Assessment Data Security
Assessment data is stored on servers in the Netherlands and is seen only by the people the commissioning organization authorizes, plus the Esperto and hosting staff who need access to run the platform.
This page is written for the people who have to check us before an assessment can run: procurement teams, information security officers and data protection officers at the organizations our partners work with, and those partners themselves. It summarizes what Esperto B.V. does with assessment data, which measures are in place, who our sub-processors are and what happens when something goes wrong.
Everything here follows the wording of our standard data processing agreement. Where this page and that agreement differ, the agreement prevails. If a question in your questionnaire is not answered here, we make no statement about it, and privacy@esperto.one will tell you what applies.
Esperto is a processor or a sub-processor. Never the owner of your data.
Under the GDPR, the organization that decides why an assessment runs is the controller. Esperto only processes data on that organization's documented instructions. Depending on who commissions the assessment, Esperto sits in one of two positions. Our data processing agreement covers both without amendment.
Esperto as processor
You run assessments with your own employees, clients or coachees, for your own purposes. You are the controller and Esperto is your processor.
- Youcontroller
- →
- Espertoprocessor
- →
- ACC ICTsub-processor, hosting
Esperto as sub-processor
You are a consultancy, coach or assessment provider delivering a program to a client, for example a bank or a corporate. Your client is the controller, you are the processor and Esperto is your sub-processor within the meaning of Article 28(4) GDPR.
- Your clientcontroller
- →
- Youprocessor
- →
- Espertosub-processor
- →
- ACC ICTsub-processor, hosting
One set of obligations for both situations
Every obligation Esperto accepts in the data processing agreement applies towards our customer and, in the second situation, for the benefit of the end client as well. The customer passes on the controller's instructions and is Esperto's single point of contact, may exercise the controller's rights to information, assistance and audit on the controller's behalf, and may pass on everything Esperto provides. Response times are set so that the customer can in turn meet its own obligations towards the controller.
What Esperto is controller for
Esperto is itself the controller for the contact, account and invoicing data of its customers' contact persons. That data is covered by our privacy statement, not by the data processing agreement.
What is in place today, in the order security schedules use
The list below follows Annex 2 of our data processing agreement. It uses the order commonly found in the security schedules of larger organizations, so that it can be mapped onto a tender questionnaire line by line. It contains only measures that are in place. Where a heading is missing, Esperto makes no statement about it.
All traffic between respondents, users and the platform is encrypted in transit (TLS). Respondents are identified by name and email address only; no government identification numbers are collected.
Access to customer personal data is granted on a need-to-know basis through individual named accounts, with strong, unique passwords for administrator access. Everyone who works for or with Esperto is bound by a confidentiality obligation. Esperto has data processing agreements with the suppliers that process personal data on its behalf.
The platform is hosted in data centers in the Netherlands operated by hosting partner ACC ICT. The hosting partner makes automated daily backups of the hosted application landscape on a disk-to-disk-to-disk basis and replicates them to a second, geographically separate data center in the Netherlands, so that an incident at one location cannot affect the environment and its backups together. Standard backup retention is seven days and can be adjusted on request. Restores are tested periodically, including a check that restored data is usable and not merely present. Active storage is replicated to a storage environment outside the data center in which it runs. The hosting partner manages incident handling around the clock.
Esperto reviews these measures at least once a year and whenever the platform, its hosting or a sub-processor changes, and updates the annex of the data processing agreement accordingly.
Users of the customer sign in with individual accounts. Organizations that run assessments in their own environment can switch on single sign-on and enforce it for their users. Authentication then runs through the organization's own identity provider, including any multi-factor requirement that provider applies. Where single sign-on is not switched on, users sign in with an email address and a password. Respondents access their questionnaire through a personal invitation. Esperto's own administrator access uses individual accounts with strong, unique passwords. Access to the hosting partner's management portal requires two-factor authentication with a software token; this applies to the hosting partner's portal only and is separate from the single sign-on option for customer environments.
All traffic is encrypted in transit (TLS).
Assessment data is stored on servers in data centers in the Netherlands managed by ACC ICT. All data centers involved, including the location that holds the replicated backups, are in the Netherlands, and stored data does not leave the Netherlands. Access to the servers is limited to the hosting partner and to Esperto administrators, each through individual accounts.
