controller's instructions and is Esperto's single point of contact, may exercise the controller's rights to information, assistance and audit on the controller's behalf, and may pass on everything Esperto provides. Response times are set so that the customer can in turn meet its own obligations towards the controller.

What Esperto is controller for

Esperto is itself the controller for the contact, account and invoicing data of its customers' contact persons. That data is covered by our privacy statement, not by the data processing agreement.

Technical and organizational measures

What is in place today, in the order security schedules use

The list below follows Annex 2 of our data processing agreement. It uses the order commonly found in the security schedules of larger organizations, so that it can be mapped onto a tender questionnaire line by line. It contains only measures that are in place. Where a heading is missing, Esperto makes no statement about it.

Pseudonymization and encryption

All traffic between respondents, users and the platform is encrypted in transit (TLS). Respondents are identified by name and email address only; no government identification numbers are collected.

Confidentiality

Access to customer personal data is granted on a need-to-know basis through individual named accounts, with strong, unique passwords for administrator access. Everyone who works for or with Esperto is bound by a confidentiality obligation. Esperto has data processing agreements with the suppliers that process personal data on its behalf.

Availability, resilience and ability to restore

The platform is hosted in data centers in the Netherlands operated by hosting partner ACC ICT. The hosting partner makes automated daily backups of the hosted application landscape on a disk-to-disk-to-disk basis and replicates them to a second, geographically separate data center in the Netherlands, so that an incident at one location cannot affect the environment and its backups together. Standard backup retention is seven days and can be adjusted on request. Restores are tested periodically, including a check that restored data is usable and not merely present. Active storage is replicated to a storage environment outside the data center in which it runs. The hosting partner manages incident handling around the clock.

Testing, assessing and evaluating the measures

Esperto reviews these measures at least once a year and whenever the platform, its hosting or a sub-processor changes, and updates the annex of the data processing agreement accordingly.

User identification and authorization

Users of the customer sign in with individual accounts. Organizations that run assessments in their own environment can switch on single sign-on and enforce it for their users. Authentication then runs through the organization's own identity provider, including any multi-factor requirement that provider applies. Where single sign-on is not switched on, users sign in with an email address and a password. Respondents access their questionnaire through a personal invitation. Esperto's own administrator access uses individual accounts with strong, unique passwords. Access to the hosting partner's management portal requires two-factor authentication with a software token; this applies to the hosting partner's portal only and is separate from the single sign-on option for customer environments.

Protection of data during transmission

All traffic is encrypted in transit (TLS).

Protection of data during storage

Assessment data is stored on servers in data centers in the Netherlands managed by ACC ICT. All data centers involved, including the location that holds the replicated backups, are in the Netherlands, and stored data does not leave the Netherlands. Access to the servers is limited to the hosting partner and to Esperto administrators, each through individual accounts.

Physical security of the processing locations

The platform is not hosted on Esperto's premises. The data centers in the Netherlands are operated by ACC ICT; physical security of those locations is the hosting partner's responsibility under its agreement with Esperto. Details are available to customers on request.

Events logging

Server logs are kept and retained for a limited period, which Esperto states to customers on request.

System configuration

Each customer environment is configured by Esperto on the customer's instruction: assessments, branding and, where chosen, single sign-on. The questionnaires do not ask for special categories of data, and free-text fields carry an instruction not to enter such data.

Certifications

Esperto B.V. holds no security certification of its own. Our hosting partner ACC ICT holds its own certifications; their current status is stated in Annex 2 of our data processing agreement, and certificates are available on request through privacy@esperto.one.

Data minimization

Only the data needed to invite a respondent and to deliver the report is collected. Special categories of data are not requested. Any special category data that nonetheless reaches the platform is deleted once identified.

Data quality

Respondents enter their own answers. Identity data (name, email address, role or team) is supplied by the customer, which can correct it in the platform. Esperto rectifies data on instruction. Scoring follows the documented logic of the assessment concerned.

Limited data retention

Retention is set by the controller. Esperto deletes or returns the data as set out in the data processing agreement, within 30 days after the instruction. Backups are overwritten in the hosting partner's normal cycle, with a standard retention of seven days.

