Enkratos Privacy Policy
Effective date: 16 August 2026 · Last updated: 2 September 2026
Enkratos is a training and compliance platform operated by Enkratos Inc., a Wyoming corporation ("Enkratos", "we", "us"). This policy explains what personal information we handle, why, and the choices you have. It applies to everyone who uses Enkratos, wherever you live.
How to delete your data
If your employer gave you your Enkratos account, ask your employer's Enkratos administrator to erase you. They can do it from inside the product, and it removes your profile, your training records, your certificates and your continuing-education credits in full.
If you created your own account, or you cannot reach your administrator, email privacy@enkratos.io from the address on your account and say you want your data deleted. We confirm within 10 business days and complete the erasure within 45 calendar days.
What is deleted: your name, email address, phone number, postal address, employee or badge number, job role and site, together with your training records, quiz attempts and answers, completions, certificates, continuing-education hours, signatures and any questions you sent a trainer.
What may be kept, and for how long: nothing beyond what the law requires us to retain. Closed accounts are scheduled for deletion immediately and erased after a short grace period. Where a law obliges us to keep a specific record longer, we keep only that record and delete the rest. Section 6 explains our retention rules in full.
1. The two roles we play — please read this first
How this policy applies to you depends on how you reached us.
If you are a visitor, a prospect, or someone who created an Enkratos account directly, we decide what we collect and why, and the rights described in section 7 apply to us directly. In the language of most privacy laws, we are the controller of that information.
If your employer gave you an Enkratos account to take training, we act on your employer's behalf — a service provider, or processor, depending on which law applies to you. Your employer decides what training you are assigned, what records are kept, and how long they are kept. We handle that information only on their written instructions. Requests to see, correct or delete your training records should go to your employer, who can act on them through their Enkratos administrator. If you contact us directly, we will pass your request to them and help them respond.
We do not use employee training data for our own purposes, do not sell it, and do not combine it across customers.
2. What we collect
Account and profile information, provided by you or by your employer's administrator: name, work email address, phone number, postal address, employee or badge number, job role or position, and the site or region you are assigned to.
Training records created as you use the service: courses assigned to you, lessons opened, time spent on lessons and courses, quiz and exam attempts including the answers you gave and your score, completions, certificates and their serial numbers, continuing-education hours, and progress through curricula.
Attestations and signatures, where a course requires one: the name you type to sign, the exact wording you agreed to, the date and time, the email address on your account at that moment, the IP address you signed from, and your browser and device description. This is deliberate — it is what makes the signature meaningful to an auditor years later.
Communications data: the training emails and reminders we send you, whether they were delivered, bounced or were opened, unsubscribe status, and — if you use the mobile app and allow notifications — a push notification token for your device.
Security and integrity records: a log of when confidential source material was captured on screen, and an audit log of changes to accounts and access levels.
Technical data: we store your login session in your browser or app so you stay signed in.
What we do not collect. We do not collect Social Security numbers, government identification numbers, financial account numbers, biometric data, health data, precise geolocation, racial or ethnic origin, religious beliefs, union membership, or the contents of your private communications. We do not track you across other websites. We do not use advertising cookies or trackers.
3. Where it comes from
Directly from you; from your employer when they set up your account or import a staff list; and automatically from your use of the service.
4. Why we use it
- To deliver training and record who completed what, when, and to what standard
- To produce certificates and compliance evidence your employer can show a regulator or auditor
- To send assignment, reminder and completion emails, and app notifications if you enable them
- To keep the service secure, prevent cheating on assessments, and detect misuse
- To support you when you contact us
- To meet our own legal obligations
We do not use your information to build advertising profiles, and we do not train artificial-intelligence models on it.
About our AI features, specifically. Most of them assist course authors — drafting lessons, writing quiz questions, generating illustrations, translating a course, and transcribing training video. Those features send course content only: the lesson text, the document an author uploaded, the questions being written. No learner's name, email address, score, answer or completion record is ever sent to an AI provider.
There is one exception you should know about. If your employer leaves the AI study tutor switched on, the questions you type to it are sent to our AI provider so it can answer them, together with the course material you are studying. No name, email address or account identifier is sent with them, and we do not keep a transcript. But whatever you choose to type is transmitted, so treat it as you would any message to an outside service. Courses marked as regulatory never use the AI tutor — those questions go to a human trainer.
5. Who we share it with
We do not sell personal information, and we do not share it for targeted or cross-context behavioural advertising. We have not done so in the preceding twelve months.
