APPLICATION PRIVACY POLICY
BLENDED LEADING
Version: 1.0 / Effective date: 01.06.2026

1. Introduction and Scope 

This Privacy Policy (the “Policy”) describes how Lean Digital Solutions EOOD, with registered office and address of management: city of Sofia, postal code 1303, Vazrazhdane district, 12 Chiprovtsi Street, fl. 2, UIC 202204879 (hereinafter “Blended Leading”, “we”, “us”) processes the personal data of the natural persons who use the Blended Leading software platform and application (the “Application”).

This Policy has been drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR” or the “Regulation”), the Personal Data Protection Act (PDPA) and the applicable national legislation of the Republic of Bulgaria.

In the Application, Blended Leading acts as a processor of personal data on behalf of the Corporate Client, including with respect to data on access, security, use of the functionalities and activity metrics, processed solely on the documented instructions of the Corporate Client.

2. Definitions

  • “Controller” – a natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (Article 4(7) GDPR).
  • “Processor” – a natural or legal person which processes personal data on behalf of the controller (Article 4(8) GDPR).
  • “Corporate Client” or “Client” – the legal entity (employer or organization) that has entered into a contract with Blended Leading for the use of the Application on behalf of its employees/associates/leaders.
  • “User” – a natural person (employee, leader, manager or other associate of the Corporate Client) who uses the Application.
  • “360 report” – a 360-degree feedback report that the User uploads voluntarily to the Application.
  • “Personality tool” – a psychometric tool for assessing personality characteristics (e.g. DISC and similar), the results of which the User uploads voluntarily to the Application.
  • “DPA” – the Data Processing Agreement concluded between Blended Leading and the Corporate Client under Article 28 GDPR.
Processing category
Capacity of Blended Leading
Who is the controller?

Registration, access, usage metrics

Processor

Corporate Client

Leadership model and segmentations (divisions, locations)

Processor

Corporate Client

Microsoft Teams integration (User.Read, direct messages)

Processor

Corporate Client

360 report and results from Personality tools (DISC, etc.)

Processor

Corporate Client

AI processing of open-ended questions for individual recommendations to the User

Processor

Corporate Client

3. Roles

With respect to the processing of personal data that Blended Leading carries out in the Application at the Corporate Client’s instruction, Blended Leading acts in its capacity as a PROCESSOR OF PERSONAL DATA within the meaning of Article 4(8) GDPR.

The CONTROLLER of your personal data in this case is your employer or the organization that has granted You access to the Application (the Corporate Client). It determines the purposes and means of the processing, instructs Blended Leading on what to process and how, and bears the primary responsibility towards You for the protection of your personal data.

IMPORTANT! For full information about the processing, the purposes, the legal bases, the retention periods and your rights in your capacity as a data subject, please refer to the privacy policy of your employer/organization and to the relevant Data Processing Agreement (DPA).

4. Categories of data processed in the capacity of processor

Within this capacity, Blended Leading processes the following categories of personal data on behalf of the Corporate Client:

  • Identification data: first name, surname, corporate email address, username (from the Corporate Client’s Azure AD / Microsoft 365);
  • Professional data: position, department/division, location, team and other segmentation attributes that the Corporate Client has entered into the Application;
  • Technical and usage data: date and time of access, log records, whether the User has read/acknowledged received guidance and tips, processed solely on behalf of and on the documented instructions of the Corporate Client;
  • Activity metrics: frequency of use, which functionalities have been used, aggregated statistics on the level of engagement, processed solely in the capacity of personal-data processor;
  • Leadership-model data: competencies, clusters and corporate values defined by the Corporate Client (in principle these do not contain personal data);
  • 360 report content: quantitative competency ratings, open-ended text comments from assessors, names/initials of assessors (if included in the report);
  • Results from Personality tools (DISC and similar): profiles, scales, descriptions of behavioral characteristics. Personality assessments may contain sensitive information about psychological and behavioral characteristics. Blended Leading applies enhanced technical and organizational measures for their protection. We recommend that You do not upload documents containing special categories of data within the meaning of Article 9 GDPR (for example, health information, religious beliefs, etc.);
  • Generated individual recommendations: strengths, areas for improvement, development guidance derived by the AI;
  • Metadata: date of upload, report identifier, 360/Personality-tool provider used, version of the AI processing.

5. Purposes and Legal Bases

The purposes of the processing are determined by the Corporate Client. In principle, they include:

  • Performance of an employment or service relationship and/or the legitimate interests of the Corporate Client in the management and development of human resources;
  • Analysis of leadership competencies at the organization, division or team level;
  • Management of access to the Application and information security;
  • Extraction and structuring of the results from the 360 reports and the Personality tools that You have uploaded;
  • Generation of personalized analyses of your strengths and areas for improvement;
  • Generation of individual development recommendations, guidance and tips that are shown to You in the Application and/or sent to You via Microsoft Teams;
  • Comparisons with aggregated and anonymized data of other leaders within your organization, on the documented instructions of the Corporate Client and subject to an anonymization threshold;
  • Improvement of the quality of the Application’s functionalities (only on the basis of aggregated/anonymized data).

