Saltar al contenido

Política de privacidad

Last updated 5 August 2026.

This Privacy Policy explains how the iLactation learning platform (“the Platform”, “we”, “us”) collects, uses, retains, and protects personal data when you use our continuing-education service, and the rights you have over your data under the EU General Data Protection Regulation (GDPR) and equivalent laws.

1. Who we are

The data controller for personal data processed through the Platform is:

  • Entity: iLactation Limited
  • Registered office: 16/F Wing Hing Commercial Building, 139 Wing Lok Street, Sheung Wan, Hong Kong
  • Privacy contact: privacy@ilactation.com

The Platform operates separate regional sites (English, Spanish, Dutch). This policy applies to all of them.

2. Scope

This policy covers the learning platform (account, course/conference access, video viewing, certificates, payments, and support). It does not cover third-party websites we link to, or the separate iLactation marketing website, which has its own policy.

Local processing is carried out under Hong Kong’s Personal Data (Privacy) Ordinance. Processing relating to people in the European Union is also governed by the GDPR. The UK GDPR applies in the same way to people in the United Kingdom.

The company’s directors access the Platform from the United Kingdom and Australia, and our platform developer provides technical support from the United Kingdom. Accounting records are shared with the company’s accountants and auditor in Hong Kong. Where access from Australia touches data held for people in the EU, it is protected by the safeguards described in the international transfers section below (performance of a contract, Art. 49(1)(b)).

3. What we collect, and why

We collect only what we need to run the service. The table below lists each category, why we process it, and the lawful basis under GDPR Art. 6.

CategoryWhat it includesWhyLawful basis (Art. 6)
AccountEmail, name, hashed password, and (optional) profile details: organisation, professional/lactation role, country, credentialsCreate and operate your account; show your name on certificatesContract (Art. 6(1)(b))
AuthenticationPasskey credentials (WebAuthn), one-time login codes, session metadataSecurely sign you inContract (Art. 6(1)(b))
RegistrationsWhich conferences/courses you register forGive you access to content you’ve enrolled in; record attendanceContract (Art. 6(1)(b))
Viewing / attendanceWhich video seconds you’ve watched and your completion percentage per presentationAward attendance and continuing-education certificates, which require verified viewingContract (Art. 6(1)(b))
CertificatesCertificates issued to you, each carrying a certificate number that can be quoted back to us to confirm the certificate is genuineIssue and let third parties verify your CE creditsContract / legal record (Art. 6(1)(b))
PaymentsAmount, currency, status, country, and payment-processor reference IDs (we never store full card numbers)Process payment and keep accounting/tax recordsContract + legal obligation (Art. 6(1)(b), (c))
Security & audit logsSign-in events, IP address, browser/device, approximate location (country), timestampsProtect accounts, detect and investigate fraud and abuseLegitimate interests (Art. 6(1)(f)) — security & fraud prevention
Usage analyticsPage views and video-play events with a hashed (non-reversible) IP, browser family, device type, country (no city), and a temporary per-tab visit identifier, and, when you arrive from one of our posts or emails, the campaign label on the link (so we can tell which announcements are useful)Understand and improve how the service is used, in aggregateLegitimate interests (Art. 6(1)(f)) — service improvement
Diagnostic error logsTechnical error details, the page where it happened, browser, IP, approximate locationDiagnose and fix faultsLegitimate interests (Art. 6(1)(f)) — reliability
Email recordsTransactional emails we send you (e.g. receipts, certificate notices) and their delivery statusProve and troubleshoot delivery of service emailsContract + legitimate interests (Art. 6(1)(b), (f))
Support questionsQuestions you submit through the platformAnswer youContract / legitimate interests (Art. 6(1)(b), (f))

We also keep aggregated usage statistics (daily counts by page, browser, country, etc.). These contain no personal data — they are counts only — and are retained indefinitely for trend analysis.

Data minimisation in analytics. Our usage analytics are deliberately privacy-minimising: IP addresses are hashed before storage (we cannot recover the original IP from analytics), we record country only (never city), and the per-tab visit identifier is temporary (held only in your browser tab’s session storage, not a persistent cookie or device ID).

We do not sell personal data, and we do not use it for behavioural advertising or cross-site tracking.