We use a small number of service providers, each contractually restricted to processing data only for us:
| Provider | What they handle |
|---|---|
| Supabase | Application hosting, database and file storage |
| Cloudflare Stream | Hosting and delivery of training video, and automatic transcription of it for captions and search |
| Amazon Web Services / Resend | Sending training emails and recording delivery |
| Expo | Mobile app delivery and push notifications |
| Rustici Software (SCORM Cloud) | Playing training packages imported from other systems, where a customer uses that feature. It receives an anonymous learner code — never your name or email. |
| OpenAI | Course authoring assistance, image generation, translation, transcription of training audio and video, content moderation, and — where enabled — the AI study tutor. Sent without any learner identifier. |
| Anthropic | An alternative provider for translation and the AI study tutor. Same content, same absence of identifiers. |
We may also disclose information if required by law, to protect our rights or someone's safety, or in connection with a merger or sale of the business — in which case this policy continues to apply until replaced.
6. How long we keep it
Your employer sets the retention period for their training records. We provide controls for them to set that period, to export a person's data, and to erase a person or an entire account.
Some compliance records are intentionally tamper-evident: completions, signatures and continuing-education credits are sealed when written and cannot afterwards be altered — by your employer, by us, or by anyone else. They can still be deleted in full when a valid erasure request is carried out, but they cannot be quietly edited. This is a deliberate design choice: an audit record that can be changed is not evidence.
When an account is closed, we schedule its data for deletion and complete that deletion after a short grace period, unless we are required to keep something longer by law.
7. Your privacy rights
We give everyone the same rights, wherever you live. You do not have to be in a place with a privacy statute to ask us for any of this:
- Know what personal information we have collected about you, where it came from, why we collect it, and who we disclose it to
- Access a copy of it in a portable format
- Correct inaccurate information
- Delete it, subject to legal exceptions
- Object to or restrict a particular use, where the law where you live provides for that
- Not be discriminated against for exercising any of these rights. We will not deny you service, charge you differently, or give you a lesser experience.
Selling and sensitive information. We do not sell personal information and we do not share it for targeted advertising, so there is nothing for you to opt out of and you will not find a "Do Not Sell or Share My Personal Information" link. We do not collect the categories that privacy laws treat as sensitive — see section 2 for the list of what we deliberately do not touch.
Depending on where you live, specific laws may add to the list above. Examples include the California Consumer Privacy Act, the Utah Consumer Privacy Act and similar state laws in Colorado, Connecticut, Virginia and elsewhere, and the UK and EU General Data Protection Regulation. Where a law gives you more than the list above, that law wins. Where it gives you less, you still get the list above.
How to exercise them. If your employer provides your account, contact your employer's Enkratos administrator — they can produce your record or erase it from within the product. Otherwise, or if you cannot reach them, email privacy@enkratos.io. We will confirm receipt within 10 business days and respond within 45 calendar days, extending once by a further 45 days where necessary, and will tell you if we do.
We will verify your identity before acting — usually by confirming control of the email address on the account. An authorised agent may act for you with written permission, and we may still ask you to confirm it directly.
Appeals. If we refuse a request, you may ask us to reconsider by replying to our decision. You may also complain to the privacy regulator where you live — for example the California Privacy Protection Agency, your state Attorney General, or your national data protection authority.
8. Where we operate
Enkratos Inc. is based in the United States and our service providers are listed in section 5. If you use Enkratos from outside the United States, your information will be handled in the United States.
If you are in the EEA or the UK, our legal basis for handling learner data is our customer's legitimate interest in maintaining a compliant workforce, and their legal obligations; for our own account holders, the performance of our contract with you. Where we transfer personal data out of the EEA or the UK we rely on the European Commission's standard contractual clauses and the UK addendum.
9. Notices for specific regions
Privacy laws differ from one place to another, and new ones take effect regularly. We have not tried to list every one of them here, and we do not maintain a separate policy for each state or country.
If the law where you live gives you a right we have not described above, you have that right with us as well. Write to privacy@enkratos.io, tell us what you are asking for and where you live, and we will treat it as a valid request. The same is true of disclosures: if a law that applies to you requires us to tell you something this policy does not cover, ask and we will answer.
Nothing in this policy is intended to limit a right you hold under the law where you live. Where this policy and that law disagree, that law governs.
10. Security
Access is restricted to your own organisation and enforced in the database itself, not merely hidden in the interface. Data is encrypted in transit and at rest. Compliance evidence is cryptographically sealed.
Confidential training material is view-only and watermarked. On Android, screenshots and screen recording of that material are blocked by the operating system. On iOS, screen recording is blocked; screenshots cannot be prevented by any app, so instead we detect them, tell the learner they were recorded, and log them. No system is perfectly secure, and we do not claim otherwise.
11. Children
Enkratos is a workplace tool and is not directed at anyone under 16. We do not knowingly collect information from children. If you believe a child's information has reached us, contact us and we will delete it.
12. Changes
If we make a material change we will update the date above and, where the change affects you significantly, tell account holders directly.
13. Contact
Enkratos Inc.1541 E 1060 N
Orem, UT 84097
United States
Email: privacy@enkratos.io
