Legal

Privacy Policy

How we collect, use, and protect personal data when you use Corsable. Effective June 2026.

1. Introduction and scope

Corsable is a competency-based learning and development platform. This policy applies to the personal data we process when individuals and organisations use our website and product, including frameworks, knowledge gates, voice competency exams, training programs, the AI tutor, and assessment evidence.

Where an organisation deploys Corsable to its workforce, that organisation is typically the controller of its learners' data and Corsable acts as a processor on its instructions. For individual learners using Corsable directly, we act as the controller for that account.

2. Information we collect

Account information

Name, email address, password (stored hashed), job title and seniority where provided, organisation membership, language preference, and similar profile details needed to create and run your account.

Content and materials

Materials you upload or create: competency frameworks, imported PDFs, videos, slides, rubrics, lessons, and program structures, together with any text you enter into the AI tutor or other features.

Usage data

Information about how the product is used, such as pages visited, features accessed, device and browser details, approximate location derived from IP address, and log data used to keep the service secure and reliable.

Exam and assessment records

Records generated by knowledge gates and live AI voice competency exams, including scores, transcripts, rubric outcomes, proctoring and anti-cheat signals, timestamps, and certificates. These form the audit-ready evidence at the heart of the platform.

3. How we use information

4. Legal bases (GDPR)

Where the GDPR applies, we rely on one or more of the following legal bases:

5. Sharing and sub-processors

We do not sell personal data. We share it only as needed to run the service: with the organisation that administers your account, and with vetted service providers who host our infrastructure, deliver AI processing, and support communications and operations on our behalf.

These sub-processors act under contractual obligations to protect the data and process it only on our instructions. We may also disclose information where required by law or to protect the rights and safety of users and the public.

6. Data retention

We retain personal data for as long as an account is active and as needed to provide the service. Assessment and certification evidence may be retained longer where an organisation requires a durable record of competency or where law requires it. When data is no longer needed, we delete or anonymise it. Organisations can configure retention and request deletion within the limits of their own obligations.

7. Security

We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls, and audit logging. Our security programme is being formalised: SOC 2 is in progress and our practices are designed to be GDPR ready. No system can be guaranteed completely secure, and we continue to improve our controls over time.

8. International transfers

Corsable operates across regions, so personal data may be processed in countries other than your own. Where data is transferred internationally, we put appropriate safeguards in place, such as standard contractual clauses, to ensure it remains protected to the standard required by applicable law.

9. Your rights

Subject to applicable law, you may have the right to:

If your account is administered by an organisation, please direct requests to that organisation first; we will assist them as their processor. You can contact us at any time to exercise your rights, and you may lodge a complaint with your local data protection authority.

10. Children

Corsable is intended for use by organisations and adult learners. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can address it.

11. Changes to this policy

We may update this policy as the platform and our practices evolve. When we make material changes, we will revise the effective date and, where appropriate, provide additional notice. Continued use of Corsable after an update means you accept the revised policy.

12. Contact

For any questions about this policy or to exercise your rights, contact us at [email protected]. You may also wish to review our Terms and Security pages.

Questions about your data?

We are happy to walk through how Corsable handles personal data, evidence, and retention for your organisation.