endtoend
HomeContact

Legal

Privacy Policy

Effective Date: July 27, 2026

This Privacy Policy explains how endtoend.it, a sole trader operating in Israel under the trade name "endtoend.it" ("endtoend.it," "we," "us") collects, uses, discloses, and protects personal data in connection with the Service.

This Policy is written for two audiences: (a) Organizations (our customers, typically the employer) and their administrators; and (b) Authorized Users (typically engineers/employees) who take assessments within an Organization's workspace. Where your employer or engagement provider is our customer, please also review any internal notice your employer provides, as your employer may have additional obligations or arrangements with us (see Our Role below).

Our Role: Controller vs. Processor

With respect to identity data, assessment responses, reasoning transcripts, environment reports, and derived scores collected through an Organization's workspace, we act as a processor / service provider on behalf of the Organization (the controller/business) under GDPR, UK GDPR, and CCPA/CPRA, respectively. The Organization determines the purposes for which engineers are assessed and how results are used in employment decisions. We act as an independent controller only for limited purposes: account security, fraud/abuse prevention, aggregated/de-identified service analytics, billing (once applicable), and legal compliance.

Enterprise customers who need a Data Processing Addendum or related compliance documentation may contact us to discuss — see Data Processing Addendum below.

Categories of Data We Collect

CategoryExamplesSource
Identity dataName, work email, profile info via Clerk/OAuth (Google, Microsoft, GitHub)You, via Clerk
Organization dataCompany domain, organization name, declared engineer-count band, role (Owner/Manager vs. Engineer)Organization admin
Assessment responsesAnswers to the adaptive AI proficiency questionnaireAuthorized User
Reasoning/workflow transcriptsAI engineering reasoning assessment content, which may be processed by LLMsAuthorized User
Environment discovery reportsSanitized reports describing an Authorized User's AI development environment/tooling setupAuthorized User (upload)
Scores and derived analyticsComputed scores, summaries, trends, completion statusGenerated by the Service
Device/technical/log dataIP address, browser/device type, timestamps, usage/session logsAutomatically collected
Support communicationsEmails or messages sent to info@endtoendit.ioYou

We ask Authorized Users not to upload secrets (API keys, credentials, tokens) or unnecessary third-party personal data in environment reports; environment reports are intended to be sanitized/scrubbed of secrets, and we do not intend to retain source code.

How We Use Personal Data

  • Provide and operate the Service, including delivering assessments and generating scores/dashboards
  • Verify domain claims and manage Organization workspaces
  • Maintain assessment integrity, detect fraud/abuse/collusion, and enforce our Terms
  • Maintain security of the Service and prevent unauthorized access
  • Provide customer support
  • Improve and develop the Service, generally using aggregated or de-identified data where feasible
  • Comply with legal obligations and respond to lawful requests

We do not sell personal data, and we do not use Customer Content to train third-party foundation models beyond what's needed for real-time scoring/classification, except as separately disclosed or agreed.

Legal Bases for Processing (GDPR / UK GDPR)

PurposeLegal basis
Providing the Service to the OrganizationPerformance of a contract with the Organization; for individual engineers, typically the Organization's legitimate interests in workforce assessment, or contract where the engineer is a party
Assessment scoring, including AI-assisted evaluationLegitimate interests (ours and the Organization's), performance of contract
Security, fraud/integrity monitoringLegitimate interests
Legal complianceLegal obligation
Any optional analytics/cookies beyond essentialConsent, where required

Assessment scores and AI-assisted outputs are decision-support indicators for the Organization. They are not solely automated decisions that produce legal or similarly significant effects on individuals under GDPR Art. 22; Organizations retain human responsibility for any employment-related decisions.

How We Share Personal Data

We do not sell personal data. We share personal data with:

  • Subprocessors / service providers, who process data on our behalf under contract:
    • Clerk — authentication and identity management
    • Railway — hosting infrastructure (application services, managed Postgres, Redis), region: Amsterdam (EU)
    • OpenAI — LLM inference for reasoning/workflow scoring and classification
    This is the complete list of subprocessors as of the effective date above. If this list changes, we will update this Policy and its effective date.
  • The Organization: derived scores, completion status, and summary/trend data are shared with the Organization's Owners/Managers. Raw answers, full transcripts, and underlying evidence are not shared with the Organization through the Service, except where reasonably necessary for a legal dispute, regulatory request, or assessment-integrity investigation (handled manually, limited to what is necessary, and logged internally — not available as a self-serve feature).
  • Legal/compliance: where required by law, legal process, or to protect rights, safety, or security.
  • Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.

