This privacy policy was last updated on August 25, 2026.
1. Introduction
DG-Learning processes personal data when providing its website, webshop, online learning platform, courses, group management, support and certificates.
We handle personal data carefully and only process it for clearly defined purposes. This privacy policy explains:
- which personal data we process;
- how we obtain this personal data;
- why we use this personal data;
- the legal grounds on which we process it;
- with whom personal data may be shared;
- how long we retain personal data;
- which rights you have.
This privacy policy applies to the website www.dglearning.eu, the webshop, the online learning platform, the associated account functions and the services provided by DG-Learning.
The products and services offered by DG-Learning are primarily intended for business customers and organisations. Students may receive an account directly or may be enrolled by an employer, client or group leader.
2. Data controller
DG-Learning is, in principle, the data controller within the meaning of the General Data Protection Regulation for the processing activities described in this privacy policy.
Contact details:
DG-Learning
Jacob Roggeveenstraat 171
2404 ZA Alphen aan den Rijn
The Netherlands
Chamber of Commerce number: 89314204
VAT identification number: NL004716653B15
Telephone: +31 (0)6 54 95 56 70
Email: [email protected]
Website: www.dglearning.eu
3. Responsibilities of business customers and group leaders
Business customers, employers, clients and group leaders may provide DG-Learning with the personal data of students and enrol students in a course.
The relevant organisation or group leader is responsible for:
- lawfully collecting and providing this personal data;
- informing students about their enrolment;
- only enrolling individuals who are authorised to participate in the course;
- keeping the provided personal data accurate and up to date;
- handling progress data, test results, certificates and exports to which access is granted with due care.
An employer or client may also be an independent data controller for its own use of this personal data.
Where DG-Learning processes personal data solely on the documented instructions of a client in a specific situation, additional agreements or a data processing agreement may be concluded.
4. Which personal data do we process?
Depending on how you use the website and our services, we may process the following personal data.
Contact and identification details
- first and last name;
- company name;
- job title or department, if provided;
- address details;
- telephone number;
- email address;
- correspondence and contact details.
Account and profile details
- username;
- securely hashed password;
- account role and access rights;
- preferred language;
- profile details;
- profile picture and cover image, if you add these yourself;
- optional employment and profile information;
- date on which the account was created;
- most recent login and recent account activity.
Passwords are not stored in readable form.
Order, group and licence details
- courses ordered;
- order number and order date;
- selected payment method and payment status;
- invoice details;
- group name;
- number of licences purchased and used;
- connection between the customer, group leader, group, course and student;
- enrolment date and expiry date of course access;
- information about the extension, modification or termination of course access.
Course and progress data
- course enrolments;
- course components started and completed;
- progress percentage;
- date and time of course activity;
- most recent activity;
- quiz attempts;
- answers given;
- correct and incorrect answers;
- scores and pass status;
- time spent on quiz questions or course components;
- final test results;
- date and time on which a course or final test was completed;
- information about resetting course progress or test results.
Certificate data
- name of the student;
- course followed;
- test result;
- completion date;
- date of issue;
- any validity or expiry date;
- certificate number or other certificate details;
- the digitally generated certificate file;
- information about viewing, downloading or sending a certificate.
Certificates are stored in a protected storage location within the hosting environment of DG-Learning. They are not intended to be publicly accessible without authorisation.
Payment data
- order amount;
- payment status;
- transaction reference;
- selected payment method;
- date and time of payment;
- any refund or cancellation.
DG-Learning does not generally receive complete bank or credit card details. These details are processed by the payment service provider during online payments.
Communication and support data
- email messages;
- support requests;
- private messages sent to DG-Learning;
- reports of errors or problems;
- responses from DG-Learning;
- any attachments or screenshots;
- status and processing details of a support request;
- technical information required to investigate a problem;
- sending and delivery status of necessary service emails.
Technical and security data
- IP address;
- date and time of a visit or request;
- browser and device details;
- operating system;
- pages and files requested;
- referring page;
- error messages;
- server and security logs;
- information about failed or suspicious login attempts;
- technically necessary cookie and session data.
Reviews and ratings
When you voluntarily submit a rating or review, we may process the following personal data:
- name;
- company position or role;
- star rating;
- written review;
- consent for publication;
- date of submission.
