1. Introduction
Trainery One, LLC ('TraineryXChange,' 'we,' 'us,' or 'our') is committed to protecting your privacy. This Privacy Policy ('Policy') describes how we collect, use, disclose, and safeguard personal information when you access or use our website at traineryxchange.com, our TraineryLMS platform, our content marketplace, and all related services (collectively, the 'Platform').
This Policy applies to all visitors, registered users, Customer administrators, and learners who interact with the Platform. It applies regardless of whether you are using the Platform on behalf of an organization or as an individual.
By accessing or using the Platform, you agree to the terms of this Policy. If you do not agree, please do not use the Platform. We encourage you to review this Policy periodically. We will notify registered users of material changes by email or through a notice on the Platform at least thirty (30) days before changes take effect. Continued use after that date constitutes acceptance.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information received from third parties.
2.1 Information You Provide Directly
When you register for an account, request a demo, submit an inquiry, or use the Platform, we may collect:
- Account information: name, work email address, job title, organization name, phone number, and password.
- Billing and payment information: billing address, payment method details (processed through a third-party payment processor; we do not store full card numbers).
- Profile information: role, department, and preferences you configure in the Platform.
- Communications: messages you send to us via email, support tickets, or forms.
- User-generated content: training content, learning paths, or materials you upload to the Platform.
2.2 Information Collected Automatically
When you use the Platform, we automatically collect certain technical and usage information, including:
- Log data: IP address, browser type and version, operating system, referring URLs, pages visited, and timestamps.
- Device information: device type, unique device identifiers, and network information.
- Learning activity data: course enrollments, launch records, completion status, assessment scores, time spent on content, and certification records. This data is used to provide reporting and compliance tracking services.
- Cookies and similar technologies: we use cookies and similar tracking technologies to maintain sessions, remember preferences, and analyze usage. See Section 9 for more details.
2.3 Information from Third Parties
We may receive information about you from:
- Your employer or organization (our Customer), which may provide your name, email, and role when provisioning your access to the Platform.
- Third-party LMS platforms that you connect to the Platform via LTI, which may pass user context data as part of the integration.
- Marketing and analytics partners who provide aggregated insights to help us improve our services.
2.4 Sensitive Information
We do not intentionally collect sensitive personal information such as racial or ethnic origin, religious beliefs, health information, or financial account numbers. Please do not submit such information through the Platform.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Improving the Platform
- Creating and managing your account.
- Delivering training content and learning management features.
- Providing LTI and LMS integration services.
- Generating completion records, certificates, and compliance reports.
- Troubleshooting technical issues and providing customer support.
- Improving the Platform's features, performance, and content quality.
3.2 Communications
- Sending transactional emails such as account creation confirmations, password resets, and receipt notifications.
- Sending administrative notices related to your account or the Platform.
- Sending marketing communications about our products and services, where you have given consent or where we have a legitimate interest to do so. You may opt out at any time.
3.3 Analytics and Research
- Analyzing usage patterns to understand how the Platform is used and to identify areas for improvement.
- Generating anonymized and aggregated statistics that do not identify individual users ('Aggregate Data'). Aggregate Data may be used internally or shared with partners.
3.4 Legal and Compliance
- Complying with applicable law, regulation, legal process, or government request.
- Enforcing our Terms of Use and other agreements.
- Protecting the rights, property, and safety of TraineryXChange, our users, and the public.
3.5 Legal Basis (for EEA/UK Users)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data on the following legal bases: (a) performance of a contract, to provide the Platform and Services you have requested; (b) legitimate interests to improve our Platform, communicate with you, and prevent fraud; (c) consent, for marketing communications; and (d) legal obligation, to comply with applicable laws. You may withdraw consent at any time without affecting the lawfulness of prior processing.
4. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
4.1 With Your Organization
If you access the Platform as an employee or learner under a Customer account, your learning activity data, completion records, and certification status may be visible to your organization's administrators. We are a data processor in this context and act on your organization's instructions.
4.2 With Service Providers
We share information with third-party vendors who help us operate the Platform, including:
- Cloud hosting and infrastructure providers (e.g., servers, databases, CDN services).
- Payment processors for billing and subscription management.
- Email and communication service providers.
- Analytics and performance monitoring tools.
- Customer support platforms.
All service providers are bound by contractual obligations to protect your information and use it solely for the purposes for which they have been engaged. We require them to implement appropriate security measures.
4.3 With Content Publishers
If you access training content from a third-party Publisher, that Publisher may receive anonymized or aggregated data about course usage (such as completion rates) to support quality assurance and content updates. Publishers do not receive personally identifiable learner information unless required by a specific licensing arrangement and disclosed to you.
4.4 Business Transfers
If TraineryXChange is involved in a merger, acquisition, asset sale, or restructuring, your information may be transferred to the acquiring entity. We will notify registered users of any such transfer and any material changes to how your information is used.
4.5 Legal Disclosures
We may disclose your information if required by law, legal process, or government request, or if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation; (b) protect the rights or property of TraineryXChange; (c) prevent or investigate fraud or security incidents; or (d) protect the safety of our users or the public.
