Privacy Center Trust Portal Gateway
At Symplicity, student success is our mission — and protecting student privacy is foundational to that mission. We empower university administrators and staff with the tools, transparency, and documentation they need to safeguard every student's right to privacy throughout their time on campus and beyond.
Welcome to Your Trust Portal.
- Company and Data Privacy Team Information
- Documentation for procurement and renewal activities
- Information about how Symplicity governs
- Learning resources to give you a data privacy refresher
- Tools to complete your own due diligence activities
- Sub-processor information
Global Privacy Regulations
Privacy regulations applicable to Symplicity's operations worldwide
Acting General Counsel
Information Security Officer
Symplicity Corporation
Data privacy has long been a natural extension of my background in cybersecurity, where confidentiality is one of the three foundational pillars. When the General Data Protection Regulation (GDPR) was introduced, I did not expect that Symplicity would eventually operate in an environment governed by more than thirty national data privacy laws, along with numerous state and regional regulations across those jurisdictions. The global privacy landscape has expanded rapidly, bringing with it both increased complexity and greater responsibility for organizations entrusted with personal data.
At Symplicity, protecting the personal information entrusted to us is a core commitment. Working alongside exceptional colleagues across our organization, we have built and matured a comprehensive privacy program designed to meet the expectations of institutions, regulators, and the students our platforms ultimately serve.
Throughout this process, we have partnered with experienced privacy counsel across multiple regions and worked closely with universities, regulators, and policymakers. In some cases, we have had the opportunity to provide input during legislative efforts as new privacy regulations were being developed.
Our work in privacy is ongoing. As regulations continue to evolve, we remain committed to learning, adapting, and strengthening our practices.
Over time, the volume of compliance reviews, questionnaires, and documentation requests across the higher education technology ecosystem has increased significantly.
For that reason, we created this Privacy Center. It is intended to serve as a resource for institutions using Symplicity platforms to stay informed about privacy developments, access information relevant to due diligence and compliance activities, and learn best practices for administering systems that process sensitive student data.
Over the years, I have had the privilege of working with hundreds of university and college general counsels, privacy officers, and compliance professionals as Symplicity's student success platforms have expanded globally.
If you have questions about data privacy, regulatory compliance, or the protection of student information within Symplicity platforms, please feel free to contact me or the Symplicity Higher Ed Support team.
In partnership,
Andrew Wippl
Data Protection Officer / Information Security Officer
Symplicity Corporation
Trending Resources
Most-requested privacy documents and resources.
Data Processing Agreement (DPA)
Standard contractual terms for data processing between controller and processor under GDPR Article 28.
PublicSub-Processor List
Current list of authorized sub-processors and their processing purposes across all product lines.
PublicData Protection Impact Assessment
Comprehensive DPIA covering all products and high-risk processing activities in GDPR and ICO-compliant formats.
Request AccessTransfer Impact Assessment
Transfer Risk Assessment for all international data transfers ensuring Schrems II compliance.
Request AccessPrivacy Policy
Our comprehensive privacy policy covering data collection, use, retention, and your rights.
PublicCookie Policy
Details on cookie usage, types, and management options across our services and web properties.
PublicSOC 2 Type II Report (Privacy)
Independent audit report covering all five Trust Services Criteria including Privacy, conducted by Prescient Security.
Request AccessDSAR Process Guide
Step-by-step guide for handling Data Subject Access Requests across processor and controller products.
PublicBy Organization
View privacy practices and data handling specific to each entity.
Symplicity
Parent OrganizationRegulatory Frameworks
Privacy Topics
Explore our privacy practices, controls, and compliance measures in detail.
Privacy Program Overview
Comprehensive privacy program led by the DPO, built on privacy-by-design principles with alignment to GDPR, CCPA/CPRA, PIPEDA, LGPD, and Australian Privacy Act.
Data Processing Roles & Responsibilities
Symplicity acts as data processor for most products and data controller for Recruit and CareerHub Central, with clear role definitions.
Data Protection Impact Assessments
Comprehensive DPIAs for all products and high-risk processing, available in Symplicity and ICO-compliant formats.
Data Processing Agreements
Comprehensive DPAs complying with GDPR Article 28, UK GDPR, LGPD, and other applicable data protection regulations.
Transfer Risk Assessments
Transfer Risk Assessments for all international data transfers ensuring Schrems II compliance.
