Eluneo

Eluneo legal

Privacy Policy

This policy explains how MOOCit SAS processes personal data when people visit Eluneo, administer a workspace, use a learner portal, purchase training, or contact us.

Effective date: July 27, 2026

1. Who we are and our role

Eluneo is an online learning-management service provided by MOOCit SAS, a French company registered with the Orléans Trade and Companies Register under number 810 156 497.

MOOCit SAS is the data controller for personal data used to operate Eluneo accounts, subscriptions, the public website, security, and support. When a Customer uses Eluneo to manage learners and deliver training, that Customer normally determines why and how learner data is used. In that situation, the Customer is the controller and MOOCit SAS acts as its processor under the Data Processing Addendum in our Terms of Service.

Data controller

MOOCit SAS

97 allée Maurice Ravel, 45160 Olivet, France

RCS Orléans 810 156 497

hello@eluneo.com

2. Personal data we process

Depending on how Eluneo is used, we may process:

  • Account and workspace data: name, email address, authentication identifiers, password hash, organization, role, workspace membership, language, and interface preferences.
  • Portal and learner data: learner name, email, profile, groups, assignments, eligibility, registration method, and portal access.
  • Learning activity: launches, attempts, status, progress, completion, scores, time, interactions, SCORM runtime data, xAPI or cmi5 statements, attendance, resource activity, certificates, and related reporting records.
  • Customer Content: course packages, documents, links, portal assets, certificate designs, and other content uploaded or configured through the Service.
  • Subscription and commerce data: plan, billing cycle, currency, billing contact, Stripe customer and transaction identifiers, order status, product, price, discount, tax, and refund metadata. Complete payment-card details are handled by Stripe and are not stored by Eluneo.
  • Technical and usage data: IP address, device and browser information, request and security logs, session activity, approximate IP-based location where enabled, error details, and feature usage.
  • Support data: messages, attachments, diagnostic information, and other details you provide when contacting us.

3. How we obtain data

We receive data directly from account holders, administrators, learners, purchasers, and support contacts; automatically from use of the Service; from Customers that enroll or invite learners; and from integrations enabled by a Customer, such as identity, meeting, commerce, and content services.

If your account or learner access is managed by an organization, that organization may provide your data to Eluneo and control your learning records. Questions about the organization’s purposes or retention choices should first be directed to that organization.

4. Why we use personal data

We use personal data to:

  • create, authenticate, and administer accounts and workspaces;
  • host portals and deliver courses, resources, sessions, and certificates;
  • record learning activity and provide progress and reporting;
  • manage subscriptions, orders, payments, taxes, and entitlements;
  • send transactional, security, account, and support communications;
  • provide support, diagnose faults, and improve reliability and usability;
  • protect users, prevent fraud and abuse, and enforce our Terms; and
  • meet accounting, tax, regulatory, and legal obligations.

5. Legal bases

Where the GDPR applies, our legal bases include:

  • Contract: processing needed to provide an account, subscription, purchase, or requested Service.
  • Legitimate interests: security, fraud prevention, support, service administration, product improvement, and limited business communications, balanced against individual rights.
  • Legal obligation: accounting, tax, regulatory, and lawful disclosure requirements.
  • Consent: optional communications or features where consent is required. Consent can be withdrawn at any time.

For learner data processed on a Customer’s behalf, the Customer determines the applicable legal basis and instructs us through the Service and the Data Processing Addendum.

6. Sharing and service providers

We do not sell personal data. We disclose data only as needed to operate Eluneo, follow Customer instructions, complete a transaction, protect the Service, or comply with law. Recipients may include:

  • Scaleway for European cloud infrastructure, hosting, databases, backups, and object storage;
  • Stripe for Eluneo subscriptions, connected portal accounts, checkout, payment processing, and fraud prevention;
  • transactional email, authentication, and support providers;
  • meeting, identity, image, map, or other integrations enabled or requested by a Customer;
  • professional advisers, auditors, insurers, authorities, or courts where reasonably necessary or legally required; and
  • a successor in a merger, acquisition, financing, reorganization, or sale of relevant assets, subject to appropriate safeguards.

Providers receive only the data needed for their role and are subject to contractual confidentiality and data-protection obligations where required.

7. Data location and international transfers

Eluneo’s primary application infrastructure and storage are hosted in the European Union. Some providers or integrations may process limited data outside the European Economic Area, the United Kingdom, or Switzerland.

Where a restricted international transfer occurs, we rely on an adequacy decision, approved Standard Contractual Clauses, or another lawful transfer mechanism and apply supplementary safeguards where appropriate.

8. Retention and deletion

We retain account and workspace data while the account or subscription is active and for a limited period afterward to support reactivation, security, dispute resolution, and deletion workflows. Customers control much of the learner-data lifecycle through assignments, course versions, learner status, and deletion features.

We keep billing, transaction, and legal records for applicable statutory periods. Security logs and backups are retained for limited operational cycles. When data is no longer needed, it is deleted or anonymized, subject to legal holds, fraud prevention, backup rotation, and the Data Processing Addendum.

9. Cookies and local storage

Eluneo uses essential cookies and similar browser storage for authentication, security, language, theme, portal selection, and session continuity. These are necessary for requested functionality.

If we introduce optional analytics or marketing cookies, we will provide any consent controls required by applicable law before using them. You can also control browser storage through your browser, but blocking essential cookies may prevent sign-in or other features from working.

10. Security

We use technical and organizational measures designed to protect personal data, including HTTPS encryption in transit, password hashing, role-based access controls, least-privilege service access, signed or time-limited file access where appropriate, logging, backups, infrastructure hardening, and security monitoring.

No system can guarantee absolute security. Customers are responsible for secure credentials, appropriate administrator permissions, lawful portal configuration, and promptly reporting suspected compromise.

11. Your data-protection rights

Depending on the processing and applicable law, you may have rights to information, access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent without affecting earlier lawful processing.

To exercise rights concerning an Eluneo account or MOOCit SAS’s own processing, contact hello@eluneo.com. We may need to verify your identity. If your request concerns learner data controlled by a Customer, we may direct the request to that Customer or assist it in responding.

You may lodge a complaint with your local supervisory authority. In France, this is the Commission Nationale de l’Informatique et des Libertés (CNIL).

12. Children and learner portals

Eluneo administration accounts are intended for people able to enter a binding agreement. Customers determine the audiences for their learner portals and are responsible for any notices, consent, authorization, age requirements, or safeguards needed when providing training to minors.

13. Changes to this policy

We may update this policy as Eluneo, our providers, or legal requirements change. We will publish the revised policy and update its effective date. Material changes may also be announced by email or through the Service.

Privacy questions or requests

Email hello@eluneo.com or write to MOOCit SAS, 97 allée Maurice Ravel, 45160 Olivet, France.