Skip to main content

Legal

Privacy Policy

Last Updated: March 18, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how Canada Digital Learning Hub (“we”, “us”, or “our”) collects, uses, and protects personal data when you visit our website or contact us about our learning content and programme. Canada Digital Learning Hub is a privately operated education platform for adults across Canada. It is not a government service and is not affiliated with the Government of Canada or any provincial authority.

The data controller responsible for processing your personal data is:

Legal entity: Lambora B.V.

Registered address: Oostenstein 8, 9291 GR Kollum, Netherlands

Contact email: [email protected]

We do not appoint a dedicated Data Protection Officer (DPO) because we do not conduct large-scale processing of special-category data. If this changes, we will update this policy and provide DPO contact details.

2. Personal Data We Collect

We collect personal data in a few practical ways: when you send us a message, when your browser loads pages on our site, and when you choose cookie preferences. The categories below reflect how a typical learning website operates.

  • Identity and contact data: name, email address, phone number, and province/territory if you provide it in a form.
  • Form content: message text and any learning or enrolment details you choose to share with us.
  • Technical data: IP address, browser type and version, device type, operating system, and language settings.
  • Usage data: pages viewed, time spent on pages, referrer information, and click paths used to navigate the site.
  • Cookies and identifiers: cookie IDs and consent choices stored in your browser (see Section 4).
  • Conversion events: whether a form was submitted or an enrolment request was completed, and the page you were on when that happened.

We do not intentionally collect special-category data (for example, health data, religious or political information), financial account details, or government-issued identifiers. Please do not include sensitive information in free-text form fields.

3. Why We Process Personal Data & Legal Bases (GDPR Article 6)

We process personal data only when we have a lawful basis under the General Data Protection Regulation (GDPR). The legal basis depends on what you are doing on the site and which cookies you choose to allow.

  • Contact and enrolment inquiries: to respond to questions, provide programme details, and manage communications. Legal basis: Article 6(1)(b) (steps prior to entering into a contract) and Article 6(1)(a) (consent) where applicable.
  • Analytics: to understand which pages are useful, how readers move through lessons, and where content needs improvement. Legal basis: Article 6(1)(a) (consent).
  • Marketing and remarketing: to measure advertising performance and show relevant messages to people who previously interacted with the site. Legal basis: Article 6(1)(a) (consent).
  • Security and fraud prevention: to protect the site, reduce abuse, and investigate suspicious activity. Legal basis: Article 6(1)(f) (legitimate interests).
  • Legal compliance: to meet legal obligations (for example, responding to lawful requests). Legal basis: Article 6(1)(c) (legal obligation).

Automated decision-making (GDPR Article 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals.

4. Cookies & Tracking

Cookies are small text files stored on your device. Some cookies are required for basic site operation, while others help us measure usage or support advertising measurement. We also use similar technologies such as pixel tags (small pieces of code used to record page views or conversions) and server-side tracking where applicable.

Our cookie categories match our Cookie Policy at /cookie-policy/.

Essential (always active)

Essential cookies are required for the site to function. They support basic continuity (for example, keeping a session stable) and store your cookie preference choices. Essential cookies do not require consent under EU ePrivacy rules when used strictly for necessary functionality.

  • Examples: _site_session, cookie_consent, and security-related cookies such as CSRF protections.
  • Retention: session to 12 months depending on cookie type and your browser settings.

Analytics (requires consent)

If you opt in, analytics cookies help us understand how the site is used so we can improve lesson clarity and navigation. We use Google Analytics 4 (GA4) with IP anonymization where available and retention settings aligned to educational content measurement rather than surveillance.

  • Examples: _ga, _ga_XXXXXXXXXX (GA4 property-specific cookie).
  • Data retention: 14 months (GA4 settings).

Marketing (requires consent)

If you opt in, marketing cookies support advertising measurement and relevant messaging. They help us understand which ads lead to visits and which pages lead to enquiries. Marketing cookies may also be used to build remarketing audiences and lookalike audiences.

  • Examples: _gcl_au (Google Ads), _fbp and _fbc (Meta).
  • Typical retention: 90 days for marketing identifiers, depending on provider policies and browser settings.

Beyond cookies, certain providers may derive identifiers from combinations such as IP address and User-Agent. If we use server-side integrations (for example, Meta Conversion API or server-side Google Tag Manager), we implement them with consent controls and with data minimization. Where hashing is used for identifiers, it is applied before transfer.

5. Consent (EEA/UK)

Users in the European Economic Area (EEA) and the United Kingdom receive a consent notice under GDPR and UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (Article 6(1)(a)).

Your consent choice is recorded in a browser cookie named cookie_consent and typically remains for 12 months unless you change it. You can withdraw consent at any time by using “Manage cookie preferences” in the footer or by clearing cookies in your browser settings. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.

6. Sharing With Advertising & Service Partners

We use a small set of service providers to operate and improve the site. When you opt in to analytics or marketing cookies, certain data may be shared with those providers to deliver the requested functionality.

