Privacy Policy
NDTAcademy.com, LLC
Effective Date: July 4, 2026
1. Scope
This Privacy Policy explains how NDTAcademy.com, LLC handles personal information collected through the Platform. It applies to students, company administrators, and visitors. For cookies specifically, see the Cookie Policy.
2. Information We Collect
Account & profile: name, email, password (never stored in plain text, see §6), employer, job title, phone, and mailing address if you provide them.
Identity verification: to tie training records to a real person, our verification partner Persona collects your government ID images and a selfie. Those images are captured and stored by Persona, not on our servers. We store only the verification outcome: inquiry ID, status, verification timestamps, and the verified name/date-of-birth/address fields Persona returns, which may prefill your student profile for certificate accuracy.
Training records: enrollments, lesson completions, quiz and examination attempts and scores, active-engagement time logs, certificates, and course versions completed.
Payments: processed by Stripe. We store purchase records (what was bought, amount, status, Stripe identifiers) but never your full card number, CVC, or bank credentials.
Technical: IP address and browser user-agent in security and audit logs; essential session cookies.
Data minimization: we collect only what the training-records mission requires. We do not run third-party advertising or analytics trackers, and we do not sell or rent personal information.
3. How We Use Information
To deliver courses and examinations; to create auditable formal-training records under SNT-TC-1A / NAS410 expectations; to issue and verify certificates; to process payments and prevent fraud; to secure the Platform (rate limiting, audit logging); to provide support; and, with your consent, to send product updates you can opt out of at any time.
4. Sharing
We share personal information only with:
Your company administrator, if your account belongs to a company roster, your org’s admins can see your name, training progress, hours, attempts, and certificates (that is the product); Certificate verifiers, anyone holding a certificate’s verification code can see the name, course, hours, dates, version, and validity status printed on it, nothing more; Service providers, Supabase (database/auth hosting), Stripe (payments), Persona (identity verification), and our hosting provider, each bound to process data only to provide their service; Legal, where required by law, or to a successor in a merger/acquisition under the same commitments. We never sell personal information.
5. Retention
Formal training records (completions, attempts, hour logs, course versions) are retained a minimum of 10 years; certificates are retained permanently so they remain verifiable across employment changes. Identity verification outcomes are kept for the life of the account plus 7 years (fraud defense). Payment records are kept 7 years (tax). Security/audit logs are kept at least 7 years. Marketing emails are kept until you unsubscribe. The full schedule is published in our data retention policy.
6. Security
Passwords are hashed with bcrypt by Supabase Auth and are never visible to us. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 at the database layer). Row-level security restricts every database row to its owner, their organization admins, or platform administrators. Administrative actions are recorded in an append-only audit log. See Security at NDT Academy for details and security.txt for vulnerability reporting.
7. Your Rights
You may access and correct your profile in the dashboard, and export your complete training record (JSON or CSV) from your transcript page. You may request deletion of your account and personal information at privacy@NDTAcademy.com; we will erase personal data not required by law or by the training-records retention above. Where records must be retained (e.g., issued certificates and their supporting evidence), we will restrict rather than erase them and tell you what was kept and why. Depending on your residence (e.g., EU/UK GDPR, California CPRA), you may have additional rights, to portability, restriction, objection, and to complain to a supervisory authority; we honor verified requests accordingly and do not discriminate for exercising them.
8. Admin Access to Student Records
Platform administrator access to student records is limited to named, individually authorized staff, follows least privilege, and is logged. Administrators may never alter completed training evidence: completion records, attempts, and time logs are append-only at the database level, and certificate changes are restricted to revocation with a recorded reason.
9. Children
The Platform is professional training and is not directed to children under 16; we do not knowingly collect their data and will delete it on discovery.
10. International Transfers
Our infrastructure is hosted in the United States (Supabase, us-east-2). If you use the Platform from outside the U.S., your information is processed in the U.S. under this policy’s safeguards.
11. Changes
We will post any revision with a new effective date and notify account holders of material changes by email or in-product notice before they take effect.
Contact
Questions about this policy may be directed to:
NDTAcademy.com, LLC, Attn: Legal
Email: legal@NDTAcademy.com
