Policies

Privacy policy

What we collect, why we collect it, how long we keep it, and what you can tell us to do about it.

MyLearnPlus is a training business operated by Livezen Technologies, which is the data controller for the personal data described here. Our registered office is on every invoice we issue and we will send it to anybody who asks at [email protected] — you need it to exercise the rights set out below, so we will not make you hunt for it. This policy replaces any earlier version, and the date this one took effect is shown at the foot of this page. It is written to meet the Sri Lanka Personal Data Protection Act No. 9 of 2022 and, where it applies to you, the UK and EU General Data Protection Regulation. Questions, requests and complaints go to [email protected], marked for the attention of the data protection contact.

What we collect

  • Booking and account data: your name, email address, telephone number, billing country, the organisation you are booking for, job title where you give it, and your account login details.
  • Payment data: the amount, currency, date, invoice and purchase order references, and the last four digits and type of card. Full card numbers are captured and processed by our payment provider and never reach our systems.
  • Learning data: the courses you book, attendance, progress through self-paced modules, quiz and practice question responses, questions you ask the instructor, and the certificate issued to you.
  • Content you bring: exercise files, images, documents and prompts you upload or share in a class.
  • Class recordings: the instructor's screen and audio, and any audio, video or chat you contribute while a session is being recorded.
  • Support and correspondence: emails, contact and quote forms, and the notes we make when handling your enquiry.
  • Website and device data: IP address, browser and device type, pages viewed, and cookie identifiers. Analytics and marketing cookies are set only where you consent through the cookie banner; the cookies in use are listed there and your choice can be changed at any time.

We do not deliberately collect special category data. Where you tell us about a health condition or an access requirement so that we can make an adjustment, we use it only for that purpose, share it only with the instructor who needs it, and delete it after the course.

Why we use it, and our lawful basis

  • To deliver the course you booked and to give you materials, recordings, certificates and support. Basis: performance of a contract with you, or our legitimate interest in delivering a contract with your employer where they booked on your behalf.
  • To take payment and issue invoices. Basis: performance of a contract and compliance with a legal obligation.
  • To meet tax, accounting and company law obligations. Basis: legal obligation.
  • To answer enquiries and quote for corporate training. Basis: steps taken at your request before entering a contract, or legitimate interests.
  • To improve courses, using feedback, attendance and aggregated progress data. Basis: legitimate interests, and we use aggregated rather than individual data wherever it will do the job.
  • To send course news and offers by email. Basis: your consent, or the legitimate interest in contacting existing customers about similar training. Every message carries an unsubscribe link and we act on it immediately.
  • To keep the site and accounts secure and to prevent fraud. Basis: legitimate interests.

We do not sell personal data, we do not share it with advertisers, and we do not make decisions with legal or similarly significant effects about you using automated processing alone.

Who we share it with

Only with organisations that need it to run the school: our website and learning platform hosting, our payment provider, our email and calendar provider, the video conferencing service used for live classes, our accounting service, and our instructors, who see only what they need to teach you. Where you are booked by an employer, we confirm your attendance and completion to the person who booked, because that is what they are paying for; we do not share your individual quiz answers or class questions with them without your agreement. We disclose data to a regulator, a court or a law enforcement body only where we are legally required to.

International transfers

We operate from Sri Lanka and serve learners worldwide, so some of our providers store data outside your country. Where personal data protected by the GDPR leaves the UK or EEA, we rely on an adequacy decision or on Standard Contractual Clauses with the provider. Where personal data leaves Sri Lanka, we transfer it in line with the requirements of the Personal Data Protection Act. Ask us and we will tell you which provider handles a given category of data and where it sits.

How long we keep it

  • Booking, invoicing and tax records: for as long as Sri Lankan tax and company law requires us to retain accounting records.
  • Learner account, course history and certificate records: for as long as your account is open, and for three years after your last course so that we can re-issue a certificate or confirm your training history. You can ask us to close the account sooner.
  • Class recordings and self-paced access: twelve months from the class or purchase date, after which the recording is deleted from learner access.
  • Files you bring into a class: deleted once the course is complete, and immediately on request.
  • Support correspondence: twenty-four months.
  • Marketing contact data: until you unsubscribe or ask us to erase it, after which we keep a minimal suppression record so that we do not contact you again by mistake.
  • Website analytics: retained in aggregated form; cookie identifiers expire as listed in the cookie banner.

Your rights

Under the GDPR, where it applies to you, you have the right to be informed, to access a copy of your data, to have inaccurate data corrected, to erasure in certain circumstances, to restrict or object to processing including direct marketing, to data portability, and to withdraw consent at any time without affecting processing already carried out.

Under the Sri Lanka Personal Data Protection Act, you have the right to be informed about processing, to access your data, to have it corrected, to have it erased where the grounds in the Act are met, to withdraw consent, to object to processing including processing for direct marketing, to request a review of a decision made solely by automated means, and to complain to the Data Protection Authority.

How to exercise them

Email [email protected] and tell us which right you want to use and which email address or booking it concerns. We may ask one question to confirm your identity, and we will not use that check to delay you. We respond within thirty days. There is no charge, unless a request is manifestly excessive or repetitive, in which case we will tell you why and what it would cost before doing anything. If we refuse a request we will explain the reason.

Complaints

Come to us first, because most problems are fixed in a day. If you remain dissatisfied, you may complain to the Data Protection Authority of Sri Lanka, or, if you are in the UK or the EEA, to your national supervisory authority.

Security and changes to this policy

Access to learner data is limited to staff and instructors who need it, accounts are protected by individual logins, and data is encrypted in transit. No system is perfect; if a breach affects your rights we will tell you and the relevant authority as the law requires. When this policy changes we update the effective date at the top and, where the change is significant, we email account holders rather than relying on you to check.

Ask us about your data

Access, correction, erasure, an unsubscribe, or a question about where something is stored. One email address handles all of it.

This version has been in effect since 7 September 2026.