
Built to pass procurement, not just product review
Security and trust are often the first real blocker for regulated buyers evaluating Creatium or the APIs, so here’s where we stand today.
We do not use any input, output, or personal information to train third-party service provider AI technology.
Where we stand
Data privacy
We don’t use your inputs, outputs, or personal information to train third-party AI providers. Creatium is built to comply with GDPR and UK GDPR, along with privacy laws in Canada, Australia, New Zealand, South Africa, and 20 US states.
Security practices
We disclose every AI subprocessor we rely on (including Anthropic, OpenAI, ElevenLabs, Cartesia, Perplexity, and AWS and Azure AI) and apply human review to AI-generated content in our services work.
Compliance
We align to GDPR, UK GDPR, and FERPA. We only list certifications we can produce evidence for. See the certifications below, and ask us anytime.
Accessibility
We conform to WCAG 2.1 AA and Section 508, with captions, screen-reader support, and respect for system preferences like reduced motion. A VPAT is available on request.
LMS integration
Coach content is SCORM-compliant and distributes through your LMS with progress tracking, centralized content management, and learning-path delivery.
Certifications & conformance
What we can produce evidence for today. Ask and we’ll share the report, DPA, or VPAT.
GDPR & UK GDPR
Built to comply, with a Data Processing Addendum available for customers.
FERPA
Supports FERPA obligations for customers handling student education records.
WCAG 2.1 AA + Section 508
Conformant, with captions and screen-reader support. A VPAT is available on request.
SSO / SAML
Enterprise single sign-on through your SAML identity provider.
How we handle AI and your data
We never use your inputs, outputs, or personal information to train third-party AI.
Every AI subprocessor we use is disclosed in our privacy notice.
AI-generated content in our services work is reviewed by a human.
Avatars are used only with consent from the individuals or their estates, with consultation for Indigenous communities.

What we commit to contractually
Encryption in transit and at rest
Access controls, encryption in transit and at rest, logical segregation, vulnerability management, and logging and monitoring.
Breach notification
We’ll notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own compliance obligations.
Deletion and backup retention
We delete your content within 60 days of termination, plus standard backup retention of up to 90 additional days, after which backups are overwritten.
Subprocessor change notice
At least 30 days' notice before we add a new subprocessor, with the right to object on reasonable grounds.
Audit rights
On reasonable notice, we’ll provide the information needed to demonstrate compliance, and permit an on-site audit once every 12 months.
Subprocessors
Anthropic
AI
OpenAI
AI
ElevenLabs
AI
Cartesia
AI
Perplexity
AI
Amazon Web Services (AWS) AI
AI
Microsoft Azure AI
AI
Google Analytics
Analytics
