Preloader
Child Protect Training Portal

Privacy Policy

This Privacy Policy explains how Child Protect collects, uses, stores, protects, and shares personal data when learners, parents, caregivers, schools, organizations, and trusted adults use the Child Protect Training Portal.

Legal and Safety Notice

This Privacy Policy is provided for transparency and general platform guidance. It explains how personal data may be handled when using the Child Protect Training Portal. It does not replace legal advice, school policy, official reporting procedures, emergency services, medical care, child protection authority guidance, or regulatory obligations. Schools and organizations should review their own legal, safeguarding, data protection, and Ministry of Education related responsibilities before using the platform.

Our privacy commitment

Child Protect provides safeguarding awareness training for learners, parents, caregivers, schools, organizations, and trusted adults. Because this training may involve children, students, school communities, and sensitive safety topics, we aim to collect only what is needed, use data for clear training purposes, protect learner information carefully, and explain privacy rights in plain language.

🔒

Privacy by purpose

We use personal data for defined training, account, support, certificate, security, and organization administration purposes.

🧒

Child and learner protection

Learner information is handled with extra care, especially where a learner is a child, student, or part of a school or youth organization.

📋

Clear records

Training progress and certificate records help learners, schools, and organizations understand completion status where enabled.

Privacy and education context in Thailand

Child Protect is designed for safeguarding training in education and child-facing environments. When schools or organizations use the portal, they may also have their own duties under Thai law, Ministry of Education expectations, school policies, child protection procedures, and data protection obligations.

  • Thailand’s Personal Data Protection Act B.E. 2562, as amended or supplemented, may apply to the collection, use, disclosure, storage, transfer, and protection of personal data.
  • Schools and education providers may need to align training, student safety, records, and communication with Ministry of Education or relevant education authority expectations.
  • Child-facing organizations should treat learner data, child safety information, and safeguarding concerns as protected information requiring careful handling.
  • Where a school, parent, caregiver, guardian, employer, or organization provides learner data, that party should ensure it has the proper authority, consent, notice, or lawful basis to do so.
  • Organizations should maintain their own safeguarding, data retention, incident response, access control, and reporting procedures.

What personal data we may collect

The exact data collected depends on how the portal is used, whether a learner creates an account, whether training is assigned by an organization, and whether certificates or progress tracking are enabled.

Data category Examples Why it may be used
Account data Name, email address, username, password credentials, role, organization, account status. To create accounts, manage access, authenticate users, provide training, and support account security.
Learner data Assigned courses, course progress, completed lessons, knowledge checks, completion status, certificate records. To deliver training, track progress, confirm completion, and provide certificates where enabled.
Organization data School or organization name, group assignment, training administrator, learner lists, completion reports. To support school or organization training administration, onboarding, refresher training, and reporting.
Support data Messages sent through contact forms, support questions, technical issues, course access requests. To respond to requests, resolve problems, and improve training support.
Technical data IP address, browser type, device information, log data, session records, security events. To protect the platform, prevent misuse, troubleshoot issues, and maintain service reliability.
Payment or billing data Invoice details, transaction references, billing contact data if paid services are used. To process purchases, subscriptions, invoices, records, and financial compliance where applicable.

Children, students, and guardian involvement

Because Child Protect training may be used by children or students, we apply a child-aware approach to privacy. We do not design the portal to collect unnecessary child data, and we encourage schools, parents, caregivers, guardians, and organizations to provide appropriate notice and consent before assigning training to children.

How child learner data should be handled

  • Only the minimum learner information needed for training should be provided.
  • Parents, guardians, schools, or authorized organizations should be involved where required.
  • Children should receive age-appropriate explanations about training and privacy where possible.
  • Training records should be accessed only by authorized users with a legitimate training or safeguarding role.
  • Child data should not be used for unrelated marketing or unrelated profiling.

School and organization responsibility

  • Confirm the legal basis or consent for enrolling learners.
  • Keep learner lists accurate and up to date.
  • Limit administrator access to people who need it.
  • Use training progress and certificates only for appropriate education, safeguarding, or organizational purposes.
  • Follow internal policies and applicable Thai legal requirements for child data and student records.

How we use personal data

Personal data is used to operate the training portal, provide safeguarding training, support learners and organizations, secure the platform, and maintain appropriate records.

  • To create, verify, and manage learner, parent, caregiver, staff, administrator, or organization accounts.
  • To provide training content, course access, learner dashboards, training steps, knowledge checks, progress tracking, and certificates.
  • To help schools or organizations manage assigned training and completion records where enabled.
  • To respond to contact form messages, support requests, course access questions, certificate questions, and technical issues.
  • To protect the security of the portal, detect misuse, prevent unauthorized access, and maintain system reliability.
  • To comply with applicable laws, lawful requests, contractual obligations, financial records, reporting obligations, or dispute resolution needs.
  • To improve training quality, platform usability, support materials, and safeguarding awareness resources.

Legal basis and lawful use

Depending on the situation, Child Protect may rely on one or more lawful bases to process personal data. The exact basis may depend on the learner, account type, organization arrangement, consent status, contract, legal duty, or safety need.

Consent

Consent may be used for optional communications, certain account features, or where a parent, guardian, learner, school, or organization gives permission for training participation.

Contract or service delivery

Data may be needed to provide the training portal, manage accounts, deliver courses, track progress, provide support, and issue certificates where enabled.

Legitimate or lawful interests

Data may be used to protect the platform, maintain records, improve services, prevent misuse, support safeguarding awareness, and manage organization training.