The platform is not hosted on Esperto's premises. The data centers in the Netherlands are operated by ACC ICT; physical security of those locations is the hosting partner's responsibility under its agreement with Esperto. Details are available to customers on request.
Server logs are kept and retained for a limited period, which Esperto states to customers on request.
Each customer environment is configured by Esperto on the customer's instruction: assessments, branding and, where chosen, single sign-on. The questionnaires do not ask for special categories of data, and free-text fields carry an instruction not to enter such data.
Esperto B.V. holds no security certification of its own. Our hosting partner ACC ICT holds its own certifications; their current status is stated in Annex 2 of our data processing agreement, and certificates are available on request through privacy@esperto.one.
Only the data needed to invite a respondent and to deliver the report is collected. Special categories of data are not requested. Any special category data that nonetheless reaches the platform is deleted once identified.
Respondents enter their own answers. Identity data (name, email address, role or team) is supplied by the customer, which can correct it in the platform. Esperto rectifies data on instruction. Scoring follows the documented logic of the assessment concerned.
Retention is set by the controller. Esperto deletes or returns the data as set out in the data processing agreement, within 30 days after the instruction. Backups are overwritten in the hosting partner's normal cycle, with a standard retention of seven days.
Esperto maintains the data processing agreement, a published privacy statement and data processing agreements with its suppliers. Privacy contact: privacy@esperto.one. Esperto is not required to appoint a data protection officer and has not appointed one.
Reports and respondent data can be exported from the platform in a structured, commonly used and machine-readable format. Data is deleted on instruction within 30 days, with written confirmation on request.
Esperto assists the customer with requests from respondents and with security, breach notification, impact assessments and prior consultation. Requests from respondents received by Esperto are forwarded to the customer without undue delay.
Every sub-processor is bound by a written contract with obligations at least equivalent to the data processing agreement. Assessment data, including backups, is held only in data centers in the Netherlands and does not leave the Netherlands.
Who processes data on our behalf, and in which country
Esperto engages three sub-processors. Only one of them, our hosting partner, touches assessment data. The list below is Annex 3 of the data processing agreement.
| Name | Registered seat | Role | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| ACC ICT | ACC ICT B.V., Nieuwegein, the Netherlands | Hosting and management of the assessment platform, including backups. Processes all assessment data. | The Netherlands | Not applicable (EEA) |
| Hostinger | Hostinger International Ltd., Larnaca, Cyprus | Hosting of the website espertoassessments.com and the checkout environment. Processes the data of persons who order through the website. Does not process assessment data. | Germany (data center) | Not applicable (EEA) |
| Microsoft (Microsoft 365) | Microsoft Ireland Operations Limited, Dublin, Ireland | Email, document storage and collaboration used by Esperto staff for support and correspondence with the customer. May contain customer personal data incidentally, for example a respondent list sent by the customer by email. | European Union (Microsoft EU Data Boundary) | Standard Contractual Clauses in Microsoft's Data Protection Addendum, for any remaining transfer |
For transparency: two parties that are not sub-processors of assessment data
ActiveCampaign (ActiveCampaign LLC, Chicago, United States) sends our newsletters and service emails to customer contact persons. That is data for which Esperto is the controller and it does not include respondent data. ActiveCampaign is certified under the EU-US Data Privacy Framework.
Stripe processes payments as an independent controller and is not a sub-processor.
Changing a sub-processor
Esperto informs customers in writing at least 30 days before a new sub-processor starts processing customer personal data. Customers may object within that period on reasonable grounds relating to data protection. If the objection cannot be accommodated within a reasonable time, the customer may terminate the affected part of the services without penalty.
Expert partners are not sub-processors
Many assessments on the platform are provided by an expert partner who owns the methodology. Where the agreement or the information shown to respondents before the assessment states that the expert partner receives assessment data (usage data at aggregate level or, in some partnerships, individual responses, for example where the expert debriefs the results), Esperto makes that data available on the customer's instruction. The expert partner is an independent controller for its own use of that data. In any other case Esperto does not disclose customer personal data to an expert partner.
Flow-down and responsibility
Esperto enters into a written contract with each sub-processor that imposes data protection obligations at least equivalent to those in our data processing agreement, in particular on instructions, confidentiality, security, assistance, deletion and audit. Esperto remains fully liable to the customer for the performance of each sub-processor's obligations.
