Privacy Policy

What we collect, who gets it, and what you can do about it.

Effective 9 October 2026. This covers Quadrant, at disc-quadrant.com, and the People Purpose marketing site that feeds it.

Read this first

This is a draft. It has not been reviewed by a lawyer. It was written by reading our own source code and writing down what the code actually does, including the parts that are unfinished or awkward. It is published now because a company that handles other people's information owes them a straight account of it, and having no page at all was worse than having a draft.

If you are a lawyer reading this on behalf of a client, or on our behalf: good. Tell us what is wrong with it. privacy@disc-quadrant.com.

On this page

  1. Who we are
  2. The three kinds of people here
  3. Where we operate
  4. What we collect
  5. Why we collect it
  6. The consent basis for each
  7. Employees in Alberta and BC
  8. Who else gets your information
  9. Where it is stored, and borders
  10. Who inside our clients, and inside us, can see it
  11. How long we keep it
  12. Numbers a computer works out
  13. Getting at your own information
  14. Email we send
  15. Analytics and cookies
  16. The talent network
  17. Security, honestly
  18. What we have not finished
  19. How to complain
  20. Changes to this page

1. Who we are

Quadrant is built and run by People Purpose Corporation, a company incorporated in Manitoba, Canada. It is operated by one person, Rod Penner. There is no privacy department. When you write to us, Rod reads it.

Under Canadian federal privacy law, PIPEDA, an organisation has to name someone who is accountable for the personal information it holds and make its practices readily available. That is what this page is for.

2. The three kinds of people here

Quadrant sits between an employer and the people that employer hires or is thinking about hiring. That means we hold information about people who never signed up with us and never agreed to anything with us directly. It matters which one you are, because it changes who decides what happens to your information.

1. You are a client company

You pay us for Quadrant. $30 a month plus $7 a month for each person on your roster, in Canadian dollars. You have an account, you signed up, and you agreed to our terms. Your relationship with us is a service contract.

2. You are an applicant to a job, or an employee of a client company

Your information is in Quadrant because an employer put it there, or sent you a link and you filled it in. You are not our customer. In most cases you have no contract with us at all.

For this group, the employer is generally the one deciding what your information is for. They chose to run a hiring process, they wrote the job description, they decide what to do with what they learn. We hold and process the information on their instructions. In privacy language, they are the organisation with the obligations to you, and we are the service provider carrying out the work. That does not let us off the hook — we are responsible for handling it properly — but it does mean that if you want your information out of an employer's Quadrant account, we will normally need to talk to them, because it is theirs.

Nothing on the candidate side of Quadrant costs money. We do not charge, and will never charge, a person looking for work — not to apply, not to take an assessment, not to be in a pool, not for a copy of their own results. If anyone ever asks you to pay us to be considered for a job, it is not us.

3. You used a free tool on our public site

You took the free assessment, used Read-a-person, asked for a leadership read, or joined our mailing list, for yourself. No employer is involved. Here we are the one deciding what your information is for, and you deal with us directly.

3. Where we operate

We sell to companies in Manitoba, Ontario, British Columbia, Alberta and Saskatchewan, mostly in trades and construction, mostly between 20 and 500 employees.

The federal law, PIPEDA, applies to us. Alberta and British Columbia each have their own private-sector privacy law, both called PIPA, which apply to provincially regulated employers in those provinces and which have specific rules about employee information — see section 7. Manitoba, Ontario and Saskatchewan have no general private-sector privacy statute of their own, so PIPEDA governs there.

Quebec is not a market for us. We do not sell into Quebec and this policy is not written to meet Quebec's Law 25. We do not claim to comply with it. If you are a Quebec employer, we are not the right supplier for you right now.

4. What we collect

If you apply for a job through Quadrant

On the application form: your full name, phone number and email address, all required. A resume file if you upload one (PDF or Word, up to 3 MB). Your answers to the employer's screening questions, if that role has them. A tick confirming you are sharing your application with the employer and with Quadrant.

Then, in the assessment itself: your name, email and company. Twenty-four forced-choice style questions and twenty-five character questions. Records created before 18 August 2026 may also hold six now-retired most/least blocks, kept until their removal is complete. Whether you are currently employed, and if you say yes, three extra questions about commitment that you would not otherwise be shown. How long you took, and when you started. A tick if you want to hear about other roles.

