This Privacy Policy describes how personal information may be collected, used, stored, shared and protected when individuals use the HEAL360 website, learning management platform, Enterprise interfaces and related digital services (collectively, the “Platform”). It should be read together with the HEAL360 Terms and Conditions, Cookie Policy and any organisation-specific privacy notice or agreement.
1. Scope of this Policy
This Policy applies to personal information processed through HEAL360 in connection with website visitors, learners, instructors, administrators, organisation representatives and other authorised Platform users. Where HEAL360 is provided through an employer, hospital, educational institution or other organisation, that organisation may determine why and how certain personal information is processed and may provide additional privacy information.
2. Information we may collect
Depending on the services used and configuration of the Platform, information may include account and identity details such as name, email address, username and organisation; role, department and access information; course enrolment, progress, assessment, competency and certificate information; user-submitted content; support and correspondence records; login, session, device, browser, security and audit information; and information generated through enabled Platform functions or integrations.
3. Information provided by organisations
An organisation using HEAL360 may provide information about its users in order to create accounts, assign roles, enrol learners, administer training, manage organisational structures or generate authorised reports. The organisation is responsible for ensuring that it has an appropriate basis and authority to provide such information.
4. How personal information may be used
Personal information may be processed to provide and operate the Platform; authenticate users and secure accounts; manage organisations, roles and permissions; deliver courses and learning activities; record progress, assessments, competencies and certificates; provide support; maintain audit and security records; enable authorised integrations; improve Platform reliability and usability; communicate service-related information; and comply with applicable legal or contractual obligations.
5. Legal basis and organisational responsibility
The lawful basis for processing depends on the relevant jurisdiction, the relationship between the parties and the purpose of processing. Processing may, where applicable, be based on performance of a contract, legitimate interests, compliance with legal obligations, consent, or another lawful basis. Enterprise customers should determine and document the lawful basis applicable to personal information they control through their HEAL360 deployment.
6. Healthcare and sensitive information
HEAL360 is primarily a learning, competency and workforce platform. Users must not upload patient information, health information or other sensitive or confidential information unless the relevant organisation has expressly authorised that use, the Platform is appropriately configured for it, and applicable privacy, security, contractual and regulatory requirements have been addressed.
7. AI-enabled functions
Where AI-enabled functions are configured, information submitted to those functions may be processed to generate the requested output. Users should submit only information they are authorised to process. Organisations should review the AI provider, data flows, retention settings, contractual protections and applicable privacy requirements before enabling AI functions for personal, confidential or sensitive information.
8. Third-party services and integrations
HEAL360 may connect to external services configured or authorised by an administrator. Information may be exchanged with those services when required to provide the enabled function. Third-party providers can have their own privacy practices and terms. Organisations should review each integration and ensure that appropriate privacy, security and contractual controls are in place.
9. Cookies and similar technologies
HEAL360 may use cookies and similar browser technologies for sessions, authentication, security, preferences and other configured functions. Further information is provided in the HEAL360 Cookie Policy.
10. Information sharing
Personal information may be made available to authorised users within the relevant organisation according to roles and permissions, to service providers or integration providers where necessary to deliver configured services, and to authorities or other parties where disclosure is required by applicable law or a valid legal process. Personal information should not be sold as part of the normal operation of the HEAL360 learning platform.
11. Data security
Appropriate technical and organisational safeguards should be used to protect personal information against unauthorised access, alteration, disclosure, loss or misuse. Measures may include authenticated access, role-based permissions, secure transport, session controls, logging, backups, infrastructure protections and administrative procedures. No internet-based system can guarantee absolute security.
12. Data retention
Personal information should be retained only for as long as reasonably required for the relevant learning, operational, contractual, audit, security or legal purpose. Retention periods can vary by data category and organisation. Enterprise customers may have their own retention requirements and should configure or manage records accordingly.
13. International data transfers
Where personal information is transferred or made accessible across national borders through hosting, service providers or integrations, the responsible parties should ensure that any required transfer mechanism, contractual protection or other safeguard is in place under applicable law.
14. User privacy rights
Depending on applicable law, individuals may have rights relating to access, correction, deletion, restriction, objection, portability, withdrawal of consent or complaints to a competent authority. These rights are not absolute and may be subject to legal exceptions. Where HEAL360 is provided through an organisation, requests concerning organisation-controlled information may need to be directed to that organisation.
15. Account information and corrections
Users should keep their account information accurate. Where profile editing is available, users may update permitted information through the Platform. Other corrections may require assistance from an authorised administrator.
16. Children and younger users
HEAL360 should not knowingly process information about children through a deployment unless the responsible organisation has determined that the use is appropriate and has implemented any consent, notice, safeguarding or other requirements required by applicable law.
17. Security incidents
Suspected unauthorised access, disclosure, loss or misuse of personal information should be reported promptly through the designated support or security channel. Relevant organisations should follow their incident response and breach-notification obligations where applicable.
18. Automated processing
Where automated or AI-assisted functions are used, organisations should assess whether applicable law imposes transparency, human-review or other requirements. HEAL360 learning or analytics outputs should not be treated as the sole basis for a legally or similarly significant decision unless the responsible organisation has confirmed that such use is lawful and appropriate.
19. Links to other websites
The Platform may contain links to external websites or services. Their privacy practices are governed by their own notices and are not controlled by this Policy.
20. Changes to this Privacy Policy
This Policy may be updated to reflect changes to the Platform, data practices, integrations, security requirements or applicable law. The effective date and version should be updated when material changes are published and additional notice should be provided where required.
21. Contact and privacy requests
Questions, privacy requests or concerns should be submitted through the contact channel published on heal360connect.com or, where the account is provided by an organisation, to that organisation’s designated administrator or privacy contact. The final published version should identify the legal entity responsible for HEAL360 and its formal privacy contact details.
Privacy information summary
Area | Examples | Purpose |
Account information | Name, email, username, organisation, role | Account creation, authentication and access |
Learning records | Enrolment, progress, assessments, certificates | Learning delivery and authorised reporting |
Technical/security data | Session, login, device, browser and audit records | Security, troubleshooting and service operation |
Support information | Queries, correspondence and issue details | Customer support and issue resolution |
Integration data | Information exchanged with enabled providers | Provide administrator-configured functions |
Publication checklist
Insert the full legal name and registered address of the entity operating or contracting for HEAL360.
Add a dedicated privacy contact email/address and, where applicable, Data Protection Officer details.
Confirm hosting locations, processors/sub-processors and international transfer arrangements.
Verify actual retention periods for user, learning, audit, support and backup records.
Confirm the lawful bases and controller/processor roles applicable to each HEAL360 service.
Verify all enabled analytics, AI and third-party integrations against the Cookie Policy and privacy notice.
Review requirements under the laws applicable to the countries and organisations where HEAL360 is offered.
Important: This document is a general privacy-policy template for the HEAL360 platform. Before publication, the actual production data flows, legal entity details, processors, retention periods and applicable jurisdictions should be verified and the final policy reviewed by qualified legal counsel.