Privacy Policy

Last updated May 7, 2026

ISHIR INC.

Privacy Notice

AI Maturity Assessment Platform

assessment.ishir.ai

Effective Date

May 01, 2026

Last Updated

May 07, 2026

Version

1.1

Controller

ISHIR INC., 2001 Ross Ave Suite #700-140, Dallas, TX 75201

Contact

legal@ishir.com | +1 (888) 994-7447

Jurisdiction Scope

Texas (TDPSA, CIPA), GDPR/UK GDPR, CCPA/CPRA, PIPEDA, India DPDPA

Privacy Notice

This Privacy Notice applies to the ISHIR AI Maturity Assessment platform operated by ISHIR INC. (“we,” “us,” or “our”) at https://assessment.ishir.ai (the “Assessment Platform”). It describes how we collect, use, store, share, and protect your personal information when you use the Assessment Platform, and explains the rights available to you under applicable law.

This Privacy Notice is separate from and supplements the ISHIR corporate Privacy Notice available at https://www.ishir.com/privacy-policy.htm, which governs our main website. Where both notices could apply, this Notice takes precedence for activities conducted through the Assessment Platform.

Questions or concerns? Contact us at legal@ishir.com or write to: ISHIR INC., 2001 Ross Ave Suite #700-140, Dallas, TX 75201.

1. What the Assessment Platform Does

The ISHIR AI Maturity Assessment is a B2B digital tool designed to help organizational leaders understand their company’s current AI maturity level. The platform:

Asks 40 structured multiple-choice questions across five domains: Data & AI Readiness, Cybersecurity & AI Policies, Strategy & Skills, Technical Audit & Gaps, and Services Fit;

Uses automated scoring and AI-assisted analysis to generate a personalized AI Maturity Profile for your organization;

Delivers a results summary, gap analysis, and tailored recommendations;

Offers optional follow-up outputs including a detailed Action Report and an executive presentation deck; and

Maintains user accounts that store assessment history and results for registered users.

2. What Information We Collect

2.1 Personal Information You Provide

When you register, complete the assessment, or request follow-up materials, we collect:

Data Category

Examples

When Collected

Identity & Contact

First name, last name, business email address, phone number (optional)

Registration / results delivery

Professional Context

Job title, company name, industry, company size, geographic region

Registration form

Account Credentials

Email address, hashed password

Account creation (registered users)

Assessment Responses

Answers to 40 questions across 5 domains including AI policy status, cybersecurity practices, technology stack indicators, and strategic maturity

During assessment completion

Communication Preferences

Opt-in/opt-out choices for reports, follow-up, marketing emails

Registration and account settings

Request Data

Requests for Action Reports, decks, speaking engagements, or consultations

Post-assessment forms

2.2 Organizational Data

Assessment responses describe your organization’s internal practices, policies, and capabilities rather than personal attributes. However, because you are providing this information in your professional capacity and it is associated with your identity and employer, we treat it with the same care as personal data. Organizational data includes:

Descriptions of your organization’s AI tool usage and governance policies;

Indicators of cybersecurity posture, known gaps, and policy maturity;

Information about your organization’s technology infrastructure and vendor relationships;

Strategic priorities, skill gaps, and readiness for AI adoption; and

Indicators of shadow AI usage or unmanaged AI risk within your organization.

How We Handle Organizational Data

We do not share identifiable organizational assessment data with third parties for commercial purposes other than to deliver your requested outputs (reports, decks) and to enable ISHIR's advisory and sales follow-up as described in Section 5. Aggregated, anonymized benchmarking data may be used as described in Section 4.

2.3 Automatically Collected Technical Data

When you use the Assessment Platform, we automatically collect standard technical information including:

IP address and approximate geolocation (country/region level);

Browser type, version, and operating system;

Device type and screen resolution;

Pages visited, session duration, and click-path within the platform;

Referring to the URL (how you arrived at the platform); and

Authentication events (login time, session tokens).

2.4 Cookies and Tracking Technologies

The Assessment Platform uses cookies and similar technologies for the following purposes:

Cookie Type

Provider

Purpose

Strictly Necessary

ISHIR (first-party)

Session management, authentication, CSRF protection. Cannot be disabled.

Functional

ISHIR (first-party)

Remembering assessment progress, language/region preferences.

Analytics

Google Analytics 4

Understanding platform usage, user flows, drop-off points. Anonymized where possible.

Marketing / Retargeting

HubSpot

Lead tracking, email campaign attribution, CRM sync. Subject to your consent or opt-out right.

You can manage your cookie preferences at any time via the Cookie Settings link in the footer of this platform. Disabling analytics and marketing cookies will not prevent you from completing the assessment.

