Introduction and scope
Definitions
This section defines terms used throughout the privacy information related to Virelin's Digital Literacy and IT Security Awareness Courses. Definitions clarify what we mean by personal data, processing activities, the roles of data subjects and Virelin as a data controller, and the technical terms used to describe cookies and analytics.
- Personal data refers to any information that identifies or can reasonably identify an individual, such as name, email address, job title, organization, contact details, and training records. It includes data provided directly by learners as well as identifiers collected automatically during use of our training platform.
- Processing means any operation performed on personal data, whether automated or manual, including collection, storage, retrieval, consultation, use, disclosure, analysis, modification, deletion and destruction in the context of providing training and related services.
- User (or data subject) means any individual who registers for, participates in, or otherwise interacts with Virelin's online or classroom-based digital literacy and IT security awareness courses, including employees of client organisations and individual learners.
- Service refers to Virelin's instructional offerings delivered online or in-person, course materials, assessment tools, user accounts, progress tracking, certificates, administrative communication, and any associated support or billing functions.
- Cookies are small text files placed on a user's device by the website or its service providers to enable platform functions, remember preferences, measure usage, and support analytics. Cookies may be session-based or persistent and include first-party and third-party cookies.
Data collection
Virelin collects information necessary to deliver training, manage accounts, process payments, maintain security, and improve course content. We limit collection to data relevant to these purposes and apply technical and organisational measures to protect it.
Types of data collected
Data provided directly by users
When registering or engaging with courses, users may provide personal and professional information required to create accounts, enroll in courses, and issue completion records.
- Full name and contact details (email address, phone number).
- Organisational affiliation, job title, department and work role where applicable.
- Account credentials and authentication data used to access the learning platform.
- Training enrolment choices, course progress, assessment results and certification records.
- Billing and payment details when paid services are used (kept only as needed for invoicing and compliance).
- Support communications and any feedback or survey responses provided by the user.
Automatically collected data
The platform collects technical and usage information automatically to maintain service operation, monitor security, and understand how users interact with course materials.
- Device and browser information (device type, operating system, browser version).
- IP address and approximate location derived from IP for security and fraud prevention.
- Usage data such as pages viewed, time spent on lessons, clicks, and interactions within the learning environment.
- Log files and diagnostic data related to errors, system performance and security events.
- Cookie identifiers and similar tracking vouchers used for session management and analytics.
- Aggregate or anonymised metrics used for service improvement and reporting.
Data shared by third parties
Virelin may receive personal data from client organisations or trusted partners to enable group enrolment, single sign-on or integration with corporate learning management systems.
- Client HR or training administrators may supply participant lists and role details for group enrolment.
- Identity provider information used for single sign-on (SSO) and authentication where enabled.
- Payment gateway providers supplying confirmation of processing for invoiced services.
How we use personal data
Purposes of processing
Virelin processes personal data to deliver training services, administer accounts, protect the platform, and meet legal and contractual obligations. Processing is limited to specified, explicit and legitimate purposes.
- Provision and administration of courses, user accounts, progress tracking and certification issuance.
- Communication with learners about course logistics, updates, technical support and important notices.
- Billing, invoicing and payment reconciliation for paid training services.
- Security monitoring, fraud detection, access control and incident response.
- Improvement of course content and platform features through aggregated analytics and user feedback.
- Compliance with legal obligations, requests from authorities, and internal audit processes.
- Facilitating integration with client systems such as LMS or identity providers where explicitly requested.
- Statistical reporting to client organisations about participation and learning outcomes, provided in aggregated or pseudonymised form where possible.
Legal bases for processing
Processing activities rely on lawful bases appropriate to the purpose and jurisdiction, including consent where required, contract performance, legitimate interests, and legal obligations.
- Contractual necessity to provide training and fulfil the terms of a paid or funded enrolment.
- Consent, where users have given clear permission for specific processing such as marketing communications.
- Legitimate interests for security, fraud prevention, service improvement and platform administration, balanced against user rights.
- Legal obligation to retain or disclose information to comply with statutory requirements or lawful requests from public authorities.
Cookies and similar technologies
Virelin uses cookies and similar technologies to operate the learning platform, remember preferences, secure user sessions and gather analytics. Users can manage cookie preferences via their browser or the cookie settings provided on the site.
We employ session cookies for authentication and navigation, persistent cookies for user preferences and settings, and third-party cookies for analytics and optional embedded content.
Cookie categories include essential (required for service delivery), functional (preferences), performance (analytics) and marketing (third-party tracking for optional features). Essential cookies are necessary for access to core course functionality.
Users may control cookie settings through their browser or decline non-essential cookies where technically feasible. Disabling certain cookies can affect platform functionality or the ability to track course progress.
For detailed cookie settings and a full list of cookies, see the cookie policy available on ylorin.pro.
Data sharing and recipients
Virelin shares personal data only with parties required to provide or support the training service, subject to appropriate contractual and technical safeguards.
- Service providers and vendors who host or maintain the learning platform (cloud providers, hosting, backup and security services).
- Analytics and performance measurement providers used to understand platform usage and improve content.
- Payment processors and invoicing partners for payment handling and reconciliation.
- Client organisations (employers or training sponsors) where they have enrolled participants or requested reporting.
