GDPR Data Protection Notice
Knolyx Tech SRL · knolyx.com
Effective date: 2025 November 24
This GDPR Data Protection Notice explains how we, Knolyx Tech SRL (“Knolyx”, “we”, “us”), process your personal data when you create and use a Knolyx account on our learning platform (the “Platform”).
This Notice is intended to satisfy the information requirements of Articles 12–14 GDPR and supplements our main Privacy Policy. In case of conflict, the Privacy Policy and any applicable agreement with your organization (the “Customer”) will prevail.
By creating an account and clicking “I agree” during registration, you acknowledge that you have read and understood this GDPR Data Protection Notice.
1. Identity and Contact Details of the Controller
In most cases:
-
Your organization (e.g., employer, university, training provider) is the data controller for personal data processed through the Platform for learning, training, and compliance purposes.
-
Knolyx acts as a data processor for those purposes, under a data processing agreement with the Customer.
For some activities (such as operating our infrastructure, securing and improving the Platform, managing your Knolyx account where you register directly with us, and direct marketing where permitted), Knolyx also acts as an independent data controller.
Knolyx Tech SRL
2nd Aleea Politehnicii Street, District 6
Bucharest, Romania, 061344
Email: office@knolyx.com
Telephone: +40 765 331 509
If your access is provided by a Customer, they should also provide their own contact details and privacy information to you.
2. Categories of Personal Data We Process
Depending on how you use the Platform and how your organization configures it, we may process:
-
Identification & contact data
-
Name, email address, username, profile photo (if added), role, department, organization, phone (if provided).
-
-
Account & authentication data
-
Password (stored in encrypted form), login timestamps, account status, access rights and roles.
-
-
Learning & usage data
-
Courses and modules assigned or enrolled, progress, completion status, scores, certificates, badges, learning paths, comments, forum posts, messages, and other activity within the Platform.
-
-
Embed entity & content interaction data
-
Metadata about embedded content (e.g., URLs, titles, descriptions), view duration, interactions (play/pause/seek), completion rates, and learning progress related to embedded content.
-
-
Technical and device data
-
IP address, browser type and version, operating system, device identifiers, session IDs, performance and error logs, security logs.
-
-
Communication data
-
Support requests, feedback, email and in-app notification engagement (open/click information), responses to surveys where used.
-
-
Marketing and consent data (where applicable)
-
Your marketing preferences and records of consent and withdrawal.
-
We do not intentionally seek to collect special categories of data (e.g., health, religion) through the Platform, unless your organization consciously configures such fields under its own responsibility and lawfully informs you.
3. Purposes and Legal Bases for Processing
Where the GDPR applies, we rely on the following legal bases:
-
Performance of a contract (Art. 6(1)(b) GDPR)
To:-
Create and manage your user account
-
Provide access to courses, content, and Embed entities
-
Track and record your learning progress, assessments, and certifications
-
Provide user support related to the Platform
-
-
Legitimate interests (Art. 6(1)(f) GDPR)
For:-
Securing and maintaining the Platform (fraud detection, abuse prevention, security logging)
-
Generating aggregate analytics for Customers (e.g., learning statistics, platform usage trends)
-
Improving features, performance, and user experience
-
Protecting our rights, enforcing our terms, and defending legal claims
We balance these interests against your rights and freedoms and take appropriate safeguards.
-
-
Legal obligations (Art. 6(1)(c) GDPR)
For:-
Compliance with applicable laws, such as tax, accounting, and regulatory requirements
-
Responding to lawful requests from competent authorities, where required
-
-
Consent (Art. 6(1)(a) GDPR)
For:-
Optional direct marketing communications from Knolyx (e.g., newsletters, product updates), where required by law
-
Certain cookies, tracking technologies, or personalized ads where consent is the lawful basis
-
Participation in certain research, beta or feedback programs, if offered
You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
-
Where we process your data on behalf of a Customer, the legal basis usually stems from the Customer’s relationship with you (e.g., employment, enrollment, or training contract). In that case, the Customer should inform you about its specific purposes and legal bases.
4. Recipients and Categories of Recipients
We may share personal data with:
-
Customer / your organization
-
Admins, managers, trainers and other authorized users who manage learning programs, assignments, progress, and compliance.
