Skip to content

Legal

Privacy Policy

Last updated:

Template notice

This document is a template prepared for Rodrik Consulting LLC and should be reviewed by qualified legal counsel before publication.

Confidentiality is foundational to ROHA. This policy describes what we collect, what we deliberately do not collect, and how we protect the perspectives employees entrust to the assessment.

1. Who we are

ROHA (the “Rodrik Organizational Health Assessment”) is developed, owned and operated by Rodrik Consulting LLC (“Rodrik Consulting,” “we,” “us” or “our”). This Privacy Policy explains how we handle information in connection with the ROHA website, the ROHA application used by organizations, and the ROHA surveys completed by employees of those organizations (together, the “Service”).

ROHA serves two distinct groups, and we treat their information differently: organization users (the owners and administrators who register an organization and manage assessments) and survey participants (employees and other members of an organization who respond to a ROHA survey).

2. Our role and our customers' role

For organization account information, Rodrik Consulting determines how that information is used and acts as the party responsible for it. For survey data, the organization that commissions an assessment (our “customer”) decides to conduct the assessment and how to use its aggregated results, and Rodrik Consulting processes survey data on the customer’s behalf to provide the Service. Where applicable law uses terms such as “controller” and “processor,” or “business” and “service provider,” these roles should be read accordingly.

3. Information we collect from organization users

When an organization registers for ROHA or uses the application, we collect:

  • Account information, such as name, work email address, job title, and authentication credentials (passwords are stored only in hashed form by our authentication provider).
  • Organization information, such as organization name, industry, size, primary contact details, and the departments, locations and other structure configured for assessments.
  • Campaign configuration, such as campaign names, dates, privacy mode (confidential or anonymous), and settings.
  • Billing information. Payments are processed by Stripe. We receive limited information from Stripe, such as the plan purchased, payment status and billing contact details. Card details are entered directly with Stripe; ROHA never receives or stores full card numbers or security codes.
  • Usage and security information, such as sign-in events and significant administrative actions recorded in an audit log, and technical logs needed to operate and secure the Service.
  • Communications, such as messages sent through our contact form (name, email, organization, topic and message).

4. Information we collect from survey participants

ROHA is designed to collect as little information about survey participants as possible while still producing useful aggregated results.

What participants provide

  • Ratings for each assessment statement, from two perspectives (current state and desired state), including “Not Applicable” selections.
  • Optional written answers to open-ended questions.
  • Optional permission for a written comment to be quoted verbatim in reports. Without this permission, comments may inform aggregated themes but are not quoted.
  • In confidential campaigns only, optional demographic selections defined by the organization, such as department, location, level and tenure. Anonymous campaigns collect no demographic information.

What we do not collect

  • Participants do not create accounts and are not asked for their name, email address or employee ID.
  • We do not store IP addresses or submission times with survey responses.
  • We do not use tracking or advertising cookies on survey pages.

To protect the integrity of a campaign and the Service, we may apply rate limiting to survey and form submissions. Rate limiting uses a short-lived, one-way cryptographic value derived from network information that rotates daily; raw network addresses are not stored for this purpose and the value is not linked to responses.

Written comments

Written comments are automatically screened for names, email addresses, telephone numbers and other potential identifiers before they are analyzed or displayed. Screening reduces—but cannot entirely eliminate—the chance that a comment contains identifying details, so we encourage participants not to include information that could identify themselves or others.

5. How survey confidentiality is protected

  • Aggregated reporting only. Organization users see aggregated results. Individual responses are never displayed in the dashboard, reports or exports available to organizations.
  • Minimum group size. Results for any group—including the organization as a whole and any filter by department, location, level or tenure—are shown only when at least five people in that group responded. Additional suppression is applied so that small groups cannot be inferred by subtracting one result from another.
  • Release at close. Results are released when a campaign closes, reducing the risk of inferring individual responses from changes during the campaign.

Platform administrator access

Rodrik Consulting operates the ROHA platform. Our authorized personnel with database administration responsibilities could technically access raw response records. Such access is limited to operating, securing, supporting and maintaining the Service; is subject to strict internal controls; and is never used to attempt to identify participants or to disclose individual responses to an organization. Because ROHA does not collect names, email addresses or employee IDs, raw response records are not linked to named individuals.

