Privacy & data protection
This page is written to be read, not to protect us from you. It covers the three kinds of people whose data we hold — individuals who take an assessment, practitioners who apply for certification, and corporate clients who run teams through the instrument — because they trust us with very different things.
The short version
- ✓Anonymous by default — the individual assessment needs no account and no name.
- ✓We never sell personal data, and we run no advertising.
- ✓No individual result reaches an employer, sponsor or coach without that person's explicit consent.
- ✓Team reporting is aggregate only, never below five completed assessments.
- ✓AI marks written answers; a person makes every certification decision, and you can ask for a human re-mark.
- ✓Data lives in Mumbai, India; named processors only, under contract.
1. Who we are
LightningCoach operates lightningcoach.com and is the data controller for the personal data described here, except where a corporate client engages us to process their team data — in that case the client is the controller and we are their processor. For anything on this page, write to admin@lightningcoach.com with the subject “Data request”.
2. If you take the assessment (individuals)
You are anonymous by default. The leadership assessment asks for no account, no name and no email. Your session is identified only by an unguessable link — whoever holds the link holds the result, which is why we tell you to treat it like a ticket.
We collect your answers, the time you spend on each scenario, and the result we compute from them. Legal basis: performing the service you asked for (contract). Timing data exists to make your report more useful — where you hesitated — and to catch gamed responses, not to profile you beyond the report you see.
If you choose to save your result by email, we store that email for exactly one purpose: sending and retrieving your result. Legal basis: your consent, withdrawable any time from the same address. We do not add you to marketing lists you did not ask for.
Anonymised, aggregated response data — stripped of anything that could identify a person — is retained to build norms and improve the instrument. That is what makes the assessment free.
3. If you apply for certification (practitioners)
Certification is the one place we require identity, because we put our name on yours. We collect your name, LinkedIn identity, email, years of experience, any coach training history, your readiness-screen result, and your professional-standing declaration. Legal basis: taking steps to enter a contract with you, and our legitimate interest in certifying only people we have actually vetted.
Your misconduct declaration is never public. It is visible to the people reviewing your application and to no one else. The public registry shows your name, certificate ID, status and year — nothing more.
On AI marking: written answers in the readiness screen are marked by an AI model against published rubrics. No certification decision is made by the model alone — a person reviews every application, and you can request a human re-mark of any written answer by writing to us. This is your right under GDPR Article 22, and it would be our practice anyway.
If your credential is revoked for an ethics breach, the registry entry is marked revoked rather than deleted. A verification registry that forgets its revocations would be worthless to the clients who rely on it.
4. If you run a team through it (corporate clients)
For team engagements, your organisation is the controller of its participant data and we act as processor under your instructions. A data processing agreement (DPA) with standard contractual clauses is available on request before any engagement starts.
The structural protections are not negotiable, because they protect your people from you as much as from us: reporting is aggregate only, no breakdown is shown below five completed assessments, and no individual result reaches you without that individual’s explicit consent — requested from them, not from whoever pays.
Participants join through an invite link without creating accounts. What you see is the distribution of imprints and capability signals across the team; what you do not see is who answered what.
5. Where your data lives
Primary storage is in Mumbai, India. We use a short list of processors, each under contract, each for one job:
| Processor | What they do | Where |
|---|---|---|
| Supabase (on AWS) | Database and authentication | Mumbai, India |
| Vercel | Website hosting and cookieless analytics | Global edge network |
| Resend | Transactional email (result delivery) | United States |
| Anthropic | AI marking of written answers in the readiness screen. API inputs are not used to train their models. | United States |
| Identity verification at sign-in only — we receive name, profile URL and email; we post nothing. | United States |
Where data moves between jurisdictions — including to processors in the United States — transfers rest on the processors’ standard contractual clauses. We do not use processors that reserve the right to use your content for their own purposes.
6. How long we keep things
| What | How long | Then |
|---|---|---|
| Anonymous assessment responses and results | 24 months from completion | Deleted, or irreversibly anonymised into aggregate norms |
| Saved results and the email you gave us to keep them | Until you ask us to delete them, or 24 months of inactivity | Deleted |
| Certification applications that were declined or withdrawn | 12 months from the decision | Deleted |
| Certified practitioner records | Life of the credential | If revoked, a minimal record (certificate ID and status only) is kept so the public registry stays truthful |
| Team and corporate engagement data | Duration of the engagement plus 90 days | Deleted, or anonymised into aggregates |
7. Your rights
Under the GDPR (if you are in the EU/UK) you can ask for access to your data, have it corrected or deleted, receive a copy in a portable format, restrict or object to processing, and withdraw any consent you gave. Under India’s Digital Personal Data Protection Act 2023 you hold closely equivalent rights, including grievance redressal. We apply the same standard to everyone regardless of where you live — rights should not depend on jurisdiction.
To exercise any of them: email admin@lightningcoach.com with the subject “Data request”. We respond within 30 days. For anonymous assessments, include your result link — it is the only way we can find your data, which is the point of the design.
You can also complain to your supervisory authority — in the EU, your national data protection authority; in India, the Data Protection Board. We would rather you wrote to us first, but that is your choice, not a condition.
8. Cookies, analytics and age
We use only the cookies the service needs to function (session and sign-in). Our analytics are cookieless and aggregate — page views and funnel events, not individuals followed around the web. There is no advertising, no third-party ad trackers, and consequently no cookie banner asking you to accept them.
You must be 18 or over to use LightningCoach.
9. Changes
When this policy changes materially, the version number and effective date at the top change with it, and the previous version is available on request. We will not quietly weaken a commitment and hope nobody reads the diff.