Responsive image

 

General terms and conditions of use

 

By using the SpotLMS.com website (“Service”), you acknowledge and agree to the following terms and conditions (“Terms of Use”).

The Terms of Use, available in the client account creation form, must be read and accepted prior to creating a Client account in the SpotLMS service, and constitute the Agreement between Cyrus RH (“We”, “Provider” or “SpotLMS”), and “You” (the “Client”) ordering the “Services”. Cyrus RH refers to the company Cyrus RH SAS, a party to this Agreement, which is a company based in FRANCE and having its registered office at 21 rue Marc Donadille, 13013 Marseille, FRANCE, SIREN 447 803 354. “Services” refers to the learning management solution service accessible via the Internet and hosted by SpotLMS, made available to you on a SaaS basis from a website URL (“Portal”). An Authorized User means any employee, contractor, agent, or other individual of the Client authorized by the Client to access and use the Services, via subscriptions purchased or provided free of charge by the Client, for the purposes specified herein. The Client is responsible for ensuring that Authorized Users comply with this Agreement.

Cyrus RH reserves the right to update and modify the “Terms of Use” at any time without prior notice. Any new features that enhance or improve the current Service, including the release of new tools or resources, shall be subject to the Terms of Service. Continued use of the Service after such changes have been made available constitutes the user’s consent to such changes. You may review the most current version of the Terms of Service by visiting the “Terms of Use” page..

Failure to comply with any of the terms below will result in the termination of your account. Although SpotLMS prohibits such conduct and content on the Service, you understand and agree that SpotLMS cannot be held responsible for Content posted on the Service and that you may nevertheless be exposed to such information. You agree to use the Service at your own risk.

Account Terms

  1. You must be a human being. Accounts created by bots or other automated methods are not permitted.
  2. You must provide your real first and last name, a valid email address, and any other information required to complete the registration process.
  3. Your login may only be used by one person – a single login shared by multiple people is not permitted. You may create separate logins for as many individuals as your plan allows.
  4. You are responsible for maintaining the security of your account and password. Cyrus RH cannot and will not be liable for any loss or damage resulting from your failure to comply with this security obligation.
  5. You are responsible for all Content posted on the Service and for all activity that occurs under your account (even when the content is posted by others who have accounts under your account).
  6. An individual or legal entity may not maintain more than one free account.
  7. You may not use the Service for any illegal or unauthorized purpose. You must not, in the use of the Service, violate any laws of your jurisdiction (including but not limited to copyright laws).

Payments, Refunds, Plan Changes

  1. A valid credit card or PayPal account is required for payment. A credit card number or other payment method is not required for free accounts.
  2. The Service is billed in advance on a monthly or annual basis and is non-refundable. There will be no refunds or credits for partial months or years of service. To ensure equal treatment of all customers, no exceptions will be made.
  3. Prices do not include taxes, duties, or governmental charges; you are responsible for payment of any such taxes, duties, or fees.
  4. A credit card or PayPal account will be required for any change to your plan.
  5. Downgrading your Service may result in the loss of Content, features, or account capacity. Cyrus RH disclaims any liability for such loss.
  6. Upgrading from a paid plan to a more comprehensive plan may be done at any time. The cost of the new plan will be reduced by the unused portion of the current plan on a pro rata basis for the remaining time.
  7. Downgrading from a paid plan to a lower or free plan does not give rise to any refund. The change will take effect immediately if conditions allow. If the number of courses / users exceeds the limit authorized under the newly selected plan, the change cannot be completed until the account administrator removes sufficient courses / users to enable activation of the new plan.
  8. At the end of a paid plan that is not renewed, the account will be converted to a free plan. If conditions do not allow this (too many courses or users), the account will be blocked and the account administrator must contact a Cyrus RH representative by email to request unblocking.

Cancellation and Termination

  1. You are solely responsible for properly canceling your account. Requests by email or phone to cancel your account will not be considered a valid “cancellation”. A cancellation link is provided within the Service.
  2. If you cancel the Service before the end of your current paid period, your cancellation will take effect immediately. You permanently forfeit any right to a refund for the remaining period.
  3. Cyrus RH has the right to suspend or terminate your account and refuse any current or future use of the Service for any reason, at any time and without notice, including in the following cases: (a) fraud, hacking, criminal acts, gross negligence, willful or unintentional misconduct, violation of any law or regulation in connection with the performance of your obligations hereunder; and/or (b) demonstrated use that negatively impacts the performance of the Service; and/or (c) violation of these Terms of Service. Such termination will result in the deactivation or deletion of your account or access to your account, and the forfeiture and abandonment of all Content in your account.
  4. For paid subscriptions, SPOT LMS begins performance of the Service immediately upon validation of your order and, as such, you expressly waive your right of withdrawal in accordance with the provisions of Article L.221-28 1° of the French Consumer Code.

