Sygma
FuncționalitățiCum funcționeazăÎntrebări frecventePentru Educatori

Privacy Policy

ROEN

What data Sygma collects, why we collect it, who we share it with, and what rights you have.

Effective from 14 September 2026 · version 1.1

In short

  • —We collect only what is needed to run your account and personalise your learning: basic identity, study activity and minimal technical data.
  • —We do not sell your data and we use no advertising or cross-site tracking cookies.
  • —Study content and messages to the AI tutor are sent to Google for processing, under contracts that prohibit their use for training general models.
  • —Your card details never reach us — payments are handled entirely by Stripe.
  • —You can access, correct, export or delete your data at any time by writing to our contact address.

Ne ajuți să îmbunătățim Sygma?

Cu acordul tău, trimitem către Sentry rapoarte tehnice și înregistrări ale interacțiunilor pentru depanare, asociate cu ID-ul și adresa de e-mail a contului tău când ești autentificat. Textul, câmpurile de formular și imaginile din înregistrări sunt mascate sau blocate.

Opțional, pentru acest browser. Poți refuza fără să pierzi funcționalități și poți retrage acordul din Profil sau Confidențialitate. Jurnalele tehnice esențiale de pe server rămân active.

Diagnostice opționale: dezactivate

Confidențialitate și preferințe

1. The data controller and how to contact us

The controller of personal data processed through the Sygma platform (also referred to in some materials as "MedAI"), available at sygma.ro, is:

ItemDetail
ControllerLouperkos Investments LTD
Registered officeEfesou, 9, 5280 Paralimni, Cyprus
VAT numberCY60045221P
Data protection e-mailcontact@sygma.ro

We process data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national law. For any question, request or complaint about your data, use the e-mail address above — it is the dedicated, monitored channel.

This policy applies to site visitors, students, teachers and administrators who use the Platform. It does not apply to third-party sites we may link to.

2. What data we process

We process only the categories below. The "Source" column shows whether the data comes directly from you or is generated by your use of the Platform.

CategorySpecific dataSource
Account dataE-mail address, full name, profile picture (if you upload one), account role (student / teacher / administrator), account creation date. Your password is stored only as an irreversible cryptographic value by our authentication provider — we never see it in clear text.From you
Google sign-inIf you choose Google sign-in: your Google account identifier, e-mail address, name and profile image as supplied by Google. We never receive your Google password.From Google, with your consent
Profile preferencesLeaderboard display name, interface language, theme (light/dark), in-app notices you dismissed, questions and flashcards you marked as favourites.From you
Learning activityAnswers to questions (options chosen, correctness, score, response time), study and flashcard sessions, simulations and exams taken, progress across topics, subtopics and concepts, estimated mastery level, correct-answer streaks, recurring misconceptions identified, the baseline assessment taken at enrolment, exam-board enrolments and the date of last activity.Generated by use
AI tutor conversationsThe messages you write in chat, the generated replies, illustrations generated at your request, the conversation title and associated technical metadata (for example, the reference material used for an answer). A generated illustration may be reviewed by our team and made available to the other users of the same exam board; in that case only the image and its automatically generated description are shared — never your message, your name or any other account identifier.From you + generated
Game elementsVirtual coin balance, transaction history in the internal economy, progress in the simulated environment and answer streaks.Generated by use
Uploaded material (teacher role)PDF files and images you upload, the content extracted from them, the chapters and topics defined, the questions and flashcards generated, and the identifier of the account that uploaded them.From you
Billing dataCustomer and subscription identifiers at the payment processor, chosen plan, billing cadence, subscription status and next renewal date. We do not store your card number, expiry date or CVV — these are collected and held directly by the payment processor.From the payment processor
Reports and supportThe name and e-mail address associated with the report, the description of the problem, its category, the page you sent it from, browser information and, optionally, a screenshot you attach.From you
Technical and security dataApplication error and performance logs, the internal user identifier associated with the event, browser and device type, event timestamp, and session recordings with all text and all form fields masked and media blocked.Generated automatically
We do not request and do not want medical data about you or about patients. The Platform is not intended for processing special categories of data (Art. 9 GDPR). Please do not enter identifiable health data of real individuals into the chat, into reports, or into uploaded material.

