List of active policies
| Name | Type | User consent |
|---|---|---|
| Privacy Policy for accessing Neda eCampus | Privacy policy | All users |
Summary
Data Privacy Policy
Neda eCampus attaches great importance to responsible and transparent management of personal data.
Below we provide users with information as to:
- Information processed upon website visits
- Information processed upon contact and newsletter subscription
- Opting out of data storage
- User rights regarding personal data
Full policy
Privacy Notice
Last updated: 13 July 2026
1. Purpose and scope of this Privacy Notice
Neda eCampus is committed to processing personal data lawfully, fairly, transparently and securely.
This Privacy Notice explains how personal data are processed when you:
-
visit the Neda eCampus website;
-
create or use an Neda eCampus account;
-
enrol in or participate in a course;
-
complete learning activities, assignments, tests or assessments;
-
communicate with instructors, administrators or support personnel;
-
use discussion forums, messaging or collaboration functions;
-
request or receive a certificate;
-
subscribe to newsletters or other optional communications;
-
use an external identity provider to sign in; or
-
otherwise interact with Neda eCampus.
This notice applies to the Neda eCampus platform, available at https://www.learn.neda-els.com, and to the associated services operated by Neda eLearning Solutions.
Separate terms may apply to individual courses, payment services, third-party websites or services operated by other organisations.
2. Data controller and contact details
For processing activities for which Neda eLearning Solutions determines the purposes and means of processing, the data controller is:
Khusraw Parwez, trading as Neda eLearning Solutions
Neda eLearning Solutions / Neda eCampus
Blumenstrasse 2/10
3170 [insert municipality]
Austria
Email: learn@neda-els.com
General enquiries: office@neda-els.com
Telephone: +43 676 4079 215
Privacy-related requests should be sent to learn@neda-els.com.
Unless a formally appointed data protection officer is published on the platform, this email address is the data-protection contact and should not be described as the contact of a “Data Protection Officer.”
3. Courses provided on behalf of other organisations
Some courses may be commissioned, sponsored or administered by an employer, educational institution, international organisation, public authority or other client organisation.
In these cases, the sponsoring organisation may determine why participants are enrolled, which learning records are required and how those records are used. That organisation may therefore be the controller of some or all participant data, while Neda eLearning Solutions processes the data on its behalf as a processor.
Where another organisation is the controller:
-
its privacy notice will apply to the processing it controls;
-
questions about its use of participant data should normally be directed to that organisation; and
-
Neda eLearning Solutions will process the data in accordance with its contractual instructions and applicable data-protection law.
Neda eLearning Solutions may remain an independent controller for certain activities, such as platform security, its own accounting obligations, legal claims and management of its contractual relationships.
4. Categories of personal data processed
Depending on how you use Neda eCampus, we may process the following categories of personal data.
4.1 Account and profile data
This may include:
-
first name and surname;
-
username;
-
email address;
-
telephone number, where requested;
-
password in encrypted or hashed form;
-
profile photograph, where voluntarily provided;
-
preferred language;
-
country, time zone or location information provided by you;
-
organisation, employer, position or professional role;
-
account status and registration date; and
-
account and communication preferences.
4.2 Course and learning data
This may include:
-
course enrolments and enrolment status;
-
course access and participation records;
-
completion status and learning progress;
-
attendance records;
-
assignment submissions and uploaded files;
-
test, quiz and examination responses;
-
grades, scores, feedback and assessment results;
-
learning activity timestamps;
-
badges, competencies and certificates;
-
certificate or credential identifiers;
-
instructor comments;
-
survey and evaluation responses;
-
discussion forum posts;
-
messages sent through the platform; and
-
records of interaction with course content and learning activities.
4.3 Communications and support data
This may include:
-
correspondence with Neda eCampus;
-
support requests and technical enquiries;
-
complaints and feedback;
-
course-related communications;
-
newsletter subscriptions;
-
consent and communication-preference records; and
-
information provided during calls, meetings or online support sessions.
4.4 Technical, log and security data
This may include:
-
IP address;
-
login and logout timestamps;
-
browser type and version;
-
operating system and device information;
-
language and time-zone settings;
-
referring website;
-
pages and learning resources accessed;
-
session identifiers;
-
authentication events;
-
failed login attempts;
-
audit logs;
-
diagnostic information; and
-
information relating to suspected misuse, fraud or security incidents.
