Privacy policy
Data we process
We process account identity and contact details, authentication-provider records, profile choices, course enrolments, progress, assessment answers and scores, repository evidence, certificates, community contributions, consent history, rights requests, contact messages, and pseudonymised technical security logs.
Purposes and legal bases
Account, learning, assessment, and certification processing is necessary to provide the requested service. Security and support processing serves our legitimate interest in operating and protecting the platform. Public profiles and optional product updates depend on a choice you can withdraw in your privacy center.
Service providers and recipients
The platform may use Google for single sign-on, Microsoft Graph for service email, and European hosting infrastructure needed to deliver, back up, and secure the application. Authorized academy staff access data only for course delivery, support, assessment, security, and rights-request handling.
Retention
Processed contact messages are scheduled for deletion after 365 days, read notifications after 180 days, and security audit events after 365 days. Completed privacy-request evidence is anonymised after six years. Account erasure removes identifying and free-text data while retaining anonymised academic and certificate evidence where integrity and verification require it.
Your rights
You may request access, rectification, erasure, restriction, portability, or objection. Signed-in learners can download a portable JSON copy and submit a tracked request from the privacy center. Identity verification may be required, and the normal response target is 30 days.
Cookies
We use necessary session and security cookies for authentication and form protection. We do not currently use advertising cookies.