PROTRAININGS DATA PROTECTION ADDENDUM
This Data Protection Addendum (this "Addendum") describes how ProTrainings, LLC ("ProTrainings") handles personal data for its business customers. It applies to any agreement between ProTrainings and a business customer that incorporates it (each, the "Agreement"), including:
- the ProTrainings Products and Services Agreement published at www.protrainings.com/terms_and_conditions, as it applies to Subscribers that are organizations;
- any ProTrainings master services agreement; and
- the ProTrainings Master Reseller Agreement, where the parties have executed this Addendum.
This Addendum does not apply to individuals who purchase ProTrainings products or services for themselves, whose personal data is governed by the ProTrainings Privacy Policy, or to AED program management services, which are governed by the applicable AED Services Schedule.
"Customer" means the customer under the Agreement, including a reseller partner under the Master Reseller Agreement. Capitalized terms not defined in this Addendum have the meanings given in the Agreement.
If this Addendum conflicts with the Agreement or with the ProTrainings Privacy Policy as to Personal Data, this Addendum controls, except where an Order Form expressly states that it overrides a specific section of this Addendum.
1. DEFINITIONS
1.1 "Applicable Privacy Law" means all U.S. federal and state laws that apply to a party's processing of Personal Data under the Agreement, including the California Consumer Privacy Act, as amended (the "CCPA"), and other state consumer privacy laws, in each case to the extent they apply.
1.2 "Certification Records" means the following Personal Data for each Learner who achieves Completion: name; unique identifier; Course; Completion date; pass status; Certificate number and verification identifier; issue and expiration dates; the instructor or skill evaluator of record, where applicable; and professional license number and licensing body, where the Learner uses continuing education reporting.
1.3 "Customer Data" means all Personal Data other than Certification Records. Customer Data includes roster and enrollment data; email and mailing addresses; login credentials and profile data for accounts created for training under the Agreement; LMS and integration identifiers; progress data; detailed assessment responses; Course telemetry; and support communications about Learners.
1.4 "Customer Integration" means any learning management system, SCORM or LTI launcher, single sign-on connection, API, webhook, batch file transfer, or other technical integration through which Customer or its systems exchange data with the Platform.
1.5 "De-identified Data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, and that ProTrainings maintains in accordance with Section 7.
1.6 "Learner" means an individual who accesses a Course under the Agreement, including an Authorized User under the Products and Services Agreement or a master services agreement and a Learner under the Master Reseller Agreement.
1.7 "Personal Data" means information relating to an identified or identifiable Learner that ProTrainings receives from or on behalf of Customer, or generates, in providing the Services. Personal Data includes Learner Data under the Master Reseller Agreement.
1.8 "Security Incident" means a confirmed unauthorized access to, or acquisition, disclosure, alteration, or destruction of, Personal Data, or a confirmed compromise of credentials used to access the Platform or a Customer Integration. Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as pings, port scans, blocked login attempts, or denial-of-service attacks.
1.9 "Services" means the Courses, the Platform, Certificates, Certificate verification, and related services ProTrainings provides under the Agreement.
1.10 "Student Data" means Personal Data about K-12 students that a K-12 school, school district, or other educational agency provides, or causes to be provided, in its educational capacity.
1.11 "Subprocessor" means a third party that ProTrainings engages to process Personal Data on its behalf. A vendor that does not process Personal Data is not a Subprocessor.
2. SCOPE AND ROLES
2.1 Personal Data Processed. ProTrainings processes the following categories of Personal Data under the Agreement:
| Category |
Examples |
When collected |
| Identity |
First and last name, unique identifier |
All Learners |
| Contact |
Email address, mailing address |
Learners with Platform accounts. Not collected through the Reseller Program. |
| Account |
Login credentials |
Learners with Platform accounts |
| Training |
Enrollment, progress, assessment results and responses, Completions, Course telemetry |
All Learners |
| Certification |
Certification Records |
Learners who achieve Completion |
| Professional license |
License number and licensing body |
Only where continuing education reporting is used |
Through the Reseller Program, ProTrainings receives only a unique identifier and first and last name for each Learner, together with training data generated on the Platform.
