30Grow · 3035Tech

Privacy Policy

This policy explains how 3035Tech handles personal data in 30Grow. It covers the public website, manager signup, recruiting and survey links, and employee spaces.

Version 2026.10 · effective October 7, 2026

1. Who takes part in processing

3035Tech operates 30Grow. In many recruiting and people-management flows, the customer company determines purposes and data and acts as controller; 3035Tech processes that data to provide the platform under the customer’s instructions and contract.

For the public website, commercial signup, security, and 30Grow account administration, 3035Tech may act as controller. Requests about a hiring process or employment relationship may also need to be handled by the company responsible for that process.

2. Data we may process

  • Identity and contact details, including name, email, phone, and professional information.
  • Recruiting data, including applications, jobs, pipeline history, resumes, notes, and decisions recorded by authorized managers.
  • Assessment answers and T1–T9 and Motivators results. These are work-style hypotheses, not clinical diagnoses.
  • People-management data, such as 1:1s, development plans, goals, performance, climate, learning, onboarding, and enabled operational signals.
  • Sensitive HR data when the module is enabled, including internal compensation, HR-operation documents and requests, and whistleblowing report content.
  • Technical and security data, including IP address, browser, session, authentication events, audit trails, and abuse prevention.

3. Why we use data

The legal basis depends on the flow and the relationship between the person, the customer, and 3035Tech. It may include contract performance, legal obligations, legal claims, legitimate interests, or consent where applicable. The customer is responsible for defining and communicating the proper basis for processing under its control.

  • Provide, secure, and maintain the platform and its accounts.
  • Run recruiting and people-management processes configured by the customer.
  • Create results, comparisons, and auxiliary indicators for human conversations and decisions.
  • Send requested invitations, operational alerts, and communications.
  • Meet legal, contractual, audit, and security obligations.
  • Improve the product with aggregated or minimized metrics, without using whistleblowing report text in analytics.

4. Decisions and assessments

30Grow provides rankings, fit indicators, alerts, and summaries to support responsible people. These features should not make solely automated decisions about hiring, promotion, termination, or another significant effect. A person must review the output together with context, interviews, and technical criteria.

5. Sharing and service providers

Data may be processed by providers needed for hosting, databases, storage, email, abuse protection, and technical operations. We limit access to what is necessary and apply contractual and operational safeguards. We do not sell personal data.

When a provider processes data outside Brazil, the transfer must use applicable legal and contractual mechanisms.

6. Retention and deletion

We keep data while the account or process is active and for as long as needed for contracts, legal obligations, audits, security, or legal claims. The customer may set additional periods compatible with its legal responsibilities.

Invitations and sessions expire or can be revoked. Eligible old assessments may be removed in batches under configured policy. Records subject to preservation duties, including some HR documents, compensation, audit, and reports, are not automatically deleted without controller validation. Backups follow the provider’s technical cycle and cease to contain the data as they are overwritten.

7. Security and tenant isolation

We use authentication, role and module authorization, company scoping, audit trails, transport encryption, and operational controls. No method removes all risk, so we maintain response and review procedures.

Managers from one company must not access another company’s data. A technical super administrator may access companies for authorized support and operations, with explicit scope and auditing.

8. Your rights

Subject to applicable law, you may request confirmation and access, correction, information about sharing, anonymization, blocking, portability or deletion where applicable, withdrawal of consent, and review of automated decisions. Some requests require identity verification or must be handled by the customer acting as controller.

To submit a request, email the channel below with your name, email used, related company, and request. Do not send passwords, tokens, full identity documents, or sensitive report content in the first message.

9. Cookies and local technologies

We use cookies and local storage required for sessions, language, theme, security, and operation. Public metrics, when enabled, must avoid assessment content, documents, compensation, or report content. Blocking essential cookies may prevent login. On the landing page, Google Analytics loads only after you accept analytics; you can change this choice in Cookies. We measure visits and button clicks without sending names, emails, form contents, or URL parameters.

How Google uses information from sites or apps that use its services

10. Changes and contact

We may update this policy to reflect legal, technical, or product changes. The current version and date appear at the top of this page. Material changes will be communicated through appropriate channels.