4.5 Payment and transaction data
Where paid services are offered, we may process:
-
billing name and address;
-
invoice information;
-
course or service purchased;
-
payment amount and currency;
-
payment date and status;
-
transaction identifiers; and
-
information required for accounting and tax purposes.
Payment-card details may be processed directly by an external payment provider. Neda eCampus should not store full payment card details unless this is expressly stated and appropriate payment security controls are in place.
4.6 Data received from third parties
We may receive personal data from:
-
an organisation that enrols or nominates you for a course;
-
an employer or educational institution;
-
a course administrator or instructor;
-
an external identity or social-login provider selected by you;
-
a payment provider;
-
an integration or learning tool you choose to use; or
-
another person who registers you with appropriate authority.
When you use an external sign-in service, Neda eCampus may receive information such as your name, email address, account identifier and other information displayed during the sign-in process. The external provider processes information under its own privacy terms.
4.7 Special categories of personal data
Neda eCampus does not generally require information concerning health, disability, racial or ethnic origin, religious beliefs, political opinions, trade-union membership, genetic or biometric data, or information concerning a person’s sex life or sexual orientation.
Such information may occasionally be processed when:
-
it is necessary to provide an accessibility adjustment or reasonable accommodation;
-
it is required for a specifically identified course or programme;
-
the person has voluntarily and explicitly provided it for an appropriate purpose; or
-
another legal basis under Article 9 GDPR applies.
Where such data are necessary, additional information about the purpose, legal basis, access restrictions and retention period will be provided where appropriate.
Users should not disclose sensitive personal information in public profile fields, discussion forums, assignments, or messages unless it is specifically required and an appropriate secure process is in place.
5. Purposes and legal bases for processing
We process personal data only where an applicable legal basis exists.
5.1 Creating and administering user accounts
Purposes:
-
creating and maintaining accounts;
-
authenticating users;
-
providing access to courses and platform functions;
-
managing enrolments and user preferences; and
-
providing requested platform services.
Legal basis: Article 6(1)(b) GDPR, where processing is necessary to enter into or perform a contract with you.
Where an account is provided through a sponsoring organisation, processing may instead be carried out on behalf of that organisation or on the basis of legitimate interests under Article 6(1)(f) GDPR.
5.2 Delivering courses and learning activities
Purposes:
-
providing course materials;
-
recording participation and progress;
-
processing assignments and assessments;
-
enabling communication with instructors;
-
issuing feedback, grades, badges or certificates; and
-
verifying completion or credentials.
Legal basis: Article 6(1)(b) GDPR, where the processing is necessary to provide a course or service requested by you.
For organisation-sponsored training, the legal basis may be the legitimate interests of Neda eLearning Solutions and the sponsoring organisation under Article 6(1)(f) GDPR, or another legal basis identified by the sponsoring organisation.
5.3 Communicating with users and providing support
Purposes:
-
responding to enquiries;
-
providing technical and administrative support;
-
sending essential course and account notifications;
-
communicating changes to courses or services; and
-
handling feedback and complaints.
Legal basis: Article 6(1)(b) GDPR where communications are necessary for the requested service, and Article 6(1)(f) GDPR for efficient support, service administration and resolution of enquiries.
Essential service, account and course messages are not marketing communications and may still be sent when a user has opted out of newsletters.
5.4 Platform security and misuse prevention
Purposes:
-
protecting accounts and systems;
-
detecting unauthorised access;
-
preventing fraud, misuse and cyberattacks;
-
maintaining system availability and integrity;
-
investigating security incidents; and
-
enforcing applicable platform rules.
Legal basis: Article 6(1)(f) GDPR, based on our legitimate interests in maintaining a secure and reliable learning platform.
Processing may also be necessary under Article 6(1)(c) GDPR where a legal security or reporting obligation applies.
5.5 Improving Neda eCampus
Purposes:
-
diagnosing technical problems;
-
assessing platform performance;
-
understanding how features and learning resources are used;
-
improving course design, accessibility and usability; and
-
producing aggregated statistics and reports.
Legal basis: Article 6(1)(f) GDPR, where the processing is necessary for service improvement and does not override the rights and interests of users.
