Questions and answers
Straight answers about where data lives, who can see it, and what we do and do not do. Every question has its own link you can share.
Your account and assessment data are stored on single-tenant servers in Helsinki, Finland (Hetzner), inside the EU. Nightly backups are encrypted and stored separately, in Cloudflare R2. Reference data such as occupation taxonomies is not personal data.
We build for GDPR and can point to what is implemented: EU hosting, parental consent for users under 16 (Article 8), data export and permanent deletion inside the product, a consent audit trail, and data-processing agreements with our sub-processors. Where a school or organisation acts as the data controller, we process data on its instructions. We have not appointed a Data Protection Officer because Article 37 does not currently require one. Complaints can go to the Finnish Data Protection Ombudsman (tietosuoja.fi).
Institutions can request one by emailing [email protected]. Tell us your organisation and whether it acts as the data controller, and we will take it from there.
Yes, some. Your account and assessment data stay on our EU servers, but a few providers (for example AI processing, payments, email delivery and error monitoring) may process limited data outside the EU. Those transfers rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism. The Sub-processors tab lists each provider, what it handles and where it is.
No. Your assessment is scored by a deterministic, rule-based engine; the calculations are mathematics, not AI. AI is used only to phrase results that were already computed, and to power the counselor assistant over a completed profile plus general career information. Before a request leaves our systems, direct identifiers are removed: name, email address and username. Requests can include your assessment results (including scores), your age and gender if you gave them, and text you type into AI features; name, email address and username are not included. AI requests are routed through OpenRouter, which we instruct to use only providers that do not collect or train on prompts. The AI tab lists every feature and what it receives.
In transit: TLS 1.2 or later on every connection, including to our databases. Backups: encrypted at rest, stored off-site, and proven recoverable through a live restore drill. Live database volume: encrypted with LUKS2 (AES-XTS, 512-bit), which protects the data if a disk is removed or improperly decommissioned. While the server is running the volume is mounted and readable by the server itself, as it must be for the database to work.
For users under 16 we require verifiable parental consent, or, where a school is the data controller, the school's authorisation, before assessment data is processed (GDPR Article 8). If parental consent is requested but not confirmed within 7 days, the account and its data are deleted automatically. We measure career interests and personality only, and collect no special-category data.
Yes. You can export your data in a machine-readable format (JSON) and delete your account at any time. Deletion is permanent and irreversible across our systems, including our authentication provider. The exception is billing records, which Finnish accounting law requires us to keep for 6 years. Details are in the Privacy Policy.
Our internal targets are 99.5% uptime per month, data loss of at most 24 hours (RPO, matched to our nightly backups) and recovery within 30 minutes for a service-level incident (RTO, measured on a real incident). These are targets, not a contractual SLA.
Access follows least privilege, and administrative access is only over secured, non-public channels. If you use NexPath through a school or organisation, its authorised counselors and administrators can see your assessment results and progress.
Email [email protected] with “Security” in the subject and include the steps to reproduce it. Please do not access, change or delete other people's data while testing. Our contact details are also published in security.txt at /.well-known/security.txt.
Not answered here?
Ask us directly and we will answer from the same address.