SMS Training Academy
SMS Training Academy Powered by Sustainable Management System Inc. Powered by SMS Inc.
Home Courses eLearning Instructor-Led Calendar Reviews Blog Verify About Contact
Login Browse Courses
Home All Courses eLearning Instructor-Led Training Calendar Reviews Blog Verify Certificate About Us Contact Us
Login / My Account
Legal

Privacy Policy

Effective: June 2026 Sustainable Management System Inc., New York, USA

Contents

  • 1. Introduction
  • 2. Data Controller
  • 3. Data We Collect
  • 4. How We Use Your Data
  • 5. Legal Basis (GDPR)
  • 6. Data Sharing
  • 7. International Transfers
  • 8. Data Retention
  • 9. Security
  • 10. Cookies
  • 11. Your Rights
  • 12. Children's Privacy
  • 13. Changes to Policy
  • 14. Contact Us

This Privacy Policy explains how SMS Training Academy collects, uses, stores, and shares your personal information. We are committed to protecting your privacy and handling your data transparently and in compliance with applicable data protection laws.

1. Introduction

SMS Training Academy ("we", "us", "our") operates as the professional training division of Sustainable Management System Inc. ("SMS"), incorporated in New York, USA. This Privacy Policy governs the collection, processing, storage, and sharing of personal data in connection with your use of the SMS Training Academy website (smscert.com), learning management system, participant portal, and all associated services (collectively, the "Platform").

We respect your privacy and are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable regional data protection frameworks where required by law.

2. Data Controller

The data controller responsible for your personal information is:

Sustainable Management System Inc.

277 Cherry Street, Suite-12N, New York, NY, USA

info@smscert.com

For individuals in the European Economic Area or United Kingdom, SMS acts as the data controller and has implemented appropriate safeguards for international data transfers as described in Section 7.

3. Data We Collect

3.1 Account and Registration Data

When you create a Participant account, we collect: full name, email address, phone number (optional), country/region, organisation or employer name (optional), professional title, and any other information you provide in your profile.

3.2 Training and Learning Data

Through your use of the Platform and training programmes, we collect: courses enrolled, progress and completion records, assessment scores and attempt history, attendance records (for ILT and VILT), completion dates, certificate numbers and issuance records, and learning activity logs (time spent, pages accessed, videos viewed).

3.3 Payment and Transaction Data

When you make a payment, we collect transaction information including: the amount paid, currency, date and method of payment, invoice and receipt details, and transaction reference numbers. We do not store full payment card numbers on our servers. Card payment data is processed and stored securely by our payment processor, Stripe Inc. Bangladesh taka payments are processed by SSLCommerz Ltd.

3.4 Technical and Usage Data

We automatically collect certain technical data when you access the Platform, including: IP address, browser type and version, operating system, device type, pages visited, time and duration of visits, referral URLs, and session identifiers. This data is collected through server logs and analytics tools.

3.5 Communications Data

We retain records of communications you initiate with us via contact forms, email, or support channels, including the content of those communications, for the purposes of responding to enquiries and maintaining records.

3.6 Cookies and Tracking

We use cookies and similar tracking technologies as described in Section 10.

4. How We Use Your Personal Data

We use personal data collected through the Platform for the following purposes:

  • Account management: Creating and maintaining your Participant account, enabling login and access to Programme content.
  • Programme delivery: Providing access to enrolled courses, tracking progress, administering assessments, and issuing certificates.
  • Payment processing: Processing enrolment fees, issuing invoices, managing refunds, and maintaining financial records.
  • Communication: Sending enrolment confirmations, certificates, receipts, course updates, technical alerts, and responses to enquiries.
  • Service improvement: Analysing usage patterns to improve Platform functionality, content quality, and user experience.
  • Legal compliance: Meeting legal and regulatory obligations, including financial record-keeping, anti-fraud measures, and responding to lawful requests from authorities.
  • Marketing (with consent): Where you have opted in, sending information about new programmes, offers, and professional development resources. You may opt out at any time.

5. Legal Basis for Processing (GDPR)

For individuals subject to the GDPR or UK GDPR, we process personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide training services following enrolment, including account management, programme access, and certificate issuance.
  • Legitimate interests (Art. 6(1)(f)): Platform security, fraud prevention, service improvement, and alumni communications, where our interests are not overridden by your data protection rights.
  • Legal obligation (Art. 6(1)(c)): Maintaining financial records, responding to lawful authority requests, and meeting tax and regulatory reporting requirements.
  • Consent (Art. 6(1)(a)): Marketing communications and non-essential cookies, where your opt-in consent has been obtained.

6. Data Sharing

6.1 Within the SMS Group

Your personal data may be shared with other entities within the Sustainable Management System group — including Sustainable Management System Bangladesh and Sustainable Management System UAE — where necessary for operational purposes, programme delivery in your region, or regional compliance requirements. All group entities are bound by equivalent data protection standards.

6.2 Payment Processors

Stripe Inc. — For international card payments. Stripe is a PCI-DSS Level 1 compliant payment processor. Data shared with Stripe includes: name, email, billing address, and transaction details. Stripe's privacy practices are governed by Stripe's Privacy Policy.

