Legal

Privacy Policy

How we collect and use personal data — UK GDPR & EU GDPR.

Version 1.2 — in effect from 28 July 2026. Last updated: 28 July 2026.
Privacy enquiries: support@corganize.com.

1. Who we are

Corganize is operated by Sync Mixing Ltd, a company registered in England and Wales (company number 14325775) with its registered office at Unit A30, Red Scar Industrial Estate, Longridge Road, Preston PR2 5NA, United Kingdom ("Corganize", "we", "us"). We are the controller of the personal data described in this policy, and we are registered with the Information Commissioner's Office (ICO) under registration reference ZB526465.

Contact us about privacy at support@corganize.com or by post at our registered office.

Important — our two roles. This policy covers personal data we process as a controller: data about visitors to our website, prospective customers, and the people who register and administer customer accounts.

Where our business customers upload data about their own staff, clients or contacts into the Corganize platform ("Customer Data"), we process that data as a processor on the customer's behalf and under their instructions — that processing is governed by the Data Processing Schedule in our Terms and Conditions and by the relevant customer's own privacy notice, not by this policy. If your data is in a customer's Corganize account, please contact that customer in the first instance; we will refer any request we receive to them.

2. Personal data we collect

We collect the following categories of personal data:

We do not intentionally collect special category data (such as health data) or data about children through our website or in our own controller activities.

3. How and why we use personal data

The table below sets out the purposes for which we use personal data and our lawful basis under Article 6 UK GDPR / EU GDPR:

PurposeData usedLawful basis
Creating and administering accounts; providing and supporting the platformAccount, usage, communications dataPerformance of a contract (Art. 6(1)(b))
Billing, invoicing and collecting paymentAccount, billing dataPerformance of a contract; legal obligation (tax and accounting records) (Art. 6(1)(b), (c))
Service communications (e.g. security alerts, changes to terms, renewal notices)Account dataPerformance of a contract; legitimate interests
Securing the Services, preventing fraud and abuse, network and information securityAccount, usage dataLegitimate interests (Art. 6(1)(f)); in the UK, network security is also a recognised legitimate interest under the Data (Use and Access) Act 2025
Improving and developing the ServicesUsage data, aggregated where possibleLegitimate interests
Responding to enquiries from prospective customersAccount, communications dataLegitimate interests; steps prior to entering a contract
Establishing, exercising or defending legal claims; complying with law and regulatorsAny of the above as relevantLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights and interests; you can ask us for information about that assessment, and you have the right to object (see section 8).

We do not currently operate a marketing newsletter. If we introduce one, we will only send marketing to business contacts on the basis permitted by law, and every message will contain an unsubscribe link.

4. Who we share personal data with

We share personal data with the following categories of recipients, in each case only to the extent necessary.

Service providers (sub-processors)

The providers below support the delivery of the Services. They act under contracts that restrict how they may use the data. This list also serves as the sub-processor list referred to in Schedule 1 of our Terms and Conditions; we give at least 30 days' notice before adding or replacing a sub-processor.

ProviderPurposeLocation of processing
Hetzner Online GmbHHosting of the application, database and uploaded files; primary off-site backup storageGermany (EU)
rsync.netSecondary off-site backup storage. Backups are encrypted before they leave our servers; this provider stores only encrypted data and holds no decryption key.United States
Resend, Inc.Sending transactional and notification email (invitations, reminders, service messages)United States
Anthropic PBCAI features (content formatting, assistant, question suggestions), where a customer has enabled them. Content sent for processing is not used to train models.United States
OpenAI, L.L.C.Speech-to-text transcription of audio and narrated video uploaded for lesson creation, where a customer has enabled it. Content sent for processing is not used to train models.United States
Cloudflare, Inc.Bot protection on our public sign-up form (Turnstile). No cookies are set by this feature.EU and United States
Google Ireland Ltd / Google LLCOptional single sign-on, where a customer has enabled it. We receive only the name, email address and profile image associated with the account. Also website statistics (Google Analytics) on our public website, only with your consent.EU and United States
Meta Platforms Ireland LtdMeasuring our advertising campaigns (Meta pixel) on our public website and blog, only with your consent.EU and United States

Other recipients

We do not sell personal data, and we do not use it for advertising.