2.2 Customer Data. For Customer Data, ProTrainings is Customer's service provider or processor under Applicable Privacy Law and processes Customer Data on Customer's behalf under Section 3. Customer is the business or controller.
2.3 Certification Records. ProTrainings issues Certificates in its own name, operates public Certificate verification, and stands behind each Certificate during and after its validity period. For Certification Records, ProTrainings is an independent business or controller under Applicable Privacy Law and determines its own purposes under Section 4. Certification Records are not Customer Data.
2.4 Direct Relationships. Payment information that a Learner provides to ProTrainings for a Student Paid purchase, and Personal Data about individuals who obtain ProTrainings products or services outside the Agreement, are handled by ProTrainings as an independent business under its Privacy Policy and are outside this Addendum.
2.5 Prohibited Data. Customer shall not provide, and shall configure its systems not to transmit, any of the following: protected health information; Social Security numbers or other government-issued identifiers, other than a professional license number for continuing education reporting; financial account or payment card information; health or medical information; or any other Personal Data not required for the Services. Reseller Program partners are also bound by the contact data restriction in the Master Reseller Agreement. ProTrainings has no obligation under this Addendum for data provided in breach of this Section.
2.6 Minors. If Customer enrolls Learners under the age of 18, Customer is responsible for providing all notices and obtaining all consents required by law before those Learners access the Services. Customer shall not enroll any Learner under the age of 13 without ProTrainings' prior written approval.
2.7 Student Data. This Addendum does not cover Student Data. ProTrainings processes Student Data only under separate school-specific terms agreed in writing before any Student Data is provided, such as a school rider under the Master Reseller Agreement. Customer shall not provide Student Data without those terms in place.
3. CUSTOMER DATA
3.1 Instructions. ProTrainings processes Customer Data only to provide the Services and as described in the Agreement and this Addendum, which together are Customer's complete instructions. Additional instructions require the parties' written agreement. ProTrainings will notify Customer if it believes an instruction violates Applicable Privacy Law.
3.2 Permitted Purposes. ProTrainings may process Customer Data to:
- deliver Courses and administer assessments;
- issue Certificates, which creates Certification Records under Section 4;
- provide support to Customer and Learners;
- send Learners Service communications under Section 3.4;
- protect the security and integrity of the Platform and its assessments, including detecting fraud and cheating;
- maintain and improve Course quality, including psychometric analysis of assessment items;
- comply with law; and
- create De-identified Data under Section 7.
ProTrainings does not use Learner names or contact information for the purposes in clause (f) or for analysis of Course telemetry under clause (e). This does not limit ProTrainings' use of Certification Records under Section 4.1(d).
3.3 Service Provider Commitments. ProTrainings shall not:
- sell or share Customer Data, as those terms are defined in the CCPA;
- retain, use, or disclose Customer Data for any purpose other than the purposes in Section 3.2, including for any commercial purpose other than providing the Services, or outside the direct business relationship between ProTrainings and Customer; or
- combine Customer Data with Personal Data it receives from or on behalf of another person, or collects from its own interactions with an individual, except as permitted by Applicable Privacy Law.
ProTrainings shall comply with its obligations under Applicable Privacy Law, provide the level of privacy protection that Applicable Privacy Law requires, and notify Customer if it determines it can no longer meet its obligations. Customer may then take reasonable and appropriate steps to stop and remediate unauthorized processing of Customer Data. ProTrainings certifies that it understands and will comply with the restrictions in this Section 3.3.
3.4 Learner Communications. As part of the Services, ProTrainings sends Learners who have an email address on file account and enrollment messages, Course refresher emails, and Certificate expiration and renewal reminders. Each message that is not strictly transactional includes an unsubscribe link. On Customer's written request, ProTrainings will suppress refresher and renewal messages for Customer's Learners. ProTrainings does not use Customer Data to market products or services unrelated to the Services. Because ProTrainings does not collect Learner contact information through the Reseller Program, this Section 3.4 does not apply to Reseller Program Learners.