A review will only be published if consent has been given. You may withdraw this consent at a later date.
Other data
We may also process personal data that you actively provide to us, for example by email, telephone, through a form, in a support message or during other communication with DG-Learning.
We ask you not to provide special categories of personal data, a citizen service number or a copy of an identity document unless DG-Learning explicitly requests this in an exceptional situation and has a valid reason for doing so.
5. How do we obtain personal data?
We may receive personal data:
- directly from you;
- through an order or account registration;
- when you follow a course;
- when you take a quiz or final test;
- when you contact us;
- from your employer, client or group leader;
- when a group leader enrols you in a course;
- automatically when you use the website and learning platform;
- from our payment service provider in the form of payment and transaction statuses;
- from authorised employees or administrators who update personal data within the platform.
When an employer, client or group leader enrols a student, we generally receive the student’s name, email address, group and the course in which the student is enrolled.
6. Purposes and legal grounds
We only process personal data when there is a valid legal ground for doing so.
Performance of a contract
We process personal data for:
- processing and fulfilling orders;
- creating and managing accounts;
- providing access to purchased courses;
- creating and managing groups and licences;
- enrolling students;
- recording course progress and test results;
- making results available to authorised group leaders;
- generating, storing and providing certificates;
- answering questions and providing support;
- sending necessary service messages;
- processing payments, cancellations and refunds.
Legal obligation
We process personal data when this is necessary to comply with legal obligations, including:
- maintaining financial records;
- retaining invoices and order details;
- providing data to authorised public authorities where we are legally required to do so;
- handling requests under privacy legislation.
Legitimate interest
We may process personal data on the basis of a legitimate interest for:
- securing our website, accounts and systems;
- preventing and investigating fraud, misuse and unauthorised access;
- recording and resolving technical errors;
- monitoring the operation and availability of the platform;
- improving the reliability and user-friendliness of our services;
- establishing, exercising or defending legal claims;
- retaining proof of necessary service messages that have been sent;
- checking that course access, progress, results and certificates are processed correctly;
- providing effective group management to business customers.
We balance our interests against the privacy interests of the individuals concerned and do not process more personal data than necessary.
Consent
We only use consent where this is appropriate or legally required, for example for:
- publicly publishing a review or rating;
- publicly displaying voluntarily provided profile information where the user chooses to do so;
- other voluntary processing activities for which explicit consent is requested.
You may withdraw your consent at any time. Withdrawal of consent does not affect processing that lawfully took place before the consent was withdrawn.
7. Required and optional data
Some personal data is necessary for us to provide our services.
At least a name and a unique email address are required to create a personal course account. Without this information, we cannot provide a personal account, course enrolment, progress registration or certificate.
Additional company, address and invoice details may be required for an order and invoice.
Profile details such as a profile picture, cover image, job title or additional employment information are generally optional. Not providing this optional information does not affect your ability to follow a course.
8. Group leaders, employers and clients
When a student is added to a group, authorised group leaders of that group may view personal data that is necessary to manage the enrolment and monitor course results.
Depending on the functions used, group leaders may have access to:
- first and last name;
- email address;
- enrolment date;
- course and group;
- progress and completion status;
- most recent course activity;
- quiz and final test results;
- answers given and their assessment;
- date and time of completion;
- expiry date of course access;
- certificates obtained.
Group leaders may download or export results, student lists and reports. They may also download certificates and, where this forms part of the service, receive a certificate by email.
A group leader only has access to students and course data belonging to groups for which that group leader is authorised. Other students do not have access to the personal data, results or certificates of fellow students.
DG-Learning may carry out access checks and restrict access where there are indications of misuse or unauthorised use.
9. Profiles and visibility
Student profiles are not publicly accessible to visitors to the website.
Where necessary, a profile may be visible to:
- the relevant user;
- authorised administrators of DG-Learning;
- the authorised group leader of a group in which the user is enrolled.
Other students do not have access to another user’s profile or course results.
Any public example profiles of administrators or DG-Learning Support are excluded from this standard setting.
10. Certificates
After successfully completing a designated final test, a personal certificate may be generated automatically.
