Privacy Policy
Last updated 12 September 2026
Draft — not yet in force
This document is complete in substance but is missing details only the operator can supply: the registered company name, the registered address and the governing jurisdiction. Until those are set, this page is excluded from search engines and should not be relied on. It has not been reviewed by a lawyer.
This explains what personal data Edesy handles in running Edesy, and what you can do about it. It covers https://lms.edesy.in and the course sites our customers publish using the Platform.
1. Two different relationships — start here
Almost every confusing question about this platform is answered by working out which of two relationships you are in.
- You run a course site with us. We hold your account and billing data, and we are responsible for it. This policy governs that.
- You are a learner who enrolled on somebody's course. The organisation whose site you used decides what to collect about you and why. They are responsible for it; we only store and process it on their instructions.
If you are a learner and want your data corrected or deleted, ask the organisation you learned with — their contact details are on the site you enrolled through. We will help them act on your request, but we cannot make that decision for them, and we will not quietly override them.
2. What we collect
From customers who hold an account with us:
- Account details — name, email address, and the organisation you represent.
- Authentication data — a password hash, or the identifier returned by your single sign-on provider. We never store a password in a readable form.
- Billing data — plan, billing contact, and payment records. Card numbers go to our payment provider and never reach our servers.
- Support correspondence — what you write to us, so we can answer it.
- Technical records — IP address, browser type and timestamps, kept as server logs.
From learners, on behalf of the organisation whose course they took:
- Name, email address and whatever else that organisation chose to ask for.
- Enrolment, progress through lessons, assessment attempts and scores, and certificates issued.
- Sign-in times and the device identifier described below.
4. Why we use it
- To provide the service you or your organisation asked for — this is the basis for most of it.
- To take payment and meet our tax and accounting obligations.
- To keep accounts secure: detecting abuse, enforcing device and access limits, and investigating incidents.
- To answer support requests.
- To understand how the marketing site is used, so it can be improved.
We do not use your content or your learners' data to train machine-learning models, and we do not sell personal data to anyone.
6. How long we keep it
- Account and site data — for as long as the account is open, then 30 days after it closes so you can export it, and then deleted.
- Billing records — kept for as long as tax and accounting law requires, which is longer than the account itself.
- Server logs — a short operational period, then discarded.
- Learner records — for as long as the organisation whose course it is keeps them. Deletion of those is their instruction to give.
Backups age out on their own cycle, so a deleted item may persist in a backup briefly after it disappears from the service.
7. Your rights
Depending on where you live you may have the right to see a copy of your data, correct it, have it deleted, restrict or object to how it is used, or receive it in a portable form.
To exercise any of these as a customer, write to [email protected]. We will respond within one month, and sooner where we can.
Customers do not need to ask us for an export — learner records, progress and transactions can be exported as CSV from the dashboard at any time, including on the way out.
If you are a learner, send the request to the organisation you learned with. If they do not respond at all, tell us and we will chase them; we cannot decide it for them.
If you believe we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to your data-protection authority.
8. Security
- Traffic is encrypted in transit.
- Passwords are stored only as hashes, never in a readable form.
- Access is separated by organisation and by role, and enforced on the server rather than hidden in the interface.
- Administrative actions are recorded in an audit log.
No system is perfect. If a breach affects you we will tell you, and the relevant authority, within the time the law requires.
9. International transfers
The processors listed above operate internationally, so data may be processed outside the country you live in. Where that happens we rely on the transfer safeguards those providers offer under their own agreements.
10. Children
The Platform is sold to organisations and adults. We do not knowingly collect data from children directly. A customer running courses for under-18s is responsible for obtaining whatever consent the law where they operate requires.
11. Changes to this policy
We will give at least 30 days' notice of a material change, by email to account owners and a notice on this page. The date at the top is when the wording last changed.
12. Contact
Data-protection questions go to [email protected], or through https://lms.edesy.in/contact.
- Operator:
- Edesy