AI Processing and Third-Party Model Providers

Reasoning/workflow assessment content may be sent to OpenAI's API for scoring, classification, or interview-style evaluation. Under OpenAI's standard API terms, this data is not used to train OpenAI's models, but may be retained briefly by OpenAI for abuse and misuse monitoring purposes, consistent with OpenAI's API data usage policies. We do not use this content to train our own general-purpose models beyond generating the individual's own assessment output.

International Data Transfers

Depending on where you and the Organization are located, personal data may be transferred to and processed in countries other than your own, including the United States (notably for authentication via Clerk and LLM inference via OpenAI) and the hosting region noted above. Where required, we rely on appropriate safeguards for such transfers under each subprocessor's Data Processing Addendum — typically the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable).

Retention

  • Trigger: the retention period is measured from the Organization's last activity in the Service (e.g., last login, last assessment completed, or last administrative action by an Organization Owner/Manager), not from when each individual item was created.
  • Assessment data (answers, reasoning/workflow transcripts, environment discovery reports, and derived scores) is deleted approximately 1 year after the Organization's last activity.
  • The Organization/account record itself is retained (organization name, domain, admin identity, seat/plan information) even after assessment data is deleted, so the workspace is not lost and can resume activity later without re-provisioning.
  • Data may be retained longer where required by law, to resolve disputes, enforce agreements, or in security backups, which are deleted or overwritten on a rolling basis.
  • Organization-configurable shorter retention periods are not currently available; if introduced, this section will be updated.

Your Rights

Depending on your location, you may have rights to: access, correct, export (data portability), or delete your personal data, and to object to or restrict certain processing.

Requesting a full copy of your data. Any Authorized User can request a complete copy of all personal data we hold about them by emailing info@endtoendit.io from the email address associated with their account. This includes: identity/account data, all assessment responses and reasoning/workflow transcripts, environment discovery reports, and derived scores — not only the summary-level data visible to your Organization's managers. The manager-visibility limitation restricts what your Organization can see through the product; it does not restrict what you yourself can request directly from us about your own data. We aim to provide the export within 30 days of a verified request, in a common electronic format (e.g., JSON or PDF).

Because many Authorized User accounts exist within an employer-controlled Organization workspace, where we act as a processor on behalf of your employer, we may need to notify your Organization of the request or process it jointly with your Organization— this depends on your jurisdiction's law and the nature of the request (e.g., an access/export request is more likely to be fulfillable directly than a deletion request, which may affect your employer's records). Self-serve export/deletion tools are not currently available in the product; all requests are handled manually on a best-efforts basis.

We do not currently market the Service to users in the United States. If we begin doing so, we will update this Policy with any additional notices and mechanisms required under applicable U.S. state privacy laws (including CCPA/CPRA for California residents). We do not sell personal data.

Cookies and Similar Technologies

We currently use only essential cookies/tokens required for authentication and session management (via Clerk) and core Service functionality. We do not currently use analytics, advertising, or marketing cookies, so no cookie consent banner is used.

Security

We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and hosting on infrastructure providers (Railway) with their own security safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children / Age Restrictions

The Service is intended for workforce/professional use by individuals of at least 18 years of age (or the applicable age of working majority) and is not directed to children. We do not knowingly collect personal data from children.

Data Processing Addendum / Enterprise Terms

Enterprise customers who require a Data Processing Addendum, Standard Contractual Clauses, or related security/compliance documentation may contact us at info@endtoendit.io to discuss. We do not currently publish a standard DPA; terms are considered case by case.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to Organization Owners and/or an in-product notice before taking effect.

Contact

Privacy questions or rights requests: info@endtoendit.io
General support: info@endtoendit.io

endtoend.it · AI Engineering Proficiency AssessmentTerms · Privacy