The certificate may:
- be displayed in the student’s account;
- be stored in the student’s personal certificate overview;
- be stored as a digital file in a protected storage location;
- be sent to the student by email;
- be viewed or downloaded by an authorised group leader;
- where applicable, be provided to the authorised group leader by email.
We use certificate data to provide evidence of completion, keep the certificate available, provide information about any expiry date and answer questions about its validity or issue.
11. Necessary service emails
DG-Learning does not send commercial newsletters, advertising messages or other marketing emails.
We may send necessary emails that form part of our services, including:
- order and payment confirmations;
- pro forma invoices and invoices;
- account and login instructions;
- confirmations of course enrolment;
- information about activated course access;
- reminders about a course that has not yet been completed;
- messages about the expiry of course access;
- certificates and messages about certificates;
- messages about certificates that are due to expire;
- responses to support requests;
- security and account notifications;
- information about important changes that affect an ongoing service or contract.
These messages are not commercial marketing and are necessary for performing the contract, managing the account or providing the requested service.
12. Payments through Mollie
Online payments are processed through Mollie.
To process and verify a payment, the following data may be provided to Mollie:
- name;
- email address;
- company and address details;
- order number;
- order amount;
- selected payment method;
- description of the order;
- technical data processed during the payment.
Mollie may also process payment data itself, such as a bank account number, card details, IP address, device details and transaction details.
As a payment service provider, Mollie is independently responsible to a significant extent for processing personal data that is necessary to execute, secure and administer payments. Mollie’s own privacy policy also applies to these processing activities.
DG-Learning generally only receives the information from Mollie that is necessary to determine whether a payment has been completed, failed, cancelled or refunded.
13. Storage and software used
DG-Learning uses a self-hosted WordPress environment.
Within this environment, software is used for:
- account and profile management;
- the webshop and orders;
- managing courses;
- recording progress and results;
- group management;
- generating and storing certificates;
- processing support requests;
- sending necessary service emails.
WordPress, WooCommerce, BuddyBoss and LearnDash, among others, operate as software components within the hosting environment of DG-Learning.
The use of this software does not mean that account, course and progress data is automatically stored on servers belonging to the software suppliers BuddyBoss or LearnDash. The data is generally stored in DG-Learning’s own WordPress database and file storage.
A software supplier may only be given access to personal data when this is necessary for technical support and DG-Learning has explicitly granted access. Access will then be limited as much as possible to what is necessary.
14. With whom do we share personal data?
We do not sell personal data or provide it to third parties for commercial purposes.
We may share personal data with the following recipients where this is necessary.
Hosting and technical management
The website, database, course data, orders and certificate files are processed within the hosting environment of DG-Learning.
DG-Learning uses TransIP for this purpose and may also use technical administrators who are only granted access where this is necessary for management, maintenance or security.
Cloudflare
DG-Learning uses Cloudflare for DNS, security, protection against unwanted traffic and the faster and more reliable delivery of the website.
Cloudflare may process technical request data, including:
- IP address;
- browser and device details;
- time of a request;
- page or file requested;
- security and network data.
Mollie
Mollie processes the data required for online payments and for its legal obligations as a payment service provider.
Email and communication service providers
Service providers required for sending, delivering and securing necessary emails may process email addresses, message data and technical delivery information.
Administration and professional advisers
Where necessary, personal data may be provided to:
- a bookkeeper or accountant;
- a legal adviser;
- a tax adviser;
- an insurer;
- other professional advisers who are subject to confidentiality obligations.
Gevaarlijke Stoffen Training en Advies B.V.
DG-Learning works together with Gevaarlijke Stoffen Training en Advies B.V.
Where this organisation is involved in content-related support, administration, customer service or the performance of services, authorised employees may have access to the personal data necessary for those activities.
Employers, clients and group leaders
Information about enrolment, progress, results and certificates may be made available to the authorised employer, client or group leader who ordered the course or group licences.
Public authorities and legal parties
We may provide personal data where we are legally required to do so or where this is necessary to establish, exercise or defend legal claims.
Where a service provider processes personal data on behalf of DG-Learning, we enter into a data processing agreement where required or make other appropriate privacy and security arrangements.
15. Processing outside the European Economic Area
We aim to process personal data within the European Economic Area as much as possible.