3.5 Personnel. ProTrainings limits access to Customer Data to personnel and Subprocessors who need it to perform the Services and who are bound by confidentiality obligations.
3.6 Assistance. ProTrainings will provide the information about the Services reasonably available to it that Customer needs to respond to individual requests, complete data protection assessments required by Applicable Privacy Law, and meet its security and breach notification obligations. ProTrainings may meet this obligation through its standard documentation, including the materials described in Section 11.1.
4. CERTIFICATION RECORDS
4.1 Purposes. ProTrainings uses Certification Records to:
- issue, verify, reissue, and replace Certificates;
- send Certificate renewal reminders;
- submit continuing education reporting at the Learner's direction;
- protect the integrity of its certification program, including investigating fraud;
- respond to inquiries from employers, regulators, approving and accrediting bodies, and licensing boards;
- establish, exercise, or defend legal claims; and
- comply with law.
4.2 Public Verification. ProTrainings operates public verification of Certificates. A verification result is limited to the information needed to confirm a Certificate, such as the Learner's name, the Course, the issue and renewal dates, and the Certificate's status.
4.3 Retention. ProTrainings retains Certification Records for at least ten (10) years after the applicable Certificate expires. ProTrainings currently has no routine deletion schedule for Certification Records and may retain them longer. ProTrainings may adopt a deletion schedule in the future, subject to that minimum and applicable law. Where an Agreement refers to training records associated with a Certificate, that term means Certification Records. Termination or expiration of the Agreement does not affect Certification Records.
4.4 Customer Access. During the Agreement and afterward, for as long as ProTrainings retains the records, Customer may obtain Certificate verification and copies of its Learners' Certificates at no charge.
4.5 Use Limits. ProTrainings does not sell or share (as those terms are defined in the CCPA) Certification Records created under the Agreement, and does not use them to market products or services unrelated to the Services. ProTrainings discloses Certification Records only for the purposes in Section 4.1, to Subprocessors, and to a successor in a merger, acquisition, or sale of all or substantially all of ProTrainings' assets. Nothing in the Agreement or this Addendum restricts ProTrainings from dealing with an individual who independently obtains ProTrainings products or services.
4.6 Responsibility. ProTrainings is responsible for its own compliance with Applicable Privacy Law for Certification Records.
5. RETENTION AND END OF SERVICES
5.1 During the Agreement. ProTrainings retains Customer Data for as long as needed to provide the Services, subject to Section 6.
5.2 After the Agreement Ends. After the Agreement ends, ProTrainings may continue to retain Customer Data to support Certificate reissuance and recertification, support and compliance inquiries, and dispute resolution. ProTrainings currently has no routine deletion schedule for Customer Data. On Customer's written direction given after the Agreement ends, ProTrainings will delete or de-identify Customer Data, except to the extent retention is required by law or permitted under Section 5.5.
5.3 No Return. ProTrainings does not return Customer Data. Customer may export training records and Certificates at any time during the Agreement through the Platform administrator interface or a Customer Integration.
5.4 Backups. Personal Data that has been deleted or de-identified may remain in backup systems until those backups expire in the ordinary course. Personal Data in backups remains subject to this Addendum and is not restored for active use.
5.5 Legal Holds. ProTrainings may retain Personal Data beyond any period in this Addendum, and may decline or delay deletion under Section 5.2 or Section 6, where required by law or needed for a pending or reasonably anticipated claim, investigation, or legal proceeding, for as long as that need continues.
6. INDIVIDUAL REQUESTS AND DELETION
6.1 Requests Handled Under Applicable Law. ProTrainings handles requests to access, correct, or delete Personal Data in accordance with Applicable Privacy Law, within the time periods it requires.
