Privacy Policy
This policy explains what personal data Learnery collects, why we collect it, how we use and protect it, and the rights you have. Learnery ("we", "us") provides an online workplace AI training service at learnery.io. Learnery is operated by , based in Athens, Greece; our full legal identity, registered address and tax number are on our Legal notice. If your employer bought your seat, our Data processing with them also applies. For any privacy question, write to [email protected].
1. Information we collect
- Account data. When a business or an employee registers, we store name, work email, company, chosen industry and role, language, and login credentials or the Google account identifier used to sign in.
- Training data. Lesson progress, quiz answers, prompt exercises, chat practice, and certificates earned inside the seminar. The text you type into the exercises, and the questions you ask the AI tutor, are sent to our AI provider to generate feedback and examples, as described in section 5.
- Assessment data. If you complete our free AI readiness assessment, we store your answers, the resulting score and readiness band, and, when you ask us to email the report, your work email and any company name and team size you give us.
- Payment data. When a business buys seats, payment is processed by Stripe. We receive an order record and a payment reference. We never see or store full card numbers.
- Contact and sales data. If you use our contact form, or ask us to send you the result of our ROI calculator, we store the name, company, phone, work email, job title, team size and message you give us, so we can reply.
- Where employee data comes from. If your employer bought your seat, we received your name and work email from your employer rather than from you, and your employer decides who is invited.
- Usage and device data. Page visits, referring website, campaign parameters (UTM values), approximate device type, browser, operating system, and a hashed identifier. We do not store raw IP addresses in the clear.
2. How we use your data
- To provide the training service and keep track of progress and certificates.
- To process seat purchases and send order confirmations.
- To answer contact requests and follow up about a rollout.
- To understand which channels and campaigns bring us visitors, using our own first party analytics, so we can improve the product and our marketing.
- To keep the service secure and prevent abuse.
3. Legal bases
Where the GDPR applies, we rely on the following legal bases. Performance of a contract, to run the service you or your employer signed up for and to take payment. Consent, for the attribution cookie described in section 4, which we set only if you accept it in the cookie notice. Legitimate interests, to keep the service secure, to prevent abuse, to answer a business enquiry you send us, and to measure our own audience with analytics that run on our own servers, set no cookie and do not profile you. Legal obligation, for example keeping invoices for tax. Where we rely on consent you may withdraw it at any time, and where we rely on legitimate interests you may object.
4. Cookies and analytics
We keep cookies to a minimum. We use a session cookie to keep you logged in, a cookie to remember your language, and a first party attribution cookie that records which campaign or referring site brought you to us, so we know where our customers come from. That attribution cookie is set only if you choose Accept in our cookie notice, it lasts 90 days, and choosing Essential only means it is never set at all. We also keep a cookie that records your cookie choice, so we do not ask you again.
While we are advertising we do load one measurement tag, the Google tag, on every page. It lets us see which adverts bring people here, and it sets cookies from Google’s own domain once you have agreed. We also load the Meta pixel, and only if you agree: if you refuse it is never fetched and Meta learns nothing about your visit. It lets us show our adverts again to people who have visited the site, and it sets cookies from Meta’s own domain.
While we are advertising, and only if you agreed in the cookie notice, one further thing happens, and only when you buy: our server sends Google and Meta a message saying that a purchase took place, its value, and the click code that was in the link you arrived on. That code is how they recognise which advert you clicked. We do not send your name, your email address, your telephone number, or any scrambled form of them, and we send nothing at all about visitors who do not buy. This happens from our server, so there is still no advertising pixel on any page of this site and still no advertising cookie in your browser. The click code is not anonymous, because recognising your click is the whole point of it, so we treat it as personal data about you. Our legal basis is your consent under Article 6(1)(a), and you can withdraw it at any time from the cookie notice, after which nothing further is sent.
While the Google tag is running, one thing happens even if you refuse. The tag loads for every visitor and sends Google a message saying a page was opened: the address of the page, where you came from, your browser type, the time, and the fact that you refused. It writes no cookie, sends no name and sends no identifier, and Google uses it to estimate the visits and sales it is not permitted to measure directly. Your IP address reaches Google as part of that request, as it does with any request a browser makes to any server, so we do not describe this as anonymous. If you accept, the same tag also measures the visit properly and records the sale. You can change your answer at any time from the cookie notice.