Accountability

Esperto maintains the data processing agreement, a published privacy statement and data processing agreements with its suppliers. Privacy contact: privacy@esperto.one. Esperto is not required to appoint a data protection officer and has not appointed one.

Data portability and erasure

Reports and respondent data can be exported from the platform in a structured, commonly used and machine-readable format. Data is deleted on instruction within 30 days, with written confirmation on request.

Assistance to the controller

Esperto assists the customer with requests from respondents and with security, breach notification, impact assessments and prior consultation. Requests from respondents received by Esperto are forwarded to the customer without undue delay.

Measures for sub-processors

Every sub-processor is bound by a written contract with obligations at least equivalent to the data processing agreement. Assessment data, including backups, is held only in data centers in the Netherlands and does not leave the Netherlands.

Why the list stops where it stops. We describe what exists, not what a questionnaire hopes to find. If your questionnaire asks about something that is not on this page, the answer is that we make no statement about it, and we will tell you in writing what does apply.
Sub-processors

Who processes data on our behalf, and in which country

Esperto engages three sub-processors. Only one of them, our hosting partner, touches assessment data. The list below is Annex 3 of the data processing agreement.

NameRegistered seatRoleLocation of processingTransfer mechanism
ACC ICTACC ICT B.V., Nieuwegein, the NetherlandsHosting and management of the assessment platform, including backups. Processes all assessment data.The NetherlandsNot applicable (EEA)
HostingerHostinger International Ltd., Larnaca, CyprusHosting of the website espertoassessments.com and the checkout environment. Processes the data of persons who order through the website. Does not process assessment data.Germany (data center)Not applicable (EEA)
Microsoft (Microsoft 365)Microsoft Ireland Operations Limited, Dublin, IrelandEmail, document storage and collaboration used by Esperto staff for support and correspondence with the customer. May contain customer personal data incidentally, for example a respondent list sent by the customer by email.European Union (Microsoft EU Data Boundary)Standard Contractual Clauses in Microsoft's Data Protection Addendum, for any remaining transfer

For transparency: two parties that are not sub-processors of assessment data

ActiveCampaign (ActiveCampaign LLC, Chicago, United States) sends our newsletters and service emails to customer contact persons. That is data for which Esperto is the controller and it does not include respondent data. ActiveCampaign is certified under the EU-US Data Privacy Framework.

Stripe processes payments as an independent controller and is not a sub-processor.

Changing a sub-processor

Esperto informs customers in writing at least 30 days before a new sub-processor starts processing customer personal data. Customers may object within that period on reasonable grounds relating to data protection. If the objection cannot be accommodated within a reasonable time, the customer may terminate the affected part of the services without penalty.

Expert partners are not sub-processors

Many assessments on the platform are provided by an expert partner who owns the methodology. Where the agreement or the information shown to respondents before the assessment states that the expert partner receives assessment data (usage data at aggregate level or, in some partnerships, individual responses, for example where the expert debriefs the results), Esperto makes that data available on the customer's instruction. The expert partner is an independent controller for its own use of that data. In any other case Esperto does not disclose customer personal data to an expert partner.

Flow-down and responsibility

Esperto enters into a written contract with each sub-processor that imposes data protection obligations at least equivalent to those in our data processing agreement, in particular on instructions, confidentiality, security, assistance, deletion and audit. Esperto remains fully liable to the customer for the performance of each sub-processor's obligations.

Transfers outside the EEA

Assessment data does not leave the Netherlands

Three rules from our data processing agreement govern international transfers.

1

Assessment data stays in the Netherlands

Respondent data, answers, scores and reports are stored and processed on servers in the Netherlands and are not transferred outside the European Economic Area. That includes backups.

2

Other customer data only under a transfer instrument

Esperto does not transfer other customer personal data, such as an email from a customer contact person, to a country outside the EEA without an adequacy decision, and does not permit a sub-processor to do so, unless the transfer is covered by the Standard Contractual Clauses or another Chapter V instrument, Esperto has assessed whether the destination country requires supplementary measures and has implemented them, and the transfer is listed in Annex 3 with the mechanism used.

