Skip to content

Privacy Policy

Last updated 27 August 2026.

This Privacy Policy explains how the iLactation learning platform (“the Platform”, “we”, “us”) collects, uses, retains, and protects personal data when you use our continuing-education service, and the rights you have over your data under the EU General Data Protection Regulation (GDPR) and equivalent laws.

1. Who we are

The data controller for personal data processed through the Platform is:

  • Entity: iLactation Limited
  • Registered office: 16/F Wing Hing Commercial Building, 139 Wing Lok Street, Sheung Wan, Hong Kong
  • Privacy contact: privacy@ilactation.com

European Representative under Article 27 of GDPR

We have appointed EUREP (Bizlegal t/a EUREP, Company number 635921, Ireland) as our Representative under Article 27 of the EU General Data Protection Regulation (“GDPR”). All GDPR queries from EU Data Subjects or Data Protection authorities should be submitted to eurep.ie via their dedicated form. You may also contact us directly at privacy@ilactation.com.

The Platform operates separate regional sites (English, Spanish, Dutch). This policy applies to all of them.

2. Scope

This policy covers the learning platform (account, course/conference access, video viewing, certificates, payments, and support). It does not cover third-party websites we link to, or the separate iLactation marketing website, which has its own policy.

Local processing is carried out under Hong Kong’s Personal Data (Privacy) Ordinance. Processing relating to people in the European Union is also governed by the GDPR. The UK GDPR applies in the same way to people in the United Kingdom.

The company’s directors access the Platform from the United Kingdom and Australia, and our platform developer provides technical support from the United Kingdom. Accounting records are shared with the company’s accountants and auditor in Hong Kong. Where access from Australia touches data held for people in the EU, it is protected by the safeguards described in the international transfers section below (performance of a contract, Art. 49(1)(b)).

3. What we collect, and why

We collect only what we need to run the service. The table below lists each category, why we process it, and the lawful basis under GDPR Art. 6.

CategoryWhat it includesWhyLawful basis (Art. 6)
AccountEmail, name, hashed password, and (optional) profile details: organisation, professional/lactation role, country, credentialsCreate and operate your account; show your name on certificatesContract (Art. 6(1)(b))
AuthenticationPasskey credentials (WebAuthn), one-time login codes, session metadataSecurely sign you inContract (Art. 6(1)(b))
RegistrationsWhich conferences/courses you register forGive you access to content you’ve enrolled in; record attendanceContract (Art. 6(1)(b))
Viewing / attendanceWhich video seconds you’ve watched and your completion percentage per presentationAward attendance and continuing-education certificates, which require verified viewingContract (Art. 6(1)(b))
CertificatesCertificates issued to you, each carrying a certificate number that can be quoted back to us to confirm the certificate is genuineIssue and let third parties verify your CE creditsContract / legal record (Art. 6(1)(b))
PaymentsAmount, currency, status, country, and payment-processor reference IDs (we never store full card numbers)Process payment and keep accounting/tax recordsContract + legal obligation (Art. 6(1)(b), (c))
Security & audit logsSign-in events, IP address, browser/device, approximate location (country), timestampsProtect accounts, detect and investigate fraud and abuseLegitimate interests (Art. 6(1)(f)) — security & fraud prevention
Usage analyticsPage views and video-play events with a hashed (non-reversible) IP, browser family, device type, country (no city), and a temporary per-tab visit identifier, and, when you arrive from one of our posts or emails, the campaign label on the link (so we can tell which announcements are useful)Understand and improve how the service is used, in aggregateLegitimate interests (Art. 6(1)(f)) — service improvement
Diagnostic error logsTechnical error details, the page where it happened, browser, IP, approximate locationDiagnose and fix faultsLegitimate interests (Art. 6(1)(f)) — reliability
Email recordsTransactional emails we send you (e.g. receipts, certificate notices) and their delivery statusProve and troubleshoot delivery of service emailsContract + legitimate interests (Art. 6(1)(b), (f))
Support questionsQuestions you submit through the platformAnswer youContract / legitimate interests (Art. 6(1)(b), (f))

We also keep aggregated usage statistics (daily counts by page, browser, country, etc.). These contain no personal data — they are counts only — and are retained indefinitely for trend analysis.

