Effective 10 August 2026. This covers Quadrant, at disc-quadrant.com, and the People Purpose marketing site that feeds it.
This is a draft. It has not been reviewed by a lawyer. It was written by reading our own source code and writing down what the code actually does, including the parts that are unfinished or awkward. It is published now because a company that handles other people's information owes them a straight account of it, and having no page at all was worse than having a draft.
If you are a lawyer reading this on behalf of a client, or on our behalf: good. Tell us what is wrong with it. privacy@disc-quadrant.com.
On this page
Quadrant is built and run by People Purpose Corporation, a company incorporated in Manitoba, Canada. It is operated by one person, Rod Penner. There is no privacy department. When you write to us, Rod reads it.
Under Canadian federal privacy law, PIPEDA, an organisation has to name someone who is accountable for the personal information it holds and make its practices readily available. That is what this page is for.
Quadrant sits between an employer and the people that employer hires or is thinking about hiring. That means we hold information about people who never signed up with us and never agreed to anything with us directly. It matters which one you are, because it changes who decides what happens to your information.
You pay us for Quadrant. $30 a month plus $7 a month for each person on your roster, in Canadian dollars. You have an account, you signed up, and you agreed to our terms. Your relationship with us is a service contract.
Your information is in Quadrant because an employer put it there, or sent you a link and you filled it in. You are not our customer. In most cases you have no contract with us at all.
For this group, the employer is generally the one deciding what your information is for. They chose to run a hiring process, they wrote the job description, they decide what to do with what they learn. We hold and process the information on their instructions. In privacy language, they are the organisation with the obligations to you, and we are the service provider carrying out the work. That does not let us off the hook — we are responsible for handling it properly — but it does mean that if you want your information out of an employer's Quadrant account, we will normally need to talk to them, because it is theirs.
Nothing on the candidate side of Quadrant costs money. We do not charge, and will never charge, a person looking for work — not to apply, not to take an assessment, not to be in a pool, not for a copy of their own results. If anyone ever asks you to pay us to be considered for a job, it is not us.
You took the free assessment, used Read-a-person, asked for a leadership read, or joined our mailing list, for yourself. No employer is involved. Here we are the one deciding what your information is for, and you deal with us directly.
We sell to companies in Manitoba, Ontario, British Columbia, Alberta and Saskatchewan, mostly in trades and construction, mostly between 20 and 500 employees.
The federal law, PIPEDA, applies to us. Alberta and British Columbia each have their own private-sector privacy law, both called PIPA, which apply to provincially regulated employers in those provinces and which have specific rules about employee information — see section 7. Manitoba, Ontario and Saskatchewan have no general private-sector privacy statute of their own, so PIPEDA governs there.
Quebec is not a market for us. We do not sell into Quebec and this policy is not written to meet Quebec's Law 25. We do not claim to comply with it. If you are a Quebec employer, we are not the right supplier for you right now.
On the application form: your full name, phone number and email address, all required. A resume file if you upload one (PDF or Word, up to 3 MB). Your answers to the employer's screening questions, if that role has them. A tick confirming you are sharing your application with the employer and with Quadrant.
Then, in the assessment itself: your name, email and company. Twenty-four forced-choice style questions, twenty-four character questions and six most/least blocks. Whether you are currently employed — and if you say yes, three extra questions about commitment that you would not otherwise be shown. How long you took, and when you started. A tick if you want to hear about other roles.
And, without you typing it: your IP address. We store it on the assessment record. We use it to stop one person submitting the assessment more than six times an hour. It is not shown to the employer. There is currently no process that deletes it.
Name, email, phone, your current role, your region, a description of what you are looking for, and a resume as text or as a file. Plus a consent tick.
Your name, email, company and job title. The same assessment battery as above. Five "how to manage me" preferences you set yourself. Your job description, as text or an uploaded file. If your company runs reviews through Quadrant, your own ratings and written notes and your manager's ratings and written notes about you. If you are enrolled in the Growth Program, your progress, your answers to the lesson questions, a written reflection of up to 4,000 characters, and any certificate, which carries your name and your company.
