Privacy Policy

Last Updated: October 3, 2026

1. Introduction

LMS Tech ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our learning management platform and related services (the "Services").

We operate globally, serving users in India, the United States, and Europe. This policy complies with:

  • Europe: General Data Protection Regulation (GDPR) - EU 2016/679
  • United States: California Consumer Privacy Act (CCPA), Family Educational Rights and Privacy Act (FERPA), and Children's Online Privacy Protection Act (COPPA)
  • India: Information Technology Act, 2000, and Digital Personal Data Protection Act, 2023 (DPDP Act)

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password, phone number, organization details
  • Profile Information: Profile picture, bio, educational background, skills, certifications
  • Educational Data: Course enrollment, progress, grades, assignments, assessments, certificates
  • Communication Data: Messages, forum posts, feedback, support tickets
  • Payment Information: Billing address, payment method (processed securely by third-party processors)

2.2 Information We Collect Automatically

  • Usage Data: Pages viewed, features used, time spent, actions taken
  • Device Information: IP address, browser type, device type, operating system
  • Log Data: Access times, pages viewed, referral URLs, crash data
  • Cookies and Tracking: See our Cookie Policy for details

2.3 Information from Third Parties

  • OAuth providers (Google, etc.) when you use social login
  • Payment processors for transaction verification
  • Educational institutions providing course content

3. How We Use Your Information

We use your information for the following purposes:

  • Service Provision: Deliver, maintain, and improve our Services
  • Account Management: Create and manage your account
  • Communication: Send course updates, notifications, support responses
  • Personalization: Customize your learning experience and recommendations
  • Analytics: Understand usage patterns and improve Services
  • Security: Detect fraud, prevent abuse, ensure platform security
  • Legal Compliance: Comply with applicable laws and regulations
  • Marketing: Send promotional content (with your consent, where required)

Legal Basis for Processing (GDPR)

  • Performance of contract (to provide Services)
  • Legitimate interests (to improve Services and ensure security)
  • Legal obligation (to comply with laws)
  • Consent (for marketing and non-essential cookies)

4. How We Share Your Information

We may share your information with:

  • Educational Institutions: Your organization/school administrators to track progress
  • Service Providers: Cloud hosting (AWS), payment processors (Razorpay), email services (Resend)
  • AI Services: OpenAI/Anthropic for AI assistant features (anonymized where possible)
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In case of merger, acquisition, or sale of assets

We do NOT:

  • Sell your personal information to third parties
  • Share your educational records without consent (except as required by FERPA)
  • Use your data for purposes incompatible with this policy

5. Data Retention

We retain your information for as long as necessary to:

  • Provide Services and maintain your account
  • Comply with legal obligations (e.g., tax records: 7 years)
  • Resolve disputes and enforce agreements

Specific retention periods:

  • Account data: Active accounts + 2 years after deletion
  • Educational records: As required by FERPA (typically 5 years)
  • Payment records: 7 years (tax compliance)
  • Analytics data: Anonymized after 26 months (GDPR compliance)

6. Your Rights

For EU Users (GDPR Rights):

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure ("Right to be Forgotten"): Request deletion of your data
  • Restriction: Limit how we process your data
  • Data Portability: Receive your data in a portable format
  • Object: Object to processing based on legitimate interests
  • Withdraw Consent: At any time for consent-based processing
  • Lodge a Complaint: With your local data protection authority

For California Users (CCPA Rights):

  • Right to Know what personal information is collected
  • Right to Delete personal information
  • Right to Opt-Out of sale (note: we don't sell data)
  • Right to Non-Discrimination for exercising rights

For Indian Users (DPDP Act Rights):

  • Right to access information about personal data processing
  • Right to correction and erasure of inaccurate data
  • Right to nominate another individual to exercise rights after death
  • Right to lodge grievance with Data Protection Board

To exercise your rights, contact us at: privacy@lmstech.com

7. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs) for transfers from EU
  • Adequacy Decisions where applicable
  • Data Processing Agreements with all service providers

Primary data storage locations: AWS (US-East, EU-West, AP-South regions based on your location)

8. Data Security

We implement industry-standard security measures:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Regular security audits and penetration testing
  • Access controls and authentication (MFA available)
  • Secure development practices
  • Employee training on data protection
  • Incident response procedures

Despite our efforts, no method of transmission or storage is 100% secure. If you suspect a security breach, contact us immediately at security@lmstech.com.

9. Children's Privacy

COPPA Compliance (USA): We do not knowingly collect information from children under 13 without verifiable parental consent. Educational institutions using our Services for students under 13 must obtain necessary consents.

GDPR (EU): Users under 16 (or lower age set by member state) require parental consent for information society services.

India: Children under 18 require parental/guardian consent as per DPDP Act.

If you believe we have collected data from a child without proper consent, contact us at privacy@lmstech.com.

10. Cookies

We use cookies and similar tracking technologies. See our Cookie Policy for detailed information about:

  • Types of cookies we use
  • Purpose of each cookie
  • How to manage cookie preferences
  • Third-party cookies

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by:

  • Posting the updated policy on this page
  • Updating the "Last Updated" date
  • Sending email notification (for significant changes)
  • In-app notification

Your continued use of Services after changes indicates acceptance of the updated policy.

12. Contact Us

For privacy-related inquiries, contact:

Email: privacy@lmstech.com

Data Protection Officer (DPO): dpo@lmstech.com

Mailing Address:
LMS Tech Privacy Team
[Your Address]

Supervisory Authorities:

  • EU: Contact your local data protection authority (list here)
  • India: Data Protection Board (once operational under DPDP Act)
  • USA: Federal Trade Commission (FTC)

13. Region-Specific Disclosures

California Residents (CCPA)

Categories of Personal Information Collected (Last 12 Months):

  • Identifiers (name, email, IP address)
  • Commercial information (transaction history, course purchases)
  • Internet activity (usage data, browsing history)
  • Geolocation data
  • Audio/visual information (profile photos, recorded sessions)
  • Education information (courses, grades, certificates)

Do Not Sell: We do not sell personal information.