1. Introduction
Marine Diagnostic Tools LLC ("MDT," "we," "our") operates the MDT Learning platform at www.mdtlearning.com. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our learning management system. This policy applies to all visitors and users of MDT Learning, regardless of location.
2. Information We Collect
Account Information
- Name and email address (provided during account creation or invitation)
- Hashed password (we never store passwords in plain text)
- Account role (learner or administrator)
Learning Data
- Course enrollment and completion records
- Quiz scores and assessment results
- SCORM/xAPI interaction data (time spent, progress, bookmarks)
- Certificates earned
- Learning path progress
Technical Data
- IP address (for security, rate limiting, and abuse prevention only)
- Browser type and version (via standard HTTP headers)
- Session tokens (HTTP-only cookies for authentication)
Data We Do NOT Collect
- We do not use tracking cookies, advertising pixels, or analytics services
- We do not collect payment card or financial data (payments are handled by third-party processors before reaching our platform)
- We do not collect biometric data
- We do not collect geolocation data beyond IP address
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions requiring a legal basis, we process your personal data under the following grounds:
- Contract performance: Processing necessary to provide the training services you or your employer enrolled you in (account management, course delivery, progress tracking, certificate generation).
- Legitimate interests: Security measures (rate limiting, IP logging, brute force protection) to protect the platform and its users from abuse.
- Legal obligation: Retaining records as required by applicable law.
We do not rely on consent as a legal basis for processing because we do not engage in marketing, advertising, or any processing beyond what is necessary to deliver training services and protect the platform.
4. How We Use Your Information
- Delivering and tracking course content and progress
- Generating completion certificates
- Providing learner dashboards and progress reports to administrators
- Sending transactional emails (account invitations, password resets)
- Protecting against unauthorized access, brute force attacks, and abuse
- Maintaining audit logs for security incident investigation
We do not use your information for marketing, advertising, profiling, or automated decision-making.
5. Data Sharing
We do not sell, rent, or trade your personal information. We do not share your data with data brokers. We may share data only in these limited cases:
- With your employer/organization: Administrators in your organization can view your course progress and completion status as part of the training program.
- Service providers: We use Resend (email delivery) and Railway (hosting) to operate the platform. These providers process data on our behalf under data processing agreements and do not use your data for their own purposes.
- Legal requirements: We may disclose information if required by law, subpoena, or court order, or to protect our legal rights and user safety.
6. Data Retention
We retain your data only as long as necessary:
- Account and learning data: Retained while your account is active or as required by your employer's training program.
- Security logs: Audit log entries are retained for 90 days, then automatically purged.
- Temporary tokens: Password reset and invitation tokens expire and are purged within 24 hours.
- Upon deletion: When you request account deletion, we remove your personal data within 30 days. Anonymized, aggregated statistics may be retained for platform improvement.
7. Data Security
We protect your data with industry-standard measures:
- Passwords hashed with bcrypt (cost factor 10)
- HTTPS encryption for all data in transit
- HTTP-only, Secure, SameSite=Strict cookies for sessions
- Rate limiting on authentication and sensitive endpoints
- Automatic IP banning after repeated failed login attempts (brute force protection)
- CSRF protection on all mutation endpoints
- Global request rate limiting for DDoS mitigation
- File upload restrictions (type whitelist, size limits)
- Input sanitization and output encoding to prevent injection attacks
8. Your Rights
All users, regardless of location, have the following rights:
- Access: Request a copy of all personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your account and all associated personal data.
- Data Portability: Download your learning data in a portable JSON format using the data export feature available from your dashboard.
GDPR Rights (EEA/UK Users)
If you are in the European Economic Area or United Kingdom, you additionally have the right to:
- Restrict processing: Request that we limit how we use your data.
- Object to processing: Object to processing based on our legitimate interests.
- Lodge a complaint: File a complaint with your local data protection authority (e.g., the ICO in the UK, CNIL in France, or your country's supervisory authority).
We do not transfer personal data outside the United States except as necessary to deliver email via our email service provider (Resend). We do not engage in cross-border data transfers that would require Standard Contractual Clauses or similar mechanisms.
CCPA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) and its amendment the CPRA provide you with specific rights:
- Right to Know: You may request that we disclose what personal information we have collected, used, disclosed, and sold about you in the preceding 12 months.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary because we never engage in these practices.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by the CCPA.
To exercise any of these rights, contact us at privacy@marinediagnostictools.com. We will verify your identity before processing your request and respond within 45 days as required by law. You may also use the data export feature on your dashboard.
Categories of personal information collected in the preceding 12 months: Identifiers (name, email), internet activity (IP address, browser type), and professional information (course progress, training records). We have not sold any personal information in the preceding 12 months.
9. Cookies
We use only essential cookies required for authentication and session management. Specifically:
- mdt_session: An HTTP-only, Secure session cookie containing your encrypted authentication token. This cookie is strictly necessary for the platform to function and cannot be disabled.
We do not use advertising, analytics, performance, or tracking cookies. No third-party cookies are set by our platform. Because we only use strictly necessary cookies, no cookie consent banner is required under GDPR, but we provide this disclosure for transparency.
10. Email Communications (CAN-SPAM Compliance)
We comply with the CAN-SPAM Act of 2003:
- We send only transactional emails (account invitations, password resets, and system notifications). We do not send marketing or promotional emails.
- All emails accurately identify the sender as Marine Diagnostic Tools LLC.
- All emails include our physical mailing address.
- We do not use deceptive subject lines or misleading header information.
- Because our emails are purely transactional (directly related to your account and the service you are using), they are exempt from CAN-SPAM's opt-out requirements. However, you may contact us at any time to inquire about email communications.
If we ever begin sending commercial or marketing emails in the future, we will update this policy, obtain any required consent, and provide a clear unsubscribe mechanism in every message.
11. Unsubscribe and Communication Preferences
All emails sent by MDT Learning are transactional and directly related to your account (password resets, account invitations). We do not operate a marketing email list. If you wish to stop receiving all communications from MDT Learning, you may request account deletion by contacting privacy@marinediagnostictools.com. After your account is deleted, you will receive no further emails from us.
12. Children's Privacy (COPPA)
Our platform is designed for professional marine industry training and is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will promptly delete that information. If you believe a child under 16 has provided us with personal data, please contact us at privacy@marinediagnostictools.com.
13. Do Not Track Signals
Our platform does not track users across third-party websites and does not respond to Do Not Track (DNT) signals because we do not engage in any form of cross-site tracking.
14. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the State of South Carolina, United States, without regard to its conflict of law provisions. Users in the EEA/UK retain all rights provided by GDPR regardless of governing law.
15. Changes to This Policy
We may update this policy from time to time. We will notify registered users of material changes via email and update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy. Previous versions are available upon request.
16. Contact & Data Protection Requests
For any privacy-related questions, data access requests, deletion requests, or complaints:
Marine Diagnostic Tools LLC
Richland County, South Carolina, United States
Email: privacy@marinediagnostictools.com
Website: www.marinediagnostictools.com
We aim to respond to all privacy requests within 30 days (or 45 days for CCPA requests as permitted by law). If you are unsatisfied with our response, EEA/UK users may lodge a complaint with their local supervisory authority.