If your company sets up weekly check-ins with you. This is switched on person by person by someone with a managing role in your company — it is built to be started by your manager in a sit-down with you, though any owner, admin or HR login can press the button — never by us, and never by default. It cannot be switched on at all until the org chart says who you report to, or, for the top of the chart, until an accountability partner has accepted. Each week the check-in stores: a one-word answer to how your capacity is — steady, stretched or struggling; an optional written note attached to that word; up to five priorities for the week, each marked red, yellow or green; and asks — short requests for help, filed under manager, teammate, tools, training or wellbeing, with your manager's response. It also stores who you picked as your backup for when you are away, accountability-partner invitations and acceptances, and a stamp of when your weekly meeting happened and who recorded it. The written note is the most personal field in Quadrant, and who can see it is deliberately narrow — section 10 spells it out.
Managers can also write free-text notes about you and about applicants, up to 8,000 characters at a time, stamped with who wrote them and when.
Your email address, a stored hash of your password, when you last signed in and when you confirmed your email. Your role in your company's account. Your email address is stamped on the record every time you move a candidate through a stage, add a note, or run one of the AI tools, so there is a trail of who did what.
If a client company uses the customer tools in Quadrant, it can store company addresses and contact names, emails and phone numbers for its own customers and prospects. Those people never interact with Quadrant and have no idea it exists. That information belongs to the client and is theirs to justify. We hold it for them.
We do not ask for or store your date of birth, your government identifiers, your bank details, your health information, or anything about your race, religion, sex, or family status. We do not run background checks, credit checks or criminal record checks. We do not buy lists of people. We do not take payment information from anyone except client companies, and that is handled by Stripe, not by us — we never see a card number.
Free-text fields are the honest exception to "we do not ask". A check-in note, an ask filed under wellbeing, or a manager's note contains whatever the writer chooses to type, and people do type personal things — that is what the fields are for. We never ask for health or family information, but we cannot stop a sentence from containing it. That is exactly why the check-in note's visibility is as narrow as section 10 describes.
PIPEDA says we have to tell you the actual purposes, not vague ones. Here they are.
| What | What it is for |
|---|---|
| Your name, email, phone | So the employer knows who applied and can reach you, and so we can send you your own status updates and results. |
| Your resume and screening answers | So the hiring manager can read them. Screening answers can raise a flag on your card, which is a note for a person to read. Nothing is rejected automatically. |
| Your assessment answers, and the scores worked out from them | To describe how you naturally work and communicate, so the employer can ask better interview questions, onboard you better, and manage you better. The assessment informs a hiring decision. It does not make one. It is not a test you can fail and it does not measure whether you can do the work. |
| How long you took, and consistency checks across your answers | To flag when a set of answers looks idealised, so a human reads the profile with that in mind. |
| Your IP address | Rate limiting and abuse prevention. Six assessment submissions per hour, and a daily cap on free Read-a-person use. |
| Whether you are currently employed | It decides whether you are shown three questions about commitment to a current employer. If you are not employed, you never see them. |
| Your job title and job description, if you are on a team | The job description sets the standard for the seat. It is used to build the targets for that role, to shape review scorecards, and to produce a read on how well your measured style lines up with the seat you are in. |
| Manager notes and review ratings | To run a documented review and development process inside the employing company. |
| Weekly check-in entries: your capacity word, your note, your priorities, your asks | To give you and your manager a standing weekly conversation with a written spine, and to flag patterns worth a human conversation — section 12 lists exactly what is computed from them. |
| Login details and the who-did-what stamps | To sign you in, and so a company can see which of its people took which action on a candidate's record. |
| Company account details, roster count, admin email | To bill the company. $30 a month plus $7 a month per person on the roster. |
| Marketing list details | To send you the emails you asked for, and to stop sending them when you say so. |
We do not sell personal information. We do not rent it, trade it, or hand it to advertisers or data brokers. We do not use your assessment answers to train AI models — see section 8 for what our AI supplier's terms say.
