Privacy Policy
Last updated May 7, 2026
ISHIR INC.
Privacy Notice
AI Maturity Assessment Platform
assessment.ishir.ai
Effective Date | May 01, 2026 |
Last Updated | May 07, 2026 |
Version | 1.1 |
Controller | ISHIR INC., 2001 Ross Ave Suite #700-140, Dallas, TX 75201 |
Contact | legal@ishir.com | +1 (888) 994-7447 |
Jurisdiction Scope | Texas (TDPSA, CIPA), GDPR/UK GDPR, CCPA/CPRA, PIPEDA, India DPDPA |
Privacy Notice
This Privacy Notice applies to the ISHIR AI Maturity Assessment platform operated by ISHIR INC. (“we,” “us,” or “our”) at https://assessment.ishir.ai (the “Assessment Platform”). It describes how we collect, use, store, share, and protect your personal information when you use the Assessment Platform, and explains the rights available to you under applicable law.
This Privacy Notice is separate from and supplements the ISHIR corporate Privacy Notice available at https://www.ishir.com/privacy-policy.htm, which governs our main website. Where both notices could apply, this Notice takes precedence for activities conducted through the Assessment Platform.
Questions or concerns? Contact us at legal@ishir.com or write to: ISHIR INC., 2001 Ross Ave Suite #700-140, Dallas, TX 75201.
1. What the Assessment Platform Does
The ISHIR AI Maturity Assessment is a B2B digital tool designed to help organizational leaders understand their company’s current AI maturity level. The platform:
Asks 40 structured multiple-choice questions across five domains: Data & AI Readiness, Cybersecurity & AI Policies, Strategy & Skills, Technical Audit & Gaps, and Services Fit;
Uses automated scoring and AI-assisted analysis to generate a personalized AI Maturity Profile for your organization;
Delivers a results summary, gap analysis, and tailored recommendations;
Offers optional follow-up outputs including a detailed Action Report and an executive presentation deck; and
Maintains user accounts that store assessment history and results for registered users.
2. What Information We Collect
2.1 Personal Information You Provide
When you register, complete the assessment, or request follow-up materials, we collect:
Data Category | Examples | When Collected |
Identity & Contact | First name, last name, business email address, phone number (optional) | Registration / results delivery |
Professional Context | Job title, company name, industry, company size, geographic region | Registration form |
Account Credentials | Email address, hashed password | Account creation (registered users) |
Assessment Responses | Answers to 40 questions across 5 domains including AI policy status, cybersecurity practices, technology stack indicators, and strategic maturity | During assessment completion |
Communication Preferences | Opt-in/opt-out choices for reports, follow-up, marketing emails | Registration and account settings |
Request Data | Requests for Action Reports, decks, speaking engagements, or consultations | Post-assessment forms |
2.2 Organizational Data
Assessment responses describe your organization’s internal practices, policies, and capabilities rather than personal attributes. However, because you are providing this information in your professional capacity and it is associated with your identity and employer, we treat it with the same care as personal data. Organizational data includes:
Descriptions of your organization’s AI tool usage and governance policies;
Indicators of cybersecurity posture, known gaps, and policy maturity;
Information about your organization’s technology infrastructure and vendor relationships;
Strategic priorities, skill gaps, and readiness for AI adoption; and
Indicators of shadow AI usage or unmanaged AI risk within your organization.
How We Handle Organizational Data We do not share identifiable organizational assessment data with third parties for commercial purposes other than to deliver your requested outputs (reports, decks) and to enable ISHIR's advisory and sales follow-up as described in Section 5. Aggregated, anonymized benchmarking data may be used as described in Section 4. |
2.3 Automatically Collected Technical Data
When you use the Assessment Platform, we automatically collect standard technical information including:
IP address and approximate geolocation (country/region level);
Browser type, version, and operating system;
Device type and screen resolution;
Pages visited, session duration, and click-path within the platform;
Referring to the URL (how you arrived at the platform); and
Authentication events (login time, session tokens).
2.4 Cookies and Tracking Technologies
The Assessment Platform uses cookies and similar technologies for the following purposes:
Cookie Type | Provider | Purpose |
Strictly Necessary | ISHIR (first-party) | Session management, authentication, CSRF protection. Cannot be disabled. |
Functional | ISHIR (first-party) | Remembering assessment progress, language/region preferences. |
Analytics | Google Analytics 4 | Understanding platform usage, user flows, drop-off points. Anonymized where possible. |
Marketing / Retargeting | HubSpot | Lead tracking, email campaign attribution, CRM sync. Subject to your consent or opt-out right. |
You can manage your cookie preferences at any time via the Cookie Settings link in the footer of this platform. Disabling analytics and marketing cookies will not prevent you from completing the assessment.
