Your training compliance relies on sensitive data. We protect it with the highest industry standards.
All your data is stored on servers in the European Union (France and Germany), meeting data sovereignty requirements.
Data encrypted in transit (TLS 1.3) and at rest (AES-256). Your compliance documents and learner data are protected at every step.
Transparent privacy policy, designated DPO, right of access, rectification and erasure. Your data belongs to you.
Daily backups with 30-day retention. Point-in-time recovery available. Your data is never lost.
Redundant infrastructure with 24/7 monitoring. Public status page for transparency. Your courses stay accessible.
No banking data passes through our servers. Stripe is PCI DSS Level 1 certified, the highest industry certification level.
Clear and accessible privacy policy. You know exactly what data we collect and why.
Every data processing is based on explicit consent or a documented legal basis.
You can export all your data at any time from your dashboard.
Complete deletion of your account and all data upon request, within 30 days.
A Data Protection Officer is available for any questions regarding your personal data.
All our subprocessors (Supabase, Vercel, Stripe, Resend) are GDPR compliant and host data in the EU.
PostgreSQL database hosted in EU, with Row Level Security and encryption at rest.
Global CDN with automatic TLS termination and built-in DDoS protection.
PCI DSS Level 1 payments. No banking data on our servers.
Transactional emails with SPF/DKIM/DMARC authentication.
Our team is available to answer all your questions about security and data protection.