Privacy Policy
Our at-home learning programs are broken up into weekly lesson plans and require very little setup.
Privacy Policy
Updated August 26, 2026
1. PURPOSE AND SCOPE
This policy describes how Sycamore Informatics (Sycamore) collects, uses, discloses, processes, protects, and retains personal information relating to individuals (“Personal Data”) when you visit or interact with our Websites, contact us, request information about our products or services, or use our software products or services.
This Privacy Statement applies to all Sycamore Informatics staff, Affiliates, Websites, and Services. It describes our privacy practices for collecting, sharing, and processing Personal Data and how you can learn about your rights and choices regarding processing your Personal Data
Human Resources (HR) Data Scope: This Privacy Policy applies to Non-HR Personal Data (Website Visitors, Business Contacts, and Customer Study / Product Data). Human Resources (HR) Data of Sycamore personnel in the EU, UK, or Switzerland is governed separately under internal HR privacy statements made available to personnel.
2. DATA PRIVACY FRAMEWORK COMMITMENT AND PRINCIPLES ADHERENCE
Sycamore Informatics, Inc. complies with the EU-U.S. Data Privacy Framework (Previously Privacy Shield Framework), Swiss-U.S. Data Privacy Framework (Previously Privacy Shield Framework) and UK Extension to the EU-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union, Switzerland and the United Kingdom (and Gibraltar) to the United States. These frameworks provide participating organizations with a reliable mechanism for personal data transfers to the United States from the European Union, Switzerland and the United Kingdom (and Gibraltar) while ensuring data protection that is consistent with applicable data protection requirements.
Sycamore Informatics, Inc has certified to the U.S. Department of Commerce that it adheres to the Data Privacy Framework Principles with respect to Personal Data transferred from the European Union, the United Kingdom (and Gibraltar), and Switzerland to the United States in reliance on the applicable Data Privacy Framework. If there is any conflict between the terms in this privacy policy and the Data Privacy Framework Principles, the Data Privacy Framework organizations shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visithttps://www.dataprivacyframework.gov. A list of Data Privacy member organizations can be found at:https://www.dataprivacyframework.gov/list.
Sycamore commits to respond promptly to inquiries and requests by the U.S. Department of Commerce International Trade Administration (ITA) for information relating to the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
3. CATEGORIES OF PERSONAL DATA COLLECTED
When contacting Sycamore or requesting information from the Sycamore website, we may collect information such as your email. When accessing secured areas for our services, such as the collaboration site, Sycamore Software as Services for our product, and online user guides, we may collect information such as full name, company name, email address, phone number, login ID, and password.
Sycamore collects business contact details from our customers, suppliers, and other business partners in the EU, UK, and Switzerland (“EU, UK, and Swiss Business Contacts”), including name, job title, company affiliation, and contact details. From our website, visitors who request additional information about our products or who wish to access secure areas of our website, we collect name, company name, email address, mailing address, phone number, portal login ID, and password.
Categorization of Covered Data:
Website Visitor Data: Technical information, cookies, IP addresses, browser types, and usage data collected via our website.
Business Contact Data (Non-HR Data): Professional contact details of customer representatives, partners, suppliers, and prospective leads.
Customer Study / Product Data: Personal data provided or uploaded by corporate customers to our cloud products for processing on their behalf.
Data Controller vs. Processor Roles: When Sycamore provides its software to a Customer and processes Personal Data subject to GDPR on the Customer's behalf, Sycamore acts as a Data Processor, and the Customer acts as the Data Controller. The Customer is responsible for determining the purposes and means of processing and for responding to requests from individuals concerning their Personal Data. Sycamore processes Personal Data provided by or uploaded by customers strictly as instructed by them and does not directly control or own that Personal Data.
Sycamore Informatics does not store any Protected Health Information (PHI) in its products for user authentication, audit trail, or user notifications. Sycamore’s customers may store this information as part of their data and are subject to their privacy policies.
Sycamore Informatics has a policy on cookies collected by its website. See Cookie Policy for details.
4. PURPOSES OF DATA COLLECTION AND PROCESSING
Sycamore Informatics uses personal information collected from our Website to perform the services requested. This may include the following examples:
Gather support issues and requests from customers
Obtain contact information from prospective customers who visit our website
User authentication and identification within our products
Administer your account
Send requested product or service information
Send product updates
Send marketing communications
Respond to questions and concerns
Improve our website and marketing efforts
We collect and process personal data from website visitors and customers in the EU, UK, and Switzerland for the following specific purposes:
Service Delivery: Providing, maintaining, and improving our products and services.
Customer Data Processing: Processing personal data on behalf of our corporate customers in accordance with our contractual obligations.
Business Operations & Communications: Communicating with business partners regarding commercial matters, contract management, and general administration.
Marketing & Information: Sharing information about our services, updates, and relevant offerings.
Legitimate Business Interests: Conducting day-to-day operational, security, and administrative tasks necessary to support our legal and legitimate business objectives.