6.2 Customer Data. For Customer Data, ProTrainings acts on Customer's verified written instructions, including instructions relaying a Learner's request, subject to the exceptions available to a service provider or processor under Applicable Privacy Law. If ProTrainings receives a request regarding Customer Data directly from an individual, ProTrainings will direct the individual to Customer or forward the request to Customer.
6.3 Certification Records. ProTrainings responds to requests regarding Certification Records as an independent business. ProTrainings may decline or limit deletion of Certification Records where retention is necessary to comply with a legal obligation, to establish, exercise, or defend legal claims, or to maintain the integrity of Certificate verification, or where another exception under Applicable Privacy Law applies. A request from Customer to delete Certification Records is handled on the same basis. Name corrections on Certificates follow ProTrainings' reissuance policy.
6.4 Effect of Deletion. Where ProTrainings deletes a Certificate or Certification Record, it can no longer be verified, reissued, or replaced, it no longer appears in Customer's administrator view, and copies Customer retrieved beforehand remain Customer's responsibility. ProTrainings cannot recall information already reported to a licensing board or continuing education registry. Deletion is subject to Sections 5.4 and 5.5.
6.5 Reseller Program Learners. ProTrainings holds only an identifier and a name for Reseller Program Learners and cannot verify their identity on its own. Partner shall relay requests from its Learners to ProTrainings, together with the Learner's unique identifier and Partner's confirmation that the request comes from the Learner. ProTrainings will handle relayed requests under this Section 6, and may refer a Reseller Program Learner who contacts it directly to Partner.
6.6 Verification. ProTrainings may take reasonable steps to verify the identity and authority of any person making a request before acting on it.
7. DE-IDENTIFIED AND AGGREGATED DATA
ProTrainings may create De-identified Data and aggregated data from Personal Data and use it for any lawful purpose, provided it does not identify Customer, any End Customer, or any individual. ProTrainings shall:
- take reasonable measures to ensure the data cannot be linked to an individual;
- publicly commit to maintain and use the data only in de-identified form and not to attempt to re-identify it, except to test its de-identification processes; and
- contractually require any recipient of the data to meet the same obligations.
De-identified Data is not Personal Data.
8. SUBPROCESSORS
8.1 Use of Subprocessors. Customer authorizes ProTrainings to use Subprocessors to provide the Services. ProTrainings will provide its current list of Subprocessors on written request to legal@protrainings.com.
8.2 Subprocessor Terms. Each Subprocessor is bound by written terms, which may be the Subprocessor's standard terms of service or data processing terms, that require it to protect Personal Data and use it only to provide services to ProTrainings. ProTrainings remains responsible for its Subprocessors' processing of Personal Data under this Addendum.
8.3 Changes. ProTrainings will give at least thirty (30) days' notice before a new Subprocessor begins processing Customer Data, by email to each Customer that has asked to receive change notices by writing to legal@protrainings.com. Where a change is urgently needed for security or service continuity, ProTrainings will give notice as soon as practicable.
8.4 Objection. Customer may object to a new Subprocessor on reasonable data protection grounds by written notice to legal@protrainings.com before it begins processing Customer Data. The parties will discuss the objection in good faith. If it is not resolved within thirty (30) days, Customer may stop using the affected Services, and fees and refunds are governed by the Agreement.
8.5 Location. ProTrainings hosts Personal Data in the United States.
9. SECURITY
9.1 ProTrainings Safeguards. ProTrainings maintains reasonable administrative, technical, and physical safeguards appropriate to the nature of the Personal Data and designed to protect it against unauthorized access, use, or disclosure. ProTrainings may change its safeguards over time but will not materially reduce the overall protection of Personal Data.
9.2 Customer Safeguards. Customer shall maintain reasonable safeguards for its own systems, including any Customer Integration, API credentials, and administrator accounts, and for all Personal Data it retrieves from the Platform. Customer shall promptly deactivate the credentials of personnel who no longer need access.
