Legal
Privacy Policy
This Privacy Policy explains how endtoend.it, a sole trader operating in Israel under the trade name "endtoend.it" ("endtoend.it," "we," "us") collects, uses, discloses, and protects personal data in connection with the Service.
This Policy is written for two audiences: (a) Organizations (our customers, typically the employer) and their administrators; and (b) Authorized Users (typically engineers/employees) who take assessments within an Organization's workspace. Where your employer or engagement provider is our customer, please also review any internal notice your employer provides, as your employer may have additional obligations or arrangements with us (see Our Role below).
Our Role: Controller vs. Processor
With respect to identity data, assessment responses, reasoning transcripts, environment reports, and derived scores collected through an Organization's workspace, we act as a processor / service provider on behalf of the Organization (the controller/business) under GDPR, UK GDPR, and CCPA/CPRA, respectively. The Organization determines the purposes for which engineers are assessed and how results are used in employment decisions. We act as an independent controller only for limited purposes: account security, fraud/abuse prevention, aggregated/de-identified service analytics, billing (once applicable), and legal compliance.
Enterprise customers who need a Data Processing Addendum or related compliance documentation may contact us to discuss — see Data Processing Addendum below.
Categories of Data We Collect
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, work email, profile info via Clerk/OAuth (Google, Microsoft, GitHub) | You, via Clerk |
| Organization data | Company domain, organization name, declared engineer-count band, role (Owner/Manager vs. Engineer) | Organization admin |
| Assessment responses | Answers to the adaptive AI proficiency questionnaire | Authorized User |
| Reasoning/workflow transcripts | AI engineering reasoning assessment content, which may be processed by LLMs | Authorized User |
| Environment discovery reports | Sanitized reports describing an Authorized User's AI development environment/tooling setup | Authorized User (upload) |
| Scores and derived analytics | Computed scores, summaries, trends, completion status | Generated by the Service |
| Device/technical/log data | IP address, browser/device type, timestamps, usage/session logs | Automatically collected |
| Support communications | Emails or messages sent to info@endtoendit.io | You |
We ask Authorized Users not to upload secrets (API keys, credentials, tokens) or unnecessary third-party personal data in environment reports; environment reports are intended to be sanitized/scrubbed of secrets, and we do not intend to retain source code.
How We Use Personal Data
- Provide and operate the Service, including delivering assessments and generating scores/dashboards
- Verify domain claims and manage Organization workspaces
- Maintain assessment integrity, detect fraud/abuse/collusion, and enforce our Terms
- Maintain security of the Service and prevent unauthorized access
- Provide customer support
- Improve and develop the Service, generally using aggregated or de-identified data where feasible
- Comply with legal obligations and respond to lawful requests
We do not sell personal data, and we do not use Customer Content to train third-party foundation models beyond what's needed for real-time scoring/classification, except as separately disclosed or agreed.
Legal Bases for Processing (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service to the Organization | Performance of a contract with the Organization; for individual engineers, typically the Organization's legitimate interests in workforce assessment, or contract where the engineer is a party |
| Assessment scoring, including AI-assisted evaluation | Legitimate interests (ours and the Organization's), performance of contract |
| Security, fraud/integrity monitoring | Legitimate interests |
| Legal compliance | Legal obligation |
| Any optional analytics/cookies beyond essential | Consent, where required |
Assessment scores and AI-assisted outputs are decision-support indicators for the Organization. They are not solely automated decisions that produce legal or similarly significant effects on individuals under GDPR Art. 22; Organizations retain human responsibility for any employment-related decisions.
How We Share Personal Data
We do not sell personal data. We share personal data with:
- Subprocessors / service providers, who process data on our behalf under contract:
- Clerk — authentication and identity management
- Railway — hosting infrastructure (application services, managed Postgres, Redis), region: Amsterdam (EU)
- OpenAI — LLM inference for reasoning/workflow scoring and classification
- The Organization: derived scores, completion status, and summary/trend data are shared with the Organization's Owners/Managers. Raw answers, full transcripts, and underlying evidence are not shared with the Organization through the Service, except where reasonably necessary for a legal dispute, regulatory request, or assessment-integrity investigation (handled manually, limited to what is necessary, and logged internally — not available as a self-serve feature).
