Legal

Privacy Policy

ManageToLearn runs branded, fully isolated learning academies. This policy explains what personal data we handle, why, and the choices you have.

Who this policy covers

It applies to the ManageToLearn platform and the academies hosted on it. If you are a learner or staff member inside an academy, that academy is the primary controller of your personal data; ManageToLearn processes it on the academy's behalf to deliver the Service. For academy administrators who sign up directly, we act as the controller.

Information we collect

We collect what is needed to run an academy: account details (name, email, role); the learning content, assignment submissions, and grades you create or are given; and operational records such as sign-in events and activity logs. We do not sell personal data, and we do not use it for advertising.

How we use information

To authenticate you, deliver courses and cohorts, route submissions to human evaluators, issue and verify certificates, send transactional email (invitations, grade releases, password resets), keep the Service secure, and meet legal obligations. Assignments are read and graded by people — there is no automated grading or profiling that produces decisions about you without human judgment.

Isolation between academies

Each academy's data lives in its own separate database — never a shared table keyed by a tenant column. Your academy's data is not commingled with, or queryable from, any other academy. This isolation is the core of how ManageToLearn is built.

Service providers

We share data only with the processors needed to operate the Service, under contract and limited to that purpose: a cloud infrastructure and storage provider that hosts the application and stored files, a transactional email provider that delivers our notifications, and — once paid billing is enabled — a payment processor that handles card details, which we never see or store ourselves.

Data retention and archives

We keep your data for as long as your academy is active and as required to provide the Service or comply with law. Archived batches become read-only but are retained as part of your academy's permanent record. When an academy is closed, its data is deleted or anonymised within a reasonable period unless we are legally required to keep it.

Security

Passwords are stored only as salted Argon2id hashes, never in plain text. Traffic is encrypted in transit with HTTPS/TLS, uploaded files are scanned for malware, and access to production data is restricted and audited. No system is perfectly secure, but we work to protect your data using industry-standard measures.

Your rights and choices

Subject to applicable law, you may request access to, correction of, a copy of, or deletion of your personal data. Learners and staff should contact their academy administrator; academy administrators and direct users can contact us. We will respond within the time required by law.

Cookies and sessions

We use a single strictly-necessary session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.

Children

The Service is intended for organisations and is not directed to children under 16. We do not knowingly collect their personal data; if you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected by a new effective date above, and where appropriate we will notify academy administrators.

Contact

Questions about this policy or your data? Email privacy@managetolearn.com. ManageToLearn is operated from India, and this policy is governed by Indian law.


See also our Terms of Service, or return to the home page.