Data Handling and Confidentiality
This note sets out how respondent data is collected, protected and used in a HumanOS diagnostic pilot. It is intended for HR, legal and works-council review and forms part of the pilot terms.
What the diagnostic collects
The survey measures perceptions of AI at work: how people experience AI tools in relation to their role, their confidence in using them, and the wider conditions around adoption. It takes approximately fifteen minutes and is available in English and Arabic.
It does not collect performance data, HR records, health information, or opinions about named individuals. Demographic items are limited to team, function, seniority band and tenure band, used solely for aggregated reporting.
Confidentiality of individual responses
- Individual responses are never shared with the employer, in any form, at any stage.
- All reporting is aggregated. No team-level results are reported for groups of fewer than ten respondents, and no subgroup or category is reported below five, so no individual can be identified through small-group cuts.
- Above these floors, reporting cuts are checked for identifiability across role, seniority and nationality before release.
- Survey responses are not linked to names or email addresses. Where email is used for distribution, the distribution list is held separately from response data and the two are never joined.
- Participation is voluntary, and this is stated to respondents at the point of invitation.
Storage, access and retention
Response data is held by HumanOS on access-controlled systems. Access is limited to the HumanOS principal. Raw data is not transferred to the client organisation or to any third party. Data is retained for twelve months to support the pilot readout and any agreed follow-up, then deleted. Earlier deletion is available on written request at any time.
Use of results
The client receives an aggregated report: the distribution of adoption profiles by agreed reporting cuts, together with recommendations. HumanOS retains anonymised, aggregated results for the continuing development of the instrument. Nothing identifying the organisation is published, referenced or shared externally without prior written consent.
Compliance
Data handling under this pilot is designed in line with the principles of UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL): purpose limitation, data minimisation, storage limitation and confidentiality.