Legal

Privacy Policy

Last updated: August 4, 2026

Peerfold is a learning platform operated by Impulse Creative (“Peerfold”, “we”). Organizations (“customers”) run training workspaces on it; their learners take courses on portals we host for the customer. This policy explains what personal data the platform processes, in which role, and what happens to it.

Two roles

For learner data — the people taking courses — the customer is the data controller and Peerfold is a processor: we process learner data on the customer’s instructions, under the Data Processing Addendum. For account data — admin accounts, billing records, workspace telemetry — Peerfold is the controller.

What we process as a processor

  • Learner identity: email address and name, scoped to one workspace. Learners are never a cross-customer identity — the same email in two workspaces is two unrelated records.
  • Learning activity: enrollments, lesson progress, quiz and exam attempts, continuing-education credits, deadlines, and issued certificates (which render the learner’s name into the certificate artifact).
  • Assistant conversations: when a workspace enables the built-in assistant, learner questions and answers are stored as append-only transcripts the workspace’s training team can review — the assistant discloses this to learners in-product.
  • Commerce: order records with the buyer’s email. Card numbers never touch our systems — payment is processed by Stripe, and we store only Stripe’s references.
  • CRM copies: when a customer connects HubSpot, Day.ai or Salesforce, learner records and activity are written into the customer’s own CRM at the customer’s direction. Those copies live in systems the customer controls; the platform never reads them back for display.

What we process as a controller

  • Admin accounts: email, name, hashed credentials, session records.
  • Billing: plan, subscription and invoice records via Stripe.
  • Operational telemetry: audit logs of administrative and API actions (who did what, when), kept for the security of the workspace itself.

Security

These are properties of the running system, not policies beside it:

  • Every database query is scoped to a single workspace (tenant isolation is structural).
  • Third-party credentials and tokens are encrypted at rest with AES-256-GCM.
  • Sessions are httpOnly cookies; sign-in codes are single-use and expire in 10 minutes.
  • OAuth grants to AI assistants require an explicit admin consent screen, are scoped to one workspace, and are revocable in one click — revocation kills every token the grant ever minted.
  • Every mutation — UI, API, or agent — is audit-logged.
  • Per-workspace CORS and embedding allowlists; encrypted SSO/IdP secrets.

Subprocessors

Infrastructure we choose and are responsible for. Learner data reaches a subprocessor only as needed for the function named.

Customer-connected services

Distinct from subprocessors: integrations a workspace admin connects deliberately, under the customer’s own agreement with that vendor — HubSpot, Day.ai, Salesforce, Zoom, Microsoft Teams, GoToWebinar, Contrast, Wistia, Synthesia, Canva, Zapier, credential issuers (Badgr, Credly, Accredible, Certifier), and enterprise SSO identity providers. Data flows to them only after the connection is made, and stops when it is disconnected.

Cookies and local storage

The platform uses functional, host-only cookies: admin and learner sessions, and — on merchant sites using the embeddable cart — a cart token in the browser’s local storage. There is no cross-site advertising tracking. Customers may add their own analytics or tracking to their portals; for that, the customer is the controller.

Your rights

Learners exercise access, rectification, export and erasure rights through the workspace that controls their data; we support the customer in honoring them. Erasure is handled so that legally meaningful artifacts survive without identifying the person — an issued certificate keeps its serial number and verification while the name is redacted. Admins can edit their own profile data directly and can request account deletion at privacy@peerfold.com.

Data retention

Concrete lifetimes for every category are published separately in the Data Retention Policy.

Changes and contact

We update this policy when the system’s data handling changes, and the date above changes with it. Questions: privacy@peerfold.com.

Questions? Write to hello@peerfold.com and a person will answer.

Contact us