- Legal/compliance: where required by law, legal process, or to protect rights, safety, or security.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
AI Processing and Third-Party Model Providers
Reasoning/workflow assessment content may be sent to OpenAI's API for scoring, classification, or interview-style evaluation. Under OpenAI's standard API terms, this data is not used to train OpenAI's models, but may be retained briefly by OpenAI for abuse and misuse monitoring purposes, consistent with OpenAI's API data usage policies. We do not use this content to train our own general-purpose models beyond generating the individual's own assessment output.
International Data Transfers
Depending on where you and the Organization are located, personal data may be transferred to and processed in countries other than your own, including the United States (notably for authentication via Clerk and LLM inference via OpenAI) and the hosting region noted above. Where required, we rely on appropriate safeguards for such transfers under each subprocessor's Data Processing Addendum — typically the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable).
Retention
- Trigger: the retention period is measured from the Organization's last activity in the Service (e.g., last login, last assessment completed, or last administrative action by an Organization Owner/Manager), not from when each individual item was created.
- Assessment data (answers, reasoning/workflow transcripts, environment discovery reports, and derived scores) is deleted approximately 1 year after the Organization's last activity.
- The Organization/account record itself is retained (organization name, domain, admin identity, seat/plan information) even after assessment data is deleted, so the workspace is not lost and can resume activity later without re-provisioning.
- Data may be retained longer where required by law, to resolve disputes, enforce agreements, or in security backups, which are deleted or overwritten on a rolling basis.
- Organization-configurable shorter retention periods are not currently available; if introduced, this section will be updated.
Your Rights
Depending on your location, you may have rights to: access, correct, export (data portability), or delete your personal data, and to object to or restrict certain processing.
Requesting a full copy of your data. Any Authorized User can request a complete copy of all personal data we hold about them by emailing info@endtoendit.io from the email address associated with their account. This includes: identity/account data, all assessment responses and reasoning/workflow transcripts, environment discovery reports, and derived scores — not only the summary-level data visible to your Organization's managers. The manager-visibility limitation restricts what your Organization can see through the product; it does not restrict what you yourself can request directly from us about your own data. We aim to provide the export within 30 days of a verified request, in a common electronic format (e.g., JSON or PDF).
Because many Authorized User accounts exist within an employer-controlled Organization workspace, where we act as a processor on behalf of your employer, we may need to notify your Organization of the request or process it jointly with your Organization— this depends on your jurisdiction's law and the nature of the request (e.g., an access/export request is more likely to be fulfillable directly than a deletion request, which may affect your employer's records). Self-serve export/deletion tools are not currently available in the product; all requests are handled manually on a best-efforts basis.
We do not currently market the Service to users in the United States. If we begin doing so, we will update this Policy with any additional notices and mechanisms required under applicable U.S. state privacy laws (including CCPA/CPRA for California residents). We do not sell personal data.
Cookies and Similar Technologies
We currently use only essential cookies/tokens required for authentication and session management (via Clerk) and core Service functionality. We do not currently use analytics, advertising, or marketing cookies, so no cookie consent banner is used.
Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and hosting on infrastructure providers (Railway) with their own security safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children / Age Restrictions
The Service is intended for workforce/professional use by individuals of at least 18 years of age (or the applicable age of working majority) and is not directed to children. We do not knowingly collect personal data from children.
Data Processing Addendum / Enterprise Terms
Enterprise customers who require a Data Processing Addendum, Standard Contractual Clauses, or related security/compliance documentation may contact us at info@endtoendit.io to discuss. We do not currently publish a standard DPA; terms are considered case by case.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to Organization Owners and/or an in-product notice before taking effect.
Contact
Privacy questions or rights requests: info@endtoendit.io
General support: info@endtoendit.io