Data Processing and Security Overview

Data Processing and Security Overview

Effective Date: April 20, 2026
SymTrain is committed to protecting the confidentiality, integrity, and availability of customer data. This overview describes the technical and organizational practices we apply to data processed through the SymTrain platform.

1. Infrastructure and Hosting

SymTrain’s platform is hosted on a secure cloud infrastructure. Our environment is designed for availability, resilience, and data protection.

  • Services are hosted in enterprise-grade cloud environments with physical and logical security controls
  • Infrastructure is maintained with regular patching and vulnerability management practices
  • System availability is monitored continuously, with incident response procedures in place

2. Data Encryption

SymTrain encrypts data in transit and at rest.

  • In transit: All data transmitted between users and the SymTrain platform is encrypted using TLS (Transport Layer Security)
  • At rest: Stored data, including simulation inputs, performance records, and user data, is encrypted using industry-standard encryption

3. Access Controls

Access to customer data is restricted on a need-to-know basis.

  • Role-based access controls (RBAC) limit data access to authorized personnel only
  • Administrative access to production systems requires authentication and is logged
  • SymTrain employees do not access customer data except as required to deliver, support, or troubleshoot the Services, or as required by law
  • Access privileges are reviewed periodically and revoked upon role change or termination

4. Customer Data Segregation

Customer data is logically isolated within the SymTrain platform.

  • Each customer’s data is stored and processed in a logically separate environment
  • Customer data is not commingled or accessible across customer accounts
  • Customer data is not used to train AI models shared across other customers

5. AI Data Processing

SymTrain uses AI to generate simulation scenarios, coaching responses, and performance assessments.

  • User inputs submitted during simulations are processed to generate training outputs
  • AI processing occurs within SymTrain’s controlled environment and is subject to the same access and security controls as other platform data
  • Aggregated and anonymized data may be used to improve platform performance; individually identifiable data is not used for this purpose without appropriate authorization
  • AI-generated outputs are intended to support human-led training processes and are not designed to serve as autonomous decision-making tools for employment or compliance purposes

6. Website Data Collection

SymTrain’s website collects limited data to support analytics and marketing operations.

  • Analytics data is collected via Google Analytics
  • Marketing and CRM data is collected via HubSpot
  • Website data is used for operational and marketing purposes only and is handled in accordance with our Privacy Policy and Cookie Notice

7. Data Retention and Deletion

SymTrain retains customer data only as long as necessary to provide the Services and meet contractual and legal obligations.

  • Retention periods are defined in applicable service agreements and Data Processing Agreements
  • Upon contract termination or customer request, data is deleted or returned in accordance with the agreed terms
  • Backup data is subject to the same retention controls as primary data

8. Organizational Security Practices

SymTrain maintains internal policies and practices to support data security.

  • Security awareness and data handling expectations are communicated to all personnel with access to customer data
  • Vendor and subprocessor relationships are evaluated for security posture prior to engagement
  • SymTrain maintains an incident response process, including defined escalation and customer notification procedures

9. Compliance Alignment

SymTrain’s security practices are designed to align with commonly accepted industry frameworks and data protection principles, including those reflected in SOC 2, GDPR, and CCPA. Customers operating in regulated industries (including healthcare, financial services, and insurance) should evaluate SymTrain’s practices in the context of their specific compliance requirements.

For compliance documentation requests, Data Processing Agreements, or security questionnaires, contact: info@symtrain.ai

10. Limitations

While SymTrain implements reasonable and industry-aligned security measures, no system or environment provides absolute guarantees against all security risks. We encourage customers to apply appropriate internal controls and policies governing their use of the platform.

11. Updates

This overview may be updated to reflect changes in our practices, infrastructure, or compliance posture. Updates will be posted with a revised effective date.

12. Contact

For security inquiries or to report a concern:
info@symtrain.ai

Scroll to Top
SYM API Form

Try Symtrain for Free