Terms & Conditions and Privacy Notice

These terms govern your use of the iTeam team diagnostic and the diagnostic quiz, and explain — in one document — how personal information is collected, used and protected under the GDPR (EEA & UK), POPIA (South Africa) and other applicable laws.

Version 1.2 · Effective date: 16 September 2026

1. Who we are & acceptance of these terms

The iTeam team diagnostic, the iTeam diagnostic quiz and the website at www.iteamformyteam.com (together, the "Service") are operated by Beyond The Gap Proprietary Limited, registration number 2017/261460/07, a company incorporated in the Republic of South Africa, with its registered address at 11 Tintagel Road, West Beach, Milnerton, Western Cape, 7441, South Africa ("BTG", "we", "us").

"Coaching Unity International" is a brand under which the Service is presented, and is not the contracting party. It is a trading style, not a registered entity. Your agreement for the Service is with BTG alone, and every reference in these terms to "we", "us" or "BTG" means Beyond The Gap Proprietary Limited.

By creating an account, starting a diagnostic quiz, joining an assessment session, ticking an acceptance checkbox, or otherwise using the Service, you agree to these Terms & Conditions and to the processing of personal information described in the Privacy Notice contained in sections 7–11. If you do not agree, do not use the Service.

If you are accepting on behalf of a company, team or other organisation, you warrant that you have authority to bind that organisation, and "you" includes that organisation.

2. Definitions

3. The Service

iTeam is a team-diagnostic instrument. It captures where team members believe their team currently stands, and where it needs to stand, on a set of tensions ("continuums"), and produces aggregate Reports designed for facilitated debriefs. The diagnostic Quiz maps observed symptoms to recommended continuums. The Service includes optional AI-assisted content generation (section 13) and optional paid quiz reports and subscriptions (section 6).

The Service provides decision-support information for team development. It is not a psychometric test, a medical or psychological assessment, an employee-evaluation instrument, or a substitute for professional advice. Reports reflect the subjective perceptions of the people who responded, and must not be used as the sole basis for employment decisions about any individual.

4. Accounts & eligibility

5. Acceptable use

You must not:

6. Fees & purchases

7. Data protection & privacy

This section, together with sections 8–11, is our Privacy Notice. It applies to Coaches, Participants, Quiz users and website visitors.

7.1 What we collect and why

CategoryExamplesPurpose
Coach account dataName, email, hashed password or sign-in identity, access codes, settingsProvide and secure your account; communicate service messages
Participant contact dataName and email supplied by the Coach; personal invitation token; completion statusDeliver invitations and reminders; show the Coach who has completed — never what anyone answered
Session ResponsesMarker positions (−5…+5) and free-text comments per continuumGenerate aggregate team Reports. Stored against a session token, not against your name or email (see 7.2)
Quiz dataEmail, team name (optional), selected symptoms, notes, recommendation results, and any positions you declare for yourself against a continuumRun the diagnostic, deliver your results, link purchases to your entitlement
Payment dataNone at present — the Service is in advanced testing and takes no payments (section 6). If paid plans are introduced: purchase type, amount and status, processed by a payment provider named here in advanceFulfil purchases and entitlements; accounting
Technical dataIP address, request logs, rate-limit counters, audit eventsSecurity, abuse prevention, diagnosing faults
Usage analyticsPages viewed on our public website and within the Service, and the time of viewing; the website you arrived from; approximate country; device type, browser and operating system; and a daily-rotating pseudonym derived from your IP address and browser. We do not store your raw IP address against these records, and web addresses are stripped of their query strings before storage. We also record two events that are not anonymous: when a Coach signs in, and when an activation email is re-sent. Those two are recorded against your account, not anonymously — they carry your internal account reference, though never your email addressUnderstand which parts of the website and Service are used, and diagnose where people get stuck; and, for the two account events, monitor sign-in activity for security and support account recovery. First-party only — see 7.8
Coach-supplied AI keysAn API key a Coach chooses to add for AI content generationStored encrypted; used only to make the AI requests that Coach initiates (section 13)

7.2 Anonymity by design

Session Responses are engineered to be anonymous at the data layer: your email tracks whether you completed, never what you answered. Responses are keyed to a session token that is not linked to your identity in Reports. Two honest caveats:

7.3 Use of data to improve our models

Plain-language summary: we use assessment and quiz data — de-identified and aggregated wherever possible — to improve iTeam itself: better continuum content, better symptom-to-continuum mappings, better scoring and recommendation models, and better AI-assisted features. We do not sell your personal information.

Specifically, we may use:

Where this processing relies on your consent (for example, under the GDPR where consent is the appropriate basis), we ask for it at the point you first use the Service — such as the acceptance checkbox when you start a Quiz — and you may withdraw it at any time by contacting privacy@iteamformyteam.com. Withdrawal stops future use of your identifiable data for model improvement; it does not un-train improvements already derived from data that was de-identified or aggregated before withdrawal, and it does not affect processing needed to deliver the Service itself.