3. How We Use Your Information
Purpose | Description | Legal Basis (GDPR / US State Law) |
Deliver assessment results | Score your responses, generate your AI Maturity Profile, and display your results | Performance of contract / Legitimate interest |
AI-assisted profiling and scoring | Use automated logic and AI models to analyze your 40 responses and produce a scored maturity level across 5 domains | Legitimate interest; see Section 6 re: your profiling rights |
Deliver requested follow-up materials | Send your Action Report, executive deck, or connect you with an ISHIR expert on request | Performance of contract / Consent |
ISHIR sales and advisory follow-up | Share your contact details and assessment summary with ISHIR's sales/advisory team to follow up on your results and potential engagement | Legitimate interest; opt-out available at any time |
Platform analytics and improvement | Analyze usage patterns, completion rates, and user flows to improve the assessment experience | Legitimate interest |
Benchmarking (anonymized) | Aggregate anonymized assessment data to produce industry-level AI maturity benchmarks. No individual or organization is identifiable in benchmarks. | Legitimate interest; data is fully anonymized before use |
Marketing communications | Send you ISHIR insights, event invitations, and service information if you have opted in | Consent; withdraw at any time via unsubscribe link |
Account management | Maintain your login credentials, assessment history, and saved results | Performance of contract |
Security and fraud prevention | Detect and prevent unauthorized access, abuse, or manipulation of assessment results | Legitimate interest / Legal obligation |
Legal compliance | Comply with applicable law, respond to legal process, defend or assert legal rights | Legal obligation |
Sales Follow-Up Transparency Completing the assessment constitutes a genuine expression of interest in AI maturity as a business topic. ISHIR will use your contact information and assessment summary to follow up with relevant advisory resources and, where appropriate, to discuss ISHIR's services. This is a core purpose of the platform. You may opt out of sales contact at any time by emailing legal@ishir.com or using the unsubscribe link in any communication. |
4. Legal Bases for Processing (EU/UK/Canada Users)
If you are located in the European Economic Area (EEA), United Kingdom, Switzerland, or Canada, the following legal bases apply to our processing activities:
Legal Basis | Processing Activities Covered | GDPR Article |
Contractual Necessity | Delivering assessment results, account management, requested follow-up outputs | Art. 6(1)(b) |
Legitimate Interests | AI-assisted scoring, sales follow-up, platform analytics, security, benchmarking (anonymized). Our interests: providing a valuable free tool and identifying potential advisory clients. Your interests: not overridden — you are choosing to use a business tool for business purposes and may opt out. | Art. 6(1)(f) |
Consent | Marketing emails, optional cookies (analytics, retargeting). Consent is freely given and withdrawable at any time without penalty. | Art. 6(1)(a) |
Legal Obligation | Compliance with applicable law, cooperation with regulatory authorities, data breach notification | Art. 6(1)(c) |
If you are located in Canada, we rely on express consent for optional data uses and implied consent for delivering the assessment service you have requested. You may withdraw consent at any time.
5. When and With Whom We Share Your Information
5.1 ISHIR Internal Teams
Your contact information and assessment summary are shared with ISHIR’s sales and advisory teams for the purpose of providing follow-up resources and discussing potential advisory or implementation engagements. ISHIR personnel operate under confidentiality obligations and access controls.
5.2 Technology and Service Providers
We share data with vetted third-party service providers who process data on our behalf under written Data Processing Agreements. Categories include:
Category | Example Vendors | Data Shared |
CRM & Marketing Automation | HubSpot | Name, email, company, job title, assessment completion status |
Cloud Infrastructure / Hosting | AWS, GCP & Supabase | All platform data stored in secure data centers |
Analytics | Google Analytics 4 | Anonymized/pseudonymized usage data, session metrics |
AI / LLM Services | Lovable AI, Claude AI | Assessment responses (anonymized or pseudonymized where feasible) |
Email Delivery | AWS SES | Email address, name, report content for delivery |
🔍 Action Required — Vendor Inventory Before publishing this notice, ISHIR must confirm all third-party vendors used by assessment.ishir.ai (hosting, AI scoring engine, email delivery, authentication) and verify that Data Processing Agreements (DPAs) are in place with each. Under GDPR Art. 28, processing by a sub-processor without a DPA is unlawful. |
5.3 Business Transfers
If ISHIR undergoes a merger, acquisition, financing, or sale of all or a portion of its business, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on the platform if your data becomes subject to a materially different privacy practice as a result.
5.4 Legal Disclosure
We may disclose your information when required by law, court order, or government authority, or when necessary to protect our legal rights, prevent fraud, or ensure user safety.
5.5 What We Do NOT Do
We do not sell your personal information to third parties.