3. How We Use Your Information

Purpose

Description

Legal Basis (GDPR / US State Law)

Deliver assessment results

Score your responses, generate your AI Maturity Profile, and display your results

Performance of contract / Legitimate interest

AI-assisted profiling and scoring

Use automated logic and AI models to analyze your 40 responses and produce a scored maturity level across 5 domains

Legitimate interest; see Section 6 re: your profiling rights

Deliver requested follow-up materials

Send your Action Report, executive deck, or connect you with an ISHIR expert on request

Performance of contract / Consent

ISHIR sales and advisory follow-up

Share your contact details and assessment summary with ISHIR's sales/advisory team to follow up on your results and potential engagement

Legitimate interest; opt-out available at any time

Platform analytics and improvement

Analyze usage patterns, completion rates, and user flows to improve the assessment experience

Legitimate interest

Benchmarking (anonymized)

Aggregate anonymized assessment data to produce industry-level AI maturity benchmarks. No individual or organization is identifiable in benchmarks.

Legitimate interest; data is fully anonymized before use

Marketing communications

Send you ISHIR insights, event invitations, and service information if you have opted in

Consent; withdraw at any time via unsubscribe link

Account management

Maintain your login credentials, assessment history, and saved results

Performance of contract

Security and fraud prevention

Detect and prevent unauthorized access, abuse, or manipulation of assessment results

Legitimate interest / Legal obligation

Legal compliance

Comply with applicable law, respond to legal process, defend or assert legal rights

Legal obligation

Sales Follow-Up Transparency

Completing the assessment constitutes a genuine expression of interest in AI maturity as a business topic. ISHIR will use your contact information and assessment summary to follow up with relevant advisory resources and, where appropriate, to discuss ISHIR's services. This is a core purpose of the platform. You may opt out of sales contact at any time by emailing legal@ishir.com or using the unsubscribe link in any communication.

4. Legal Bases for Processing (EU/UK/Canada Users)

If you are located in the European Economic Area (EEA), United Kingdom, Switzerland, or Canada, the following legal bases apply to our processing activities:

Legal Basis

Processing Activities Covered

GDPR Article

Contractual Necessity

Delivering assessment results, account management, requested follow-up outputs

Art. 6(1)(b)

Legitimate Interests

AI-assisted scoring, sales follow-up, platform analytics, security, benchmarking (anonymized). Our interests: providing a valuable free tool and identifying potential advisory clients. Your interests: not overridden — you are choosing to use a business tool for business purposes and may opt out.

Art. 6(1)(f)

Consent

Marketing emails, optional cookies (analytics, retargeting). Consent is freely given and withdrawable at any time without penalty.

Art. 6(1)(a)

Legal Obligation

Compliance with applicable law, cooperation with regulatory authorities, data breach notification

Art. 6(1)(c)

If you are located in Canada, we rely on express consent for optional data uses and implied consent for delivering the assessment service you have requested. You may withdraw consent at any time.

5. When and With Whom We Share Your Information

5.1 ISHIR Internal Teams

Your contact information and assessment summary are shared with ISHIR’s sales and advisory teams for the purpose of providing follow-up resources and discussing potential advisory or implementation engagements. ISHIR personnel operate under confidentiality obligations and access controls.

5.2 Technology and Service Providers

We share data with vetted third-party service providers who process data on our behalf under written Data Processing Agreements. Categories include:

Category

Example Vendors

Data Shared

CRM & Marketing Automation

HubSpot

Name, email, company, job title, assessment completion status

Cloud Infrastructure / Hosting

AWS, GCP & Supabase

All platform data stored in secure data centers

Analytics

Google Analytics 4

Anonymized/pseudonymized usage data, session metrics

AI / LLM Services

Lovable AI, Claude AI

Assessment responses (anonymized or pseudonymized where feasible)

Email Delivery

AWS SES

Email address, name, report content for delivery

🔍 Action Required — Vendor Inventory

Before publishing this notice, ISHIR must confirm all third-party vendors used by assessment.ishir.ai (hosting, AI scoring engine, email delivery, authentication) and verify that Data Processing Agreements (DPAs) are in place with each. Under GDPR Art. 28, processing by a sub-processor without a DPA is unlawful.

5.3 Business Transfers

If ISHIR undergoes a merger, acquisition, financing, or sale of all or a portion of its business, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on the platform if your data becomes subject to a materially different privacy practice as a result.

5.4 Legal Disclosure

We may disclose your information when required by law, court order, or government authority, or when necessary to protect our legal rights, prevent fraud, or ensure user safety.

5.5 What We Do NOT Do

We do not sell your personal information to third parties.

We do not share identifiable organizational assessment data with third parties for advertising or data broker purposes.

We do not use assessment responses to train third-party AI models without your explicit consent.

We do not share your individual assessment results with your employer or any third party without your consent.

