Legal

Privacy Policy

Last updated: June 2026  ·  Effective date: June 2026  ·  GMPify Training

Introduction

GMPify Training ("GMPify", "we", "us" or "our") operates the websites www.gmpify.com and learn.gmpify.com and provides on-demand pharmaceutical GMP training services.

We are committed to protecting the privacy and personal information of everyone who visits our websites or uses our training platform. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have in relation to it.

This policy applies to all personal information collected through our websites, our TalentLMS training portal at learn.gmpify.com, our email communications, and any other service we provide.

Data controller: GMPify Training

Contact: training@gmpify.com

Jurisdiction: Canada

Applicable laws: Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) · General Data Protection Regulation (GDPR) for EEA users

Information we collect

Account and registration information

When you create an account on our training platform at learn.gmpify.com, we collect:

  • Full name
  • Email address
  • Organisation / company name (if provided)
  • Job title (if provided)
  • Password (stored in encrypted form - we cannot read your password)
  • Country of residence (if provided)

Training and course data

As you use our training platform, we collect and store:

  • Courses enrolled in and completed
  • Quiz results and assessment scores
  • Completion certificates issued - including date, course name and score
  • Course progress and time spent per module
  • Login history and session data

Payment information

Subscription payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. GMPify does not store, see, or have access to your full credit card details. Stripe may share limited transaction information with us such as the last four digits of your card, card type, and billing country for subscription management purposes. Stripe's privacy policy is available at stripe.com/privacy.

Communications

If you contact us by email or sign up for our mailing list, we collect:

  • Your name and email address
  • The content of your communications with us
  • Any information you voluntarily provide in your message

Technical and usage data

When you visit our websites, we and our service providers may automatically collect:

  • IP address and approximate geographic location
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on each page
  • Referring website or search query

Our marketing website at www.gmpify.com is hosted on GitHub Pages and does not use any tracking cookies, advertising pixels, or analytics scripts. It is a fully static page that makes no third-party data collection requests.

We use Google Analytics to collect anonymised data about how visitors use our website, including pages visited, time spent and traffic sources. This data does not identify individual visitors.

How we use your information

We use the personal information we collect for the following purposes:

Providing our service

  • Creating and managing your account on our training platform
  • Delivering courses, assessments and completion certificates
  • Processing subscription payments and managing billing
  • Providing customer support and responding to your enquiries
  • Maintaining training records that can be used for GMP qualification documentation

Communications

  • Sending transactional emails - account confirmation, password reset, certificate delivery, payment receipts
  • Sending course update notifications when content is revised to reflect regulatory changes
  • Sending our newsletter and course announcements, where you have opted in

Platform improvement

  • Analysing course completion rates and assessment results to improve content quality
  • Identifying and resolving technical issues
  • Understanding which courses are most valuable to our users

Legal compliance

  • Complying with applicable laws and regulations
  • Responding to lawful requests from regulatory or law enforcement authorities
  • Enforcing our Terms of Service

We do not sell, rent, or trade your personal information to any third party for marketing or commercial purposes. Your data is used only to provide and improve the GMPify training service.

Legal basis for processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal information on the following legal bases:

  • Contract performance - processing necessary to deliver the training service you have subscribed to, including account management, course delivery, and certificate issuance
  • Legitimate interests - processing necessary for our legitimate business interests, such as platform security, fraud prevention, and service improvement - provided these interests are not overridden by your rights
  • Consent - where you have given explicit consent, such as signing up to receive our newsletter or marketing communications. You may withdraw consent at any time
  • Legal obligation - processing necessary to comply with applicable law

Third-party service providers

We use a small number of carefully selected third-party providers to operate our service. Each processes personal information only to the extent necessary to provide their service to us:

TalentLMS (Epignosis LLC) - our training platform provider, which hosts learn.gmpify.com. Your account data, course progress, and certificate records are stored on TalentLMS infrastructure. TalentLMS is SOC 2 Type II certified. Privacy policy: talentlms.com/privacy

Stripe - our payment processor. Handles all subscription billing. PCI-DSS Level 1 certified. Does not share full payment card details with us. Privacy policy: stripe.com/privacy

Brevo (Sendinblue) - our email service provider, used to send transactional emails, course announcements and our newsletter. Your name and email address are shared with Brevo solely for the purpose of email delivery. Privacy policy: brevo.com/legal/privacypolicy

GitHub Pages - hosts our marketing website at www.gmpify.com. GitHub may log IP addresses of visitors as part of standard web server operations. Privacy policy: docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement

We do not use Google Analytics, Facebook Pixel, or any advertising or behavioural tracking technology on our websites.

