Legal
Privacy Policy
How LRP360 collects, uses, and protects personal data across our marketing site and 360° feedback platform.
Last updated
Overview
LRP360, Inc. ("LRP360," "we," "us") provides a multi-tenant 360-degree feedback platform for enterprise people teams. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, request a demo, or use the LRP360 service as a customer administrator, manager, subject, or rater.
We design the platform with tenant isolation (PostgreSQL Row-Level Security), role-based access, and configurable anonymity thresholds. This policy describes our practices at the platform level; your organization may impose additional policies on employee data processed through LRP360.
Who this policy covers
- Website visitors and demo requestors who interact with lrp360.com.
- Tenant administrators and managers who configure frameworks, cycles, and org structure.
- Feedback subjects and raters who participate in review cycles (including magic-link survey access without a password).
- Authorized customer contacts who manage billing, security reviews, or data subject requests on behalf of their organization.
Information we collect
Information you provide
- Contact details when you book a demo or contact us (name, work email, company, team size, optional message).
- Account credentials and profile information for tenant users (name, email, role, org unit assignments).
- Survey responses, nominations, competency ratings, and open-text feedback submitted during review cycles.
- Branding and configuration data your organization uploads (logos, framework content, cycle settings).
Information collected automatically
- Device and usage data (IP address, browser type, pages viewed, timestamps, referral source).
- Authentication and security logs (login events, token issuance, failed access attempts).
- Operational telemetry needed to maintain reliability, detect abuse, and improve performance.
Information from your organization
Customers may import employee directories via CSV bulk import (name, work email, department, manager email, and related fields). Your organization controls what data is uploaded and who may access it within LRP360. Enterprise SSO and SCIM provisioning are not generally available unless separately agreed in writing.
How we use information
- Provide, operate, and secure the LRP360 platform and related support.
- Authenticate users and raters, enforce role permissions, and maintain audit trails.
- Aggregate feedback, enforce minimum group sizes for anonymity, and generate reports.
- Process demo requests and communicate about the service, onboarding, and product updates.
- Run optional AI-assisted features only when enabled by the customer, with PII stripping before third-party model calls.
- Comply with law, respond to lawful requests, and protect the rights and safety of users and the public.
Legal bases (EEA, UK, and Switzerland)
Where GDPR or equivalent laws apply, we rely on one or more of the following: performance of a contract (providing the service to customers and authorized users), legitimate interests (securing and improving the platform, preventing fraud, and communicating about the service in a proportionate way), consent (where required—for example optional marketing or certain cookie categories), and legal obligation.
Sub-processors
We maintain a list of sub-processor categories in our Data Processing Agreement. Enterprise customers may request the current list and notification of material changes at dpa@lrp360.com.
Data retention
We retain personal data for as long as needed to provide the service, meet contractual obligations, resolve disputes, and comply with legal requirements. Demo inquiries are retained for sales follow-up and then deleted or anonymized on a reasonable schedule unless you become a customer. Customers may export tenant data during active subscriptions using in-product tools. After termination, data is retained according to the customer's agreement and our Data Processing Agreement, then deleted or anonymized unless law requires longer retention.
Security
We implement administrative, technical, and organizational measures including tenant-scoped database isolation (Row-Level Security), encrypted transport (HTTPS/TLS), access controls, and audit logging. Passwords are stored using one-way hashing. Multi-factor authentication is available for privileged accounts. No method of transmission or storage is completely secure; we continuously improve our controls and notify customers of material incidents as required by law and contract.
International transfers
LRP360 may process data in countries other than where it was collected. Our production deployment is customer-directed (typically a single region on your chosen cloud provider). A data residency preference field may be recorded for contractual and roadmap purposes but does not by itself create a separate deployment region unless expressly agreed in your order. Where required, we use appropriate safeguards such as Standard Contractual Clauses and supplementary measures.
Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. Raters and employees should typically direct requests to their employer (the data controller). Website visitors and demo requestors may contact us directly.
We will verify requests and respond within applicable timelines. You may also lodge a complaint with your local supervisory authority.
Children
LRP360 is a business service not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes affecting customers will be communicated through appropriate channels.
Contact us
Privacy questions: privacy@lrp360.com
Data processing agreements: dpa@lrp360.com
LRP360, Inc.