And, without you typing it: your IP address. We store it on the assessment record, not on the leadership read's own record described below. We use it to stop one person submitting the assessment more than six times an hour. It is not shown to the employer. Nothing deletes it from the assessment record. A second copy of it goes into the archive described next, where it also limits how many submissions one connection can file in an hour; there is not yet a scheduled deletion for that copy, and we delete it by hand.

And one thing you should know happens twice. The moment you finish an assessment, we save it raw, before anything is scored. That first save holds your name, your email, your answers, your IP address, the identifying line your browser sends about itself, the link you came in on, the company name you typed, and whether you attached a file. It exists for one reason: so that a failure later in the scoring step cannot lose the fact that you did the work. Nothing on the website can read it back; there is no page, no link and no signed-in screen anywhere that opens it, no employer can see it, and it can only be read by us, by hand, from our own machines. There is not yet a scheduled deletion for this archive; we delete from it by hand. When we do, that removes it from our database, but we do not control how long our database provider's own backups hold a copy, and we do not claim to.

If you join an open-to-work pool

Name, email, phone, your current role, your region, a description of what you are looking for, and a resume as text or as a file. Plus a consent tick.

If you work for a company that uses Quadrant

Your name, email, company and job title. The same assessment battery as above. Five "how to manage me" preferences you set yourself. Your job description, as text or an uploaded file. If your company runs reviews through Quadrant, your own ratings and written notes and your manager's ratings and written notes about you. If you are enrolled in the Growth Program, your progress, your answers to the lesson questions, a written reflection of up to 4,000 characters, and any certificate, which carries your name and your company.

If your company sets up weekly check-ins with you. This is switched on person by person by someone with a managing role in your company — it is built to be started by your manager in a sit-down with you, though any owner, admin or HR login can press the button — never by us, and never by default. It cannot be switched on at all until the org chart says who you report to, or, for the top of the chart, until an accountability partner has accepted. Each week the check-in stores: a one-word answer to how your capacity is — steady, stretched or struggling; an optional written note attached to that word; up to five priorities for the week, each marked red, yellow or green; and asks — short requests for help, filed under manager, teammate, tools, training or wellbeing, with your manager's response. It also stores the shared 1:1 agenda: short items you or whoever runs your 1:1 add ahead of the meeting, each with who added it, when, and whether it has been checked off. It also stores who you picked as your backup for when you are away, accountability-partner invitations and acceptances, and a stamp of when your weekly meeting happened and who recorded it. The written note is the most personal field in Quadrant, and who can see it is deliberately narrow — section 10 spells it out. At your 1:1, whoever runs it records what became of each of last week's priorities (done, carried forward or dropped), and can also file their own notes and short written answers for each part of the meeting, mark the KPIs on your job description green, yellow or red for that week, each mark with an optional note, and turn an agenda item into a task on your task list, which records who added each task and whether it is done. A 1:1 recorded in August 2026, when the meeting page briefly offered recording, also holds a transcript of the conversation; the page no longer records. Section 10 says which of these you see on your own page.

Managers can also write free-text notes about you and about applicants, up to 8,000 characters at a time, stamped with who wrote them and when.

If you have a Quadrant login

Your email address, a stored hash of your password, when you last signed in and when you confirmed your email. Your role in your company's account. Your email address is stamped on the record every time you move a candidate through a stage, add a note, or run one of the AI tools, so there is a trail of who did what.

If you use a free tool on our public site

Your customers, if you use the CRM

If a client company uses the customer tools in Quadrant, it can store company addresses and contact names, emails and phone numbers for its own customers and prospects. Those people never interact with Quadrant and have no idea it exists. That information belongs to the client and is theirs to justify. We hold it for them.

What we do not collect

We do not ask for or store your date of birth, your government identifiers, your bank details, your health information, or anything about your race, religion, sex, or family status. We do not run background checks, credit checks or criminal record checks. We do not buy lists of people. We do not take payment information from anyone except client companies, and that is handled by Stripe, not by us — we never see a card number.

Free-text fields are the honest exception to "we do not ask". A check-in note, an ask filed under wellbeing, or a manager's note contains whatever the writer chooses to type, and people do type personal things — that is what the fields are for. We never ask for health or family information, but we cannot stop a sentence from containing it. That is exactly why the check-in note's visibility is as narrow as section 10 describes.

