Privacy Policy
Last updated September 8, 2026
Effective date: 8 September 2026 | Last updated: 8 September 2026
This Privacy Policy explains how Zentrum24 LLC ("Zentrum24 Academy," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the Zentrum24 Academy compliance-training platform (the "Service") — a multi-tenant SaaS learning management system for regulated pharmaceutical and life-sciences (GxP) workforces. It also describes the rights available to individuals under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and comparable laws.
Please read this Policy together with our Cookie Policy, our Sub-processors page, and — for customers — the Data Processing Addendum ("DPA") that forms part of our customer agreement. If any term of the DPA conflicts with this Policy with respect to Customer Training Data (defined below), the DPA controls.
1. Who we are & our roles (controller vs. processor)
Zentrum24 LLC is the entity responsible for the Service.
- Registered entity: Zentrum24 LLC
- Registered address: 1621 Central Ave, Cheyenne, Wyoming 82001, USA
- Privacy / DPO contact: contact@zentrum24.com
- EU / UK representative (if applicable under Art. 27 GDPR): Not currently appointed.
Our role under data-protection law depends on the category of data:
- Zentrum24 Academy acts as a processor (a "service provider" under CCPA/CPRA) for Customer Training Data. When an organization ("Customer" — typically an employer) subscribes to the Service and uploads or generates training data about its own workforce, the Customer is the controller and determines the purposes and means of processing. Zentrum24 Academy processes that data only on the Customer's documented instructions, as set out in the customer agreement and DPA. "Customer Training Data" includes learner identities, role-based training assignments, course completions, quiz scores, 21 CFR Part 11 electronic signatures, completion certificates, and the related tamper-evident audit records.
- Zentrum24 Academy acts as a controller (a "business" under CCPA/CPRA) for Account and Billing Data and for data we use to operate, secure, and improve the Service. This includes the Customer's account and subscription information, the contact details of administrators and other account contacts, billing records, and our own security, operational, and diagnostic logs. For this data, Zentrum24 Academy determines the purposes and means and is directly responsible to the individuals concerned.
End users (learners), please note: if you use Zentrum24 Academy because your employer or another organization gave you access, that organization — not Zentrum24 Academy — is the controller of your training records. Questions about how your employer uses your data, and most requests to access or delete training records, should be directed to that organization. See Section 9 (Your rights).
2. What data we collect
2.1 Account data (Zentrum24 Academy as controller)
- Organization / tenant details: organization name, subscription plan and tier, and configuration settings.
- Administrator and account-contact details: full name, work email address, and role.
2.2 User personal data (as processor for Customers; as controller for admins/contacts we deal with directly)
- Full name, work email address, and optional employee ID.
- Assigned RBAC role (tenant admin, author, manager, or learner) and manager/reporting relationships.
- Authentication data: hashed passwords (bcrypt), multi-factor authentication (TOTP) secrets and backup codes, and — where enabled — SSO/SCIM identifiers. Secrets are stored using KMS-style envelope encryption; we do not store passwords in plain text.
2.3 Training records (Customer Training Data — Zentrum24 Academy as processor)
- Course and curriculum assignments, due dates, and recertification schedules.
- SCORM course progress, quiz attempts and scores, and completion status.
- 21 CFR Part 11 electronic signatures (signer identity, meaning of signature, timestamp) and generated PDF/A completion certificates.
2.4 Billing data (Zentrum24 Academy as controller)
- Subscription plan, billing cycle, invoices, and payment status. Payment card details are collected and processed directly by Stripe, Inc.; Zentrum24 Academy does not store full card numbers.
2.5 Audit, security, and technical data (Zentrum24 Academy as controller for security/operations; reflected into Customer audit trails as processor)
- Tamper-evident, hash-chained audit-log entries recording security- and compliance-relevant events.
- IP address, user-agent/browser information, timestamps, session activity, and rate-limiting counters.
- Diagnostic and error data used to detect and resolve platform errors.
We do not intentionally collect special-category (sensitive) personal data through the Service. Please do not upload health, biometric, or other sensitive data into free-text fields unless expressly agreed with us in writing.
