Privacy notice

How the CLCD app uses your information

Notice version 2026-07-21

Who is responsible

Invictus Leadership Ltd (company number 11086841), 13 Kingsway, Blakeney, Holt, England, NR25 7PL is the controller responsible for this diagnostic. Privacy questions and data requests can be sent to learning@invictusleadership.co.uk.

Information and purposes

  • Email and name identify and support your diagnostic session. Role and organisation add context only if you choose to provide them.
  • Your 64 answers and calculated scores create the immediate free snapshot and, if you purchase it, the complete leadership report.
  • After a verified report purchase, your email address is used to send one operational report-ready message with the PDF and secure view/download links. This is separate from optional marketing.
  • Stripe collects and processes payment details on its hosted Checkout page. We receive and retain limited transaction identifiers, your Checkout email, the amount and currency, status, and relevant timestamps; the app does not receive your full card number or security code.
  • Calculated scores and derived leadership patterns are sent to OpenAI through its API to create the AI-assisted interpretation. Your name, email, telephone, role, organisation, and individual item answers are not included in that request.
  • If an older session has not accepted the current AI disclosure, no AI request is made until you confirm it. We record the disclosure version and confirmation time for that session.
  • Commercial-request events let Invictus Leadership respond when you ask for coaching or programme information.
  • Optional marketing consent is separate. Leaving it unticked does not stop you completing the diagnostic.

Lawful bases

  • We rely on your consent to process the details and answers needed to provide this optional diagnostic, including sending derived scores and patterns to OpenAI for the AI-assisted interpretation. You can withdraw that consent by deleting the diagnostic or contacting us.
  • When you choose to buy the complete report, processing the Checkout and delivering that purchased report is necessary to perform that contract with you.
  • We retain essential financial transaction records where necessary to meet accounting, tax, fraud-prevention, and other legal obligations.
  • We rely on legitimate interests to keep the service secure, prevent abuse, maintain essential operational records, and respond to a report, coaching, or programme request you initiate. Those interests are limited to operating and supporting the service in ways you would reasonably expect.
  • We rely on your separate optional consent for marketing email. You can withdraw it at any time without affecting the diagnostic.

Service providers, transfers, and AI

Neon hosts the diagnostic database, Stripe processes the one-off payment on its hosted Checkout page, Resend delivers operational emails, and the OpenAI API creates the AI-assisted leadership interpretation. They process information under their applicable service and privacy terms and may use listed subprocessors.

The OpenAI request contains calculated domain and sub-competence scores and derived leadership patterns. It does not contain your name, contact details, role, organisation, or individual item answers.

OpenAI does not use API inputs or outputs to train its models by default. OpenAI may retain prompts and responses in abuse-monitoring logs for up to 30 days, unless it is legally required to retain them for longer.

These providers may process information in the United States and other jurisdictions. Where information is transferred outside the UK, provider contractual safeguards and recognised transfer mechanisms are used. Contact us if you would like more information about those safeguards.

The AI-assisted interpretation is reflective guidance based on a self-reported diagnostic. It does not make decisions about you and is not used for solely automated decisions with legal or similarly significant effects.

Essential browser storage

The app uses strictly necessary signed cookies to keep your diagnostic isolated and to open a read-only report from a secure email link. A session-scoped draft is stored in this browser so you can resume. The app does not use advertising or analytics cookies.

Storage and retention

The diagnostic server record, generated report, secure report links, and browser draft have a default 365-day retention period. The protected retention job removes expired sessions, answers, reports, fulfilment receipts, and report-email jobs together.

Deleting a diagnostic removes its report content and invalidates its secure links. Minimal payment and reconciliation records are kept separately for applicable accounting, tax, fraud-prevention, dispute, and legal retention requirements.

OpenAI may retain the limited report request and response in abuse-monitoring logs for up to 30 days, unless longer retention is legally required. Operational email systems may retain delivery records under their own configured policies. We review retention rather than extending it automatically.

Your choices and rights

The results page lets you delete the current diagnostic and withdraw its contact consent. Withdrawal does not affect processing that was lawful before withdrawal or shorten a service provider's necessary security or legal retention.

Contact Invictus Leadership to request access, correction, deletion across other sessions, restriction, objection, portability, or marketing withdrawal. We may need to verify your identity before acting on a request.

You may also raise a concern with the UK Information Commissioner's Office.

Return to the diagnostic