Privacy Policy
Privacy Policy — IL Safety Academy
Last updated: June 2026
In brief
Data in the system is collected in order to deliver safety trainings, document participation, issue certificates and retain training evidence records for the employee and the employer. Data is not sold to third parties.
IL Safety Academy operates a digital platform for managing employee safety trainings. This privacy policy explains what data we collect, how we use it, and what your rights are as an employee or as a training administrator.
1. Who we are
IL Safety Academy is a digital platform for managing employee safety trainings, documenting training delivery, comprehension exams, digital signatures, completion certificates and training evidence records.
General enquiries: info@ilsafety.com
Privacy enquiries: privacy@ilsafety.com
When the platform is used by an organisation or employer to train its employees, the organisation or employer may act as the data controller in respect of its employees, and IL Safety Academy acts as the system provider and data processor for the purpose of delivering the service, retaining documentation, issuing certificates and presenting reports to those authorised by the organisation.
2. Data controller and data processor
In respect of trainings delivered for an organisation, the employer or the organisation that assigned the training is responsible for determining the purposes of data use, which employees are directed to the training, the categories of data required, the retention period and who is authorised to view reports.
IL Safety Academy processes the data solely to deliver the service, including running the training, saving progress, marking the exam, storing the signature, issuing the certificate, retaining the evidence record and presenting reports to those authorised by the organisation.
3. What data is collected
The following data may be collected in the course of using the platform:
- the employee's first and last name
- employee number or organisational identifier
- national ID only where the organisation has defined it as required for documentation purposes
- company / employer name
- role / job title
- email address, where required to send the certificate or manage the training
- phone number, where required for contact or verification
- comprehension exam results and score
- training status
- digital signature
- completion certificate as a PDF file
- start, pause and completion times
- the version of the training that was taken
- training evidence record
- basic browser and security data, such as User-Agent, IP address or technical logs, to the extent required for security, abuse prevention and documentation
4. Data minimisation and national ID
The system is designed to collect only the data required to deliver and document the training. The default employee identifier is an employee number or organisational identifier. A full national ID is retained only where the organisation has defined it as required for documentation, regulatory or internal-policy purposes. Wherever possible, administrators are shown a reduced or partially masked identifier, in line with the system settings.
5. Purposes of data use
The data is used for the following purposes only:
- delivering and managing the digital training
- issuing a completion certificate and retaining it for documentation purposes
- retaining training evidence in line with organisational and regulatory requirements
- sending the certificate to the employee's email address
- allowing an incomplete training to be resumed
- presenting reports to the training administrator
6. Retention of training records and certificates
The evidence record, delivery data and completion certificate are stored in the system's database for audit, safety-officer documentation and compliance with legal requirements. PDF certificates are stored in a secure cloud storage service and delivered to the employee and the training administrator.
7. Disclosure to the employer and training administrator
The platform operates in the service of the organisation / employer that assigned the training. An employee's training data — including score, completion date, signature and certificate — is accessible to the training administrator authorised by the organisation. The data is not transferred to third parties unrelated to delivering the training.
Where the training is delivered on behalf of an employer or organisation, the employer or training administrator is responsible for ensuring that employees were directed to the training under appropriate authorisation and that the employee details provided to the system are correct and up to date.
8. Permissions and access to data
Access to data in the system is limited to authorised persons only, according to their role and professional need. A company manager or authorised training administrator may view only data associated with their own organisation, such as training statuses, scores, signatures and certificates of employees assigned trainings on behalf of that organisation.
9. Use of external infrastructure providers and data transfer
The platform uses external infrastructure providers for operation, storage, security and sending email. User data may be stored or processed via providers such as:
- Supabase — database and file storage
- Vercel — hosting and deployment of the web application
- Resend — sending business email messages and certificates
- OpenAI — artificial-intelligence processing for administrative capabilities in the system, including understanding a document an authorised administrator has chosen to analyse
When an authorised administrator uses the system's artificial-intelligence capabilities, the content relevant to that action is sent to OpenAI for processing. For analysing a form to be signed, the page image and the text of the document the administrator uploaded are sent, solely in order to identify where the fields are. Employee records, identity numbers from the employee database, signatures, signed forms and assignment data are not sent as part of this.
Some infrastructure providers may process or store data outside Israel. Any such transfer is made solely for the purpose of delivering the service, and in accordance with applicable law, the providers' privacy policies, the applicable agreements and accepted security mechanisms.
10. Information security
The system applies protective mechanisms such as: transport encryption (HTTPS), access control over administrator data, and service keys that are not exposed on the client side. Access to data in the system is limited to authorised persons only, according to their role and professional need. That said, no security system is entirely complete, and we advise employees not to share their personal training link with others.
11. Data retention and deletion
Training data, certificates, signatures and evidence records are retained for the period required for training documentation, compliance with legal requirements, organisational requirements, handling claims, internal audit or the defence of legal rights.
At the end of the retention period, or upon an appropriate request from the organisation or the data subject and subject to retention obligations under law, the data will be deleted or anonymised to the extent technically, legally and operationally possible and reasonable.
12. Information security incident
In the event of a suspected information security incident that may affect personal data, IL Safety Academy will act to investigate the incident, reduce the risk, document its handling and issue notifications to the required parties, to the extent required by law or by the agreements with the organisation.
13. Employee rights: access, correction and enquiry
In accordance with the Protection of Privacy Law (Israel), every employee is entitled to:
- review the data retained about them
- request correction of incorrect data
- raise a question regarding the retention and use of their data
An enquiry may be submitted to the training administrator at the organisation, or directly to the IL Safety Academy contact address set out in section 14.
14. Privacy contact
For any question, request or enquiry regarding privacy, you may write to:
Estimated response time: up to 14 business days.
15. Updates to this privacy policy
This privacy policy may be updated from time to time in line with changes to the system or to legal requirements. The current version is always published on this page with the date it was last updated. Continued use of the platform after a change to the policy constitutes agreement to the updated terms.