Assessment data does not leave the Netherlands
Three rules from our data processing agreement govern international transfers.
Assessment data stays in the Netherlands
Respondent data, answers, scores and reports are stored and processed on servers in the Netherlands and are not transferred outside the European Economic Area. That includes backups.
Other customer data only under a transfer instrument
Esperto does not transfer other customer personal data, such as an email from a customer contact person, to a country outside the EEA without an adequacy decision, and does not permit a sub-processor to do so, unless the transfer is covered by the Standard Contractual Clauses or another Chapter V instrument, Esperto has assessed whether the destination country requires supplementary measures and has implemented them, and the transfer is listed in Annex 3 with the mechanism used.
Transfers you instruct are yours
Where an instruction itself requires a transfer outside the EEA, for example because a customer asks Esperto to send a report to a recipient outside the EEA, the controller is responsible for the lawfulness of that transfer.
Scoring is profiling. Deciding is not something we do.
A bank or corporate procurement team will ask the Article 22 question sooner or later. This is the answer, in two parts: what Esperto does, and what we require from the organizations that use our assessments.
What Esperto does
The platform collects answers through an online questionnaire, scores them automatically and generates individual and, where applicable, team or organization reports. That scoring and reporting is profiling within the meaning of Article 4(4) GDPR: an automated evaluation of personal aspects, such as how someone works or how they experience their team. We are open about that, because it is the point of an assessment. The scoring logic and the meaning of each dimension are described on the page of the assessment concerned, and a respondent can always ask how an outcome was calculated.
What Esperto does not do
Esperto takes no decision about any respondent. We produce the report; we decide nothing about anyone's job, pay or position on the basis of it. Esperto's own processing therefore does not include any decision within the meaning of Article 22 GDPR.
Esperto also does not use assessment data for any purpose of its own: not for marketing, not for profiling for its own account, not for developing new products. Statistical use, such as norm groups and validation, takes place only on pseudonymised data and rests on an authorization the controller can withdraw.
What we require from the organizations that use our assessments
Every customer agrees to this in our data processing agreement, and agrees to ensure that the end client and every recipient of a report does the same:
- An assessment outcome is never the sole basis for a decision that produces legal effects concerning a respondent or similarly significantly affects a respondent, in particular a decision on selection, recruitment, promotion, remuneration, or the termination of employment or an engagement.
- Every such decision involves a meaningful assessment by a natural person who has the authority and the competence to depart from the assessment outcome.
The assessments are designed as input for development, dialogue and decision-making by people, not as a decision-making mechanism. Using an outcome as the sole basis for such a decision can amount to automated decision-making under Article 22, with obligations that fall on the controller, and it is not what these instruments are built for.
Notification within 48 hours
This is what happens when something goes wrong with assessment data, in the order it happens.
Notification
Esperto notifies the customer of a personal data breach affecting customer personal data without undue delay and in any event within 48 hours after becoming aware of it. The notification goes to the email address the customer designates for this purpose in the data processing agreement or, failing that, to the customer's contact person.
Content of the notification
The nature of the breach, the categories and approximate number of respondents and records concerned, the likely consequences, the measures taken or proposed, and a contact point at Esperto. Where not all information is available at once, Esperto provides it in phases without undue delay.
Containment and cooperation
Esperto takes the measures reasonably necessary to contain the breach and to limit its consequences, documents the breach, and cooperates with the customer and, through the customer, with the controller in their investigation.
Who notifies the authority and the respondents
That is the controller's responsibility. Esperto does not itself notify the supervisory authority or respondents of a breach affecting customer personal data, unless the law requires it to do so or the customer asks it to. The 48-hour term leaves room for the controller's own 72-hour obligation under Article 33 GDPR.
Where Esperto itself is the controller
For the contact, account and invoicing data of our own customers, Esperto is the controller. If a breach of that data is likely to result in a risk to the people concerned, Esperto reports it to the Dutch Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and informs the people concerned where the risk is high.
Respondents have rights. The controller answers them, and Esperto helps.
The GDPR gives every respondent a set of rights over their personal data. They can be exercised free of charge and without giving a reason.
Access
Ask which personal data is held and receive a copy of it.
