Privacy Policy
Last updated: 24 July 2026
Privacy Policy:
1. Who we are
TopLeader s.r.o. is a company incorporated under the laws of the Czech Republic, with its registered office at Kolodějská 82, 250 84 Sibřina – Stupice, Czech Republic, Company ID No. 19930003 (“TopLeader”, “we”, “us” or “our”).
You can contact us regarding privacy and personal data at:
This Privacy Policy explains how we collect, use, disclose and protect personal data in connection with:
-
the TopLeader website;
-
the TopLeader leadership development platform;
-
leadership and talent development programs delivered through the platform;
-
coaching, mentoring, training, facilitation and related expert services;
-
sales, demonstrations, webinars, applications to our expert network and other interactions with TopLeader.
2. Our role under data protection law
TopLeader may process personal data in different roles.
When you visit our website, contact us, request a demonstration, register for a webinar, apply to our expert network or communicate with us directly, TopLeader generally acts as the data controller.
When an organisation invites its employees or other participants to use TopLeader as part of a leadership or talent development program, the organisation generally acts as the data controller and TopLeader acts as its data processor. In those cases, the organisation determines the purposes of the program and the personal data made available to TopLeader.
TopLeader may separately act as a controller for limited operational purposes such as account security, billing, compliance with legal obligations, prevention of misuse and the management of its contractual relationships.
3. Personal data we collect
Depending on how you interact with us, we may process the following categories of personal data.
Contact and identification data
-
name and surname;
-
professional email address;
-
telephone number;
-
employer, job title and professional role;
-
country, language and time zone;
-
LinkedIn or other professional profile.
Account and profile data
-
account identifier and login information;
-
profile photograph, where provided;
-
organisation and program membership;
-
role and access permissions;
-
language and communication preferences.
Program and development data
Depending on the program configuration, this may include:
-
development priorities and goals;
-
program milestones and checkpoints;
-
participation and activation status;
-
completion of weekly activities;
-
self-assessments and feedback;
-
session allocation, booking and attendance status;
-
learning resources viewed or completed;
-
areas where follow-up may be required.
Private reflections, coaching or mentoring notes, the content of individual sessions and confidential conversations between participants and experts are not included in sponsor reporting unless the participant explicitly chooses to share specific information.
Communications and support data
-
emails and messages sent to TopLeader;
-
support requests;
-
scheduling information;
-
information provided during sales conversations, demonstrations or onboarding;
-
correspondence relating to expert applications.
Technical and usage data
-
IP address;
-
browser, operating system and device information;
-
login and authentication events;
-
page views and platform activity;
-
error logs and security logs;
-
cookie identifiers and analytics data, subject to your cookie choices.
Billing and contractual data
-
company and billing information;
-
invoicing and payment records;
-
contract and order information;
-
records required to comply with tax, accounting and legal obligations.
4. Why we use personal data
We process personal data for the following purposes and legal bases.
Providing the platform and services
We use personal data to create accounts, operate programs, enable weekly practice, provide learning resources, coordinate expert support, manage sessions and provide customer support.
The legal basis is performance of a contract, taking steps prior to entering into a contract, or processing on behalf of a customer under a data processing agreement.
Managing programs and sponsor reporting
We process agreed program signals such as activation, participation, milestones, weekly activity completion and session status so that authorised program sponsors can understand whether a program is progressing and where follow-up may be needed.
Private development content is kept separate from sponsor reporting.
Security and prevention of misuse
We process technical, authentication and usage data to protect accounts, investigate incidents, prevent misuse and maintain the security and reliability of the platform.
The legal basis is our legitimate interest in operating a secure and reliable service and, where applicable, compliance with legal obligations.
Communication, sales and customer relationships
We use contact and communication data to respond to enquiries, arrange demonstrations, prepare proposals, manage customer relationships and provide requested information.
The legal basis is taking steps at your request prior to entering into a contract, performance of a contract or our legitimate interest in managing business relationships.
Expert applications and network management
We process information submitted by coaches, mentors, trainers and facilitators to assess their application, communicate about potential opportunities and manage the TopLeader expert network.
The legal basis is taking steps at the applicant’s request, performance of a contract or our legitimate interest in maintaining an appropriate expert network.
Marketing
We may send information about TopLeader services, webinars and relevant content where you have consented or where permitted by applicable law on the basis of an existing business relationship or legitimate interest.
You can unsubscribe at any time.
Legal and administrative purposes
We process personal data where necessary to comply with accounting, tax, regulatory and other legal obligations, establish or defend legal claims, or respond to lawful requests from public authorities.
5. What program sponsors can see
Authorised customer administrators and program sponsors may see agreed program-level information such as:
-
whether a participant has activated their account;
-
participation and completion status;
-
progress against program milestones;
-
completion of agreed weekly actions;
-
session booking and attendance status, where applicable;
-
upcoming checkpoints and areas where follow-up may be needed.
Unless expressly agreed otherwise and communicated to participants, sponsor reporting does not include:
-
private reflections;
-
coaching or mentoring notes;
-
the content of individual sessions;
-
confidential conversations with an expert;
-
private messages not intended for the sponsor.
