futureZAB Privacy Policy
Plain-language summary
futureZAB operates two service models: (1) Self-Initiated Assessment — candidates voluntarily take the VibeLogic Assessment for self-development; their data is never shared with employers. (2) Employer-Requested Assessment (B2B) — an employer engages futureZAB to assess their job applicants; the report is sent to the employer. See Section 1B for the critical distinction. We use AI (Claude by Anthropic) to generate report narratives from assessment scores — no personally identifiable information is sent to AI providers. We never sell your data. Sections marked with Candidate or Employer apply only to that role.
Table of contents
1. Introduction
This Privacy Policy ("Policy") describes how Renewing Minds Consulting LLC, operating as futureZAB ("futureZAB," "Company," "we," "us," or "our"), collects, uses, stores, and protects your personal data when you access or use the futureZAB platform, website, and all related services (collectively, the "Platform").
futureZAB is a behavioral assessment platform. We provide fresh graduates ("Candidates") with personalized assessment reports based on the VibeLogic framework. We also offer a separate B2B service where employers ("Employers") may engage futureZAB to administer VibeLogic Assessments to their own job applicants.
This Policy applies to all users of the Platform. How your data is handled depends on which service model applies to you — see Section 1B below for the critical distinction.
By using the Platform or submitting the VibeLogic Assessment, you acknowledge that you have read, understood, and consent to the data practices described in this Policy. If you do not agree, please do not use the Platform.
Note: The Platform is currently in an early release stage. Features described in this Policy (such as user accounts and dashboards) reflect both current functionality and planned future capabilities. We will update this Policy as new features are released.
This Policy should be read together with our Terms & Conditions, which govern your overall use of the Platform.
1B. Two Service Models
futureZAB operates two distinct assessment service models. Your data is handled differently depending on which model applies to you. Please read this section carefully to understand which model applies to your situation.
1B.1 Self-Initiated Assessment Candidate
Applies to: Individuals who voluntarily visit www.futurezab.com and choose to take the VibeLogic Assessment for self-development purposes.
- Data controller: futureZAB is the data controller. We decide why and how your data is processed.
- Who receives the report: Only you. The Assessment Report is emailed to the address you provided.
- Database membership: Your assessment data is stored in our internal database for service operation and validation.
- Sharing with employers: We do not share your personal data with employers in this model. Employers may view aggregated, anonymized assessment insights only — never your name, contact details, or any identifying information. Each anonymized record is referenced only by a candidate ID.
- Cost: Free.
1B.2 Employer-Requested Assessment (B2B Service) Employer Candidate
Applies to: Job applicants who are asked by an employer to complete a VibeLogic Assessment as part of that employer's hiring process. This service is accessed via a dedicated URL (e.g., futurezab.com/VibeLogic-employer/[link]) provided directly by the employer to the applicant.
- Service nature: This is a business-to-business (B2B) assessment service similar to other professional assessment providers (e.g., SHL, Hogan, Predictive Index). futureZAB administers the assessment as a service to the employer.
- Data controller: The employer is the data controller. The employer has decided to collect this data for their own hiring evaluation purposes. futureZAB acts as a data processor on the employer's behalf.
- Notice to candidates: Before you start the assessment, you will be clearly informed which employer has requested it and that the resulting report will be shared with them.
- Consent: By completing the assessment after this notice, you consent to your data being shared with the requesting employer. If you do not consent, simply do not complete the assessment.
- Who receives the report: The Assessment Report is delivered to the employer. A copy will only be sent to you if the employer has explicitly arranged this with you in advance.
- Database membership: You are NOT added to the futureZAB Tribe database in this model. Your assessment data is processed under the employer's direction and is not used for any other purpose.
- Employer's data rights: The employer has the right to retain your Assessment Report as part of their hiring evaluation records, subject to their own data protection obligations and our Data Processing Agreement with them.
- Reduced data collection: The B2B assessment form collects only the minimum personal information needed for the assessment and report (no extensive demographics or career profile data).
- futureZAB's retention: futureZAB retains a minimal record of the assessment (assessment ID, completion date, score summary) for service quality and audit purposes only. We do not use this data for marketing, employer-database building, or any other purpose.
- Cost: The employer pays per assessment. There is no cost to you.
Important: futureZAB is not a recruitment agency. In the B2B Service model, we are providing an assessment tool to an employer who has independently identified you as a job applicant. We do not introduce, refer, or match candidates to employers in either service model.
2. Information We Collect
2.1 Personal information Candidate
When you submit the VibeLogic Assessment, we collect:
- Identity data: Full name, email address, phone number.
- Education data: University or institution name, field of study, graduation year (if provided).
When user accounts are introduced in a future release, additional data (profile photo, bio, login credentials) may be collected with your consent.
