1. Who we are
Corganize is operated by Sync Mixing Ltd, a company registered in England and Wales (company number 14325775) with its registered office at Unit A30, Red Scar Industrial Estate, Longridge Road, Preston PR2 5NA, United Kingdom ("Corganize", "we", "us"). We are the controller of the personal data described in this policy, and we are registered with the Information Commissioner's Office (ICO) under registration reference ZB526465.
Contact us about privacy at support@corganize.com or by post at our registered office.
Important — our two roles. This policy covers personal data we process as a controller: data about visitors to our website, prospective customers, and the people who register and administer customer accounts.
Where our business customers upload data about their own staff, clients or contacts into the Corganize platform ("Customer Data"), we process that data as a processor on the customer's behalf and under their instructions — that processing is governed by the Data Processing Schedule in our Terms and Conditions and by the relevant customer's own privacy notice, not by this policy. If your data is in a customer's Corganize account, please contact that customer in the first instance; we will refer any request we receive to them.
2. Personal data we collect
We collect the following categories of personal data:
- Account data — name, business email address, role, organisation, profile image, password (stored only as a salted hash), two-factor authentication settings and account preferences, collected when you register or are added as a user.
- Billing data — billing contact details, company details, subscription history and invoice records.
- Usage and device data — log data such as IP address, browser type, pages and features used, timestamps, sign-in and failed sign-in events, and diagnostic data, collected automatically when you use the website or platform.
- Communications data — the content of support requests, emails and other messages you send us.
- Cookie data — data collected through the strictly necessary cookies described in our Cookie Policy.
We do not intentionally collect special category data (such as health data) or data about children through our website or in our own controller activities.
3. How and why we use personal data
The table below sets out the purposes for which we use personal data and our lawful basis under Article 6 UK GDPR / EU GDPR:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and administering accounts; providing and supporting the platform | Account, usage, communications data | Performance of a contract (Art. 6(1)(b)) |
| Billing, invoicing and collecting payment | Account, billing data | Performance of a contract; legal obligation (tax and accounting records) (Art. 6(1)(b), (c)) |
| Service communications (e.g. security alerts, changes to terms, renewal notices) | Account data | Performance of a contract; legitimate interests |
| Securing the Services, preventing fraud and abuse, network and information security | Account, usage data | Legitimate interests (Art. 6(1)(f)); in the UK, network security is also a recognised legitimate interest under the Data (Use and Access) Act 2025 |
| Improving and developing the Services | Usage data, aggregated where possible | Legitimate interests |
| Responding to enquiries from prospective customers | Account, communications data | Legitimate interests; steps prior to entering a contract |
| Establishing, exercising or defending legal claims; complying with law and regulators | Any of the above as relevant | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and interests; you can ask us for information about that assessment, and you have the right to object (see section 8).
We do not currently operate a marketing newsletter. If we introduce one, we will only send marketing to business contacts on the basis permitted by law, and every message will contain an unsubscribe link.
4. Who we share personal data with
We share personal data with the following categories of recipients, in each case only to the extent necessary.
Service providers (sub-processors)
The providers below support the delivery of the Services. They act under contracts that restrict how they may use the data. This list also serves as the sub-processor list referred to in Schedule 1 of our Terms and Conditions; we give at least 30 days' notice before adding or replacing a sub-processor.
| Provider | Purpose | Location of processing |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application, database and uploaded files; primary off-site backup storage | Germany (EU) |
| rsync.net | Secondary off-site backup storage. Backups are encrypted before they leave our servers; this provider stores only encrypted data and holds no decryption key. | United States |
| Resend, Inc. | Sending transactional and notification email (invitations, reminders, service messages) | United States |
| Anthropic PBC | AI features (content formatting, assistant, question suggestions), where a customer has enabled them. Content sent for processing is not used to train models. | United States |
| OpenAI, L.L.C. | Speech-to-text transcription of audio and narrated video uploaded for lesson creation, where a customer has enabled it. Content sent for processing is not used to train models. | United States |
| Cloudflare, Inc. | Bot protection on our public sign-up form (Turnstile). No cookies are set by this feature. | EU and United States |
| Google Ireland Ltd / Google LLC | Optional single sign-on, where a customer has enabled it. We receive only the name, email address and profile image associated with the account. Also website statistics (Google Analytics) on our public website, only with your consent. | EU and United States |
| Meta Platforms Ireland Ltd | Measuring our advertising campaigns (Meta pixel) on our public website and blog, only with your consent. | EU and United States |
Other recipients
- Professional advisers — lawyers, accountants, auditors and insurers where reasonably necessary.