3. How and why we use data, and our legal bases
Where Zentrum24 Academy is a processor, we use Customer Training Data only to provide the Service on the Customer's instructions; the Customer is responsible for establishing the legal basis for its own processing (typically its legitimate interests in workforce training and its legal/regulatory obligations under GxP frameworks). Where Zentrum24 Academy is a controller, we rely on the following legal bases under GDPR/UK GDPR:
- To provide, administer, and secure the Service — including authentication, RBAC, MFA, tenant isolation, rate limiting, and audit logging. Legal basis: performance of a contract (Art. 6(1)(b)) with the Customer, and our legitimate interests (Art. 6(1)(f)) in operating a secure, reliable platform.
- To process billing and subscriptions — invoicing, payment reconciliation, and plan enforcement via Stripe. Legal basis: performance of a contract; compliance with legal obligations (Art. 6(1)(c)), e.g., tax and accounting; and legitimate interests in collecting amounts due.
- To secure the platform and prevent abuse — monitoring, intrusion detection, account-lockout, and integrity verification of the audit chain. Legal basis: legitimate interests in security and fraud prevention; compliance with legal obligations.
- To support customers and communicate service messages — responding to requests and sending operational notices (e.g., security or availability notifications). Legal basis: performance of a contract; legitimate interests.
- To improve and maintain the Service — aggregated diagnostics and troubleshooting. Legal basis: legitimate interests, balanced against your rights; we minimize and, where feasible, aggregate or de-identify.
- To meet our own legal, regulatory, and compliance obligations and to establish, exercise, or defend legal claims. Legal basis: legal obligation; legitimate interests.
- Optional analytics cookies and any marketing communications where applicable. Legal basis: consent (Art. 6(1)(a)), which you may withdraw at any time.
Under CCPA/CPRA, the "business or commercial purposes" for which we use personal information map to the uses above. Zentrum24 Academy does not "sell" personal information and does not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use sensitive personal information for purposes requiring a right to limit.
4. Cookies and similar technologies
The Service uses a strictly necessary, essential session cookie — a stateless JWT stored in an httpOnly cookie — to keep you signed in, enforce idle timeout, and protect against cross-site request forgery. This cookie is required for the Service to function and is not used for advertising.
Where enabled, we may also use optional analytics to understand usage and improve the Service; these are set only with your consent where required. You can accept or decline non-essential cookies, and withdraw consent at any time, via our cookie controls. For the full list of cookies, their purposes, durations, and how to manage them, see our Cookie Policy.
5. Sharing and sub-processors
We do not sell personal data. We disclose personal data only as described here:
- To the relevant Customer (controller): a learner's training data is accessible to their own organization's administrators and managers within that tenant.
- To sub-processors that help us run the Service under written contracts imposing data-protection obligations at least as protective as this Policy and our DPA. Our current sub-processors include:
- Vercel Inc. — application hosting and content delivery; the United States.
- Supabase — managed PostgreSQL database and private, encrypted object storage; the United States.
- Stripe, Inc. — payment processing and subscription billing; United States.
- Email / SMTP provider — transactional email delivery; a provider has not yet been selected and will be added here before launch.
- For legal and safety reasons: where required to comply with law, valid legal process, or a regulatory request, or to protect the rights, safety, and security of Zentrum24 Academy, our Customers, or others. Where a Customer's data is involved, we will, where legally permitted, notify the Customer.
- In a corporate transaction: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and applicable law.
6. International data transfers
The Service is hosted on Vercel (application hosting) and Supabase (managed PostgreSQL database and object storage), with primary processing in the the United States (AWS us-east-1 (Northern Virginia, United States)). If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border transfer rules, your personal data may be transferred to and processed in the United States or other countries whose laws may differ from those of your jurisdiction.
Where we transfer personal data internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures (such as encryption in transit and at rest). A copy of the relevant transfer mechanism is available on request at contact@zentrum24.com. Our DPA sets out the transfer terms applicable to Customer Training Data.
7. Data retention
For Customer Training Data, Zentrum24 Academy retains data for as long as the Customer's subscription is active and as instructed by the Customer, so that the Customer can meet its own GxP recordkeeping obligations (training records, e-signatures, certificates, and audit trails often must be retained for extended periods under 21 CFR Part 11, EU Annex 11, and related requirements). On termination, we return or delete Customer Training Data in accordance with the DPA, subject to any legal retention requirements.