5. THIRD-PARTY DISCLOSURES AND ONWARD TRANSFER LIABILITY
We may share or disclose your Personal Data with third parties as described in this Privacy Statement.
We may provide your Personal Data to companies or their websites (such as our Customer Service Portal Provider) that provide services to help us with business activities, such as customer support for our Services. These companies may process your Personal Data only as necessary to provide these services to us and in accordance with our instructions and applicable contractual obligations.
To help Sycamore provide SaaS and Professional Services to our customers, Sycamore may share Personal Data with third-party partners only as necessary to perform services to Sycamore and are subject to appropriate contractual, confidentiality, privacy, and security obligations. The provisions of our Customer and partner agreements cover such transfers to third parties. A list of the processors can be requested by sending your request to privacy@sycamoreinformatics.com.
We may also disclose your Personal Data:
As required by law, such as to comply with a subpoena or similar legal process,
When we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a lawful government request,
To any other third party with your prior consent to do so.
Sycamore does not publish or sell any personal data.
Onward Transfer Liability
Sycamore is responsible for the processing of personal data it receives under the Data Privacy Frameworks and subsequent transfers to any third party acting as an agent on its behalf. Sycamore complies with the Data Privacy Framework Principles for all onward transfers of personal data from the EU, UK, and Switzerland, including the onward transfer liability provisions.
Sycamore Informatics remains liable under the DPF Principles if an agent processes personal data covered by this Privacy Statement on its behalf in a manner inconsistent with the DPF Principles, unless Sycamore Informatics proves that it is not responsible for the event giving rise to the damage.
Accountability for Data Transferred to Third Parties (Controllers & Agents): Prior to transferring personal information to a third party acting as a controller, Sycamore complies with the Notice and Choice Principles and enters into a contract providing that such data may only be processed for limited and specified purposes consistent with individual consent, ensuring the recipient provides the same level of protection as the DPF Principles.
When transferring personal data to a third party acting as an agent, Sycamore:
Transfers such data only for limited and specified purposes;
Ascertains that the agent is obligated to provide at least the same level of privacy protection as required by the DPF Principles;
Takes reasonable and appropriate steps to ensure the agent effectively processes personal data in a manner consistent with Sycamore's DPF obligations;
Requires the agent to notify Sycamore if it determines it can no longer meet its protection obligations;
Upon notice, takes reasonable and appropriate steps to stop and remediate unauthorized processing; and
Provides a summary or representative copy of the relevant privacy provisions of its contract with that agent to the U.S. Department of Commerce upon request.
Transfer of Business Ownership
If Sycamore is involved in a merger, acquisition, or sale of all or a portion of our assets, personal information is considered to be among the business assets that are subject to transfer. We are committed to safeguarding the confidentiality of your personal information. Impacted users will be notified via email and/or a prominent notice on our Website of any change in ownership or uses of your Personal Data, as well as any choices you may have regarding your Personal Data. As part of the transfer of Business Ownership, the new entity's privacy policy may supersede this policy.
6. DATA INTEGRITY, RETENTION, AND CUSTOMER DATA
Customers may provide or upload data for hosting and processing purposes (“Customer Data”). Sycamore will not use, review, share, distribute, or reference any such Customer Data except as provided in the Customer Agreement for products and services , including applicable Data Processing Agreement or as may be required by law. Per the agreement, we may access Customer Data only to provide the SaaS or Professional Services, prevent or address Service or technical problems at a Customer’s request in connection with Customer support matters, or as may be required by law.
Sycamore will retain your information (including Customer Data we collect on behalf of our Customers) for as long as the Customer’s account is active or as needed to provide you with SaaS and Professional Services, subject to the terms of our agreements with the applicable customer, and as necessary to comply with our legal obligations, resolve disputes, enforce our agreements, or as otherwise reasonably necessary for our business purposes.
7. INDIVIDUAL RIGHTS, CHOICES, AND GDPR DISCLOSURES
GDPR Compliance
For Customers: Where applicable, Sycamore’s data processing commitments to its Customers comply with the GDPR and other applicable data protection laws. Sycamore Customers may e-sign and receive a countersigned copy of Sycamore’s Data Processing Addendum (which contains Standard Contractual Clause and a description of our technical and organizational measures).
The applicable Data Processing Agreement and GDPR Addendum sets out the scope, subject matter, duration, and purpose of Sycamore’s data processing, as well as the types of personal data processed and rights of data subjects. It also details Sycamore’s confidentiality obligations as a data processor, cooperation regarding inquiries from data subjects and authorities, international data transfers, Sycamore’s sub-processors, and the location and deletion of data. It contains our security measures and personal data breach indemnity commitments.
For Individuals: This section provides additional information about how Sycamore processes Personal Data that is subject to the EU General Data Protection Regulation (“GDPR”) and the UK Data Protection Regulation (“UK GDPR”). It supplements the information contained in the rest of our Privacy Statement and applies where GDPR or UK GDPR applies to Sycamore’s processing of Personal Data.