3

Transfers you instruct are yours

Where an instruction itself requires a transfer outside the EEA, for example because a customer asks Esperto to send a report to a recipient outside the EEA, the controller is responsible for the lawfulness of that transfer.

Profiling and Article 22 GDPR

Scoring is profiling. Deciding is not something we do.

A bank or corporate procurement team will ask the Article 22 question sooner or later. This is the answer, in two parts: what Esperto does, and what we require from the organizations that use our assessments.

What Esperto does

The platform collects answers through an online questionnaire, scores them automatically and generates individual and, where applicable, team or organization reports. That scoring and reporting is profiling within the meaning of Article 4(4) GDPR: an automated evaluation of personal aspects, such as how someone works or how they experience their team. We are open about that, because it is the point of an assessment. The scoring logic and the meaning of each dimension are described on the page of the assessment concerned, and a respondent can always ask how an outcome was calculated.

What Esperto does not do

Esperto takes no decision about any respondent. We produce the report; we decide nothing about anyone's job, pay or position on the basis of it. Esperto's own processing therefore does not include any decision within the meaning of Article 22 GDPR.

Esperto also does not use assessment data for any purpose of its own: not for marketing, not for profiling for its own account, not for developing new products. Statistical use, such as norm groups and validation, takes place only on pseudonymised data and rests on an authorization the controller can withdraw.

What we require from the organizations that use our assessments

Every customer agrees to this in our data processing agreement, and agrees to ensure that the end client and every recipient of a report does the same:

  • An assessment outcome is never the sole basis for a decision that produces legal effects concerning a respondent or similarly significantly affects a respondent, in particular a decision on selection, recruitment, promotion, remuneration, or the termination of employment or an engagement.
  • Every such decision involves a meaningful assessment by a natural person who has the authority and the competence to depart from the assessment outcome.

The assessments are designed as input for development, dialogue and decision-making by people, not as a decision-making mechanism. Using an outcome as the sole basis for such a decision can amount to automated decision-making under Article 22, with obligations that fall on the controller, and it is not what these instruments are built for.

Personal data breaches

Notification within 48 hours

This is what happens when something goes wrong with assessment data, in the order it happens.

Within 48 hours

Notification

Esperto notifies the customer of a personal data breach affecting customer personal data without undue delay and in any event within 48 hours after becoming aware of it. The notification goes to the email address the customer designates for this purpose in the data processing agreement or, failing that, to the customer's contact person.

As far as known

Content of the notification

The nature of the breach, the categories and approximate number of respondents and records concerned, the likely consequences, the measures taken or proposed, and a contact point at Esperto. Where not all information is available at once, Esperto provides it in phases without undue delay.

Immediately

Containment and cooperation

Esperto takes the measures reasonably necessary to contain the breach and to limit its consequences, documents the breach, and cooperates with the customer and, through the customer, with the controller in their investigation.

Controller's call

Who notifies the authority and the respondents

That is the controller's responsibility. Esperto does not itself notify the supervisory authority or respondents of a breach affecting customer personal data, unless the law requires it to do so or the customer asks it to. The 48-hour term leaves room for the controller's own 72-hour obligation under Article 33 GDPR.

Where Esperto itself is the controller

For the contact, account and invoicing data of our own customers, Esperto is the controller. If a breach of that data is likely to result in a risk to the people concerned, Esperto reports it to the Dutch Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and informs the people concerned where the risk is high.

Rights of respondents

Respondents have rights. The controller answers them, and Esperto helps.

The GDPR gives every respondent a set of rights over their personal data. They can be exercised free of charge and without giving a reason.

Access

Ask which personal data is held and receive a copy of it.

Rectification

Have data corrected or completed if it is inaccurate or incomplete.

Erasure

Have data deleted, unless the controller is legally required to keep it.

Restriction

Have processing paused, for example while a correction request is being assessed.

Portability

Receive the data in a structured, commonly used and machine-readable format. Reports and respondent data can be exported from the platform in that form.

Objection

Object to processing based on a legitimate interest.

