1. Who We Are
Data Controller: Human Capital CXO, Inc., a Delaware corporation, 5319 University Drive #181, Irvine, CA 92612, USA.
Privacy contact: privacy@humancapitalcxo.com
This Privacy Notice applies to all personal data processed in connection with this website, the HCV Model platform, and related services. It fulfils transparency obligations under the EU General Data Protection Regulation (GDPR) Arts. 13–14, the Swiss revised Federal Act on Data Protection (revFADP / nDSG) Art. 19, and the EU AI Act 2024/1689 Art. 13 transparency requirements where applicable.
2. Data We Collect
| Category | Elements | Source |
|---|---|---|
| Account & enquiry | Name, work email, company, role, and anything you write in an enquiry | You, at registration or enquiry |
| Authentication | Hashed password, session token, login timestamps | Supabase Auth |
| HCV calculation inputs | Salary, service states, probabilities, EI(cf)/IM(cf) scores, discount rate, time horizon | You, in the calculator |
| Usage | Pages visited, features used, session duration, truncated IP address | Cloudflare / server logs |
| Communications | Support emails, advisory enquiries | You, by email |
We do not collect health data, biometric data, racial/ethnic origin, political opinions, or any other Art. 9 special-category data.
3. Legal Bases and Purposes
| Purpose | GDPR basis |
|---|---|
| Providing the platform and HCV Model | Art. 6(1)(b) — contract |
| Transactional and service emails | Art. 6(1)(b) — contract |
| Security — fraud detection, audit logs | Art. 6(1)(f) — legitimate interests |
| Aggregate analytics (no profiling) | Art. 6(1)(f) — legitimate interests |
| Pilot programme contact and enrolment, from the enquiry form | Art. 6(1)(a) — consent |
| Legal compliance and accounting records | Art. 6(1)(c) — legal obligation |
4. Retention
| Data | Retention |
|---|---|
| Account & engagement data | Account lifetime + 3 years (tax/legal) |
| HCV calculation results (identified) | 24 months, then deleted or anonymised |
| M&A transaction records | 10 years (Swiss OR) |
| Server & access logs | 90 days (security only) |
| Support correspondence | 3 years from last interaction |
| Anonymised analytics | Indefinite |
5. Processors and Recipients
We do not sell personal data. We share only with the following processors under signed DPAs:
- Supabase Inc. (USA) — database & authentication. EU SCCs + Swiss adequacy framework.
- Cloudflare Inc. (USA) — CDN, access control, DDoS protection. EU SCCs in place.
- Resend (USA) — delivery of the enquiry confirmation and pilot correspondence. Receives your name and email address for that purpose. EU SCCs in place.
- Google Fonts (USA) — font delivery on public pages only. No cookies; IP transmitted transiently.
6. International Transfers
Transfers to US-based processors are covered by EU Standard Contractual Clauses (SCCs) consistent with GDPR Chapter V and Swiss DSG requirements. Supabase EU-region hosting is used where available. Enquiry correspondence is additionally received and retained in our operational mailbox.
7. Your Rights
- Access (GDPR Art. 15 / nDSG Art. 25) — copy of your data
- Rectification (GDPR Art. 16 / nDSG Art. 25) — correct inaccurate data
- Erasure (GDPR Art. 17 / nDSG Art. 25) — deletion (subject to legal retention obligations)
- Restriction (GDPR Art. 18) — pause processing during disputes
- Portability (GDPR Art. 20) — structured export of your account data
- Object (GDPR Art. 21 / nDSG Art. 30) — object to legitimate-interest processing
- Human review (GDPR Art. 22 / nDSG Art. 21) — review of any automated processing
- AI Act transparency (EU AI Act Art. 13) — right to receive meaningful information about automated HCV calculations where the platform is classified as a high-risk AI system under Annex III
Email privacy@humancapitalcxo.com. Response within 30 days. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch, +41 58 462 43 95, or with your local supervisory authority.
8. Cookies
One strictly necessary session cookie (hcv_session) maintains your login state. No advertising or behavioural tracking cookies. Cloudflare sets technical cookies for DDoS protection; these are session-scoped and strictly necessary. No consent banner is required for strictly necessary cookies.
9. EU AI Act — Transparency Obligations
Where the HCV Model platform is used for employment-affecting purposes in the EU, it is likely classified as a high-risk AI system under EU AI Act 2024/1689, Annex III (HR and workforce management). In such deployments, users are entitled to receive clear information about the system's intended purpose, accuracy metrics, human oversight mechanisms, and any known limitations. Contact compliance@humancapitalcxo.com for AI Act conformity documentation.
10. Changes
Material changes will be notified by email at least 30 days before they take effect. The version and effective date always appear at the top of this page.