3. Purposes and legal bases

PurposeData usedLegal basis (GDPR)
Optional browser diagnostics and masked session replayTechnical reports, interactions, account ID and email when signed inConsent — Art. 6(1)(a), withdrawable in Profile or Privacy
Creating the account, authentication and access managementAccount data, Google sign-inPerformance of the contract — Art. 6(1)(b)
Providing study features: adaptive question selection, spaced repetition, progress reportsLearning activity, preferencesPerformance of the contract — Art. 6(1)(b)
Operating the AI tutor and generating explanationsConversations, learning activity, relevant study contentPerformance of the contract — Art. 6(1)(b)
Processing uploaded material and generating questions and flashcardsUploaded materialPerformance of the contract — Art. 6(1)(b)
Leaderboards and gamificationDisplay name, performance indicators, game elementsPerformance of the contract — Art. 6(1)(b); the public display name remains your choice
Billing, collection, subscription management and accounting recordsBilling data, account dataPerformance of the contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
User support and handling reportsReports, account dataPerformance of the contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f)
Essential server security, fraud and abuse prevention, debuggingTechnical and security dataLegitimate interest — Art. 6(1)(f): keeping the service safe and working
Improving content quality and features, based on aggregate statisticsLearning activity in aggregated or pseudonymised formLegitimate interest — Art. 6(1)(f)
Service communications (confirmations, password reset, changes to terms, billing notices)Account dataPerformance of the contract — Art. 6(1)(b)
Marketing e-mails, if introducedE-mail address, nameConsent — Art. 6(1)(a), withdrawable at any time
Defending legal claims and complying with requests from authoritiesThe data relevant to the caseLegitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c)

Where we rely on legitimate interest, we have assessed in advance whether it is balanced against your rights and freedoms. You can obtain details of that assessment by writing to us.

4. How we use artificial intelligence

The Platform's core features rely on artificial-intelligence models provided by Google (the Gemini model family), called through its programming interface.

What is sent

  • Fragments of study material relevant to the current task (extracting content from a PDF, generating a question or flashcard, drafting an explanation);
  • The messages you write to the AI tutor and the context of the current conversation;
  • Contextual elements about your progress on the relevant topic, where needed to personalise the answer.

What is not sent

  • Your e-mail address, name, profile picture or billing data;
  • Your password, session tokens or any authentication material;
  • Your complete activity history on the Platform.
We use Google's service under the contractual terms applicable to commercial use of its programming interface, which do not permit the content sent to be used for training the provider's general models. Content may be retained temporarily by the provider to operate the service and prevent abuse, in accordance with its terms.

Automated decisions

The Platform automatically chooses which questions and flashcards to show you and estimates your mastery level per topic. This is pedagogical personalisation: it produces no legal effects and does not similarly significantly affect you within the meaning of Art. 22 GDPR. We do not use these results to make decisions about you outside the Platform, we do not send them to universities as an official assessment, and we do not use them for commercial profiling. Teachers who administer an exam board you enrolled in can see your progress within that board — see section 10.

AI-generated content can contain errors. See the notice in the Terms and Conditions about the strictly educational nature of the Platform.

5. Who else has access to the data

We do not sell your data and we do not rent it to anyone. We share it only with the service providers that help us operate the Platform, acting as processors under contracts that impose confidentiality and prohibit them from using the data for their own purposes:

ProviderRoleData it can access
SupabaseDatabase, authentication, file storage, transactional account e-mailsEssentially all account and activity data, uploaded material
VercelApplication hosting and content deliveryTraffic and request-routing data, technical logs
Google (Gemini API)AI processing of study content and conversationsStudy content, chat messages — no identity data, see section 4
StripePayment processing and billingPayment and billing data, e-mail address
SentryError and performance monitoringError logs, internal user identifier, session recordings with masked text
CloudflareAttack protection and delivery, in front of the data infrastructureTechnical network data, security cookie
Our own document-processing serviceExtracting structure and text from uploaded PDF filesThe content of uploaded files, for the duration of processing

We may also disclose data: (i) to public authorities where the law requires it; (ii) to our professional advisers (legal, accounting), under confidentiality obligations; (iii) to an acquirer in the event of a merger, acquisition or transfer of business — in which case we will inform you beforehand and this policy will continue to apply to the transferred data.