Who to contact

Did you complete an assessment through a coach, consultant or employer? Then that organization is the controller, and your request goes to them. If you send it to Esperto, we do not answer it on the merits; we forward it to that organization without undue delay and let you know that we have.

Esperto assists the controller in responding, with technical and organizational measures such as the export of reports and respondent data from the platform. Under the GDPR a controller answers within one month; if a request is complex that period may be extended by two months, and you are told before the first month is up.

Not satisfied?

You can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, via autoriteitpersoonsgegevens.nl. If you live in another EU country, you can also complain to the supervisory authority there.

For the data Esperto processes as controller, such as your contact or account data, send your request to privacy@esperto.one. Our privacy statement describes those rights in full.

Questions procurement asks

Frequently asked questions

The questions below are the ones that come back in security questionnaires and tender annexes. Every answer follows the wording of our data processing agreement and our privacy statement.

Where is assessment data stored?

On servers in data centers in the Netherlands, operated by our hosting partner ACC ICT B.V. All data centers involved, including the location that holds the replicated backups, are in the Netherlands, and stored assessment data does not leave the Netherlands.

Is assessment data transferred outside the European Economic Area?

No. Respondent data, answers, scores and reports are stored and processed in the Netherlands and are not transferred outside the EEA. Other customer data, such as an email from a customer contact person, is only processed outside the EEA under an adequacy decision or the Standard Contractual Clauses, after an assessment of the destination country, and only where the transfer is listed in Annex 3 of the data processing agreement with the mechanism used.

Who are Esperto's sub-processors?

Three. ACC ICT B.V. in Nieuwegein, the Netherlands, hosts and manages the assessment platform including backups. Hostinger International Ltd. in Larnaca, Cyprus, hosts the website and checkout in a data center in Germany and does not process assessment data. Microsoft Ireland Operations Limited in Dublin, Ireland, provides the email and documents Esperto staff use for support, within the Microsoft EU Data Boundary. Esperto gives 30 days' written notice before adding or replacing a sub-processor, and customers may object on reasonable grounds.

Is Esperto ISO 27001 or SOC 2 certified?

No. Esperto B.V. holds no security certification of its own and does not hold a SOC 2 report. Our hosting partner ACC ICT holds its own certifications; their current status is stated in Annex 2 of our data processing agreement, and certificates are available on request through privacy@esperto.one. We state the position exactly as it is, so that your questionnaire can record it correctly.

Does the platform support single sign-on and multi-factor authentication?

Organizations that run assessments in their own environment can switch on single sign-on and enforce it for their users. Authentication then runs through the organization's own identity provider, including any multi-factor requirement that provider applies. Where single sign-on is not switched on, users sign in with an email address and a password. Respondents access their questionnaire through a personal invitation. Esperto's own administrator access uses individual accounts with strong, unique passwords, and access to the hosting partner's management portal requires two-factor authentication with a software token.

How are backups handled, and can data be restored?

Our hosting partner makes automated daily backups of the hosted application landscape on a disk-to-disk-to-disk basis and replicates them to a second, geographically separate data center in the Netherlands. Standard backup retention is seven days and can be adjusted on request. Restores are tested periodically, including a check that restored data is usable and not merely present. Active storage is replicated to a storage environment outside the data center in which it runs.

What happens if there is a data breach, and how quickly are we informed?

Esperto notifies the customer without undue delay and in any event within 48 hours after becoming aware of a personal data breach affecting customer personal data. The notification contains, as far as known at that moment, the nature of the breach, the categories and approximate number of respondents and records concerned, the likely consequences, the measures taken or proposed, and a contact point at Esperto, with further information following in phases. Notifying the supervisory authority and respondents remains the controller's responsibility; the 48-hour term leaves room for the controller's own 72-hour obligation.

How long is assessment data kept, and how is it deleted?

Retention is set by the controller and recorded in Annex 1 of the data processing agreement; the default is until the end of the services. Within 30 days after the end of the services the customer instructs Esperto whether the data is to be returned or deleted. Return takes place through an export in a structured, commonly used and machine-readable format. Esperto deletes the data, and ensures that its sub-processors delete it, within 30 days after the instruction, and confirms deletion in writing on request. Data in backups is overwritten in the hosting partner's normal backup cycle, with a standard retention of seven days.