We do not share identifiable organizational assessment data with third parties for advertising or data broker purposes.
We do not use assessment responses to train third-party AI models without your explicit consent.
We do not share your individual assessment results with your employer or any third party without your consent.
6. AI-Assisted Scoring and Automated Profiling
Your Rights Regarding Automated Processing The Assessment Platform uses automated logic and AI assistance to process your 40 responses and produce an AI Maturity Score. Under GDPR Article 22 and applicable US state laws, you have the right to understand how this profiling works, to know what factors influence your score, and to request human review of your results. |
How the Scoring Works
Your responses to the 40-question assessment are processed as follows:
Each response is assigned a weighted score based on the maturity level it indicates within its domain;
Scores across the five domains (Data & AI Readiness, Cybersecurity & AI Policies, Strategy & Skills, Technical Audit & Gaps, Services Fit) are aggregated into an overall AI Maturity Level;
Your maturity level is classified on a four-point scale: AI Shy → AI Curious → AI Enabled → AI Native;
AI-assisted analysis generates personalized insights, gap highlights, and tailored recommendations based on the pattern of your responses; and
Where you request an Action Report or executive deck, AI models assist in generating the narrative and recommendations in those documents.
Nature of the Decision
The assessment result is informational and advisory — it does not produce legal or similarly significant effects. It does not determine your eligibility for any service, employment, credit, or legal benefit. You are free to accept, reject, or supplement the results with your own judgment. A qualified ISHIR advisor reviews all Action Reports before delivery.
Your Profiling Rights
Regardless of jurisdiction, you may:
Request an explanation of how your specific score was calculated;
Correct any responses you believe were submitted in error and receive an updated score;
Request human review of your AI Maturity Profile by a qualified ISHIR advisor; and
Request deletion of your assessment data and any derived scores at any time.
To exercise any of these rights, email legal@ishir.com with the subject line “Assessment Data Request.”
7. International Data Transfers
ISHIR operates globally with teams in the United States (Dallas, TX), India (Noida), Estonia (EU), and Latin America. Data submitted through the Assessment Platform may be stored, processed, or accessed from these locations.
Transfers from the EEA and UK
Where personal data is transferred from the EEA or United Kingdom to countries not subject to an adequacy decision (including the United States and India), we rely on:
Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914/EU for EEA-originating transfers; and
The UK International Data Transfer Agreement (IDTA) for transfers of UK personal data.
We supplement these mechanisms with appropriate technical safeguards including encryption in transit and at rest, and access controls limiting data to personnel with a need to know.
India (DPDPA)
For data processed at our Noida delivery center, we comply with applicable requirements of India’s Digital Personal Data Protection Act (DPDPA) 2023, including purpose limitation and data security obligations. We will update our practices as implementing rules under the DPDPA are finalized.
You may request a copy of the applicable transfer safeguards by contacting legal@ishir.com.
8. How Long We Keep Your Information
Data Category | Retention Period | Rationale |
Account credentials (active account) | Duration of account + 90 days post-deletion request | Account management; grace period for reactivation |
Assessment responses and scores | 3 years from completion, or duration of account if longer | Allows trend comparisons across reassessments; client relationship management |
Generated reports and decks | 3 years, or until you delete your account | Allows you to re-download prior outputs |
Contact / lead data (non-account users) | 3 years from last interaction or last email open, whichever is later | Legitimate interest in maintaining business relationship |
Marketing email engagement data | 3 years, deleted on unsubscribe | Campaign performance analytics; suppression list maintenance |
Platform analytics / session logs | 13 months | Industry standard; Google Analytics default |
Anonymized benchmark data | Indefinite (no personal data retained) | Anonymization removes personal data; aggregate data retained for industry benchmarks |
Legal / compliance records | 7 years | Statutory obligations — Texas records law, tax, potential litigation |
When retention periods expire, data is securely deleted or anonymized. If deletion is temporarily impossible (e.g., data in backup archives), the data is isolated from further processing until deletion occurs.
9. How We Protect Your Information
We implement appropriate technical and organizational security measures including:
Encryption of data in transit using TLS 1.2 or higher;
Encryption of data at rest for stored assessment responses and account data;
Role-based access controls limiting data access to personnel with a legitimate business need;
Multi-factor authentication for ISHIR staff accessing the assessment platform backend;
Regular security testing and vulnerability assessments; and
Formal incident response procedures.
Despite these measures, no system is completely secure. You use the Assessment Platform at your own risk and should not submit information you consider highly sensitive (e.g., specific vendor vulnerabilities, system credentials, proprietary trade secrets) through assessment responses.