Consent under PIPEDA has to be meaningful, and it has to fit what is being collected. Here is what we rely on, and where the ticks actually are.
Withdrawing consent. You can withdraw consent, subject to legal and contractual limits and to reasonable notice. Section 13 tells you exactly how, and is honest about which routes are one click and which are an email to a human.
Alberta's PIPA and BC's PIPA both have a category called personal employee information. In broad terms, they allow an organisation to collect, use and disclose information about its own employees without their consent where it is reasonably required to establish, manage or end the employment relationship — but only if the organisation has given the employee notice of what it is collecting and why.
That notice is your employer's job, not ours. We are the software. Your employer is the organisation that decided to gather this and decided what it is for. Under both statutes, the duty to tell you sits with them.
If you are an employee in Alberta or BC and nobody told you your assessment, your job description, your review notes and your manager's notes about you were going into a system called Quadrant, then something has gone wrong upstream of us. Ask your employer. And tell us at privacy@disc-quadrant.com, because we would rather know.
Two things worth saying plainly to employees:
If you took an assessment through a link a company sent you, that company sees your results. Its people can open your profile, your report, your resume, your notes and your scores according to their role in the account. See section 10 for who inside a company sees what.
We operate the platform, so we can technically reach everything in it. See section 10.
These are the suppliers that actually touch personal information. This list is what our code sends, function by function, not a generic list.
| Supplier | What it does for us | What it receives |
|---|---|---|
| Supabase | Our database, our file storage and our login system. | Everything in section 4. Every record, every assessment, every note, plus resume and job-description files. |
| Netlify | Hosts the website and runs the server code. | Every request to the site, which means IP addresses and browser details. Our server logs, which in some places include names and email addresses. |
| Anthropic (Claude) | The AI behind our written reports, resume reads, interview kits, review scorecards, alignment reads and the in-app assistant. | Depends on the feature, and it is more than people assume. It can include: your name; your full score profile; up to 8,000 characters of your resume for a hiring read, 6,000 for a skills score, 12,000 for reformatting; the whole of an uploaded PDF, sent as a document; up to 60,000 characters of an interview transcript; your job description; your DISC profile compared against a named manager's; and, for Read-a-person, the raw text you pasted about someone else. The in-app assistant also sends a 7,000-character snapshot of whatever is on the user's screen, which on a hiring page includes candidate names and details. |
| Resend | Sends every email we send. | The recipient's email address, their name, and the content of the message. |
| Stripe | Takes payment from client companies. | The company's account id, the number of people on the roster, and the billing administrator's email address. No candidate or employee information goes to Stripe. We never see or store a card number. |
| Google Analytics | Tells us which pages get used. | Standard web analytics: pages viewed, device, approximate location, and an identifier for your browser. See section 15, which is not a comfortable section. |
| Cloudflare | Delivers three code libraries that read PDF and Word files in your own browser. | Only the fact that your browser fetched a script, and the IP address that came with it. Your file is read inside your browser and is not sent to Cloudflare. |
| Adzuna | A job board we pull public postings from. | Nothing about you. The traffic goes one way, out from us. No applicant information is sent to Adzuna. |
About the AI. Anthropic's commercial API terms state that inputs sent through the API are not used to train their models. We use two separate keys with Anthropic — one for the product features and one for the in-app assistant — and we have not confirmed that both sit under identical commercial terms. We are saying that here rather than assuring you of something we have not checked.
About phone numbers. We collect them and show them to the employer. We have text-message code in the product but nothing in the live product uses it, so as of today no phone number you give us is sent to a messaging service.
We will disclose personal information if a law, a warrant, a subpoena or a court order requires it, or where it is necessary to investigate a breach of an agreement or of the law, or to protect someone from harm. If our business is ever sold or merged, information would move with it, and we would tell affected clients before it did.
