Política de privacidad
Last updated 5 August 2026.
This Privacy Policy explains how the iLactation learning platform (“the Platform”, “we”, “us”) collects, uses, retains, and protects personal data when you use our continuing-education service, and the rights you have over your data under the EU General Data Protection Regulation (GDPR) and equivalent laws.
1. Who we are
The data controller for personal data processed through the Platform is:
- Entity: iLactation Limited
- Registered office: 16/F Wing Hing Commercial Building, 139 Wing Lok Street, Sheung Wan, Hong Kong
- Privacy contact: privacy@ilactation.com
The Platform operates separate regional sites (English, Spanish, Dutch). This policy applies to all of them.
2. Scope
This policy covers the learning platform (account, course/conference access, video viewing, certificates, payments, and support). It does not cover third-party websites we link to, or the separate iLactation marketing website, which has its own policy.
Local processing is carried out under Hong Kong’s Personal Data (Privacy) Ordinance. Processing relating to people in the European Union is also governed by the GDPR. The UK GDPR applies in the same way to people in the United Kingdom.
The company’s directors access the Platform from the United Kingdom and Australia, and our platform developer provides technical support from the United Kingdom. Accounting records are shared with the company’s accountants and auditor in Hong Kong. Where access from Australia touches data held for people in the EU, it is protected by the safeguards described in the international transfers section below (performance of a contract, Art. 49(1)(b)).
3. What we collect, and why
We collect only what we need to run the service. The table below lists each category, why we process it, and the lawful basis under GDPR Art. 6.
| Category | What it includes | Why | Lawful basis (Art. 6) |
|---|---|---|---|
| Account | Email, name, hashed password, and (optional) profile details: organisation, professional/lactation role, country, credentials | Create and operate your account; show your name on certificates | Contract (Art. 6(1)(b)) |
| Authentication | Passkey credentials (WebAuthn), one-time login codes, session metadata | Securely sign you in | Contract (Art. 6(1)(b)) |
| Registrations | Which conferences/courses you register for | Give you access to content you’ve enrolled in; record attendance | Contract (Art. 6(1)(b)) |
| Viewing / attendance | Which video seconds you’ve watched and your completion percentage per presentation | Award attendance and continuing-education certificates, which require verified viewing | Contract (Art. 6(1)(b)) |
| Certificates | Certificates issued to you, each carrying a certificate number that can be quoted back to us to confirm the certificate is genuine | Issue and let third parties verify your CE credits | Contract / legal record (Art. 6(1)(b)) |
| Payments | Amount, currency, status, country, and payment-processor reference IDs (we never store full card numbers) | Process payment and keep accounting/tax records | Contract + legal obligation (Art. 6(1)(b), (c)) |
| Security & audit logs | Sign-in events, IP address, browser/device, approximate location (country), timestamps | Protect accounts, detect and investigate fraud and abuse | Legitimate interests (Art. 6(1)(f)) — security & fraud prevention |
| Usage analytics | Page views and video-play events with a hashed (non-reversible) IP, browser family, device type, country (no city), and a temporary per-tab visit identifier, and, when you arrive from one of our posts or emails, the campaign label on the link (so we can tell which announcements are useful) | Understand and improve how the service is used, in aggregate | Legitimate interests (Art. 6(1)(f)) — service improvement |
| Diagnostic error logs | Technical error details, the page where it happened, browser, IP, approximate location | Diagnose and fix faults | Legitimate interests (Art. 6(1)(f)) — reliability |
| Email records | Transactional emails we send you (e.g. receipts, certificate notices) and their delivery status | Prove and troubleshoot delivery of service emails | Contract + legitimate interests (Art. 6(1)(b), (f)) |
| Support questions | Questions you submit through the platform | Answer you | Contract / legitimate interests (Art. 6(1)(b), (f)) |
We also keep aggregated usage statistics (daily counts by page, browser, country, etc.). These contain no personal data — they are counts only — and are retained indefinitely for trend analysis.
Data minimisation in analytics. Our usage analytics are deliberately privacy-minimising: IP addresses are hashed before storage (we cannot recover the original IP from analytics), we record country only (never city), and the per-tab visit identifier is temporary (held only in your browser tab’s session storage, not a persistent cookie or device ID).
We do not sell personal data, and we do not use it for behavioural advertising or cross-site tracking.
4. Cookies and similar technologies
We use only strictly-necessary cookies and storage:
- Authentication — to keep you signed in.