Service Modifications and Prices

  1. Prices for all Services, including but not limited to monthly or annual subscription fees, may be changed upon thirty (30) days’ notice from Cyrus RH. Such notice may be provided at any time by posting the pricing changes on the website.
  2. Cyrus RH shall not be liable to you or to any third party for any modification, price change, suspension, or discontinuance of the Service, subject to the provisions of Article 21.

Content and Personal Data

  1. You own all content (including personal data) that you and Authorized Users enter for the purpose of using the Services and you are solely responsible for the legality, reliability, integrity, accuracy, and quality of such content. SpotLMS may suspend or terminate use of the Services and this Agreement immediately upon receipt of notice alleging that You and/or an Authorized User has used the Services for purposes that violate any local, state, governmental, or foreign law, including but not limited to the posting of information that may infringe third-party rights, defame a third party, be obscene or pornographic, harass or abuse others, violate hacking or other criminal laws, etc. You hereby acknowledge and agree that performance of this Agreement requires us to process, transmit, and store Personal Data in accordance with the constraints described in the “Personal Data Protection Policy”, which forms an integral part of this Agreement.
  2. You further acknowledge and agree that We process data relating to Your users that are collected and used by Us, as well as connection data created through the use and operation of the Services, in order to administer or manage Our provision of the Services on Your account. Such data may include personal data and information regarding contractual commitments between Us and You, whether collected at initial registration or subsequently in connection with the provision, management, or administration of the Services, including billing and payment collection. You further acknowledge and agree that We also process Personal Data collected when You submit a support or troubleshooting request, including information about the Service, Your Portal, and other details related to the support incident, such as authentication information, Service status information, and error tracking files. We process such Personal Data in order to respond to the request and resolve the reported issue.
  3. We will process the above-mentioned Personal Data for the duration of our business relationship in compliance with legal obligations.
  4. You hereby acknowledge and agree that we will use your name and email address to communicate with you for purposes of providing the Service and promoting new services. You may unsubscribe from such electronic communications at any time, free of charge, by clicking the “unsubscribe” button included in the communication. You acknowledge that certain priority messages may not be subject to opt-out, such as alerts prior to account deletion, payment requests to avoid Service interruption, etc.

Cookies

  1. We use cookies to ensure persistence of Service login sessions. By continuing to browse the Service, you agree to the use of cookies. It is not possible to use the Service without cookies.

Copyright and Content Ownership

  1. We do not claim any intellectual property rights over the content you provide to the Service. Your profile and uploaded content remain yours.
  2. Cyrus RH does not pre-screen content, but Cyrus RH has the right (but not the obligation), at its sole discretion, to refuse or remove any content available through the Service.
  3. Content is considered inappropriate when uploaded, downloaded, shared, submitted, or used if it: a) infringes the intellectual property of SpotLMS or a third party; proprietary or other rights, including copyrights, trademarks, patents, trade secrets, intellectual property, publicity, or other proprietary rights; b) you do not have the right to use; c) is misleading, fraudulent, illegal, obscene, defamatory, threatening, harmful to minors, pornographic (including pedophilic content, which we will remove and report to law enforcement), indecent, harassing, hateful, encouraging illegal or criminal behavior, or otherwise inappropriate; d) attacks others based on race, ethnicity, national origin, religion, gender, sexual orientation, disability, or medical condition; e) contains viruses, bots, worms, scripts, exploits, cryptocurrency mining, or similar elements; f) is intended to be provocative; g) could otherwise cause harm to SpotLMS or a third party.
  4. The visual identity, appearance, and SPOT LMS logo of the Service are protected by copyright. You may not reproduce, copy, or reuse any part of the HTML/CSS code, JavaScript, or graphical elements without the express written authorization of Cyrus RH.

