Privacy and data protection
Privacy policy
This policy explains in plain language what personal data is handled when you use Talivo, why it is needed, and the choices and rights available to you.
Who is responsible for your data?
The organisation that invited you to its training portal normally decides why your learner data is used and is the data controller for that activity. Talivo operates Talivo on the organisation’s behalf and may also be responsible for limited platform administration, security, and support data. Contact your organisation first if you are unsure who controls your data.
What Talivo will never do
Some commitments are easier to judge as promises than as paragraphs, so they are stated plainly. Talivo does not:
- Collect card numbers, bank details, or any payment credentials. There is no checkout in the product at all.
- Sell, rent, or share your personal data for advertising or any unrelated commercial purpose.
- Set advertising or analytics cookies, or track you across other websites.
- Build behavioural profiles, or make automated decisions with legal or similarly significant effects about you.
- Use facial recognition, biometric matching, or any technique that identifies a person from an image.
- Use your personal data to train artificial-intelligence models.
- Collect data because it might be useful later. Each item below exists because a feature you use needs it.
Data we handle
Talivo stores only information needed to provide and protect the training service. Depending on how your organisation configures the portal, this may include:
- Identity and contact details such as your name, email address, language, profile picture, and organisation-requested profile fields.
- Memberships, assigned courses, reading progress, saved notes and highlights, quiz or exam answers and results, and completion history.
- Records of practical or classroom approval, where your training includes a part that is assessed in person as well as online.
- Certificates, including certificate identifiers, issue and expiry dates, course details, and the information captured when a certificate is issued.
- A photograph, only where your organisation issues an identity card that carries one. See the separate section below.
- A delivery address, only where you or your organisation orders a printed card to be posted.
- Content you choose to submit, such as forum posts, questions to your organisation, uploaded material, and support messages.
- Notifications generated for you inside the portal, such as a new certificate or an answer to a question you asked.
- Technical and security data such as session records, IP address, browser information, timestamps, and audit or error logs.
Why we use the data
The data is used to create and secure accounts, deliver courses and assessments, save progress, calculate configured quiz and exam results, issue and verify certificates, communicate service information, provide support, prevent abuse, and meet legal obligations. The applicable legal basis is set by the responsible organisation and may include performance of a contract, legal obligation, legitimate interests, or consent where consent is required.
Data collected for one of those purposes is not quietly reused for another. Your reading progress is not sold as insight, your exam answers are not mined for research, and your questions to your organisation are not read for product analytics.
No payment data
Talivo does not provide checkout or card payment functionality and does not collect or store card numbers, bank details, or other payment credentials. Where your organisation pays for Talivo, that is arranged separately by invoice between the organisation and the operator, and it involves no learner data.
Photographs on identity cards
Some organisations issue a training card that carries a photograph so that a person checking the card can confirm it belongs to the holder. This only happens where your organisation has ordered a card design with a photograph on it.
- The photograph is supplied by your organisation, not taken by Talivo, and only its administrators and Talivo platform administrators can add, replace, or remove it.
- It is stored privately and is never published, never given a public web address, and never shown on the public certificate verification page.
- Location, camera, and other hidden data are stripped from the image when it is uploaded.
- No facial recognition, biometric template, or identity matching of any kind is performed on it. It is treated as an ordinary photograph, because that is what it is.
- Once the card it was supplied for has been produced and sent, the working copy is deleted. The issued card keeps its own copy, because that is what makes the card checkable.
- If you ask your organisation to erase your photograph, the card carrying it is revoked and the image is deleted.
If you would rather not have a photograph on your card, tell your organisation. They can issue a card design without one.
Service providers and sharing
The minimum necessary data may be processed by contracted providers that keep the service running, such as hosting, database and file storage, email delivery, and security or abuse-prevention services. They may process data only to provide those services under the applicable agreements and instructions.
If your organisation enables and you use an optional feature such as a video study room, AI study assistance, or CAPTCHA verification, the provider of that feature may receive the content or technical data needed to respond. The feature should identify itself when you use it.
AI study assistance is optional and works only where your organisation has switched it on, so it may not be part of your portal at all. Where it is in use, what reaches the AI provider is the text of the chapter you are reading and the question you typed. Your name, email address, and account details are not sent, and your questions are not used to train the provider’s models.
Personal data is not sold or rented, used for advertising, or shared for unrelated commercial purposes.
Videos inside course material
A course chapter may contain a video hosted by YouTube or Vimeo. Nothing is requested from those services when the chapter opens: you see a still card with the title and a play control, drawn by Talivo, and no script, image, or connection reaches the video provider.
When you choose to play the video, it loads from the provider through their privacy-enhanced address. From that moment the provider receives technical data such as your IP address and may set its own cookies, acting as an independent controller under its own privacy terms rather than on Talivo’s instructions. If you never press play, nothing is sent.
Public certificate verification
Certificates can have a public verification link or identifier. Anyone who has it may be able to see the certificate status, holder name, organisation, course title, and issue or expiry dates. A photograph is never shown on that page, even where the printed card carries one. Do not publish your verification link more widely than you intend.
If you contact us before becoming a user
If you request a demonstration or ask about getting started through the public Talivo site, the details you submit are stored so the operator can reply and arrange it. That record holds what you typed, the language of the page, and a one-way hashed form of your IP address kept to limit abuse of the form. It is not linked to any training portal, is not used for advertising, and is deleted when it is no longer needed for the conversation you started.
Cookies
Talivo uses necessary cookies for sign-in, security, session continuity, and remembering essential preferences. Talivo does not set advertising or analytics cookies. An optional external feature may use its own cookies or receive technical data when you open it; that provider’s terms then apply to its processing.
Retention and account deletion
Data is kept while the account and training relationship are active and afterwards only for as long as the responsible organisation needs it for the purposes above, certificate validity, security records, dispute handling, or a legal obligation. Data that is no longer needed should be deleted or de-identified.
Where self-service deletion is available, you can delete your account in Profile settings after confirming your password. This removes the account and data directly tied to it, including the uploaded profile picture, learning records, and certificates. Limited records may be retained or de-identified where deletion is restricted by law or a necessary security or legal record must be preserved. You can also contact support or your organisation to request deletion.
Your data-protection rights
Subject to the circumstances and applicable law, you can ask the responsible organisation to:
- Give you access to your personal data and information about how it is used.
- Correct inaccurate or incomplete data.
- Delete data or restrict how it is used.
- Provide portable data where the right to portability applies.
- Consider an objection or withdrawal of consent where that legal basis applies.
You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the competent supervisory authority where you live.
Security
Talivo uses access controls, tenant separation, encrypted connections, password hashing, audit records, and other technical and organisational safeguards designed to protect data. No online service can promise absolute security, so please use a strong password and report suspected misuse promptly.
Each organisation’s data is separated from every other organisation’s. Where the same person trains with two organisations, each holds its own record, and neither can see the other’s.
Questions, support, or a rights request
Start with the administrator or support contact for the organisation that gave you access. They can answer questions about why your learner data is used and handle most access, correction, and deletion requests. For Talivo platform or privacy support, use the contact below when provided.
No central support email is published in this environment. Use the support contact provided by your organisation.
Changes to this policy
This page may be updated when the service or legal requirements change. The date at the top shows the latest revision. Material changes should be communicated through the portal or by the responsible organisation.