- Site/region selection — to remember which regional site you’re using.
- Bot protection (Cloudflare Turnstile) — to tell humans from automated abuse.
Because we use no analytics, advertising, or other non-essential cookies, and because our analytics use no persistent identifier, no cookie-consent banner is required. The per-tab visit identifier used for analytics lives in your browser’s session storage and is discarded when you close the tab.
5. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, registrations | For the life of your account (see erasure below) |
| Certificates | For the life of your account (see erasure below) |
| Completion records (which presentations you completed, when, and credits awarded) | Six years after the last date that programme was offered, per IBLCE preferred provider guidance (see erasure, §6) |
| Payments and related accounting records | At least seven years, as required by section 51C of the Hong Kong Inland Revenue Ordinance |
| Security & audit logs | 12 months |
| Usage analytics (raw, identifiable-by-hash events) | 30 days, then deleted; only non-personal aggregate counts remain |
| Diagnostic error logs | 90 days |
| Email delivery records | 24 months |
| Aggregate usage statistics | Indefinitely (contain no personal data) |
When you delete your account, we erase your personal data (see §6), except for completion records. Completion records (your name, the presentation, the completion date, and credits awarded) are kept in identifiable form for six years after the programme was last offered, under the legal-obligation exception in Art. 17(3)(b) GDPR, because accreditation audits require evidence of who completed which presentation. We also retain certain other records where the law requires (e.g. accounting) or where we have an overriding legitimate interest (e.g. a short-lived security log).
6. Your rights
Under the GDPR you have the right to:
- Access your data and get a copy (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erase your data (“right to be forgotten”) (Art. 17), subject to legal-retention exceptions.
- Port your data in a machine-readable format (Art. 20).
- Restrict or object to processing based on legitimate interests, including our security and analytics processing (Art. 18, 21).
- Withdraw consent where we rely on consent (we generally do not).
- Lodge a complaint with a data-protection supervisory authority (Art. 77).
How to exercise them
- Access / export: download a complete copy of your data from your account settings at any time.
- Erasure: delete your account from your account settings. This erases your personal data, except for completion records (your name, the presentation, the completion date, and credits awarded), which we keep in identifiable form for six years after the programme was last offered, because accreditation audits require evidence of who completed which presentation (Art. 17(3)(b) GDPR). Accounting records we must keep by law are also retained.
- Rectification: edit your profile in your account settings. To change the name printed on issued certificates, contact support@ilactation.com.
- Other requests / questions: contact privacy@ilactation.com. We respond within one month (Art. 12(3)).
7. Who we share data with (processors)
We share personal data only with service providers (“processors”) who help us run the Platform, under contracts that require them to protect it and use it only on our instructions. They fall into these categories:
- Payment processors
- Cloud hosting and database providers
- Video delivery
- Email delivery
- Bot and abuse protection
- Document storage and AI document reading (all EU-region for tracker documents)
- Error monitoring
We maintain a full register of named processors internally, in accordance with GDPR Article 30.
We may also disclose data where required by law or to protect our rights, users, or the public.
8. International transfers
Some processors listed above may process data outside the European Economic Area. Where they do, the transfer is protected by an appropriate safeguard under GDPR Chapter V — an adequacy decision or Standard Contractual Clauses.
9. Complaints
If you believe we have mishandled your data, please contact us first so we can put it right. You may also lodge a complaint with the data-protection supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement. Our EU representative, once appointed, can be contacted as the EU contact point for this policy (details will be added here on appointment).
10. Security and data breaches
We protect your data with measures including hashed passwords, passkey (WebAuthn) support, session-revocation controls, account-lockout protection, encrypted connections, signed/expiring video links, and access controls that isolate each regional site’s data.
A data breach means unauthorised access to, or accidental loss, alteration or unlawful destruction of, personal data we hold. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant data protection authority within 72 hours of becoming aware of it. If a breach is likely to put you at high risk, for example to your identity or finances, we will also tell you directly, without undue delay, explaining what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself. Questions about data security can be sent to privacy@ilactation.com at any time.
11. Children
The Platform is a professional continuing-education service intended for adults (typically healthcare professionals). It is not directed at children, and we do not knowingly collect data from anyone under 16.
12. Changes to this policy
We will post any changes here and update the “Last updated” date. Material changes will be communicated through the Platform.
13. Contact
iLactation · privacy@ilactation.com
