Privacy Policy

...Between ourselves...

Effective Date: July 1st, 2026

E-Learning SAS (“CrossKnowledge”), 2 rue des Martinets, 92500 Rueil-Malmaison, France, is the data controller for personal data processing where we determine the purposes and means. We have appointed a Privacy Officer who can be contacted at [email protected].

CrossKnowledge prioritizes privacy and is dedicated to safeguarding the personal data of all its stakeholders with the utmost care. We ensure that personal data is processed fairly and lawfully. This Privacy Policy applies to our customers, partners, and website visitors, covering the personal data collected and processed by CrossKnowledge through our public websites, marketing activities, partner and community interactions, events, content downloads, and the Learning Impact Alliance / Learning Impact Program. 

This Privacy Policy provides essential information on how CrossKnowledge, as a data controller, collects and processes personal data, the purposes for which it is used, and your rights as a data subject under the EU General Data Protection Regulation (GDPR) and UK GDPR.

For CrossKnowledge customers
Our Data Processing Addendum (DPA) describes how we process Customer Data in accordance with your instructions. A DPA is part of your agreement with us by default.

Controller vs. processor
For marketing, websites, and community activities described in this Policy, CrossKnowledge acts as the data controller. When we process Customer Data on behalf of a customer under the DPA, CrossKnowledge acts as a data processor and the customer acts as the controller. CrossKnowledge may also act as an independent controller for its own business purposes, such as billing, account administration, security, legal compliance, and marketing communications.

You can provide us with your personal data in the context of various activities, as outlined below. We always collect the minimum information necessary and process it only for the purposes described.

When you join the community or enroll in the program, we collect and process your name, email address, job title, organisation, country, and information regarding your interest in joining either the Alliance or the Program.

Your enrolment data will be used to send you Learning Impact Program and community administration messages (such as program updates, module releases, invitations to community sessions, and service-related information). Where we use your details to send marketing communications about CrossKnowledge products and services, we will do so in accordance with Section 1.8 (including obtaining prior consent where required) and you can opt out at any time without affecting program administration communications.

When registering for a webinar or event, we process your full name, email address, and company, function, department and number of employees to manage your registration and participation. Depending on the context, the legal basis is performance of a contract (registration) and/or our legitimate interests in running the event; where required, we will ask for your consent for related marketing communications.

When downloading content, we process your details to provide you with the requested material and measure interest. If we contact you for marketing purposes, we will do so based on your consent where required, or our legitimate interests where permitted, and you can opt out at any time.

In some cases, we receive personal data from third parties, such as our partners, event co-hosts, or third-party platforms (for example, when you register for a co-hosted event or interact with us on professional networks). The categories of data may include contact details, professional information, and participation or engagement details. We use this information for the purposes described in this Policy and, where required, provide additional notices at the time we first communicate with you.

Where we have not obtained personal data directly from you, we will provide the information required by Article 14 GDPR within the applicable timeframe, unless an exemption applies. 

We use analytics tools to collect and analyze information about how visitors use our websites (such as page views, interactions, approximate location, device and browser information). This helps us measure performance, troubleshoot issues, and improve the website and our content. Where these analytics tools rely on non-essential cookies or similar technologies, they are used only with your consent as described in Section 6.2. Website analytics do not by themselves result in you receiving marketing emails.

Where possible, we configure analytics to limit identifiability, for example by using aggregation, pseudonymisation or similar privacy-protective settings. 

Where we send you marketing communications (for example, newsletters, product updates, or invitations), we do so in accordance with applicable laws on electronic marketing. Where required, we will obtain your prior consent before sending such communications. Where consent is not required, we may rely on our legitimate interests, for example when contacting business customers about similar services, subject to your right to object at any time.

You can opt out of marketing emails at any time by using the unsubscribe link in each message or by contacting us at [email protected]. Opting out will not affect service or transactional communications (e.g., security notices, billing messages, or program administration emails).

We process your personal data on the following legal grounds (depending on the activity and applicable law). Where we rely on legitimate interests, we have carried out a balancing assessment to ensure our interests are not overridden by your rights and freedoms:

2. Sharing of your information

CrossKnowledge is committed to not selling personal data. We disclose personal data only as described in this Policy and where necessary for legitimate business, legal or service purposes.

Your personal data can be stored and processed in countries both within and outside the European Economic Area (EEA), United Kingdom and Switzerland. Data is only transferred to CrossKnowledge affiliates, subsidiaries, or third parties in such countries when permitted under applicable data protection legislation.

