Privacy Policy
Effective date: 1 June 2026
Last updated: 7 July 2026
1. Who we are
Codelivly ("Codelivly", "we", "us", "our") operates the Codelivly cybersecurity eLearning platform at codelivly.com. Codelivly is developed as part of the Islington College project. For data protection purposes, Codelivly is the data controller responsible for your personal data.
Contact for privacy matters: [email protected]
2. Personal data we collect
We may collect and process the following categories of personal data:
- Account data: name, email address, username, password hash, profile information, and authentication tokens.
- Learning data: course progress, lesson completions, quiz results, certificates earned, XP/reputation, and related activity logs needed to operate your dashboard.
- Payment data: subscription plan, billing history, and transaction identifiers. Card and wallet details are processed by Stripe or PayPal (whichever you choose at checkout); we do not store full payment card numbers on our servers.
- Sign-in data from other services: if you sign in or link an account with Google, GitHub, or LinkedIn, that provider shares your name, email address, profile picture, and a provider account ID with us. We never receive your password for those services.
- Communications: support messages, newsletter preferences, and email delivery metadata.
- Technical data: IP address, browser type, device information, and cookies (see our Cookie Policy).
3. How we use your data and legal bases
We process personal data only where we have a lawful basis under UK GDPR / GDPR:
- Contract: to create and manage your account, deliver courses and interactive content, issue certificates, and process subscriptions you purchase.
- Legitimate interests: to secure the platform, prevent abuse, improve content, and understand aggregate usage — balanced against your rights.
- Consent: for optional marketing emails and non-essential cookies where required. You may withdraw consent at any time.
- Legal obligation: where we must retain records for tax, accounting, or regulatory purposes.
4. Data retention
We retain personal data only as long as necessary:
- Account and learning records: for the life of your account and up to 24 months after closure, unless a longer period is required by law or active disputes.
- Payment and invoice records: up to 7 years for accounting and tax compliance.
- Marketing consent records: until you unsubscribe plus a reasonable audit period.
- Server and security logs: typically up to 90 days, unless needed for incident investigation.
5. Sharing and processors
We do not sell your personal data. We share data with trusted processors who act on our instructions, including:
- Stripe — card payment processing and subscription billing (Stripe privacy policy).
- PayPal — payment processing and subscription billing (PayPal privacy policy).
- Google, GitHub, LinkedIn — sign-in (OAuth) when you choose to use them.
- Cloudflare — bot and abuse protection (Turnstile) on some forms.
- Error monitoring — crash and error reports so we can fix bugs; these are technical reports, not advertising trackers.
- Email / SMTP providers — transactional and marketing email delivery.
- Hosting and infrastructure providers — application hosting, databases, and content delivery.
Our team operates from the United Kingdom and Nepal, and your data may be processed in those locations and by the processors above elsewhere. International transfers use appropriate safeguards such as Standard Contractual Clauses where required. Processors are bound by contractual data protection terms.
6. Cookies
We use cookies and similar technologies as described in our Cookie Policy.
7. Your rights
Depending on your location, you may have the right to:
- Access a copy of your personal data.
- Rectify inaccurate data.
- Erase data in certain circumstances ("right to be forgotten").
- Restrict or object to processing.
- Data portability for data you provided, where processing is based on contract or consent.
- Withdraw consent at any time for consent-based processing.
- Lodge a complaint with the Information Commissioner's Office (ICO) in the UK or your local supervisory authority.
Self-serve: you can update your profile in Settings, request an export of your data from Settings → Privacy, and delete your account from Settings → Account — no email required.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, to request deletion or correction, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. To exercise these rights, use the self-serve tools above or email us.
To exercise any right, email [email protected]. We respond within one month unless an extension is permitted by law.
8. Security
We implement appropriate technical and organisational measures, including encryption in transit (HTTPS), passwords stored only as strong one-way hashes, HttpOnly session cookies, rate limiting, optional two-factor authentication, access controls, and monitoring. No method of transmission over the Internet is 100% secure; we cannot guarantee absolute security, but if we discover a breach affecting you we will notify you as required by law.
9. Children
Codelivly is not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data.
10. Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated effective date.