1. Introduction
This Privacy Policy describes how CISOSHARE INSPECTION AUDIT SERVICES - L.L.C - S.P.C ("Cisoshare", "we", "us") collects, uses, and protects personal information through the Cisoshare Training Platform ("Platform"). By using the Platform, you consent to the practices described in this policy.
2. Information We Collect
We collect the following types of information when you use the Platform:
- Account information: organization name, your full name, email address, and authentication credentials.
- Attendee data: full names, email addresses, department, job title, employee ID, and phone number as provided by your organization for training enrollment.
- Training data: course enrollment records, assessment scores, completion dates, and certificate details.
- Identity verification: selfie photographs captured during training completion for certificate verification purposes.
- Usage data: browser type, access times, and pages viewed for platform improvement and security monitoring.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To deliver training content, manage enrollments, and track course progress.
- To issue training completion certificates and manage certificate validity.
- To process enrollment payments through our payment provider.
- To generate compliance reports and training evidence for your organization.
- To send service-related communications such as magic links, enrollment confirmations, and certificate notifications.
4. Data Retention
We retain training records, certificates, and associated data for as long as necessary to fulfill compliance requirements and the purposes described in this policy. You may request deletion of your personal data at any time, subject to applicable legal and regulatory retention obligations.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Personally identifiable information (PII) is encrypted at rest using AES-256-GCM encryption.
- All data transmitted between your browser and our servers is protected using TLS encryption.
- Multi-factor authentication (MFA) is required for all administrator accounts.
- Access controls ensure that organizational data is isolated and accessible only to authorized users.
6. Your Rights
In accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, you have the following rights:
- Right to access your personal data held by us.
- Right to request correction of inaccurate or incomplete data.
- Right to request deletion of your personal data, subject to legal retention requirements.
- Right to request a copy of your data in a portable format.
7. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at mail@cisoshare.ae.