This Privacy Policy explains how legal name of the organisation — to be confirmed ("Support Central", "SC", "we", "us") collects, uses and protects personal data when you use:
- our websites — this site (synchsupport.org), the E&T Academy (academy.synchsupport.org) and the Community Relations portal (comrel.synchsupport.org);
- our Discord bots — the Academy bot and ComRel's bot, Doodle — in the Support Central Discord servers and in partner communities' servers;
- our Discord servers, where the bots and our staff operate.
It is written to be read. If anything here is unclear, ask us — see "Contact us" at the bottom.
If you are in the UK, the European Economic Area or Switzerland, our GDPR Notice sets out our legal bases and your rights in more detail. Use of our services is also covered by our Terms & Conditions.
Who we are
Support Central is a volunteer-run community network. legal name of the organisation — to be confirmed is the data controller for the personal data described here. The E&T Academy and the Department of Community Relations (ComRel) are parts of Support Central, not separate organisations.
Contact us about privacy at privacy contact email — to be confirmed, or open a support ticket in our Discord server.
The short version
- You sign in to our portals with Discord. We never see or store your Discord password.
- We keep what we need to run the community: your Discord ID and name, what you do in our portals, and the records moderation, training and volunteering need.
- Our bots read messages in the servers they're in, to do their jobs (counting, games, replies, wellbeing checks). They don't use AI, and they only keep message text in the specific cases listed below.
- We don't sell your data, we don't show adverts, and this website sets no tracking cookies.
- You can ask to see, correct or delete your data at any time.
What we collect, and where it comes from
Your Discord identity. When you sign in with Discord, Discord tells us your user ID, username, display name and avatar. For the Academy and ComRel portals we also read your roles in our own servers (to decide what you can access); for the Community Programs provider portal we read the list of servers you're in and your permissions there (to confirm you run a partner community). We never receive your email address, password or private messages.
E&T Academy learning records. Courses, pathways and simulations you enrol in; your progress; exam attempts and answers; grades and instructors' feedback; certificates; course ratings and comments; help requests and the chat with staff; simulation transcripts; content reports you file; and learner-access applications (which include how long you've been in our server or a partner's server, and whether you hold a qualifying role).
Certificates are public by design. Every certificate has a verification page showing your name, the course, your score (where there is one) and the issue date, so anyone you give the link or reference to can check it's real.
Guild Teams. If you join a partner community's team in the Academy, that community can see your progress and certificates on the training it assigns you. It sees more — your other certificates, or your scores — only if you switch that on. See the Terms for the full rules; you can leave a team at any time.
Volunteer (staff) records. If you apply to volunteer or join the team, we keep your application and its answers, your staff file (role, team, region, time zone, start date), leave-of-absence requests and their reasons, resignations, promotions, onboarding progress, weekly reports, tasks and quota results, and notes management adds about your work.
Moderation and support. Support tickets and their full transcripts; moderation actions taken against an account (what, why, by whom); appeals; and reports you make.
Community features. Event sign-ups, giveaway entries and winners, suggestions, questions you ask management (anonymous by default — management sees the question, not who asked), payout requests, reminders you set with Doodle, and your economy activity (coins, games, bonds, fines) — the economy balance itself is held by UnbelievaBoat, a third-party Discord bot.
Messages our bots read. Our bots need to read messages in the channels they're in to work. They process message text in real time and keep only:
- the number of messages each member sends per day and server — used for staff activity quotas and community statistics, not the messages themselves;
- support ticket transcripts (see above);
- messages that mention Doodle but that he didn't understand — the last 200, for up to 30 days, so we can teach him new replies;
- wellbeing alerts (see next).
Wellbeing ("care") checks. Doodle looks for messages suggesting someone may be in distress or at risk. When one matches, he points the person to support resources, removes their message from the public channel for their privacy, and alerts our moderators — including a copy of what was written — so a trained person can check in. This can involve sensitive information about someone's health. We use it only to look after the person concerned, and it is seen only by our moderation team.
Technical data. Our portals keep a sign-in cookie (see "Cookies" below) and a record of when you last signed in. Like any website, our servers and our network provider, Cloudflare, process your IP address to deliver pages and protect against abuse.