6. How we use information

We use information to:

  • Provide, operate and maintain the Service, including calculating scores and producing dashboards and reports;
  • Authenticate users, manage organization accounts, and enforce plan limits;
  • Process payments and manage subscriptions;
  • Respond to inquiries and provide support;
  • Secure the Service, prevent abuse, and maintain audit records;
  • Improve the reliability and quality of the Service, using aggregated or de-identified information where possible; and
  • Comply with legal obligations and enforce our agreements.

We do not sell personal information, and we do not use survey data for advertising.

7. AI-assisted analysis

Certain plans include an AI-generated organizational intelligence report. To produce it, we send the following to our AI provider, Anthropic, through its commercial API:

  • Aggregated scores, gaps and distributions calculated by ROHA’s scoring engine, for groups that meet the privacy threshold; and
  • Written comments after they have been screened for identifiers.

We do not send participant names, email addresses, employee IDs, individual response records or demographic profiles of individual participants. The AI does not calculate or alter scores; it interprets results that have already been calculated. AI-generated content can contain errors, and reports distinguish observed findings from hypotheses that should be tested by leadership.

Information sent to Anthropic is processed under Anthropic’s commercial terms. Under those terms, API inputs and outputs are not used to train Anthropic’s models by default.

8. Service providers and disclosures

We share information only as needed to provide the Service, with providers bound by contractual confidentiality and security obligations:

  • Supabase — database hosting, authentication and storage.
  • Stripe — payment processing and subscription billing.
  • Anthropic — AI analysis of aggregated results and screened comments, as described above.
  • Hosting and email delivery providers — to serve the application and send account-related messages.

We may also disclose information if required by law or legal process, to protect the rights, safety or property of Rodrik Consulting, our customers or others, or in connection with a merger, acquisition or sale of assets, subject to this Privacy Policy.

9. Cookies

ROHA uses cookies only for authentication and session management—for example, to keep organization users signed in securely. We do not use advertising cookies or third-party tracking cookies. Survey participants do not need to sign in, and survey responses are not associated with authentication cookies.

10. Data retention

Each organization controls how long its survey data is retained. The default retention period is 36 months, and it can be configured for each organization between 6 and 120 months. When the retention period for a campaign expires, its survey data is deleted or de-identified.

Organization account information is retained while the account is active and for a reasonable period afterward to meet legal, accounting and security obligations. Billing records may be retained longer where required by law. Audit logs are retained to support security and accountability.

11. Export and deletion

Organization owners can export their organization’s data and request deletion of their organization and its associated data from within the application. Exports are designed to preserve participant confidentiality and do not identify individual participants. Following a deletion request, data is removed from active systems within a reasonable period, and from backups according to their normal rotation.

12. Security

We use administrative, technical and organizational safeguards designed to protect information, including:

  • Tenant isolation, so each organization’s data is logically separated;
  • Database row-level security policies that restrict access to authorized users;
  • Role-based access control within organizations;
  • Encryption of data in transit and at rest provided by our hosting infrastructure;
  • Audit logging of significant administrative actions; and
  • Restricted, controlled access by Rodrik Consulting personnel.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete or obtain a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Organization users can update most account information within the application.

Survey participants: because ROHA does not link responses to names, email addresses or employee IDs, we generally cannot locate, correct or delete an individual’s survey response. Questions about a particular assessment should be directed to the organization that invited you.

We will not discriminate against anyone for exercising privacy rights.

14. International data transfers

Rodrik Consulting is based in the United States, and our service providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers.

15. Children

The Service is intended for organizations and their adult workforce. It is not directed to children under 16, and we do not knowingly collect personal information from children.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify organization owners by email or within the application.

17. Contact us

To ask a question or make a privacy request, please use our contact form and select “Privacy and data protection,” or reach Rodrik Consulting LLC through rodrikconsulting.com. We may need to verify your identity before responding to certain requests.