Legal
Privacy Policy
What personal data the platform processes, on what basis, who it is shared with, and what rights the people who train on it have.
1. Who is responsible for your data
This distinction decides who you should send your requests to, so it comes first.
| Situation | Controller | 3LS role |
|---|---|---|
| Your account was created by your employer or a training body | That organisation | Processor — we handle the data only on its instructions |
| You visit our public site or request a demo | 3L Systems | Controller |
| You are our commercial or administrative contact at a customer organisation | 3L Systems | Controller |
If your account belongs to an organisation and you want to exercise a right over your training data, start with that organisation. We help them answer you.
2. What data we process
| Category | Examples |
|---|---|
| Identity and account | Name, work email address, profile photo if you upload one, organisation, assigned role, groups and cohorts |
| Authentication | Hashed password, sessions and tokens, single sign-on identifier, sign-in records and failed attempts |
| Learning activity | Enrolments, modules opened, resume position in a video, time spent on each item, completion percentage, deadlines |
| Assessment | Answers given, scores, number of attempts, pass or fail, automatic feedback |
| Certification | Certificates issued, date, verification code, revocations |
| Content you create | Personal notes, forum posts, files you submit |
| Technical data | IP address, device and browser type, language, video streaming quality, error logs |
| Support | Messages you send us and the history of how they were resolved |
3. Where it comes from
- From you — when you fill in your profile, study, answer assessments or contact us.
- From your organisation — when it creates your account, imports a user list by CSV or connects its HR system.
- From the identity provider — when you sign in with SSO, we receive the attributes your organisation configured.
- Automatically — technical records generated by normal use of the service.
4. Why we use it, and on what basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Give you access and maintain your account | Identity, authentication | Performance of the contract with your organisation (Art. 6(1)(b)) — or its legitimate interest |
| Deliver the training, save progress and let you resume | Learning activity | Performance of the contract |
| Assess, mark and issue certificates | Assessment, certification | Performance of the contract; legal obligation where training is mandatory |
| Progress and compliance reporting for your organisation | Activity, assessment, certification | Employer's legitimate interest in verifying compliance (Art. 6(1)(f)) |
| Deadline and completion notifications | Contact, activity | Performance of the contract |
| Security, fraud prevention and audit logging | Technical, authentication | Legitimate interest (Art. 6(1)(f)) and legal obligation |
| Improve the platform using aggregate statistics | Technical, aggregated activity | Legitimate interest — results do not identify individuals |
| Marketing to customer and prospect contacts | Identity, business contact details | Consent or legitimate interest, with an easy opt-out |
5. Who we share it with
We do not sell personal data and do not release it for third-party advertising. We share only with those needed to run the service:
| Recipient | What for | Where |
|---|---|---|
| Your organisation | Administrators and managers see enrolments, progress, scores and certificates | — |
| Amazon Web Services | Application and database hosting (ECS, RDS), file storage (S3), video delivery and transcoding (CloudFront, MediaConvert) | AWS REGION |
| TRANSACTIONAL EMAIL PROVIDER | Invitations, notifications and password recovery | REGION |
| Sentry | Application error logging | REGION |
| PUSH NOTIFICATION PROVIDER | Mobile app notifications | REGION |
| Public authorities | Where legally required, and only to the extent required | — |
All processors are contractually bound to handle data only for the agreed purposes and with appropriate security. The current list is on the GDPR page.
6. International transfers
The platform is hosted in AWS REGION and support is provided from Cabo Verde. This means data belonging to users in the European Union may be processed outside the European Economic Area.
Where that happens we rely on MECHANISM: EUROPEAN COMMISSION STANDARD CONTRACTUAL CLAUSES, together with the supplementary technical measures described in the security section. Cabo Verde is a party to Council of Europe Convention 108 and has its own data protection legislation and supervisory authority, the Comissão Nacional de Protecção de Dados.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While the account is active; deleted N days after deactivation |
| Progress and assessment results | For the term of the contract with the organisation, plus N years as proof of compliance |
| Certificates and verification records | N years — a certificate is useless if it can no longer be verified |
| Audit and security logs | N months |
| Technical and error logs | N days |
| Billing and accounting | The applicable statutory period, 10 years |
Once those periods end, data is deleted or irreversibly anonymised. Aggregate statistics that no longer identify anyone may be kept.
8. How we protect it
- Encryption in transit (TLS) and at rest in the database and file storage.
- Tenant isolation — an organisation reaches only its own data, enforced in the API and not just in the interface.
- Role-based access control on least privilege, with stronger authentication on administrative accounts.
- Audit logs of sensitive actions, recording who, when and the previous value.
- Penetration testing and security review before each major release, following the OWASP Top 10.
- Regular backups with tested restores, and monitoring with real-time alerting.
If a personal data breach occurs that poses a risk to individuals, we notify the responsible organisation without undue delay so that it can meet its own notification duties within the statutory deadlines.
9. Your rights
Under the GDPR and Cabo Verdean data protection law, you have the right to:
- Know what data we hold about you and get a copy.
- Correct inaccurate or incomplete data.
- Ask for erasure, where there is no ground to keep it.
- Ask us to restrict processing, or object to it where it rests on legitimate interest.
- Receive your data in a structured, commonly used format and have it sent to another controller.
- Withdraw consent at any time where processing relies on it, without affecting what was lawful before.
- Lodge a complaint with a supervisory authority.
If your account belongs to an organisation, send your request to that organisation. If it reaches us directly, we pass it on and tell you we have. We respond within one month, extendable by two months in complex cases.
Supervisory authorities: in Cabo Verde, the Comissão Nacional de Protecção de Dados; in the European Union, the authority where you live or work.
10. Automated decisions
Multiple-choice assessments are marked automatically, but against an answer key written by people, and an administrator can review a result manually, with that change recorded. Course recommendations are based on training history and have no legal effect on you.
We make no solely automated decisions with legal effects on you. What your organisation decides on the basis of results — promotion, performance review — is its decision, not ours.
11. Children
The platform is built for professional and institutional settings and is not intended for anyone under 16. If an organisation uses it to train minors, it must ensure the proper legal basis, including the consent of the holder of parental responsibility where required.
13. Changes to this policy
If we change this policy materially, we tell you by email and by notice in the platform before it takes effect. The date at the top always shows the last update, and we keep earlier versions available on request.