Privacy Policy
Last updated: 23 February 2026
CompliLearn ("we", "us", or "our") operates the CompliLearn platform at complilearn.co.bw. We are committed to protecting the personal information of our users and complying with Botswana's Data Protection Act, 2024. This Privacy Policy explains what data we collect, how we use it, and the rights you have regarding your information.
1. Information We Collect
When you register for an account, subscribe to a plan, or use our training platform, we may collect the following categories of personal information:
- Identity information: Full name, job title, and role within your organisation.
- Contact information: Email address, phone number, and business postal address.
- Organisation details: Business name, practice or facility name, and number of employees.
- Account credentials: Email and hashed password used to authenticate your account.
- Payment information: Billing details required by our payment processor. We do not store full card numbers on our servers.
- Usage data: Pages visited, scenarios completed, training progress, quiz scores, time spent on modules, and device or browser information.
- Communication records: Messages, support requests, and feedback you send to us.
2. How We Use Your Data
We process your personal information for the following purposes:
- Account management: Creating and maintaining your account, authenticating access, and managing your subscription.
- Training delivery: Providing AI-powered data protection training scenarios, generating personalised learning content, and adapting difficulty based on your progress.
- Progress tracking: Recording scenario completions, quiz results, and compliance milestones so that you and your organisation can monitor readiness for the Data Protection Act.
- Compliance reporting: Generating team-level and organisation-level reports for practice owners and compliance officers.
- Communication: Sending transactional emails (account verification, password resets, subscription confirmations), training reminders, and product updates.
- Service improvement: Analysing aggregate usage patterns to improve our training content, user experience, and platform reliability.
- Legal obligations: Complying with applicable laws, regulations, and lawful requests from authorities in Botswana.
3. Legal Basis for Processing
Under Botswana's Data Protection Act, 2024, we process your personal data on the following lawful bases: performance of a contract (to deliver the training services you have subscribed to); your consent (for optional communications and marketing); legitimate interest (to improve our platform and protect against fraud); and compliance with legal obligations (to meet regulatory requirements under Botswana law).
4. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes described in this policy:
- Active accounts: Your data is retained for the duration of your subscription and for 12 months following cancellation, to allow for reactivation or dispute resolution.
- Training records: Completion certificates and compliance records are retained for 5 years to support regulatory audit requirements.
- Payment records: Transaction history is retained for 7 years in accordance with Botswana's financial record-keeping requirements.
- Usage analytics: Aggregated and anonymised usage data may be retained indefinitely for service improvement purposes.
When data is no longer required, it is securely deleted or anonymised in accordance with industry best practices.
5. Third-Party Sharing
We do not sell your personal information. We share data only with trusted service providers who assist us in operating the platform, and only to the extent necessary:
- Payment processors: We use secure third-party payment providers to handle subscription billing. They receive only the information necessary to process your payment and are bound by their own privacy policies and PCI-DSS compliance.
- Cloud hosting: Our platform is hosted on secure cloud infrastructure. Hosting providers may process data on our behalf but do not access or use your data for their own purposes.
- AI model providers: To deliver AI-powered training scenarios, prompts and responses are processed through third-party AI services. These interactions do not include your full personal profile and are not used to train external models.
- Email delivery: We use third-party email services to send transactional and notification emails. These providers receive your email address and name solely for the purpose of delivering messages on our behalf.
All third-party providers are contractually required to protect your data and process it only according to our instructions.
6. Cookies and Tracking
Our platform uses cookies and similar technologies to provide and improve the service:
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled without affecting platform functionality.
- Analytics cookies: Used to understand how users interact with the platform, which training modules are most accessed, and where users encounter difficulties. This data is collected in aggregate form.
- Preference cookies: Store your settings such as theme preference and language selection to improve your experience across visits.
You can manage cookie preferences through your browser settings. Note that disabling essential cookies may prevent you from using the platform.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS) and at rest, secure password hashing, regular security reviews, and restricted access controls. While we take reasonable steps to safeguard your data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights Under the Data Protection Act, 2024
Under Botswana's Data Protection Act, 2024, you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data, subject to our legal retention obligations.
- Right to restriction: You may request that we limit the processing of your data in certain circumstances.
- Right to data portability: You may request your data in a structured, commonly used, and machine-readable format.
- Right to object: You may object to processing of your data for direct marketing or where processing is based on legitimate interest.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the details below. We will respond to your request within 30 days, as required by law. If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Botswana Information and Data Protection Commission.
9. International Data Transfers
Some of our service providers operate outside of Botswana. Where your data is transferred internationally, we ensure that adequate safeguards are in place as required by the Data Protection Act, 2024. These safeguards include contractual clauses that require recipients to protect your data to a standard equivalent to that provided under Botswana law.
10. Children's Privacy
CompliLearn is a professional training service designed for healthcare practitioners and business personnel. We do not knowingly collect personal information from children under the age of 18. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or by posting a prominent notice on our platform. The "Last updated" date at the top of this page indicates when this policy was most recently revised. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal information, please contact us:
- Email: support@complilearn.co.bw
- Address: CompliLearn (Pty) Ltd, Gaborone, Botswana