We use essential cookies and, with your consent, analytics to improve LearnWize. Learn more
Your security officer, privacy officer, and buyer get what the vendor review asks for: data processing, rollout, support, a DPA, and an evidence dossier after the briefing. The platform proves per employee that the knowledge duty under the EU AI Act, the Dutch Cybersecurity Act (NIS2), the Dutch AML act (Wwft), and DORA is met.
DPA + TOMs
available for review
EU-only
data hosting
Invite-only
controlled provisioning
The topics procurement teams use to evaluate a compliance evidence platform, and how LearnWize stacks up.
Data residency
EU-only hosting and database infrastructure
GDPR, Schrems II, personal data, and works council expectations make EU data residency critical for a dossier that records per employee which training duty is met.
Compliance & certifications
GDPR-focused DPA, TOMs, subprocessor list, retention matrix, and security FAQ
Your security officer needs verifiable documentation, not claims.
Integrations
SCORM 1.2 export for your LMS now, xAPI/cmi5 on the roadmap; controlled CSV bulk provisioning; SSO/SAML scoped per enterprise rollout
Keeps first rollout practical while giving IT a clear path for identity-provider integration.
Scope model
Seat volume, support level, implementation work, and sector needs are documented per rollout
Procurement gets clarity on scope, responsibilities, and the expansion path before rollout.
SLA & support
Contract-specific support, escalation contacts, incident workflow, and optional SLA terms
Enterprise commitments should match the signed scope, support model, and rollout risk.
Content ownership
Customer retains ownership of custom content; export right at contract end
Offboarding should be clear before rollout, including exports, deletion, and evidence retention.
The controls and evidence we can review with your privacy, security, and procurement teams.
Invite-only access, organization-scoped roles, server-side admin operations, code-login invitations, and audit logging for provisioning actions.
Core platform data is hosted on EU-based infrastructure. The DPA and subprocessor list confirm vendor roles, locations, and transfer safeguards.
Data Processing Agreement, TOMs, subprocessor list, retention matrix, and data-subject request assistance for customer-controlled platform data.
Release checks, health monitoring, documented incident response, breach escalation to the customer without undue delay, and contract-specific support terms.
We first confirm your rollout, tenant, and support scope, then share the applicable privacy, security, legal, and procurement documents.
learnwize
Request the documents for your vendor review
Scoped after briefing
30 minutes to walk through all RFP questions, demo the security stack, and define the rollout scope.
The topics that come up most often in vendor evaluations.