Skip to content
Operations & Data Protection

Who can see what — and why we don’t show most of it.

You are the controller under the GDPR, we are the processor. This is not a contractual formula but the architecture of the software.

You see

  • everything about your people — it’s your data
  • Your usage, updated daily and itemized
  • every access our support has ever had

We see

  • Totals: seats, minutes, render seconds
  • no names, no matriculation numbers, no content
  • a single case — if you release it
Four Commitments

And where they fit in the product.

Client separation in code — dedicated instance as premium

As a rule, the database separates your data from that of other customers via row-level rules that every query passes through; a guard in the code ensures no table is created without a tenant column. Those who want their own database and provisioning can book the dedicated instance — a university runs this way today.

Support only upon your approval

No operator account with permanent access. You grant access for ONE case, for a maximum of seven days, revocable at any time. Every access is logged in a protocol that you can read.

You issue them, not us

Certificates and diplomas bear your issuer identity on your domain, with your key. We sign nothing. What business does a software company have with a university certificate? None.

Content belongs to you

What we build for you will be delivered as a versioned package — with a checksum to prove what was delivered. After that, it belongs to you, even if you leave.

Technical

Where everything runs.

EU

Application and database in the European Union. Frankfurt for data, Paris for speech recognition.

Encrypted

Transmission end-to-end, storage encrypted, access via row-level rules in the database — not just in the application code.

Second Factor

For every admin interface and every admin action. Not just for viewing.

Questions about data processing? Let’s talk →