Last updated: July 2024
LMSLight LLC and its affiliated companies (“LMS Light”, “we” or “us”), provides a cloud-based Learning Management System (LMS) to assist organizations with online training needs. This privacy notice sets out how LMS Light collects and uses information about you when you use our products and services (“services”) and why we collect certain personal data. This notice also explains the choices that you can make about the way that we use your information.
Your privacy protection is important to us. This is why we have adopted the following legislation: EU’s General Data Protection Regulation 2016/679 (“GDPR”), UK General Data Protection Regulation (“UK GDPR”) and the California Consumer Privacy Act 2018 (“CCPA”). This privacy notice relates to all personal data we process and addresses the legislation mentioned.
‘Personal data’, in this privacy notice, means any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
We remain committed to building a secure LMS that protects the privacy and security of learners’ and employees’ data. We provide all users with the tools to ensure that their data, information and operations are secure and protected. Privacy features embedded with LMS Light LMS ensure that LMS Light is GDPR compliant and adheres to local privacy legislation requirements. However, some responsibility for compliance and safety rests with the organization that controls each LMS Light installation. We encourage institutions and organizations to implement security measures for their LMS Light installation and:
We have also included some useful resources for your use in engaging with LMS Light:
In order for us to provide you with our services or for correspondence purposes we need to collect your personal data. We ensure that the information we collect and use is confined to this purpose. We always process your personal data for specific purposes, with the nature of the data collected depending on your interaction with us. We are committed to transparency in this.
Our legal basis for controlling or processing personal data are:
Article 6.1(a) GDPR (Consent): You provide informed consent to us or have a reasonable expectation that we will use your information in a certain way – for example, to engage in our community discussions, or to hear about new services or offers. You can withdraw your consent at any time either by selecting ‘delete my data’ within the specific service or by request to privacy@lmslight.io;
Article 6.1(b) GDPR (Contract): Providing our services and fulfilling our obligations to you, usually relating to a terms of service or partnership agreement;
Article 6.1(c) GDPR (Legal Obligation): The necessity to meet compliance with our legal obligations; and/or
Article 6.1(f) GDPR (Legitimate Interest): Where it is in our legitimate interests to do so. We only rely on ‘legitimate interests’ as the legal basis for processing by us, or third parties we use, for these purposes:
Where we rely on a specific basis for processing your information and you wish to object to that processing, you must be aware that it might not be possible for you to continue using our services.
The special categories of personal data (Article 9 of GDPR) we process are:
If we need to pass on special category personal data (see Article 9 of GDPR) to a third party, we will only do that in accordance with the legal basis under Article 6 of GDPR as outlined above.
If you would like more details please refer to our Register of GDPR Information.
LMS Light collects personal data from you when you interact with us. This can be through our websites, over the phone, in person, including, without limitation, when you:
We may need to pass your personal data on to third-party service providers contracted to LMS Light in the course of dealing with you. We do this because there are services, such as our video conferencing facility, which will not work unless we are able to make these transfers. Any third parties we share your data with are obliged to keep your personal data secure and use it only for necessary service delivery. When your data is no longer required to fulfill the service, those third parties will be directed to dispose of your data in accordance with our standard procedures.
We seek to enter into Data Processing Agreements with our third party service providers to ensure they only process your data as instructed by us. If you obtain products or services directly from us on behalf of others we will ensure you enter into a Data Processing Agreement (DPA) with us. You will also need to enter into a DPA with your students/employees/customers when using our systems.
We will process (collect, store and use) the information you provide in a manner compatible with GDPR. We maintain physical, organizational and technical safeguards for all personal data we hold. We will endeavor to keep your information accurate and up to date, and not keep it for longer than is necessary. We are required to retain certain information in accordance with the law, such as information needed for income tax and audit purposes. How long certain kinds of personal data should be kept are governed by specific business sector requirements and agreed practices. Personal data can be held in addition to these periods depending on individual business needs.
We will process different forms of personal data for as long as it is necessary and proportionate for the purpose for which it has been supplied and we will store the personal data for the shortest amount of time possible, taking into account legal and service requirements.
We have no interest in collecting any data beyond that needed to ensure our services work for you. If you are going to be contacted by us for marketing purposes, we will not rely solely on this privacy notice. We will endeavor to seek your consent appropriately. LMS Light does not sell data, and has no intentions in doing so in the future.
At any point while we are in possession of or we process your personal data, you have the following rights:
Where we are your Data Controller, please make your request directly to the Data Protection Officer at dpo@lmslight.io. We will always respond within one week.
However, if we are processing your data on behalf of your Data Controller (your service provider) you should contact them directly.
This privacy notice outlines how we manage your personal data. If the website you are using is not hosted by us or you click on a link to another website, we encourage you to read their privacy notice.
At LMS Light, we understand the importance of protecting the personal data of children under the age of 16. It is not our intention to collect personal data from a child. If you believe that a child has disclosed personal data or that we hold personal information about a child, please email us at privacy@lmslight.io.
Before we action a personal data request we need to verify your identity. We accept a request made through your personal LMS Light account while you are logged in. We sometimes require additional information such as a color copy of your passport, driving license or national ID card.
LMS Light updates our privacy notice when necessary or in response to:
The “last updated” date at the top of this privacy notice reflects when the most recent changes were made. We encourage you to periodically review this privacy notice for any amendments.
If you have any questions about our privacy notice, please contact us via email at privacy@lmslight.io, or by mail at:
LMS Light LLC
11470 Hanbury Manor Blvd
Noblesville, IN 46060