The legal bases for this processing are set out in the Corporate Client’s privacy policy. As a rule, these are: Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(c) GDPR (legal obligation) and/or Article 6(1)(f) GDPR (legitimate interest).

6. Microsoft 365 / Teams Integration

Upon installation of the Application in Microsoft Teams – following prior approval by the Corporate Client’s network administrator and subsequent activation by the User in their own Teams environment – the Application obtains the following permissions in Microsoft Graph:

  • Sending direct messages (chat) to the Users, in order to provide them with personalized tips, guidance and notifications;
  • User.Read (or equivalent) – reading basic data from the user profile (email address and username) for the purposes of linking the account in the Application with the Corporate Client’s account in Azure AD.

Express notice: The Application does NOT read email, chats, private messages, files or other content data from Microsoft 365. Activation of the integration is carried out following administrator approval of the application by the Corporate Client and a separate activation action by the User, where applicable.

7. AI Processing

The Application uses artificial intelligence (AI) tools provided by Microsoft Azure AI Foundry to process the open-ended text answers in the 360 reports and to generate individual recommendations.

Information about this processing:

  • Logic of the processing: the AI extracts relevant behavioral indicators from the open-ended answers, maps them to the Corporate Client’s leadership model, counts their frequency and classifies them as positive or negative. On this basis, strengths and areas for improvement are generated.
  • Scope of the AI processing: the AI processes only predefined pages of the uploaded documents, not the entire report.
  • Significance and envisaged consequences: the result of the AI processing is used exclusively for personal development and does not serve to make decisions with legal consequences or that similarly significantly affect You. The recommendations are informative in nature and do not replace your own judgment or that of your employer.
  • No solely automated decision-making: Blended Leading does NOT carry out, in relation to You, solely automated decision-making that produces legal effects or similarly significantly affects You within the meaning of Article 22 GDPR.
  • Right to human intervention: You have the right to request human intervention in the review of the generated recommendations, to express your point of view and to contest the result.
  • No training of AI models on your data: Blended Leading has contractually obliged the AI provider NOT to use your personal data to train or improve its models.

8. Sub-processors

For the performance of the service, Blended Leading uses a limited number of sub-processors that provide infrastructure, technical and analytical services. They are listed in the “Sub-processors” Annex to the DPA with the Corporate Client and include:

  • Hosting provider – hosting of the Application in the EU/EEA;
  • Microsoft – Microsoft 365 / Teams integration;
  • AI provider – processing of open-ended answers and generation of individual recommendations;
  • Email service provider – transactional emails to the Users;
  • Other sub-processors – according to a list that is updated periodically.

Blended Leading concludes a written contract with each sub-processor under Article 28(4) GDPR and is responsible towards the Corporate Client for their compliance. The Corporate Client may object to a particular sub-processor under the terms of the DPA.

9. International Data Transfers

Where sub-processors are located outside the European Union and the European Economic Area, the transfer of data is based on:

  • A European Commission decision on an adequate level of protection (Article 45 GDPR); or
  • The EC Standard Contractual Clauses (SCC) under Article 46(2)(c) GDPR, accompanied where necessary by additional technical and organizational measures based on a Transfer Impact Assessment (TIA), in line with the case-law of the Court of Justice of the EU in Case C-311/18 (Schrems II) and EDPB Recommendation 01/2020.

10. Retention Period

The retention periods in this capacity are determined by the Corporate Client and are set out in the DPA. As a rule, the data is processed for as long as the contract with the Corporate Client is in force and is thereafter deleted or returned in accordance with its instructions.

11. Exercise of Rights

In its capacity as a processor, Blended Leading CANNOT by itself fulfil requests for the exercise of your rights under the GDPR (access, rectification, erasure, restriction, portability, objection). Such requests must be addressed to the Corporate Client (your employer/organization), which is the controller. If we receive such a request, we will forward it to the relevant Corporate Client without undue delay and will assist it in fulfilling your requests in accordance with Article 28(3)(e) GDPR.

12. Data Security

Blended Leading applies appropriate technical and organizational security measures, including (but not limited to):

  • Encryption of data at rest and in transit using up-to-date algorithms;
  • Pseudonymization of data during processing by the AI, insofar as technically possible;
  • Access control on the principle of least privilege and multi-factor authentication for employees;
  • Log records of access and processing;
  • Periodic vulnerability tests and penetration testing;
  • Procedures for the management of incidents and personal-data security breaches (Articles 33–34 GDPR);
  • Contractual confidentiality obligations for all employees and sub-processors.

13. Children

The Application is not directed at persons under 18 years of age and is not used by such persons. Blended Leading does not knowingly process the personal data of children.

14. Changes to the Policy

Blended Leading may update this Policy from time to time. The current version is always available in the Application and on the Blended Leading website. In the event of material changes, we will notify You via a notification in the Application and/or by email before they take effect.