5. Why we collect it

PIPEDA says we have to tell you the actual purposes, not vague ones. Here they are.

WhatWhat it is for
Your name, email, phoneSo the employer knows who applied and can reach you, and so we can send you your own status updates and results.
Your resume and screening answersSo the hiring manager can read them, and so your screening answers can be checked against any hard requirements the employer has set. If an answer does not meet a hard requirement, or a question with a hard requirement is left unanswered, your application closes automatically when you submit it. Section 12 explains this and names the two other things that close an application automatically.
Your assessment answers, and the scores worked out from themTo describe how you naturally work and communicate, so the employer can ask better interview questions, onboard you better, and manage you better. The assessment informs a hiring decision. It does not make one. It is not a test you can fail and it does not measure whether you can do the work.
How long you took, and consistency checks across your answersTo flag when a set of answers looks idealised, so a human reads the profile with that in mind.
Your IP addressRate limiting and abuse prevention. Six assessment submissions per hour, and a daily cap on free Read-a-person use. The leadership read is recorded with an address but is not currently capped, so a room full of people on one wifi connection is never mistaken for one person abusing it.
Whether you are currently employedIt decides whether you are shown three questions about commitment to a current employer. If you are not employed, you never see them.
Your job title and job description, if you are on a teamThe job description sets the standard for the seat. It is used to build the targets for that role, to shape review scorecards, and to produce a read on how well your measured style lines up with the seat you are in.
Manager notes and review ratingsTo run a documented review and development process inside the employing company.
Weekly check-in entries: your capacity word, your note, your priorities, your asksTo give you and your manager a standing weekly conversation with a written spine, and to flag patterns worth a human conversation — section 12 lists exactly what is computed from them.
Login details and the who-did-what stampsTo sign you in, and so a company can see which of its people took which action on a candidate's record.
Company account details, roster count, admin emailTo bill the company. $30 a month plus $7 a month per person on the roster.
Marketing list detailsTo send you the emails you asked for, and to stop sending them when you say so.

We do not sell personal information. We do not rent it, trade it, or hand it to advertisers or data brokers. We do not use your assessment answers to train AI models — see section 8 for what our AI supplier's terms say.

Consent under PIPEDA has to be meaningful, and it has to fit what is being collected. Here is what we rely on, and where the ticks actually are.

Withdrawing consent. You can withdraw consent, subject to legal and contractual limits and to reasonable notice. Section 13 tells you exactly how, and is honest about which routes are one click and which are an email to a human.

7. Employees of client companies in Alberta and British Columbia

Alberta's PIPA and BC's PIPA both have a category called personal employee information. In broad terms, they allow an organisation to collect, use and disclose information about its own employees without their consent where it is reasonably required to establish, manage or end the employment relationship — but only if the organisation has given the employee notice of what it is collecting and why.

That notice is your employer's job, not ours. We are the software. Your employer is the organisation that decided to gather this and decided what it is for. Under both statutes, the duty to tell you sits with them.

If you are an employee in Alberta or BC and nobody told you your assessment, your job description, your review notes and your manager's notes about you were going into a system called Quadrant, then something has gone wrong upstream of us. Ask your employer. And tell us at privacy@disc-quadrant.com, because we would rather know.

Two things worth saying plainly to employees:

8. Who else gets your information

The employer

If you took an assessment through a link a company sent you, that company sees your results. Its people can open your profile, your report, your resume, your notes and your scores according to their role in the account and where they sit on its org chart. See section 10 for who inside a company sees what.

People Purpose

We operate the platform, so we can technically reach everything in it. See section 10.

Companies that do work for us

These are the suppliers that actually touch personal information. This list is what our code sends, function by function, not a generic list.

