What we collect, what we don't, and the rights you have over your data. Written in plain English, with a short answer first and the detail below.
Privacy is a right, not a feature. We engineer the platform to protect user identity and minimise data exposure at every layer, and we publish this page so you can check our claims against reality.
We never sell your data, we never use it to train our AI models, and we collect the minimum required to deliver the service.
Three rules we apply to every product decision that touches customer data.
Every category of data the platform touches, and what we use it for.
| Category | What we do with it |
|---|---|
| Identity data | Name and work email, used solely to authenticate and contact you. |
| Training progress | Lesson completions and risk scores, visible to your administrator and never shared externally. |
| AI data | Each customer's data is isolated. We never train our AI models on your private data. |
| Payment info | Processed via secure bank transfer. We do not store card data on our systems. |
Under GDPR and equivalent frameworks, you have the following rights over data we hold about you. All requests are handled within 24 hours.
To deliver the service, we share the minimum necessary data with these vetted providers under strict Data Processing Agreements.
| Provider | Purpose | Region |
|---|---|---|
| GCP / AWS | Infrastructure and object storage. | EU (Ireland, Germany) |
| Cloudflare | Edge security, WAF, and single sign-on (Zero Trust). | Global edge, EU metadata |
| AWS SES | Transactional email delivery. | EU (Ireland) |
To exercise any of the rights above, or for any privacy question, contact the address below from your work email. Please include enough detail for us to identify the relevant account.