| Cookie | What it is for | How long | Needs your consent |
|---|---|---|---|
ATSID |
Keeps you signed in | Until you close the browser | No |
lang |
Remembers the language you chose | 365 days | No |
lrn_cookie_ack |
Remembers your cookie choice so we do not ask again | 365 days | No |
lrn_attr |
Records which campaign or site brought you here | 90 days | Yes |
5. Who we share data with
We share personal data only with service providers that help us run Learnery, under contracts that protect your data:
- OpenAI as our only AI provider, and for safety screening. The text learners type into the exercises, the chat practice, the prompt lab, and the questions they ask the AI tutor are sent to OpenAI so it can generate feedback and examples. The AI output shown to learners is sent back to OpenAI to be screened for harmful content. Our contract for data from the European Economic Area is with OpenAI Ireland Limited, and where OpenAI moves that content to the United States it does so under the European Commission standard contractual clauses. Under its API terms, this content is not used to train its models.
- Cloudflare in front of our website. Every request to learnery.io passes through Cloudflare, which sees your IP address and the page you asked for, and filters attacks before they reach us. Cloudflare is based in the United States and transfers rely on the European Commission standard contractual clauses.
- Stripe for payment processing.
- Google only when you choose to sign in with a Google account. You authenticate with Google directly and it tells us your email address and account identifier. Google handles that sign in under its own privacy policy, as its own controller rather than on our behalf.
- DATAHOST and our email provider (Greece) to deliver the service and transactional messages. Our servers are in Greece.
- Google for advertising measurement, only while we are advertising and only if you consented. Our contract is with Google Ireland Limited. When you buy, our server sends the click code from your Google advert, the purchase value and the time. Transfers to the United States rely on the European Commission standard contractual clauses and on Google being certified under the EU and US Data Privacy Framework.
- Meta for advertising measurement, on the same terms and under the same consent. Our contract is with Meta Platforms Ireland Limited. When you buy, our server sends the click code from your Facebook or Instagram advert, the purchase value and the time. Transfers to the United States rely on the European Commission standard contractual clauses and on Meta being certified under the EU and US Data Privacy Framework.
We do not sell your personal data, and we do not share it with advertising networks.
6. International transfers
Your account, your training records and our database are held in the European Union, on servers in Greece. Some of the providers in section 5 move data to the United States, and we name the safeguard for each of them rather than describing it in general terms. OpenAI: our contract for data from the European Economic Area is with OpenAI Ireland Limited, and onward transfers to the United States are made under the standard contractual clauses adopted by the European Commission on 4 June 2021. Cloudflare: transfers to the United States are made under the same standard contractual clauses. Stripe: our contract is with Stripe Payments Europe Limited in Ireland, and transfers to the United States are made under the same clauses. Google is deliberately not in that list: signing in with a Google account is something you do with Google directly, under its own privacy policy, rather than a transfer we make. We do not send personal data to a provider in a country that has neither an adequacy decision nor those clauses in place. You may ask us for a copy of the safeguards and we will send it: write to [email protected].
7. How long we keep data
We keep account and training data for as long as the account is active, and for a reasonable period afterwards to meet legal and accounting duties. Usage and analytics records are kept at event level and deleted automatically after 400 days. Email delivery logs are kept for 90 days and AI interaction logs for 180 days. Contact, lead and assessment records are kept for up to 24 months so we can follow up and keep a record of the enquiry, after which they are deleted automatically. You can ask us to delete them sooner at any time. You can request deletion at any time using the contact details in section 12.
8. Your rights
Subject to applicable law, you have the right to access your data, correct it, erase it, restrict or object to processing, and receive a copy in a portable format. You may withdraw consent at any time where processing is based on consent. To exercise any right, write to [email protected]. We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you for advertising: quiz scoring and AI feedback are automated, but they decide nothing about your employment. You also have the right to complain to a data protection authority, either the Hellenic Data Protection Authority in Athens or the authority where you live or work. Restriction in practice means we suspend the account: nothing is processed except that the record continues to be stored, and it can be lifted at your request. Where we have shared data with a provider in section 5, we pass on a correction or an erasure to the ones that can act on it, and we tell you where one cannot. Our AI provider deletes API content on its own fixed schedule and gives us no way to delete it sooner, so for that provider a request takes effect as it expires.
9. Security
We protect data with encryption in transit, hashed credentials, access controls, and regular review. Your account and training data are stored in the European Union, on servers in Greece. No system is perfectly secure, but we work to keep your data safe.
10. Children
Learnery is a workplace tool intended for adults. It is not directed at children.
11. Changes
We may update this policy. When we do, we will change the date above and, for material changes, tell account holders.
12. Contact
Questions about privacy? Write to [email protected] or use our Contact page.