SupplierWhat it does for usWhat it receives
Supabase Our database, our file storage and our login system. Everything in section 4. Every record, every assessment, every note, plus resume and job-description files.
Netlify Hosts the website and runs the server code. Every request to the site, which means IP addresses and browser details. Our server logs, which in some places include names and email addresses.
Anthropic (Claude) The AI behind our written reports, resume reads, interview kits, review scorecards, alignment reads and the in-app assistant. Depends on the feature, and it is more than people assume. It can include: your name; your full score profile; up to 8,000 characters of your resume for a hiring read, 6,000 for a skills score, 12,000 for reformatting; the whole of an uploaded PDF, sent as a document; up to 60,000 characters of an interview transcript; your job description; your DISC profile compared against a named manager's; and, for Read-a-person, the raw text you pasted about someone else. The in-app assistant also sends a 7,000-character snapshot of whatever is on the user's screen, which on a hiring page includes candidate names and details.
Resend Sends every email we send. The recipient's email address, their name, and the content of the message.
Stripe Takes payment from client companies. The company's account id, the number of people on the roster, and the billing administrator's email address. No candidate or employee information goes to Stripe. We never see or store a card number.
Cloudflare Delivers three code libraries that read PDF and Word files in your own browser. Only the fact that your browser fetched a script, and the IP address that came with it. Your file is read inside your browser and is not sent to Cloudflare.
Adzuna A job board we pull public postings from. Nothing about you. The traffic goes one way, out from us. No applicant information is sent to Adzuna.

About the AI. Anthropic's commercial API terms state that inputs sent through the API are not used to train their models. We use two separate keys with Anthropic — one for the product features and one for the in-app assistant — and we have not confirmed that both sit under identical commercial terms. We are saying that here rather than assuring you of something we have not checked.

About phone numbers. We collect them and show them to the employer. We have text-message code in the product but nothing in the live product uses it, so as of today no phone number you give us is sent to a messaging service.

Other disclosures

We will disclose personal information if a law, a warrant, a subpoena or a court order requires it, or where it is necessary to investigate a breach of an agreement or of the law, or to protect someone from harm. If our business is ever sold or merged, information would move with it, and we would tell affected clients before it did.

9. Where it is stored, and borders

Canadian law lets an organisation use suppliers in other countries to process information on its behalf, and does not require your separate consent to do so. What it does require is that we tell you, plainly, that this happens, and that while your information is in another country it is subject to that country's laws — including access by that country's courts and law enforcement. So: it happens, and it is.

Anthropic, Resend, Stripe, Netlify, Google and Cloudflare are all American companies. Unless we say otherwise here, you should assume information that reaches them is processed in the United States.

An honest gap. Our database is hosted by Supabase, and the physical region of our database was not something we could determine from our own code. We are confirming it and will name the country on this page when we have. We would rather tell you we do not yet know than guess at a country and be wrong about where your assessment answers physically sit.

10. Who inside our clients, and inside us, can see it

Inside a client company

A client account has roles. In plain terms:

Which of your colleagues holds which role is your employer's decision, not ours. Whether a partner firm is involved is also your employer's decision.

What an employee sees about themselves versus what their manager sees

This asymmetry is real and you should know about it. If you are an employee with a Quadrant login, your own page shows you your job description, your course progress and your task list (tasks made from your 1:1 agenda are marked that way). If your company runs weekly check-ins with you, it also shows you your week: your capacity word and note, your Top 5 for this week, last week's five and what became of each one, your asks and the answers to them, the shared 1:1 agenda, when your next 1:1 is, the marks your manager gives the KPIs on your job description in your weekly 1:1, and a list of your recent 1:1s.

When you finish the assessment, you see your own result on that screen and can keep a copy then. After that, your page shows your DISC result and your report: your primary and secondary style, your style mix, your five self-rated character measures (drive, humility, coachability, compassion and positivity) and the written profile built from them. If you hold the "employee" login, they appear there only once your manager or your company turns that on for you; until then your page says they are held with your manager. Any other login sees them already, and on a record created before 18 August 2026 may also see a behaviour-based rating and the gap between it and the self-rating, until that data's removal is complete.

The notes your manager files in your 1:1s, and the notes they add to your KPI marks, appear on your page only if your manager or your company turns that on for you. When it is on, you see them for your latest 1:1 and in your list of recent ones, marked as shared with you, and the meeting page shows your manager which note boxes you will see. The transcript of a recorded 1:1 is never shown on your page. If you hold an owner, admin or HR login, you can already open every 1:1 record in your company, your own included, transcript and all, so for you this switch is always on and your filed notes show on your page whatever it is set to.

