1. The data controller and how to contact us
The controller of personal data processed through the Sygma platform (also referred to in some materials as "MedAI"), available at sygma.ro, is:
| Item | Detail |
|---|---|
| Controller | Louperkos Investments LTD |
| Registered office | Efesou, 9, 5280 Paralimni, Cyprus |
| VAT number | CY60045221P |
| Data protection e-mail | contact@sygma.ro |
We process data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national law. For any question, request or complaint about your data, use the e-mail address above — it is the dedicated, monitored channel.
This policy applies to site visitors, students, teachers and administrators who use the Platform. It does not apply to third-party sites we may link to.
2. What data we process
We process only the categories below. The "Source" column shows whether the data comes directly from you or is generated by your use of the Platform.
| Category | Specific data | Source |
|---|---|---|
| Account data | E-mail address, full name, profile picture (if you upload one), account role (student / teacher / administrator), account creation date. Your password is stored only as an irreversible cryptographic value by our authentication provider — we never see it in clear text. | From you |
| Google sign-in | If you choose Google sign-in: your Google account identifier, e-mail address, name and profile image as supplied by Google. We never receive your Google password. | From Google, with your consent |
| Profile preferences | Leaderboard display name, interface language, theme (light/dark), in-app notices you dismissed, questions and flashcards you marked as favourites. | From you |
| Learning activity | Answers to questions (options chosen, correctness, score, response time), study and flashcard sessions, simulations and exams taken, progress across topics, subtopics and concepts, estimated mastery level, correct-answer streaks, recurring misconceptions identified, the baseline assessment taken at enrolment, exam-board enrolments and the date of last activity. | Generated by use |
| AI tutor conversations | The messages you write in chat, the generated replies, illustrations generated at your request, the conversation title and associated technical metadata (for example, the reference material used for an answer). A generated illustration may be reviewed by our team and made available to the other users of the same exam board; in that case only the image and its automatically generated description are shared — never your message, your name or any other account identifier. | From you + generated |
| Game elements | Virtual coin balance, transaction history in the internal economy, progress in the simulated environment and answer streaks. | Generated by use |
| Uploaded material (teacher role) | PDF files and images you upload, the content extracted from them, the chapters and topics defined, the questions and flashcards generated, and the identifier of the account that uploaded them. | From you |
| Billing data | Customer and subscription identifiers at the payment processor, chosen plan, billing cadence, subscription status and next renewal date. We do not store your card number, expiry date or CVV — these are collected and held directly by the payment processor. | From the payment processor |
| Reports and support | The name and e-mail address associated with the report, the description of the problem, its category, the page you sent it from, browser information and, optionally, a screenshot you attach. | From you |
| Technical and security data | Application error and performance logs, the internal user identifier associated with the event, browser and device type, event timestamp, and session recordings with all text and all form fields masked and media blocked. | Generated automatically |
3. Purposes and legal bases
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Optional browser diagnostics and masked session replay | Technical reports, interactions, account ID and email when signed in | Consent — Art. 6(1)(a), withdrawable in Profile or Privacy |
| Creating the account, authentication and access management | Account data, Google sign-in | Performance of the contract — Art. 6(1)(b) |
| Providing study features: adaptive question selection, spaced repetition, progress reports | Learning activity, preferences | Performance of the contract — Art. 6(1)(b) |
| Operating the AI tutor and generating explanations | Conversations, learning activity, relevant study content | Performance of the contract — Art. 6(1)(b) |
| Processing uploaded material and generating questions and flashcards | Uploaded material | Performance of the contract — Art. 6(1)(b) |
| Leaderboards and gamification | Display name, performance indicators, game elements | Performance of the contract — Art. 6(1)(b); the public display name remains your choice |
| Billing, collection, subscription management and accounting records | Billing data, account data | Performance of the contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| User support and handling reports | Reports, account data | Performance of the contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) |
| Essential server security, fraud and abuse prevention, debugging | Technical and security data | Legitimate interest — Art. 6(1)(f): keeping the service safe and working |
| Improving content quality and features, based on aggregate statistics | Learning activity in aggregated or pseudonymised form | Legitimate interest — Art. 6(1)(f) |
| Service communications (confirmations, password reset, changes to terms, billing notices) | Account data | Performance of the contract — Art. 6(1)(b) |
| Marketing e-mails, if introduced | E-mail address, name | Consent — Art. 6(1)(a), withdrawable at any time |
| Defending legal claims and complying with requests from authorities | The data relevant to the case | Legitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interest, we have assessed in advance whether it is balanced against your rights and freedoms. You can obtain details of that assessment by writing to us.