2.2 Assessment data Candidate
When you complete the VibeLogic Assessment, we collect and generate:
- Response data: Your answers to the 25 scenario-based assessment questions.
- Scoring data: Computed metric scores across six dimensions, overall score bands.
- Archetype data: Your assigned archetype and archetype variation, determined by your scoring pattern.
- Trait labels: Behavioral trait chips derived from your score profile (e.g., working style, drive pattern).
- AI-generated profile: Narrative summary and full report generated by AI from your assessment scores.
2.3 Employer data Employer
When you engage with futureZAB as an Employer, we may collect:
- Company information: Company name, registration number (SSM), industry, company size, website URL.
- Contact information: Authorized representative's name, email address, phone number, job title.
- Payment details: Billing information processed through Stripe. futureZAB does not store credit card numbers directly — these are handled by our PCI-compliant payment processor.
- Purchase history: Records of Report Access purchases, plan subscriptions, and transaction receipts.
2.4 Usage data
We automatically collect certain technical data when you use the Platform:
- Device information: Browser type and version, operating system, screen resolution.
- Network data: IP address, approximate geographic location (country/region level).
- Activity data: Pages visited, features used, timestamps, session duration.
- Referral data: How you arrived at the Platform (e.g., referral link, search engine).
3. How We Use Your Information
We use the information we collect for the following purposes:
- Assessment processing & delivery: To process your VibeLogic Assessment submission, generate your report, and deliver it to you via email.
- Assessment processing: To score the VibeLogic Assessment, compute metrics, assign archetypes, and generate trait labels from your responses.
- AI-generated profile creation: To send assessment scores (archetype, variation, metric scores, trait labels) to AI providers (Claude by Anthropic, OpenAI) for narrative profile generation. See Section 4 for full details.
- Report delivery: To deliver Assessment Reports to candidates and to provide assessment data to employers upon Report Access purchase.
- Communication: To send your assessment report and occasional platform updates. You may opt out of non-essential communications at any time.
- Platform improvement: To analyze aggregated, anonymized usage patterns to improve the assessment methodology, user experience, and Platform features.
- Legal compliance: To comply with applicable laws, regulations, and legal processes, including the Malaysia Personal Data Protection Act 2010 (PDPA).
4. AI-Generated Profiles Candidate
futureZAB uses artificial intelligence to generate narrative candidate profiles from assessment data. This section explains exactly how AI is used and what data is involved.
4.1 How AI profiles are generated
After you complete the VibeLogic Assessment, your scores are processed by our internal scoring engine. The resulting assessment data is then sent to AI language models (currently Claude by Anthropic and OpenAI) to generate a written narrative profile, including a Summary Card description and Full Report.
4.2 Data sent to AI providers
The following assessment data is sent to AI providers for profile generation:
- Your assigned archetype and archetype variation.
- Your metric scores across the six assessment dimensions.
- Your trait labels (behavioral chips such as working style and drive pattern).
4.3 Data NOT sent to AI providers
We take deliberate steps to protect your privacy. The following data is never sent to AI providers:
- Your name, email address, phone number, or any other personally identifiable information (PII).
- Your university, graduation year, or any demographic data.
- Your profile photo or location.
- Your raw assessment responses (individual question answers).
4.4 Complete data processing pipeline
Your assessment data is processed through the following stages:
- Collection: You submit your responses via Tally (third-party form builder).
- Storage: Responses are transferred to and stored in Notion (cloud database).
- Scoring: Our internal scoring engine processes your answers to compute metric scores, assign archetypes, and determine working styles.
- AI narrative: Assessment scores (no PII) are sent to Claude by Anthropic to generate your written profile narrative.
- Report generation: Your Candidate Report (PDF) is generated internally and uploaded to Notion.
- Delivery: Your report is emailed to you as a PDF attachment. The delivery timestamp is recorded.
4.5 Human review
All AI-generated profiles are reviewed by a futureZAB administrator before being published to the Platform. Profiles are not made live automatically. This review ensures quality, accuracy, and appropriateness of the generated content.
5. Information Sharing
We do not sell, rent, or trade your personal data to third parties. We share information only in the following limited circumstances:
5.1 With employers Employer
How candidate data is shared with employers depends on which service model applies (see Section 1B):
Self-Initiated Assessment (Section 1B.1):
- No personal data sharing: Your name, contact information, university, and other identifying details are never shared with employers in this model.
- Anonymized insights only: Anonymized assessment insights (archetype, working style, drive pattern, metric score bands, trait labels) may be displayed in aggregate form, referenced only by a candidate ID. No employer can identify you from this data.
Employer-Requested Assessment / B2B (Section 1B.2):
- Report shared with the requesting employer: Your full Assessment Report is delivered to the specific employer who requested the assessment. You are informed of this before starting the assessment.
