Legal

Privacy Policy

Last updated 26 August 2026.

1. Who we are

RGM Academy is operated by Effekt Group Oy, a private limited company registered in Finland, business ID 2713562-6, at Hyvinkää, 05720, Finland. Given the size of the operation we are not required to appoint a Data Protection Officer, and privacy questions come straight to us at hello@rgmacademy.app.

RGM Academy is provided to organizations and to the people they enroll. Individual self-serve sign-ups are closed. This policy covers everyone whose data we handle: people using a seat their employer bought, the small number of individuals who still hold a subscription bought before we closed self-serve sales, newsletter subscribers, and anyone who simply visits the website.

2. Which of us decides what happens to your data

This matters more than it sounds, because it decides who you go to when you want something done. There are two situations and we are in a different role in each.

SituationWho decides (controller)What it means for you
Your employer bought a seat and enrolled youYour employer. We act on their instructions (we are the processor)Ask your employer first about access, correction or deletion. We will help them, and we will pass your request straight to them if you come to us
You hold your own subscription, subscribe to the newsletter, contact us, or just browse the siteEffekt Group Oy. We are the controllerCome straight to us. Section 10 sets out your rights and how to use them

Where we act as a processor, a written data processing agreement with your employer governs what we may do. Any organization can request a copy of it, and the current list of the providers we use, from hello@rgmacademy.app.

Where your details came from. If your employer enrolled you, we did not get your name and work email address from you. We got them from your employer, who gave them to us so we could create your account.

3. What we collect, why, and for how long

We collect only what we need to run the platform. For each type of data, here is what we hold, the legal basis under the GDPR, and how long we keep it.

DataWhy we hold it (legal basis)How long
Account data: your name, your email address, and a securely hashed passwordTo create and secure your account and sign you in (performance of our contract, or our contract with your employer)While the account is active, then deleted when it is closed
Learning data: lesson progress, points, challenge scores, simulator settings, notes and bookmarksTo deliver the course, show your progress, and issue certificates (contract)While the account is active
Certificate data: the name you type onto a certificate, which module, and the dateTo issue a credential you can show to someone else (contract). See section 8Until you close your account or ask us to revoke it
Billing data: a Stripe customer reference, your plan and its status, and invoices. Never your card numberTo take payment and run the subscription (contract), and to keep the records tax law requires (legal obligation)For the life of the subscription, then as long as Finnish accounting law requires, which is six years
AI Strategist inputs: your simulator settings and any text you submit to itTo generate the coaching you asked for (contract)Sent to our AI provider for that one request. We keep no copy of the text. We do keep a count of how many requests you have made, to apply fair-use limits
Communications: emails you send us, support chat messages, and feedback you submit in the appTo reply to you and fix what you reported (legitimate interest in running and improving the service)Up to two years after the exchange ends, or sooner if you ask
Newsletter: your email address and your marketing choiceTo send the newsletter you asked for (consent)Until you unsubscribe or ask us to delete
Consent records: what you agreed to, when, and the IP address and browser the request came fromTo prove that a marketing consent was genuinely given, which the GDPR requires us to be able to do (legal obligation)Kept as a record for as long as we could need to rely on it, and reviewed yearly
Security data: IP addresses used for rate limiting on sign-in and on the AI featureTo stop abuse and brute-force attempts (legitimate interest in keeping the platform secure)Cleared on a rolling basis
Technical and analytics data: pages viewed, device and browser, approximate location, page-speed measurementsTo understand how the site is used and keep it fast (consent, through the cookie choice in section 6)Up to 14 months in Google Analytics. Nothing at all if you decline
Error reports: technical diagnostics when something breaks, which can include your account identifierTo find and fix faults (legitimate interest in a working service)90 days

We do not sell your personal data, we do not use it to build advertising profiles, and we do not make any decision about you by automated means that has a legal or similarly significant effect.

We do not use your data, or anything you type into the AI feature, to train artificial intelligence models. Our AI provider is contractually bound not to train its models on what we send it.

4. Who we share data with

We use a small set of providers to run the platform. Each one receives only what it needs. The three marked as needing your permission do not receive anything at all unless you have said yes in the cookie choice.

ProviderWhat it doesWhat it receivesWhere
SupabaseDatabase, sign-in, storageName, email, hashed password, all learning dataEU (Stockholm)
VercelHosting and content deliveryTechnical request data including IP addressEU and US
StripeSubscription paymentsEmail, and the payment details you enter with Stripe directlyEU and US
AnthropicPowers the AI RGM StrategistYour simulator settings and any text you submit. No name, no email, no account identifierUS
ResendSends account and service emailsYour email addressEU and US
SentryError monitoringTechnical error data, which can include your account identifier. Configured not to collect personal data or record what you typeEU
BeehiivSends the newsletter, only if you opted inYour email addressUS
Google Analytics (needs your permission)Site usage analyticsPseudonymous usage and device data, and the pages you viewEU and US
Vercel Speed Insights (needs your permission)Measures how fast pages load for real visitorsPage-speed measurements and a device identifierEU and US
Crisp (needs your permission)Live chat supportWhat you type in chat and basic contact detailsEU (France)

We will also disclose data where the law requires it, and to a buyer if the business is ever sold, in which case this policy continues to apply until you are told otherwise.