4.6 With Your Consent
We may share your information for any other purpose with your prior written consent.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services. Specifically:
- Account data is retained for the duration of your subscription and for a reasonable period afterward to handle post-termination queries, typically no longer than three (3) years.
- Learning activity records and certification data are retained for the duration of the Customer's subscription, plus the period required by the Customer's compliance obligations, or as specified in the Customer's data processing agreement.
- Billing and payment records are retained as required by applicable tax and financial regulations, typically seven (7) years.
- Support correspondence is retained for a period of three (3) years following resolution.
6. Data Security
We implement industry-standard technical and organizational security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit using TLS/HTTPS protocols.
- Encryption of data at rest using AES-256 or equivalent standards.
- Role-based access controls limiting internal access to personal data.
- Regular security assessments and vulnerability monitoring.
- Incident response procedures and breach notification protocols.
7. Your Privacy Rights
Depending on your location, you may have the following rights with respect to your personal information:
7.1 General Rights
We share information with third-party vendors who help us operate the Platform, including:
- Access: request a copy of the personal information we hold about you.
- Correction: request that we correct inaccurate or incomplete information.
- Deletion: request that we delete your personal information, subject to legal retention requirements.
- Restriction: request that we restrict processing of your information in certain circumstances.
- Data portability: request your personal information in a structured, machine-readable format.
- Objection: object to our processing of your information where we rely on legitimate interests.
7.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to:
- Know what personal information we collect, use, and disclose about you.
- Delete your personal information.
- Opt out of the sale or sharing of your personal information. (We do not sell personal information.)
- Non-discrimination for exercising your privacy rights.
- Limit the use of sensitive personal information.
To exercise your California privacy rights, submit a request to support@traineryxchange.com or call 800.397.5215. We will respond within forty-five (45) days as required by law.
7.3 EEA, UK, and Switzerland Residents (GDPR)
If you are located in the EEA, UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) or equivalent legislation, including those listed in Section 7.1. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, contact our Data Protection contact at support@traineryxchange.com. We aim to respond within thirty (30) days.
7.4 How to Submit a Request
To exercise any of the rights described in this Section, please email support@traineryxchange.com with the subject line 'Privacy Rights Request.' We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.
8. Children's Privacy
The Platform is designed for use by corporate organizations and their adult employees. It is not directed to individuals under the age of 18, and we do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a person under 18, please contact us at support@traineryxchange.com and we will take prompt steps to delete such information.
9. Cookies and Tracking Technologies
We use the following categories of cookies and similar technologies:
Essential cookies: required for the Platform to function, including session management and security. These cannot be disabled.
Functional cookies: remember your preferences and settings to enhance your experience.
Analytics cookies: help us understand how users interact with the Platform, enabling us to improve performance and content. We use tools such as Google Analytics.
Marketing cookies: used to deliver relevant advertising and track campaign effectiveness. These are only placed with your consent.
9.2 Managing Cookies
You can control cookies through your browser settings. Please note that disabling essential cookies may prevent certain features from functioning. Most browsers allow you to refuse third-party cookies. For more information on managing cookies, visit your browser's help section.
We do not currently respond to Do Not Track (DNT) signals, as there is no industry-standard interpretation. We will update this position if a standard is established.
10. Third-Party Links and Integrations
The Platform may contain links to third-party websites, tools, or services. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through the Platform. TraineryXChange is not responsible for the privacy practices or content of third-party sites.
When you connect the Platform to a third-party LMS or HR system, that system's privacy practices are governed by its own policies. We recommend reviewing those policies before enabling integrations.
11. International Data Transfers
TraineryXChange is based in the United States. If you are located outside the US, your information may be transferred to and processed in the US or other countries where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
For transfers from the EEA, UK, or Switzerland to the US, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission. Contact support@traineryxchange.com to request a copy of applicable transfer mechanisms.
12. Data Processing on Behalf of Customers
When TraineryXChange processes personal data on behalf of a Customer (such as learner completion records and activity data), we act as a data processor and the Customer acts as the data controller. In this capacity, we process data only in accordance with the Customer's documented instructions and applicable law.
Enterprise Customers may request a Data Processing Addendum (DPA) that specifies our obligations as a processor under GDPR and applicable US privacy laws. Please contact support@traineryxchange.com to request a DPA.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify registered users of material changes via email or a prominent notice on the Platform at least thirty (30) days before the changes take effect. The 'Last Updated' date at the top of this Policy indicates when it was most recently revised.
If you object to any changes to this Policy, you should stop using the Platform and contact us at support@traineryxchange.com. Your continued use of the Platform after changes take effect constitutes acceptance of the revised Policy.
14. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us at:
Trainery One, LLC
6801 Pleasant Pines Drive, Suite 103
Raleigh, NC 27613
Email: support@traineryxchange.com
Phone: 800.397.5215
Hours: 8:00 AM – 5:00 PM ET, Monday – Friday