Legal
Privacy Policy
Last updated 26 August 2026.
1. Who we are
RGM Academy is operated by Effekt Group Oy, a private limited company registered in Finland, business ID 2713562-6, at Hyvinkää, 05720, Finland. Given the size of the operation we are not required to appoint a Data Protection Officer, and privacy questions come straight to us at hello@rgmacademy.app.
RGM Academy is provided to organizations and to the people they enroll. Individual self-serve sign-ups are closed. This policy covers everyone whose data we handle: people using a seat their employer bought, the small number of individuals who still hold a subscription bought before we closed self-serve sales, newsletter subscribers, and anyone who simply visits the website.
2. Which of us decides what happens to your data
This matters more than it sounds, because it decides who you go to when you want something done. There are two situations and we are in a different role in each.
| Situation | Who decides (controller) | What it means for you |
|---|---|---|
| Your employer bought a seat and enrolled you | Your employer. We act on their instructions (we are the processor) | Ask your employer first about access, correction or deletion. We will help them, and we will pass your request straight to them if you come to us |
| You hold your own subscription, subscribe to the newsletter, contact us, or just browse the site | Effekt Group Oy. We are the controller | Come straight to us. Section 10 sets out your rights and how to use them |
Where we act as a processor, a written data processing agreement with your employer governs what we may do. Any organization can request a copy of it, and the current list of the providers we use, from hello@rgmacademy.app.
Where your details came from. If your employer enrolled you, we did not get your name and work email address from you. We got them from your employer, who gave them to us so we could create your account.
3. What we collect, why, and for how long
We collect only what we need to run the platform. For each type of data, here is what we hold, the legal basis under the GDPR, and how long we keep it.
| Data | Why we hold it (legal basis) | How long |
|---|---|---|
| Account data: your name, your email address, and a securely hashed password | To create and secure your account and sign you in (performance of our contract, or our contract with your employer) | While the account is active, then deleted when it is closed |
| Learning data: lesson progress, points, challenge scores, simulator settings, notes and bookmarks | To deliver the course, show your progress, and issue certificates (contract) | While the account is active |
| Certificate data: the name you type onto a certificate, which module, and the date | To issue a credential you can show to someone else (contract). See section 8 | Until you close your account or ask us to revoke it |
| Billing data: a Stripe customer reference, your plan and its status, and invoices. Never your card number | To take payment and run the subscription (contract), and to keep the records tax law requires (legal obligation) | For the life of the subscription, then as long as Finnish accounting law requires, which is six years |
| AI Strategist inputs: your simulator settings and any text you submit to it | To generate the coaching you asked for (contract) | Sent to our AI provider for that one request. We keep no copy of the text. We do keep a count of how many requests you have made, to apply fair-use limits |
| Communications: emails you send us, support chat messages, and feedback you submit in the app | To reply to you and fix what you reported (legitimate interest in running and improving the service) | Up to two years after the exchange ends, or sooner if you ask |
| Newsletter: your email address and your marketing choice | To send the newsletter you asked for (consent) | Until you unsubscribe or ask us to delete |
| Consent records: what you agreed to, when, and the IP address and browser the request came from | To prove that a marketing consent was genuinely given, which the GDPR requires us to be able to do (legal obligation) | Kept as a record for as long as we could need to rely on it, and reviewed yearly |
| Security data: IP addresses used for rate limiting on sign-in and on the AI feature | To stop abuse and brute-force attempts (legitimate interest in keeping the platform secure) | Cleared on a rolling basis |
| Technical and analytics data: pages viewed, device and browser, approximate location, page-speed measurements | To understand how the site is used and keep it fast (consent, through the cookie choice in section 6) | Up to 14 months in Google Analytics. Nothing at all if you decline |
| Error reports: technical diagnostics when something breaks, which can include your account identifier | To find and fix faults (legitimate interest in a working service) | 90 days |
We do not sell your personal data, we do not use it to build advertising profiles, and we do not make any decision about you by automated means that has a legal or similarly significant effect.
We do not use your data, or anything you type into the AI feature, to train artificial intelligence models. Our AI provider is contractually bound not to train its models on what we send it.
4. Who we share data with
We use a small set of providers to run the platform. Each one receives only what it needs. The three marked as needing your permission do not receive anything at all unless you have said yes in the cookie choice.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, sign-in, storage | Name, email, hashed password, all learning data | EU (Stockholm) |
| Vercel | Hosting and content delivery | Technical request data including IP address | EU and US |
| Stripe | Subscription payments | Email, and the payment details you enter with Stripe directly | EU and US |
| Anthropic | Powers the AI RGM Strategist | Your simulator settings and any text you submit. No name, no email, no account identifier | US |
| Resend | Sends account and service emails | Your email address | EU and US |
| Sentry | Error monitoring | Technical error data, which can include your account identifier. Configured not to collect personal data or record what you type | EU |
| Beehiiv | Sends the newsletter, only if you opted in | Your email address | US |
| Google Analytics (needs your permission) | Site usage analytics | Pseudonymous usage and device data, and the pages you view | EU and US |
| Vercel Speed Insights (needs your permission) | Measures how fast pages load for real visitors | Page-speed measurements and a device identifier | EU and US |
| Crisp (needs your permission) | Live chat support | What you type in chat and basic contact details | EU (France) |
We will also disclose data where the law requires it, and to a buyer if the business is ever sold, in which case this policy continues to apply until you are told otherwise.