Those are the two sharing switches, "Full DISC report" and "1:1 notes". Each is set for one person at a time, and both start off, except where your login already shows it: the DISC switch is always on for any login other than "employee", and the notes switch for an owner, admin or HR login. Your manager on the org chart, the person in the nearest filled seat above yours, can turn either one on or off whatever login they hold, and so can an owner, admin or HR login at your company, which includes the certified people at a partner firm while your company has partner access switched on. Each change is recorded with who made it and when. The switches change only what your own page shows you, not what anyone else sees.

Depending on their login, your manager and the owners, admins and HR at your company see more than your page shows you, whichever switches are on: your candour flags, your "how to manage me" preferences, an AI-written read on how well you line up with your seat (expressed as aligned, tension or misfit), the full AI-written narrative report, your review ratings and notes, and the transcript of any 1:1 that was recorded. On a record created before 18 August 2026, your manager may also see the self-rating and behaviour-based rating separately, rather than just the gap, until that data's removal is complete.

Your page also has a "Download everything held about me" button, which gives you a file at any time without asking anyone. That file is your legal access copy, and it holds more than your screens show: every answer you gave on the assessment and every score worked out from them, candour flags included, and your answers about commitment to your employer if you were asked them, even while your result is held from your page; the details stored with your record, such as your "how to manage me" preferences and, if one has been made, the alignment read; your Growth Program history; and, while the 1:1 notes switch is on, the 1:1 notes your page shows you. Other people's records are left out, though a note your manager wrote may name someone else. The file does not include your stored IP address, uploaded files such as a resume, your reviews, your weekly check-ins, asks, task list, job description and the KPI marks on it, a 1:1 transcript, or the free-text notes a manager keeps on your record; most of those are on your own page. For those, or for anything else your manager sees, ask us at privacy@disc-quadrant.com. You have a right to access your own information and we will not hide behind the interface.

The weekly check-in note

The written note you can attach to your weekly capacity word is the most personal field in Quadrant — people use it for things like "rough week at home". So it has the narrowest visibility in the product, and the narrowing is enforced in the server code, not just hidden on a screen: the note is returned only to you, to whoever runs your 1:1 (the person you report to on the org chart, or the accountability partner you picked if nobody is above you), whatever kind of login they hold, and to someone with a managing role in your company — the owners, admins and HR listed above — opening your individual check-in page or the 1:1 meeting page, and, while your company has partner access switched on, the certified people at its partner firm, who have an administrator's access. It is never included in the team summary, never in the Monday digest email, and never in the eight-week history strip; we have checked the three server reads behind those screens and none of them selects the note column. The digest does carry your one-word capacity flag and the text of your open asks — asks are requests you are sending your manager, so they travel to your manager — but the note does not. Items on the shared 1:1 agenda are emailed too: at 8am the morning after an item is added, both people in that 1:1, you and whoever runs it, get an email with the item's text and who added it. Nobody else gets that email, and the note is never in it. And check-ins cannot be switched on for you at all until the org chart says who you report to, or an accountability partner you invited has accepted — whoever that is, is who your weekly meeting is built around.

Inside People Purpose

At the database level we can technically reach everything, and we should say so rather than let you assume otherwise. Our server code uses a database key that bypasses the database's own row-level permissions. What keeps one company's records separate from another's is our application code filtering by company on every request, not a wall inside the database. That is about the key, and it has not changed. What follows is about the product, and that has.

Platform administrator accounts — today, that is Rod — can step inside a client company's account and act as its owner. That used to be an unconditional master key with no record and no notice. It is not any more. On a paying account, nobody at Quadrant can open your account unless you invite us in, and you are told and shown every time we do. An owner or admin opens the door in Settings under "Support access", for 24 or 72 hours. It shuts by itself when the time runs out, and the revoke button shuts it on our very next click. That page shows you whether access is open right now, who opened it, when it expires, every area we opened and on what day, and the same record for past sessions. The first time we actually use a grant, your owners and admins get an email saying we are in.

We do keep a break-glass path, and you should know its shape. There will be a case where the broken thing is your login, so you cannot grant anything. In that case a platform administrator can open access without asking — but only for four hours, only with a written reason, and your owners and admins are emailed immediately with that reason. It lands in the same list on the same Settings page, marked "Emergency", with the same revoke button. So it is a documented front door rather than a back one: we can let ourselves in, and we cannot do it quietly.