Where non-essential cookies, tracking technologies or third-party analytics are involved, the legal basis is consent under Article 6(1)(a) GDPR.
Whenever reasonably possible, service-improvement analysis will use aggregated, anonymised or pseudonymised data.
5.6 Accounting, taxation and legal compliance
Purposes:
-
issuing and retaining invoices;
-
maintaining accounting records;
-
responding to lawful regulatory or authority requests;
-
fulfilling tax and commercial-law obligations; and
-
demonstrating compliance with applicable law.
Legal basis: Article 6(1)(c) GDPR.
5.7 Establishing, exercising or defending legal claims
Purposes:
-
managing contractual disputes;
-
investigating complaints or alleged misconduct;
-
enforcing legal rights;
-
retaining relevant evidence; and
-
obtaining professional advice.
Legal basis: Article 6(1)(f) GDPR, based on our legitimate interest in protecting and enforcing our legal rights.
5.8 Newsletters and promotional communications
Newsletters, course advertisements and other promotional communications are sent only where:
-
you have provided valid consent; or
-
another limited legal permission for direct marketing applies.
Legal basis: Article 6(1)(a) GDPR and the applicable requirements of the Austrian Telecommunications Act 2021.
You may withdraw newsletter consent or unsubscribe at any time by using the unsubscribe function in the message or contacting learn@neda-els.com.
Withdrawing marketing consent does not affect essential account, transactional or course-related communications.
5.9 Special categories of personal data
Where processing is based on explicit consent, the legal basis is Article 9(2)(a) GDPR.
In other cases, processing will occur only where another applicable condition under Article 9 GDPR or Austrian law has been identified and communicated.
6. Legitimate interests
Where we rely on Article 6(1)(f) GDPR, our legitimate interests may include:
-
operating an effective eLearning platform;
-
administering organisation-sponsored training;
-
maintaining platform and network security;
-
preventing fraud and misuse;
-
improving functionality, accessibility and user experience;
-
supporting users;
-
maintaining evidence of qualifications and course completion; and
-
establishing, exercising or defending legal claims.
Before relying on legitimate interests, we assess whether the processing is necessary and whether the rights and interests of affected individuals override those interests.
You may object to processing based on legitimate interests as described in Section 13.
7. Required and optional information
Fields marked as mandatory during registration or enrolment are required to create an account, provide the requested course or service, meet a legal requirement, or administer an organisation-sponsored programme.
Failure to provide mandatory information may mean that:
-
an account cannot be created;
-
enrolment cannot be completed;
-
a payment cannot be processed;
-
a certificate cannot be issued; or
-
a requested service cannot be provided.
Optional profile information does not have to be provided and may normally be removed by the user.
8. Cookies and similar technologies
Neda eCampus uses cookies and similar technologies.
8.1 Strictly necessary technologies
Some cookies and local-storage functions are necessary for:
-
logging users in;
-
maintaining authenticated sessions;
-
remembering security or privacy choices;
-
operating essential platform functions;
-
balancing server requests; and
-
preventing fraud or misuse.
These technologies may be used without cookie consent when strictly necessary to provide a service requested by the user.
Personal data associated with these technologies is processed on the basis of Article 6(1)(b) or Article 6(1)(f) GDPR, as appropriate.
8.2 Optional technologies
Analytics, personalisation, advertising or other non-essential technologies will be activated only after valid consent has been obtained.
Users must be able to:
-
accept optional technologies;
-
reject optional technologies;
-
select individual categories; and
-
withdraw or change their choices later.
Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal.
Further information, including cookie names, providers, purposes and lifetimes, must be provided in a separate Cookie Policy and through the cookie-preference interface.
The use of Neda eCampus does not by itself constitute consent to non-essential cookies.
9. Recipients of personal data
Access to personal data is limited to persons and organisations that require the information for an authorised purpose.
Recipients may include:
-
authorised Neda eLearning Solutions personnel;
-
course administrators, instructors, assessors and support personnel;
-
the organisation that sponsored or commissioned a course;
-
Moodle or LMS hosting and technical-support providers;
-
server, cloud-storage and backup providers;
-
email and communication service providers;
-
external authentication and identity providers selected by the user;
-
payment and accounting providers;
-
video-conferencing or media-delivery providers used for a course;
-
analytics providers, where the user has consented;
-
accessibility or learning-tool providers selected for a course;
-
professional advisers, including accountants, auditors, lawyers and insurers;
-
courts, regulators, law-enforcement authorities or public bodies where disclosure is legally required; and
-
potential successors in connection with a lawful reorganisation, transfer or sale of the business.
