Portal Privacy Policy

Effective date: 20 September 2026

This policy applies only to the B5.LY Business Portal (the Portal), not to the consumer service on bigfive.ly.

1. Who we are

GLORIAPR Ltd, trading as BigFive / B5.LY where applicable, operates the Portal.

  • Company number: 16313878
  • Address: Office 12012, 182–184 High Street North, East Ham, London E6 2JA, United Kingdom
  • Privacy contact: Support@b5.ly

2. Our data-protection roles

We are a controller for account-owner and staff data used to create, secure, bill, support, and administer Portal accounts. For personal data about participants invited by a Portal client, the client generally acts as controller and we act as its processor, following documented instructions and the data-processing terms in section 19 of the Terms of Service (DPA). We may act as controller for limited security, fraud-prevention, and service-integrity records.

Participants should normally direct privacy requests to the organisation or practitioner that invited them. We will redirect and assist where required.

3. Data we process

Account and business data

We may process names, business contact details, organisation and profile information, account roles, accepted-policy versions, authentication events, support messages, and security records.

Payment and credit data

We may process Stripe customer and payment references, order status, pack quantity, amount, tax, refund or dispute status, credit-lot dates, balances, and ledger history. Stripe receives payment-card details through its checkout. We do not need to store full card numbers.

Participant and assessment data

Depending on how the client uses the Portal, we may process participant names and emails, invitation and completion status, assessment responses, required scoring inputs, derived scores, generated reports, sharing settings, and relevant security and device records. API clients may choose not to send participant identifiers where the integration supports that choice.

Work within Portal modules

We also process the information you save for your professional work: role requirements and candidate-review notes; Coaching topics, situations, preparation and agreed takeaways; Leadership situations, focus areas, actions and follow-up reflections; team membership and context; and relationship pairs and context. These records are separate from the underlying personality report. Saving professional notes does not automatically send them to a participant. Sharing and export actions may create a separate client-facing copy; review that copy and its recipient before sending it.

AI-assisted Coaching

When a client asks the Portal to prepare a Coaching draft, we send OpenAI the topic, any optional situation details the client entered, and limited pseudonymous report evidence such as facet titles, meanings, and percentile results. We do not intentionally send the participant’s name, email, raw assessment answers, or internal identifiers. Clients should avoid entering personal or sensitive details that are not needed for the preparation.

AI-assisted Hiring preparation

When you request a suggested role blueprint, we send OpenAI the role title and optional job description. The request uses role information, not a candidate's report. The service removes recognisable email addresses, phone numbers and certain credentials from these fields before sending them, but this filter cannot identify every personal or confidential detail. Check the text yourself before requesting a draft.

OpenAI data handling

Both AI features disable saved API responses and use no external tools. OpenAI says API data is not used for training by default. Standard abuse-monitoring retention is generally up to 30 days, with legal and safety exceptions; temporary prompt caching may also apply. This is not zero retention. Review all drafts before use. OpenAI's current data controls.

4. Why we process data

We use account, contact and transaction data to fulfil our contract with you: providing access, purchases, support and service notices. Required registration fields are necessary to create and secure an account; optional professional context is your choice. We rely on legitimate interests for proportionate security, fraud prevention, service reliability and aggregate usage statistics, balancing these interests against your rights. Accounting and legally required disclosures rely on legal obligations. Optional Google analytics relies on your consent, which you can withdraw.

The client determines the lawful basis for participant data processed on its behalf. The Portal does not make employment or other legally significant decisions about participants. You must apply human judgement when using assessment results.

5. Service communications

We send messages needed to operate an account, such as email verification, security notices, purchase confirmations, credit-expiry reminders, material service changes, and support replies. These are operational communications, not recurring-payment notices. Marketing messages, if introduced, will use the choices required by applicable law.

6. Payments

Stripe processes checkout and payment information for one-time credit purchases and may calculate tax from the billing information supplied at checkout. Stripe’s own privacy terms apply to processing it performs for its purposes. The Portal stores only the payment and order references needed to fulfil, reconcile, refund, dispute, and audit a purchase.