Does Esperto use our data for its own purposes?

No. Esperto does not use customer personal data for marketing, for profiling for its own account or for the development of new products. Statistical use of assessment data, such as norm groups and the validation of an assessment, takes place only on pseudonymised data from which name, email address and other direct identifiers have been removed and kept separately. It never results in a report at the level of an individual respondent, and it rests on an authorization in the data processing agreement that the controller can withdraw at any time.

Is there automated decision-making within the meaning of Article 22 GDPR?

Not on Esperto's side. The platform scores answers automatically and generates a report, which is profiling within the meaning of Article 4(4) GDPR, and Esperto is open about that. Esperto takes no decision about any respondent. Organizations that use our assessments agree in the data processing agreement not to use an outcome as the sole basis for a decision on selection, recruitment, promotion, remuneration or termination, and to have every such decision involve a meaningful assessment by a person with the authority and the competence to depart from the outcome.

Can we audit Esperto?

Yes. In the first instance Esperto provides the data processing agreement and its annexes, answers to a reasonable written security questionnaire, and any recent report or attestation that Esperto or its hosting partner holds. Where that information does not reasonably suffice, the customer or an independent auditor bound by confidentiality may audit Esperto's compliance: at most once every twelve months unless there has been a breach or a supervisory authority requires it, announced 30 days in advance with a stated scope, during business hours, and limited to the systems, documents and people involved in the processing. In the sub-processor situation the end client exercises these rights through our customer, or directly where its contract with our customer requires that.

Is there a data processing agreement, and does it cover the sub-processor situation?

Yes. Esperto has a standard data processing agreement under Article 28 GDPR, version 2.2 of 6 September 2026, in English with a Dutch translation available. It is written so that it works both where our customer is the controller and where our customer is itself a processor for an end client and Esperto is the sub-processor, without amendment. Its annexes describe the processing, the technical and organizational measures and the sub-processors, and may be passed on to the end client and to a supervisory authority.

Do the assessments collect special categories of personal data?

No. The questionnaires do not ask for special categories of personal data within the meaning of Article 9 GDPR or data relating to criminal convictions, and free-text fields carry an instruction not to enter such data. Respondents are identified by name and email address, with organization and role or team where applicable; no government identification numbers are collected. If special category data nonetheless reaches the platform, Esperto deletes it once identified and informs the customer.

Who do respondents contact to exercise their rights?

The organization that commissioned the assessment, such as the coach, consultant or employer, because that organization is the controller. If a request reaches Esperto directly, Esperto does not answer it on the merits but forwards it to the customer without undue delay and tells the respondent that it has done so. Reports and respondent data can be exported from the platform in a structured, commonly used and machine-readable format to support access and portability requests.

Documents and contact

Need it on paper?

Procurement rarely accepts a web page on its own. These are the documents behind it, and the address where questionnaires go.

Standard data processing agreement

Version 2.2, 6 September 2026. Article 28 GDPR, Dutch law, written for both chain positions. Annex 1 describes the processing, Annex 2 the technical and organizational measures, Annex 3 the sub-processors. English; a Dutch translation is available on request.

Download the DPA (PDF)

Privacy statement

Who Esperto is, when it is a controller and when a processor, what it processes and why, and the rights of the people concerned. Version 1.2, in English and Dutch.

Read the privacy statement

Security questionnaire or audit

Send your questionnaire and we answer in writing. The data processing agreement, its annexes and any report or attestation that Esperto or its hosting partner holds come first; an audit takes place only where that information does not reasonably suffice.

Send a questionnaire

Privacy contact

Questions about this page, a specific assessment, a sub-processor or a transfer mechanism: privacy@esperto.one. Certificates of our hosting partner and the details marked “on request” above are sent through the same address.

Esperto is not required to appoint a data protection officer and has not appointed one.

Esperto B.V.
Europalaan 93
3526 KP Utrecht, the Netherlands
Chamber of Commerce (KvK) 88522237
VAT NL864666536B01
privacy@esperto.one