The New Elearning The New Elearning
Privacy policy

How we handle personal data

This policy explains what The New Elearning collects, why we use it, how long we keep it, and how you can exercise your rights. Last updated: July 27, 2026.

Who is responsible

The New Elearning is the controller for marketing, sales, account administration, cookie consent records and platform operations. For customer learning records, the customer account may be the controller and The New Elearning acts as processor under a Data Processing Agreement when one is in place.

Contact: [email protected].

Data we process

Category Examples Purpose Legal basis
Account and learner data Name, email, role, account, group, locale, SSO provider identifiers. Create accounts, authenticate users, assign training and manage access. Contract, legitimate interests and customer instructions where we act as processor.
Training records Assignments, step completions, question attempts, certificates and audit events. Deliver learning, prove completion, issue certificates and provide compliance exports. Contract, legitimate interests and customer instructions.
Sales inquiries Name, work email, company, plan, message and optional UTM attribution. Respond to demo, pricing and product requests. Consent when you submit the form and legitimate interests for B2B follow-up.
Cookie consent records Policy version, selected purposes, timestamp, signed consent identifier, IP address and user agent. Record and verify consent, rejection or withdrawal. Legal obligation and legitimate interests.
Security and operations data Session cookies, request metadata, IP address, user agent, API key usage and error diagnostics. Keep the service secure, troubleshoot issues and prevent abuse. Legitimate interests and legal obligation.

Cookies and analytics

Necessary cookies keep sessions, security tokens and explicit preferences working. Optional Umami Cloud analytics only loads after analytics consent, and rejecting analytics does not block access.

Read the cookie policy to see each cookie and browser storage item.

Processors and third parties

  • Hetzner Cloud hosts the application servers, database, local file storage and backups in Europe.
  • Umami Cloud processes optional aggregate analytics only after analytics consent.
  • Google and Microsoft process SSO authentication data when an enabled SSO provider is used.
  • Slack receives lead notifications if the Slack webhook is configured.
  • Sentry receives error diagnostics only when a Sentry DSN is configured; default PII sending is disabled.
  • Email providers process transactional emails such as invitations, password resets and lead acknowledgements when configured.

We do not sell personal data or use advertising pixels.

Retention

  • Account, learner and training records are kept while the account is active and as needed for contractual, certificate and audit purposes.
  • Audit events are append-only and may keep actor or learner names in metadata after an account is deleted so historical records remain meaningful.
  • Lead inquiries are kept for up to 24 months after the last meaningful interaction unless a longer business or legal need applies.
  • Cookie consent records are kept for up to 24 months after the last consent event, unless needed longer to demonstrate compliance.
  • Privacy requests and response records are kept for up to 36 months to demonstrate timely handling.
  • Operational logs and error diagnostics are kept only as long as needed for security, debugging and abuse prevention.

Your rights

Depending on your role and jurisdiction, you can request access, rectification, erasure, restriction, portability, objection, consent withdrawal, information about automated decision-making and review of automated decisions.

Submit a request through the data rights form. We aim to respond within 30 days.

Automated decisions

The app automatically grades configured quiz answers, records step completion, applies attempt limits and issues certificates when course requirements are met. These features support training administration and do not make solely automated decisions with legal or similarly significant effects.

Security

Production traffic is served over TLS, access is role-scoped, API keys are stored as one-way digests, and audit records are append-only at the application layer. More detail is available on the security page.

Back to home