Security and privacy at Campus

How we protect your data, where it lives, and how we work with AI.

  • Never used to train AI
  • EU-hosted in Frankfurt
  • GDPR-ready
  • Encrypted
  • Invite-only

The basics

Never used to train AI

Content you send to our AI coach is processed under terms that forbid using it to train AI models. Your learning stays your learning.

Hosted in the EU

All platform data and storage run in Frankfurt, Germany (AWS eu-central-1), in a single region. Apart from the AI-coach flow, nothing leaves the EU, and that flow is safeguarded and disclosed.

GDPR-ready

We maintain a published privacy policy and a signed Data Processing Agreement, and we support data-subject requests.

Encrypted

Encrypted in transit over TLS 1.2+ (HTTPS) and at rest with AES-256. Secrets and credentials stay server-side and are never exposed to the browser.

A closed platform

There is no open signup. Every account is created by invitation, so we always know exactly who is on the platform.

Access is scoped

Learners cannot reach one another's data. Access is role-based with least privilege, enforced at both the application and the data layer.

How we keep Campus secure

Security is something we test continuously, not a box we check once.

  • Continuous security testing

    We run automated security checks every day, probing the platform for weaknesses so we can fix them before they reach production.

  • Attack prevention by design

    Our AI coach is a single, controlled assistant rather than an open, user-steerable agent, which keeps the surface for prompt injection and data exfiltration small. The AI can only ever act on content a learner already has access to.

  • Dependencies and monitoring

    We monitor our dependencies for known vulnerabilities and patch them promptly. Errors are reported to our team directly, with personal data suppressed.

  • Audit and activity logging

    User actions are recorded, so changes are traceable and we can see who did what. This is operational and security logging, not a tool for monitoring individual learners.

  • Modern authentication

    Sign-in is passwordless by default, using secure email links and one-time codes. Two-factor authentication is available, and role-scoped permissions give precise control over who can do what.

  • A modern, maintained stack

    Campus is built on a modern, actively maintained technology stack. All data changes are validated server-side, so the integrity of a change never depends on the browser.

Privacy and your data

Who can see your data, what reaches the AI, and the control you keep over it.

Your conversations are private

Coaching conversations with Henrik are visible only to the learner. Trainers, leaders, and administrators see learning progress, never the content of a conversation.

Least-privilege access

Access is role-based and enforced at both the application and the data layer, so people only see what their role allows. Learners cannot reach one another's data, and administrative access to the underlying data is limited to our own team.

The AI receives only what it needs

You decide what to share with the coach; a sector and a general description of your team are enough. Content is processed under data-processing terms and is never used to train AI models.

Your data stays in your control

We process only what the platform needs to run. You can request export or deletion of personal data, and when a contract ends, data is deleted on a defined schedule.

More and advanced

For reviewers, procurement, and works councils.

Subprocessors

ProviderWhat it receivesRegionDPAGDPR
Amazon Web ServicesHosting and storage of platform dataFrankfurt, EU
AnthropicContent sent to the AI coach, under safeguards and never used for trainingUnited States
OpenAISearch embeddings of course contentUnited States
ResendRecipient name, email address, and message contentUnited States
SentryTechnical error diagnostics, with personal data suppressedUnited States

Legal and assurance

Our privacy policy is published in English and German. A signed Data Processing Agreement, the subprocessor list, and our responses to standard security questionnaires are available, and we work with an external Data Protection Officer. For German works councils, we are glad to walk through logging, retention, and confidentiality.

ZakirAngelTomPhil

Talk to us

Campus developers Zakir, Ángel and Tom, and Philip (Head of Business Development), are available any time to answer your questions.

Contact us

Frequently asked questions

Is our data used to train AI?
No. Content processed by the AI coach is handled under enterprise terms that prohibit using it for model training. Nothing on Campus feeds an AI training set.
Where is our data stored?
On AWS in Frankfurt, Germany, in a single EU region. The one exception is content you send to the AI coach, processed by Anthropic in the US under Standard Contractual Clauses, never used for training.
Can my manager see my coaching conversations?
No. Coaching conversations are visible only to the learner. Trainers, leaders, and administrators see learning progress, not conversation content.
Can we use Campus without exposing who we are?
Largely, yes. You can describe your context without identifying detail: give a sector instead of a company, and describe teams in general terms. Customers remain responsible for what their learners choose to enter.
Do you have a Data Processing Agreement?
Yes. We maintain a signed Data Processing Agreement alongside a published privacy policy and a subprocessor list.
What about certifications?
We build on infrastructure certified to ISO 27001, SOC 1/2/3, and C5 (AWS). These are our infrastructure provider's certifications; we do not currently hold or claim our own ISO 27001 or SOC 2 certification.