Two honest exceptions. One: if Rod is a named member of your account, he needs no grant — but he appears by name in your Member accounts list, where you can see him and remove him. Two: while your account is complimentary — the setup phase, before a paid subscription starts, when People Purpose is building your roster and hiring out with you — People Purpose has standing access and individual visits are not itemised. (This is about People Purpose itself. A separate partner firm, if your company has one, is covered in the role list above and has its own switch and its own visit list in Settings.) Your Settings page says so in those words rather than claiming the door is shut. That standing access ends by itself the day your subscription begins, and the invite-and-log rule applies from then on.

All of this fails closed. If we cannot read the grant, or cannot write the access record, the request is refused rather than quietly allowed. We are writing it down at this length because a policy that quietly implies more protection than the code delivers would be a false statement about our security, and that is worse for everyone than an uncomfortable paragraph.

Links that work without a login

Several things in Quadrant are reached by a link rather than a password: an assessment invitation, a short apply code, a shared report link, a job-description upload link, a review form, an opt-out link, an unsubscribe link. Most are signed so they cannot be guessed. One is not signed: a shared report link is the assessment's own random identifier, and anyone who has that link can open that report without signing in. It cannot be guessed, but it can be forwarded. Treat a report link like a document, not like a locked door.

11. How long we keep it

The plain answer

One thing expires on its own, on a schedule. Everything else stays until somebody deletes it, by hand. We still do not have a general retention schedule.

We have checked our own code for this, and we have corrected this paragraph because the previous version of it was wrong. Recorded screening interview video goes 90 days after the invitation, and sooner when the application is closed or rejected, the candidate is hired, or the role is filled — and also when a screening deadline you were given runs out and the application closes itself. The raw assessment archive described in section 4 does not have a scheduled deletion yet; we clear it by hand. Nothing else in Quadrant deletes personal information because it has got old. Assessment answers, scores, the IP address on the assessment record, applications, notes, reviews, weekly check-ins and resumes are all kept indefinitely until a person deletes them.

What we do instead of a schedule, today:

Things you should specifically know are not cleaned up by any of that today:

We intend to set actual retention periods for the rest of it and build the jobs that enforce them. One of those jobs, for recorded screening interview video, already exists and is named above; the raw assessment archive does not have one yet, so until it does we delete from it by hand. If a period matters to you, ask and we will delete on request rather than making you wait for a schedule that is not built yet.

12. Numbers a computer works out

Quadrant calculates things about people. You are entitled to know what, and how much weight it carries.

When an application closes automatically

Three things close an application without a person acting at the time. Nothing else does.

Three other automatic actions exist, and each follows a decision a person makes at the time. When a manager marks someone hired, everyone else on that role is automatically closed and sent an honest update. A manager can close a role and notify its whole pipeline in one action, with a preview first. And marking someone hired automatically converts them from an applicant into a team member and copies the job description across.

The fit number

When an employer builds a role profile, they set target ranges for the seat. Quadrant then works out a number out of 100 comparing an applicant's measured style mix and character answers against those targets. Half the number comes from how far the style mix is from the target mix; the other half counts only shortfalls below a target, so exceeding a target costs nothing. It is arithmetic, not AI, and it is the same calculation for everyone.

What that number is not. It is not validated. Nobody has run a study on whether it has an adverse impact on any group, and our own code says so in writing. It ranks a list on a screen so a hiring manager can decide who to read first. It does not remove anyone from a pipeline, and no part of the product acts on it by itself. If an employer used it as a cutoff, they would be using it against our written guidance and, we would argue, against what employment and human rights law expects.

Two guardrails do exist in the code. If a job description was generated around a specific named employee, that role cannot be scored against at all. And the number is not shown everywhere: the interview guide, the page an interviewer opens with one named person in front of them, is not given it. The server strips it out before the response leaves us, so the browser never receives it. What that page shows instead is the per-measure comparison — which measures sit at the role's target and which sit under it, with both numbers — because that is a thing to ask about rather than a mark out of a hundred. The number still exists on the employer's list of applicants, which is what the paragraph above describes.

