Privacy Policy

Last Updated: 1 January 2025

1. Introduction

MedoraGP ("we", "us", "our", or "the Platform") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our learning management system in compliance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018.

Data Controller: MedoraGP is the data controller responsible for your personal data. Our contact details are provided in Section 13 of this Privacy Policy.

Please read this Privacy Policy carefully. By using the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data as described herein, where consent is the legal basis for processing.

2. Information We Collect

2.1 Personal Information

We collect personal information that you provide directly to us, including:

  • Account Information: First name, last name, email address, password (hashed), phone number
  • Profile Information: Bio, profile picture, organization affiliation
  • Communication Preferences: Email notification settings, course update preferences, marketing preferences
  • Payment Information: Payment card details are processed securely through Stripe and are not stored on our servers

2.2 Educational Data

We collect information related to your educational activities:

  • Course enrollments and enrollment history
  • Course progress and completion data
  • Assignment submissions and grades
  • Quiz attempts and scores
  • Discussion forum posts and interactions
  • File uploads and resource downloads
  • Learning analytics and engagement metrics

2.3 Automatically Collected Information

When you use the Platform, we automatically collect certain information:

  • Device Information: IP address, browser type, device type, operating system
  • Usage Data: Pages visited, time spent on pages, click patterns, search queries
  • Location Data: General geographic location based on IP address
  • Cookies and Tracking Technologies: See Section 6 for details

2.4 Information from Third Parties

We may receive information from third-party services:

  • Payment Processors: Stripe provides payment transaction data (not full card details)
  • Authentication Services: If you use third-party authentication (e.g., OAuth), we receive basic profile information
  • Analytics Providers: Aggregated usage statistics and performance metrics

3. How We Use Your Information and Legal Basis

Under UK GDPR and EU GDPR, we must have a legal basis for processing your personal data. We use the collected information for the following purposes and legal bases:

  • Service Provision (Legal Basis: Contract): To provide, maintain, and improve the Platform's functionality as necessary to perform our contract with you.
  • Account Management (Legal Basis: Contract): To create and manage your account, authenticate users, and process enrollments as necessary to perform our contract with you.
  • Course Delivery (Legal Basis: Contract): To deliver course content, track progress, and facilitate learning activities as necessary to perform our contract with you.
  • Communication (Legal Basis: Contract/Legitimate Interest): To send course updates, announcements, respond to inquiries, and provide customer support. Course-related communications are necessary for contract performance; other communications are based on legitimate interest.
  • Payment Processing (Legal Basis: Contract/Legal Obligation): To process course payments, manage subscriptions, and handle refunds as necessary to perform our contract and comply with financial regulations.
  • Grading and Assessment (Legal Basis: Contract): To facilitate assignment grading, quiz administration, and gradebook management as necessary to perform our contract with you.
  • Personalization (Legal Basis: Legitimate Interest): To customize your learning experience and recommend relevant courses based on our legitimate interest in improving user experience.
  • Analytics (Legal Basis: Legitimate Interest): To analyze Platform usage, improve services, and generate reports for instructors and administrators based on our legitimate interest in improving our services.
  • Security (Legal Basis: Legitimate Interest): To detect, prevent, and address security issues, fraud, and unauthorized access based on our legitimate interest in protecting our Platform and users.
  • Legal Compliance (Legal Basis: Legal Obligation): To comply with applicable laws, regulations, and legal processes where we have a legal obligation to do so.
  • Marketing (Legal Basis: Consent): With your explicit consent, to send promotional communications about new courses and features. You can withdraw your consent at any time.

Where we rely on legitimate interest, we have balanced our interests against your rights and freedoms and determined that our legitimate interests do not override your fundamental rights. You have the right to object to processing based on legitimate interest (see Section 8).

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Within the Platform

  • Instructors: Instructors can see student names, enrollment status, assignment submissions, and grades for their courses
  • Administrators: Platform administrators have access to user data necessary for platform management
  • Other Students: Your name and profile information may be visible to other students in shared courses and discussion forums

4.2 Service Providers

We share information with trusted third-party service providers who assist in operations:

  • Payment Processing: Stripe processes payments (see Stripe's privacy policy for details)
  • Hosting and Infrastructure: Cloud service providers that host our Platform
  • Analytics: Analytics services to understand Platform usage (data is typically aggregated and anonymized)
  • Email Services: Email service providers for sending notifications and communications

4.3 Legal Requirements

We may disclose information if required by law, court order, or government regulation, or to:

  • Comply with legal obligations
  • Protect our rights, property, or safety
  • Prevent fraud or security issues
  • Respond to government requests

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

4.5 With Your Consent

We may share your information in other ways with your explicit consent.

5. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using SSL/TLS protocols
  • Secure password hashing and storage
  • Regular security assessments and updates
  • Access controls and authentication mechanisms
  • Secure payment processing through PCI-compliant providers (Stripe)
  • Regular backups and disaster recovery procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on the Platform:

6.1 Types of Cookies

  • Essential Cookies: Required for Platform functionality, authentication, and security
  • Functional Cookies: Remember your preferences (e.g., theme settings, language)
  • Analytics Cookies: Help us understand how users interact with the Platform
  • Session Cookies: Temporary cookies that expire when you close your browser
  • Persistent Cookies: Remain on your device for a set period or until deleted

6.2 Managing Cookies

You can control cookies through your browser settings. However, disabling certain cookies may limit Platform functionality. We also use HTTP-only cookies for secure session management.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:

  • Account Data: Retained while your account is active and for a reasonable period after account closure
  • Educational Data: Retained to maintain academic records and comply with educational requirements
  • Payment Records: Retained as required by financial regulations and tax laws
  • Communication Data: Retained for customer support and record-keeping purposes

When data is no longer needed, we will securely delete or anonymize it in accordance with our data retention policies.

