Privacy Policy
Effective Date: 26th of August, 2026
This Privacy Policy explains how Success Sync Technologies Limited, a company registered in Ireland (company number 782705) with its registered office at Sunbury, Tower Hill, Glounthaune, Cork, T45 RH79, Ireland, trading as Success.co (“we,” “us,” or “our”), collects, uses, and protects your personal data when you use our services. By accessing or using our services, you agree to the practices described in this policy.
If you have any questions or need this policy in an alternative format, please contact us at privacy@success.co.
What This Privacy Policy Covers
This policy covers how we handle Personal Data, which is any information that identifies or relates to you. It applies to data we collect when you use our services, but not to third-party companies or individuals we don’t own or control.
Our Role
We handle Personal Data in two distinct capacities, and different parts of this policy apply to each.
As a controller: When you visit our website, sign up for an account, contact us, attend a demo, or receive our marketing, we decide how your Personal Data is used and we are the controller of that data.
As a processor: When a customer organisation uses Success.co, the data its users enter into the platform—V/TOs, Rocks, Scorecards, Issues, To-Dos, processes, accountability charts, meeting content, uploaded files, and the Personal Data those contain—is controlled by that customer organisation. We process it on their instructions under our agreement with them.
If you are a user within a customer organisation and want to access, correct, or delete data held in the platform, please contact your organisation’s account administrator in the first instance. We will assist our customer in responding to your request, but we cannot act on it independently where we are only the processor.
Personal Data We Collect
We collect the following categories of Personal Data:
Profile or Contact Data:
Name, email, physical address, and unique identifiers like passwords.
Payment Data:
Payment card type, billing address, and contact information.
Device/IP Data:
IP address, device ID, and browser/operating system information.
Web Analytics:
Interactions with our website, referring sources, and non-identifiable request IDs.
Social Network Data:
Email, phone number, and username if you connect via social media.
Other Identifying Information:
Information you voluntarily provide, such as emails or survey responses.
How We Collect Personal Data
We collect data from:
You: When you create an account, use our services, or contact us.
Automated Tools: Cookies and similar technologies track your interactions with our services.
Third Parties: Vendors and analytics providers help us improve our services.
Why We Collect Personal Data
We use your data to:
Provide, customize, and improve our services.
Process transactions and manage your account.
Communicate with you and respond to inquiries.
Market our services (with your consent).
Meet legal obligations and enforce our terms.
Our Lawful Bases (EEA and UK)
Where the GDPR or UK GDPR applies and we act as controller, we rely on the following lawful bases:
Performance of a contract: Creating and administering your account, providing the services, processing payments and managing billing.
Legitimate interests: Securing the services, preventing fraud and abuse, maintaining logs, product analytics and service improvement, and operating and improving AI Features. Our interest is in keeping the services secure, available, and improving.
Consent: Marketing communications, and cookies or similar technologies where consent is required.
Legal obligation: Meeting tax, accounting and other statutory requirements, and responding to lawful requests.
You may object to processing based on legitimate interests, and withdraw consent at any time, as described under Your Rights.
Where we act as processor for a customer organisation, that organisation is responsible for establishing the lawful basis for the Personal Data it puts into the services.
How We Share Personal Data
We may share your data with:
Service Providers: Hosting, payment processing, analytics, email delivery, and AI inference partners.
Business Partners: Companies we collaborate with for joint offers.
Legal Authorities: When required by law or to protect our rights.
Successors: In case of a merger, acquisition, or bankruptcy.
We do not sell your Personal Data for money. We do use advertising and analytics technologies that may share identifiers with third parties for advertising measurement and targeting, which some US state privacy laws treat as a “sale” or “share.” You can opt out at any time by contacting us at privacy@success.co.
Sub-processors
We use a small set of vendors to deliver our services. The current list—including each vendor’s purpose and the categories of data it handles—is maintained on our Security page. It includes our hosting, storage, CDN, payments, transactional email, analytics, and AI providers. We update that page before engaging a new sub-processor.
Artificial Intelligence Features
Success.co includes features that use artificial intelligence, including Ask AI and AI-assisted scoring, suggestions, drafting, and rewriting across Rocks, Issues, To-Dos, Scorecards, processes, and V/TO content (“AI Features”).
What is sent: AI Features are invoked by you or your colleagues. When invoked, we transmit the data needed to generate a response. Depending on the feature, this may include the prompt or instruction given, the item being worked on, and related content from your company’s workspace—such as V/TO content, Rocks, Scorecards and measurables, Issues, To-Dos, documented processes, and accountability chart entries, including the names and role titles they contain.
Who processes it: AI Features are delivered through OpenRouter, Inc. (United States), which routes each request to an underlying large language model provider. The model providers we currently use are listed on our Security page. We keep that list current.
Training: Neither OpenRouter nor any model provider is permitted to use your prompts, the content sent with them, or the responses generated, to train, fine-tune, or otherwise improve any AI or machine learning model. We do not do so either.