- Legal and regulatory authorities when required by law, court order or to protect the rights, property or safety of others.
- Affiliates or business partners in relation to merger, acquisition or corporate restructuring with appropriate confidentiality safeguards.
International data transfers
Some processing and storage may occur outside Singapore where service providers operate. Transfers are managed in line with applicable law and only where appropriate safeguards are in place.
Virelin implements safeguards such as standard contractual clauses, data processing agreements, adequacy assessments and technical protections (encryption) to mitigate risks when transferring data across borders.
Storage and retention
Retention policy
Virelin retains personal data only for as long as necessary to fulfil the purposes described, to meet contractual and legal obligations, and to resolve disputes or enforce agreements. Retention periods are reviewed periodically.
Account information and course records are retained for the duration of the active account and for a defined period thereafter to support certification verification and contractual reporting, unless a longer retention period is required by law.
Support communications and correspondence are retained as needed to resolve support issues, to maintain a record of service requests, and for compliance purposes, with retention periods proportionate to the purpose.
System logs related to security events and platform performance are retained for a limited period to enable incident contribute and to maintain platform reliability.
When data is no longer required, Virelin will securely delete or anonymise it. Users may request deletion of personal data subject to applicable legal and contractual constraints.
Security measures
Virelin applies administrative, technical and physical measures to protect personal data against unauthorised access, disclosure, alteration and destruction. Security practices are periodically reviewed and updated in response to changing risks.
- Encryption of data in transit (TLS) and encryption at rest for sensitive stored information where appropriate.
- Access control policies, role-based permissions, and multi-factor authentication for administrative access.
- Regular security monitoring, vulnerability management, incident response procedures and staff training on data protection.
Rights of data subjects
Your rights
Depending on your jurisdiction and the nature of the processing, you may have rights in relation to your personal data. Virelin provides mechanisms to exercise these rights in a timely manner.
- Right of access: request confirmation of processing and a copy of personal data processed by Virelin.
- Right to rectification: request correction of inaccurate or incomplete personal data.
- Right to erasure: request deletion of personal data where retention is no longer necessary and legal constraints do not apply.
- Right to restriction of processing: request limitation of processing in specific circumstances.
- Right to object: object to processing based on legitimate interests or direct marketing where applicable.
- Right to data portability: receive personal data in a structured, commonly used and machine-readable format where processing is based on consent or contract.
- Right to withdraw consent: withdraw consent to processing where consent is the lawful basis, without affecting prior lawful processing.
- Right to lodge a complaint with a supervisory authority if you consider your data protection rights have been infringed.
How to make rights requests
To exercise your rights, contact Virelin using the contact details provided on ylorin.pro or the address at 710A Ang Mo Kio Avenue 8, Singapore 561710. Include sufficient information to identify yourself and specify the request. Business ID: S2680178A.
[email protected]
Virelin will acknowledge and respond to valid requests within a reasonable timeframe in line with applicable law, typically within 30 calendar days of receiving a complete request, subject to extensions where permitted.
Data protection and regulatory compliance
Where applicable, Virelin complies with relevant data protection regulations, including provisions that apply to data subjects in the European Economic Area. We implement measures to uphold data subject rights and apply appropriate legal bases for processing.
- Virelin acts as data controller for the personal data collected in the provision of training services and is responsible for processing in accordance with applicable law.
- When processing is based on consent, users are informed of the purpose and can withdraw consent at any time without affecting prior lawful processing.
- Virelin uses contracts, technical measures and documented procedures to protect personal data and to govern any transfers outside the EEA where applicable.
- Data subjects may exercise their rights by contacting Virelin; they may also seek assistance from a supervisory authority within their member state if they believe their rights have not been respected.
- Right to data portability: You may request a machine-readable copy of personal data you provided to Virelin for the purpose of portability to another service where technically feasible.
- Right to lodge a complaint: If you consider that Virelin has not handled your personal data in line with applicable law, you may lodge a complaint with the relevant supervisory authority in Singapore.
Supervisory authority: In Singapore, concerns about personal data handling can be directed to the Personal Data Protection Commission (PDPC). Virelin will cooperate with any supervisory authority contribute to the extent required by applicable law.
Other purposes and legal bases
Marketing communications
Virelin may use contact details to send course updates, administrative notices and offers related to digital literacy and IT security awareness. Marketing communications will be based on your consent or other lawful basis where applicable. You may receive occasional announcements about new course modules, schedule changes and relevant security advisories.
To stop marketing communications, update your preferences in your account settings or contact Virelin using the contact details below. Unsubscribe requests will be processed promptly and you may still receive transactional or safety-related messages.
Children and age-sensitive data
Virelin's services are designed for adult learners and professionals. We do not intentionally collect personal data from children under 16. If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete that data in accordance with applicable law and our policies.
Third-party links and integrations
Our platform may include links to third-party websites, tools or learning resources. These third parties operate under their own terms and privacy notices. Virelin is not responsible for third-party privacy practices or content and recommends reviewing their policies before sharing personal information.
Changes to this policy
Virelin may update this privacy information to reflect changes in our practices, services or legal requirements. Material changes will be posted on the site and the effective date updated. Please check this page periodically to stay informed.