A 360° only works if raters can answer honestly and the leader can be sure their report will not be passed around unnoticed. Both assurances can be made in a process document – or enforced in the software. LEADBeyond 360° does the latter; confidentiality here is a property of the system, not a promise: the anonymity rules apply during aggregation on the server, not merely in the display, and access rights are enforced server-side per role. This page describes the rules as a data-protection officer or CHRO would audit them; it is not legal advice. What "anonymous" can and cannot mean in any 360° is covered in Is 360° feedback anonymous?.
When a rater group is shown separately – and when it is not
Each rater group – supervisors, peers, direct reports – is reported separately only once the number of completed raters in that group reaches the anonymity threshold. The default is two; the consulting team configures it per cycle, and HR does not see it as a setting. Below it, a group's answers are folded into the pooled "all others" view and appear nowhere on their own.
A second rule closes the gap thresholds alone leave open: if a group value could be derived by subtracting the other groups from the total, the pooled value is withheld too (the residual rule). No single answer remains recoverable – not even with a calculator.
| Situation | What the report shows |
|---|---|
| Group meets the threshold | Its own value per dimension and item, compared with the self-view |
| Group below the threshold | Answers folded into "all others"; no separate value |
| Group value could be derived by subtraction | The pooled value is withheld as well |
| Fewer than two groups meet the threshold | No report without a logged decision by the consulting team |
A report is generated only once the self-assessment is complete, at least two rater groups meet the threshold, and the deadline has passed or every invited rater has completed; only the consulting team can make an exception, and every exception is logged. What this means for nominations: How many raters does a 360° need?.
Free text: never attributed, never processed by AI
Raters can comment on every item and answer three open questions at the end (stop, start, continue). The same rules apply to all free text:
- No comment is ever linked to a name – in any view, for any role.
- Comments appear in randomised order; they carry a group label such as "peers" only if that group meets the threshold.
- If only one rater completed the assessment in total, all free text is hidden.
- In the current version free text is not analysed, clustered or summarised by AI; it is shown verbatim and threshold-protected. There is no automated decision-making within the meaning of Art. 22 GDPR.
Supervisors: visible separately only by explicit opt-in
In many programmes the supervisor group is one person. By default it follows the same threshold as every other group – a single supervisor is not shown separately but counted within "all others". Where the supervisor's view should deliberately be visible, the consulting team can enable this explicitly per cycle; it is off by default. Even then the residual rule collapses the column if the remaining rater base is too thin. Agree this in programme design, before invitations go out, and make it transparent to the supervisor – never apply it afterwards.
Who sees what: the access matrix
| Role | Sees | Does not see |
|---|---|---|
| Leader | Own report after release; who was nominated and who has completed (name, group, status) | Individual answers or any link between a value and a person |
| Raters | Their own assignments and their status | Reports, scores or answers of anyone else |
| HR / client admin | Cycles, progress, completion rates, assignments with group and status, whether and when a report was released | Individual scores, report content, PDFs, free text, response-quality flags, the anonymity threshold as a setting |
| Consulting team | All reports of their organisations, response-quality flags, their own annotations | Individual answers linked to a name |
| LEADBeyond administration | All reports; emergency withdrawal of a report, with audit log | Individual answers linked to a name |
HR has exactly one exception: an organisation-wide aggregate – distributions per dimension, pillar values, training priorities, the spread of defense patterns, the share with a Well-being risk – without names, individual scores or free text. It appears only when three conditions hold at once: the cycle is closed, at least five leaders have a report, and the consulting team has explicitly enabled the view for that cycle. The reasoning behind this model: Can HR see individual 360° results?.
Equally important is what HR cannot do: methodology – anonymity threshold, scoring, release mode – stays with the consulting team. HR creates cycles, adds leaders, proposes process settings, sends reminders and tracks progress: full process oversight, no access to results.
Why no report goes out unreviewed, and none can be changed afterwards
No report reaches a leader unreviewed. Once generated, it goes to the consulting team, who can add a report-level note and per-dimension annotations, put it on hold, or release it – by explicit click or automatically on a pre-agreed go-live date unless on hold. Only the release triggers the notification to the leader.
A released report is immutable: it stays pinned to its released version. A late response or a correction creates a new version, which the leader sees only after another explicit, logged release. There is no quiet "un-release"; an emergency withdrawal is an administrative exception, audit-logged and communicated to the leader personally. The PDF export carries "Confidential – LEADBeyond 360° Leadership Assessment" in its footer.
Where the data lives and who processes it on our behalf
Database, authentication, file storage (including the PDF reports) and the application itself run in Frankfurt am Main. The privacy policy names the processors working for LEADBeyond under Art. 28 GDPR processing agreements; the regions reflect our configuration:
- Supabase – database, authentication and file storage, EU region Frankfurt.
- Vercel – hosting and delivery of the application, server region Frankfurt am Main.
- Resend – transactional email such as invitations and reminders, configured for its EU sending region.
- Sentry – error and stability monitoring, where enabled.
We phrase the EU question exactly as the privacy policy does: the platform is designed for data storage within the EU; where an individual provider processes data outside the EU/EEA, this rests on appropriate safeguards, in particular EU standard contractual clauses. One concrete example: Resend itself documents that account data, email metadata and logs are stored in the United States whatever sending region is selected. Anyone promising that data "never leaves the EU" is promising more than such a provider chain can deliver.