General Conditions

  1. Your use of the Service is at your sole risk. The Service is provided on an “as is” and “as available” basis.
  2. Technical support is provided only to paid account holders and is available exclusively via email or chat.
  3. You understand that Cyrus RH uses third parties, distributors, and vendors to provide the hardware, software, networking, storage, hosting, and related technologies required to operate the Service.
  4. You must not modify, adapt, or hack the Service or modify another website so as to falsely imply that it is associated with the Service.
  5. You agree not to misrepresent yourself or conceal the origin of any content (including through spoofing, phishing, header manipulation, or other identifiers), impersonate any other person, or falsely imply sponsorship or association with SpotLMS or any other third party.
  6. You agree not to reproduce, duplicate, copy, sell, resell, or exploit any portion of the Service, use of the Service, or access to the Service without the express written permission of Cyrus RH.
  7. You agree not to violate the privacy of others, including their private and confidential communications, without their express permission, and not to collect personal information about other users (including account names or usernames) from the SpotLMS Service.
  8. We may, but have no obligation to, remove content and accounts containing content that we determine in our sole discretion to be illegal, offensive, threatening, defamatory, pornographic, obscene, or otherwise objectionable, or that violates any intellectual property rights or any provision of these Terms of Service.
  9. We reserve the right to contact you from time to time by email. You may easily opt out of such communications.
  10. Any verbal, physical, written, or other abuse (including threats of violence) of any customer, employee, or member of Cyrus RH will result in immediate account termination.
  11. SpotLMS does not permit: (a) compromising the integrity of our systems, including probing, scanning, or testing the vulnerability of any system or network hosting our Services; (b) manipulating the Services or their data, reverse engineering or hacking our Services, unauthorized modification of Service data, bypassing security or authentication measures, or attempting to gain unauthorized access to related services, systems, networks, or data; (c) modifying, disabling, or compromising the integrity or performance of the Services, systems, networks, or data; (d) decrypting or tampering with transmissions to or from servers used to operate the Services; (e) overloading or attempting to overload our infrastructure by creating an unreasonable burden on our systems and resources (CPU, memory, disk space, bandwidth, etc.).
  12. You must not upload, post, host, or transmit unsolicited emails, SMS messages, or “spam”.
  13. You must not transmit any computer viruses or malicious code.
  14. You must not use meta tags or any other “hidden text” including the names or trademarks of SpotLMS or its suppliers.
  15. You must not access SpotLMS services, tools, features, data, etc. by any means other than through our Web interface or the standard Service API.
  16. Cyrus RH does not warrant that (i) the Service will meet your specific requirements; (ii) the Service will be uninterrupted, timely, secure, or error-free; (iii) the results obtained from use of the Service will be accurate or reliable; (iv) the quality of any products, services, information, or other material purchased or obtained through the Service will meet your expectations; and (v) any errors in the Service will be corrected.
  17. You expressly understand and agree that Cyrus RH shall not be liable for any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to damages for loss of profits, goodwill, use, data, or other intangible losses resulting from: (i) the use or inability to use the Service (except as provided in Article 21.3); (ii) the cost of procurement of substitute goods and services resulting from any goods, data, information, or services purchased or obtained through the Service; (iii) unauthorized access to or alteration of your transmissions or data; (iv) statements or conduct of any third party on the Service; or (v) any other matter relating to the Service.
  18. The failure of Cyrus RH to exercise or enforce any right or provision of the Terms of Service shall not constitute a waiver of such right or provision. The Terms of Service constitute the entire agreement between you and Cyrus RH and govern your use of the Service, superseding any prior agreements between you and Cyrus RH (including, but not limited to, any prior versions of the Terms of Service).
  19. SpotLMS (in its sole discretion) determines that a user has violated these Terms of Use.
  20. Questions regarding the Terms of Service should be sent to: contact at spotLMS dot com
  21. Availability, Service Continuity, and Limitation of Liability:
    -1. Nature of the commitment: The Provider endeavors to ensure Service availability 24/7. However, the Client acknowledges that the Service is provided via the Internet and depends on third-party physical infrastructures (data centers, electrical and telecommunications networks).
    -2. Exclusions of liability: Cyrus RH shall not be held liable, and no compensation shall be due, in the event of unavailability resulting from:
    * Failure of hardware infrastructure and physical servers not directly managed by Cyrus RH;
    * Malicious intrusion, cyberattack, virus, or act of cyber-malicious activity (“hacking”) originating from third parties, despite the implementation of security measures in line with industry standards;
    * Interruption caused by Internet service providers or telecommunications networks;
    * Force majeure as defined by Article 1218 of the French Civil Code and the case law of French courts.
    -3. Compensation threshold: By exception, if total and continuous unavailability of the Service, exclusively attributable to a technical failure under the direct control of Cyrus RH, exceeds four (4) consecutive calendar days, the Client may request commercial compensation. Such compensation shall be strictly limited, at the discretion of Cyrus RH, either to an extension of the subscription proportionate to the duration of the unavailability, or to a credit applied to the next invoice, to the exclusion of any damages for commercial loss or data loss.