The skills and experience read

Separately, the AI compares a resume against a job description. It works out the requirements the job description asks for, then judges each one as evident, partial or not evident, and has to supply a quote from the resume for anything it marks evident or partial. We check that quote is really in the resume before it is shown, and drop it if it is not. Each requirement also carries an estimate of the capacity your work history suggests you operated at with that skill, which is a reading rather than a quote and is labelled that way where it appears. The result is saved on your application record. It is a language model's judgment, not a calculation, and it carries all the limits that implies. It is shown to a person; it does not act on its own. Requirements that would stand in for a protected characteristic are stripped out by our code before anything is judged, in either direction. Applications from before mid-August 2026 may instead carry the single score out of 100 that this replaced.

The alignment read

For an existing employee, Quadrant can compare their profile against their job description and store a one-word band — aligned, tension or misfit — with a short written explanation, on their record. Their manager sees it. The employee does not see it on any screen, whichever sharing switches are on, but if one has been stored it is in the file the "Download everything held about me" button on their own page gives them. Ask us and we will show you yours.

Check-in flags

If your company uses weekly check-ins, three flags are computed from them, none of which act on their own. They appear on the company dashboard, which — as the role list in section 10 says — every login role except the employee login can open. A capacity watch: three submitted check-ins in a row rated below steady, or two "struggling" ratings across your last four submitted check-ins, puts a check-in-on-them flag beside your name — the flag, never your note. Weeks you skip are simply not counted, in either direction. A stale meter: a count of consecutive recorded check-in weeks that have gone by without the weekly meeting being held, shown against the manager, not the employee. And an over-leveraged flag on any manager with more than six direct reports. Each is plain arithmetic on the records described in section 4, each exists to prompt a human conversation, and nothing escalates, notifies anyone outside your company, or changes anyone's standing on its own.

You can ask

If a number about you was worked out by Quadrant, you can write to privacy@disc-quadrant.com and ask what it was, what went into it and what it means. We will tell you. If you think it is wrong, tell us and tell the employer — they are the ones deciding what to do with it.

13. Getting at your own information

Under PIPEDA you can ask what we hold about you, ask for a copy, ask us to correct it if it is wrong, and withdraw your consent. Here is the actual route for each, including where the route is a person and not a button.

What works with one click, today

What requires an email to a human

Correction, erasure, and access to anything the download above leaves out all go through privacy@disc-quadrant.com, and so does any request from someone without a Quadrant login. Apart from that download there is no self-service export, and there is no self-service delete. A request is handled by a person, by hand. We will:

The limits, stated straight. If your information is in a client company's account, that company is the one deciding what happens to it, and there are records — a manager's notes about a candidate, a review, a hiring file — that they may have their own legal reason to keep. We will always tell you what we hold, and we will tell you which employer to talk to. We may not be able to delete an employer's record of you on your say-so alone. Where we can delete, we will, and quickly.

We may also refuse or limit access where the law says we must — for instance where releasing something would reveal personal information about another person that cannot be severed. If we refuse, we will tell you in writing, tell you why, and tell you how to complain about it.

One thing that is deliberately one-way. If you have clicked a link telling us never to contact you about roles again, nothing on a later form quietly undoes that — not leaving a box unticked, and not ticking it either. The code that records a tick specifically leaves your withdrawal standing. If you want back in, tell a person: privacy@disc-quadrant.com. We built it that way on purpose.

14. Email we send

Canada's anti-spam law, CASL, governs commercial email. Our position on each kind of message:

Emails your employer's account sends to you as an applicant go to you. We are not copied on them. The one address of ours that appears on them is the accommodation line, which you can write to if you need the assessment in another format or need more time — we pass that on to the employer, who arranges it.

15. Analytics and cookies

No analytics runs on this site today. If we switch on Google Analytics for the public marketing pages again, it will set no cookies, and it will never run anywhere you are signed in or anywhere a personal link takes you. This page will say so when that happens.

The history matters, so here it is. We used to run Google Analytics across most of the site — including, for a time, pages whose addresses carry a personal link — without asking first. On 11 August 2026 we removed it entirely rather than add a cookie banner, because the default setup was sending Google the full address of pages it had no business seeing.

If we switch it back on, it will be narrower than before, in three ways. Where: only public marketing pages: the home page, product pages, the job board and public job ads, the character profiles, and policy pages like this one. Never the signed-in product, never an assessment, never a report, never any page you reach through a link that was emailed to you. What: before anything is sent, the page address will be stripped down to its path plus recognised campaign codes, a short allowlist, so a link that carries anything personal is cut off before Google sees a byte of it. How: it will be configured to store nothing on your device, no cookies, no identifiers, so it will not be able to recognise you across visits and there will be nothing to consent to storing. It will also honour your browser’s Do Not Track and Global Privacy Control signals: send either and it will not run at all.