6. Transfers outside the European Economic Area

Our hosting and storage infrastructure is configured to keep data within the European Union. However, some of the providers listed above (in particular those for AI processing, payments and monitoring) are United States companies or may process data outside the EEA.

For those situations we make sure the transfer is protected by at least one of the mechanisms set out in Chapter V of the GDPR:

  • an adequacy decision of the European Commission, including the provider's certification under the EU–US Data Privacy Framework where applicable;
  • the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional technical measures such as encryption in transit and minimisation of the data transmitted.

You can obtain further information about the mechanism applicable to a given provider, and a copy of the relevant safeguards, by writing to contact@sygma.ro.

7. How long we keep data

CategoryRetention period
Account and profile dataFor as long as the account exists. On account deletion: removed within 30 days, except data we must keep under a legal obligation.
Learning activity and progressFor as long as the account exists. On deletion it is removed or irreversibly anonymised so that it can no longer be linked to you.
AI tutor conversationsFor as long as the account exists, or until you delete the conversation. On account deletion: removed within 30 days.
Uploaded material and content derived from itUntil deleted by the person who uploaded it, or until account deletion. Content already published to an exam board may be retained by the institution that administers it, on the terms agreed with that institution.
Invoices and accounting records10 years from the end of the financial year, under statutory archiving obligations.
Reports and support correspondence3 years from resolution, so we can handle follow-up complaints and evidence how a matter was resolved.
Technical and error logs90 days as a rule. Session recordings are kept for at most 30 days.
Data needed to defend a legal claimUntil the dispute is finally resolved or the applicable limitation period expires.

Once these periods expire, data is permanently deleted or anonymised. Aggregated, anonymised data — from which you can no longer be identified — may be kept indefinitely for statistics and to improve content quality.

8. Your rights

As a data subject you have the following rights:

  • Right of access — to find out whether we process data about you and to receive a copy of it;
  • Right to rectification — to correct inaccurate data or complete incomplete data; you can change much of it directly from your profile page;
  • Right to erasure ("right to be forgotten") — to request removal of your data, under Art. 17 GDPR;
  • Right to restriction of processing — to request that processing be suspended, in the situations set out in Art. 18 GDPR;
  • Right to data portability — to receive the data you provided to us in a structured, commonly used, machine-readable format, or to have it transmitted to another controller;
  • Right to object — to object to processing based on our legitimate interest, on grounds relating to your particular situation;
  • Right to withdraw consent — at any time, for processing based on consent, without affecting the lawfulness of processing carried out beforehand;
  • Right not to be subject to an automated decision with legal or similarly significant effects — see section 4;
  • Right to lodge a complaint with a supervisory authority.

How to exercise your rights

Write to contact@sygma.ro, preferably from the address linked to your account. We reply within one month of receiving your request; that period may be extended by two months for complex requests, in which case we will tell you within the first month. Exercising your rights is free of charge; we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive, under Art. 12(5) GDPR. If we have reasonable doubts about the requester's identity, we may ask for additional verification information.

Supervisory authorities

  • Romania — National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, sector 1, Bucharest, dataprotection.ro;
  • Cyprus — Office of the Commissioner for Personal Data Protection, dataprotection.gov.cy;
  • or the supervisory authority of the member state where you habitually reside or work.

We encourage you to contact us first — in most cases we can resolve the matter directly and quickly.

9. Cookies and similar technologies

The browser stores your diagnostics choice, notice version, and choice time under sygma-diagnostics-v1 for up to 180 days. The choice applies only to this browser. On the production site, signing out disables optional diagnostics; clearing browser storage or a changed consent version requires a new choice. Sentry may store replay session state only after acceptance on the production site. Production browser diagnostics are based on consent (Article 6(1)(a) GDPR).

