Legal information
Privacy Policy - Draft for Legal Approval
Version 1.1 · Updated 01 Oct 2026
PRIVACY POLICY
Draft for legal review - replace controller/contact details before publication.
Version 1.1
1. WHO WE ARE
[INSTITUTION LEGAL NAME] ("we", "us") operates this learning platform. The data controller address is [REGISTERED ADDRESS]. Privacy contact: [PRIVACY EMAIL].
2. DATA WE COLLECT
We may collect identity and contact details, account credentials, Student ID, country/language, enrollment and batch data, attendance, coursework, assessment and examination records, certificates, payment/invoice information, support messages, security logs and information submitted in documents. We collect only what is needed for the stated purpose.
3. WHY WE USE DATA
We use data to create and secure accounts, process applications and payments, deliver teaching and assessments, maintain academic records, issue and verify certificates, provide support, prevent fraud and abuse, meet legal/accounting duties, protect our systems and communicate service information. We do not use student academic data for unrelated advertising.
4. LEGAL BASES
Depending on the activity, processing is based on contract or steps requested before contract, legal obligation, legitimate interests, vital interests where applicable, or consent. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.
5. SHARING AND PROCESSORS
We use authorised providers for hosting, private file storage, email/SMS, payments, support, security, plagiarism checking and other necessary services. Each provider must be assessed, documented in our processor register and bound by appropriate data-processing terms. We do not sell personal data.
6. INTERNATIONAL TRANSFERS
Some providers may process data outside your country. Before use, we document the destination, transfer mechanism and safeguards required by applicable law, such as an adequacy decision or approved contractual clauses.
7. RETENTION
We retain academic results and certificate verification records for the minimum period required for legitimate academic, legal and verification purposes. Application, payment, audit, security-log, deletion-request and document retention periods are listed in our GDPR Operations Runbook. We securely delete or anonymise data when the period expires unless a documented legal hold applies.
8. YOUR RIGHTS
Subject to applicable law, you may request access, correction, portability/export, restriction, objection or deletion. Use the Data Privacy area in your portal or contact [PRIVACY EMAIL]. We may retain limited records where required for legal, accounting, fraud-prevention or certificate-verification purposes and will explain the reason.
9. SECURITY
We use access controls, authentication, least privilege, audit logging, secure transport, private storage for sensitive documents, backups and incident-response procedures. No internet service is risk-free; suspected incidents should be reported immediately to [SECURITY EMAIL].
10. CHILDREN
The service is intended for users who can lawfully enter the relevant education agreement. Where local law requires parental or guardian involvement, the institution will use an appropriate verification process.
11. COMPLAINTS
Contact [PRIVACY EMAIL] first. You may also complain to the supervisory authority in the country where you live or work or where you believe an infringement occurred.
12. CHANGES
We publish the current version and effective date on this page. Material changes will be communicated through an appropriate channel.
Draft for legal review - replace controller/contact details before publication.
Version 1.1
1. WHO WE ARE
[INSTITUTION LEGAL NAME] ("we", "us") operates this learning platform. The data controller address is [REGISTERED ADDRESS]. Privacy contact: [PRIVACY EMAIL].
2. DATA WE COLLECT
We may collect identity and contact details, account credentials, Student ID, country/language, enrollment and batch data, attendance, coursework, assessment and examination records, certificates, payment/invoice information, support messages, security logs and information submitted in documents. We collect only what is needed for the stated purpose.
3. WHY WE USE DATA
We use data to create and secure accounts, process applications and payments, deliver teaching and assessments, maintain academic records, issue and verify certificates, provide support, prevent fraud and abuse, meet legal/accounting duties, protect our systems and communicate service information. We do not use student academic data for unrelated advertising.
4. LEGAL BASES
Depending on the activity, processing is based on contract or steps requested before contract, legal obligation, legitimate interests, vital interests where applicable, or consent. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.
5. SHARING AND PROCESSORS
We use authorised providers for hosting, private file storage, email/SMS, payments, support, security, plagiarism checking and other necessary services. Each provider must be assessed, documented in our processor register and bound by appropriate data-processing terms. We do not sell personal data.
6. INTERNATIONAL TRANSFERS
Some providers may process data outside your country. Before use, we document the destination, transfer mechanism and safeguards required by applicable law, such as an adequacy decision or approved contractual clauses.
7. RETENTION
We retain academic results and certificate verification records for the minimum period required for legitimate academic, legal and verification purposes. Application, payment, audit, security-log, deletion-request and document retention periods are listed in our GDPR Operations Runbook. We securely delete or anonymise data when the period expires unless a documented legal hold applies.
8. YOUR RIGHTS
Subject to applicable law, you may request access, correction, portability/export, restriction, objection or deletion. Use the Data Privacy area in your portal or contact [PRIVACY EMAIL]. We may retain limited records where required for legal, accounting, fraud-prevention or certificate-verification purposes and will explain the reason.
9. SECURITY
We use access controls, authentication, least privilege, audit logging, secure transport, private storage for sensitive documents, backups and incident-response procedures. No internet service is risk-free; suspected incidents should be reported immediately to [SECURITY EMAIL].
10. CHILDREN
The service is intended for users who can lawfully enter the relevant education agreement. Where local law requires parental or guardian involvement, the institution will use an appropriate verification process.
11. COMPLAINTS
Contact [PRIVACY EMAIL] first. You may also complain to the supervisory authority in the country where you live or work or where you believe an infringement occurred.
12. CHANGES
We publish the current version and effective date on this page. Material changes will be communicated through an appropriate channel.
