Legal

Privacy Policy

Version: 1.0  ·  Last Updated: March 20, 2026  ·  Effective Date: March 20, 2026
Contents
  1. Who We Are
  2. What We Collect and Why
  3. Legal Basis for Processing (GDPR)
  4. How We Use Your Data
  5. Third-Party Processors
  6. Retention Periods
  7. Your Rights
  8. International Transfers
  9. Cookies and Tracking
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us

1. Who We Are

Syllabi ("Syllabi," "we," "us," or "our") provides an AI-powered learning management platform that helps organizations create, deliver, and track compliance training and professional development content. Our platform is accessible at syllabi-hsek.polsia.app.

When you use Syllabi, we act as the data controller for your personal data — meaning we determine the purposes and means by which your data is processed. For customers who process their own employees' personal data through our platform, Syllabi acts as a data processor. That relationship is governed by our Data Processing Agreement (DPA).

If you have questions about this policy or how we handle your data, see Section 12 (Contact Us).

2. What We Collect and Why

2.1 Account Data

When you register or join an organization on Syllabi, we collect:

We do not use passwords. Authentication is passwordless via single-use magic links sent to your email.

2.2 Course and Training Content

When your organization generates courses, we store:

Uploaded source documents (PDFs, Word files, PowerPoints) are processed in server memory to generate course content and are discarded immediately after generation — they are never written to disk or stored in our database.

2.3 Learner Activity Data

As learners complete courses, we record:

This data is scoped strictly to your organization and is not shared with or visible to other organizations.

2.4 Authentication and Security Data

2.5 Payment Data

Billing is handled by Stripe, Inc. We do not store your full credit card numbers on our servers. We receive and store your subscription status, plan tier, and Stripe customer ID. For details on how Stripe handles your payment data, see stripe.com/privacy.

2.6 Usage and Analytics Data

We collect lightweight, privacy-respecting analytics using a self-hosted tracker (no third-party cookies). This includes:

No cross-site tracking. No advertising profiles built from this data.

2.7 Compliance Records

For organizations using compliance features, we store signed agreement records (BAA, DPA), compliance settings, and HIPAA-mode configuration. These records include the signing user's name, email, timestamp, and IP address at time of signing.

4. How We Use Your Data

We use your data only to:

🚫 We do not sell your personal data. We do not use your data to train AI models. We do not build advertising profiles. Your organization's training content is never used to improve Syllabi's own models or shared with other customers.

5. Third-Party Processors

We share your data only with the following sub-processors, who are contractually bound to process your data only as directed by us and under appropriate security measures.

Sub-Processor Purpose Data Transferred Location
Render, Inc. Application hosting and compute All application data (processed in memory) United States
Neon, Inc. PostgreSQL managed database All persisted data (encrypted at rest) United States
Anthropic, PBC AI course generation (Claude models) Extracted document text, generation prompts United States
OpenAI, LLC AI course generation (GPT models) Extracted document text, generation prompts United States
Stripe, Inc. Payment processing and subscription management Email, billing name, payment method (tokenized) United States
Postmark (ActiveCampaign, Inc.) Transactional email delivery (magic links) Email address, email content United States
Cloudflare, Inc. CDN, DDoS protection, DNS IP address, request metadata (in transit) United States / Global
GitHub, Inc. Source code repository and CI/CD No personal data United States

Both Anthropic and OpenAI's API terms prohibit using API inputs to train their models. Extracted document text is sent to these APIs only to generate your course content and is not retained by them for training purposes.

Anthropic API policy: Content submitted via the API is not used to train Anthropic's models. anthropic.com/privacy

OpenAI API policy: API inputs and outputs are not used to train OpenAI models by default. openai.com/enterprise-privacy

6. Retention Periods

We retain your data for as long as your account is active or as needed to provide the service. Specific retention periods:

Data Category Retention Period Notes
Account data (email, name) Until account deletion + 30 days 30-day grace period for accidental deletion
Course content and learning paths Until org cancels or deletes content Org admin can delete at any time
Learner completion records Until org cancels or requests deletion HIPAA Mode: 6 years minimum
Audit logs 2 years (standard) HIPAA Mode: 6 years minimum per §164.312(b)
Uploaded source documents Not retained Processed in-memory only; discarded after generation
Payment records 7 years Required by financial regulations
Signed agreements (BAA/DPA) Duration of service + 7 years Required for compliance audit trail
Magic link tokens 15 minutes or until used Single-use; expire immediately on click
Session tokens (JWT) 7 days Invalidated on logout

7. Your Rights

Under GDPR (Articles 15–22), UK GDPR, and similar privacy laws, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at privacy@syllabi-hsek.polsia.app.