Online Storage Space and SpotDrive

The online storage space is intended for all data related to your Spot LMS account, including course resources, user data, dedicated videos, virtual class recordings, shared documents, as well as files uploaded and organized via SpotDrive.

Storage capacity: The available volume depends on the subscribed commercial plan. By way of indication, for shared hosting (excluding dedicated servers), allocation is as follows:

  • 100 GB: chats and shared documents (chat server),
  • Depending on the plan: dedicated videos (streaming server),
  • 100 GB: virtual class recordings,
  • 100 GB: video conferences,
  • 100 GB: course resources, user data, and SpotDrive documents.
  • Rights and access: SpotDrive allows you to upload, organize, and share training documents, with fine-grained permission management by user profile.
  • Quota overrun: When the allocated quota is reached, the addition of new content may be restricted or suspended until space is freed or additional capacity is subscribed.
  • Liability: The Client remains solely responsible for the legality, compliance, and relevance of stored and shared documents. Cyrus RH disclaims all liability in the event of data loss, unauthorized access, or misuse of documents.
  • Scalability: Cyrus RH reserves the right to adapt, limit, or suspend SpotDrive or any other storage service for technical, security, or legal compliance reasons, without compensation to the Client.

For plans on dedicated servers, storage capacity is tailored to your needs by sizing servers according to your resources.

Virtual Class Volume

Virtual classes enable the organization of synchronous training sessions with a group of learners, simulating an in-person classroom environment. The number of virtual classes is limited per month depending on the subscribed commercial plan. Reset occurs at the beginning of each calendar month. Virtual classes are highly resource-intensive in terms of CPU and bandwidth. Excessive use of virtual classes by a single client on a shared server would prevent other clients from using the Service, thereby causing harm. To avoid this situation, the number of simultaneous virtual classes is limited. The limitation depends on the subscribed commercial plan. Example: if the plan limits concurrent virtual classes to 2, it will not be possible to launch a third virtual class if 2 virtual classes are already in progress. We recommend properly closing a virtual class to free up a slot and allow another class to be launched; otherwise, a virtual class will automatically close 6 hours after it is launched. If your needs exceed the limits of existing commercial plans, you may request a customized plan suitable for intensive use, including the deployment of a dedicated virtual class server.

Limitation on the Number of REST API Transactions

The SPOT LMS course server is used by many users. We impose limits on API requests to protect the system from receiving more data than it can handle and to ensure fair distribution of resources among users.
Limits depend on server characteristics, its load as determined by the number of users on the server and their activities, etc.
The limit is defined by the maximum number of API transactions possible during the last 10 seconds. It is specific to each server and is returned during a Token-type API call.
If you need to perform more API requests than the imposed limit, you must use a more powerful server under an appropriate commercial plan.

Use of Artificial Intelligence (AI) Services

Under certain commercial plans, Spot LMS provides features based on Artificial Intelligence, including but not limited to the generation of course modules, advanced progress reports with archiving and availability to learners, as well as the automatic creation of multiple-choice questionnaires (MCQs) and question-and-answer content.

  • Monthly quota: Use of these features is strictly limited to a monthly request volume, varying according to the subscribed commercial plan. Exceeding the quota results in temporary suspension of such features until reset at the beginning of the calendar month, unless additional capacity is subscribed.
  • Client responsibility: AI-generated content and reports are produced automatically and provided as assistance tools only. It is the Client’s sole responsibility to verify their accuracy, relevance, and compliance prior to any educational use or distribution to learners.
  • No warranty: Cyrus RH does not warrant the reliability, completeness, or suitability of AI-generated content for the Client’s pedagogical or legal objectives. Use of such content is at the Client’s own risk.
  • Limitation of liability: Cyrus RH shall under no circumstances be held liable, in any capacity, for any direct or indirect consequences resulting from the use of AI features, including but not limited to errors, omissions, regulatory non-compliance, infringement of third-party rights, or any material, immaterial, commercial, or reputational damage.
  • Compliant use: The Client undertakes to use AI features in compliance with applicable laws and regulations, intellectual property rights, and legitimate educational practices. Any abusive, improper, or non-compliant use may result in suspension or termination of the account.
  • Scalability: Cyrus RH reserves the right to modify, limit, or discontinue all or part of AI features at any time, in particular for legal compliance, security, or technical performance reasons, without giving rise to any compensation to the Client.
Date of last update: 12/30/2025

