1. Introduction
Your privacy is important to us. Cyber Security Rtain (“we,” “our,” “us”) is committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable privacy laws. This Privacy Policy explains what data we collect, how we use it, and the rights you have regarding your personal data.
2. What Data We Collect
- Identification & login information: Name, email address, username, and login credentials.
- Company association: The organization you are linked to for training and reporting purposes.
- Training activity data: Course enrollments, activity logs, progress tracking, completion status, test results, certifications, and interaction data within the LMS.
- Technical information: Device type, IP address, browser type, and usage statistics (collected automatically to ensure platform security and functionality).
3. How We Use Your Data
We process your data only for legitimate purposes, including:
- Providing services: To deliver cybersecurity training content, enable course access, and manage your LMS account.
- Tracking & reporting: To monitor learning progress, record results, and generate reports for your company administrators for compliance and workforce development.
- Platform improvement: To analyze usage trends and enhance system functionality, security, and user experience.
- Legal & compliance obligations: To meet legal requirements or respond to lawful requests from authorities.
We do not sell or share your personal data with third parties for marketing purposes.
4. Legal Basis for Processing
- Performance of a contract: To provide training services under the agreement with your employer.
- Legitimate interests: To improve and secure our LMS services.
- Legal obligations: To retain training records when required for compliance, regulatory, or auditing purposes.
- Consent: When explicitly required, such as opting into optional communications.
5. Data Retention
We retain personal data for as long as your account remains active or as required to fulfill the purposes outlined in this policy. Training history may be stored beyond account deactivation when necessary for compliance, certification validation, or corporate reporting.
If you request permanent deletion of your data, we will honor it unless retention is legally required.
7. Your Rights Under GDPR
- Right of access – Request a copy of the personal data we hold about you.
- Right to rectification – Request corrections to inaccurate or incomplete information.
- Right to erasure (“right to be forgotten”) – You may deactivate your account at any time. This restricts access and stops further processing of your data. Training records may be retained for compliance or reporting. If you want all your data permanently deleted, contact us at privacy@example.com.
- Right to restriction of processing – Request that we limit how your data is used under certain circumstances.
- Right to data portability – Request a copy of your data in a structured, commonly used, machine-readable format.
- Right to object – Object to processing based on legitimate interests or direct communications (if applicable).
- Right to lodge a complaint – You may complain to your local data protection authority if you believe your rights are being violated.
8. International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your information.
9. Contact Us
If you have questions about this policy or want to exercise your rights, please contact us at:
Email: privacy@example.com
Subject line: Data Privacy Request