Quadrant still uses the cookies and browser storage it needs to keep you signed in and to remember your place in an assessment. Those are not optional; without them the product does not work. They identify you to us, not to anyone else. Be aware of what the assessment one holds: once you press Begin, your name, your email, the company and title you typed, and the answers you have given so far are kept on that device for up to 24 hours, so that a closed tab or a flat battery does not cost you the work. It is erased the moment our server confirms it has your submission, and it expires by itself after 24 hours whether or not you come back. Nothing is written before you press Begin, so loading the page on a shared or public computer and walking away leaves nothing behind.

If you visited before 11 August 2026, Google’s _ga cookies may still sit in your browser from that period. Nothing reads them — the analytics described above stores nothing on your device and does not read what the old setup left behind. You can delete them in your browser settings and nothing about this site will change.

16. The talent network

We designed a shared talent pool across the companies hiring on Quadrant. It is switched off. The job that would copy people between accounts stops at its first line unless a server switch is set to on, and there is no screen anywhere in Quadrant that lets one company search another company's people.

Two honest caveats. First, that is a pause set by a configuration value, not a guarantee written into the code — and the job is still on a daily schedule, doing nothing. Second, while it was running it copied some client records into our own pool, and those copies are still there; we are working through them. Our methodology page sets out the full position, including the one route by which a person can still move between companies today, which is a human at People Purpose placing a candidate from our own recruiting pool into a client's pipeline by hand.

17. Security, honestly

What is true: everything travels over encrypted connections. Passwords are hashed by our login provider, not stored by us and not visible to us. Uploaded resumes and job descriptions go into a private file store, not a public one. We never see or store payment card details.

What is true with a qualification: most server requests check who you are and what role you hold before returning anything, and most links that reach a page without a login are signed so they cannot be guessed. Not all. The shared report link is the assessment's own random identifier rather than a signature, and the request behind it takes no credential: hand that link to anyone and they can open that person's scores, name, company and the role they applied to. Our free Read-a-person tool also runs for people who are not signed in, limited by a daily count against your address rather than by a login. Those are the two exceptions we know of, and section 10 describes the first one from the other direction.

What is also true, and stated in section 10: separation between one company's records and another's is enforced by our application code, not by the database itself. Platform administrator access into a paying client's account now needs that client's invitation, expires on its own, is logged where the client reads it, and emails them when it is used — with a four-hour break-glass path that also emails them, with a reason, immediately. One person operates this company, which means the security of your information still depends on the practices of one person and the suppliers listed in section 8.

No system is completely secure and we are not going to tell you ours is. If we ever have a breach that creates a real risk of significant harm to you, we will report it to the Privacy Commissioner and notify affected people, as PIPEDA requires, and we will keep a record of it.

18. What we have not finished

Openness means telling you what is missing, not just what is working. Everything here is stated somewhere above; this is the same list in one place, so nobody has to hunt for the bad news.

If one of these matters to you before you buy, or before you take an assessment, say so and we will tell you where it stands. Some of it will be fixed by the time you read this, and when it is, this page changes.

19. How to complain

Start with us. privacy@disc-quadrant.com. Tell us what happened and what you want done. We will acknowledge it, investigate it, and write back within 30 days with what we found and what we did. If we got it wrong, we will say so and fix it. If we disagree with you, we will tell you why in writing, so you have something to take to a regulator.

If we do not sort it out, go over our heads. That is your right and we are not going to make it awkward.

If your complaint is really about what your employer did with your information, the regulator will likely want to deal with your employer. We will cooperate with either of you.

20. Changes to this page

We will change this page as the product changes and as the gaps in section 18 get closed. The effective date at the top will change with it. If a change materially affects how we use information we already hold about you, we will do more than quietly edit the page — we will tell affected clients directly, and where we hold your email and the change matters to you, we will tell you.

Quadrant is operated by People Purpose Corporation, Manitoba, Canada. See also how the assessment works and how to use it responsibly and the shorter assessment privacy and fair use note. Where the two differ, this page is the fuller and more current account.

Ask us about your information → Talk to us