 

Privacy Policy

 

Introduction

SPOT LMS is committed to a continuous process of compliance with the General Data Protection Regulation of 27 April 2016. With this new regulation SPOT LMS reinforces its policy of personal data protection so that the data of our customers is protected. users are collected and used in a transparent, confidential and secure manner.

Personal data protection policy from 25 May 2018

Our Personal Data Protection Policy describes the how SPOT LMS processes the personal data of visitors and users (hereinafter referred to as "SPOT LMS"). after the "Users") when browsing our site www.spotlms.com (hereinafter the "Site"). The Personal Data Protection Policy is an integral part of the General Conditions of Use of the Site.

SPOT LMS pays constant attention to our Users' data. We can thus be to modify, supplement or update the Privacy Policy. We're here to help We invite you to regularly consult the latest version in force, accessible on our Site. If any major changes are made, we will inform you by email or by our services for you allow these amendments to be reviewed before they take effect. If you continue to use our Services Following Publication or Notification of Changes to the protection of personal data, this means that you accept updates.

What personal data is collected and for what purposes?

When you use our platform and/or during your registration, we collect and process personal data concerning you such as:  your surnames and forenames.

We will also ask you to send us your email address in order to use this data for the creation of an account, sending emails for information and notifications, as well as for the newsletter.

We also collect your nickname, avatar, mailing address, sex, phone number, email address, phone number, e-mail address, and email address. IP address, and some information available on your social networks. We will also ask you to send us a mini biography, or a biography, on an optional basis.

SPOT LMS uses Learning Analytics methods to analyze the courses taken, the quizzes and controls, routes, etc... We use this data for the analysis and the display. This data is used for various purposes, including gathering your experience user and track your progress, set up a follow-up and statistics according to your motivation.

When you register on the platform, you can register thanks to the form of creation of account and/or user.

As part of satisfaction surveys, we can use a satisfaction measurement tool for clients (Net Promoter Score). You will be asked via this tool to write an opinion on the use of the service SPOT LMS.

Why do we use cookies?

Definition of "cookie" and its utilization. A "cookie" is a text file that is placed on your computer at the time of the visit our platform. In your computer, cookies are managed by your internet browser.

We use cookies on our Site for the purposes of your browsing, optimization and marketing. personalization of our Services on our platform by memorizing your preferences. Cookies us also show how our platform is used. We automatically collect your IP address and information relating to the use of our Site. Our platform can thus be remember your identity when a connection has been established between the server and the web browser. The information previously provided in a web form can thus be kept.

Different types of cookies are used on our Site:

  • Cookies that are strictly necessary for the operation of our platform. They allow you to to use the main features of our platform (for example access to your account). Without these cookies, you will not be able to use our platform normally.
  • Analytical" cookies: in order to improve our services, we use cookies from audience measurements such as the number of pages viewed, the number of visits, the activity of Users and their return frequency, notably thanks to Google Analytics services. These cookies allow only the establishment of statistical studies on the traffic of Users on our platform, the results of which are completely anonymous to allow us to know the use and the performance of our platform and improve its operation. Accepting these cookies is a necessary condition for the use of our platform. If you refuse them, we can't give you guarantee normal use on our platform.
  • Functional Cookies: These are cookies that allow us to personalize your experience on our platform by memorizing your preferences. These cookies may be placed by a third party party on our behalf, but it is not authorized to use them for purposes other than those described.

Types of cookies used. The following types of cookies are used on this Site:

  • Temporary" Cookies: This type of cookie is active in your browser until you leave our platform and expire if you do not access the Site for a certain period of time.
  • Permanent" or "tracking" cookies: this type of cookie remains in your browser's cookie file. browser for a longer period, depending on your web browser settings. The Permanent cookies are also called tracker cookies.