5. What your employer can see, if your employer bought your seat

Today, nobody at your employer can see your individual progress through RGM Academy. There is no manager view in the product yet.

We are building one, and here is what it will and will not do, so you know before it arrives. It reports on progress: which lessons have been completed and how far through the course someone is. It is not a performance assessment, and it is not designed to rank people.

An organization can choose aggregate-only reporting, and many will. In that mode a manager sees team-level totals with a minimum number of people behind every figure, so no individual's progress or score can be identified at all. Some countries and some employee representative bodies require exactly this, and we built the option for that reason. Your employer chooses the mode, and your employer is the right person to ask which one applies to you.

6. Cookies, and the choice you get

Nothing beyond the strictly necessary runs until you say yes. The first time you visit, we ask. Until you answer, and if you decline, no analytics, no page-speed measurement, no newsletter attribution and no live chat is loaded at all. You can change your mind at any time with . The same control sits in the footer of every public page, and in your account settings once you are signed in.

WhatGroupPurposeLifetime
sb-[project]-auth-tokenStrictly necessaryKeeps you signed inSession, refreshed while you stay signed in
rgma.cookie-consent.v1 (stored in your browser, not a cookie)Strictly necessaryRemembers this choice so we stop asking. It never leaves your deviceUntil you clear it or change it
_ga, _ga_[id]MeasurementGoogle Analytics: tells return visits apartUp to 2 years
Vercel Speed Insights identifierMeasurementGroups page-speed measurements from one deviceSession
crisp-client cookiesLive chatKeeps your chat conversation together between pagesUp to 6 months

If you withdraw permission, we delete the cookies we can reach from your browser and reload the page so nothing further loads. Anything a provider already holds is theirs to delete, and section 10 tells you how to ask.

7. International transfers

Your account and learning data are stored in the EU. Some providers in the table above are based in the United States, and where data reaches them we rely on the European Commission's Standard Contractual Clauses, together with each provider's own certification under the EU-US Data Privacy Framework where they hold one. You can ask us for details of the safeguards that apply to any particular provider.

8. Your certificate is published, by your choice

When you complete a module or the course, you can choose to issue yourself a certificate. If you do, we create a page at a web address containing a long random code. That page shows your name, which certificate it is, and the date, and nothing else. Your email address, your scores and your account identifier are not on it and are never served from it.

The page is reachable by anyone who has the address, which is the whole point: it is how someone you show it to can confirm the certificate is genuine. The address cannot be guessed, we tell search engines not to index it, and issuing the certificate in the first place is entirely your decision. If you want it taken down, email us and we will remove it. Closing your account removes it too.

9. Deleting your account, and what survives

You can delete your account yourself from your account settings. Deletion removes your profile, your name, your email address, your progress, your notes and bookmarks, your challenge scores, your certificates and their public pages, and it unsubscribes you from the newsletter.

Two things survive, and you should know what they are. Invoices and payment records are kept because Finnish accounting law requires it, for six years, and they are not used for anything else. Records of marketing consent are kept as evidence that the consent and the withdrawal both happened, because we have to be able to show that. Everything else goes.

If your employer bought your seat, closing your account is normally your employer's decision rather than ours, because it is their licence. Tell us anyway and we will make sure it is handled.

10. Your rights, and how to use them

Under the GDPR you have the right to get a copy of your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time without that affecting what happened before you withdrew it.

  • The quickest routes. Change your name in your account settings. Delete everything from your account settings. Turn marketing off in your account, or use the unsubscribe link in any newsletter. Change your cookie choice with .
  • For anything else, email hello@rgmacademy.app. We reply within one month, which is the deadline the GDPR sets, and normally much sooner. We may ask you to confirm who you are before we act, so that nobody else can use your rights against you.
  • If your employer enrolled you, send access, correction and erasure requests to your employer, because it is their decision to make. If you send one to us we will pass it straight to them and tell you we have.

If you think we have handled your data wrongly, please tell us first and give us a chance to fix it. You can also complain to the Office of the Data Protection Ombudsman (tietosuoja.fi), the Finnish supervisory authority, or to the data protection authority in the country where you live or work.

11. How we protect it

Data is encrypted in transit. Passwords are hashed and we never see them. Every table holding personal data is protected at the database level so one account cannot read another's rows, and the keys that could bypass that protection exist only on the server and never reach your browser. Card details are handled by Stripe and never touch our systems. Error monitoring is configured not to collect personal data or record what you type. Access to production data is limited to the people who need it, which today is one person.

No system is perfectly secure. If a breach affects your data and the law requires it, we will tell the supervisory authority within 72 hours and tell you without undue delay.

12. Children

RGM Academy is built for working professionals and is not intended for anyone under 16. We do not knowingly collect data from children, and we delete it if we find we have.

13. Changes to this policy

We may update this policy as the platform changes. The date at the top always shows when the text last changed, we tell account holders about material changes, and where a change means we would be doing something new with data you consented to, we ask you again rather than assume.

14. Contact

For any privacy question, to exercise your rights, or to request our data processing agreement, email hello@rgmacademy.app. You can also read our Terms of Service.

Last updated 26 August 2026. Effekt Group Oy, business ID 2713562-6, Hyvinkää, 05720, Finland.