Retention: Model providers process requests under zero-data-retention terms and do not keep your content after returning a response. For performance, parts of a request may be held briefly in an ephemeral cache at the model provider—typically five minutes, and no longer than one hour—so that repeated requests can be answered more efficiently. Cached content is scoped to our account, used only to serve our own subsequent requests, and expires automatically. OpenRouter stores the full content of AI Feature requests, together with request logs and metadata, and makes this available to us for private review. That data is held encrypted at rest in an isolated storage environment with separate access controls, is visible only to two named administrators at Success.co, and is not used by OpenRouter for model training, analytics, or any other purpose. It is retained for a minimum of three months and may be retained for longer.
Location: OpenRouter and the model providers are located in the United States. See International Data Transfers below.
Accuracy: AI-generated output is produced by statistical prediction and can be inaccurate or incomplete. It is not professional advice and should be reviewed before being relied on. Our Terms of Service set out the terms that apply to AI Features.
Choice: AI Features are only used when you or a colleague actively invokes them. Your company can also turn AI Features off entirely: a user with full-access permission—Owner, Admin, Implementer, or Practice Manager—can disable them for your whole organisation in settings. While disabled, nothing is sent to OpenRouter or any model provider. Turning AI Features off does not delete request records already held; those are removed on our normal deletion cycle.
Sensitive data: Please do not enter special category data (such as health, biometric data, racial or ethnic origin, religious belief, or trade union membership), payment card details, government identification numbers, or information about children into AI Features.
Cookies and Similar Technologies
We use cookies and similar technologies to:
Strictly necessary: Keep you signed in, maintain your session, secure the services, and route traffic. These cannot be disabled.
Analytics: Understand how our services and website are used.
Marketing and advertising: Measure and target our advertising.
Where required by law, we set analytics and marketing cookies only with your consent, which you can give or withdraw at any time. You can also manage cookies through your browser settings, though disabling strictly necessary cookies will limit functionality.
Data Security
We maintain technical and organisational measures designed to protect Personal Data, including encryption in transit (TLS) and at rest (AES-256), database-level tenant isolation using row-level security, federated authentication only (we do not store passwords), role-based access control, and rate limiting. Full detail is on our Security page. No system can be guaranteed completely secure.
Data Retention
We retain Personal Data for as long as needed for the purpose it was collected, and then delete or anonymise it. In practice:
Account and workspace content: For the life of the account. Deleted records are soft-deleted and purged after 30 days.
Workspace content after account termination: Deleted within 30 days of termination, or earlier on request.
Application and infrastructure logs: 30 days. Administrative audit logs are retained for up to 400 days.
Database backups: 30 days. Point-in-time recovery window: 7 days.
Transactional email content, including meeting summaries and notification content: 45 days.
Product analytics: Up to 90 days.
AI Feature requests, responses and logs held by OpenRouter: Minimum of three months, and may be retained for longer.
Billing and transaction records: 6 years, as required by Irish tax law.
Marketing contact records: Until you unsubscribe, plus a suppression record to honour your opt-out.
Because our database backups are also retained for 30 days, deleted data is fully removed from our systems—including backups—within 30 days.
Children’s Privacy
Success.co is a business tool intended for use by adults in a workplace context. It is not directed at children, and we do not knowingly collect Personal Data from anyone under 16. If you believe a child has provided us Personal Data, contact us at privacy@success.co and we will delete it promptly.
Your Rights
Depending on where you live, you may have the right to:
Access the Personal Data we hold about you and receive a copy.
Have inaccurate data corrected.
Have your data deleted.
Restrict or object to certain processing, including processing based on our legitimate interests.
Object to direct marketing at any time.
Receive your data in a portable, machine-readable format.
Withdraw consent where our processing relies on it, without affecting processing already carried out.
Not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. We do not make such decisions about you. AI Features generate suggestions for people to review; they do not make decisions.
To exercise these rights, contact us at privacy@success.co. We will respond within one month, and will tell you if we need longer. We may need to verify your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.
If you are a user within a customer organisation, see Our Role above—for content inside the platform, please contact your account administrator.
Complaints. If you are in the EEA, you have the right to lodge a complaint with a supervisory authority. Our lead authority is the Irish Data Protection Commission (www.dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28). You may also complain to the authority where you live or work. If you are in the UK, you may complain to the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.
International Data Transfers
We are established in Ireland, and our infrastructure is hosted in the United States. Personal Data we process is therefore transferred outside the European Economic Area and the United Kingdom, including to the United States.
Where we transfer Personal Data out of the EEA or UK, we rely on one or more of the following safeguards:
The European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies.
The EU–US Data Privacy Framework and its UK Extension, where the recipient is certified under it.
An adequacy decision covering the recipient country.
We apply supplementary technical measures to protect transferred data, including encryption in transit and at rest.
You can ask which safeguard applies to a particular transfer by contacting us at privacy@success.co.
Changes to This Policy
We may update this policy from time to time. If we make significant changes, we will notify you via email or through our services. Continued use of our services after changes means you accept the updated policy.
Contact Us
If you have questions about this policy or your data, please contact us at:
Privacy enquiries and rights requests: privacy@success.co
Security: security@success.co
General support: support@success.co
Registered address: Success Sync Technologies Limited (company no. 782705), Sunbury, Tower Hill, Glounthaune, Cork, T45 RH79, Ireland.
US office: 1422 Delgany Street, Suite 200, Denver, CO 80202, USA.


