SCORMBridge
  • How it works
  • Capabilities
  • Pricing
Sign inGet started
LOST END FOUND LTD · LEGAL

Privacy Policy

Last updated 22 August 2026 · Terms of Service · Data Processing Addendum

This policy explains what personal data LOST END FOUND LTD (trading as SCORMBridge, “we”, “us”) collects, why, how long we keep it, who we share it with, and your rights under UK data-protection law (the UK GDPR and the Data Protection Act 2018) and, where it applies, the EU GDPR.

SCORMBridge is a platform on which publishers host e-learning courses and license them to client organisations, whose learners launch the courses from the organisation’s own learning management system (LMS). Because of that, we wear two hats — see “Our role” below. If you are a learner, your employer or training provider (the LMS operator) is usually the organisation responsible for your data, and their privacy notice applies alongside this one.

CONTENTS
  1. 1. Who we are
  2. 2. Our role: controller or processor
  3. 3. What we collect
  4. 4. Why we use it, and on what legal basis
  5. 5. Who sees it
  6. 6. Where data is stored and international transfers
  7. 7. How long we keep it
  8. 8. Security
  9. 9. Your rights
  10. 10. Cookies and local storage
  11. 11. Children
  12. 12. Changes to this policy

1. Who we are

The data controller for our website and portal accounts is LOST END FOUND LTD, a company registered in England and Wales under company number 15713779, registered office 86-90 Paul Street, London, England, EC2A 4NE. ICO registration: ZC197323.

Questions, requests and complaints: support@scormbridge.app (subject “Privacy”). We do not have a statutory data protection officer; the founder handles privacy matters personally.

2. Our role: controller or processor

  • Controller — for our public website, demo requests, and the accounts of people who sign in to the SCORMBridge portal (publisher staff, client administrators and members). This policy covers that processing in full.
  • Processor — for the data that flows through the SCORM proxy when a learner launches a licensed course. There we act on the instructions of the client organisation (and the publisher) under our Data Processing Addendum. The controller for learner data is the organisation that operates the LMS; if you are a learner, contact them first and we will assist them.

3. What we collect

Account and organisation data (we are controller)

  • Name, email address, password (stored only as a salted hash), optional profile picture, role, and the organisation or publisher you belong to.
  • Preferences you set (theme, locale, time zone, notification choices).
  • Sign-in security data: session tokens, the IP address and browser (user agent) of each sign-in, and short-lived rate-limit counters keyed by IP address.
  • Invitations: the email address invited, the inviting user, and the role offered.
  • Billing references: Stripe customer, subscription and checkout identifiers, plan and billing status. Card details never touch our systems — they are entered on pages hosted by Stripe. Publishers who sell through the marketplace also have a Stripe Connect account reference.
  • Support and demo requests: name, email, company, message, and what you tell us.
  • White-label settings: brand names, colours, logos and custom domains you configure.

Course content

Publishers upload course packages (files). These are business content, not normally personal data, but a publisher may include personal data in a course (for example a presenter’s name or image). Content is stored privately and served only to licensed learners through signed, short-lived links.

Learner launch and tracking data (we are processor)

  • The learner identifier and name the LMS passes to the course (for example cmi.core.student_id / student_name), a per-launch session identifier, the host name of the LMS page that launched the course, the browser user agent, and the time of launch.
  • Learning records the course reports back through the SCORM bridge: completion status, success status, score, time spent, and the SCORM data model values the course saves (including suspend_data, which can contain free text a course chooses to store).
  • IP addresses are used transiently for rate limiting and appear in our hosting provider’s request logs; we do not store them against launch records.

Usage analytics

We run our own analytics (Umami, self-hosted by us — no third-party advertising or tracking networks). It collects page views and product events, the page URL, referrer, browser, device type and country derived from the IP address, without cookies. Signed-in users are identified to analytics by their opaque account id, role and organisation id — never by name or email. Session replay (a recording of clicks and scrolling) runs on the public marketing site only, never inside the portal.

4. Why we use it, and on what legal basis

PurposeDataLegal basis
Providing the portal: accounts, organisations, licences, package downloads, reportingAccount, organisation, billing referencesPerformance of a contract (our Terms)
Delivering licensed courses to learners and reporting results to the LMS and to the client/publisherLaunch and tracking dataProcessor — on the client’s and publisher’s instructions; their lawful basis is typically contract or legitimate interests
Keeping the service secure: sign-in, sessions, rate limiting, abuse prevention, licence enforcementSign-in security data, IP addresses, launch metadataLegitimate interests (protecting the service and our customers)
Service emails: invitations, password resets, licence granted / expiring / suspended, weekly publisher digests, operator alertsEmail address, name, licence detailsPerformance of a contract and legitimate interests; these are not marketing emails
Billing and accountingBilling references, invoicesContract; legal obligation (tax and company records)
Understanding and improving the productPseudonymous analyticsLegitimate interests — you can opt out of analytics with a browser “Do Not Track”-style setting we honour (see Cookies below)
Responding to demo requests and supportWhat you send usLegitimate interests / steps before a contract

We do not sell personal data, do not use it for advertising, and do not make automated decisions with legal or similarly significant effects.

