Who is responsible
HumaMap is the data controller for the personal data described here. Contact us at hello@humamap.com or Ragnagade 7, 2100 København Ø, Denmark.
Data we process
- Account data such as your name, email, password hash and security sessions.
- Profile data you add, including your photo, background, skills, direction and visibility choices.
- Core, Evidence and Reflection assessment data and the HumaMap model built from it.
- Ask HumaMap conversations and limited usage metadata such as model, token counts, latency and errors.
- Technical information needed for security, email delivery and reliable operation.
Uploaded assessment files are temporary.
We extract the needed structured data, then delete the original file after processing or expiry. Unfinished uploads expire after one hour.
Why we use it
We process account, profile and assessment data to provide the HumaMap service and fulfil our agreement with you. We use limited operational data for security, abuse prevention and service reliability based on our legitimate interests.
We do not sell personal data. We do not use HumaMap to make automated hiring, firing, medical or other high-stakes decisions.
AI processing
Ask HumaMap sends only the context needed for your question to Mistral's API. It is private to your authenticated account, read-only and cannot silently change your canonical HumaMap.
AI responses are explanations and reflection prompts, not professional, psychological, medical or employment advice. You can delete individual conversations from the chat.
Service providers and transfers
We use specialised processors to run HumaMap: Vercel for hosting and private file storage, Neon for PostgreSQL, Resend for transactional email and Mistral for AI responses.
Where processing occurs outside the European Economic Area, we rely on the provider's applicable transfer safeguards, such as the European Commission's Standard Contractual Clauses.
Retention and deletion
Your account data remains while your account is active. Deleted accounts are removed from the live database, while encrypted recovery backups expire after no more than 14 days. AI usage metadata is retained for no more than 90 days. Legal or security obligations may require limited information to be kept longer.
Your choices and rights
You can change visibility, download a structured copy of your data and permanently delete your account from Settings. Depending on applicable law, you may also ask for access, correction, restriction, portability or objection.
Contact hello@humamap.com. You may also complain to the Danish Data Protection Agency, Datatilsynet.
Security and changes
We use encrypted connections, private storage, access controls, rate limits, backups and monitoring. No system is risk-free, but we limit the data and access required for each feature.
We will update this page when the service or our processing changes materially. The current version and effective date will always appear here. See also our Terms of Service.