Canadian law lets an organisation use suppliers in other countries to process information on its behalf, and does not require your separate consent to do so. What it does require is that we tell you, plainly, that this happens, and that while your information is in another country it is subject to that country's laws — including access by that country's courts and law enforcement. So: it happens, and it is.
Anthropic, Resend, Stripe, Netlify, Google and Cloudflare are all American companies. Unless we say otherwise here, you should assume information that reaches them is processed in the United States.
An honest gap. Our database is hosted by Supabase, and the physical region of our database was not something we could determine from our own code. We are confirming it and will name the country on this page when we have. We would rather tell you we do not yet know than guess at a country and be wrong about where your assessment answers physically sit.
A client account has roles. In plain terms:
Which of your colleagues holds which role is your employer's decision, not ours.
This asymmetry is real and you should know about it. If you are an employee with a Quadrant login, your own page shows you your primary and secondary style, your style mix, five health numbers, the size of the gap between how you rated yourself and how you answered behaviour questions, your job description and your course progress.
Your manager sees more: your email, your candour flags, the two halves of that gap separately rather than just its size, your "how to manage me" preferences, an AI-written read on how well you line up with your seat — expressed as aligned, tension or misfit — your review ratings and notes, and your full written report.
If you want to see the parts your manager sees, ask us at privacy@disc-quadrant.com. You have a right to access your own information and we will not hide behind the interface.
The written note you can attach to your weekly capacity word is the most personal field in Quadrant — people use it for things like "rough week at home". So it has the narrowest visibility in the product, and the narrowing is enforced in the server code, not just hidden on a screen: the note is returned only to you, and to someone with a managing role in your company — the owners, admins and HR listed above — opening your individual check-in page. It is never included in the team summary, never in the Monday digest email, and never in the eight-week history strip; we have checked the three server reads behind those screens and none of them selects the note column. The digest does carry your one-word capacity flag and the text of your open asks — asks are requests you are sending your manager, so they travel to your manager — but the note does not. And check-ins cannot be switched on for you at all until the org chart says who you report to, or an accountability partner you invited has accepted — whoever that is, is who your weekly meeting is built around.
We can see everything, and we should say so rather than let you assume otherwise. Our server code uses a database key that bypasses the database's own row-level permissions. What keeps one company's records separate from another's is our application code filtering by company on every request, not a wall inside the database.
Platform administrator accounts — today, that is Rod — can step inside any client company's account and act as its owner, and pass every role and subscription check. There is currently no audit log of that, and no notification to the client when it happens. It is used for support and for fixing things. It is a real capability and it is not currently constrained by anything except one person's judgment.
We are writing that down because a policy that quietly implies otherwise would be a false statement about our security, and that is worse for everyone than an uncomfortable paragraph.
Several things in Quadrant are reached by a link rather than a password: an assessment invitation, a short apply code, a shared report link, a job-description upload link, a review form, an opt-out link, an unsubscribe link. Most are signed so they cannot be guessed. One is not signed: a shared report link is the assessment's own random identifier, and anyone who has that link can open that report without signing in. It cannot be guessed, but it can be forwarded. Treat a report link like a document, not like a locked door.
We do not have a retention schedule yet. Nothing expires on its own. If nobody deletes it, it stays.
We have checked our own code for this. There is no scheduled job anywhere in Quadrant that deletes personal information because it has got old. Assessment answers, scores, IP addresses, applications, notes, reviews, weekly check-ins and resumes are all kept indefinitely until a person deletes them.
What we do instead of a schedule, today:
Things you should specifically know are not cleaned up by any of that today:
We intend to set actual retention periods and build the jobs that enforce them. Until we have, the honest description of our practice is the one above, and if a period matters to you, ask and we will delete on request rather than making you wait for a schedule that does not exist.
Quadrant calculates things about people. You are entitled to know what, and how much weight it carries.
There is no path in Quadrant where a computer marks someone as rejected. A rejection is only ever written by a person clicking it. Screening answers can raise flags on your card, and the application page tells you so: those flags are notes for a person to read.
