Privacy Policy
Last updated 22 August 2026 · Terms of Service · Data Processing Addendum
This policy explains what personal data LOST END FOUND LTD (trading as SCORMBridge, “we”, “us”) collects, why, how long we keep it, who we share it with, and your rights under UK data-protection law (the UK GDPR and the Data Protection Act 2018) and, where it applies, the EU GDPR.
SCORMBridge is a platform on which publishers host e-learning courses and license them to client organisations, whose learners launch the courses from the organisation’s own learning management system (LMS). Because of that, we wear two hats — see “Our role” below. If you are a learner, your employer or training provider (the LMS operator) is usually the organisation responsible for your data, and their privacy notice applies alongside this one.
1. Who we are
The data controller for our website and portal accounts is LOST END FOUND LTD, a company registered in England and Wales under company number 15713779, registered office 86-90 Paul Street, London, England, EC2A 4NE. ICO registration: ZC197323.
Questions, requests and complaints: support@scormbridge.app (subject “Privacy”). We do not have a statutory data protection officer; the founder handles privacy matters personally.
2. Our role: controller or processor
- Controller — for our public website, demo requests, and the accounts of people who sign in to the SCORMBridge portal (publisher staff, client administrators and members). This policy covers that processing in full.
- Processor — for the data that flows through the SCORM proxy when a learner launches a licensed course. There we act on the instructions of the client organisation (and the publisher) under our Data Processing Addendum. The controller for learner data is the organisation that operates the LMS; if you are a learner, contact them first and we will assist them.
3. What we collect
Account and organisation data (we are controller)
- Name, email address, password (stored only as a salted hash), optional profile picture, role, and the organisation or publisher you belong to.
- Preferences you set (theme, locale, time zone, notification choices).
- Sign-in security data: session tokens, the IP address and browser (user agent) of each sign-in, and short-lived rate-limit counters keyed by IP address.
- Invitations: the email address invited, the inviting user, and the role offered.
- Billing references: Stripe customer, subscription and checkout identifiers, plan and billing status. Card details never touch our systems — they are entered on pages hosted by Stripe. Publishers who sell through the marketplace also have a Stripe Connect account reference.
- Support and demo requests: name, email, company, message, and what you tell us.
- White-label settings: brand names, colours, logos and custom domains you configure.
Course content
Publishers upload course packages (files). These are business content, not normally personal data, but a publisher may include personal data in a course (for example a presenter’s name or image). Content is stored privately and served only to licensed learners through signed, short-lived links.
Learner launch and tracking data (we are processor)
- The learner identifier and name the LMS passes to the course (for example
cmi.core.student_id/student_name), a per-launch session identifier, the host name of the LMS page that launched the course, the browser user agent, and the time of launch. - Learning records the course reports back through the SCORM bridge: completion status, success status, score, time spent, and the SCORM data model values the course saves (including
suspend_data, which can contain free text a course chooses to store). - IP addresses are used transiently for rate limiting and appear in our hosting provider’s request logs; we do not store them against launch records.
Usage analytics
We run our own analytics (Umami, self-hosted by us — no third-party advertising or tracking networks). It collects page views and product events, the page URL, referrer, browser, device type and country derived from the IP address, without cookies. Signed-in users are identified to analytics by their opaque account id, role and organisation id — never by name or email. Session replay (a recording of clicks and scrolling) runs on the public marketing site only, never inside the portal.
4. Why we use it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the portal: accounts, organisations, licences, package downloads, reporting | Account, organisation, billing references | Performance of a contract (our Terms) |
| Delivering licensed courses to learners and reporting results to the LMS and to the client/publisher | Launch and tracking data | Processor — on the client’s and publisher’s instructions; their lawful basis is typically contract or legitimate interests |
| Keeping the service secure: sign-in, sessions, rate limiting, abuse prevention, licence enforcement | Sign-in security data, IP addresses, launch metadata | Legitimate interests (protecting the service and our customers) |
| Service emails: invitations, password resets, licence granted / expiring / suspended, weekly publisher digests, operator alerts | Email address, name, licence details | Performance of a contract and legitimate interests; these are not marketing emails |
| Billing and accounting | Billing references, invoices | Contract; legal obligation (tax and company records) |
| Understanding and improving the product | Pseudonymous analytics | Legitimate interests — you can opt out of analytics with a browser “Do Not Track”-style setting we honour (see Cookies below) |
| Responding to demo requests and support | What you send us | Legitimate interests / steps before a contract |
We do not sell personal data, do not use it for advertising, and do not make automated decisions with legal or similarly significant effects.
6. Where data is stored and international transfers
The platform runs on Cloudflare. Our databases, course content and profile pictures are stored in Cloudflare’s Western Europe region, and requests are handled at Cloudflare data centres close to the user, which can be anywhere in the world. Payments are handled by Stripe (Ireland / USA). Analytics run on a server we operate.
Where personal data leaves the UK or EEA, it does so under the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses built into our providers’ data-processing terms, together with their security commitments.
7. How long we keep it
| Data | Retention |
|---|---|
| Portal accounts | Until you delete your account (Settings → Danger zone) or an organisation administrator removes you; we then delete the account record and anonymise references to it |
| Sign-in sessions | Expire after 30 days of inactivity; you can revoke them any time in Settings |
| Invitations | 7 days, or until accepted or revoked |
| Learner launch and tracking data | For the life of the licence it belongs to, then deleted within 12 months of the client relationship ending — or within 30 days of a verified deletion request from the client organisation |
| Course content | Until the publisher deletes the version or course, or closes their account |
| Billing and accounting records | 6 years after the tax year they relate to (UK requirement) |
| Demo and support requests | 12 months after the conversation ends |
| Analytics | Pseudonymous by design (no IP addresses stored; opaque identifiers only) and retained in that form; aggregate statistics indefinitely |
| Backups | Point-in-time database recovery is kept for up to 30 days by our hosting provider |
8. Security
Data is encrypted in transit (TLS) and at rest by our hosting provider. Passwords are stored only as salted hashes. Course content is in private storage and is served only through signed links that expire and are bound to a specific licence, which is re-checked on every page load. Access to the portal is role-based and tenant-scoped; public endpoints are rate limited; secrets are held in the hosting provider’s secret store. We describe our measures in more detail in the DPA. No system is perfectly secure; if we become aware of a personal-data breach that affects you, we will tell you and, where required, the ICO.
9. Your rights
Under UK (and EU) data-protection law you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to how we use it; and provide it in a portable format. Where we rely on legitimate interests you can object, and where we rely on consent you can withdraw it at any time. Email support@scormbridge.app; we normally respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk) — we would appreciate the chance to address your concern first.
If you are a learner, the organisation that operates your LMS is the controller for your learning records; please contact them, and we will help them respond.
11. Children
The portal is for business use and not directed at children. Courses may be delivered to learners of any age by a client organisation; in that case the organisation is responsible for the lawful basis and any parental consent, and we act only on its instructions.
12. Changes to this policy
We will post changes here and update the date at the top. For material changes affecting portal users we will also email account holders or show a notice in the portal. Continued use after the change takes effect means you accept the updated policy.