10.1
Security measures.
We use administrative, physical and technical safeguards appropriate to the information and risk, including role-based access, encryption, account controls, multi-factor authentication where supported, confidentiality requirements, logging where appropriate, backup and recovery controls, vendor management and incident-response procedures.
10.2
Minimization.
We limit collection, access, use and disclosure to information reasonably necessary for an authorized purpose and avoid retaining sensitive source information when a minimum result or verification record is sufficient.
10.3
User responsibility.
Users should protect account credentials, Booking Access Links, meeting links and devices, and should promptly report suspected unauthorized access or misdirected information.
11.
Retention and Destruction
11.1
Participant records.
Participant and training records follow the retention rule applicable to the service. Unless a different legal or contractual period applies, the default lifecycle generally ends 12 months plus one day after the applicable certificate or 365 Safety Record of Completion expires, or after completion where no expiry exists.
11.2
Financial records.
Checkout, payment, refund, transaction, invoice and reconciliation records are retained for at least seven years and are then reviewed rather than automatically deleted.
11.3
Operational, safety and conduct records.
Ordinary operational complaint, safety, quality or facility records are generally retained through closure plus three years. Serious safety, legal, insurance or safeguarding matters may be retained through closure plus five years or longer where required by law, contract, insurer, dispute or preservation hold.
11.4
Other records.
Support, privacy, security, vendor and Personnel records are retained for the period reasonably required by their purpose and applicable legal, contractual, audit, dispute or business requirements.
11.5
Preservation holds.
A legal, regulatory, contractual, insurance, complaint, investigation or litigation hold may extend an ordinary retention period for the affected information.
11.6
Destruction.
When retention ends and no hold applies, records are securely destroyed or otherwise disposed of using controls appropriate to the medium and sensitivity.
12.
Access, Corrections, Deletion Requests and Complaints
12.1
Requests.
You may contact the Privacy Officer to request access to Personal Information, request a correction, ask for deletion or disposition review, or make a privacy complaint, subject to applicable law and other lawful restrictions.
12.2
Verification.
We verify the requester's identity and authority proportionately before disclosing, correcting or deleting Personal Information.
12.3
Corrections.
A correction made in a 365 Safety record does not automatically update information already submitted to another organization. Where applicable, the external organization's separate correction process must also be followed.
12.4
Deletion and disposition.
A deletion request is reviewed against the applicable retention rule and any legal, contractual, accounting, audit, certification, insurance, dispute or preservation requirement. Receiving a request does not automatically require immediate destruction.
12.5
Response.
We document and respond to privacy requests and complaints in accordance with the applicable legal and operational process.
13.
Cookies and Technical Functions
13.1
Cookies and local storage.
Our website may use cookies or similar technologies that are necessary for session management, security, preferences, booking functions and other website features.
13.2
Browser controls.
You may be able to block or delete cookies through your browser, but doing so may prevent some website, booking or account functions from working properly.
13.3
Advertising profiles.
This policy does not authorize the creation of unrelated behavioural advertising profiles from Participant or training activity.