Data Security Incidents
In the event of a data security incident affecting your personal information, we will notify you in accordance with applicable law:
Texas residents: within 60 days of discovery (Tex. Bus. & Com. Code § 521.053); the Texas Attorney General will be notified if the breach affects 250 or more Texas residents;
EU/EEA residents: supervisory authority notification within 72 hours (GDPR Art. 33); individual notification without undue delay if there is high risk to your rights and freedoms (GDPR Art. 34);
UK residents: ICO notification within 72 hours (UK GDPR Art. 33); and
California residents: notification in the most expedient time possible (Cal. Civ. Code § 1798.82).
Notifications will be sent to the email address associated with your account or, where required, via substitute notice.
10. Your Privacy Rights
10.1 Rights Available to All Users
Regardless of where you are located, you may:
Access a copy of the personal information we hold about you;
Correct inaccurate or incomplete information;
Delete your account and associated personal data;
Withdraw consent for marketing communications at any time (via unsubscribe link or email to legal@ishir.com);
Request human review of any automated scoring or AI-generated output; and
Request a copy of your assessment responses and generated reports.
10.2 Additional Rights for EU/UK/Swiss/Canadian Users (GDPR)
If you are located in the EEA, UK, Switzerland, or Canada, you additionally have the right to:
Data portability — receive your data in a structured, machine-readable format;
Restrict processing in certain circumstances (e.g., while a correction request is pending);
Object to processing based on legitimate interests, including profiling for sales purposes;
Not be subject to solely automated decision-making that produces significant legal effects (note: our assessment results are advisory, not legally significant — see Section 6); and
Lodge a complaint with your national supervisory authority (EU Member State DPA, UK ICO, Swiss FDPIC, or Canadian OPC).
EU/UK users may also contact our designated EU/UK Representative at:
[EU Representative Name and Address — to be confirmed per GDPR Art. 27]
10.3 Additional Rights for US State Residents
If you are a resident of California, Texas, Colorado, Connecticut, Virginia, or another state with applicable privacy law, you additionally have the right to:
Opt out of the “sale” or “sharing” of your personal data for targeted advertising purposes;
Opt out of profiling in furtherance of decisions that produce legal or significant effects (note: our profiling is advisory only);
Non-discrimination for exercising any privacy right;
Obtain a list of categories of third parties to whom we have disclosed your personal data; and
Appeal a denied rights request to your state Attorney General.
Texas TDPSA opt-out requests will be honored within 15 business days. California CCPA/CPRA requests will be honored within 45 calendar days (extendable once by 45 additional days with notice).
10.4 How to Exercise Your Rights
Submit a data subject access request at: [Termly DSR portal link — confirm same portal as main site or create separate one for assessment.ishir.ai]
Or email: legal@ishir.com with the subject line “Assessment Privacy Request — [Your Name]”
We will verify your identity before processing requests. Verification may require confirming your email address or account credentials. We will respond within the timeframe required by applicable law.
11. Minors
The Assessment Platform is designed exclusively for business professionals and organizational decision-makers. We do not knowingly collect personal information from individuals under 18 years of age. By using the platform, you represent that you are at least 18 years old and are acting in your professional capacity on behalf of your organization. If we learn that data has been submitted by a minor, we will delete it promptly. Contact legal@ishir.com if you believe this has occurred.
12. Do-Not-Track and Global Privacy Control
Most web browsers include a Do-Not-Track (“DNT”) setting. Because no uniform standard for honoring DNT signals has been established, we do not currently respond to browser DNT signals on the Assessment Platform.
With respect to the Global Privacy Control (GPC) signal: California law (CPRA) recognizes GPC as a legally valid opt-out of the sale or sharing of personal data. We [do / do not] currently recognize and honor GPC signals on this platform. [If honoring: Activating GPC in a supported browser will automatically opt you out of analytics and retargeting cookies.] This section will be updated as applicable state law evolves.
13. Updates to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The updated version will display a revised “Last Updated” date at the top of this notice. We will notify you of material changes by:
Sending an email to the address associated with your account (for registered users); and/or
Displaying a prominent notice on the Assessment Platform for a period of 30 days following the change.
We encourage you to review this notice periodically. Your continued use of the Assessment Platform following notice of material changes constitutes your acceptance of the updated terms.
14. How to Contact Us
For any questions, concerns, or requests regarding this Privacy Notice or the handling of your personal data on the Assessment Platform:
Privacy Contact | legal@ishir.com |
ISHIR INC., Attn: Privacy — Assessment Platform, 2001 Ross Ave Suite #700-140, Dallas, TX 75201 | |
Phone | +1 (888) 994-7447 |
EU/UK Representative | [To be appointed — see Section 10.2] |
DPO (if applicable) | [To be confirmed] |
DSR Portal | [Termly or equivalent portal URL] |
Corporate Privacy Notice | https://www.ishir.com/privacy-policy.htm |