1. Scope and who is responsible
This policy covers the Trung tâm Đào tạo ITI website and learning platform. It applies to learners whose accounts are issued by their company, learners who sign up on their own, training administrators, instructors and visitors to the public pages.
Platform operator: GEN-LMS. Personal data contact: our support team (via the contact form).
If you are an employee of a company that uses the platform, that company is the controller of your learning data: it decides which courses to assign and how reports are used, and the operator processes the data under its contract with them. If you signed up on your own, the operator is the controller of your data.
2. Data we collect
We collect the following four groups of data and nothing outside this list:
- Account data
- Name, email, sign-in ID, phone number, job title, profile photo, company, department, position, job level and staff code. Most of it is provided by your company when it issues your account; you add the phone number and profile photo yourself.
- Learning data
- Assigned and self-chosen courses, progress and study time per item, quiz attempts and answers, submissions, live session attendance, certificates, badges, points, lesson notes and competency assessments recorded by your manager.
- Technical data
- Sign-in and last activity times, the notifications sent to you, and server access logs (IP address, browser, pages opened) used for security and troubleshooting.
- Data you choose to send
- Discussion posts, messages to instructors, course reviews, and what you fill in on the contact form of the public site.
We do not ask for, and do not knowingly collect, sensitive data such as health, political opinions or biometric data.
3. How we use it
- To give you access to courses and record your learning progress.
- To issue certificates and let third parties verify them by code.
- To produce progress and compliance reports for your company.
- To notify you about assigned courses, deadlines, grading results and your account.
- To keep the system secure, detect unusual access and fix problems.
- To improve content using aggregate figures such as completion rates and question difficulty, not tied to individuals.
4. Legal basis
We process data on four bases: performing the service contract with your company (or with you, if you signed up yourself); legal obligations to keep training records; our legitimate interest in keeping the system secure; and your consent for activities that need separate consent.
Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.
5. Sharing
We do not sell personal data. Data is shared only in these cases:
- With your company: training administrators and line managers see the staff profile, progress, results, submissions and certificates of the people they manage.
- With instructors: instructors see learners' attempts, submissions, grades and messages in the courses they teach.
- When a certificate is checked: anyone with the certificate code can look up the holder's name, the course title and the issue date, but no email or contact details.
- With infrastructure providers: companies providing servers, networking and email delivery, under contracts with confidentiality terms and only as far as needed to run the service.
- When the law requires it: on a valid written request from a competent authority.
6. Retention
Account and learning data are kept for as long as the account exists, so your company can check training records and you keep your certificates. When your deletion request is approved, the data is anonymised as described in section 7. Some data is deleted automatically by a daily job:
- Report files exported by companies (which contain staff names): deleted after 30 days.
- Copies of your personal data that you request: downloadable for, and deleted after, 7 days.
- Read notifications: deleted 180 days after being read; unread ones are kept.
- Details sent through the contact form: deleted after 365 days.
- The admin log (administrator actions and sign-ins, with IP address and browser): kept as evidence, with no automatic deletion yet; only the administrators of the company or partner concerned and the operator can read it.
Server access logs are rotated by size and overwritten automatically; they are not kept long term.
System backups follow the operator's backup schedule and are used only to recover from incidents. Deleted data may remain in older backups until those are replaced.
7. Your rights and how to use them
Under Vietnamese personal data protection law (Decree 13/2023/ND-CP), you have the following rights over your personal data:
- To know which of your data is processed, why, and who can see it.
- To give, or withdraw, consent for processing that needs consent.
- To access and get a copy of your own data.
- To have wrong or outdated data corrected.
- To have your data deleted, except where the law requires it to be kept.
- To object to, or ask us to restrict, some processing.
- To complain to, or bring a claim before, the competent authorities.
Doing it in the product
Get a copy: go to Settings, Privacy and choose "Request a copy". The system packages all the data about you into a ZIP file (JSON and CSV) within minutes and notifies you in the app; the download link works for 7 days.
Delete your account and data: also in Settings, Privacy, choose "Request account deletion" and re-enter your password to confirm. Platform staff handle the request within 72 hours; if it is rejected, for example because the law requires records to be kept, you get a notification with the reason. Once approved:
- the account can no longer sign in and every open session ends immediately;
- your name, email, sign-in ID, phone number, job title, profile photo and staff code are replaced with non-identifying values;
- your discussion posts, messages, reviews, written answers and submission content are replaced with a "deleted" line; notes, notifications and settings are removed;
- learning results stay in your company's training reports but are no longer linked to your name; certificates can still be checked by code but no longer show your name.
Corrections: you can change your name, phone number and profile photo yourself in Settings, Account; your job title, department and position are changed by your company's training administrator.
Send any other personal data request to our support team (via the contact form); we respond within 72 hours. If your account was issued by your company, we may need to involve that company, as it is the controller of your learning data.
9. Security
Connections to the system are encrypted in transit. Private files (submissions, course materials, reports, data copies) can only be downloaded through permission-checked routes, never from public links. Passwords are stored hashed. Administrative actions on staff accounts are logged.
No system is perfectly secure. If an incident affects personal data, we notify the companies involved and the competent authority within the legally required time.
10. Hosting and transfers abroad
Data is stored on servers owned or rented by the operator. If any part of the infrastructure (servers, content delivery, email delivery) is located outside Vietnam, transfers abroad follow Vietnamese personal data protection law and are covered by contractual confidentiality commitments from the recipient. The list of providers and storage locations is available to companies on request.
11. Changes to this policy
When this policy changes, we update the effective date at the top of the page. For changes that significantly affect your rights, we let you know in the product or by email before they apply.
12. Privacy contact
For any question or request about personal data, use the contact form and choose the matching topic.
Getting a copy or requesting deletion is fastest from Settings, Privacy. Questions about how your company uses your learning data are best sent to your company's training administrator.