Data minimisation in analytics. Our usage analytics are deliberately privacy-minimising: IP addresses are hashed before storage (we cannot recover the original IP from analytics), we record country only (never city), and the per-tab visit identifier is temporary (held only in your browser tab’s session storage, not a persistent cookie or device ID).

We do not sell personal data, and we do not use it for behavioural advertising or cross-site tracking.

4. Cookies and similar technologies

We use only strictly-necessary cookies and storage:

  • Authentication — to keep you signed in.
  • Site/region selection — to remember which regional site you’re using.
  • Bot protection (Cloudflare Turnstile) — to tell humans from automated abuse.

Because we use no analytics, advertising, or other non-essential cookies, and because our analytics use no persistent identifier, no cookie-consent banner is required. The per-tab visit identifier used for analytics lives in your browser’s session storage and is discarded when you close the tab.

5. How long we keep it

DataRetention
Account, profile, registrationsFor the life of your account (see erasure below)
CertificatesFor the life of your account (see erasure below)
Campaign attribution on your account (which link brought you to us)Kept while your account exists, deleted with your account
Completion records (which presentations you completed, when, and credits awarded)Six years after the last date that programme was offered, per IBLCE preferred provider guidance (see erasure, §6)
Payments and related accounting recordsAt least seven years, as required by section 51C of the Hong Kong Inland Revenue Ordinance
Security & audit logs12 months
Usage analytics (raw, identifiable-by-hash events)30 days, then deleted; only non-personal aggregate counts remain
Diagnostic error logs90 days
Email delivery records24 months
Aggregate usage statisticsIndefinitely (contain no personal data)

When you delete your account, we erase your personal data (see §6), except for completion records. Completion records (your name, the presentation, the completion date, and credits awarded) are kept in identifiable form for six years after the programme was last offered, under the legal-obligation exception in Art. 17(3)(b) GDPR, because accreditation audits require evidence of who completed which presentation. We also retain certain other records where the law requires (e.g. accounting) or where we have an overriding legitimate interest (e.g. a short-lived security log).

6. Your rights

Under the GDPR you have the right to:

  • Access your data and get a copy (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erase your data (“right to be forgotten”) (Art. 17), subject to legal-retention exceptions.
  • Port your data in a machine-readable format (Art. 20).
  • Restrict or object to processing based on legitimate interests, including our security and analytics processing (Art. 18, 21).
  • Withdraw consent where we rely on consent (we generally do not).
  • Lodge a complaint with a data-protection supervisory authority (Art. 77).

How to exercise them

  • Access / export: download a complete copy of your data from your account settings at any time.
  • Erasure: delete your account from your account settings. This erases your personal data, except for completion records (your name, the presentation, the completion date, and credits awarded), which we keep in identifiable form for six years after the programme was last offered, because accreditation audits require evidence of who completed which presentation (Art. 17(3)(b) GDPR). Accounting records we must keep by law are also retained.
  • Rectification: edit your profile in your account settings. To change the name printed on issued certificates, contact support@ilactation.com.
  • Other requests / questions: contact privacy@ilactation.com. We respond within one month (Art. 12(3)).

7. Who we share data with (processors)

We share personal data only with service providers (“processors”) who help us run the Platform, under contracts that require them to protect it and use it only on our instructions. They fall into these categories:

  • Payment processors
  • Cloud hosting and database providers
  • Video delivery
  • Email delivery
  • Bot and abuse protection
  • Document storage and artificial intelligence (AI) document reading (all EU-region for tracker documents)
  • Error monitoring

We maintain a full register of named processors internally, in accordance with GDPR Article 30.

We may also disclose data where required by law or to protect our rights, users, or the public.

8. International transfers

Some processors listed above may process data outside the European Economic Area. Where they do, the transfer is protected by an appropriate safeguard under GDPR Chapter V — an adequacy decision or Standard Contractual Clauses.