8. Your Privacy Rights (UK GDPR / EU GDPR)

If you are located in the UK or European Economic Area (EEA), you have the following rights under UK GDPR and EU GDPR regarding your personal data:

8.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process your personal data and to access your personal data, including a copy of the data we hold about you.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to have inaccurate personal data corrected and incomplete personal data completed. You can update your personal information through your account settings or by contacting us.

8.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)

You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary, you withdraw consent, or the data has been unlawfully processed. This right is subject to legal and operational requirements (e.g., we may need to retain certain data for legal compliance or to fulfill our contract with you).

8.4 Right to Restrict Processing (Article 18 GDPR)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or object to processing.

8.5 Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where technically feasible.

8.6 Right to Object (Article 21 GDPR)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

8.7 Right to Withdraw Consent (Article 7 GDPR)

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have violated data protection laws. In the UK, this is the Information Commissioner's Office (ICO) atico.org.uk. In the EU, you can contact your local data protection authority.

Exercising Your Rights:

To exercise any of these rights, please contact us using the information provided in Section 13. We will respond to your request within one month (this may be extended by two months for complex requests). We may need to verify your identity before processing your request. In most cases, there is no charge for exercising your rights, though we may charge a reasonable fee if requests are manifestly unfounded or excessive.

9. Children's Privacy

The Platform is not intended for users under the age of 16 in the UK and EEA (or the minimum age of digital consent in your jurisdiction, which may be 13-16 years depending on the country). We do not knowingly collect personal information from children without appropriate parental consent.

If you are under 16 (or the applicable minimum age in your jurisdiction), you must have your parent's or guardian's consent to use the Platform. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly.

If you are a parent or guardian and believe we have collected information from your child without consent, please contact us immediately using the details provided in Section 13.

10. International Data Transfers

Your information may be transferred to and processed in countries outside the UK and European Economic Area (EEA). These countries may have data protection laws that differ from UK GDPR and EU GDPR.

10.1 Adequacy Decisions: We may transfer your data to countries that have been deemed to provide an adequate level of data protection by the UK government or European Commission (e.g., countries with adequacy decisions).

10.2 Appropriate Safeguards: Where we transfer data to countries without adequacy decisions, we implement appropriate safeguards as required by UK GDPR and EU GDPR, including:

  • Standard Contractual Clauses (SCCs) approved by the UK government or European Commission
  • Binding Corporate Rules (BCRs) where applicable
  • Certification schemes approved under GDPR
  • Other legally recognized transfer mechanisms

10.3 Third-Party Processors: When we use third-party service providers (e.g., Stripe, cloud hosting providers) that process data outside the UK/EEA, we ensure they have appropriate safeguards in place and comply with UK GDPR and EU GDPR requirements.

10.4 Your Rights: You have the right to obtain information about the safeguards we have put in place for international transfers. Please contact us using the details in Section 13 if you would like more information.

11. Third-Party Links and Services

The Platform may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to third-party websites or services. We encourage you to review the privacy policies of any third-party sites or services you access through our Platform.

Stripe: Payment processing is handled by Stripe. When you make a payment, Stripe collects and processes your payment information in accordance with their privacy policy. We do not store your complete payment card information on our servers.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on the Platform and updating the "Last Updated" date. Your continued use of the Platform after such changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.

13. Contact Us and Data Protection Inquiries

If you have questions, concerns, or requests regarding this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us:

MedoraGP
Data Controller
Email: [email protected]
Address: Your UK Business Address
Phone: +44 XXXX XXXXXX

UK Supervisory Authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom

14. UK and EU Data Protection Compliance

14.1 UK GDPR Compliance

This Privacy Policy is designed to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are located in the UK, your rights are set out in Section 8 above. You have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.ukor by calling 0303 123 1113.

14.2 EU GDPR Compliance

This Privacy Policy is designed to comply with the EU General Data Protection Regulation (EU GDPR). If you are located in the European Economic Area (EEA), your rights are set out in Section 8 above. You have the right to lodge a complaint with your local data protection authority. A list of EU data protection authorities can be found at edpb.europa.eu.

14.3 Data Protection Officer

If we are required to appoint a Data Protection Officer (DPO) under GDPR, we will provide their contact details here. Currently, for data protection inquiries, please contact us using the details provided in Section 13.

14.4 Automated Decision-Making

We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. If this changes, we will update this Privacy Policy and provide you with information about the logic involved and the significance and consequences of such processing.

14.5 Special Categories of Personal Data

We do not intentionally collect special categories of personal data (sensitive personal data) as defined in Article 9 of GDPR (e.g., health data, biometric data, data revealing racial or ethnic origin). If you provide such information voluntarily, we will process it only with your explicit consent or as otherwise permitted by law.

By using MedoraGP, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.