LEGAL

Privacy Policy

OREL Technologies respects your privacy. This policy explains what personal information we collect, why we collect it, how we use, protect, and share it, the controls we apply, and the choices and rights available to you. It applies to our website, our learning platform (OrelLMS), and the services and subscriptions we provide.

Last updated: 2026

1. Who we are and what this policy covers

This privacy policy applies to OREL Technologies ("OREL", "we", "us") and to all individuals who visit our website, subscribe to or use our services, or otherwise provide us with personal information.

The policy explains our practices for the personal information we handle — whether you are a visitor, a learner, an instructor, an administrator, or a contact at one of our customer organizations.

2. Information we collect

Information you provide: name, work email address, organization, and role, when you register, subscribe, request a quote, or contact us.

Account information: login identifiers, account settings, and usage preferences for the services you use.

Learning and service data: in OrelLMS, records of course enrollment and completion, knowledge-check and simulation results, and risk scores that the platform produces to run your training and demonstrate outcomes.

Technical data: device and browser information, IP address, and basic usage logs, gathered automatically when you visit our site or use our services, to keep them secure and functioning.

3. How we collect information

Directly from you: when you fill in forms, correspond with us, or set up and use an account.

Automatically: through standard website and platform technology that logs technical and usage data.

From your organization: when an employer or service administrator provides information about you as part of onboarding, role assignment, or enrollment in a training program.

4. How we use your information

To deliver, operate, and secure the services you or your organization has subscribed to.

To produce the completion, risk, and compliance records that your organization relies on as audit evidence.

To respond to enquiries, scope engagements, and provide service and account communications.

To detect, investigate, and prevent security incidents, fraud, or misuse.

To comply with legal and regulatory obligations and to enforce our agreements.

5. Lawful bases for processing

Where applicable data-protection law requires a lawful basis, we process personal information under: performance of a contract (delivering services you subscribed to), legitimate interests (operating and securing our services, and reasonable business communication), compliance with a legal obligation, or consent where we rely on it.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

6. What we do not do

We do not sell or rent personal information.

We do not collect payment card details on our website; billing is handled through your engagement or subscription agreement with us.

We do not use personal information for purposes beyond those described in this policy without a lawful basis.

7. Data we do not process

We do not collect payment card details on our site.

8. Sharing and disclosure

We share personal information only where necessary to provide the service or where required by law:

With our team and the processing partners that help operate the platform and deliver the service, under contracts that require them to protect your information.

With your organization, where you are enrolled through an employer or administrator, to the extent that organization has a right to the relevant training and compliance records.

Where law, regulation, or legal process requires disclosure, or to protect the rights, property, or safety of OREL, our users, or the public.

We do not share personal information with third parties for their own marketing purposes.

9. International data transfers

Where personal information is accessed or transferred across national borders, we apply appropriate safeguards in line with applicable law to keep that information protected.

When data is processed by a partner in another jurisdiction, we ensure contractual or other appropriate protections are in place.

10. Security and retention

Personal information is protected with access controls, encryption in transit, and the organizational, technical, and procedural safeguards described in our Information Security Management System (ISMS) policy.

We retain personal information only as long as needed to provide the service, fulfil the purposes described here, and meet legal, contractual, and audit obligations. When it is no longer needed, we delete or anonymize it.

Where our customers require us to keep training and compliance records, retention is governed by the agreement with the relevant organization.

11. Cookies and similar technologies

Our website may use cookies and similar technologies to support essential functions, remember preferences, and gather basic usage information.

We do not use advertising cookies or third-party advertising trackers on our site.

You can control or disable cookies through your browser settings; doing so may affect some site functionality.

12. Children’s privacy

Our services are directed to organizations and adults, and we do not knowingly collect personal information from children without appropriate consent.

If you believe a child has provided us personal information without proper authorization, contact us using the details below and we will delete it.

13. Your rights and choices

Subject to applicable law, you may request: access to the personal information we hold about you, its correction if it is inaccurate or incomplete, its deletion, or restriction of or objection to certain processing.

You may also request data portability where applicable, and withdraw consent where we rely on it.

To exercise a right, contact us using the details below. We will respond within a reasonable timeframe and may ask you to verify your identity or authority first.

Where you are enrolled through an employer or administrator, we may direct your request to the organization that manages your account, as that organization controls the related records.

14. Data controllers and your organization

Where an employer or organization subscribes to OrelLMS and enrolls learners, that organization may act as the data controller of the learning records, with OREL acting as a processor on its behalf.

In such cases, we process the relevant information under the direction of that organization and our agreement with it.

15. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about individuals solely by automated means, without human review.

16. Links to third parties

Our site may link to third-party websites or services that have their own privacy policies. We are not responsible for the practices of those sites, and we encourage you to review their policies before providing them information.

17. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, services, or legal requirements.

When we make material changes, we will post the updated policy on this page with a revised "last updated" date, and notify you where appropriate.

18. Contact and complaints

For any privacy question, request, or complaint, email [email protected].

If you believe we have not addressed a concern and you are in a jurisdiction where a supervisory authority applies, you may also raise it with the relevant data-protection authority.

Questions? Email [email protected]