Last updated: 16 July 2026
ThinkProfiler is a self‑reflection and cognitive assessment tool designed to help users understand their information‑processing preferences. This Privacy Policy explains what data is collected, how it is used, how it is stored, and how it is protected in accordance with the General Data Protection Regulation (GDPR).
Depending on how you access the ThinkProfiler assessment, our legal role under the GDPR differs:
As a Processor (B2B Flow): If you are a Client / Participant taking the assessment via an invitation from a Coach / Professional, the Coach is the Data Controller under the GDPR. ThinkProfiler acts strictly as the Data Processor, processing your responses and generating the Report on behalf and under the instructions of your Coach.
As a Controller: If you are a Coach creating an Account, purchasing Credits, or if you access our website directly as an individual user, ThinkProfiler acts as the Data Controller for your account and billing data.
When completing or participating in the ThinkProfiler assessment, we process:
Assessment responses: Answers to the questionnaire.
Client/Participant details: Email address (required to send the assessment link) and Name (used to personalize the Report).
Coach/Professional details: The email address of the inviting Coach (required to manage credit billing and deliver the Report).
Technical and administrative identifiers: Unique Client, Submission, and Coach/Invitation IDs used solely to link, process, and securely deliver the Report to the correct recipients.
ThinkProfiler itself does not initiate the use of tracking cookies or behavioral tracking technologies. However, because this website is hosted on Google Sites, Google automatically places cookies and processes data (such as IP addresses and traffic analytics) to ensure basic site functionality, security, and to provide aggregated traffic statistics. These data tracking activities are controlled entirely by Google. For more information, please consult Google’s Privacy Policy.
ThinkProfiler strictly adheres to the core principles of the GDPR:
Data Minimization: We only collect the minimum amount of personal data necessary to operate the service.
Purpose Limitation: Personal data is never used or processed for purposes incompatible with the original assessment delivery, service operation, or anonymized model improvement.
If we process your data as a Controller, or support a Controller's processing, we rely on the following legal bases:
Contract (Art. 6(1)(b)) – Processing assessment responses, email address, and optional name is necessary to perform the service, generate the Report, and deliver it.
Consent (Art. 6(1)(a)) – For optional fields such as name.
Legitimate Interest (Art. 6(1)(f)) – For maintaining service quality, debugging automation errors, and improving the ThinkProfiler scoring model using anonymized and aggregated data.
You are not subject to automated decision‑making or profiling that produces legal or similarly significant effects.
Your data is used to calculate your cognitive profile and generate your personalized Report.
Important: If you were invited by a Coach, the generated Report is automatically delivered directly to your inviting Coach via secure email.
Emails are sent automatically through the ThinkProfiler automation system using our Google Workspace infrastructure.
Your data is processed through secure cloud‑based systems:
Tally (secure form submission)
Stripe (secure payment processing and transaction handling)
Google Sheets (storing and calculating responses)
Google Docs & Drive (report generation and storage)
Gmail (email delivery and automatic storage of sent messages)
Assessment data may be used in fully anonymized and aggregated form to improve scoring models, validate cognitive dimensions, and enhance reliability. Individually identifiable data is never used to train or refine our models. For quality control, individual records may be reviewed in a fully anonymized form (with all identifying personal information removed).
All data is protected using appropriate technical and organizational measures, including encryption in transit and at rest, access control, and secure cloud infrastructure provided by Google Workspace and Tally.
In the highly unlikely event of a personal data breach, ThinkProfiler will notify affected users (and where applicable, the inviting Coaches as Controllers) and the relevant supervisory authorities without undue delay and in accordance with GDPR Articles 33 and 34.
ThinkProfiler prioritizes local EU-based data storage. Tally hosts data within the EU (Germany/Belgium). Google Workspace is configured to store operational data in EU‑based datacenters where available. If any processing occurs outside the EEA, it is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs).
Completed Assessments & Reports: Identifiable personal data (name, email address, and the generated PDF Report) is retained for a maximum of 12 months after delivery. This period is necessary for quality control, resolving delivery failures, and addressing support questions.
Automated 12-Month Cleanup: After 12 months, our automated GDPR cleanup process permanently deletes the PDF Report from Google Drive, purges the corresponding emails from Gmail, and removes the client's name and email address from our active databases. Assessment responses are then kept exclusively in a fully anonymized and aggregated form, making it impossible to link the data back to an individual.
Uncompleted Invitations (The 2-Month Window): If a Client does not start or complete the assessment within 2 months (60 days) after an invitation is sent by a Coach, the pending record (containing the Client's email address if pre-filled) is automatically and permanently deleted from our active databases to protect data hygiene.
You have the right to access, correct, delete (right to be forgotten), restrict, or object to the processing of your personal data, as well as the right to data portability.
Where the processing of your data is based on consent (such as providing an optional name), you have the right to withdraw your consent at any time without affecting the lawfulness of processing before its withdrawal.
Note for Invited Clients: Because your Coach is the Data Controller, we recommend contacting your inviting Coach directly to exercise these rights. We will fully support the Coach in executing your request.
To exercise your rights directly with us, contact: report@thinkprofiler.com. You also have the right to lodge a complaint with your local supervisory authority (in the Netherlands: the Autoriteit Persoonsgegevens).
ThinkProfiler uses the following sub‑processors to operate the workflow:
Tally – secure form submission and initial data collection.
Google Workspace (Sheets, Docs, Drive, Gmail) – data processing, database management, report generation, and email delivery.
Stripe – secure payment processing and billing management.
Stripe Note: Payment data processed by Stripe is handled under Stripe’s legal role as an independent Data Controller. ThinkProfiler does not store or have direct access to your full credit card or banking details.
ThinkProfiler is not directed at children. In accordance with Article 8 of the GDPR and Dutch privacy regulations, users must be at least 16 years old to use this service. We do not knowingly collect or process data from individuals under 16 without verifiable parental consent.
We reserve the right to update this Privacy Policy at any time. The “Last updated” date at the top of this document reflects the most recent version.
For questions, concerns, or data requests:
Email: report@thinkprofiler.com