We do not use Participant emails or names to improve models, and we do not permit third parties to train their own models on your identifiable data.

What we actually do today. The rights above are reserved, not exercised. We do not currently operate any automated process that extracts Response values or free-text comments across Sessions for these purposes, and the scoring thresholds and split-detection rules in the Service are fixed values set by us — they are not fitted to customer data. If that changes, this notice will be updated first, and the controls in the paragraph below will apply.

Client Organisations under a written agreement. Where a Client Organisation engages us under a signed agreement, that agreement prevails over this section. Such Sessions are treated as service delivery only by default: their Response statistics and their free-text comments are used solely to deliver that Client Organisation's own Reports, and for no other purpose. Secondary use of either applies only where it is expressly agreed in writing, and the two may be agreed independently of each other. Where an agreement requires us to destroy a Client Organisation's information on termination, we will do so and certify it in writing on request.

7.4 Service providers (sub-processors)

ProviderRoleLocation of processing
SupabaseDatabase (all Session, Quiz and account records)European Union — AWS eu-north-1, Stockholm
RenderHosting for our API, and for the app's own files (its scripts, styles and images). Every request that carries Session, Quiz or account data goes to the API; the app's files are delivered separately, over a content-delivery network, and carry noneEuropean Union — Frankfurt, Germany, for the API and for the stored files. The content-delivery network that serves those files has locations worldwide, so the request for them — and with it your IP address — may be handled outside the EU
AfrihostStatic web hosting for our public website at iteamformyteam.comSouth Africa
ResendTransactional email (invitations, reminders, account messages)European Union — Ireland, for sending and for the stored message records. The provider is a United States company, so its personnel may access data in the course of providing the service
AnthropicAI content generation, only when a Coach initiates it, and only using an API key that Coach supplies (section 13). The Service does not send Participant Responses, free-text comments or contact details to this providerUnited States
Google FontsServes the typefaces used by this page and the public website. Your browser requests them directly, which discloses your IP address to Google. The app itself does not use itUnited States

Your Session and Quiz records — every response, comment and account — are stored and processed inside the European Union, on the database and application hosts named above. One narrow exception leaves it, and it is in the table: where a Coach initiates AI content generation, that request goes to a provider in the United States using the Coach's own key, carrying no Participant responses, comments or contact details. Two further cases are named for completeness, although neither moves those records outside the European Union. Email we send you — an invitation, a reminder, an account message — is delivered by a provider whose sending infrastructure and message records are in the European Union (Ireland), so the recipient's name, email address and the link itself pass through it there; that provider is a United States company, and its personnel may access data in the course of providing the service, which is a form of access rather than a transfer of storage. And the app's own files — its scripts, styles and images — are delivered over a content-delivery network with locations worldwide, so the request for them may be handled outside the EU and your IP address seen there. No Session, Quiz or account data travels that path; everything that carries such data goes to our API in Frankfurt. Nothing else is transferred, and transfers are covered by the safeguards in 8.3 and 9. The providers above are the complete list; we engage no payment processor, and no advertising, analytics or tracking provider of any kind. The usage analytics described in 7.1 and 7.8 are entirely first-party: they are recorded by our own API and stored in our own database, and no third party receives them. Each provider processes personal information under contractual terms consistent with this notice, and we will update this list before any new provider begins processing.

7.5 Retention & deletion

7.6 Security

We apply proportionate technical and organisational measures, including: encrypted transport (HTTPS); hashing of passwords; encryption of stored API keys; signed, session-scoped role tokens; per-identity access scoping on every read and write; rate limiting and abuse caps on public endpoints; audit logging of sensitive actions; and anonymity-by-design separation of completion tracking from Response content. No system is perfectly secure; if we become aware of a breach affecting your personal information we will notify you and the relevant authorities as required by law (GDPR arts. 33–34; POPIA s22).

7.7 Our role: controller / responsible party — or processor / operator

7.8 Cookies, browser storage and analytics

We set no cookies. The Service and this website do not use cookies for advertising, tracking or measurement, and we do not operate a third-party analytics or advertising tag of any kind. There is therefore no advertising or tracking consent to give or withdraw.

We do use your browser's own storage for the Service to function:

Neither is used to build a profile of you or to follow you across other websites, and neither leaves your browser except to authenticate you to us.

First-party usage analytics. We record page views on our public website and within the Service, as described in 7.1. This happens on our own servers from the ordinary request — there is no tracking script, no analytics SDK, and no identifier stored on your device for it. Visitors are counted using a pseudonym derived from your IP address and browser with a secret that changes every day, so the same person cannot be recognised from one day to the next, and your raw IP address is not stored against these records. Your browser's user-agent is reduced to coarse categories — device type, browser family and operating system — and is not stored in full. Approximate country comes from a two-letter code our hosting provider attaches at the network edge; we do not run any IP-geolocation lookup. Query strings are removed before storage, because access links carry tokens in them, and identifiers inside a web address are replaced before it is stored. These records are deleted after twelve months (7.5).

