Hosted in the EU
All customer data is stored and processed on servers in the European Union. On Microsoft Azure in West Germany (West Europe region).
GDPR-first by design
Privacy isn't a settings page we added later. Anonymity thresholds, data minimisation, and consent-gated sensitive data are built into how the product works.
Security controls as standard
MFA, Google & Microsoft single sign-on, role-based permissions, and audit trails; included on every plan, not sold as an enterprise upgrade.
Documents published, not gated
Our DPA, Master Services Agreement, sub-processor list, and security overview are public pages on this site. Send them to your legal team today.
Your organisation's data (reviews, survey responses, goals, employee records) is stored and processed within the European Union.
We keep our sub-processor list short and public. Every third party that touches customer data is named on our Sub-Processors page, along with what they do and where they process data. When the list changes, the page changes.
Most vendors treat privacy as a compliance layer. In TeamMaven, it shapes how features work:
Survey anonymity is enforced, everywhere.
Survey results only ever display once a minimum of five responses exist for any group. This threshold is a hard rule across every view (heatmaps, comment feeds, trend charts, and exports) so individuals can't be identified by cross-filtering, elimination, or renaming org attributes. Admins can even reply privately to anonymous survey comments without the respondent's identity ever being revealed.
You control exactly what employees see in reviews.
Admins choose per review round whether employees see a manager's summary, full anonymised peer feedback, or nothing at all; supporting everything from transparent 360s to confidential talent reviews. Reviewer views can be anonymised too, so managers can't identify who said what.
Sensitive demographic data is off by default.
Fields like gender and ethnicity are hidden and uncollected unless your organisation explicitly opts in at the tenant level with a full audit trail of who enabled it and when. They never appear on public profiles, regardless of settings.
Changes leave a trail.
Score overrides in reviews, HR calibration adjustments, and legal acceptances are recorded with a visible audit history before and after, who and when.
For the fuller technical picture, see our Security page.
TeamMaven's AI features (currently in beta) follow four non-negotiable rules:
Where AI processing happens
AI features run on Azure OpenAI Service in the European Union; Microsoft-hosted infrastructure in-region. Your data is never sent to OpenAI, is never used to train AI models, and never leaves the EU for inference.
If we ever change the underlying model provider, three commitments hold regardless: inference stays in the EU, your data is never used for model training, and the provider appears on our sub-processor list before the change goes live.
Data Processing Agreement - Our GDPR Art. 28 commitments as your processor
Sub-Processors - Every third party that processes customer data, and where
Security Overview - Technical and organisational measures
Master Services AgreementT - The commercial terms
Privacy PolicyH - How we handle data on this website and in the product
Doing a vendor assessment? Start here.
This page plus the documents above should answer most of a standard vendor privacy assessment. If your DPO or IT lead has questions we haven't covered (or a security questionnaire that needs completing) email info@teammaven.io and you'll get an answer from the person who actually built the product, usually within a day.