Some technical service providers or their subprocessors may process personal data outside the European Economic Area. This may, for example, occur in connection with Cloudflare’s global security and network infrastructure.
Where personal data is processed outside the European Economic Area, we ensure that there is a valid legal basis for the transfer and that appropriate safeguards are in place. This may include:
- an adequacy decision by the European Commission;
- participation in a data protection framework recognised by the European Commission;
- standard contractual clauses adopted by the European Commission;
- additional technical and organisational security measures.
You may contact us for more information about the safeguards used for a specific transfer.
16. Cookies
DG-Learning only uses strictly necessary and functional cookies and similar technologies that are required for the website, webshop and online learning platform to function correctly and securely.
These cookies may be used for:
- ensuring the secure operation of the website;
- recognising a logged-in user;
- securing a user session;
- remembering the selected language;
- keeping track of the contents of the shopping basket;
- completing the ordering and payment process;
- remembering technically necessary settings;
- distributing and securing internet traffic;
- preventing misuse and unwanted login attempts;
- temporarily storing data required to display a page correctly.
DG-Learning does not use cookies for:
- commercial advertisements;
- personalised advertising;
- tracking across different websites;
- building commercial user profiles;
- marketing purposes;
- analytical measurements that require consent.
Because only strictly necessary and functional cookies are used, prior consent is not required for these cookies.
The retention period differs for each cookie. Some cookies are deleted when you close your browser. Other cookies remain for a limited period to support a necessary function, such as remembering a language preference or maintaining a secure login.
You can delete or block cookies through your browser. If you block necessary cookies, you may be unable to log in, place an order or use certain parts of the learning platform.
When you are redirected to Mollie or another payment service during a payment, that party may use cookies that are necessary for its own security and payment processing. The privacy and cookie policy of that party applies to those cookies.
17. Automated processing
Certain actions within DG-Learning are carried out automatically, including:
- creating accounts and groups after an order;
- linking courses and licences;
- recording and calculating course progress;
- calculating test results;
- determining whether the required pass mark has been achieved;
- generating certificates;
- calculating expiry dates;
- sending necessary instruction, reminder, certificate and expiry messages;
- updating the status of orders and payments.
DG-Learning does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for an individual.
An automatically calculated test result may be reviewed by DG-Learning and, where necessary, corrected if there is a technical error or a demonstrably incorrect result.
18. Retention periods
DG-Learning does not retain personal data for longer than necessary for the purpose for which it was collected, unless a legal obligation or legitimate interest requires a longer retention period.
We generally apply the following periods and criteria.
Account and profile details
Account and profile details are retained for as long as the account remains active and the user has access to our services.
When an account is deleted, we delete or anonymise the account and profile details unless certain data must still be retained due to a legal obligation, certificate verification, an ongoing contract, a dispute or another legitimate reason.
Orders, invoices and financial records
Order, invoice and payment details that form part of our financial records are generally retained for seven years from the end of the relevant financial year, or longer if another statutory retention period applies.
Course enrolments and incomplete progress
Data relating to an incomplete course is retained for as long as access remains active and afterwards for as long as is reasonably necessary for support, recovery, extension, administration or the handling of questions.
This data is generally deleted or anonymised no later than two years after the expiry of course access or the most recent relevant course activity, unless a longer period is necessary.
Completion data, test results and certificates
Data required to demonstrate completion of a course, a test result or an issued certificate is generally retained for a maximum of seven years after the completion or issue date.
A longer period may apply where this is necessary because of:
- a contract with a client;
- the validity period of a certificate;
- a legal or sector-specific obligation;
- a dispute or legal claim;
- an explicit request to keep a certificate available for longer.
Support requests and correspondence
Support requests and related correspondence are generally retained for a maximum of two years after they have been resolved, unless the content forms part of a contract, complaint, dispute or technical file for which a longer retention period is necessary.
Technical error reports and support logs
Technical error reports and internal support logs are generally retained for a maximum of six months, unless they are required for longer to investigate a recurring problem, security incident or dispute.
Email and delivery logs
Technical data relating to the sending of necessary service emails is generally retained for a maximum of six months, unless a longer period is necessary to handle a problem, complaint or dispute.