6. AI-Assisted Scoring and Automated Profiling

Your Rights Regarding Automated Processing

The Assessment Platform uses automated logic and AI assistance to process your 40 responses and produce an AI Maturity Score. Under GDPR Article 22 and applicable US state laws, you have the right to understand how this profiling works, to know what factors influence your score, and to request human review of your results.

How the Scoring Works

Your responses to the 40-question assessment are processed as follows:

Each response is assigned a weighted score based on the maturity level it indicates within its domain;

Scores across the five domains (Data & AI Readiness, Cybersecurity & AI Policies, Strategy & Skills, Technical Audit & Gaps, Services Fit) are aggregated into an overall AI Maturity Level;

Your maturity level is classified on a four-point scale: AI Shy → AI Curious → AI Enabled → AI Native;

AI-assisted analysis generates personalized insights, gap highlights, and tailored recommendations based on the pattern of your responses; and

Where you request an Action Report or executive deck, AI models assist in generating the narrative and recommendations in those documents.

Nature of the Decision

The assessment result is informational and advisory — it does not produce legal or similarly significant effects. It does not determine your eligibility for any service, employment, credit, or legal benefit. You are free to accept, reject, or supplement the results with your own judgment. A qualified ISHIR advisor reviews all Action Reports before delivery.

Your Profiling Rights

Regardless of jurisdiction, you may:

Request an explanation of how your specific score was calculated;

Correct any responses you believe were submitted in error and receive an updated score;

Request human review of your AI Maturity Profile by a qualified ISHIR advisor; and

Request deletion of your assessment data and any derived scores at any time.

To exercise any of these rights, email legal@ishir.com with the subject line “Assessment Data Request.”

7. International Data Transfers

ISHIR operates globally with teams in the United States (Dallas, TX), India (Noida), Estonia (EU), and Latin America. Data submitted through the Assessment Platform may be stored, processed, or accessed from these locations.

Transfers from the EEA and UK

Where personal data is transferred from the EEA or United Kingdom to countries not subject to an adequacy decision (including the United States and India), we rely on:

Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914/EU for EEA-originating transfers; and

The UK International Data Transfer Agreement (IDTA) for transfers of UK personal data.

We supplement these mechanisms with appropriate technical safeguards including encryption in transit and at rest, and access controls limiting data to personnel with a need to know.

India (DPDPA)

For data processed at our Noida delivery center, we comply with applicable requirements of India’s Digital Personal Data Protection Act (DPDPA) 2023, including purpose limitation and data security obligations. We will update our practices as implementing rules under the DPDPA are finalized.

You may request a copy of the applicable transfer safeguards by contacting legal@ishir.com.

8. How Long We Keep Your Information

Data Category

Retention Period

Rationale

Account credentials (active account)

Duration of account + 90 days post-deletion request

Account management; grace period for reactivation

Assessment responses and scores

3 years from completion, or duration of account if longer

Allows trend comparisons across reassessments; client relationship management

Generated reports and decks

3 years, or until you delete your account

Allows you to re-download prior outputs

Contact / lead data (non-account users)

3 years from last interaction or last email open, whichever is later

Legitimate interest in maintaining business relationship

Marketing email engagement data

3 years, deleted on unsubscribe

Campaign performance analytics; suppression list maintenance

Platform analytics / session logs

13 months

Industry standard; Google Analytics default

Anonymized benchmark data

Indefinite (no personal data retained)

Anonymization removes personal data; aggregate data retained for industry benchmarks

Legal / compliance records

7 years

Statutory obligations — Texas records law, tax, potential litigation

When retention periods expire, data is securely deleted or anonymized. If deletion is temporarily impossible (e.g., data in backup archives), the data is isolated from further processing until deletion occurs.

9. How We Protect Your Information

We implement appropriate technical and organizational security measures including:

Encryption of data in transit using TLS 1.2 or higher;

Encryption of data at rest for stored assessment responses and account data;

Role-based access controls limiting data access to personnel with a legitimate business need;

Multi-factor authentication for ISHIR staff accessing the assessment platform backend;

Regular security testing and vulnerability assessments; and

Formal incident response procedures.

Despite these measures, no system is completely secure. You use the Assessment Platform at your own risk and should not submit information you consider highly sensitive (e.g., specific vendor vulnerabilities, system credentials, proprietary trade secrets) through assessment responses.

Data Security Incidents

In the event of a data security incident affecting your personal information, we will notify you in accordance with applicable law:

Texas residents: within 60 days of discovery (Tex. Bus. & Com. Code § 521.053); the Texas Attorney General will be notified if the breach affects 250 or more Texas residents;

EU/EEA residents: supervisory authority notification within 72 hours (GDPR Art. 33); individual notification without undue delay if there is high risk to your rights and freedoms (GDPR Art. 34);

UK residents: ICO notification within 72 hours (UK GDPR Art. 33); and

California residents: notification in the most expedient time possible (Cal. Civ. Code § 1798.82).