7.1 Right of Access (Art. 15)

You have the right to request a copy of the personal data we hold about you, including information about how we use it, who we share it with, and how long we retain it.

7.2 Right to Rectification (Art. 16)

If any personal data we hold about you is inaccurate or incomplete, you can request that we correct it. You can update your name and email directly in your account settings, or contact us for corrections we cannot make ourselves.

7.3 Right to Erasure — "Right to be Forgotten" (Art. 17)

You can request that we delete your personal data. We will honor this request unless we are required to retain data by law (e.g., financial records, HIPAA audit logs) or to fulfill an existing contract. Account deletion removes your personal data and disassociates your activity from your identity.

7.4 Right to Restriction of Processing (Art. 18)

You can request that we restrict processing of your data while a dispute is under review — for example, if you contest the accuracy of data we hold or object to our processing.

7.5 Right to Data Portability (Art. 20)

You can request a machine-readable export of your personal data. Organization admins can export learner completion records, audit logs, and course data from the admin panel. For a personal data export, contact us directly.

7.6 Right to Object (Art. 21)

You can object to processing based on legitimate interests. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.

7.7 Right to Withdraw Consent

Where we rely on your consent to process data (if applicable), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before your withdrawal.

7.8 Right to Lodge a Complaint

If you believe we have mishandled your data, you have the right to lodge a complaint with your local data protection authority. In the EU, you can find your supervisory authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office (ICO).

Response time: We will respond to rights requests within 30 days of receipt. If your request is complex, we may extend this by up to 60 additional days and will notify you of the extension.

8. International Transfers

Syllabi is operated from the United States. All of our sub-processors are based in the United States. If you are located in the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the United States.

We rely on the following transfer mechanisms to ensure an adequate level of protection:

If you are a business customer in the EEA or UK and require a signed Data Processing Agreement for GDPR compliance, you can execute one electronically on our DPA page.

9. Cookies and Tracking

9.1 What We Use

Syllabi uses localStorage (not cookies) to store your authentication token on the client side. We do not use third-party tracking cookies or advertising pixels.

Storage Key Purpose Expires
syllabi_token Stores your JWT authentication token to keep you signed in 7 days (or when you sign out)

9.2 Analytics

We run a self-hosted, privacy-first analytics tracker. It records page paths, referrers, and a one-way hashed (SHA-256) version of your IP address. The raw IP is never stored. No cross-site tracking. No cookies set by our analytics.

9.3 No Third-Party Advertising

We do not run retargeting ads. We do not share your browsing behavior with any advertising platform. There are no Facebook Pixel, Google Ads, or similar trackers on any Syllabi page.

10. Children's Privacy

Syllabi is designed for use by organizations and their employees. Our service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will delete it promptly.

If you believe we have inadvertently collected data from a minor, contact us at privacy@syllabi-hsek.polsia.app.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

Your continued use of Syllabi after a policy update constitutes your acceptance of the revised policy. If a change materially reduces your rights, we will seek fresh consent where required by law.

Previous policy versions are available upon request. Consent records reference the policy version that was in effect at the time of acceptance.

12. Contact Us

For any privacy-related questions, rights requests, or concerns about how we handle your data:

Privacy Contact — Syllabi

Email: privacy@syllabi-hsek.polsia.app

Subject line: Privacy Request — [Your Name / Organization]

For GDPR-specific requests (access, erasure, portability), please include your email address and organization name. We will respond within 30 days.

For EU/UK customers requiring a signed DPA, visit our Data Processing Agreement page.