Data retention

We retain your personal information for as long as necessary to provide our service and comply with our legal obligations:

  • Active account data - retained for the duration of your subscription and for a period of 3 years after account closure, to allow for reactivation and to maintain training records
  • Completion certificates and training records - retained for 7 years after the date of issue. This is consistent with standard GMP training record retention expectations in the pharmaceutical industry and allows learners to reference certificates for inspection purposes
  • Payment records - retained for 7 years to comply with Canadian tax and financial record-keeping requirements
  • Email communications - retained for 2 years from the date of the most recent communication
  • Newsletter subscribers - retained until you unsubscribe, with a suppression record retained thereafter to honour your opt-out

When retention periods expire, data is securely deleted or anonymised.

Your privacy rights

Depending on your location, you have the following rights in relation to your personal information:

Rights under Canadian privacy law (PIPEDA)

  • Right of access - you have the right to know what personal information we hold about you and to receive a copy of it
  • Right to correction - you have the right to have inaccurate or incomplete personal information corrected
  • Right to withdraw consent - where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal
  • Right to complain - you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca

Additional rights under GDPR (EEA / UK users)

  • Right to erasure - the right to request deletion of your personal information, subject to legal retention obligations
  • Right to data portability - the right to receive your personal information in a structured, machine-readable format
  • Right to restrict processing - the right to ask us to limit how we use your personal information in certain circumstances
  • Right to object - the right to object to processing based on legitimate interests
  • Right to complain - you have the right to lodge a complaint with your national data protection authority

To exercise any of these rights, please contact us at training@gmpify.com. We will respond within 30 days. We may need to verify your identity before processing your request.

Cookies and tracking

Our marketing website at www.gmpify.com does not use cookies. It is a fully static page with no analytics, advertising pixels, or tracking of any kind.

Our training platform at learn.gmpify.com uses essential cookies required for the platform to function - specifically for maintaining your login session and remembering your course progress. These are strictly necessary cookies and cannot be disabled without breaking the service. We do not use advertising or behavioural tracking cookies on the training platform.

We do not use Google Analytics, Facebook Pixel, LinkedIn Insight Tag, or any other advertising or behavioural tracking technology on any of our websites.

Security

We take the security of your personal information seriously. The measures we have in place include:

  • HTTPS encryption - all data transmitted between your browser and our websites is encrypted using TLS
  • Password security - account passwords are stored using industry-standard one-way hashing. We cannot read your password
  • Access controls - access to personal data is restricted to personnel who need it to provide the service
  • Payment security - payment card data is processed exclusively by Stripe and never passes through or is stored on our systems
  • Platform security - our training platform (TalentLMS) is SOC 2 Type II certified

While we take all reasonable steps to protect your personal information, no internet-based service can guarantee absolute security. In the event of a data breach that poses a risk to your rights, we will notify you and relevant authorities as required by applicable law.

International data transfers

GMPify is based in Canada. Our service providers - TalentLMS, Stripe, and Brevo - may process data on servers located in the United States and the European Union.

Canada is recognised by the European Commission as providing an adequate level of data protection for commercial organisations subject to PIPEDA. Where we transfer data to the United States, we ensure appropriate safeguards are in place through our service provider agreements.

Children's privacy

Our training platform is designed for professional adults working in the pharmaceutical industry. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has provided us with personal information, we will take steps to delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, service, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify active subscribers by email.

We encourage you to review this policy periodically. Continued use of our service after any changes constitutes your acceptance of the updated policy.

Contact us

If you have any questions, concerns or requests relating to this Privacy Policy or the way we handle your personal information, please contact us:

GMPify Training

Email: training@gmpify.com

Website: www.gmpify.com

Jurisdiction: Canada

We aim to respond to all privacy enquiries within 30 days.

If you are located in Canada and are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.

If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection authority.