The reporting boundary should be communicated to participants before the program begins.
6. Artificial intelligence features
Some TopLeader features may use artificial intelligence to generate or recommend content such as weekly practice suggestions, learning recommendations, summaries or draft development prompts.
Relevant inputs may be processed by specialised AI service providers acting on behalf of TopLeader. We apply data minimisation and contractual safeguards and limit the information sent to what is reasonably necessary for the requested function.
TopLeader does not use Customer Personal Data to train publicly available or general-purpose AI models.
Users should not enter highly sensitive, confidential or special-category personal data into AI-enabled fields unless this has been expressly authorised within their organisation’s program.
AI-generated content is intended to support development and reflection. It may be incomplete or inaccurate and should be reviewed by the user. TopLeader does not use AI features to make solely automated decisions that produce legal or similarly significant effects concerning an individual.
Further information is available in our AI Transparency notice.
7. Who we share personal data with
We may disclose personal data only where necessary to:
-
cloud hosting and infrastructure providers;
-
authentication, security and monitoring providers;
-
email, communication and customer-support providers;
-
website, analytics and cookie-management providers;
-
scheduling, webinar and event providers;
-
AI service providers;
-
coaches, mentors, trainers or facilitators involved in the relevant program;
-
authorised customer representatives and program administrators;
-
professional advisers, auditors or insurers;
-
public authorities where disclosure is required by law.
Service providers may process personal data only for the agreed purposes and are subject to appropriate confidentiality and data protection obligations.
We do not sell personal data.
8. International data transfers
We aim to process personal data within the European Economic Area wherever reasonably possible.
Where personal data is transferred outside the EEA, we use an applicable legal transfer mechanism, such as:
-
an adequacy decision adopted by the European Commission;
-
the European Commission’s Standard Contractual Clauses;
-
another safeguard permitted by applicable data protection law.
Further information about relevant transfer safeguards is available on request.
9. Security
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include, as appropriate:
-
access controls and role-based permissions;
-
encryption in transit and at rest;
-
authentication and account-security controls;
-
separation of customer data;
-
logging and monitoring;
-
backup and recovery procedures;
-
confidentiality obligations;
-
incident-response procedures;
-
periodic review of security measures.
No system can be guaranteed to be completely secure. Users are responsible for protecting their login credentials and notifying us promptly of suspected unauthorised access.
10. Retention
We retain personal data only for as long as necessary for the purposes described in this Policy.
Customer Personal Data processed on behalf of an organisation is normally retained for the duration of the relevant agreement and deleted or returned in accordance with the applicable agreement and Data Processing Agreement. Unless otherwise agreed or required by law, deletion is completed within six months after termination.
Other retention periods depend on the relevant context:
-
enquiry and sales records are retained while the business relationship remains active and for a reasonable follow-up period;
-
expert applications are retained while the application is being assessed and for a reasonable period for relevant future opportunities;
-
marketing data is retained until consent is withdrawn, the person unsubscribes or the data is no longer required;
-
billing, accounting and contractual records are retained for the periods required by applicable law;
-
security and technical logs are retained for periods reasonably necessary to protect the platform and investigate incidents;
-
cookie data is retained according to the duration stated in the cookie settings.
Data may be retained for longer where required to comply with law, resolve disputes or establish, exercise or defend legal claims.
Anonymous or irreversibly aggregated information may be retained without a fixed time limit.
11. Your rights
Subject to applicable law, you may have the right to:
-
obtain information about the processing of your personal data;
-
request access to your personal data;
-
request correction of inaccurate or incomplete data;
-
request deletion of personal data;
-
request restriction of processing;
-
object to processing based on legitimate interests;
-
withdraw consent at any time;
-
receive certain data in a portable format;
-
object to direct marketing;
-
lodge a complaint with a supervisory authority.
Where TopLeader processes personal data on behalf of your employer or another customer, we may refer your request to that organisation as the relevant controller.
Requests may be sent to info@topleader.io. We may need to verify your identity before responding.
You may also lodge a complaint with the Czech supervisory authority:
Office for Personal Data Protection
Úřad pro ochranu osobních údajů
Prague, Czech Republic
12. Cookies
Our website uses essential cookies required for security and basic operation.
Analytics, advertising or other non-essential cookies are used only in accordance with your cookie choices and applicable law. You can change or withdraw your choices through the cookie settings available on the website.
More information about individual cookies, their providers and duration is available in the cookie settings.
13. Children
TopLeader is a business and professional-development service and is not intended for children. We do not knowingly offer the platform directly to persons under 16 years of age.
14. Changes to this Policy
We may update this Policy to reflect changes in our services, technology, legal obligations or processing activities.
The current version will be published on our website with the date of the latest update. Where required, we will provide additional notice of material changes.
15. Contact
Questions, requests or concerns about privacy may be sent to:
TopLeader s.r.o.
Kolodějská 82
250 84 Sibřina – Stupice
Czech Republic
Company ID No. 19930003
info@topleader.io