Legal obligation

Some records may be processed or retained where required by law, accounting rules, dispute handling, regulatory obligations, or lawful requests.

Vital or safety interests

In limited situations, information may be used or disclosed where necessary to protect a child, learner, or other person from serious harm.

School or organization authority

Where a school or organization assigns training, that organization may be responsible for confirming its authority, notice, consent, or lawful basis.

Safeguarding, privacy, and reporting boundaries

Child Protect provides training and awareness. It is not an emergency reporting service and does not replace a school, parent, guardian, government authority, medical provider, legal advisor, or child protection agency.

If there is immediate danger

If a child or young person is in immediate danger, contact the appropriate local emergency service, child protection service, school safeguarding contact, or trusted authority right away. Information submitted through the training portal or contact form may not be monitored as an emergency channel.

When personal data may be shared

We do not sell learner personal data. Personal data may be shared only when needed to provide the service, support training, comply with obligations, protect safety, or operate the portal responsibly.

  • With authorized school or organization administrators for assigned training, learner progress, and certificate records.
  • With service providers that help operate hosting, security, email, analytics, support, payment processing, or platform maintenance.
  • With parents, guardians, schools, or organizations where they are responsible for learner access or training management.
  • With legal, regulatory, law enforcement, emergency, or child protection authorities where required or where safety requires responsible disclosure.
  • With professional advisors, auditors, insurers, or legal representatives where necessary for compliance or dispute handling.
  • With a successor organization if the service is reorganized, merged, transferred, or sold, subject to appropriate privacy protections.

Cookies, analytics, and technical records

The platform may use cookies, session tools, server logs, and similar technologies to operate securely and improve the user experience.

Essential cookies

Used for login sessions, account access, security, form protection, and basic platform operation.

Performance information

May help us understand page performance, technical issues, course access problems, and service reliability.

Security logs

May be used to detect unauthorized access, abuse, suspicious activity, or platform errors.

Data protection and security

We use reasonable administrative, technical, and organizational safeguards to protect personal data. No online system can be guaranteed completely secure, but child and learner data should always be handled with careful access control and responsible security practices.

  • Access controls for accounts and administrator areas.
  • Password protection and account authentication tools.
  • Role-based access where supported by the platform.
  • Secure hosting and server-side controls appropriate for the service.
  • Administrative controls for learner records, progress records, and certificate records.
  • Security monitoring, backups, and maintenance where appropriate.
  • Limiting data access to authorized people who need it for training, support, security, compliance, or administration.

Retention and deletion

We keep personal data only for as long as reasonably necessary for training access, course completion, certificates, support, security, legal compliance, financial records, or school and organization training administration.

1

Active account period

Account, training, and progress data may be kept while the user or organization continues to use the portal.

2

Completion and certificate records

Completion records may be kept to allow learners, schools, or organizations to confirm training completion where certificates are enabled.

3

Legal and operational retention

Some data may be retained for accounting, legal, security, audit, dispute, or compliance purposes.

4

Deletion or anonymization

When data is no longer needed, it may be deleted, anonymized, securely archived, or restricted according to applicable requirements and technical capability.

Your privacy rights

Subject to applicable law, identity verification, school or organization authority, and legal exceptions, individuals may have rights over their personal data.

Rights you may request

  • Request access to personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion where data is no longer needed or where deletion is legally available.
  • Withdraw consent where processing is based on consent.
  • Object to certain processing where legally available.
  • Request restriction of processing in appropriate circumstances.
  • Request data portability where technically and legally applicable.
  • Ask questions or raise a complaint about how personal data is handled.

How requests are handled

  • We may need to verify your identity before responding.
  • For child learner data, we may need to verify parent, guardian, school, or organization authority.
  • Some requests may need to be handled through the school or organization that assigned the training.
  • Some records may need to be kept for legal, security, training, certificate, or compliance reasons.
  • We will aim to respond within a reasonable time and explain if we cannot fully complete a request.

International access and data transfers

The Child Protect Training Portal may be accessed from Thailand or other countries. Hosting, support, email, analytics, security, or technical service providers may involve systems or personnel located outside the user’s country.

Cross-border protection approach

Where personal data is transferred or accessed internationally, we aim to use appropriate safeguards, service provider controls, contractual protections, access limits, and security measures consistent with the nature of the data and applicable legal requirements.

Responsibilities of schools and organizations

When a school or organization uses Child Protect for learner training, it may act as a data controller or responsible party for learner assignment, parent or guardian communication, internal records, and local compliance.

  • Provide privacy notice to learners, parents, guardians, staff, or participants where required.
  • Confirm the lawful basis, consent, or authority for enrolling learners and sharing learner data.
  • Limit training administrator access to authorized staff only.
  • Use learner progress and certificate records only for appropriate education, training, safeguarding, or organization purposes.
  • Maintain internal policies for safeguarding, child protection, incident reporting, data retention, and access control.
  • Notify Child Protect promptly if learner data should be corrected, restricted, removed, or transferred to a different administrator.
  • Follow applicable Thai law, Ministry of Education expectations, school policy, and child protection procedures.

Updates to this Privacy Policy

We may update this Privacy Policy when the platform changes, training features are added, legal requirements change, or privacy practices are improved. The updated version will be posted on this page with the revised effective date.

Recommended review: Schools, organizations, parents, caregivers, and learners should review this page periodically. If the way learner data is used changes materially, additional notice or consent may be required depending on the situation.

Effective date: July 2026

Questions about privacy or learner data?

Contact Child Protect for questions about account data, learner records, training progress, certificates, organization access, or privacy requests.

Contact Child Protect Child Data Notice