2. WHO ARE WE?
Lepaya provides learning journeys consisting of Power Skill Trainings by offering more than 80 Soft and Hard Skill training modules to employers. Lepaya’s Power Skill Trainings upskill the workforce of employers and enable employees to be more effective in their work and enjoy more happiness in life. The Lepaya platform can be accessed through one of the Lepaya apps, e.g. the Lepaya mobile app, the desktop app through ‘learn.lepaya.com’ and/or the Lepaya Learning app for MS Teams (together all apps will be referred to as the “Lepaya Apps”).
3. HOW AND WHY DO WE USE PERSONAL DATA?
Lepaya processes personal data as supplied by you or your employer (hereinafter called “Personal Data”), so we can provide our services and deliver our training modules. We will always process your Personal Data based on one of the legal bases provided for in the GDPR (see article 5). We do not process any sensitive Personal Data, such as ethnic origin, political opinions, religious or philosophical beliefs. The Personal Data necessary to sign you up for the Lepaya Apps as a user are as follows: first name, last name and email address.
4. LEPAYA ACTS AS DATA PROCESSOR
Lepaya is considered a data processor as defined in Article 28 of the GDPR when it comes to processing your Personal Data. This means that Lepaya acts on behalf of its given instructions and will only process Personal Data in line with these instructions. Lepaya does not determine the purpose and means by which your Personal Data is processed.
5. ON WHICH LEGAL BASIS WILL YOUR PERSONAL DATA BE PROCESSED?
The processing of your Personal Data is necessary for the performance of a contract as defined in Article 6(1)(b) of the GDPR. We process your Personal Data for the performance or preparation of an agreement with our client, your employer. We process your Personal Data that we receive from your employer so that we can provide our services to your employer, and ultimately to you. Without processing this data, it is not possible to provide our services and offer you our (virtual) learning via the Lepaya Apps.
6. WHICH PERSONAL DATA IS COLLECTED AND PROCESSED?
We collect information that is provided to us by you, or by your employer, so we have the necessary information to sign you up for the Lepaya Apps. The following data is collected and processed by us:6.1. Personal information that is disclosed to us The personal information that we collect depends on your interactions with us and the Lepaya Apps, the choices you make and the products and features you use. The personal information we collect can include the following:
- Personal information provided by your employer: we collect the following Personal Data in order to run the Lepaya Apps properly: first name, last name, e-mail address and (optionally) job title.
- Information provided by you (by using the Lepaya Apps): we collect your app usage and data collected from surveys. You can also (optionally) provide us with a profile picture for display in the app. When using the AI Coach module, we also process video material provided by you. This video material will only be used internally for the functioning of the relevant module.
- Credentials: we collect passwords, password hints, and similar security information used for authentication.6.2 Information automatically collected We automatically collect certain information when you visit, use or navigate the Lepaya Apps. This information may include device and usage information, such as your IP address, browser and/or device characteristics, operating system, language preferences, and referring URLs. This information is needed to maintain the security and operation of the Lepaya Apps, since this information gives us a better understanding of the usage of the Lepaya Apps in various different aspects and we need to consider all relevant aspects in the case that we need to release a new feature or deprecate an old version of the app. Furthermore, it is important that we are aware of any impact that new features might cause to users if they are not using the latest devices.
- Do not investigate, scan or test the Platform or any other related system or network, or violate any security or authentication.
6.3 Information collected through our Lepaya Apps
If you use our Lepaya Apps, we may also collect the following information:(i) Mobile Device Access (optional): we may request access or permission to certain features from your mobile device, including your mobile device’s camera and other features.
- Mobile Device Access (optional): we may request access or permission to certain features from your mobile device, including your mobile device’s camera and other features.
- Mobile Device Data: we may automatically collect device information (such as your mobile device ID, model and manufacturer), operating system, and version information. We collect this information to maintain the security and operation of the Lepaya Apps. More information on this can be found in clause 6.2.
- Push Notifications: we may request to send you push notifications regarding your account or the Lepaya Apps. If you wish to opt-out from receiving these notifications, you may turn them off in your device’s settings.