4. Cookies and similar technologies

We use only strictly-necessary cookies and storage:

  • Authentication — to keep you signed in.
  • Site/region selection — to remember which regional site you’re using.
  • Bot protection (Cloudflare Turnstile) — to tell humans from automated abuse.

Because we use no analytics, advertising, or other non-essential cookies, and because our analytics use no persistent identifier, no cookie-consent banner is required. The per-tab visit identifier used for analytics lives in your browser’s session storage and is discarded when you close the tab.

5. How long we keep it

DataRetention
Account, profile, registrationsFor the life of your account (see erasure below)
CertificatesFor the life of your account (see erasure below)
Completion records (which presentations you completed, when, and credits awarded)Six years after the last date that programme was offered, per IBLCE preferred provider guidance (see erasure, §6)
Payments and related accounting recordsAt least seven years, as required by section 51C of the Hong Kong Inland Revenue Ordinance
Security & audit logs12 months
Usage analytics (raw, identifiable-by-hash events)30 days, then deleted; only non-personal aggregate counts remain
Diagnostic error logs90 days
Email delivery records24 months
Aggregate usage statisticsIndefinitely (contain no personal data)

When you delete your account, we erase your personal data (see §6), except for completion records. Completion records (your name, the presentation, the completion date, and credits awarded) are kept in identifiable form for six years after the programme was last offered, under the legal-obligation exception in Art. 17(3)(b) GDPR, because accreditation audits require evidence of who completed which presentation. We also retain certain other records where the law requires (e.g. accounting) or where we have an overriding legitimate interest (e.g. a short-lived security log).

6. Your rights

Under the GDPR you have the right to:

  • Access your data and get a copy (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erase your data (“right to be forgotten”) (Art. 17), subject to legal-retention exceptions.
  • Port your data in a machine-readable format (Art. 20).
  • Restrict or object to processing based on legitimate interests, including our security and analytics processing (Art. 18, 21).
  • Withdraw consent where we rely on consent (we generally do not).
  • Lodge a complaint with a data-protection supervisory authority (Art. 77).

How to exercise them

  • Access / export: download a complete copy of your data from your account settings at any time.
  • Erasure: delete your account from your account settings. This erases your personal data, except for completion records (your name, the presentation, the completion date, and credits awarded), which we keep in identifiable form for six years after the programme was last offered, because accreditation audits require evidence of who completed which presentation (Art. 17(3)(b) GDPR). Accounting records we must keep by law are also retained.
  • Rectification: edit your profile in your account settings. To change the name printed on issued certificates, contact support@ilactation.com.
  • Other requests / questions: contact privacy@ilactation.com. We respond within one month (Art. 12(3)).

7. Who we share data with (processors)

We share personal data only with service providers (“processors”) who help us run the Platform, under contracts that require them to protect it and use it only on our instructions. They fall into these categories:

  • Payment processors
  • Cloud hosting and database providers
  • Video delivery
  • Email delivery
  • Bot and abuse protection
  • Document storage and AI document reading (all EU-region for tracker documents)
  • Error monitoring

We maintain a full register of named processors internally, in accordance with GDPR Article 30.

We may also disclose data where required by law or to protect our rights, users, or the public.

8. International transfers

Some processors listed above may process data outside the European Economic Area. Where they do, the transfer is protected by an appropriate safeguard under GDPR Chapter V — an adequacy decision or Standard Contractual Clauses.

9. Complaints

If you believe we have mishandled your data, please contact us first so we can put it right. You may also lodge a complaint with the data-protection supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement. Our EU representative, once appointed, can be contacted as the EU contact point for this policy (details will be added here on appointment).

10. Security and data breaches

We protect your data with measures including hashed passwords, passkey (WebAuthn) support, session-revocation controls, account-lockout protection, encrypted connections, signed/expiring video links, and access controls that isolate each regional site’s data.

A data breach means unauthorised access to, or accidental loss, alteration or unlawful destruction of, personal data we hold. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant data protection authority within 72 hours of becoming aware of it. If a breach is likely to put you at high risk, for example to your identity or finances, we will also tell you directly, without undue delay, explaining what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself. Questions about data security can be sent to privacy@ilactation.com at any time.

11. Children

The Platform is a professional continuing-education service intended for adults (typically healthcare professionals). It is not directed at children, and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

We will post any changes here and update the “Last updated” date. Material changes will be communicated through the Platform.

13. Contact

iLactation · privacy@ilactation.com