OWIlabs

Data & Security

People told us something. Here is how we hold it.

How engagement data is collected, aggregated, protected and deleted, and the ten ethics lines that govern what a model is allowed to do with it.

Why this page exists

Trust is a design question before it is a legal one.

Our Principles page sets out what we owe the companies and the people we work with. This page is the layer underneath it: how engagement data moves, what protects it, and the rules a model has to satisfy before it is allowed to produce a report.

We describe what is built rather than what we hope to build later. Where your procurement, security or legal team needs an answer specific to your organization, a person gives it to you in writing.

Read our Principles

Data lifecycle

What happens to what people tell us.

01

Stated purpose, then consent

Before a conversation starts, the person is told who we are, who commissioned the work, and what it is for. It is not a performance review, and nobody is carried past that point without agreeing to continue.

02

A reference, not a name

Booking a conversation takes a work email and a phone number, entered by the person themselves and used to arrange the time and nothing else. Those details do not travel with the answers: what enters the analysis carries a reference rather than a person, and no profile, score or dossier is built for a named individual.

03

Aggregated before it is delivered

What leadership receives is structure and pattern with the evidence behind it. Recordings, transcripts and individual answers are not handed to the employer, and findings that could only describe one person do not ship.

04

Kept only as long as it is needed

Engagement data is kept for as long as the engagement requires and no longer. You can ask us to delete it, and we confirm in writing what was removed.

Safeguards

The controls around the data.

The short version of how engagement data is protected, in the terms a security review asks for. If your team needs the longer version, ask and we will write it out.

These are the standards our handling is built to, not a certification claim. We would rather tell you what exists and what is still on our list.

01

Encrypted in transit and at rest

Engagement data is encrypted while it moves and while it is stored.

02

Reachable only by the delivery team

Access is limited to the people delivering your engagement, through named accounts rather than a shared credential.

03

Collected to the minimum

We take what an engagement needs and nothing more: the contact details a person enters to book their conversation, and what they choose to say in it. No keystrokes, no access to inboxes or calendar accounts, no monitoring of activity.

04

Never reused for another client

Data gathered for one client is never used to train a model for another, and we never sell data to anyone.

05

No individual attribution

We do not surface individual attribution and we do not enable performance surveillance. What we produce is structural, about the organization rather than the people inside it.

06

Built to Loi 25, PIPEDA and GDPR standards

Those standards shape the handling from the first conversation onward, and requests to access, correct or delete personal data go to info@owilabs.com.

AI ethics manifesto

Ten lines that govern the model.

Security is what keeps the data safe. These ten lines decide what the model is allowed to do with it, and they constrain design decisions already made inside OWI.

01

We model organizations, not people.

The map represents structure: how work moves, where decisions actually get made, where ownership sits. Individual employees are the source of that picture, and no profile, score, or dossier is ever built for a named person. If a finding can only be stated about one individual, it does not enter the model.

02

Workforce intelligence is not surveillance.

OWI does not read keystrokes, does not connect to inboxes or calendar accounts, and does not track activity as it happens. What a person gives us before a conversation is the contact details they enter themselves to book a time. What feeds the model is one anonymous 30 minute interview per person, in English or French, taken on their own schedule and with the purpose stated up front, and the answers are aggregated before anyone at the client organization sees them. Continuous monitoring of individuals is a different category of tool, and it is not what we build.

03

Transparent logic, not black-box authority.

Every pattern and every recommendation in a report traces back to a rule or a piece of evidence we can state in plain language. If a finding cannot be walked through step by step with the client reading it, it does not ship. A model nobody can interrogate is not intelligence, it is an opinion in a confident font.

04

Computational models are representations, not reality.

We hold the map to one standard: the most accurate account of how the organization actually works that the evidence will support, built from what the people inside it said rather than from an org chart or a process diagram. A representation earns its authority by showing its work, not by claiming to be the thing itself. Where a reading is uncertain or the evidence behind it is thin, the report says so instead of rounding up to look more finished.

05

Human decisions require human accountability.

OWI's outputs inform decisions, they do not make them. No workflow we build lets an automated output trigger a consequential move on its own. A reorg, a role change, a headcount decision: a person reads the evidence, decides, and owns the call. The model can put the evidence on the table. It cannot be the one held responsible for what is done with it.

06

Bias is structural before it is algorithmic.

Before any pattern detection runs, we look at who was and was not in the conversation, and whether the questions were weighted toward one part of the organization. A model built on a skewed sample reproduces that skew no matter how careful the analysis downstream is, so which parts of the organization took part, and which did not, is reported in the deliverable rather than left as a footnote to it.

07

Data governance is non-negotiable.

We collect what an engagement needs and nothing more, encrypted in transit and at rest, kept only as long as the engagement requires, and reachable only by the people delivering it. Built to Loi 25, PIPEDA, and GDPR standards from the first conversation onward. Data gathered for one client is never used to train a model for another.

08

Simulation does not imply endorsement.

Modeling a scenario shows what that scenario would produce. It is not a recommendation to pursue it. An AI adoption path, a restructuring option, a merger sequence: we simulate options precisely so a leader can see which ones are bad ideas before committing to one. Showing where a path leads and arguing for it are different acts, and the report is written to keep them apart.

09

The asymmetry of power demands active responsibility.

The people whose day to day work we study rarely hold the leverage the leaders commissioning the study do. That imbalance means the duty to protect them does not stop at consent. It runs through aggregation thresholds, anonymization by design, and turning down engagements built to identify individuals rather than understand structure.

10

We submit our systems to scrutiny.

We treat our own methodology as something to be checked, not trusted by default. A client can ask how any specific finding was derived and get the derivation. Outside review of our anonymization and bias controls is welcomed rather than resisted. A manifesto that cannot be questioned is not an ethics practice, it is a marketing page, and this is meant to be the former.

Questions we get asked

What procurement and legal ask first.

Who at our company can see individual answers?

Nobody. Leadership receives aggregated findings: structure, patterns and the evidence behind them. Recordings, transcripts and individual answers stay with us.

Where is our data held, and who else touches it?

OWI Labs is based in Montreal, Quebec, and runs its own infrastructure. For a given engagement we confirm in writing where the data is held and which categories of provider are involved, under NDA if you prefer.

How long do you keep it, and can we have it deleted?

Only as long as the engagement requires. You can ask us to delete engagement data at any time by writing to info@owilabs.com, and we tell you what was removed.

Do you train AI on our data?

Not for anyone else. What one client entrusts to us is never used to build a model for another client, and it is never sold to anyone.

Can a participant stop partway through?

Yes. The purpose is stated at the start, participation is a choice, and a person can end the conversation whenever they want without giving a reason.

Can we see how a finding was produced?

Yes. Every pattern traces back to a rule or a piece of evidence we can state in plain language, and we will walk through any specific finding with the people reading it.

Living up to it

Ask us how a finding was derived.

These ten lines are worth something only if you can push on them. If you want to see how a specific pattern in your report was produced, or you think an engagement should have been declined under principle nine, that conversation is open.

Talk to us

A clearer picture. A better next move.

Change begins
with understanding.