4. How we use artificial intelligence
The Platform's core features rely on artificial-intelligence models provided by Google (the Gemini model family), called through its programming interface.
What is sent
- Fragments of study material relevant to the current task (extracting content from a PDF, generating a question or flashcard, drafting an explanation);
- The messages you write to the AI tutor and the context of the current conversation;
- Contextual elements about your progress on the relevant topic, where needed to personalise the answer.
What is not sent
- Your e-mail address, name, profile picture or billing data;
- Your password, session tokens or any authentication material;
- Your complete activity history on the Platform.
Automated decisions
The Platform automatically chooses which questions and flashcards to show you and estimates your mastery level per topic. This is pedagogical personalisation: it produces no legal effects and does not similarly significantly affect you within the meaning of Art. 22 GDPR. We do not use these results to make decisions about you outside the Platform, we do not send them to universities as an official assessment, and we do not use them for commercial profiling. Teachers who administer an exam board you enrolled in can see your progress within that board — see section 10.
AI-generated content can contain errors. See the notice in the Terms and Conditions about the strictly educational nature of the Platform.
5. Who else has access to the data
We do not sell your data and we do not rent it to anyone. We share it only with the service providers that help us operate the Platform, acting as processors under contracts that impose confidentiality and prohibit them from using the data for their own purposes:
| Provider | Role | Data it can access |
|---|---|---|
| Supabase | Database, authentication, file storage, transactional account e-mails | Essentially all account and activity data, uploaded material |
| Vercel | Application hosting and content delivery | Traffic and request-routing data, technical logs |
| Google (Gemini API) | AI processing of study content and conversations | Study content, chat messages — no identity data, see section 4 |
| Stripe | Payment processing and billing | Payment and billing data, e-mail address |
| Sentry | Error and performance monitoring | Error logs, internal user identifier, session recordings with masked text |
| Cloudflare | Attack protection and delivery, in front of the data infrastructure | Technical network data, security cookie |
| Our own document-processing service | Extracting structure and text from uploaded PDF files | The content of uploaded files, for the duration of processing |
We may also disclose data: (i) to public authorities where the law requires it; (ii) to our professional advisers (legal, accounting), under confidentiality obligations; (iii) to an acquirer in the event of a merger, acquisition or transfer of business — in which case we will inform you beforehand and this policy will continue to apply to the transferred data.
6. Transfers outside the European Economic Area
Our hosting and storage infrastructure is configured to keep data within the European Union. However, some of the providers listed above (in particular those for AI processing, payments and monitoring) are United States companies or may process data outside the EEA.
For those situations we make sure the transfer is protected by at least one of the mechanisms set out in Chapter V of the GDPR:
- an adequacy decision of the European Commission, including the provider's certification under the EU–US Data Privacy Framework where applicable;
- the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional technical measures such as encryption in transit and minimisation of the data transmitted.
You can obtain further information about the mechanism applicable to a given provider, and a copy of the relevant safeguards, by writing to contact@sygma.ro.
7. How long we keep data
| Category | Retention period |
|---|---|
| Account and profile data | For as long as the account exists. On account deletion: removed within 30 days, except data we must keep under a legal obligation. |
| Learning activity and progress | For as long as the account exists. On deletion it is removed or irreversibly anonymised so that it can no longer be linked to you. |
| AI tutor conversations | For as long as the account exists, or until you delete the conversation. On account deletion: removed within 30 days. |
| Uploaded material and content derived from it | Until deleted by the person who uploaded it, or until account deletion. Content already published to an exam board may be retained by the institution that administers it, on the terms agreed with that institution. |
| Invoices and accounting records | 10 years from the end of the financial year, under statutory archiving obligations. |
| Reports and support correspondence | 3 years from resolution, so we can handle follow-up complaints and evidence how a matter was resolved. |
| Technical and error logs | 90 days as a rule. Session recordings are kept for at most 30 days. |
| Data needed to defend a legal claim | Until the dispute is finally resolved or the applicable limitation period expires. |
Once these periods expire, data is permanently deleted or anonymised. Aggregated, anonymised data — from which you can no longer be identified — may be kept indefinitely for statistics and to improve content quality.