Rectification
Have data corrected or completed if it is inaccurate or incomplete.
Erasure
Have data deleted, unless the controller is legally required to keep it.
Restriction
Have processing paused, for example while a correction request is being assessed.
Portability
Receive the data in a structured, commonly used and machine-readable format. Reports and respondent data can be exported from the platform in that form.
Objection
Object to processing based on a legitimate interest.
Who to contact
Did you complete an assessment through a coach, consultant or employer? Then that organization is the controller, and your request goes to them. If you send it to Esperto, we do not answer it on the merits; we forward it to that organization without undue delay and let you know that we have.
Esperto assists the controller in responding, with technical and organizational measures such as the export of reports and respondent data from the platform. Under the GDPR a controller answers within one month; if a request is complex that period may be extended by two months, and you are told before the first month is up.
Not satisfied?
You can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, via autoriteitpersoonsgegevens.nl. If you live in another EU country, you can also complain to the supervisory authority there.
For the data Esperto processes as controller, such as your contact or account data, send your request to privacy@esperto.one. Our privacy statement describes those rights in full.
Frequently asked questions
The questions below are the ones that come back in security questionnaires and tender annexes. Every answer follows the wording of our data processing agreement and our privacy statement.
Where is assessment data stored?
On servers in data centers in the Netherlands, operated by our hosting partner ACC ICT B.V. All data centers involved, including the location that holds the replicated backups, are in the Netherlands, and stored assessment data does not leave the Netherlands.
Is assessment data transferred outside the European Economic Area?
No. Respondent data, answers, scores and reports are stored and processed in the Netherlands and are not transferred outside the EEA. Other customer data, such as an email from a customer contact person, is only processed outside the EEA under an adequacy decision or the Standard Contractual Clauses, after an assessment of the destination country, and only where the transfer is listed in Annex 3 of the data processing agreement with the mechanism used.
Who are Esperto's sub-processors?
Three. ACC ICT B.V. in Nieuwegein, the Netherlands, hosts and manages the assessment platform including backups. Hostinger International Ltd. in Larnaca, Cyprus, hosts the website and checkout in a data center in Germany and does not process assessment data. Microsoft Ireland Operations Limited in Dublin, Ireland, provides the email and documents Esperto staff use for support, within the Microsoft EU Data Boundary. Esperto gives 30 days' written notice before adding or replacing a sub-processor, and customers may object on reasonable grounds.
Is Esperto ISO 27001 or SOC 2 certified?
No. Esperto B.V. holds no security certification of its own and does not hold a SOC 2 report. Our hosting partner ACC ICT holds its own certifications; their current status is stated in Annex 2 of our data processing agreement, and certificates are available on request through privacy@esperto.one. We state the position exactly as it is, so that your questionnaire can record it correctly.
Does the platform support single sign-on and multi-factor authentication?
Organizations that run assessments in their own environment can switch on single sign-on and enforce it for their users. Authentication then runs through the organization's own identity provider, including any multi-factor requirement that provider applies. Where single sign-on is not switched on, users sign in with an email address and a password. Respondents access their questionnaire through a personal invitation. Esperto's own administrator access uses individual accounts with strong, unique passwords, and access to the hosting partner's management portal requires two-factor authentication with a software token.
How are backups handled, and can data be restored?
Our hosting partner makes automated daily backups of the hosted application landscape on a disk-to-disk-to-disk basis and replicates them to a second, geographically separate data center in the Netherlands. Standard backup retention is seven days and can be adjusted on request. Restores are tested periodically, including a check that restored data is usable and not merely present. Active storage is replicated to a storage environment outside the data center in which it runs.
What happens if there is a data breach, and how quickly are we informed?
Esperto notifies the customer without undue delay and in any event within 48 hours after becoming aware of a personal data breach affecting customer personal data. The notification contains, as far as known at that moment, the nature of the breach, the categories and approximate number of respondents and records concerned, the likely consequences, the measures taken or proposed, and a contact point at Esperto, with further information following in phases. Notifying the supervisory authority and respondents remains the controller's responsibility; the 48-hour term leaves room for the controller's own 72-hour obligation.
How long is assessment data kept, and how is it deleted?