Use of third-party cookies. We may use third party partners, such as Google Analytics, to track visitor activity on our platform or to identify your interests on our platform and customize the offer that is addressed to you on our platform or outside our platform. Information that may thus be collected by third party advertisers may include data such as geo-location data or contact information, such as e-mail addresses. The privacy policies of these third party advertisers provide privacy protection to advertisers. additional information on how cookies are used.

We ensure that partner companies agree to process the information collected on our website. platform exclusively for our needs and in accordance with our instructions, in compliance with the European regulations and undertake to implement appropriate safety and security measures. data privacy protection.

Disabling cookies. You can deactivate cookies at any time by selecting ` the appropriate settings in your browser to disable cookies (the section of the browser used specifies the procedure to follow).

We draw your attention to the fact that disabling cookies can reduce or prevent accessibility to all or part of certain functions.

With regard to promotional emails: You may withdraw your consent at any time by (i) unchecking the relevant box in your account, (ii) clicking the unsubscribe link provided in each of our communications or (iii) by contacting us.

With regard to targeted advertising on third-party sites (only for free accounts): you can refer to our Policy about Cookies to understand how to withdraw your consent.

We collect the information you provide to us, including when:

  • you navigate on our platform and applications
  • you create, modify and access your personal account
  • you fill in a contact form
  • you use notifications
  • contact our Customer Service

Is your data shared with third parties?

The personal data concerning you collected on our platform are intended for own use by SPOT LMS and can be transmitted to companies subcontractors that SPOT LMS may use in the performance of its services.

SPOT LMS does not sell or rent your personal information to third parties for marketing purposes, in any manner whatsoever. case.

We also work closely with third party companies who may have access to your personal data, in particular:

  • When you expressly request it;
  • When we use search engine and analytical solutions providers to improve and optimize our platform;
  • When we have a legal obligation to do so or if we believe in good faith that it is necessary to (i) respond to any claim against SPOT LMS, (ii) comply with the SPOT LMS (iii) to enforce any contract entered into with our members, such as the Terms of Use and this Privacy Policy (iv) in the event of an emergency involving the public health or physical integrity of a person, (v) in the (vi) to ensure rights, property and safety; or SPOT LMS, its members and more generally any third party;
  • In addition, SPOT LMS does not disclose your personal data to third parties, except if (1) you (or your account administrator acting on your behalf) make the request or authorize the disclosure; (2) disclosure is required to process transactions or provide services that you have (3) SPOT LMS is required to do so by a government authority or a regulation, in case of judicial requisition, subpoena or any other requirement or to establish or defend a legal claim; or (4) the acts as agent or subcontractor for SPOT LMS in the performance of the Services (by For example, SPOT LMS uses the services of a telecommunications company).

If SPOT LMS or all or part of its assets are acquired by a third party, the data in our possession will, where applicable, be transferred to the new owner.

Upon request, we can provide you with a list of the countries where we keep your data and those where we do not. they transit occasionally.

We keep your data in the European Union but we also transfer them outside the Union European to the United States. The U.S. entities to which we transfer your data have Privacy Shield or we have entered into specific contracts and clauses with them established by the European Commission to supervise and secure the transfer of your data. data to these providers. We may use the services of U.S. companies to whom we have access. subcontract your data to respond to your requests, provide online payment tools, we will provide commercial and advertising services or emailing and SMS services.

How are your personal data protected?

SPOT LMS applies technological security measures generally recognized so that the personal data collected are not, lost, misused, accessed, altered or disclosed by unauthorized third parties unless the communication of such data is imposed by the regulations in force, in particular at the request of an authority judicial, police, gendarmerie or any other authority empowered by law.

The security of personal data also depends on the Users. Users who are members SPOT LMS are committed to maintaining the confidentiality of their login and password. The members also agree not to share their account and to declare to SPOT LMS any use of their account. unauthorized use of said account as soon as they become aware of it.

How long do SPOT LMS users keep their personal data?

The personal data provided by the SPOT LMS users will be deleted after a certain period and depending on the data processed.

1 year after your last use of our platform, the customer account and all user accounts of the account customer are deleted without the possibility of restoration.

We do not retain any of your data after the customer account is deleted.

Are you a minor?

Our goal being to make education accessible to all, minors can access the Site to search for information.

Before accessing the Site, the consent of minors under 16 years of age must be given by the owner of the Site. parental authority.