8. Your rights
As a data subject you have the following rights:
- Right of access — to find out whether we process data about you and to receive a copy of it;
- Right to rectification — to correct inaccurate data or complete incomplete data; you can change much of it directly from your profile page;
- Right to erasure ("right to be forgotten") — to request removal of your data, under Art. 17 GDPR;
- Right to restriction of processing — to request that processing be suspended, in the situations set out in Art. 18 GDPR;
- Right to data portability — to receive the data you provided to us in a structured, commonly used, machine-readable format, or to have it transmitted to another controller;
- Right to object — to object to processing based on our legitimate interest, on grounds relating to your particular situation;
- Right to withdraw consent — at any time, for processing based on consent, without affecting the lawfulness of processing carried out beforehand;
- Right not to be subject to an automated decision with legal or similarly significant effects — see section 4;
- Right to lodge a complaint with a supervisory authority.
How to exercise your rights
Write to contact@sygma.ro, preferably from the address linked to your account. We reply within one month of receiving your request; that period may be extended by two months for complex requests, in which case we will tell you within the first month. Exercising your rights is free of charge; we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive, under Art. 12(5) GDPR. If we have reasonable doubts about the requester's identity, we may ask for additional verification information.
Supervisory authorities
- Romania — National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, sector 1, Bucharest, dataprotection.ro;
- Cyprus — Office of the Commissioner for Personal Data Protection, dataprotection.gov.cy;
- or the supervisory authority of the member state where you habitually reside or work.
We encourage you to contact us first — in most cases we can resolve the matter directly and quickly.
10. What other users can see
- Leaderboards: the display name you choose and the related performance indicators are visible to other participants in that leaderboard. You can change the display name from your profile page — you are not required to use your real name.
- Teachers and board administrators: if you enrol in an exam board, the teachers who administer it can see your progress within that board — answers, accuracy rates, topics mastered and gaps identified — so they can adapt the material and support you. They cannot see your AI tutor conversations and cannot see your activity in other boards.
- Resource collaborators: teachers you add as collaborators on a resource or board can see the material and generated content associated with it, together with the identity of the person who uploaded it.
- Data isolation: access to data is technically restricted at the database level through row-level security policies, so one user cannot read another's data outside the situations described above.
11. How we protect data
- All traffic is encrypted in transit (HTTPS/TLS) and stored data is encrypted at the provider infrastructure level;
- Access to data is segmented by role and enforced directly in the database through row-level security policies;
- Passwords are stored only as irreversible cryptographic values, managed by the authentication provider;
- Service keys and secrets are held in environment variables, separate from application code, and are never exposed in the browser;
- Session recordings used for debugging have all text and all form fields masked and media blocked; authorisation headers and cookies are stripped before an error report leaves the server;
- Uploaded files are stored in private buckets, accessible only through temporary signed URLs;
- Internal access to production data is limited to the people who need it to operate the Service.
No system is completely secure. If a personal data breach occurs that is likely to affect your rights and freedoms, we will notify the supervisory authority within 72 hours and inform you without undue delay where the risk is high, in accordance with Art. 33–34 GDPR.
12. Minors
The Platform is aimed at medical students and teaching staff. The minimum age to create an account is 16; people aged 16 to 18 need the consent of a parent or legal guardian to enter into the contract.
We do not knowingly collect data from people under 16. If you learn that a child under that age has provided us with data, contact us at contact@sygma.ro and we will delete the account and associated data without delay.
13. Changes to this policy
We may update this policy when we introduce new features, change providers, or where legislation requires it. The version in force and the date it applies from are shown at the top of the page.
For substantial changes — for example a new processing purpose or a new category of recipients — we will notify you by e-mail and/or through a visible in-app message at least 30 days before they take effect. If the change requires your consent, we will ask for it separately.
14. Contact
For any question about this policy or about the processing of your data, write to us at contact@sygma.ro.
| Controller | Louperkos Investments LTD |
| Address | Efesou, 9, 5280 Paralimni, Cyprus |
| VAT number | CY60045221P |
| contact@sygma.ro | |
| Document version | 1.1 — effective 14 September 2026 |