1. Our no-sharing commitment
ARiiSE does not sell, rent, trade, or share Client or learner data with others for advertising, marketing, profiling, or their independent business purposes. We do not use Client or learner data to advertise to Users, build advertising audiences, sell mailing lists, or make it available to third parties for their own purposes.
2. Who this policy applies to
This policy applies to institutions and other clients that use the Services, and to their authorised administrators, teachers, staff, students, parents, guardians, and other users whose data is placed on the Platform.
For Client, learner, teacher, and staff data, the Client is normally the Data Fiduciary and ARiiSE acts as its Data Processor. ARiiSE acts as an independent Data Fiduciary only for its own business-contact, billing, support, and website data. The Client is responsible for notices, permissions, consent or other lawful basis, and documented processing instructions.
3. Data we may process
- Account, identity, and contact details, such as names, usernames, email addresses, phone numbers, institutional role, and login details.
- Learning and academic records, such as course enrolment, attendance, grades, submissions, certificates, reports, and progress data.
- Content supplied to the Platform, such as course materials, messages, uploaded files, images, and assessment material.
- Technical and security data, such as IP address, device or browser information, session information, audit logs, and security events.
- Support and billing information, such as support tickets, authorised contacts, invoices, payment status, and communications with ARiiSE.
4. Why we use data
- To provide, configure, host, maintain, and support the Platform.
- To authenticate users, control access, prevent misuse, and protect the security of the Platform and data.
- To generate reports, exports, backups, and functions requested by the Client.
- To communicate about support, service operation, billing, renewal, security, or material changes.
- To comply with applicable law and valid legal requests, resolve disputes, investigate incidents, and enforce our agreements.
5. Limited circumstances where data may be accessed or disclosed
We do not disclose Client or learner data to unrelated third parties. Access or disclosure is limited to the following circumstances:
- The Client and its authorised representatives, according to their access permissions.
- The hosting vendor named in the Service Order, including AWS, DigitalOcean, Hostinger, or a local vendor selected by the Client.
- An essential service provider engaged solely to operate, secure, back up, or support the agreed Services, only where necessary and subject to written confidentiality and data-protection obligations.
- A disclosure required by applicable law, a valid court order, or a lawful request from an authorised government authority.
- A necessary investigation or response to fraud, a security incident, misuse, or a threat to people, the Platform, or data.
6. Hosting, storage, and security
The Service Order identifies the hosting vendor and deployment location. ARiiSE-managed hosting may use infrastructure operated by AWS, DigitalOcean, Hostinger, or a local vendor. We use commercially reasonable technical and organisational safeguards designed to protect data from unauthorised access, alteration, loss, disclosure, or destruction.
If ARiiSE confirms a security incident that materially affects Client Data, we will notify the Client without undue delay. Users and Clients must protect account credentials and promptly report suspected unauthorised access.
7. Retention, backups, and deletion
We retain data for the Client’s active service term and for the backup-retention period stated in the Service Order. We retain data longer only where required by law or necessary to resolve a dispute or security incident.
When a Client-authorised user deletes data, ARiiSE removes it from the active Platform after 7 days. It may remain in protected backups for the stated backup-retention period and is not restored except for an authorised recovery request. If the Client does not renew, ARiiSE retains Platform data for 30 days after the overdue renewal date, after which it may be deleted or the Platform deprovisioned, subject to applicable law.
8. Access, correction, exports, and requests
An authorised Client representative may request student data, reports, a backup, or an export at info@ariiseglobal.com. We acknowledge a valid request within 7 Business Days and provide the available information in the agreed format through a secure channel. The Service Order states what is included; substantial custom processing may require a separate quotation.
Data Principals may contact info@ariiseglobal.com to ask about ARiiSE’s processing of personal data, raise a grievance, or exercise applicable rights. We will verify the request, coordinate with the Client where it controls the educational record, and respond within 30 calendar days unless applicable law requires a shorter period.
9. Children’s data, changes, and contact
Where the Platform is used by children, ARiiSE processes children’s data only under the Client’s documented instructions and for the agreed educational service. The Client must obtain any required verifiable parent or guardian consent. ARiiSE does not use children’s data for targeted advertising or behavioural monitoring.
This Privacy Policy takes effect on 5 September 2026. We may update it when our Services, practices, or legal obligations change. For privacy questions, requests, concerns, or complaints, contact info@ariiseglobal.com.