Our platform does not provide for the registration, collection or storage of information relating to any person 13 years of age or younger.

You should read this Privacy Policy with your parents or guardian. legal representative to ensure that you and your parents or legal representative understand it.

When you have given your consent when you were minors, personal data you were collected.

You will be able to exercise your right to forget if you no longer wish your personal data to be stored. in our databases.

What are your rights ?

In accordance with the regulations in force, the Users of our platform have the following rights following :

  • right of access and rectification ;
  • update, user data completeness ;
  • right to block or delete the personal data of Users, when they are is inaccurate, incomplete, ambiguous, out of date, or whose collection, use, disclosure or storage is prohibited;
  • right to withdraw consent at any time ;
  • right to limit the processing of Users' data ;
  • right to object to the processing of personal data ;
  • the right to the portability of the data that the Users will have provided, when these data make the object of automated processing based on their consent or a contract.

If you wish to know how SPOT LMS uses this personal data, ask to rectify it or to oppose a treatment you can send an email to the address data-protection@spotlms.com or send to a letter to the following address: Cyrus HD - Data Protection Officer, 21 rue marc donadille, 13013 Marseille France. Finally, SPOT LMS Users can file a complaint with the authorities of control, and in particular CNIL)

Your requests will be processed within 30 days. In addition to your request, we will ask you to contact a photocopy of a proof of identity so that SPOT LMS can verify your identity.

How to contact us - contact details data protection officer

If you have any questions or complaints, or if you have any questions wish to provide SPOT LMS with recommendations or comments to improve our Policy of personal data protection you can send an email to the address data-protection@spotlms.com or send to a letter to the following address: Cyrus HD - Data Protection Officer, 21 rue marc donadille, 13013 Marseille France.

 

Security at SPOT LMS

Protecting your data is our highest priority

 

Overview

As users of our own product, we understand how important the security and privacy of your data is.
We are committed to providing our customers with a highly secure and reliable environment for its cloud-based application. We have therefore developed a security model that covers all aspects of cloud-based SPOT LMS systems.

The security model and controls are based on international protocols and standards and industry best practices, such as ISO/IEC 27001, the standard for information security management systems (ISMS) and ISO/IEC 27018 , Security techniques - Code of practice for protection of personally identifiable information in public clouds.

As part of the company’s focus on security issues, the company security team performs on a regular basis:
  • Monitoring and analyzing the infrastructure for suspicious activities and potential threats.
  • Issuing periodic security internal review.
  • Dynamically updating the security model and addressing new security threats.
  • Systematically examining the organization's information security risks, taking into account threats and vulnerabilities.
  • Designing and implementing a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address the risks that are deemed unacceptable.
  • Adopting an overarching management process to ensure that the information security controls continue to meet the organization's evolving information security needs.

Protecting Customer Data

Our systems are hosted on OVH infrastructure. They've devoted an entire portion of their site to explaining their security measures, which you can find in the following links:
https://www.ovh.com/world/about-us/security

No one other than our directors can access the data of clients and this is only done by a director if it is necessary to solve client-related issues.

Authorizing Access

Customer data is stored only in the production environment. Directors only have approval to access user data in order to solve client requests, issues or bugs. All logs of SSH connections to our production environment are saved and archived. Attachments in your account are encrypted and delivered on a per-user-access controlled basis.
We know the data you share in SPOT LMS is private and confidential. We have strict controls over our directors' access to internal data and we are committed to ensuring that your data is never seen by anyone who should not see it.

Secure Software Design

Any new feature or code that will be implemented into our system starts with an in-depth analysis of security and privacy risks. All code is saved into a version control repository and evaluated in a test environment before deploying it into our production environment. All code is reviewed by a second developer to ensure code quality.

Physical Security Protocols

Security controls at OVH data centers are based on standard technologies and follow the industry’s best security practices. The physical security controls are constructed in such a way as to eliminate the effect of single points of failure and retain the resilience of the computing center.

Environmental Controls

A variety of environmental controls are implemented at the data center facilities.
  • Servers are locked inside the infrastructure in a designated area.
  • The server area is cooled by a separate air conditioning system, which keeps the climate at the desired temperature to prevent service outage.
  • The facilities are protected by a fire suppression system, which protects the computing equipment and has built-in fire, water, and smoke detectors.
  • The facilities have on-site generators, which serve as an alternative power source.
  • There is 24-hour video surveillance of all entrances and exits, lobbies, and ancillary rooms. The videos are recorded and monitored, and retained for later use.

