Development Assessment Privacy Notice — working draft
Prepared 30 September 2026. Do not publish this draft until the bracketed details are completed and the retention and consent arrangements described below are implemented.
Development Assessment Privacy Notice
Who is responsible for your information?
Matthew Gorner is responsible for the personal information collected through the Psychosynthesis Development Assessment on MatthewGorner.com. For privacy enquiries, requests about your information, or withdrawal of consent, email developmentmap@matthewgorner.com.
What information is collected?
The assessment collects your name, email address, age range, selected answers and written reflections. These may include sensitive information about your psychological wellbeing, mental health, relationships or spiritual experiences. The website also records submission information such as your IP address, submission date and consent selections.
Your assessment record includes calculated scores, pattern indicators, selected developmental pathways, wellbeing review flags, draft report text and workflow review information. Please avoid including information that identifies other people in your written answers.
Why is it used?
Your information is used to process your assessment, identify suggested developmental starting points, review whether a Development Map is appropriate, prepare and review a draft, and communicate with you about the assessment. If a report is approved, it is sent to the email address you provide. Submission does not guarantee a report.
The assessment supports personal development and reflection. It is not a diagnosis, psychotherapy or crisis-support service, and submissions are not monitored continuously.
Consent
For the assessment service, the proposed basis for processing your personal information is consent under Article 6(1)(a) of the UK GDPR, together with explicit consent under Article 9(2)(a) where your responses reveal special-category information, including health information.
You can choose not to complete the assessment. If you withdraw consent by emailing developmentmap@matthewgorner.com, processing based on that consent will stop. This does not affect the lawfulness of processing already carried out. Withdrawal before completion may mean that a Development Map cannot be prepared or delivered.
[Before publication: confirm and document these bases and implement a separate, clear explicit-consent statement in the form. Replace “proposed basis” with “basis” only when this is in place. Identify any additional processing purposes and bases separately.]
How scoring and AI are used
Fixed scoring rules calculate developmental scores, suggested pathways and wellbeing review routes. OpenAI’s API is used to help prepare report wording from selected scores, pattern indicators, pathway results, the saved safety status and action route, and written reflections.
The current generator does not deliberately send your name, email address, age range or individual wellbeing-question answers to OpenAI. However, anything you include in a written reflection may be included in the information sent, so please avoid unnecessary identifying details.
AI does not set or override safety classifications or pathway selections. Matthew reviews every report before it is released and may edit or withhold a draft.
OpenAI states that API data is not used to train its models by default. The generator disables storage of response application state, but this does not remove all provider retention: standard abuse-monitoring logs may contain request and response content and are generally retained for up to 30 days, subject to stated legal and security exceptions.
Who receives or accesses the information?
Matthew is the only person who reviews assessment entries within the practice. Hostinger provides the website hosting and website backups. The email service supplied through Hostinger is provided by Titan. OpenAI processes the information sent through its API. These suppliers may process information as necessary to provide and protect their services.
An approved report is emailed to the address you provide. Email copies and notifications may contain assessment information. Please use an address you control and consider who else may have access to that mailbox or device.
[Confirm whether any other connected services receive assessment data.]
International processing
[Complete before publication: state the relevant overseas processing locations and the UK transfer safeguards actually applicable to the Hostinger and OpenAI accounts. Include how participants can obtain information about those safeguards. Do not assume that a UK website server keeps all processing within the UK.]
How long is information kept?
Identifiable assessment responses, draft and final reports, and associated assessment email copies are kept for up to 90 days from submission, then deleted from active records.
Deleted information may remain in protected automatic website backups until they expire. Hostinger states that automatic daily backups are retained for seven days and automatic weekly backups for six weeks. These periods run from the backup date, so a backup created shortly before deletion from active records may remain for up to a further six weeks.
[Before publication: confirm whether manual or downloaded backups contain assessment records; their retention must be specified separately. Establish a process to reapply deletions after restoring a backup. Confirm Titan deleted-item retention and deletion of local email or report copies.]
The OpenAI retention arrangements described above are separate from the 90-day period for records controlled by Matthew.
[Before publication: implement this retention process. Separately document any limited records that need a different retention period, their purpose, legal basis and period. Do not promise deletion that the actual systems cannot deliver.]
Your choices and rights
You can contact Matthew to request access to your information, correct inaccurate information, request deletion or restriction, withdraw consent, or request a portable copy where applicable. Some rights depend on the circumstances and legal requirements. AI-generated interpretations can also be raised with Matthew for review; they are reflective suggestions rather than established facts about you.
For concerns about how your information is handled, contact developmentmap@matthewgorner.com. You can also complain to the UK Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/.
Sources used to prepare this draft
- ICO privacy-information requirements: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/the-right-to-be-informed/what-privacy-information-should-we-provide/
- ICO explicit-consent guidance: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/consent/what-is-valid-consent/
- OpenAI API data controls: https://developers.openai.com/api/docs/guides/your-data
- Hostinger backup guidance (account-specific schedule still to be verified): https://www.hostinger.com/support/5981435-how-to-download-backups-at-hostinger/
