Skip to content

Privacy Policy

Last updated: 2026-07-17

Who we are

Dryade Training ("we", "us") operates this training platform. We process personal data only as required to deliver the training programme you are enrolled in.

What we collect

Account data: your email address, name, role, locale preference, cohort memberships, and authentication factors (password hash, MFA secret, backup codes).

Usage data: which slides you have viewed, which exercises you have completed, the time spent per slide, your AI tutor conversations (when you initiate them), notes and flashcards you create, and quiz attempts.

Operational metadata: server logs containing request paths, response codes, and (for security forensics) hashed IP addresses. Raw IP addresses are never stored.

Why we collect it

To deliver the training: track progress, issue certificates, recommend levels, generate weekly nudges, and keep your account secure.

To improve the curriculum: aggregate completion rates and time-spent metrics drive editorial decisions about which slides need clarification.

To meet legal obligations: audit logs of administrative actions are retained for 365 days for compliance forensics.

Account integrity (anti-sharing)

Accounts are personal. To keep training records and certificates honest, we look for patterns of one account being active from different networks at the same time. This uses only data already listed above: activity timestamps, a salted hash of the network (never the raw IP address — no location can be derived from it), and the player tab identifier. No device fingerprinting and no geolocation are used.

These checks produce signals that a human administrator reviews; no automated decision or penalty is ever applied. This processing rests on our legitimate interest in preventing fraud (GDPR Recital 47) and is separate from the learning-support purposes above — learning data is not silently repurposed.

Cookies

We set a strictly necessary session cookie via NextAuth so you stay signed in. This cookie is exempt from consent under GDPR Article 5(3).

We do not set advertising or third-party tracking cookies. The cookie banner offers a "Necessary only" option which has no functional impact today; it exists so future optional analytics can be opt-in by default.

How long we keep it

Account data: for as long as your account is active. When you delete your account, we wait 30 days (so you can undo a rage-click via an administrator) and then hard-delete every row that contains your personal data. An audit log keeps your user id only for one further year for compliance forensics, then it too is purged.

Logs: rotated daily, retained 14 days.

Audit logs: 365 days; older rows are archived offline in compressed form.

Your rights

Under GDPR you may at any time: access your data (we will export it), correct it (via the profile page or by contacting an admin), erase it (Delete my account on the profile page; immediate sign-out, hard delete after 30 days), restrict processing, or object to processing.

You also have the right to lodge a complaint with your local supervisory authority.

Where to write to us

For data-protection enquiries: contact your training administrator or the operator of this deployment. The operator is responsible for honouring requests within 30 days.