Retention is set by the controller and recorded in Annex 1 of the data processing agreement; the default is until the end of the services. Within 30 days after the end of the services the customer instructs Esperto whether the data is to be returned or deleted. Return takes place through an export in a structured, commonly used and machine-readable format. Esperto deletes the data, and ensures that its sub-processors delete it, within 30 days after the instruction, and confirms deletion in writing on request. Data in backups is overwritten in the hosting partner's normal backup cycle, with a standard retention of seven days.
Does Esperto use our data for its own purposes?
No. Esperto does not use customer personal data for marketing, for profiling for its own account or for the development of new products. Statistical use of assessment data, such as norm groups and the validation of an assessment, takes place only on pseudonymised data from which name, email address and other direct identifiers have been removed and kept separately. It never results in a report at the level of an individual respondent, and it rests on an authorization in the data processing agreement that the controller can withdraw at any time.
Is there automated decision-making within the meaning of Article 22 GDPR?
Not on Esperto's side. The platform scores answers automatically and generates a report, which is profiling within the meaning of Article 4(4) GDPR, and Esperto is open about that. Esperto takes no decision about any respondent. Organizations that use our assessments agree in the data processing agreement not to use an outcome as the sole basis for a decision on selection, recruitment, promotion, remuneration or termination, and to have every such decision involve a meaningful assessment by a person with the authority and the competence to depart from the outcome.
Can we audit Esperto?
Yes. In the first instance Esperto provides the data processing agreement and its annexes, answers to a reasonable written security questionnaire, and any recent report or attestation that Esperto or its hosting partner holds. Where that information does not reasonably suffice, the customer or an independent auditor bound by confidentiality may audit Esperto's compliance: at most once every twelve months unless there has been a breach or a supervisory authority requires it, announced 30 days in advance with a stated scope, during business hours, and limited to the systems, documents and people involved in the processing. In the sub-processor situation the end client exercises these rights through our customer, or directly where its contract with our customer requires that.
Is there a data processing agreement, and does it cover the sub-processor situation?
Yes. Esperto has a standard data processing agreement under Article 28 GDPR, version 2.2 of 6 September 2026, in English with a Dutch translation available. It is written so that it works both where our customer is the controller and where our customer is itself a processor for an end client and Esperto is the sub-processor, without amendment. Its annexes describe the processing, the technical and organizational measures and the sub-processors, and may be passed on to the end client and to a supervisory authority.
Do the assessments collect special categories of personal data?
No. The questionnaires do not ask for special categories of personal data within the meaning of Article 9 GDPR or data relating to criminal convictions, and free-text fields carry an instruction not to enter such data. Respondents are identified by name and email address, with organization and role or team where applicable; no government identification numbers are collected. If special category data nonetheless reaches the platform, Esperto deletes it once identified and informs the customer.
Who do respondents contact to exercise their rights?
The organization that commissioned the assessment, such as the coach, consultant or employer, because that organization is the controller. If a request reaches Esperto directly, Esperto does not answer it on the merits but forwards it to the customer without undue delay and tells the respondent that it has done so. Reports and respondent data can be exported from the platform in a structured, commonly used and machine-readable format to support access and portability requests.
Need it on paper?
Procurement rarely accepts a web page on its own. These are the documents behind it, and the address where questionnaires go.
Standard data processing agreement
Version 2.2, 6 September 2026. Article 28 GDPR, Dutch law, written for both chain positions. Annex 1 describes the processing, Annex 2 the technical and organizational measures, Annex 3 the sub-processors. English; a Dutch translation is available on request.
Download the DPA (PDF)Privacy statement
Who Esperto is, when it is a controller and when a processor, what it processes and why, and the rights of the people concerned. Version 1.2, in English and Dutch.
Read the privacy statementSecurity questionnaire or audit
Send your questionnaire and we answer in writing. The data processing agreement, its annexes and any report or attestation that Esperto or its hosting partner holds come first; an audit takes place only where that information does not reasonably suffice.
Send a questionnairePrivacy contact
Questions about this page, a specific assessment, a sub-processor or a transfer mechanism: privacy@esperto.one. Certificates of our hosting partner and the details marked “on request” above are sent through the same address.
Esperto is not required to appoint a data protection officer and has not appointed one.
Europalaan 93
3526 KP Utrecht, the Netherlands
Chamber of Commerce (KvK) 88522237
VAT NL864666536B01
privacy@esperto.one