Dex for Business · Privacy and Data Use

Capability evidence requires trust.

Dex engagements collect evidence about people and how organizations run. That only works when the boundaries are fixed in advance: what is collected, who sees it, what is reported, and what can ever appear in public.

Defined reporting boundariesParticipant safeguardsPrivate reports protectedPublic verification limited
01What is collected

Scoped to the pathway. Nothing speculative.

Collection is defined by the engagement — an assessment collects assessment evidence, a mapping collects role and capability data. Nothing is gathered “while we’re at it.”

Assessmentapplied capability evidence · role context
Mappingrole, domain, level, and unit data
Leadership feedbackprotected structured responses
Certificationsystem evidence · governance records
Enquiriescontact details · stated scope interest
02What can become public

Only the verification record. Nothing else.

The public record shows the organization’s name, certification type and scope, dates, status, credential code, and permitted claim language. Everything else — reports, results, feedback, individual data — stays private.

Organization name, scope, dates, status, code — public
Assessment results and reports — never public
Individual employee records — never public, unless authorised
Leadership feedback, in any form — never public
Internal benchmarking — never public
03Participant safeguards

Fixed before collection begins.

For leadership and conversion feedback, the safeguards are agreed and documented before anyone answers a question. Dex is not a surveillance tool — evidence gathered under pressure is not evidence.

01Who participates, and voluntarily
02How anonymity is protected
03Minimum group thresholds for any reported result
04Small-group results suppressed entirely
05What reports contain — and what is excluded
06Raw comments never shown to managers
07Retaliation risk assessed and mitigated
04Use and limits

Reports are for decisions, not marketing.

Engagement reports are delivered for internal decision-making. They are not marketing assets, and their contents may not be quoted publicly beyond the approved claim language.

This page describes Dex practice. It is not a substitute for the legal privacy policy, terms of service, data-processing agreements, employment-law advice, or sector-specific compliance obligations.

05Questions

Boundaries are part of the standard.

If your privacy, legal, or works-council review needs specifics before an engagement, ask — the boundaries are documented, not improvised.