Skip to main content
Privacy policy

Privacy, in plain language.

What we collect, why, who we share it with, and the controls you have over it. Effective 27 May 2026, last updated 27 May 2026.

1. What this policy covers

This privacy policy explains how Setec Millenium (“Setec Millenium”, “we”, “us”, “our”) handles personal data when you visit our marketing website, create an account, or use the Setec Millenium learning platform (the “Service”).

We process personal data in two distinct contexts. The marketing site (this website) processes data about visitors — for analytics, for sign-up, and for sales conversations. The Service processes data about your training programme — your team members, your participants, your quiz content, and your source materials. This policy covers both.

Where your organisation acts as the data controller and we act as the data processor (the typical arrangement for the Service), the Data Processing Addendum we sign with you controls. This policy describes our default practices; the DPA governs in the event of any conflict.

2. Data we collect

From the marketing site, we collect:

  • Account data you submit through the sign-up form.
  • Sales conversation data when you email us or book a call.
  • Anonymous usage analytics through privacy-respecting tooling (page views, referrer, device class, country-level geolocation).
  • Essential cookies for session integrity.

From the Service, we process on behalf of your organisation:

  • Team member accounts: email, name, role, last-login timestamp.
  • Participant data captured through quizzes: name, email, optional phone or company, attempt responses, scores, certificates.
  • Quiz content you author: prompts, answers, references, source materials you upload, and AI-generation history.
  • Operational telemetry: API request counts, error traces.

We do not collect payment card data — billing is handled by our payment processor, and only the last four digits and brand reach our systems.

3. How we use the data

We use marketing-site data to:

  • Respond to your enquiries and process your sign-up.
  • Improve the website through aggregated analytics — never at the individual level.
  • Comply with legal obligations and enforce our terms.

We use Service data only to operate the Service on your behalf — to render the platform, generate quizzes, score attempts, issue certificates, and produce the reports you ask for.

We never train AI models on your quiz content, source materials, or participant responses. AI generation runs through OpenRouter; we configure the integration to opt out of any provider training pipeline where the option exists.

4. AI providers and other third parties

To deliver AI generation, translation, and written-answer rating, we send structured prompts to OpenRouter. The prompts include your source material excerpts, the question being authored, and the reference answer when present. Responses return to the Service and never leave our infrastructure beyond that single request.

Other processors we rely on, each under a written data processing agreement:

  • Supabase — managed Postgres for business data.
  • Email delivery provider — for transactional email.
  • Hosting provider — for the application runtime.
  • File storage — for source materials and certificates.
  • Optional transcription provider — only when you trigger audio transcription.

We share data with these processors only to the extent necessary to deliver the Service. We do not sell personal data, and we do not share it with advertising networks.

5. Cookies and similar technologies

The marketing site uses only the cookies necessary for session integrity, theme preference, and locale selection. We do not use third-party advertising cookies.

The Service uses first-party cookies for authentication, locale selection, and the dark/light theme preference. Admin clients may set their own analytics cookies inside the Service; if they do, we surface them at the workspace level so participants can opt out.

6. Data retention

Marketing enquiries are kept for 24 months from your last contact, then deleted. Job applicant data is kept for 6 months after the closing of the position, then deleted.

Service data lives as long as your organisation keeps its workspace. On workspace termination, we delete business data within 30 days, with a 30-day grace period in case you change your mind. Backups rotate on a 35-day cycle, so residual data may persist in encrypted backups for up to 35 days after deletion.

Audit log entries are retained for the period your plan specifies (30 days on Free, 180 days on Pro, configurable on Enterprise) and then deleted.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data. If we process your data as a controller (marketing site), exercise those rights by emailing privacy@setec-millenium.app.

If the data belongs to your organisation's Service account, your organisation's privacy team is the right first contact — we will support them in fulfilling your request. We respond to verified requests within 30 days, or sooner if your local law requires.

You also have the right to lodge a complaint with your data protection authority. We encourage you to contact us first so we can address the issue directly.

8. Security

We take security seriously. The Service runs on managed infrastructure with database-level tenant isolation, immutable audit logs, encrypted-at-rest storage, and TLS in transit. Admin access requires hardware-backed multi-factor authentication and is logged.

We run an annual third-party penetration test, and we publish a summary of our security posture at /security.

If you discover a vulnerability, please report it to security@setec-millenium.app. We acknowledge responsible-disclosure reports within one business day.

9. International data transfers

We are headquartered in the European Union and maintain a US entity. Where we transfer personal data outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Agreement, where applicable) and supplementary technical and organisational measures.

Customer Service data lives in the Supabase region you select at workspace creation — typically the EU, the US, or another Supabase-supported region.

10. Children's data

The Service is intended for corporate training and is not designed for children under 16. We do not knowingly collect personal data from children. If you believe a child has signed up, contact privacy@setec-millenium.app and we will delete the account.

11. Changes to this policy

We update this policy when our practices change or when the law requires it. We post the new version on this page with a revised “Last updated” date and — for material changes — email workspace admins at least 30 days before the change takes effect.

Previous versions are available on request to privacy@setec-millenium.app.

12. How to contact us

Setec Millenium is the data controller for the marketing site and for account-level Service data.

Setec Millenium
Keizersgracht 482
1017 EG Amsterdam
The Netherlands

privacy@setec-millenium.app

Have a privacy question we haven't covered?

Email us. We answer every privacy enquiry, and the team that reads it includes the people who built the data flow in the first place.

Privacy policy — Setec Millenium — Setec Millenium