Notifications will be sent to the email address associated with your account or, where required, via substitute notice.

10. Your Privacy Rights

10.1 Rights Available to All Users

Regardless of where you are located, you may:

Access a copy of the personal information we hold about you;

Correct inaccurate or incomplete information;

Delete your account and associated personal data;

Withdraw consent for marketing communications at any time (via unsubscribe link or email to legal@ishir.com);

Request human review of any automated scoring or AI-generated output; and

Request a copy of your assessment responses and generated reports.

10.2 Additional Rights for EU/UK/Swiss/Canadian Users (GDPR)

If you are located in the EEA, UK, Switzerland, or Canada, you additionally have the right to:

Data portability — receive your data in a structured, machine-readable format;

Restrict processing in certain circumstances (e.g., while a correction request is pending);

Object to processing based on legitimate interests, including profiling for sales purposes;

Not be subject to solely automated decision-making that produces significant legal effects (note: our assessment results are advisory, not legally significant — see Section 6); and

Lodge a complaint with your national supervisory authority (EU Member State DPA, UK ICO, Swiss FDPIC, or Canadian OPC).

EU/UK users may also contact our designated EU/UK Representative at:

[EU Representative Name and Address — to be confirmed per GDPR Art. 27]

10.3 Additional Rights for US State Residents

If you are a resident of California, Texas, Colorado, Connecticut, Virginia, or another state with applicable privacy law, you additionally have the right to:

Opt out of the “sale” or “sharing” of your personal data for targeted advertising purposes;

Opt out of profiling in furtherance of decisions that produce legal or significant effects (note: our profiling is advisory only);

Non-discrimination for exercising any privacy right;

Obtain a list of categories of third parties to whom we have disclosed your personal data; and

Appeal a denied rights request to your state Attorney General.

Texas TDPSA opt-out requests will be honored within 15 business days. California CCPA/CPRA requests will be honored within 45 calendar days (extendable once by 45 additional days with notice).

10.4 How to Exercise Your Rights

Submit a data subject access request at: [Termly DSR portal link — confirm same portal as main site or create separate one for assessment.ishir.ai]

Or email: legal@ishir.com with the subject line “Assessment Privacy Request — [Your Name]”

We will verify your identity before processing requests. Verification may require confirming your email address or account credentials. We will respond within the timeframe required by applicable law.

11. Minors

The Assessment Platform is designed exclusively for business professionals and organizational decision-makers. We do not knowingly collect personal information from individuals under 18 years of age. By using the platform, you represent that you are at least 18 years old and are acting in your professional capacity on behalf of your organization. If we learn that data has been submitted by a minor, we will delete it promptly. Contact legal@ishir.com if you believe this has occurred.

12. Do-Not-Track and Global Privacy Control

Most web browsers include a Do-Not-Track (“DNT”) setting. Because no uniform standard for honoring DNT signals has been established, we do not currently respond to browser DNT signals on the Assessment Platform.

With respect to the Global Privacy Control (GPC) signal: California law (CPRA) recognizes GPC as a legally valid opt-out of the sale or sharing of personal data. We [do / do not] currently recognize and honor GPC signals on this platform. [If honoring: Activating GPC in a supported browser will automatically opt you out of analytics and retargeting cookies.] This section will be updated as applicable state law evolves.

13. Updates to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The updated version will display a revised “Last Updated” date at the top of this notice. We will notify you of material changes by:

Sending an email to the address associated with your account (for registered users); and/or

Displaying a prominent notice on the Assessment Platform for a period of 30 days following the change.

We encourage you to review this notice periodically. Your continued use of the Assessment Platform following notice of material changes constitutes your acceptance of the updated terms.

14. How to Contact Us

For any questions, concerns, or requests regarding this Privacy Notice or the handling of your personal data on the Assessment Platform:

Privacy Contact

legal@ishir.com

Mail

ISHIR INC., Attn: Privacy — Assessment Platform, 2001 Ross Ave Suite #700-140, Dallas, TX 75201

Phone

+1 (888) 994-7447

EU/UK Representative

[To be appointed — see Section 10.2]

DPO (if applicable)

[To be confirmed]

DSR Portal

[Termly or equivalent portal URL]

Corporate Privacy Notice

https://www.ishir.com/privacy-policy.htm

Anonymous session analytics

ISHIR collects anonymous session analytics — including a masked IP address (e.g. 192.168.xxx.xxx), country, region, browser, operating system, device type, language, timezone, and your assessment progress — to improve the assessment experience and platform performance.

We do not store raw IP addresses or GPS coordinates. No third-party advertising trackers are used.

© 2026 ISHIR. All rights reserved.Home