  • Google LLC (Google Analytics 4, Google Ads, Tag Manager, remarketing): cookie identifiers, usage data, conversion events, and audience signals. Privacy information: https://policies.google.com/privacy.
  • Meta Platforms, Inc. (Pixel, custom/lookalike audiences, conversion measurement): page views, conversions, audience membership, and where configured, hashed identifiers. Privacy information: https://www.facebook.com/privacy/policy.
  • Cloudflare, Inc. (CDN and security): network traffic data such as IP address and request metadata used for performance and threat detection. Privacy information: https://www.cloudflare.com/privacypolicy/.

We do not sell personal data. These providers act as processors or independent controllers depending on the product configuration. Where possible, we configure services to restrict use of site data to providing services to us rather than for the provider’s independent commercial purposes.

7. International Transfers

Lambora B.V. is based in the Netherlands. Some service providers may process data outside the EEA/UK, including in the United States. When transfers occur, we rely on appropriate safeguards.

  • EU–US Data Privacy Framework (DPF) where applicable (primary mechanism since July 2023).
  • UK Extension to the EU–US DPF where applicable.
  • Swiss–US DPF where applicable.
  • Standard Contractual Clauses (SCCs, EU 2021/914) as a fallback safeguard.
  • UK International Data Transfer Addendum / IDTA as a fallback safeguard.

8. Data Retention

We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymize it unless legal obligations require longer retention. Typical retention periods are:

  • Contact submissions: up to 2 years from the last interaction, to manage follow-up and keep a record of what was requested.
  • Analytics data: 14 months (GA4 retention setting), subject to your consent choice and provider configuration.
  • Marketing cookies: retained for the lifetime of the cookie (often 90 days) and subject to your consent.
  • Email correspondence: for the duration of the relationship plus 1 year.
  • Server and security logs: typically 90 days, unless needed longer to investigate abuse or security incidents.
  • Cookie consent record: up to 3 years for audit and compliance evidence.
  • Legal and tax records: retained as required by applicable law, commonly 6–10 years for invoicing records where relevant.

9. Your Rights (GDPR & UK GDPR)

If GDPR or UK GDPR applies to you, you may have the following rights:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to withdraw consent at any time (Article 7(3))
  • Right to lodge a complaint with a supervisory authority (Article 77)

To exercise a right, email [email protected]. We respond within 30 days. For complex requests, we may extend by up to 60 days and will explain why.

If you wish to contact a supervisory authority, the following directories may help:

10. Children

This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, contact us and we will delete it promptly.

11. Do Not Track

This website does not respond to “Do Not Track” (DNT) browser signals. Some third-party providers may offer their own DNT-related settings or opt-outs.

12. Data Deletion Requests

To request deletion of personal data, email us with the subject line Data Deletion Request. We may ask for reasonable verification to ensure we do not delete the wrong person’s data. We aim to complete deletion within 30 days, unless retention is required by law or needed for a legitimate security purpose.

13. Business Transfers

If we are involved in a merger, acquisition, asset sale, financing, insolvency, or similar event, personal data may be transferred to a successor entity. If the transfer materially changes how personal data is used, we will provide notice on the site.

14. California (CCPA / CPRA)

Although Lambora B.V. is based in the Netherlands, our content may be accessed from the United States. This section is provided for transparency.

Over the past 12 months, we may have disclosed the following categories of personal information to service providers and advertising partners, depending on your cookie consent choices:

  • Identifiers: name, email, IP address, cookie IDs.
  • Internet/network activity: page views, click paths, interaction with forms.
  • Inferences: interests or preferences used for advertising audiences.

We do not sell personal information as defined by CCPA. We may share information for cross-context behavioural advertising when marketing cookies are enabled. California residents may opt out by using our cookie preferences panel.

Rights may include: the right to know, delete, correct, opt out of sale/sharing, and non-discrimination. To submit a request, email us with the subject line California Privacy Request. We will verify requests as required. Authorized agents may submit requests with written proof of authorization.

15. Virginia (VCDPA)

Virginia residents may have rights to access, correct, delete, and obtain a copy of personal data, as well as to opt out of targeted advertising. To submit a request, email us with the subject line Virginia Privacy Request.

We do not sell personal data or engage in profiling that produces legal or similarly significant effects. If we decline a request, you may appeal by emailing Appeal of Refusal — Privacy Request. We respond to appeals within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing us with the subject Nevada Do Not Sell Request. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, the site, or legal requirements. If changes are material, we will provide a notice on the homepage at least 14 days before the change takes effect. We also update the “Last Updated” date at the top of this page.

18. Contact

If you have questions about this Privacy Policy or want to exercise a privacy right, contact:

Lambora B.V.

Oostenstein 8, 9291 GR Kollum, Netherlands

Email: [email protected]

Questions about privacy?

If you want help with cookie preferences or a data request, email us and we will respond in a reasonable time. For cookie settings, use the “Manage cookie preferences” link in the footer.