Discord announcements. Some events are posted automatically to channels in our Discord servers — for example new Academy enrolments and certificates, and staff milestones. These posts can include your name.
Why we use it (and our legal basis)
We use your data to run our community and services: to let you sign in, learn, volunteer and take part; to keep our servers safe and moderate them fairly; to answer your support tickets and appeals; to run training, certificates and staff quotas; and to protect people who may be at risk. Our GDPR Notice sets out the legal basis for each.
We do not make decisions about you based solely on automated processing that have a legal or similarly significant effect. Exams are marked automatically, but written answers are graded by our Examiners, and any decision about access, moderation or volunteering is made by a person.
Who we share it with
We don't sell personal data. We share it only as needed to run our services:
- Discord Inc. — sign-in, and everything our bots do in Discord. Discord is an independent controller of the data on its own platform.
- Cloudflare, Inc. — delivers and protects our websites.
- UnbelievaBoat — the Discord economy bot our servers use; we send it Discord user IDs and amounts to pay out rewards.
- Partner communities — only what the Terms and your own choices allow (for example Guild Teams progress, or a partner confirming you're in their server when you apply for learner access through them).
- Anyone you give a certificate link or reference to — see "Certificates are public by design".
- Authorities — only where the law requires us to, or where someone's life or safety is at risk.
Some of these providers are based outside the UK and EEA, including in the United States. Where that's the case, we rely on the safeguards the law requires — see the GDPR Notice.
The Academy's code can use an AI provider to play the "difficult user" in solo practice simulations. This feature is switched off. If we ever turn it on, we'll update this policy first and say so on the simulation page.
How long we keep it
We keep personal data only as long as we need it:
- Sign-in sessions — until you sign out, or 8 hours.
- Doodle's "didn't understand" messages — up to 30 days (and only the latest 200).
- Academy learning records and certificates — while you use the Academy. Certificates stay verifiable unless you ask us to remove them or they're revoked.
- Staff files and volunteer records — while you volunteer, and for up to 2 years after you leave, so we can confirm your service and handle any disputes.
- Unsuccessful volunteer and learner applications — up to 12 months.
- Support tickets, moderation records and appeals — up to 2 years after they're closed, or longer where a matter is still open or we need them to keep the community safe.
- Wellbeing alerts — only as long as needed to support the person concerned.
- Daily message counts — up to 2 years.
You can ask us to delete your data sooner — see "Your rights".
Your rights
You can ask us to:
- give you a copy of your data;
- correct anything that's wrong;
- delete your data (we may need to keep some records — for example a moderation record needed to keep others safe — and we'll tell you if so);
- restrict or object to how we use it;
- give you your data in a portable format.
Email privacy contact email — to be confirmed or open a support ticket in our Discord. We'll reply within one month, and we may need to confirm you own the Discord account first. If you're unhappy with how we've handled your data, you can complain to data protection authority — to be confirmed — though we'd appreciate the chance to put it right first.
Cookies and similar technology
This website (synchsupport.org) sets no cookies. It remembers your light/dark theme choice in your browser's local storage, which never leaves your device. It makes no requests to third parties other than our network provider, Cloudflare.
Our portals set one strictly necessary cookie each, which keeps you signed in: academy3.sid (E&T Academy) and comrel.sid (ComRel). These can't be read by scripts on the page and expire after 8 hours. The portals also keep small preferences in your browser's local storage (theme, dismissed tips, which tour steps you've seen). We use no analytics or advertising cookies anywhere, so there's nothing to opt in or out of.
Children
Discord requires its users to be at least 13 (older in some countries), and so do we. Our services are not designed for younger children. Some Academy content is marked as mature and shows a warning first. If you believe a child under 13 has given us their data, contact us and we'll delete it.
Security
Our data is stored on our own server, where our server is located — to be confirmed, behind Cloudflare. Access is limited to the staff who need it, by role, and actions in our portals are recorded in an audit log. Sign-in is handled by Discord, so we never hold passwords. No system is perfectly secure; if we ever have a breach that puts you at risk, we'll tell you and the regulator as the law requires.
Changes
If we change this policy we'll update the version and date at the top, and for important changes we'll announce it in our Discord.
Contact us
legal name of the organisation — to be confirmed · privacy contact email — to be confirmed · or open a support ticket in our Discord server.