Network Security

Firewalls: Applications in the hosting and cloud have firewalls installed to shield them from attack and prevent the loss of valuable customer data. The firewalls are configured to serve as perimeter firewalls to block ports and protocols.
DDoS mitigation: All application access, including direct application access and API access, are protected by a DDoS mitigation service to ensure high availability at all times, as well as prevent attacks and malicious activities.

Encryption in Transit and at Rest

SPOT LMS ensures the security and privacy of user information by encrypting data on all servers at rest and in transit.
Our systems are designed to ensure data is protected at all times. Specifically, we're using TLS v1.2 with strong ciphers to protect data in transit, and AES-256 to encrypt data at rest. User passwords are hashed and salted with a modern hash function.
SPOT LMS’s cloud-based solution is deployed using dedicated servers of OVH, enabling us to guarantee high security through utilizing a series of high tech, best in the industry solutions that work to ensure the safety of all user data on the OVH network.

External Security Audits and Penetration Tests

We work closely with industry leaders in web app and infrastructure security who perform penetration tests and audits of SPOT LMS. We monitor our product for security vulnerabilities automatically as the product grows.

System Monitoring, Logging and Alerting

SPOT LMS monitors servers to retain and analyze a comprehensive view of the security state of its production infrastructure. SPOT LMS collects and stores production servers logs for analysis. Logs are stored and indexed in a separate network.

Backup

All of the data is backed up daily to multiple disks. Backups are encrypted and distributed to various locations. Backups are saved for a period of 30 days.

Incident Management

To handle security incidents effectively, SPOT LMS has constructed incident response and notification procedures. SPOT LMS employs an Incident Handling team that responds to security incidents and mitigates risks. The team uses monitoring and tracking tools and performs real-time analysis. Additionally, the team has clear procedures in place for communicating the incidents to any involved party and for handling escalations. Every incident is forwarded to the security team leader for assessment and analysis.The level of severity is a measure of its impact on, or threat to, the operation or integrity of the institution and its information. It determines the priority for handling the incident, who manages the incident, and the timing and extent of the response.

Personnel Security

SPOT LMS realizes that the malicious activities of an insider could have an impact on the confidentiality, integrity, and availability of all types of data and has therefore formulated policies and procedures concerning the hiring of IT administrators or others with access to important and crucial systems. SPOT LMS has also formulated policies and procedures for the ongoing periodic evaluation of IT administrators or others with system access. User permissions are continuously updated and adjusted so when a user's job no longer involves infrastructure management, the user's console access rights are immediately revoked.

Security Awareness and Training

In order to help ensure that SPOT LMS employees are aligned with the security practices and aware of their duties, SPOT LMS conducts multiple information security awareness campaigns. In addition, the security obligations of users and the entity’s security commitments to users are communicated on an annual basis through the company policy.
Our engineering and operation teams keep their skills up to date regarding security best practices. We have coded many different online systems and are experienced in infrastructure security and systems security.

PCI DSS, ISO 27001 and SOC1/2

OVH's data centers have a PCI DSS certification, ISO/IEC 27001 certification, SOC 1 Type II and SOC 2 Type II certifications, service auditor’s report as the result of an indepth audit of the centers’ control objectives and control activities, including controls over information technology and all other related processes. Please visit the following links:
https://www.ovh.com/world/about-us/certifications

 

Legal Mentions

 

Legal Mentions

Cyrus RH is a simplified joint stock company (SAS) with a capital of 164640 € registered in France under the SIREN 447 803 354 and whose registered office is located at 21 rue marc donadille, 13013 Marseille, France. Cyrus RH is represented by Mr Laurent MICHEL, its Chairman.

Cyrus RH is an application software company and we provide our services as a SAAS platform.

The Director of Publication of the platform is Mr Laurent MICHEL.

The site is hosted by OVH whose address is the following : OVH - 2 rue Kellermann - 59100 Roubaix - France

Contact us

  • By email : contact@spotlms.com
  • By mail : Cyrus RH, 21 rue marc donadille, 13013 Marseille, France

You have the right to access and rectify information concerning you, which you may exercise by email at the address data-protection@spotlms.com or by mail (address above). You may also, for legitimate reasons, object to the processing of your personal data. data you concerning.

For more information on all your rights you can refer to our "Privacy Policy".