Security and server logs
Security, access and server logs are generally retained for a maximum of twelve months. Data relating to a specific security incident may be retained for longer for as long as this is necessary for the investigation and handling of the incident.
Reviews
A published review is retained until:
- consent is withdrawn;
- the individual requests deletion;
- the review is no longer relevant;
- DG-Learning decides to remove the review.
Backups
After deletion, personal data may remain temporarily in secure backups. These backups are overwritten in accordance with our normal backup cycle and are not used for other purposes.
Where a backup is restored, previously received deletion requests will be processed again.
19. Deleting an account
You can delete your account through your account settings or contact DG-Learning to request deletion.
When your account is deleted, your account and profile details will be deleted or anonymised where we no longer require this personal data.
We may not be able to delete certain personal data immediately. For example, we may be required to retain order, invoice and payment details because of our statutory record-keeping obligations.
Data relating to certificates obtained, contracts, complaints, security incidents or legal claims may also be retained for longer where this is necessary.
Personal data may remain temporarily in secure backups after deletion. These backups are overwritten in accordance with our normal backup cycle.
After your account has been deleted, you will no longer have access to your courses, results and certificates. You should therefore download any certificates you wish to keep before deleting your account.
20. Security
DG-Learning takes appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unwanted disclosure and unauthorised alteration.
Depending on the processing activity, we use measures including:
- encrypted HTTPS connections;
- protected user accounts;
- securely hashed passwords;
- access rights based on user roles;
- restrictions that ensure group leaders can only view their own groups;
- protected storage of certificate files;
- security measures for forms and data requests;
- security and access logging;
- protection against unwanted and malicious internet traffic;
- software and security updates;
- backups;
- restricted administrator access;
- agreements with service providers regarding confidentiality and security;
- checks for misuse, incorrect access and technical failures.
Only individuals who require the personal data for their work are given access to it.
No method of storage or transmission is completely free of risk. If you suspect that your account or personal data is being used improperly, please contact us immediately.
21. Personal data breaches
Where a security incident involving personal data occurs, we investigate the incident and take appropriate measures.
Where legally required, we report a personal data breach to the Dutch Data Protection Authority.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, we will also inform the affected individuals.
22. Your privacy rights
Where the legal conditions are met, you have the following rights:
- the right to information about the processing of your personal data;
- the right to access your personal data;
- the right to correct inaccurate or incomplete personal data;
- the right to erasure of personal data;
- the right to restrict processing;
- the right to data portability;
- the right to object to processing based on a legitimate interest;
- the right to withdraw consent;
- the right not to be subject to certain decisions based solely on automated processing;
- the right to lodge a complaint with the Dutch Data Protection Authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
The right to erasure is not absolute. We may refuse a request in whole or in part where we are required to retain personal data because of a legal obligation, contract, certificate verification, security interest or legal claim.
23. Submitting a privacy request
You can send a privacy request to:
Please clearly state in your request:
- which right or request it concerns;
- which account or email address the request relates to;
- how we can contact you.
We do not routinely request a copy of an identity document.
We first try to verify your identity through the email address known to us, your logged-in account or other information already known to us.
Only where we have reasonable doubts about your identity may we ask for additional information.
If a copy of an identity document is necessary in an exceptional case, we ask you to obscure any information that is not required, including your photograph, citizen service number, document number and machine-readable zone.
Any copy received will be deleted after the identity check has been completed.
We will generally respond within one month of receiving the request.
Where a request is complex or we receive multiple requests, we may extend this period by a maximum of two months. We will inform you of any extension and the reason for it within the first month.
Privacy requests are generally handled free of charge. In the case of manifestly unfounded or excessive requests, we may charge a reasonable fee or refuse the request to the extent permitted by law.
24. Complaints
If you have a complaint about the way in which we process your personal data, please contact us first at [email protected].
We will make every effort to resolve your complaint carefully.
You also have the right to lodge a complaint with the Dutch supervisory authority:
Dutch Data Protection Authority
25. Changes to this privacy policy
DG-Learning may amend this privacy policy when our services, website, systems or legal obligations change.
The most recent version will be published on www.dglearning.eu.
The date of the most recent update is always shown at the top of the privacy policy.
Where significant changes affect active accounts or ongoing services, we may also inform users through the platform or by email.