- Encryption in transit (HTTPS) and at rest (AES-256, managed by Supabase); PDFs in private storage; daily automated backups.
- Supabase and Vercel publish their own SOC 2 Type 2 reports and ISO 27001 certifications – attestations of the vendors, not of LEADBeyond GmbH.
- Sign-in: leaders and raters receive a single-use magic link (valid 24 hours), then set a password for all later logins. Two-factor authentication is mandatory for LEADBeyond administrators.
- Only technically necessary cookies – no tracking, analytics or advertising cookies, and no analytics service sending data outside the EU.
What rights data subjects have, and where the legal basis is decided
The platform processes account and contact data (name, email address, language, hashed password), assessment data (ratings 1–6, optional free text, role and assignment) and usage and log data. The rights to access, rectification, erasure, restriction, data portability and objection (Art. 15–18, 20 and 21 GDPR), and the withdrawal of consent, can be exercised by an informal email to talents@LEADBeyond.de; access requests are answered with a structured export, erasure cascades across the linked records, with log entries pseudonymised rather than deleted. The competent supervisory authority is the Bavarian State Office for Data Protection Supervision (BayLDA).
The legal basis depends on how your organisation sets the programme up – processing on behalf of the client, legitimate interest or, where obtained, consent – and is agreed contractually with you, together with the controller/processor roles, before your programme starts; the privacy policy records that roles, legal bases and processing agreements are being finalised as part of the legal review. Retention periods are governed by the privacy policy.
Frequently asked questions
What is the anonymity threshold, and who sets it?
Two completed responses per rater group by default. The consulting team configures it per cycle; HR does not see it as a setting and cannot change it.
Can the leader work out who said what?
They see who was nominated and who has completed – not who answered how. Scores appear only as group means above the threshold, free text without names and in randomised order, and the residual rule prevents calculating answers back. Why we still do not describe this as absolute anonymity is explained in Is 360° feedback anonymous?.
Are supervisor scores shown separately?
Not by default – a single supervisor falls below the threshold and is counted within "all others". The consulting team can enable the supervisor column explicitly per cycle; even then the residual rule can hide it.
What does HR see – and what not?
HR sees cycles, progress, completion rates, assignments with status and whether a report has been released. HR never sees individual scores, reports, PDFs or free text. An organisation-wide aggregate appears only for a closed cycle with at least five leaders holding a report and an explicit consultant opt-in – see Can HR see individual 360° results?.
Can a released report be changed afterwards?
No. It stays pinned to its released version. Late responses or corrections create a new version that becomes visible only after another explicit, logged release.
Where is the data hosted, and who are the processors?
Database, authentication, file storage and the application run in Frankfurt am Main. The privacy policy names Supabase, Vercel, Resend and – where enabled – Sentry as processors under Art. 28 GDPR. Where a provider processes data outside the EU, this is based on EU standard contractual clauses.
Is free text processed by AI?
No. In the current version free text is neither analysed nor clustered or summarised; it is shown verbatim and threshold-protected. There is no automated decision-making within the meaning of Art. 22 GDPR.
Can 360° results be used for promotion or pay decisions?
The assessment is built for development, not for personnel decisions: HR sees no individual results, and every report is debriefed in a conversation. How your organisation binds that purpose contractually – and whether employee representatives need to be involved – is a question for GDPR and 360° feedback and your legal counsel.
Sources
- Privacy policy of the LEADBeyond 360° platform, LEADBeyond GmbH (2026) — Last updated 21 August 2026; names processors, data categories, legal bases, data-subject rights and the supervisory authority.
- Regulation (EU) 2016/679 (GDPR) – Articles 15–22 and 28, EUR-Lex (2016)
- Supabase – Available regions, Supabase (2026) — Vendor documentation; confirms Frankfurt (eu-central-1) as a project region.
- Vercel – Regions, Vercel (2026) — Vendor documentation; confirms fra1 (Frankfurt) as a server region.
- Resend – Domain regions, Resend (2026) — Vendor documentation; source for the statement that account data, metadata and logs are stored in the United States regardless of sending region.
- Supabase – Security, Supabase (2026) — Vendor page; SOC 2 Type 2 and ISO 27001 are attestations of Supabase, not of LEADBeyond GmbH.
- Vercel – Security, Vercel (2026) — Vendor page; SOC 2 Type 2 and ISO 27001:2013 are attestations of Vercel, not of LEADBeyond GmbH.
Related reading
Trust & governance
Is 360° feedback anonymous? Anonymous in the answers, confidential in participation
Anonymous in the answers, confidential in participation: what the anonymity threshold does, why written comments are the weak point, and what you can honestly promise raters.
Read more →Trust & governance
Is 360° feedback GDPR-compliant? What HR must settle before launch
Legal basis, purpose limitation, access requests vs. rater anonymity, DPIA, processors, retention: what HR should settle before running 360° feedback – sourced, not legal advice.
Read more →Trust & governance
Can HR see individual 360° feedback results? Who should see what – and why it decides whether the feedback is honest
Who sees 360° results decides whether the feedback is honest. The access matrix, three common models, what HR legitimately needs, and how to write it into a programme charter.
Read more →