1. Who we are
The Core Standard is a trading name of eavolve Ltd (a Lily Shippen business), a company registered in England and Wales under company number 15678513, with its registered office at 62-66 Deansgate, Manchester, M3 2EN. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, eavolve Ltd is the data controller for personal data collected through The Core Standard.
You can contact our data team at hello@thecorestandard.co.uk.
2. What we collect
Candidate data
When a candidate sits a Core Standard assessment, we collect: full name, email address, self-declared role level, submitted responses to scenario modules, time spent per module, and device type and browser metadata. We do not collect IP addresses beyond short-lived session data used for fraud prevention, and we do not record audio or video.
Employer data
When an employer commissions an assessment, we collect: name, email address, company name, billing address, role description, and candidate shortlist details provided to us. Payment processing is handled by Stripe and we do not store full card details on our systems.
Website visitor data
We use privacy-respecting analytics that do not track individuals or set identifying cookies. Aggregated statistics such as page views, referrer domains, and country are collected in anonymised form.
3. Lawful basis for processing
We rely on the following lawful bases under UK GDPR Article 6:
- Consent for candidates who opt in to sit an assessment. Consent is obtained at the start of every assessment and can be withdrawn at any time.
- Contract for employers who commission an assessment. Processing is necessary to deliver the service they have paid for.
- Legitimate interest for fraud prevention, service security, and anonymised benchmarking. We have carried out a Legitimate Interest Assessment and are satisfied the interest is proportionate and does not override individual rights.
4. How we use your data
We use personal data to: deliver the commissioned assessment, generate the candidate report, issue the employer report, respond to enquiries, process payment, and maintain service security. We do not use personal data for marketing without explicit consent, and we do not sell personal data to third parties under any circumstances.
5. AI processing
Scoring of candidate responses is carried out by Anthropic's Claude large language model under an enterprise API agreement. Under that agreement, prompts and responses sent to Claude are not used to train Anthropic's models and are not retained by Anthropic beyond the immediate processing window.
Every AI-generated report is reviewed, adjusted, and signed off by a human expert (Lily Shippen) before delivery. No automated decision with significant effect is made solely by AI.
6. Data retention
We retain assessment data for 12 months from the date of completion. After 12 months, personally identifiable data is deleted and only anonymised benchmark statistics (pillar distributions, module score spreads) are retained for the purposes of calibrating the rubric.
Employer commercial records (invoices, briefing notes) are retained for seven years in line with HMRC record-keeping requirements.
Candidates and employers can request earlier deletion at any time. See section 9.
7. Who we share data with
We share candidate assessment responses with the commissioning employer and with the expert reviewing that assessment. We share necessary operational data with our processors:
- Stripe (payment processing)
- Airtable (submission pipeline and report generation)
- Make.com (automation orchestration)
- Anthropic (AI scoring via Claude API)
- Vercel (website and simulator hosting)
- Fastmail (email correspondence)
Each processor is bound by a data processing agreement and appropriate safeguards. We do not share data with any third party for marketing or research purposes without explicit consent.
8. International transfers
The majority of our processing takes place within the UK and EEA. Where data is transferred outside the UK (for example, to Anthropic in the United States), we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or equivalent safeguards, to ensure an adequate level of protection.
9. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Portability of data in a machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
To exercise any of these rights, email hello@thecorestandard.co.uk. We respond within one calendar month.
10. Cookies
The Core Standard uses only the cookies it needs to run properly. These strictly necessary cookies keep the site and your assessment session working. We do not use advertising, analytics, or cross-site tracking cookies, so there is no cookie banner to manage. Our pages load fonts from Google Fonts, which may record your IP address as part of serving them. If we add analytics in future, we will update this notice and ask for your consent first where the law requires it.
11. Security
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Access to candidate reports is restricted to the commissioning employer and the reviewing expert, enforced by authenticated single-use links. We review our security posture annually and after any incident.
If you believe your data has been compromised, email hello@thecorestandard.co.uk and we will investigate and respond within 72 hours.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to active employers and candidates. The "last updated" date at the top of this page reflects the latest revision.
13. How to contact us
Email hello@thecorestandard.co.uk or write to us at The Core Standard, 62-66 Deansgate, Manchester, M3 2EN.