Three automatic actions do exist, and all three follow a human decision. When a manager marks someone hired, everyone else on that role is automatically closed and sent an honest update. A manager can close a role and notify its whole pipeline in one action, with a preview first. And marking someone hired automatically converts them from an applicant into a team member and copies the job description across.
When an employer builds a role profile, they set target ranges for the seat. Quadrant then works out a number out of 100 comparing an applicant's measured style mix and character answers against those targets. Half the number comes from how far the style mix is from the target mix; the other half counts only shortfalls below a target, so exceeding a target costs nothing. It is arithmetic, not AI, and it is the same calculation for everyone.
What that number is not. It is not validated. Nobody has run a study on whether it has an adverse impact on any group, and our own code says so in writing. It ranks a list on a screen so a hiring manager can decide who to read first. It does not remove anyone from a pipeline, and no part of the product acts on it by itself. If an employer used it as a cutoff, they would be using it against our written guidance and, we would argue, against what employment and human rights law expects.
Two guardrails do exist in the code. If a job description was generated around a specific named employee, that role cannot be scored against at all. And the number is not shown everywhere: the interview guide, the page an interviewer opens with one named person in front of them, is not given it. The server strips it out before the response leaves us, so the browser never receives it. What that page shows instead is the per-measure comparison — which measures sit at the role's target and which sit under it, with both numbers — because that is a thing to ask about rather than a mark out of a hundred. The number still exists on the employer's list of applicants, which is what the paragraph above describes.
Separately, a hiring manager can ask the AI to compare a resume against a job description and return a number out of 100 with a sentence explaining it. That number is saved on your application record. It is a language model's judgment, not a calculation, and it carries all the limits that implies. It is shown to a person; it does not act on its own.
For an existing employee, Quadrant can compare their profile against their job description and store a one-word band — aligned, tension or misfit — with a short written explanation, on their record. Their manager sees it. As things stand, the employee does not see it on their own page. Ask us and we will show you yours.
If your company uses weekly check-ins, three flags are computed from them, none of which act on their own. They appear on the company dashboard, which — as the role list in section 10 says — every login role except the employee login can open. A capacity watch: three submitted check-ins in a row rated below steady, or two "struggling" ratings across your last four submitted check-ins, puts a check-in-on-them flag beside your name — the flag, never your note. Weeks you skip are simply not counted, in either direction. A stale meter: a count of consecutive recorded check-in weeks that have gone by without the weekly meeting being held, shown against the manager, not the employee. And an over-leveraged flag on any manager with more than six direct reports. Each is plain arithmetic on the records described in section 4, each exists to prompt a human conversation, and nothing escalates, notifies anyone outside your company, or changes anyone's standing on its own.
If a number about you was worked out by Quadrant, you can write to privacy@disc-quadrant.com and ask what it was, what went into it and what it means. We will tell you. If you think it is wrong, tell us and tell the employer — they are the ones deciding what to do with it.
Under PIPEDA you can ask what we hold about you, ask for a copy, ask us to correct it if it is wrong, and withdraw your consent. Here is the actual route for each, including where the route is a person and not a button.
Access, correction, a full copy, and erasure all go through privacy@disc-quadrant.com. There is no self-service export and no self-service delete. A request is handled by a person, by hand. We will:
The limits, stated straight. If your information is in a client company's account, that company is the one deciding what happens to it, and there are records — a manager's notes about a candidate, a review, a hiring file — that they may have their own legal reason to keep. We will always tell you what we hold, and we will tell you which employer to talk to. We may not be able to delete an employer's record of you on your say-so alone. Where we can delete, we will, and quickly.
We may also refuse or limit access where the law says we must — for instance where releasing something would reveal personal information about another person that cannot be severed. If we refuse, we will tell you in writing, tell you why, and tell you how to complain about it.