9. Complaints

If you believe we have mishandled your data, please contact us first so we can put it right. You may also lodge a complaint with the data-protection supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement. Our EU representative (see section 1, European Representative under Article 27 of GDPR) can also be contacted as the EU contact point for this policy.

10. Security and data breaches

We protect your data with measures including hashed passwords, passkey (WebAuthn) support, session-revocation controls, account-lockout protection, encrypted connections, signed/expiring video links, and access controls that isolate each regional site’s data.

A data breach means unauthorised access to, or accidental loss, alteration or unlawful destruction of, personal data we hold. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant data protection authority within 72 hours of becoming aware of it. If a breach is likely to put you at high risk, for example to your identity or finances, we will also tell you directly, without undue delay, explaining what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself. Questions about data security can be sent to privacy@ilactation.com at any time.

11. Children

The Platform is a professional continuing-education service intended for adults (typically healthcare professionals). It is not directed at children, and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

We will post any changes here and update the “Last updated” date. Material changes will be communicated through the Platform.

13. The recertification tracker

The recertification tracker is an optional feature. It is off for your account until you choose to activate it, and activating it requires your explicit consent to the processing described here. If you never activate it, none of the following applies to you.

What we store when you use the tracker. Your certification details (IBCLC L-number if you choose to give it, your cycle dates), your continuing-education records (credits earned with us, credits you add by hand, and credits read from documents you upload), your self-assessment scores if you enter them, your practice-hours log, your life-support course records, and the evidence documents you upload or email to us (for example CERP certificates, score reports, or course certificates).

Where it is stored. Your evidence documents are stored in a dedicated, encrypted storage area in the European Union (AWS, eu-central-1), separate from the platform’s general content storage. Each person’s documents are stored under their own private prefix and are only retrievable by that person’s signed-in account (or by our administrators for support, which is logged).

AI document reading. If you use the “drop any document” import or the ask-anything helper, the document or question is processed by an artificial intelligence (AI) model running on AWS Bedrock in the European Union, under our agreement with AWS. Your documents are not used to train any AI model, and this processing happens only for accounts that have separately agreed to AI processing during setup (it is a distinct, optional consent). Nothing an AI model reads is added to your records without your review and confirmation.

Email-in. If you forward a certificate to our vault address from the email address on your account, and your email provider’s signature checks out, the document goes straight into your vault as a pending import and is read like an upload. Nothing is added to your record until you review and save it. If we cannot verify the message came from you, it is held in a quarantine area for up to 7 days and then deleted, and we tell you to upload the document instead. We record the sending address and standard email authentication results with each message. We keep the record of the forwarded message (sending address and authentication results) for 90 days. The email provider that receives the message for us keeps its own copy for 30 days in the United States under the EU standard contractual clauses; we cannot shorten that. If you would rather your certificate never leave the EU, upload it directly instead of emailing it.

Aggregated statistics. We produce aggregated, anonymous statistics from tracker data — for example, how many members use a feature, or how many imported credits come from each kind of training provider — to understand and improve our offering. These are counts only: no individual member is ever identifiable in them, and we never contact you or make decisions about you based on the content of your documents.

Reminders and messages. The tracker can send you service reminders about your own cycle (deadlines, missing items). You control the cadence, including turning them off entirely. Marketing email is a separate opt-in choice at setup, unticked by default, and withdrawable at any time.

Your controls. In the tracker’s settings you can: export your tracker data (a machine-readable file plus your documents), and delete all of your tracker data — records and uploaded documents — permanently and immediately, without contacting us. Deleting your account deletes your tracker data the same way.

Retention. Tracker records and documents are kept while your account remains active, because a recertification cycle spans five years and an audit can look back across it. They are deleted when you delete them, when you delete your tracker data, or when your account is deleted. One exception applies platform-wide, not just to the tracker: as an accredited continuing-education provider we are required to keep records of who completed which presentation for six years after the last date that programme was offered. Those completion records are kept for that period even if you delete your account, and are then removed or anonymised.

14. Contact

iLactation · privacy@ilactation.com