5. International transfers

We are based in the UK, and the application, database and uploaded files are hosted in Germany (EU). Our primary backup storage is also in Germany.

Some of our service providers process personal data outside the UK and EEA, as shown in the table above — in particular our secondary backup provider, our email provider and, where enabled, our AI and single sign-on providers, which process data in the United States. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, such as: UK adequacy regulations or EU adequacy decisions (including, for US recipients, certification under the EU–US Data Privacy Framework and its UK Extension); the UK International Data Transfer Agreement or Addendum; or EU Standard Contractual Clauses, in each case with supplementary measures where needed. Backups transferred outside the EEA are encrypted before transfer with a key held only by us. You can contact us for more information about the safeguards used.

6. How long we keep personal data

DataRetention period
Account dataFor the life of the account. After an account is closed, data is retained for 30 days so that it can be exported or recovered, then permanently deleted from live systems.
Copies held in backupsEncrypted backups are retained for 30 days on a rolling basis, so deleted data is removed from backups within 30 days of deletion from live systems.
Billing and transaction recordsAt least 6 years from the end of the relevant financial year (UK tax and accounting requirements)
Support communications24 months from resolution of the request
Security logs12 months, then automatically deleted
Activity logs90 days, then automatically deleted
Cookie-consent proof3 years (to evidence consent, GDPR Art. 7)

We may keep data for longer where required by law or where reasonably necessary in connection with a legal claim.

7. Security

We maintain appropriate technical and organisational measures to protect personal data, including encryption of traffic in transit (HTTPS/TLS), database-enforced separation between customer accounts, salted password hashing, two-factor authentication for administrative access, scoped and time-limited support access that each customer grants and can revoke, encrypted backups held in three independent locations, and logging of security-relevant events. A fuller description of these measures is set out in Schedule 1 of our Terms and Conditions.

No system is completely secure, and you are responsible for keeping your account credentials confidential. If we become aware of a personal data breach affecting you which is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.

8. Your rights

Under the UK GDPR and, where it applies, the EU GDPR, you have the right to: request access to your personal data; request rectification of inaccurate data; request erasure; restrict processing; data portability; object to processing based on legitimate interests; object at any time to direct marketing (which we will always honour); and withdraw consent at any time where processing is based on consent (without affecting prior processing). You will not usually have to pay a fee, and we will respond within one month (extendable by two further months for complex requests, in which case we will tell you).

To exercise any right, contact support@corganize.com. If your personal data is held in a customer's Corganize account as Customer Data, we will pass your request to that customer, as they are the controller of that data.

9. Complaints

If you are unhappy with how we have handled your personal data, please complain to us first at support@corganize.com — we take complaints seriously, will acknowledge your complaint within 30 days, and will respond without undue delay. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113) or, if you are in the EU/EEA, to your local supervisory authority.

10. Cookies and analytics

By default we use only strictly necessary cookies on our website and platform. For details of what we use and how to control them, see our Cookie Policy.

For baseline visitor statistics we use Umami, a privacy-friendly analytics tool self-hosted on our own server. It uses no cookies, stores no identifier on your device, and does not follow you across other websites; IP addresses are used transiently to distinguish visits and are not stored. We see aggregate statistics only (pages viewed, referrer, browser type, country). Legal basis: our legitimate interest in understanding how our website is used.

In addition, with your consent (given through the cookie banner on our public website and revocable at any time), we use Google Analytics 4 to measure how visitors find and use our public pages, including which campaigns and articles bring them to us. Consent signals are handled via Google Consent Mode v2: if you do not consent, no Analytics cookie is set. If you also allow the marketing category, we use the Meta (Facebook) pixel to measure our advertising campaigns; without that consent the pixel is not loaded and no request is made to Meta. Your consent choice is stored by us in a first-party cookie; no third-party consent platform is involved. Legal basis: your consent (Art. 6(1)(a)).

11. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new "last updated" date and, where the changes are material, notify account holders by email or in-app notice.