5. Who sees it

  • Between publishers and their clients. The publisher who licenses a course to your organisation can see that organisation’s usage of it — launches, number of distinct learners, completion rates — because that is what the service is for. Client organisations see their own learners’ activity. Publishers do not see your organisation’s member accounts beyond what is needed to manage the licence.
  • Sub-processors that host or support the service, listed in the DPA: Cloudflare (hosting, database, storage, email delivery, network), Stripe (payments), and our self-hosted analytics server. They may only use the data to provide their service to us.
  • Legal and safety. If required by law, a court, or to protect the rights, safety or property of users or the public.
  • Business transfers. If the business is sold or merged, data may transfer to the new owner under the same protections; we would tell you.

6. Where data is stored and international transfers

The platform runs on Cloudflare. Our databases, course content and profile pictures are stored in Cloudflare’s Western Europe region, and requests are handled at Cloudflare data centres close to the user, which can be anywhere in the world. Payments are handled by Stripe (Ireland / USA). Analytics run on a server we operate.

Where personal data leaves the UK or EEA, it does so under the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses built into our providers’ data-processing terms, together with their security commitments.

7. How long we keep it

DataRetention
Portal accountsUntil you delete your account (Settings → Danger zone) or an organisation administrator removes you; we then delete the account record and anonymise references to it
Sign-in sessionsExpire after 30 days of inactivity; you can revoke them any time in Settings
Invitations7 days, or until accepted or revoked
Learner launch and tracking dataFor the life of the licence it belongs to, then deleted within 12 months of the client relationship ending — or within 30 days of a verified deletion request from the client organisation
Course contentUntil the publisher deletes the version or course, or closes their account
Billing and accounting records6 years after the tax year they relate to (UK requirement)
Demo and support requests12 months after the conversation ends
AnalyticsPseudonymous by design (no IP addresses stored; opaque identifiers only) and retained in that form; aggregate statistics indefinitely
BackupsPoint-in-time database recovery is kept for up to 30 days by our hosting provider

8. Security

Data is encrypted in transit (TLS) and at rest by our hosting provider. Passwords are stored only as salted hashes. Course content is in private storage and is served only through signed links that expire and are bound to a specific licence, which is re-checked on every page load. Access to the portal is role-based and tenant-scoped; public endpoints are rate limited; secrets are held in the hosting provider’s secret store. We describe our measures in more detail in the DPA. No system is perfectly secure; if we become aware of a personal-data breach that affects you, we will tell you and, where required, the ICO.

9. Your rights

Under UK (and EU) data-protection law you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to how we use it; and provide it in a portable format. Where we rely on legitimate interests you can object, and where we rely on consent you can withdraw it at any time. Email support@scormbridge.app; we normally respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk) — we would appreciate the chance to address your concern first.

If you are a learner, the organisation that operates your LMS is the controller for your learning records; please contact them, and we will help them respond.

10. Cookies and local storage

Name / purposeTypeLifetime
Sign-in session (Better Auth)Strictly necessaryUp to 30 days
“View as” indicator for platform administratorsStrictly necessarySession
UI preferences such as sidebar state and theme (browser local storage, not sent to us)FunctionalUntil cleared
Stripe Checkout / Billing Portal (set by Stripe on Stripe’s own pages)Necessary for paymentPer Stripe
Analytics (Umami)Cookieless — no cookie is set—

We set no advertising or third-party tracking cookies, so we do not show a cookie banner. Our analytics respect the browser “Do Not Track” / Global Privacy Control signal.

11. Children

The portal is for business use and not directed at children. Courses may be delivered to learners of any age by a client organisation; in that case the organisation is responsible for the lawful basis and any parental consent, and we act only on its instructions.

12. Changes to this policy

We will post changes here and update the date at the top. For material changes affecting portal users we will also email account holders or show a notice in the portal. Continued use after the change takes effect means you accept the updated policy.

LOST END FOUND LTD · support@scormbridge.app
PricingSign inBook a demoPrivacyTermsDPA
Publish, license and track SCORM courses — without handing over the file.
SCORMBridge