Privacy and data protection
Privacy policy
This policy explains in plain language what personal data is handled when you use Talivo, why it is needed, and the choices and rights available to you.
Who is responsible for your data?
The organisation that invited you to its training portal normally decides why your learner data is used and is the data controller for that activity. Talivo operates Talivo on the organisation’s behalf and may also be responsible for limited platform administration, security, and support data. Contact your organisation first if you are unsure who controls your data.
Data we handle
Talivo stores only information needed to provide and protect the training service. Depending on how your organisation configures the portal, this may include:
- Identity and contact details such as your name, email address, language, profile picture, and organisation-requested profile fields.
- Memberships, assigned courses, reading progress, saved notes and highlights, quiz or exam answers and results, and completion history.
- Certificates, including certificate identifiers, issue and expiry dates, course details, and the information captured when a certificate is issued.
- Content you choose to submit, such as forum posts, uploaded material, and support messages.
- Technical and security data such as session records, IP address, browser information, timestamps, and audit or error logs.
Why we use the data
The data is used to create and secure accounts, deliver courses and assessments, save progress, calculate configured quiz and exam results, issue and verify certificates, communicate service information, provide support, prevent abuse, and meet legal obligations. The applicable legal basis is set by the responsible organisation and may include performance of a contract, legal obligation, legitimate interests, or consent where consent is required.
No payment data
Talivo does not provide checkout or card payment functionality and does not collect or store card numbers, bank details, or other payment credentials.
Service providers and sharing
The minimum necessary data may be processed by contracted providers that keep the service running, such as hosting, database and file storage, email delivery, and security or abuse-prevention services. They may process data only to provide those services under the applicable agreements and instructions.
If your organisation enables and you use an optional feature such as a video study room, AI study assistance, or CAPTCHA verification, the provider of that feature may receive the content or technical data needed to respond. The feature should identify itself when you use it.
Personal data is not sold or rented, used for advertising, or shared for unrelated commercial purposes.
Public certificate verification
Certificates can have a public verification link or identifier. Anyone who has it may be able to see the certificate status, holder name, organisation, course title, and issue or expiry dates. Do not publish your verification link more widely than you intend.
Cookies
Talivo uses necessary cookies for sign-in, security, session continuity, and remembering essential preferences. Talivo does not set advertising or analytics cookies. An optional external feature may use its own cookies or receive technical data when you open it; that provider’s terms then apply to its processing.
Retention and account deletion
Data is kept while the account and training relationship are active and afterwards only for as long as the responsible organisation needs it for the purposes above, certificate validity, security records, dispute handling, or a legal obligation. Data that is no longer needed should be deleted or de-identified.
Where self-service deletion is available, you can delete your account in Profile settings after confirming your password. This removes the account and data directly tied to it, including the uploaded profile picture, learning records, and certificates. Limited records may be retained or de-identified where deletion is restricted by law or a necessary security or legal record must be preserved. You can also contact support or your organisation to request deletion.
Your data-protection rights
Subject to the circumstances and applicable law, you can ask the responsible organisation to:
- Give you access to your personal data and information about how it is used.
- Correct inaccurate or incomplete data.
- Delete data or restrict how it is used.
- Provide portable data where the right to portability applies.
- Consider an objection or withdrawal of consent where that legal basis applies.
You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the competent supervisory authority where you live.
Security
Talivo uses access controls, tenant separation, encrypted connections, password hashing, audit records, and other technical and organisational safeguards designed to protect data. No online service can promise absolute security, so please use a strong password and report suspected misuse promptly.
Questions, support, or a rights request
Start with the administrator or support contact for the organisation that gave you access. They can answer questions about why your learner data is used and handle most access, correction, and deletion requests. For Talivo platform or privacy support, use the contact below when provided.
No central support email is published in this environment. Use the support contact provided by your organisation.
Changes to this policy
This page may be updated when the service or legal requirements change. The date at the top shows the latest revision. Material changes should be communicated through the portal or by the responsible organisation.