Our Data Protection Officer and Information Security Officer have assessed our obligations as a data controller for Sycamore OpenData and Sycamore Oncology Link data products and as a data processor for the rest of our product suite, Sycamore CRM, Sycamore Nitro, Sycamore Andi, Sycamore Vault, and Sycamore Network. Operating in a way that fosters trust and transparency, we appreciate the GDPR benefits of improving our business, becoming more efficient, and creating better relationships with our customers and those whose data they collect.
Sycamore will process Personal Data only if and to the extent that at least one of the following applies:
You have given consent to the processing of your personal data for one or more specific purposes;
processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract;
processing is necessary for compliance with a legal obligation to which Sycamore is subject; or
processing is necessary for the purposes of the legitimate interests pursued by Sycamore or by a third party, except where such interests are overridden by your interests or your fundamental rights and freedoms.
When Sycamore collects personal data from you, we will make sure that you are aware of the purposes of the processing for which the personal data are intended as well as the legal basis for the processing, if applicable, the legitimate interests pursued by Sycamore or by a third party; the recipients or categories of recipients of the personal data, if any; and where applicable, the appropriate or suitable safeguards to protect your personal data. We will also inform you of the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period; your right to request access to and rectification or erasure of personal data or restriction of processing or to object to processing as well as the right to data portability; if processing is based on consent, the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; your right to lodge a complaint with a supervisory authority; whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract with us, as well as whether you are obliged to provide the personal data and of the possible consequences of failure to provide such data; and the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for you.
If Sycamore intends to further process the personal data for a purpose other than that for which the personal data were collected, we will provide you, prior to that further processing, with information on that other purpose and with any relevant further information.
You may exercise your data subject rights under Articles 15 to 22 of the GDPR by contacting privacy@sycamoreinformatics.com. Sycamore will provide information on action taken on a request under Articles 15 to 22 to you without undue delay and, in any event, within one month of receipt of the request.
If Sycamore needs to extend by two further months where necessary, taking into account the complexity and number of the requests that require more time, then Sycamore will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay. If you make the request by electronic form, we will provide the information to you by electronic means where possible, unless otherwise requested by you.
If Sycamore does not take action on your request, we will inform you without delay and, at the latest, within one month of receipt of the request of the reasons for not taking action and your possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
For more information on GDPR, please visit: https://gdpr.eu/what-is-gdpr/
Choices and Opt-Out
EU, UK, and Swiss website visitors have the right to access the personal data we process about them. To access your personal data, please send a request to privacy@sycamoreinformatics.com.
Because Sycamore may have limited access to personal data our customers store in our services, if you wish to request access, limit use, or disclosure, please provide the name of the Sycamore customer who provided your personal data to our services. We will refer your request to that customer and support them as needed in responding to your request.
EU, UK, and Swiss Business Contacts may choose to change personal data, unsubscribe from email lists, or cancel an account by contacting privacy@sycamoreinformatics.com.
EU, UK, and Swiss website visitors may choose to unsubscribe from our marketing communications using the unsubscribe mechanism in our emails.
8. LAWFUL REQUESTS FOR DISCLOSURE
Sycamore may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If Sycamore leaves the DPF program, Sycamore will annually affirm to the ITA its commitment to apply the DPF Principles to personal information received under the DPF program if it chooses to retain such data; otherwise, it must provide adequate protection for the information by another authorized means.
9. DISPUTE RESOLUTION, ENFORCEMENT, AND BINDING ARBITRATION
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Sycamore commits to resolving DPF Principles-related complaints about our collection and use of your personal information. Sycamore commits to respond to direct individual complaints regarding DPF compliance within 45 days of receipt.
EU, UK, and Swiss individuals with inquiries or complaints regarding our Data Privacy Framework policy should first contact Sycamore at privacy@sycamoreinformatics.com.
For any unresolved privacy or data use concerns that we have not addressed satisfactorily within 45 days, please contact our U.S.-based independent dispute resolution provider free of charge:
American Arbitration Association – ICRD-AAA at https://go.adr.org/dpf_irm.html
FTC Enforcement Authority
Sycamore’s commitments under the Data Privacy Framework are subject to the investigatory and enforcement powers of the United States Federal Trade Commission (FTC).
Binding Arbitration Option
Under certain conditions, more fully described on the Data Privacy Framework website at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
10. VERIFICATION AND SELF-ASSESSMENT
Sycamore verifies its adherence to the Data Privacy Framework Principles through an annual self-assessment process. This self-assessment confirms that the Privacy Policy is accurate, comprehensive, prominently displayed, completely implemented, and accessible. This policy can also be reviewed during an audit of Sycamore Informatics and through links on the Sycamore Informatics website.
11. CHANGES TO PRIVACY POLICY AND CONTACT INFORMATION
Sycamore Informatics reserves the right to modify this Privacy Policy at any time.
Sycamore strives to maintain communication with our current and prospective customers. Our Chief Privacy Officer will assist you with questions or inquiries.
Michael Owings
Chief Privacy Officer
privacy@sycamoreinformatics.com
Sycamore Informatics, Inc.
271 Waverley Oaks Rd, #103
Waltham, MA 02452
United States

