Legal review notice: This data-processing overview is a placeholder and must be reviewed by legal counsel before production use.
1. Roles and Scope
In many deployments, the customer organization will act as controller or equivalent decision-maker for employee training data, while the platform provider may act as processor or service provider. Actual roles depend on the final agreement and applicable law.
2. Categories of Data
Potential categories include account data, department and role metadata, training completion records, quiz results, certificates, simulation outcomes, redacted chat or voice-response metadata, export records, and audit logs.
3. Subprocessors and Infrastructure
Production documentation should identify hosting providers, storage vendors, AI providers where applicable, support systems, and other subprocessors used in the service.
4. Security Measures
Example controls may include role-based access, tenant isolation, protected storage, encryption for sensitive settings, signed access to controlled downloads, and event logging. Final commitments should appear in the governing agreement or security schedule.
5. Retention and Deletion
Retention periods, deletion timing, and return-of-data obligations should be defined according to customer policy, contract, and legal obligations. This placeholder page does not by itself establish a complete DPA.