Privacy Policy
How DriftCore handles your information.
This Privacy Policy explains how DriftCore ("DriftCore", "we", "us") collects, uses, discloses and safeguards information when you use our training and competency management platform (the "Service"). DriftCore is a business-to-business service used by mining and industrial operators to manage employee training and competency records.
Who this applies to
- •Customers and their authorised users (account admins, trainers, supervisors, employees).
- •Personnel whose training and competency records a Customer stores in the Service.
- •For personal data a Customer enters about its personnel, the Customer decides what is collected and is the data controller; DriftCore acts as the data processor on the Customer's behalf.
Information we collect
- •Account data: names, work email, role, company and site.
- •Training & competency records: packages, assessments, sign-offs, signatures, certificates, expiry dates and training hours.
- •Uploaded files: certificates, photos and PDFs you add to records.
- •Technical & audit data: log entries, IP address, device/browser information and timestamps.
- •Communications: demo requests, sales and support messages.
How we use information
- •Provide and operate the Service.
- •Authenticate users and enforce role-based access.
- •Generate certificates, reports and compliance views.
- •Maintain security, integrity and audit trails.
- •Back up and protect data against loss.
- •Respond to support and sales enquiries.
- •Meet our legal obligations.
Legal bases
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing the Service, consent (where required), and compliance with legal obligations. For personal data entered by a Customer about its personnel, the Customer is responsible for establishing the lawful basis for that processing.
Data storage, location & retention
Data is stored in encrypted cloud infrastructure, held separately from where the live application runs. Records are backed up automatically to separate storage, with an optional immutable, write-once off-site copy. We retain Customer data for the life of the subscription and delete or return it after termination in line with our agreement, except where longer retention is required by law.
Sharing & sub-processors
We do not sell personal data. We share data only with vetted service providers (sub-processors) who host or support the Service, under confidentiality and data-protection obligations. See our Data Processing Agreement for details and to request the current sub-processor list.
Security
We use role-based access control, tenant isolation, encryption in transit and at rest, audit logging, and automated backups. See our Security page for more.
Your rights
- •Access, correct or delete personal data.
- •Object to or restrict certain processing.
- •Data portability, where applicable.
- •Withdraw consent where processing is based on consent.
- •These rights apply as provided under your local law (e.g. PIPEDA in Canada, GDPR/UK GDPR, or applicable US state privacy laws). If your data was entered by an employer using DriftCore, please contact that employer (the data controller) first.
International users
The Service may process data in countries other than where you live. Where required, we apply appropriate safeguards for cross-border transfers.
Children
The Service is intended for workplace use by adults and is not directed to children.
Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new effective date.
Contact
Questions about privacy? Contact privacy@driftcore-lms.com.