SSLCommerz Ltd. — For Bangladesh taka payments. Data shared includes transaction details necessary to complete the payment. SSLCommerz is a regulated payment service provider in Bangladesh.

6.3 Service Providers

We engage trusted third-party service providers to assist in operating the Platform and delivering training, including: learning management system (LMS) infrastructure providers, video conferencing platforms (for VILT delivery), email and communication service providers, cloud hosting and storage providers, and analytics service providers. All service providers are contractually obligated to process personal data only on our instructions and to maintain appropriate security measures.

6.4 Authorised Training Partners

Where a Programme is delivered in partnership with an authorised franchise partner or regional training centre, relevant training and certificate data may be shared with that partner for the purposes of co-delivering or administering the Programme.

6.5 Legal and Regulatory Disclosure

We may disclose personal data to law enforcement, regulatory authorities, or courts where required by applicable law, or where necessary to protect the rights, safety, or property of SMS, Participants, or third parties.

6.6 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of SMS's business, personal data may be transferred to the successor entity as part of that transaction, subject to equivalent privacy protections.

We do not sell personal data to third parties for marketing purposes.

7. International Data Transfers

SMS Training Academy operates internationally. Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, Bangladesh, the UAE, and other countries where our service providers operate. Some of these countries may have data protection laws that differ from those in your jurisdiction.

Where personal data is transferred outside the European Economic Area or United Kingdom, we ensure appropriate safeguards are in place, including: Standard Contractual Clauses approved by the European Commission, adequacy decisions where applicable, and equivalent transfer mechanisms recognised under applicable law.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. Our general retention guidelines are:

  • Training records, certificates, and assessment data: 7 years from the date of completion, to support verification, re-issuance, and regulatory audit requirements.
  • Payment and financial records: 7 years from the date of transaction, in compliance with US federal and state tax retention requirements.
  • Account data (active participants): For the duration of your account plus 2 years after your last login or activity.
  • Communication records: 3 years from the date of last communication.
  • Marketing consent records: Until you withdraw consent, plus a reasonable period thereafter.

After the applicable retention period, personal data is securely deleted or anonymised.

9. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, loss, destruction, alteration, or disclosure. These measures include: encrypted data transmission (TLS/SSL), secure password hashing, role-based access controls, regular security reviews, and contractual data security obligations with service providers.

However, no method of data transmission or storage is entirely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. If you have reason to believe your account has been compromised, please contact us immediately.

10. Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the Platform. Categories of cookies used:

  • Essential cookies: Required for login sessions, security, and basic Platform functionality. Cannot be disabled without impacting Platform operation.
  • Performance cookies: Collect anonymised data on how visitors use the Platform, used to improve content and navigation. Enabled by default; may be opted out.
  • Analytics cookies: Used to understand usage patterns and measure the effectiveness of content and marketing campaigns (e.g., Google Analytics). Requires consent.
  • Marketing cookies: Used to deliver relevant advertisements and track campaign effectiveness. Requires consent.

You may manage cookie preferences through your browser settings or our cookie consent tool where available. Note that disabling certain cookies may affect Platform functionality.

11. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you and information on how it is processed.

Right of Rectification

Request correction of inaccurate or incomplete personal data held about you.

Right of Erasure

Request deletion of your personal data, subject to our legal obligations to retain certain records.

Right of Portability

Request a copy of data you provided to us in a commonly used, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Restriction

Request that we restrict processing of your data in certain circumstances.

To exercise any of these rights, please contact us at info@smscert.com or via our contact form. We will respond to verified requests within 30 days (or within the timeframe required by applicable law). We may request identity verification before processing your request.

If you are in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

Marketing opt-out: If you have opted in to marketing communications and wish to unsubscribe, you may click the unsubscribe link in any marketing email or contact us directly. Opting out of marketing does not affect transactional or service communications related to your account or enrolled programmes.

12. Children's Privacy

The Platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe that a child under 18 has provided personal data to us without appropriate parental consent, please contact us and we will take prompt steps to delete that information.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our data practices, services, or applicable law. We will notify registered Participants of material changes by email and/or by posting a notice on the Platform at least 14 days before changes take effect. The "Effective" date at the top of this Policy reflects the date of the most recent update.

14. Contact & Privacy Enquiries

For questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

Sustainable Management System Inc. — Privacy

277 Cherry Street, Suite-12N, New York, NY, USA

info@smscert.com

Contact Form

This Privacy Policy was last updated in June 2026. Previous versions are available upon written request.

SMS Training Academy
SMS Training Academy Powered by Sustainable Management System Inc.

Professional capacity building, compliance training, and internationally recognised certification programs for individuals and organisations worldwide.

Quick Links

  • All Courses
  • eLearning
  • Instructor-Led
  • Training Calendar
  • Reviews
  • Blog

Resources

  • About Us
  • Contact Us
  • Participant Login

Contact Us

training@smscert.com
info@smscert.com
277 Cherry Street, Suite-12N
New York, NY, USA
© 2026 SMS Training Academy. All rights reserved. Powered by Sustainable Management System Inc.
Privacy Policy Terms of Use Refund Policy Verify Certificate