Where discussion forums, group activities or participant directories are enabled, your name, profile information, posts, messages or submissions may be visible to instructors and other authorised participants. The relevant visibility should be indicated within the course or activity.
Service providers that process personal data on our behalf are required to act under appropriate contractual and confidentiality obligations.
Neda eLearning Solutions does not sell personal data.
10. International data transfers
We seek to use providers located in the European Economic Area where reasonably practicable.
Some external identity providers, communication providers, analytics providers, video services or other technical providers may process personal data in countries outside the European Economic Area.
Where personal data are transferred to a country outside the European Economic Area, the transfer will be based on an appropriate mechanism under Chapter V GDPR, such as:
-
an adequacy decision adopted by the European Commission;
-
European Commission Standard Contractual Clauses;
-
another legally recognised safeguard; or
-
a specific derogation applicable in limited circumstances.
Where required, additional technical, contractual or organisational safeguards will be applied.
Information about the relevant transfer mechanism or a copy of applicable safeguards may be requested from learn@neda-els.com, subject to the protection of confidential information.
11. Retention of personal data
Personal data are retained only for as long as necessary for the relevant purpose, subject to legal, contractual, accreditation and dispute-related requirements.
Unless a different period is communicated for a particular course or service, the following retention schedule applies:
Account and profile data
Account and profile data are retained while the account remains active. They will normally be deleted or anonymised within 24 months after account closure or the last meaningful account activity, unless continued retention is required for course records, legal obligations, security investigations or legal claims.
Course participation and assessment records
Course enrolments, participation records, progress data, assessment results, grades and submissions are normally retained for five years after the end of the course.
A different period may apply where:
-
a sponsoring organisation determines the retention period;
-
an accreditation, certification or donor requirement applies;
-
records are required to verify a qualification;
-
a complaint or dispute remains unresolved; or
-
the user has been informed of a different course-specific period.
Certificate verification records
A limited record containing the learner’s name, course title, completion date, certificate result and credential identifier may be retained for up to ten years after the certificate is issued for verification and fraud-prevention purposes.
Support requests and general correspondence
Support requests, complaints and related correspondence are normally retained for three years after the matter is closed, unless a longer period is necessary for legal claims or compliance purposes.
General enquiries that do not result in an account, contract or continuing relationship are normally deleted within 12 months.
Technical and security logs
Routine technical, authentication and security logs are normally retained for up to 12 months.
Relevant logs may be retained longer where they are required to investigate a security incident, suspected misuse, fraud or a legal claim.
Newsletter information
Newsletter subscription data are retained until consent is withdrawn or the subscription otherwise ends.
After an opt-out, a limited suppression record may be retained to ensure that the email address is not inadvertently added to future marketing lists.
Accounting and transaction records
Invoices, payment records and related accounting documentation are generally retained for seven years from the end of the relevant calendar year, or longer where required for an ongoing tax, audit or legal proceeding.
Cookie data
Cookie and similar-technology retention periods are specified in the Cookie Policy and cookie-preference interface.
When a retention period expires, personal data will be deleted, anonymised or securely restricted unless continued processing is legally required.
12. Data security
Neda eLearning Solutions implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Depending on the processing and associated risks, these measures may include:
-
encrypted transmission;
-
secure password storage;
-
role-based access controls;
-
multi-factor authentication for privileged accounts;
-
system logging and monitoring;
-
regular software updates and security patches;
-
backups and recovery procedures;
-
restricted administrator access;
-
confidentiality obligations;
-
processor due diligence and contractual controls;
-
incident-response procedures; and
-
periodic review of permissions and security settings.
No online system can be guaranteed to be completely secure. Users are responsible for protecting their login credentials and should promptly notify Neda eCampus if they suspect unauthorised access to their accounts.
Where a personal data breach creates a legally reportable risk, Neda eLearning Solutions will notify the competent supervisory authority and affected individuals as required by law.