Where transfers occur outside the EEA or UK, we ensure appropriate safeguards are in place in accordance with GDPR Article 46 and applicable UK transfer rules. These safeguards can include EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other approved mechanisms, and we may carry out transfer impact assessments where required. You can request information about the safeguards we use (including copies of relevant contractual clauses, where appropriate) by contacting us at [email protected]. Transfers may occur directly to our affiliates or via the sub-processors listed in our sub-processor list.

CrossKnowledge recognises the critical importance of protecting personal data. We ensure that your personal data is not retained longer than necessary for the purposes for which it was collected, the execution of a contract, or to fulfil a legal obligation. Retention periods vary depending on the type of processing activity and the purpose for which the data was collected.

Personal data collected based on your consent will be retained until you withdraw consent or until the data is no longer necessary for the purpose for which consent was obtained, whichever occurs first, unless a longer retention period is required by law. In all cases, personal data may be retained for a longer period if required by legal or regulatory reasons, or for a shorter period if you object to the processing and there is no longer a legitimate reason to retain it.

Retention periods
We apply retention criteria based on the purpose of processing, legal requirements, and limitation periods. For example: (i) contact and demo enquiries are generally retained for up to 24 months after the last interaction; (ii) marketing contact data is retained until you unsubscribe or object, and then kept on a suppression list to ensure we respect your choice; (iii) transactional and accounting records may be retained for the duration required by applicable law; and (iv) security logs are generally retained for a limited period unless needed to investigate incidents.

We implemented measures designed to restrict access to archived data and to ensure that your personal data is either deleted or anonymised once the retention period has expired.

At CrossKnowledge, we have implemented comprehensive technical and organisational security measures to safeguard your personal data against destruction, loss, falsification, alteration, unauthorised access, or disclosure to third parties, as well as any other unauthorised processing.

We are committed to maintaining the confidentiality, integrity, and availability of the information systems and services that handle personal data. Our security measures encompass physical and operational safeguards, access controls, awareness programmes, and confidentiality agreements. All employees and third-party partners are required to uphold the privacy and security of your data.

Our commitment to data security is reinforced by our ISO 27001 certification (held since 2017), which underscores our adherence to international standards for information security management. Our security measures are regularly audited and improved to address evolving threats.

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently and to provide information to site owners. CrossKnowledge websites use cookies and similar technologies to ensure the proper functioning of our websites and to enhance your experience.

We use Osano to manage cookie consent on our websites. Non-essential cookies (such as analytics, personalisation, and marketing cookies) are set only after you provide your prior consent under applicable ePrivacy rules. The legal basis for processing personal data collected through non-essential cookies is your consent. You can accept or refuse non-essential cookies and change your choices at any time by using the cookie preferences link or icon in the footer of our websites.

Our cookie preferences panel provides information about the cookies and similar technologies we use (including their purpose, provider, and duration) and records your consent choices. We keep records of consent as required to demonstrate compliance.

Cookie list
We maintain a cookie list that describes the cookies and similar technologies used on our websites (including the name, provider, purpose, category, and duration), and indicates which cookies are essential and which require consent. You can review the cookie list via the cookie preferences panel.

You can also manage cookies via your browser settings (Firefox, Google Chrome, Microsoft Edge, Safari). Please note that disabling certain cookies may result in reduced functionality on our websites.

When we offer social sharing widgets or links (for example LinkedIn, Facebook, Twitter/X and others), those platforms may set their own cookies or similar technologies when you interact with them or are logged into their services. Depending on the context, these providers may act as independent controllers or joint controllers for their own processing activities please refer to each platform’s own cookie policy for more information.

Our website may contain links to third-party websites. Third-party websites have their own privacy and data protection policies, which are not covered by this Privacy Policy. CrossKnowledge is not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party sites you visit.

You always have the right to exercise your rights as outlined in the General Data Protection Regulation. These rights include:

You can exercise any of these rights by contacting [email protected]. We will respond to your request within one month of receiving it and may ask for additional information to verify your identity.

If you find our response unsatisfactory, you have the right to file a complaint with a supervising authority. In France this would be the French Data Protection Authority (CNIL): Commission Nationale Informatique et Libertés, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online at cnil.fr.
You may also contact the data protection authority in your country of residence.

We may periodically update this Privacy Policy to reflect changes in our data processing practices or applicable laws. Updates will be posted on this webpage with the “last updated” date revised accordingly. Where changes are material, we will notify you by email or through a prominent notice on our website. We encourage you to review this Policy regularly.

If you have comments, questions or concerns relating to the processing of your personal data by CrossKnowledge, please contact our Privacy Officer
[email protected]

In the event you prefer to contact us by letter, you can do so on the following address:

CrossKnowledge Privacy Office
E-Learning SAS (CrossKnowledge)
2 rue des Martinets
92500 Rueil-Malmaison
France