Security & Data Protection
A public summary of how we protect the service and personal data. Detailed supplier, transfer and control information is provided to authorised customer reviewers on request.
Last updated: August 24, 2026
Security controls
Our controls are selected according to the nature of the service, the data processed and the risks to users and customer organisations.
Access control
Access is limited by role and business need. Team workspaces are logically separated and administrative actions are recorded.
Encryption and credential protection
Data is protected in transit, sensitive credentials are protected at rest, and passwords are stored only in non-recoverable form.
Availability and recovery
Backups, recovery procedures and service monitoring support availability and restoration after an incident.
Secure operation
We use security logging, dependency review, change controls and incident-handling procedures appropriate to the service and its risk.
Data minimisation and deletion
We limit collection to service, security and legal needs and apply retention and deletion rules by data category.
Supplier management
Providers that process personal data are subject to contractual data-protection obligations and are reviewed according to risk.
Data location and transfers
The primary application infrastructure and Academy-controlled storage are located in the European Union. Some specialised providers may process limited data outside the European Economic Area where their service is required.
International transfers use an applicable adequacy decision, the EU-US Data Privacy Framework for participating providers, or Standard Contractual Clauses with supplementary safeguards. See the Privacy Policy for the public notice. Provider-specific transfer information is available on request.
Payments and personal data
Payment-card entry is handled on the payment provider's hosted checkout. We receive the transaction and billing information needed to manage the purchase, but do not store full payment-card numbers.
We do not sell personal data and do not provide personal data to advertising networks. Optional analytics storage is controlled through the cookie banner.
Customer assurance
Team and enterprise customers can request the materials appropriate to their review:
- our Article 28 data processing agreement
- the current subprocessor and international-transfer schedule
- a detailed technical and organisational measures schedule
- a completed security questionnaire and supporting explanations
- reasonable audit assistance as described in the DPA
Detailed materials may be provided under confidentiality to avoid publishing operational information that is not needed by general site visitors.
Data processing agreement
Our public DPA summary explains the controller-processor relationship and Article 28 terms for team workspaces. Email us to receive an execution copy with the current schedules and both parties' details.
Training and certificates
The Academy provides educational content and records completion and assessment results. Academy certificates document activity within this platform; they are not an official qualification issued or endorsed by a standards or accreditation body.
Security and privacy enquiries
For a DPA, processor schedule, transfer information, security questionnaire or vulnerability report, email [email protected].
Please report suspected vulnerabilities privately and allow reasonable time for investigation before public disclosure.