For Account, Billing, and security data where we are the controller, we retain data for the duration of the customer relationship and thereafter only as long as necessary for the purposes described in this Policy — for example, to meet tax, accounting, audit, and legal-defense obligations, and to preserve the integrity of the tamper-evident audit chain. Specific retention periods: billing and tax records for seven (7) years; security and audit logs for 24 months; training and examination records for as long as the customer’s own regulatory retention obligations require.
8. How we protect data (security measures)
Zentrum24 Academy applies technical and organizational measures designed to protect personal data, including:
- Hard tenant isolation using PostgreSQL row-level security (RLS) enforced through a non-superuser application role, so one Customer's data cannot be read by another.
- Encryption in transit (TLS) and at rest, including encrypted object storage and an encrypted PostgreSQL database (Supabase).
- Strong authentication: multi-factor authentication (TOTP with backup codes), bcrypt password hashing with configurable complexity, password history, and account lockout on repeated failures.
- Secrets protection: KMS-style envelope encryption for stored MFA and SSO secrets.
- Access control: role-based access control (tenant admin, author, manager, learner) and, on eligible tiers, SAML SSO with SCIM provisioning.
- Session and abuse controls: stateless JWT sessions in
httpOnlycookies with idle timeout, plus per-tenant and per-user rate limiting. - Integrity and accountability: a tamper-evident, hash-chained audit log and 21 CFR Part 11-compliant electronic signatures.
No system can be guaranteed perfectly secure. We maintain incident-response procedures and will notify affected Customers and, where required, supervisory authorities and data subjects of a personal-data breach in accordance with applicable law and the DPA.
9. Your rights
Subject to applicable law, individuals have rights over their personal data, which may include:
- Access — to obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification — to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — to have data deleted in certain circumstances.
- Portability — to receive certain data in a structured, commonly used, machine-readable format.
- Restriction and objection — to limit or object to certain processing, including processing based on legitimate interests.
- Withdraw consent — where processing relies on consent (e.g., optional analytics), at any time, without affecting prior processing.
- CCPA/CPRA rights — to know, delete, and correct personal information, and to non-discrimination for exercising these rights. Because we do not sell or share personal information for cross-context behavioral advertising, and do not use sensitive personal information for purposes requiring it, the rights to opt out of sale/sharing and to limit sensitive-data use do not apply; a request will be honored as such if that ever changes. You may use an authorized agent, and we will verify requests as required by law.
End-user (learner) requests are typically routed through your employer/Customer. For training data, your organization is the controller. If you are a learner and want to exercise rights over your training records, please contact your organization's administrator; if you contact Zentrum24 Academy directly, we will refer or forward your request to the relevant Customer and assist them in responding, as required under our processor obligations. We do not decide the outcome of such requests on the Customer's behalf.
10. How to exercise your rights (including in-app export and deletion)
Where Zentrum24 Academy is the controller (Account, Billing, and admin/contact data), you may exercise your rights by contacting us at contact@zentrum24.com. We will respond within the timeframes required by applicable law (generally one month under GDPR/UK GDPR and 45 days under CCPA/CPRA, extendable where permitted). We may need to verify your identity before acting, and will not discriminate against you for exercising your rights.
The Service also provides self-service tools that Customers and, where enabled, their users can use directly:
- In-app data export: tenant administrators can export training records and audit data (for example, via the Service's data-export and evidence-package features) in machine-readable formats to support access and portability requests.
- Account deletion: administrators can deactivate or delete users and can request deletion of tenant data on termination, subject to the retention rules in Section 7 and the DPA.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data-protection authority) or, in California, to contact the California Privacy Protection Agency or Attorney General. We would appreciate the chance to address your concerns first.
11. Children's data
The Service is a workforce compliance-training tool intended for use by organizations and their personnel. It is not directed to children and is not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data through the Service, please contact us at contact@zentrum24.com and we will take appropriate steps, together with the relevant Customer, to delete it.
12. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Service. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify Customers through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, except where additional consent is required by law.
13. Contact us
For any questions, requests, or complaints about this Policy or our handling of personal data:
- Zentrum24 LLC
- Privacy / Data Protection contact: contact@zentrum24.com
- Postal address: 1621 Central Ave, Cheyenne, Wyoming 82001, USA
- Governing law: State of Wyoming, USA
- EU / UK representative (if applicable): Not currently appointed.
Reminder: bracketed placeholders must be completed and this Policy reviewed by qualified legal counsel before publication.