Privacy Policy

Last updated: August 2026

1. Who We Are

Wisteria ("we", "us") is a corporate learning platform operated by 369 Sales Academy PLT (registration no. 202604000656 / LLP0045881-LGN), a limited liability partnership registered in Malaysia, at getwisteria.com. We act as a data processor on behalf of your organisation (the data controller).

2. Data We Collect

We collect and process the following personal data: name; email address, where the user has one; phone number, for staff who sign in by phone instead of email; role, department and position within your organisation; learning progress, quiz results and scores; transcripts of spoken quiz answers; login timestamps and session activity; and content you create on the Platform. We do not collect home addresses, dates of birth, government identifiers, health information, or financial information.

3. Phone Numbers

Frontline staff often have no company email address, so Wisteria supports signing in with a phone number. Where a phone number is held, it is used only to sign the user in, deliver their initial invitation and temporary password, and send a one-time code if they forget their app PIN. Phone numbers are not used for training reminders or other notifications, which go by email, web push, or in-app message. They are never used for marketing, and are never sold, rented, or shared with third parties. The only external party that receives a phone number is the messaging provider that delivers those messages. Deleting a user removes their phone number; deactivating a user does not.

4. How We Use Your Data

We use your data to: operate your account and deliver training; track your progress and issue certificates; provide analytics to your organisation's administrators; send notifications related to your training; and improve the Platform.

5. AI Processing

When you use AI-assisted features (flashcard generation, quiz creation, document evaluation, spoken-answer grading), your input is sent to Anthropic (Claude) or OpenAI (Whisper) for processing. These providers act as sub-processors. Your content is not used to train any AI model, ours or theirs. Spoken quiz answers are not stored — the recording is sent for transcription and discarded, and only the resulting text is saved to your workspace.

6. Sub-Processors

We use the following third-party sub-processors: Supabase (database, authentication and file storage, Singapore); Anthropic (AI content generation and evaluation, US); OpenAI (speech-to-text transcription, US); Resend (transactional email, US); and our messaging provider, for delivery of sign-in messages to phone numbers. All sub-processors are subject to data processing agreements.

7. Where Your Data Is Stored

Your data is stored in Singapore. It is not stored in the United States or the European Union. Content sent for AI processing or email delivery is transmitted to the United States, processed, and returned; it is not stored there.

8. Data Retention

Audit logs are retained for 1 year. Notifications are retained for 30 days. Learning progress and account data are retained for the duration of your organisation's subscription, plus 30 days following termination, after which they are permanently deleted.

9. Your Rights

Under the Malaysian Personal Data Protection Act 2010 (PDPA), and equivalent laws that may apply depending on your location, you may have the right to access and correct your personal data; to withdraw consent to its processing; to limit how it is processed or disclosed; and, under some laws, to erasure and data portability. To exercise these rights, contact your organisation's administrator or email us at security@getwisteria.com. We respond within 30 days.

10. Data Protection Law

As a Malaysian entity, we process personal data in accordance with the Personal Data Protection Act 2010. Where your organisation or its staff are subject to other data protection laws — including the EU or UK GDPR, or Singapore's PDPA — we support those obligations through our Data Processing Agreement, available on request.

11. Security

We encrypt data in transit (TLS 1.2 or higher) and at rest (AES-256). Each organisation's data is separated at the database level using PostgreSQL row-level security. Passwords are stored as bcrypt hashes and never in plain text. Sensitive credentials such as integration tokens are encrypted a second time at the application level. Full detail, including the certifications we do not currently hold, is published at getwisteria.com/security.

12. International Transfers

Your data is stored in Singapore. Where content is transmitted to sub-processors in the United States for AI processing or email delivery, we rely on those providers' published transfer mechanisms, including Standard Contractual Clauses where applicable.

13. Changes to This Policy

We may update this policy. We will notify administrators of material changes. The current version is always available at getwisteria.com/privacy.

Contact

For privacy questions or data requests, email security@getwisteria.com.