- Employer's data rights: The employer has the right to retain your Assessment Report as part of their hiring evaluation records, subject to their own data protection obligations.
- No onward sharing by futureZAB: futureZAB does not share your data with any other employer. Each employer engagement is bilateral and isolated.
In both models:
- No introductions or matchmaking: futureZAB does not introduce, recommend, or refer candidates to employers. We are not a recruitment agency or employment intermediary.
5.2 With AI providers Candidate
- Assessment scores only (archetype, variation, metric scores, trait labels) are shared with Claude (Anthropic) for profile generation.
- No personally identifiable information (PII) is ever sent to AI providers. Your name, email, university, and contact details are not included.
- Assessment data sent to AI providers is used solely for generating your profile narrative and is governed by Anthropic's commercial Terms of Service, which prohibit using API inputs to train their models.
- For full details on how Anthropic processes data, see Anthropic Privacy Policy.
5.3 With payment processors Employer
- Payment transactions are processed by Stripe, a PCI DSS Level 1 certified payment processor.
- Stripe receives billing information (card details, billing address) directly — futureZAB does not store credit card numbers on our servers.
- Stripe's privacy policy governs the handling of payment data: stripe.com/privacy.
5.4 With form collection providers
- The VibeLogic Assessment is currently hosted on Tally (tally.so), a third-party form builder. When you submit the assessment, your responses are initially collected and transmitted through Tally's infrastructure before being transferred to our internal systems.
- Data collected via Tally includes your name, email address, and assessment responses (25 answers).
- Tally's privacy policy governs how they handle form submission data: tally.so/help/privacy-policy.
5.5 With data storage providers
- Assessment responses and candidate metadata are stored in Notion (notion.so), a cloud-based workspace platform, which acts as our primary database for assessment records.
- Data stored in Notion includes: submission ID, assessment answers, candidate name, email, and generated report attachments (PDFs).
- Notion also tracks whether candidate reports have been emailed (delivery timestamp).
- Notion's privacy policy governs their data handling: notion.so/privacy.
5.6 With email & service providers
- Email delivery: Candidate assessment reports are sent via email as PDF attachments using SMTP email infrastructure hosted by our domain provider. Your email address is used solely for report delivery and platform communications.
- Hosting & infrastructure: The Platform is hosted on cloud infrastructure providers that maintain industry-standard security certifications.
- Analytics: We may use analytics tools to understand aggregated usage patterns. Analytics data is anonymized and does not identify individual users.
5.7 Legal requirements
We may disclose your information if required to do so by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of futureZAB, our users, or the public.
6. Data Protection — PDPA 2010 (Malaysia)
futureZAB complies with the Personal Data Protection Act 2010 (PDPA) of Malaysia for the processing of personal data of users in our Southeast Asian launch markets. We are committed to meeting the standards of applicable data protection regulations in all markets we operate in.
6.1 The seven data protection principles
We adhere to all seven principles of the PDPA:
- General Principle: Personal data shall not be processed without the consent of the data subject. We obtain consent when you submit your assessment.
- Notice and Choice Principle: We inform you of the purpose of data collection, your rights, and who may access your data — through this Privacy Policy. You have the choice to provide or withhold consent.
- Disclosure Principle: Personal data shall not be disclosed for purposes other than those for which it was collected, except with your consent or as required by law. Candidate assessment data is shared with Employers only upon Report Access purchase, with candidate consent.
- Security Principle: We implement appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. See Section 10 for details.
- Retention Principle: Personal data shall not be kept longer than is necessary for the fulfillment of the purpose for which it was collected. See Section 9 for our retention schedule.
- Data Integrity Principle: We take reasonable steps to ensure that personal data is accurate, complete, not misleading, and kept up to date. Users may update their profile information at any time.
- Access Principle: You have the right to access and correct your personal data held by us. See Section 7 and Section 8 for details on exercising these rights.
7. Candidate Data Rights Candidate
As a Candidate, you have the following rights regarding your personal data:
- Access your report: Your Candidate Report (PDF) is emailed to you upon completion. You may request an additional copy at any time by contacting support@futurezab.com.
- Request correction: You may request corrections to your personal information by contacting us.
- Request deletion: You may request the deletion of all your personal data by contacting support@futurezab.com. Deletion requests are processed within 30 days.
- Withdraw consent: You may withdraw your consent for data processing at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
When user accounts and dashboards are introduced in a future release, additional self-service data management features (profile editing, data export, visibility controls) will be available.
8. Employer Data Rights Employer
As an Employer, you have the following rights regarding your data:
- Request information: You may request details of any data we hold about your company by contacting support@futurezab.com.