-
-
Service providers (processors)
-
Cloud hosting providers, email and notification services, analytics providers, security and monitoring tools, and other IT service providers engaged by Knolyx under written data processing agreements.
-
-
Third-party content and integration partners
-
Approved content platforms (e.g., for embedded videos) and integration partners (e.g., SSO, HR systems) where necessary for content delivery, authentication, or data synchronization, under appropriate contractual and/or technical safeguards.
-
-
Professional advisers and auditors
-
Legal, accounting, or audit professionals under confidentiality obligations.
-
-
Public authorities and regulators
-
Where required by law, court order, or administrative decision.
-
-
Potential acquirers
-
In the context of a merger, acquisition, or business transfer, subject to confidentiality and data protection obligations.
-
We do not sell your personal data.
5. International Transfers
Your data may be stored and processed in the European Union (including Romania) and, where necessary, in other countries where our service providers or Customers operate.
If data is transferred to a country outside the European Economic Area (EEA) or to a country without an adequacy decision, we will ensure appropriate safeguards such as:
-
Standard Contractual Clauses approved by the European Commission, or
-
Other lawful transfer mechanisms under GDPR.
You may request more information about these safeguards using the contact details below.
6. Data Retention
We keep your personal data only for as long as necessary to fulfill the purposes described above or as required by law, including:
-
For the duration of your account and the Customer’s contract with Knolyx
-
For a reasonable period after account deactivation to handle support, disputes, audits, or legal obligations
-
For longer where we are legally required or where necessary for the establishment, exercise, or defense of legal claims
Typically, your learning records and Embed interaction data are retained in line with the contract with your organization and relevant compliance requirements.
Where processing is based on your consent (e.g., marketing), data will be retained until you withdraw consent or the data is no longer needed.
7. Your Rights Under GDPR
Subject to the conditions and limitations in GDPR, you may have the following rights regarding your personal data:
-
Right of access – to obtain confirmation whether we process your data and receive a copy.
-
Right to rectification – to correct inaccurate or incomplete data.
-
Right to erasure – to request deletion of your data in certain circumstances (“right to be forgotten”).
-
Right to restriction – to request the restriction of processing in certain circumstances.
-
Right to data portability – to receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller.
-
Right to object – to object, on grounds relating to your particular situation, to processing based on our legitimate interests, including profiling; and to object at any time to processing for direct marketing.
-
Right to withdraw consent – where processing is based on consent, you can withdraw it at any time (this does not affect prior lawful processing).
Where your organization is the primary controller, you may need to exercise some of these rights directly with them. We will assist the Customer in responding to such requests as required.
To exercise your rights, please contact us using the details in Section 10. We may need to verify your identity before fulfilling your request.
8. Is Providing Your Data Mandatory?
When creating and using a Platform account:
-
Certain data (e.g., name, email, login credentials) is necessary to create and maintain your account and to provide the service. If you do not provide this data, you will not be able to use the Platform.
-
Other data is optional, such as some profile fields or preferences; if you do not provide them, some features may be limited but your core access to the Platform is not affected.
-
Consent-based uses (e.g., marketing emails) are voluntary, and refusal or withdrawal of consent will not affect your access to the Platform’s core learning functionality.
9. Automated Decision-Making and Profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.
We may use limited profiling and analytics (e.g., to recommend content, identify engagement patterns, or generate learning reports) to improve your learning experience and support your organization, but such processing does not involve decisions with legal or similarly significant effects without human involvement.
10. Contact and Complaints
If you have questions, requests, or concerns about how we process your personal data, or if you wish to exercise your rights under GDPR, please contact:
Knolyx Tech SRL
Attn: Data Protection / Privacy
2nd Aleea Politehnicii Street, District 6
Bucharest, Romania, 061344
Email: office@knolyx.com
Telephone: +40 765 331 509
You also have the right to lodge a complaint with your local data protection authority. In Romania, this is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Website and contact details are available on the authority’s official page.
11. Changes to This GDPR Data Protection Notice
We may update this Notice from time to time to reflect changes in our processing activities, legal requirements, or the Platform.
We will indicate the effective date at the top and may notify you via the Platform or by other appropriate means where the changes are material. Continued use of the Platform after the effective date will signify that you have read the updated Notice.