We use no advertising or cross-site tracking cookies. On the production site, optional browser diagnostics through Sentry, including performance reports and masked session replay, start only after you accept the diagnostics prompt. When signed in, these reports can include your account ID and email. On local and development builds, technical errors and logs are collected automatically without session replay or email; you can disable this browser collection in Profile or the preferences above. Refusing or disabling diagnostics does not limit access to the service. Stopping browser collection does not automatically delete reports already sent. Contact us to exercise your data rights. Essential server diagnostics continue separately with account IDs, without explicitly attaching email.
Name / typeRoleCategoryDuration
Authentication provider session cookies (sb- prefix)Keep you signed in across pages and refresh the sessionStrictly necessaryUntil sign-out or session expiry
NEXT_LOCALERemembers the interface language you chosePreference12 months
__cf_bm and similar security cookiesDistinguish human from automated traffic and protect the infrastructureStrictly necessaryUp to 30 minutes
Browser local storage (localStorage)Remembers your chosen theme and your working state in the resource editor, so you do not lose progress on reloadStrictly necessary / preferenceUntil you clear browser data

You can manage or delete cookies at any time from your browser settings. Blocking strictly necessary cookies makes signing in to the Platform impossible.

10. What other users can see

  • Leaderboards: the display name you choose and the related performance indicators are visible to other participants in that leaderboard. You can change the display name from your profile page — you are not required to use your real name.
  • Teachers and board administrators: if you enrol in an exam board, the teachers who administer it can see your progress within that board — answers, accuracy rates, topics mastered and gaps identified — so they can adapt the material and support you. They cannot see your AI tutor conversations and cannot see your activity in other boards.
  • Resource collaborators: teachers you add as collaborators on a resource or board can see the material and generated content associated with it, together with the identity of the person who uploaded it.
  • Data isolation: access to data is technically restricted at the database level through row-level security policies, so one user cannot read another's data outside the situations described above.

11. How we protect data

  • All traffic is encrypted in transit (HTTPS/TLS) and stored data is encrypted at the provider infrastructure level;
  • Access to data is segmented by role and enforced directly in the database through row-level security policies;
  • Passwords are stored only as irreversible cryptographic values, managed by the authentication provider;
  • Service keys and secrets are held in environment variables, separate from application code, and are never exposed in the browser;
  • Session recordings used for debugging have all text and all form fields masked and media blocked; authorisation headers and cookies are stripped before an error report leaves the server;
  • Uploaded files are stored in private buckets, accessible only through temporary signed URLs;
  • Internal access to production data is limited to the people who need it to operate the Service.

No system is completely secure. If a personal data breach occurs that is likely to affect your rights and freedoms, we will notify the supervisory authority within 72 hours and inform you without undue delay where the risk is high, in accordance with Art. 33–34 GDPR.

12. Minors

The Platform is aimed at medical students and teaching staff. The minimum age to create an account is 16; people aged 16 to 18 need the consent of a parent or legal guardian to enter into the contract.

We do not knowingly collect data from people under 16. If you learn that a child under that age has provided us with data, contact us at contact@sygma.ro and we will delete the account and associated data without delay.

13. Changes to this policy

We may update this policy when we introduce new features, change providers, or where legislation requires it. The version in force and the date it applies from are shown at the top of the page.

For substantial changes — for example a new processing purpose or a new category of recipients — we will notify you by e-mail and/or through a visible in-app message at least 30 days before they take effect. If the change requires your consent, we will ask for it separately.

14. Contact

For any question about this policy or about the processing of your data, write to us at contact@sygma.ro.

ControllerLouperkos Investments LTD
AddressEfesou, 9, 5280 Paralimni, Cyprus
VAT numberCY60045221P
E-mailcontact@sygma.ro
Document version1.1 — effective 14 September 2026
↑ Back to top

Contents

  1. 1. The data controller and how to contact us
  2. 2. What data we process
  3. 3. Purposes and legal bases
  4. 4. How we use artificial intelligence
  5. 5. Who else has access to the data
  6. 6. Transfers outside the European Economic Area
  7. 7. How long we keep data
  8. 8. Your rights
  9. 9. Cookies and similar technologies
  10. 10. What other users can see
  11. 11. How we protect data
  12. 12. Minors
  13. 13. Changes to this policy
  14. 14. Contact
Sygma

Platformă de învățare medicală alimentată de AI care se adaptează la cunoștințele tale și te ajută să excelezi la examene.

Produs

  • Funcționalități
  • Cum funcționează
  • Întrebări frecvente
  • Pentru Educatori

Cont

  • Autentificare
  • Înregistrare

Legal

  • Termeni și Condiții
  • Confidențialitate

© 2026 Sygma. Toate drepturile rezervate.