Two analytics events are not anonymous. When a Coach signs in, and when an activation email is re-sent, we record that event against your account, not anonymously: the record carries your internal account reference so that sign-in activity can be attributed to the right account. It never carries your email address. Everything else described above is pseudonymous. Our lawful basis for all of it is legitimate interests (8.1); you may object at privacy@iteamformyteam.com.

None of this is shared with, or sent to, any analytics or advertising company. The only third parties involved are the hosting and database providers already listed in 7.4, which process these records because they run our servers.

8. European Economic Area & United Kingdom — GDPR

If you are in the EEA or the UK, the EU General Data Protection Regulation or UK GDPR applies. This section supplements section 7.

8.1 Lawful bases

ProcessingLawful basis
Providing accounts, Sessions, Quiz results, purchasesPerformance of a contract (art. 6(1)(b))
Security, abuse prevention, service improvement analyticsLegitimate interests (art. 6(1)(f)) — balanced against your rights
Model improvement using identifiable data (7.3)Consent (art. 6(1)(a)) where required; otherwise legitimate interests applied only to de-identified/aggregated data
Invitations and reminders to ParticipantsLegitimate interests of the Client Organisation as controller; BTG processes as processor
Legal obligations (tax, accounting)Legal obligation (art. 6(1)(c))

8.2 Your rights

You may request: access to your personal data; rectification; erasure; restriction of processing; portability; and you may object to processing based on legitimate interests, withdraw consent at any time (without affecting prior processing), and lodge a complaint with your supervisory authority (in the UK, the ICO). Where BTG is processor, we will refer your request to the Client Organisation as controller and assist it in responding. Contact: privacy@iteamformyteam.com. We respond within one month, extendable as the GDPR allows.

8.3 International transfers

Where personal data is transferred outside the EEA/UK (see 7.4), we rely on adequacy decisions where available and otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), with supplementary measures where appropriate. A copy of the relevant safeguards is available on request.

8.4 Automated decision-making

The Service scores and aggregates responses and recommends continuums algorithmically, but it does not make decisions producing legal or similarly significant effects about you without human involvement. Reports are inputs to human-led conversations.

9. South Africa — POPIA

If you are in South Africa, the Protection of Personal Information Act 4 of 2013 (POPIA) applies. This section supplements section 7.

10. Rest of the world

Wherever you are, we apply the standards in section 7 as our baseline. In addition:

11. Children

The Service is a workplace and sports-team instrument. It is not directed at children. Coach accounts require you to be 18+. Participants and Quiz users must be 16+ (or the higher age your local law sets for consenting to data processing); where a Session involves a sports squad including minors, the Client Organisation is responsible for obtaining the consent of a competent person (POPIA s34–35; GDPR art. 8) before inviting them.

12. Intellectual property & report confidentiality

13. AI-assisted features

14. Disclaimers & limitation of liability

The Service is provided "as is" and "as available". To the maximum extent permitted by law, we disclaim all warranties, express or implied, including fitness for a particular purpose; we do not warrant that the Service will be uninterrupted, error-free or that Reports are suitable for any specific decision.

To the maximum extent permitted by law: (a) we are not liable for indirect, incidental, special or consequential loss, loss of profits, or loss of data; (b) our total aggregate liability arising out of the Service in any 12-month period is limited to the greater of the fees you paid us in that period and ZAR 25,000. Nothing in these terms limits liability that cannot lawfully be limited (including under the South African Consumer Protection Act where it applies, or liability for fraud).

15. Indemnity

You indemnify us against claims arising from: your breach of these terms; Participant data you submit without a lawful basis; your misuse of Reports (including attempted re-identification or adverse action against individuals); and content you submit that infringes another's rights — except to the extent a claim results from our own breach of these terms or of applicable data-protection law.

16. Suspension & termination

17. Changes to these terms

We may update these terms and this Privacy Notice. Material changes will be notified — by email to account holders, or by prominent notice in the Service — at least 14 days before they take effect, and the version and effective date above will change. Continued use after the effective date is acceptance. If a change requires fresh consent under applicable law (for example, a new use of identifiable data), we will ask for it rather than assume it.

18. Governing law & disputes

These terms are governed by the laws of the Republic of South Africa, and the Western Cape Division of the High Court of South Africa, Cape Town has non-exclusive jurisdiction, without depriving consumers of mandatory protections or forum rights granted by the law of their country of residence. Nothing in this section limits your right to complain to a data-protection authority (sections 8.2 and 9).

19. Contact

Privacy requests and questions: privacy@iteamformyteam.com
General support: support@iteamformyteam.com
Postal: Beyond The Gap Proprietary Limited, 11 Tintagel Road, West Beach, Milnerton, Western Cape, 7441, South Africa (for the attention of the Information Officer)

When you contact us about a privacy right, we may need to verify your identity before acting; for Session Responses, remember that we deliberately cannot link anonymous Responses back to you (7.2) — which also means we cannot retrieve or delete "your" individual Response from within a team's anonymous data set.