13. Your data-protection rights
Subject to the conditions and limitations of applicable law, you may have the following rights:
Right of access
You may request confirmation of whether your personal data are processed and obtain access to those data and related information.
Right to rectification
You may request correction of inaccurate data and completion of incomplete data.
Right to erasure
You may request deletion of personal data where there is no continuing lawful basis for retaining it.
The right to erasure does not apply where continued retention is required by law, necessary for legal claims or otherwise permitted under the GDPR.
Right to restriction
You may request that processing be restricted in circumstances specified by the GDPR.
Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may request eligible data in a structured, commonly used and machine-readable format.
Right to object
You may object, on grounds relating to your particular situation, to processing based on legitimate interests.
We will stop the relevant processing unless compelling legitimate grounds override your interests, rights and freedoms, or the processing is required for legal claims.
Right to object to direct marketing
You may object to direct marketing at any time. Personal data will no longer be processed for direct-marketing purposes following a valid objection.
Right to withdraw consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Rights concerning automated decisions
Where applicable, you may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
Right to lodge a complaint
You have the right to lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority in the European Union.
The Austrian supervisory authority is:
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
You are encouraged but not required to contact Neda eCampus first so the matter can be reviewed directly.
Exercising your rights
Requests should be sent to learn@neda-els.com.
We may request information necessary to verify your identity and protect your data from unauthorised disclosure.
Requests are generally answered within one month. This period may be extended, where permitted by law, due to the complexity or number of requests.
14. Children and young people
Neda eCampus is primarily designed for adult and professional learners. Individual courses may also be made available to younger learners, where expressly stated.
Where a service is offered directly to a child and consent is the relevant legal basis:
-
a person aged 14 or over may generally provide their own data-protection consent under Austrian law; and
-
for a person under 14, consent or authorisation from a parent or legal guardian will normally be required.
The GDPR consent threshold is separate from contractual capacity, course eligibility, and parental responsibility rules. A particular course may therefore require parental or guardian involvement even when the learner is aged 14 or over.
Where children are permitted to participate, Neda eCampus will seek to:
-
provide age-appropriate information;
-
collect only data necessary for the course;
-
apply appropriate visibility and communication settings;
-
limit unnecessary profiling and tracking;
-
verify parental authorisation where required; and
-
take particular care when publishing or sharing a child’s personal data.
Parents or legal guardians who believe that a child’s personal data has been processed inappropriately should contact learn@neda-els.com.
15. Automated decision-making and profiling
Neda eCampus does not currently rely solely on automated decision-making that produces legal or similarly significant effects on users.
Automated functions may be used to:
-
calculate quiz results;
-
display course progress;
-
recommend the next learning activity;
-
detect technical anomalies;
-
identify suspected misuse; or
-
support instructors and administrators.
Such functions do not ordinarily replace meaningful human review for decisions that significantly affect a learner.
If significant automated decision-making or profiling is introduced, affected users will receive additional information about:
-
the processing involved;
-
the underlying logic;
-
the significance and expected consequences;
-
the legal basis; and
-
the available safeguards and review rights.
16. External websites, integrations and embedded content
Courses may contain links to or embedded content from third-party websites, video platforms, interactive tools or external learning services.
Third parties may process personal data under their own privacy notices. Neda eLearning Solutions is not responsible for independent processing carried out by external organisations unless it has specifically selected and engaged them as processors.
Users should review the privacy information displayed before submitting personal data to an external service.
17. Changes to this Privacy Notice
This Privacy Notice may be updated to reflect:
-
changes to Neda eCampus services;
-
new platform functions;
-
changes to service providers;
-
legal or regulatory developments; or
-
changes to data-processing practices.
The current version will be published on Neda eCampus with its revision date.
Where a change materially affects users or requires new consent, appropriate notice or a new consent request will be provided before the relevant processing begins.
A change to this Privacy Notice does not retrospectively create a lawful basis for processing that was unlawful when it occurred.
18. Contact
Questions, requests and concerns relating to this Privacy Notice or the processing of personal data should be sent to:
Neda eCampus Data-Protection Contact
Email: learn@neda-els.com
Postal address:
Khusraw Parwez
Neda eLearning Solutions / Neda eCampus
Blumenstrasse 2/10
3170 Hainfeld
Austria