6.4 Third party providers and subcontractors
We may share your Personal Data within the Lepaya Group and with third parties in accordance with the GDPR. The Lepaya Group is based in the following countries: The Netherlands, Germany, Sweden, the United Kingdom (the “UK”). Your Personal Data can be safely transferred to the UK since the GDPR is virtually implemented in the UK in the Data Protection Act 2018 and the same guidelines and rules apply.
When we share your Personal Data with a third party data processor, we will put the appropriate legal framework in place in order to cover such transfer and processing, in accordance with Articles 26, 28, 29 and 44(f) GDPR. Lepaya has engaged Amazon Web Services (“AWS”) as a subcontractor in Frankfurt, Germany. All data is encrypted in rest and transit (including HTTPS encryption and Application Layer and Transport encryption).
6.5 Legal Compliance and Security
It may be necessary for us – by law, legal process, litigation and/or requests from public and governmental authorities within or outside your country of residence – to disclose your Personal Data. We may disclose your Personal Data if we determine that disclosure is reasonably necessary following the above situations.
7. FOR WHICH PURPOSES WILL YOU BE USED?
We may collect and process your Personal Data for the purposes detailed below to provide you with adequate services and products. The specific purposes can be one or more of the following:
- To grant access to all functions of the Lepaya App and the Lepaya App;
- To set up and manage a personal profile, from which you can use the Lepaya App;
- To send you information about the Lepaya App, Lepaya and our services (excluding marketing or promotion);
- To draw up anonymous statistical data and to make the Lepaya App safer;
- To provide your information to third parties based on legal obligations;
- In order to adapt and improve the Lepaya App.
8. HOW DO WE PROTECT YOUR PERSONAL DATA?
We process your Personal Data in a manner that ensures their appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction or damage. We use appropriate technical or organizational measures to achieve this level of protection (Article 25(1) and 32 GDPR).
9. HOW LONG WILL WE KEEP YOUR PERSONAL DATA?
10. WHERE IS YOUR PERSONAL DATA STORED?
We process all Personal Data only within the EU/EEA, since all data is stored with AWS in Frankfurt, Germany. Any transfer of Personal Data to a third country or to an international organization shall only take place if the conditions laid down in the GDPR are complied with.
11. OUR RECORD OF DATA PROCESSES
We handle records of all processing of Personal Data in accordance with the obligations established by the GDPR, particularly in Article 30(2). In these records, we reflect all the information necessary in order to comply with the GDPR and cooperate with the supervisory authorities as required (Article 31 GDPR).
12. NOTIFICATION OF DATA BREACHES TO THE COMPETENT SUPERVISORY AUTHORITIES
In case of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, we have the mechanisms and policies in place in order to identify it and assess it promptly. We will inform the Data Controller, your employer, immediately to discuss the breach of security and we will discuss any necessary further steps.
13. YOUR RIGHTS
Every data subject has:
- the Right of Access pursuant to Art. 15 GDPR;
- the Right to Rectification pursuant to Art. 16 GDPR;
- the Right to Erasure (“right to be forgotten”) pursuant to Art. 17 GDPR;
- the Right to Restriction of Processing pursuant to Art. 18 GDPR;
- the Right to Data Portability pursuant to Art. 20 GDPR; and
- he Right to Object pursuant to Art. 21 GDOR.
With regard to the Right of Access and the Right to Erasure, the restrictions pursuant to Articles 34 and 35 GDPR apply. In addition, data subjects have the right to lodge a complaint with a data protection supervisory authority in accordance with Art. 77 GDPR. To assert these rights, you should contact the company responsible for your Personal Data. If the above rights are asserted directly against Lepaya, Lepaya shall immediately refer the data subject to the client and await the client’s instructions.
14. HOW FAR DOES LEPAYA’S RESPONSIBILITY REACH?
15. CAN THIS PRIVACY STATEMENT BE ALTERED?
16. THANK YOU
- LTD GROUP B.V. AND SUBSIDIARIES, MAY 2023
Stay tuned for our monthly updates
Subscribe to our newsletter.
Fields marked with (*) are required.