GuideBeam processes sensitive career, personality, and psychometric data. We take that responsibility seriously — with relationship- and role-scoped access, feature-specific AI safeguards, and explicit deployment boundaries.
Our data principles
We document what data we collect, why we use it, and the access and deployment boundaries that apply.
You can grant or revoke a connected practitioner's result access. Institution team access follows active affiliation and role rules agreed for the programme.
We limit data collection and disclosure to stated purposes and authorised recipients. We do not sell personal data.
Consent model
GuideBeam applies different access rules to your own account, connected practitioners, and institution team members. Those differences must be explicit in each institutional pilot.
When you connect with a career practitioner, you choose which assessments and profile sections they can view. You can revoke access at any time.
An active institution team member can access results for students with an active affiliation. That access does not depend on the practitioner-sharing toggle, so the staff scope must be agreed before a pilot.
Affiliation and entitlement changes are recorded in append-only event tables. This is a targeted audit trail, not a claim that every data read is logged.
Your practitioner
Assessment results, career profile
Your institution
Roster and results for active affiliations
Employers
No default access
AI privacy
GuideBeam uses AI for career matching, roadmap generation, and coaching. BeamBuddy, career insights, and career archaeology use a server-side PII scrubber before prompts are sent. Other AI features are reviewed separately and are not covered by a blanket de-identification claim.
Profile and assessment data remains in GuideBeam-managed application storage until a feature needs a defined AI request.
In the named supported flows, known identifiers and common PII patterns are replaced with placeholders before the prompt is sent.
Where a response uses those placeholders, GuideBeam restores the mapped values after the model returns the response.
Before (your data)
After (what AI sees)
This illustrates the server-side scrubber used by the named features. It does not describe every AI call across the product.
Infrastructure
From the network layer to the application layer, security is built in — not bolted on.
GuideBeam is served over HTTPS, and managed service connections use encrypted transport. We do not describe this as end-to-end encryption.
The managed database and hosting platforms provide encryption-at-rest controls for stored data and backups. Provider-specific controls are available during procurement review.
Infrastructure providers publish independent assurance reports. Their certifications do not mean that GuideBeam itself is SOC 2 certified.
Current site authentication uses email/password and Google sign-in. Magic-link and one-time-password flows are configuration options; institutional SAML SSO is not a default capability today.
The shared production service stores primary application data in Singapore. AI and other subprocessors may process data in other regions; regional requirements are scoped before contracting.
Privacy posture
These statements describe the current product and policy posture. They are not security certifications or a substitute for a customer-specific procurement review.
Our privacy policy describes how GuideBeam handles personal information under the Privacy Act 1988 and Australian Privacy Principles framework, including cross-border disclosures.
Users can download a defined JSON export and request a correction. Broader access, portability, or deletion requests can be made through our privacy and support contacts.
Where the Notifiable Data Breaches scheme applies, eligible breaches must be assessed and notified under applicable law. Pilot incident terms are documented during procurement.
Personal-account deletion is configuration-controlled. Retention, backups, legal exceptions, and exit deletion are documented for each institutional pilot.
Common questions
If you have specific security or compliance requirements — especially for institutional deployments — we are happy to discuss them in detail.