One thing that is deliberately one-way. If you have clicked a link telling us never to contact you about roles again, nothing on a later form quietly undoes that — not leaving a box unticked, and not ticking it either. The code that records a tick specifically leaves your withdrawal standing. If you want back in, tell a person: privacy@disc-quadrant.com. We built it that way on purpose.
Canada's anti-spam law, CASL, governs commercial email. Our position on each kind of message:
Some applicant emails are blind-copied to jobs@disc-quadrant.com, which is us, so we can see what applicants are actually receiving. A few internal alerts about client activity go to Rod's own address.
We run Google Analytics on most of the site, including the assessment page and the pool intake page, and we do not currently show a cookie or consent banner anywhere.
That means that if you take an assessment, Google Analytics is running on that page and setting an identifier for your browser, and nobody asked you first. Your assessment answers are not sent to Google. The application form itself carries no analytics at all. We are naming this because it is a real gap between what a careful reader would expect and what the site does, and it is on the list to fix.
Quadrant also uses the cookies and browser storage it needs to keep you signed in and to remember your place in an assessment. Those are not optional; without them the product does not work.
We designed a shared talent pool across the companies hiring on Quadrant. It is switched off. The job that would copy people between accounts stops at its first line unless a server switch is set to on, and there is no screen anywhere in Quadrant that lets one company search another company's people.
Two honest caveats. First, that is a pause set by a configuration value, not a guarantee written into the code — and the job is still on a daily schedule, doing nothing. Second, while it was running it copied some client records into our own pool, and those copies are still there; we are working through them. Our methodology page sets out the full position, including the one route by which a person can still move between companies today, which is a human at People Purpose placing a candidate from our own recruiting pool into a client's pipeline by hand.
What is true: everything travels over encrypted connections. Passwords are hashed by our login provider, not stored by us and not visible to us. Uploaded resumes and job descriptions go into a private file store, not a public one. We never see or store payment card details.
What is true with a qualification: most server requests check who you are and what role you hold before returning anything, and most links that reach a page without a login are signed so they cannot be guessed. Not all. The shared report link is the assessment's own random identifier rather than a signature, and the request behind it takes no credential: hand that link to anyone and they can open that person's scores, name, company and the role they applied to. Our free Read-a-person tool also runs for people who are not signed in, limited by a daily count against your address rather than by a login. Those are the two exceptions we know of, and section 10 describes the first one from the other direction.
What is also true, and stated in section 10: separation between one company's records and another's is enforced by our application code, not by the database itself, and platform administrators can reach everything without an audit trail. One person operates this company, which means the security of your information depends on the practices of one person and the suppliers listed in section 8.
No system is completely secure and we are not going to tell you ours is. If we ever have a breach that creates a real risk of significant harm to you, we will report it to the Privacy Commissioner and notify affected people, as PIPEDA requires, and we will keep a record of it.
Openness means telling you what is missing, not just what is working. Everything here is stated somewhere above; this is the same list in one place, so nobody has to hunt for the bad news.
If one of these matters to you before you buy, or before you take an assessment, say so and we will tell you where it stands. Some of it will be fixed by the time you read this, and when it is, this page changes.
Start with us. privacy@disc-quadrant.com. Tell us what happened and what you want done. We will acknowledge it, investigate it, and write back within 30 days with what we found and what we did. If we got it wrong, we will say so and fix it. If we disagree with you, we will tell you why in writing, so you have something to take to a regulator.
If we do not sort it out, go over our heads. That is your right and we are not going to make it awkward.
If your complaint is really about what your employer did with your information, the regulator will likely want to deal with your employer. We will cooperate with either of you.
We will change this page as the product changes and as the gaps in section 18 get closed. The effective date at the top will change with it. If a change materially affects how we use information we already hold about you, we will do more than quietly edit the page — we will tell affected clients directly, and where we hold your email and the change matters to you, we will tell you.
Quadrant is operated by People Purpose Corporation, Manitoba, Canada. See also how the assessment works and how to use it responsibly and the shorter assessment privacy and fair use note. Where the two differ, this page is the fuller and more current account.