Privacy Policy
How Sodium Learn collects, uses, shares, and protects personal data across the platform and website.
1. Introduction
Sodium Learn ("Sodium Learn", "we", "us", or "our") is an intelligent learning and workforce capability platform that enables SMEs and startups to create content, deliver learning, and measure learner impact — all in one place, through three connected apps: Create, Manage, and Learn.
Organisations access Create, Manage, and Learn through their own dedicated Sodium Learn subdomain (for example, yourcompany.sodiumlearn.com) — separate from our public marketing website at sodiumlearn.com. This policy covers data practices across both, but they are different environments: browsing our marketing website (including its cookies, covered in our Cookie Policy) is a different data flow to using your organisation's own Sodium Learn environment, which is governed by our agreement with your organisation.
This policy explains how we collect, use, share, and protect personal data when:
An organisation subscribes to and administers Sodium Learn (Manage)
A user uses the platform to complete learning (Learn)
Someone creates or edits content on the platform (Create)
A visitor browses our website
Where an organisation subscribes to Sodium Learn, that organisation is generally the data controller for its users' personal data, and Sodium Learn acts as a data processor, handling that data under the organisation's instructions and our data processing terms. For account, billing, and marketing data relating to the organisation itself, and for website visitors, Sodium Learn acts as the data controller.
2. What Data We Collect
We collect some data directly. Other data is entered and managed by the client organisation within their own Sodium Learn tenant, and we process it on their behalf as a data processor.
Organisation & account data (collected by us): organisation name, billing contact details, billing address, and payment details (processed by our payment provider — we do not store full card numbers).
User data (entered and managed by the client organisation within their tenant; we process it on their behalf): name, email address, job title, department, manager, learning history, course progress, quiz and assessment results, certificates issued, and skills or role tags used to assign learning.
Content data (uploaded by the client organisation within their tenant; we process it on their behalf): files, courses, and materials created or uploaded in Create, along with authorship and version history.
Usage & device data (collected by us): log-in activity, IP address, browser and device type, and general usage patterns across Manage, Create, and Learn.
Website visitor data (collected by us): pages visited, referral source, and cookie data — see our Cookie Policy for details.
We do not knowingly collect more personal data than is needed to provide the platform.
3. How We Use Data
This processing is necessary to deliver the Sodium Learn platform. We use personal data to:
Provide, operate, and maintain Create, Manage, and Learn
Assign, deliver, and track learning, and issue certificates
Generate reporting and analytics for client organisation admins
Authenticate users and enforce role-based access control
Communicate service updates, security notices, and support responses
Improve the platform's reliability, usability, and features
Meet legal, regulatory, and contractual obligations
Detect, investigate, and prevent misuse, fraud, or security incidents
4. Our Legal Bases for Processing
Where UK GDPR applies, we rely on one or more of the following legal bases:
Contract — to provide the platform under our agreement with an organisation
Legitimate interests — to secure, maintain, and improve the platform
Consent — for optional communications or non-essential cookies, where required
Legal obligation — to comply with applicable law, such as tax and accounting requirements
5. Who We Share Data With
We share personal data only where necessary:
Sub-processors who help us run the platform, such as our infrastructure and hosting provider (Sodium Learn is built on AWS), email delivery, customer support, and analytics tools, each bound by a data processing agreement
The organisation that administers a user's account, who can access that user's progress and completion data as part of running their learning programme
Professional advisers and authorities, where required by law or to protect our rights
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
6. International Data Transfers
Where personal data is transferred outside the UK or European Economic Area, we put appropriate safeguards in place, such as standard contractual clauses, to ensure it continues to receive an equivalent level of protection.
7. Data Retention & Deletion
We keep personal data only as long as needed to provide the platform and meet legal obligations. When an organisation deletes a user account:
The account is soft-deleted and access is revoked immediately
A 30-day grace period follows, during which an admin can restore the account and all data
After the grace period, personally identifiable information is automatically anonymised — names, email addresses, and profile pictures are removed or replaced — while anonymised activity data is kept for reporting integrity
Organisations can request a full, permanent erasure of a user's data at any time by contacting our support team
8. Your Rights
If UK GDPR or the Data Protection Act 2018 applies to you, you have the right to:
Access the personal data we hold about you
Correct inaccurate or incomplete data
Request erasure of your data (subject to the retention rules above)
Restrict or object to certain processing
Receive your data in a portable format
Withdraw consent at any time, where processing is based on consent
Users should contact their organisation's admin first, as they control most user data. You can also contact us directly at privacy@sodiumlearn.com, and you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local data protection authority.
9. How We Protect Data
We protect personal data through:
Role-based access control across Create, Manage, and Learn
Secure authentication, including two-factor authentication (2FA) and single sign-on (SSO) options
Encryption of data in transit
Audit logging of key account and content actions
Enterprise Infrastructure built on AWS, designed with security and scalability in mind
No system is completely secure, but we continuously review and improve our safeguards.
10. Children's Data
Sodium Learn is a workplace platform intended for use by employees, contractors, and users on behalf of an organisation. It is not directed at, or knowingly marketed to, children.
11. Cookies
Our website and platform use cookies and similar technologies. See our Cookie Policy for full details and how to manage your preferences.
12. Changes to This Policy
We may update this policy as our platform or legal obligations change. We'll update the effective date above and, for material changes, notify organisation admins directly.
13. Contact Us
Questions about this policy or your data:
Email: privacy@sodiumlearn.com
Post: [Registered company address]