5. What your employer can see, if your employer bought your seat
Today, nobody at your employer can see your individual progress through RGM Academy. There is no manager view in the product yet.
We are building one, and here is what it will and will not do, so you know before it arrives. It reports on progress: which lessons have been completed and how far through the course someone is. It is not a performance assessment, and it is not designed to rank people.
6. Cookies, and the choice you get
Nothing beyond the strictly necessary runs until you say yes. The first time you visit, we ask. Until you answer, and if you decline, no analytics, no page-speed measurement, no newsletter attribution and no live chat is loaded at all. You can change your mind at any time with . The same control sits in the footer of every public page, and in your account settings once you are signed in.
| What | Group | Purpose | Lifetime |
|---|---|---|---|
| sb-[project]-auth-token | Strictly necessary | Keeps you signed in | Session, refreshed while you stay signed in |
| rgma.cookie-consent.v1 (stored in your browser, not a cookie) | Strictly necessary | Remembers this choice so we stop asking. It never leaves your device | Until you clear it or change it |
| _ga, _ga_[id] | Measurement | Google Analytics: tells return visits apart | Up to 2 years |
| Vercel Speed Insights identifier | Measurement | Groups page-speed measurements from one device | Session |
| crisp-client cookies | Live chat | Keeps your chat conversation together between pages | Up to 6 months |
If you withdraw permission, we delete the cookies we can reach from your browser and reload the page so nothing further loads. Anything a provider already holds is theirs to delete, and section 10 tells you how to ask.
7. International transfers
Your account and learning data are stored in the EU. Some providers in the table above are based in the United States, and where data reaches them we rely on the European Commission's Standard Contractual Clauses, together with each provider's own certification under the EU-US Data Privacy Framework where they hold one. You can ask us for details of the safeguards that apply to any particular provider.
8. Your certificate is published, by your choice
When you complete a module or the course, you can choose to issue yourself a certificate. If you do, we create a page at a web address containing a long random code. That page shows your name, which certificate it is, and the date, and nothing else. Your email address, your scores and your account identifier are not on it and are never served from it.
The page is reachable by anyone who has the address, which is the whole point: it is how someone you show it to can confirm the certificate is genuine. The address cannot be guessed, we tell search engines not to index it, and issuing the certificate in the first place is entirely your decision. If you want it taken down, email us and we will remove it. Closing your account removes it too.
9. Deleting your account, and what survives
You can delete your account yourself from your account settings. Deletion removes your profile, your name, your email address, your progress, your notes and bookmarks, your challenge scores, your certificates and their public pages, and it unsubscribes you from the newsletter.
Two things survive, and you should know what they are. Invoices and payment records are kept because Finnish accounting law requires it, for six years, and they are not used for anything else. Records of marketing consent are kept as evidence that the consent and the withdrawal both happened, because we have to be able to show that. Everything else goes.
If your employer bought your seat, closing your account is normally your employer's decision rather than ours, because it is their licence. Tell us anyway and we will make sure it is handled.
10. Your rights, and how to use them
Under the GDPR you have the right to get a copy of your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time without that affecting what happened before you withdrew it.
- The quickest routes. Change your name in your account settings. Delete everything from your account settings. Turn marketing off in your account, or use the unsubscribe link in any newsletter. Change your cookie choice with .
- For anything else, email hello@rgmacademy.app. We reply within one month, which is the deadline the GDPR sets, and normally much sooner. We may ask you to confirm who you are before we act, so that nobody else can use your rights against you.
- If your employer enrolled you, send access, correction and erasure requests to your employer, because it is their decision to make. If you send one to us we will pass it straight to them and tell you we have.
If you think we have handled your data wrongly, please tell us first and give us a chance to fix it. You can also complain to the Office of the Data Protection Ombudsman (tietosuoja.fi), the Finnish supervisory authority, or to the data protection authority in the country where you live or work.
11. How we protect it
Data is encrypted in transit. Passwords are hashed and we never see them. Every table holding personal data is protected at the database level so one account cannot read another's rows, and the keys that could bypass that protection exist only on the server and never reach your browser. Card details are handled by Stripe and never touch our systems. Error monitoring is configured not to collect personal data or record what you type. Access to production data is limited to the people who need it, which today is one person.
No system is perfectly secure. If a breach affects your data and the law requires it, we will tell the supervisory authority within 72 hours and tell you without undue delay.
12. Children
RGM Academy is built for working professionals and is not intended for anyone under 16. We do not knowingly collect data from children, and we delete it if we find we have.
13. Changes to this policy
We may update this policy as the platform changes. The date at the top always shows when the text last changed, we tell account holders about material changes, and where a change means we would be doing something new with data you consented to, we ask you again rather than assume.
14. Contact
For any privacy question, to exercise your rights, or to request our data processing agreement, email hello@rgmacademy.app. You can also read our Terms of Service.
Last updated 26 August 2026. Effekt Group Oy, business ID 2713562-6, Hyvinkää, 05720, Finland.