- Authorities — courts, regulators (including the ICO), law enforcement and tax authorities where required by law.
- Business transfers — a purchaser or prospective purchaser in connection with a merger, acquisition or sale of assets, under appropriate confidentiality protections.
We do not sell personal data, and we do not use it for advertising.
5. International transfers
We are based in the UK, and the application, database and uploaded files are hosted in Germany (EU). Our primary backup storage is also in Germany.
Some of our service providers process personal data outside the UK and EEA, as shown in the table above — in particular our secondary backup provider, our email provider and, where enabled, our AI and single sign-on providers, which process data in the United States. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, such as: UK adequacy regulations or EU adequacy decisions (including, for US recipients, certification under the EU–US Data Privacy Framework and its UK Extension); the UK International Data Transfer Agreement or Addendum; or EU Standard Contractual Clauses, in each case with supplementary measures where needed. Backups transferred outside the EEA are encrypted before transfer with a key held only by us. You can contact us for more information about the safeguards used.
6. How long we keep personal data
| Data | Retention period |
|---|---|
| Account data | For the life of the account. After an account is closed, data is retained for 30 days so that it can be exported or recovered, then permanently deleted from live systems. |
| Copies held in backups | Encrypted backups are retained for 30 days on a rolling basis, so deleted data is removed from backups within 30 days of deletion from live systems. |
| Billing and transaction records | At least 6 years from the end of the relevant financial year (UK tax and accounting requirements) |
| Support communications | 24 months from resolution of the request |
| Security logs | 12 months, then automatically deleted |
| Activity logs | 90 days, then automatically deleted |
| Cookie-consent proof | 3 years (to evidence consent, GDPR Art. 7) |
We may keep data for longer where required by law or where reasonably necessary in connection with a legal claim.
7. Security
We maintain appropriate technical and organisational measures to protect personal data, including encryption of traffic in transit (HTTPS/TLS), database-enforced separation between customer accounts, salted password hashing, two-factor authentication for administrative access, scoped and time-limited support access that each customer grants and can revoke, encrypted backups held in three independent locations, and logging of security-relevant events. A fuller description of these measures is set out in Schedule 1 of our Terms and Conditions.
No system is completely secure, and you are responsible for keeping your account credentials confidential. If we become aware of a personal data breach affecting you which is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.
8. Your rights
Under the UK GDPR and, where it applies, the EU GDPR, you have the right to: request access to your personal data; request rectification of inaccurate data; request erasure; restrict processing; data portability; object to processing based on legitimate interests; object at any time to direct marketing (which we will always honour); and withdraw consent at any time where processing is based on consent (without affecting prior processing). You will not usually have to pay a fee, and we will respond within one month (extendable by two further months for complex requests, in which case we will tell you).
To exercise any right, contact support@corganize.com. If your personal data is held in a customer's Corganize account as Customer Data, we will pass your request to that customer, as they are the controller of that data.
9. Complaints
If you are unhappy with how we have handled your personal data, please complain to us first at support@corganize.com — we take complaints seriously, will acknowledge your complaint within 30 days, and will respond without undue delay. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113) or, if you are in the EU/EEA, to your local supervisory authority.
10. Cookies and analytics
By default we use only strictly necessary cookies on our website and platform. For details of what we use and how to control them, see our Cookie Policy.
For baseline visitor statistics we use Umami, a privacy-friendly analytics tool self-hosted on our own server. It uses no cookies, stores no identifier on your device, and does not follow you across other websites; IP addresses are used transiently to distinguish visits and are not stored. We see aggregate statistics only (pages viewed, referrer, browser type, country). Legal basis: our legitimate interest in understanding how our website is used.
In addition, with your consent (given through the cookie banner on our public website and revocable at any time), we use Google Analytics 4 to measure how visitors find and use our public pages, including which campaigns and articles bring them to us. Consent signals are handled via Google Consent Mode v2: if you do not consent, no Analytics cookie is set. If you also allow the marketing category, we use the Meta (Facebook) pixel to measure our advertising campaigns; without that consent the pixel is not loaded and no request is made to Meta. Your consent choice is stored by us in a first-party cookie; no third-party consent platform is involved. Legal basis: your consent (Art. 6(1)(a)).
11. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a new "last updated" date and, where the changes are material, notify account holders by email or in-app notice.