- Request deletion: You may request the deletion of your company data by contacting us. Deletion requests are processed within 30 days. Note: transaction records may be retained for accounting and legal compliance purposes as required by applicable law.
When employer accounts and dashboards are introduced in a future release, self-service data management features will be available.
9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Active data: Personal data is retained for 24 months from last interaction with the Platform. After 24 months of inactivity, we will send you a notification email. If you do not respond within 30 days, your data will be automatically deleted from our systems.
- Assessment data: Assessment responses and scoring data are retained for validation, quality assurance, and potential reassessment purposes.
- Account deletion requests: Upon receiving a deletion request, all personal data is permanently deleted within 30 days, except where retention is required by law.
- Purchased reports: Assessment Reports that have been accessed by Employers are retained as part of the Employer's purchase record, per the Employer's service agreement. This ensures Employers retain access to reports they have paid for.
- Transaction records: Payment and billing records are retained for 7 years to comply with applicable tax and accounting regulations.
- Anonymized data: Aggregated, anonymized data (which cannot identify any individual) may be retained indefinitely for research, analytics, and platform improvement purposes.
10. Security Measures
We implement comprehensive technical and organizational measures to protect your personal data:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using HTTPS/TLS (Transport Layer Security).
- Data security: Personal data is protected using industry-standard security practices appropriate to the sensitivity of the data.
- Database encryption: Personal data stored in our database is encrypted at rest using industry-standard encryption algorithms.
- Rate limiting: API endpoints are rate-limited to prevent brute-force attacks, credential stuffing, and abuse.
- DDoS protection: The Platform is protected by Cloudflare to mitigate distributed denial-of-service attacks and other network-level threats.
- Regular backups: Database backups are performed regularly and stored securely. Backups are encrypted and access is restricted to authorized personnel only.
- Access controls: Internal access to personal data is restricted to authorized futureZAB team members on a need-to-know basis. All administrative actions are logged.
- Access controls: When user accounts are introduced, they will be protected with appropriate authentication measures.
11. Cookies & Tracking
The Platform uses cookies and similar technologies to ensure proper functionality and improve your experience:
11.1 Essential cookies
- Essential cookies: The current website uses CDN-hosted scripts (Tailwind CSS, Google Fonts, Lucide icons) which may set functional cookies. When user accounts are introduced, session cookies will be required for authentication.
- Security cookies: Used for rate limiting, bot detection, and fraud prevention.
11.2 Analytics cookies
- If analytics tools are used, cookies may be set to collect anonymized usage data (page views, session duration, feature usage). Analytics data is aggregated and does not identify individual users.
- You may opt out of analytics cookies through your browser settings.
11.3 What we do NOT use
- No third-party advertising cookies. We do not serve ads on the Platform and do not use advertising tracking pixels or cookies.
- No cross-site tracking. We do not track your activity across other websites.
- No data sold to advertisers. Cookie data is never shared with or sold to advertising networks.
12. International Data
futureZAB is built as a multi-country platform. The following provisions apply to international data handling:
- Launch market: futureZAB is initially launching in Malaysia, with planned expansion to Singapore and other Southeast Asian markets.
- Cross-border data transfers: If your data is transferred to servers or service providers located outside of Malaysia, we ensure that appropriate safeguards are in place in accordance with the PDPA 2010, including contractual data protection clauses with our service providers.
- AI provider data processing: Assessment data sent to AI providers (Anthropic, OpenAI) may be processed on servers located outside Malaysia. No personally identifiable information is included in these transfers (see Section 4).
- Timestamps: All system timestamps are stored in UTC. Local timezone display is applied in the user interface based on your detected or configured timezone.
- Local compliance: As we expand to new markets, we will update this Policy to reflect compliance with local data protection regulations (e.g., Singapore PDPA 2012).
13. Children's Privacy
The futureZAB platform is designed for users aged 18 and above, specifically targeting fresh graduates entering the workforce. We do not knowingly collect personal data from individuals under the age of 18.
If we become aware that we have inadvertently collected personal data from a minor (under 18), we will take immediate steps to delete such data from our systems. If you believe that a minor has provided personal data to futureZAB, please contact us at support@futurezab.com and we will investigate and act promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
- We will post the revised Policy on this page and update the "Last updated" date at the top.
- For material changes (changes that significantly affect how we collect, use, or share your data), we will notify you by email at least 14 days before the changes take effect.
- Your continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of the changes.
- If you do not agree with the updated Policy, you may request deletion of your data. Contact support@futurezab.com for assistance.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
- Email: support@futurezab.com
- Company: Renewing Minds Consulting LLC (operating as futureZAB)
- Website: www.futurezab.com
We aim to respond to all privacy-related inquiries within 14 business days. For data access, correction, or deletion requests, we will process your request within 30 days in accordance with the PDPA 2010.