Subprocessors
Transparent and current sub-processor list with documented change notification procedures.
Privacy Assessments & Audits
Regular privacy assessments including SOC 2 Type II with privacy criteria, HECVAT, and CAIQ.
Data Privacy Framework (DPF)
EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework participation for compliant transfers.
PII Breach Response
Comprehensive PII breach response plan with defined notification timelines.
Privacy Policy & Notices
Transparent privacy policies and notices covering all processing activities.
Protecting personal data across 45+ countries and 20 US states
Learn About Privacy
Educational resources to help you understand data protection.
What is a DPIA?
Learn what Data Protection Impact Assessments are, when they're required, and how Symplicity conducts them for every product.
Your Data Subject Rights
Understand your rights under GDPR, CCPA, and other regulations — access, rectification, erasure, portability, and more.
Privacy FAQ
Answers to common questions about how Symplicity handles personal data, international transfers, and data retention.
Privacy Glossary
Definitions of key privacy and data protection terms — from 'data controller' to 'pseudonymization' and beyond.
Processor vs. Controller
Understand when Symplicity acts as a data processor or controller, and what that means for your institution.
International Transfers
How Symplicity ensures compliant cross-border data transfers using DPF, SCCs, and Transfer Impact Assessments.
Privacy Center Trust Portal Gateway Updates
Symplicity has achieved Cyber Essentials certification across all four organizations, assessed by IASME. This UK Government-backed certification covers five key technical control areas and is mandatory for many UK Government contracts involving sensitive data.
Indiana, Kentucky, and Rhode Island joined a growing group of states enforcing comprehensive privacy statutes. These laws provide consumers with rights to access, correct, delete data, and opt out of targeted advertising.
All four Symplicity organizations have completed SOC 2 Type II and ISO 27001 audits conducted by Prescient Security. The SOC 2 report covers all five Trust Services Criteria including Privacy.
AI is transforming data usage and regulators are focused on personal data in AI development. Organizations are adopting privacy-preserving approaches including data minimization, anonymization, and privacy-enhancing technologies.
The European Commission released a proposal to simplify and modernize GDPR as part of its Digital Omnibus initiative, aiming to reduce administrative burden while maintaining core protections.
Mexico introduced a major update to its national data protection framework, modernizing the privacy framework and strengthening expectations for how organizations process personal information.
Sub-Processors
Third-party service providers engaged by Symplicity to process data on behalf of our customers.
| Sub-Processor | Processing Activity | Location | Symplicity | CareerHub | Orbis | Contratanet |
|---|---|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Service Provider. Provides self-contained AI solution, Amazon Bedrock, for Generative AI and internal tooling. Cloud Service Provider. Provides self-contained AI solution, Amazon Bedrock, for Generative AI and internal tooling. | Regional | ✓ | ✓ | ✓ | |
| Microsoft Corporation (Azure) | Cloud Service Provider. Cloud Service Provider. | Regional | ✓ | |||
| Oracle Cloud Infrastructure | Cloud Service Provider. Cloud Service Provider. | Regional | ✓ | |||
| Sutherland Global Services | System administration level privileges, utilized only when explicitly authorized by client to resolve system issues. System administration level privileges, utilized only when explicitly authorized by client to resolve system issues. | Philippines | ✓ | ✓ | ✓ | ✓ |
| Cronofy | Application calendar syncs (Symplicity application to client's Outlook/Google Calendar). Application calendar syncs (Symplicity application to client's Outlook/Google Calendar). | USA / UK | ✓ |
| Sub-Processor | Processing Activity | Location | Symplicity | CareerHub | Orbis | Contratanet |
|---|---|---|---|---|---|---|
| iOpex | Quality Assurance Quality Assurance | India | ✓ | |||
| Asana | Project Management Project Management | USA | ✓ | |||
| HubSpot | Website & CMS Website & CMS | USA | ✓ | ✓ | ✓ | ✓ |
| Zendesk, Inc. | Ticketing system for support and maintenance services. Ticketing system for support and maintenance services. | USA | ✓ | ✓ | ✓ | ✓ |
| Microsoft 365 | Email, calendar, and audio/web conferencing. Email, calendar, and audio/web conferencing. | USA | ✓ | ✓ | ✓ | ✓ |
Privacy Documents
Access privacy documentation, agreements, and compliance resources.