7. Sharing and service providers

We share data as needed with authorised staff, the client responsible for participant data, professional advisers and authorities where legally required. The Portal uses these core service providers:

  • Vercel: application hosting and web analytics.
  • MongoDB Atlas: Portal database hosting.
  • Stripe: checkout, invoices, payments and related transaction records.
  • Resend: service-email delivery.
  • Cloudflare Turnstile: protection against automated signup abuse.
  • OpenAI: the optional Coaching and Hiring draft requests described above.
  • Google Tag Manager: optional analytics tags on the production Portal when the visitor has enabled analytics.

Providers receive the data necessary for their role; a payment provider, for example, does not need the participant's personality report to process a credit purchase. The data-processing terms are included in section 19 of our Terms of Service. Contact Support@b5.ly for further subprocessor information. We do not sell participant personal data.

8. International transfers

Some providers may process data outside the United Kingdom or European Economic Area, including in the United States. Where a transfer is restricted, it must be covered by an applicable adequacy decision or contractual safeguards, such as the EU Standard Contractual Clauses and the UK Addendum or International Data Transfer Agreement, with supplementary measures where needed. You can request information about the relevant safeguards or a copy from Support@b5.ly. We do not promise that all Portal data stays in one country.

9. Retention and account closure

We keep account, order, credit-ledger, security, and audit records for as long as needed to provide the Portal, resolve disputes, prevent abuse, and meet legal obligations. A credit’s expiry does not itself delete a generated report. On account closure, we normally allow up to 30 days to export available data, unless law, security, or an active dispute requires a different period. We then delete or de-identify data according to the DPA, client instructions, legal requirements, and the purposes described here. Backups may persist for a limited controlled period.

Coaching preparation records

The latest unapplied AI draft is available for up to 30 days. Applied or superseded draft copies become eligible for cleanup sooner; the preparation saved in the topic remains part of that topic. Unreferenced technical generation records become eligible for cleanup after 90 days. Deleted Coaching topics have a 30-day recovery period. Cleanup runs periodically, so eligibility is not a promise of deletion at an exact hour. These periods do not replace the account-closure rules or the AI provider's own retention described above.

10. Security

We use measures designed to protect personal data, including access controls, authentication, encryption in transit, provider-supported encryption at rest, logging, environment separation, and incident procedures. No system can guarantee absolute security. Portal client administrators must manage their users, devices, exports, and report links responsibly.

11. Cookies, local storage and analytics

Essential cookies and local storage support login, security and preferences. We use cookieless Vercel Web Analytics for aggregate statistics on a limited set of public pages. It is enabled unless you refuse analytics. We exclude workspace, report and authentication routes and remove URL query strings and fragments from these page-view events. Optional Google tags load only after analytics consent on the production domain.

Use Cookie preferences in the public-site footer to refuse analytics or change your choice. Refusing analytics also stops Vercel page-view collection in this browser. Choices are browser-specific; clearing site storage resets them. See the Cookie Policy for details. Withdrawing consent does not affect earlier lawful processing.

12. Adults only and high-impact use

The Portal is not intended for people under 18. Clients must not invite minors. Assessment reports must not be used as the sole basis for employment, clinical, legal, credit, relationship, or other high-impact decisions.

13. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction or a portable copy of your data, and object to processing based on legitimate interests. You may withdraw consent at any time. We do not charge for an ordinary rights request and normally respond within one month; we will explain any lawful extension or refusal and may ask for proportionate identity verification. Write to Support@b5.ly, with the subject “Privacy Request”. Participants should normally contact the organisation that invited them; we will help direct the request and assist that organisation.

You may complain to the UK Information Commissioner's Office or your competent local supervisory authority. You do not need to contact us first. We do not sell personal data or use participant reports for advertising.

14. Changes and contact

We will identify the effective date of each approved version and communicate material changes where appropriate.

Privacy questions or requests: Support@b5.ly