How we protect your data, where it lives, and how we work with AI.
Content you send to our AI coach is processed under terms that forbid using it to train AI models. Your learning stays your learning.
All platform data and storage run in Frankfurt, Germany (AWS eu-central-1), in a single region. Apart from the AI-coach flow, nothing leaves the EU, and that flow is safeguarded and disclosed.
We maintain a published privacy policy and a signed Data Processing Agreement, and we support data-subject requests.
Encrypted in transit over TLS 1.2+ (HTTPS) and at rest with AES-256. Secrets and credentials stay server-side and are never exposed to the browser.
There is no open signup. Every account is created by invitation, so we always know exactly who is on the platform.
Learners cannot reach one another's data. Access is role-based with least privilege, enforced at both the application and the data layer.
Security is something we test continuously, not a box we check once.
We run automated security checks every day, probing the platform for weaknesses so we can fix them before they reach production.
Our AI coach is a single, controlled assistant rather than an open, user-steerable agent, which keeps the surface for prompt injection and data exfiltration small. The AI can only ever act on content a learner already has access to.
We monitor our dependencies for known vulnerabilities and patch them promptly. Errors are reported to our team directly, with personal data suppressed.
User actions are recorded, so changes are traceable and we can see who did what. This is operational and security logging, not a tool for monitoring individual learners.
Sign-in is passwordless by default, using secure email links and one-time codes. Two-factor authentication is available, and role-scoped permissions give precise control over who can do what.
Campus is built on a modern, actively maintained technology stack. All data changes are validated server-side, so the integrity of a change never depends on the browser.
Who can see your data, what reaches the AI, and the control you keep over it.
Coaching conversations with Henrik are visible only to the learner. Trainers, leaders, and administrators see learning progress, never the content of a conversation.
Access is role-based and enforced at both the application and the data layer, so people only see what their role allows. Learners cannot reach one another's data, and administrative access to the underlying data is limited to our own team.
You decide what to share with the coach; a sector and a general description of your team are enough. Content is processed under data-processing terms and is never used to train AI models.
We process only what the platform needs to run. You can request export or deletion of personal data, and when a contract ends, data is deleted on a defined schedule.
For reviewers, procurement, and works councils.
Our privacy policy is published in English and German. A signed Data Processing Agreement, the subprocessor list, and our responses to standard security questionnaires are available, and we work with an external Data Protection Officer. For German works councils, we are glad to walk through logging, retention, and confidentiality.




Campus developers Zakir, Ángel and Tom, and Philip (Head of Business Development), are available any time to answer your questions.