10. SECURITY INCIDENTS
10.1 Notice. Each party shall notify the other in writing within seventy-two (72) hours after becoming aware of a Security Incident, using the contact method in the Agreement. For Reseller Program partners, that is the method in the Support and Escalation Procedures. The notice will describe, to the extent then known, the nature of the Security Incident, the categories and approximate number of individuals affected, and the steps taken to contain it. The notifying party will provide updates as material information becomes available.
10.2 Cooperation. The parties shall cooperate reasonably in investigating and remediating a Security Incident and shall coordinate in good faith on any public statements.
10.3 Notifications to Individuals and Regulators.
- Customer Data. Customer is responsible for any notices to individuals, regulators, and others that Applicable Privacy Law requires for a Security Incident affecting Customer Data, including a Security Incident affecting ProTrainings' systems or its Subprocessors' systems. ProTrainings will provide the information about the Security Incident that Customer reasonably needs to give those notices. ProTrainings will not notify Customer's Learners directly about a Security Incident affecting Customer Data unless Customer asks it to in writing or the law requires ProTrainings to do so.
- Certification Records. ProTrainings is responsible for any notices that Applicable Privacy Law requires for a Security Incident affecting Certification Records.
- Costs. Each party bears its own costs of the notices it gives under this Section 10.3.
10.4 No Admission. Notice of a Security Incident is not an admission of fault or liability.
11. SECURITY REVIEWS
11.1 Information. Once every twelve (12) months, on Customer's written request, ProTrainings will provide a written summary of its security practices, which may be its standard completed security questionnaire, and will answer reasonable follow-up questions in writing. These materials satisfy any request for security information under the Agreement. ProTrainings is not required to complete Customer-specific questionnaires.
11.2 Audits. Customer may audit ProTrainings' compliance with this Addendum only (a) following a Security Incident affecting Customer's Personal Data, or (b) where a regulator with jurisdiction over Customer requires it. Audits are conducted by written questions and review of documents, with at least thirty (30) days' written notice, no more than once in any twelve (12) month period, at Customer's cost. On-site audits take place only where a regulator requires one. No audit includes access to other customers' data or to information subject to confidentiality obligations owed to third parties.
11.3 Confidentiality. All information ProTrainings provides under this Section 11 is ProTrainings' confidential information under the Agreement.
12. CUSTOMER RESPONSIBILITIES
12.1 General. Customer is responsible for:
- providing the notices and obtaining the permissions required by Applicable Privacy Law for Personal Data it or its systems provide to ProTrainings, including notice that ProTrainings issues Certificates in its own name, operates public verification, and retains Certification Records under Section 4;
- the accuracy of the names and identifiers it or its systems provide;
- the lawfulness of its instructions to ProTrainings, including its deletion instructions under Sections 5.2 and 6;
- Personal Data held in its own systems, including data it retrieves from the Platform;
- notices under Section 10.3(a); and
- complying with Sections 2.5 through 2.7.
12.2 Reseller Partners. A Reseller Program partner is responsible for its agreements with its End Customers, including any data protection terms its End Customers require, and for any notices to End Customers and Learners under Section 10.3(a). Partner has no authority to commit ProTrainings to any data protection terms other than this Addendum.
13. LIABILITY
All liability arising out of or relating to this Addendum is subject to, and counts toward, the exclusions and limitations of liability in the Agreement. This Addendum does not create a separate or additional limitation of liability.
14. CHANGES
14.1 Incorporated by Reference. Where an Agreement incorporates this Addendum by reference, ProTrainings may update it under that Agreement's terms for changes to incorporated documents.
14.2 Executed Copies. Where the parties have executed this Addendum, the executed version applies for the term of the Agreement and may be changed only by written agreement of the parties.
14.3 Versions. ProTrainings retains each version of this Addendum that has applied to Customer and will provide a copy on written request to legal@protrainings.com.
15. GENERAL
15.1 Term. This Addendum applies for as long as ProTrainings processes Personal Data under the Agreement, including after the Agreement ends.
15.2 No Third-Party Beneficiaries. This Addendum creates no rights for any third party, including Learners, except as Applicable Privacy Law requires.
Version 1.0 - Last updated September 25, 2026