TrainSec
Last updated: October 7, 2026
Scorpio Software LLC, operating as trainsec.net (“we”, “us” or “our”), is committed to protecting your privacy while providing our services (the “Services”). In this policy, “you” and “your” refer to any user or customer of the Services.
To become a customer, you need to register and open a personal account through our website. At registration, we ask you to provide certain personal information. Providing this information is voluntary, but without it you may not be able to receive our Services. By providing your personal information, you consent to our using it to deliver the Services to you.
Under applicable data protection laws, please note the following:
The company responsible for your personal data is Scorpio Software LLC, 95 Newcomb Rd., Tenafly, NJ 07670, USA.
To contact our representative, Mickey Zelansky (Data Protection Officer), email [email protected].
To register and use the platform, you must be at least 16 years old. We may, but are not obliged to, use your personal information to verify your age and enforce this restriction.
Information provided by you: first name, username, email address, country, city, street address and ZIP/postal code.
We may use your personal information in-house in order to:
We use personal information collected through our Services for a variety of business purposes. We process it in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or to comply with our legal obligations. We use the information we collect or receive:
When you create an account with us, we may process and share your data on the following legal bases:
Legitimate interests: we may process your data when it is reasonably necessary to achieve our legitimate business interests.
Legal obligations: if we reasonably suspect that your account has been used for an unauthorized, illegal or criminal purpose, you authorize us to share information about you, your account and your transactions with law enforcement. We may also disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, a court order or legal process, such as a subpoena (including requests from public authorities to meet national security or law enforcement requirements).
Vital interests: we may disclose your information where we believe it is necessary to investigate, prevent or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person, illegal activities, or as evidence in litigation in which we are involved.
We keep your personal information for at least 2 years, and otherwise only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law (such as for tax, accounting or other legal requirements).
When we have no ongoing legitimate business need to process your personal information, we will delete or anonymize it. If this is not possible, we will securely store it and isolate it from any further processing until deletion is possible.
If you ask us to delete your personal information and cancel your account, we will cancel your account and delete the information associated with it, in line with your right to be forgotten.
We store your data on our own servers and also use third-party storage providers. Third-party service providers that store or process your personal information are contractually committed to keep it protected and secure, in accordance with industry standards and regardless of any lesser legal requirements that may apply in their jurisdiction.
Under the GDPR, the CCPA and similar laws, you may request access to the personal data we hold about you, correction of inaccurate data, a portable copy of your data, or deletion of your data. To exercise these rights, email [email protected] from the address registered to your account. We will verify your identity and respond within 30 days, or sooner where the law requires. You can also update much of your account information directly in your account settings.
We use a limited number of third-party providers to operate our services, including Stripe for payment processing, Podia for course delivery and account management, MailerLite for email communications, Credly for issuing digital certificates, and Google for email and file storage. All providers are carefully vetted before use, and those that process personal data on our behalf are bound by Data Processing Agreements (DPAs) that require them to protect your data and use it only for the agreed purposes.
We maintain documented procedures for detecting, assessing and responding to security incidents. If a personal data breach affects you, we will notify affected individuals and customers, and the relevant regulatory authorities where required by law, without undue delay and in accordance with applicable law.
We protect personal data with technical and organizational measures, including access controls, multi-factor authentication, employee confidentiality agreements and regular security training. More information is available on our Security & Compliance page.
You can review or change the information in your account at any time by logging into your account settings, or by emailing us at [email protected].
You can unsubscribe from our marketing emails at any time by emailing us at [email protected]. You will then be removed from the marketing list. We will still send you service-related emails that are necessary for the administration and use of your account.
To provide the Services to you, we may transfer your data to the location where the Services are provided and process it there. By visiting or using our Services, you consent to your data being stored on servers located in the United States, where we reside. In particular, personal data collected in the United Kingdom (“UK”), Switzerland and the EEA may be transferred to and stored outside those areas.
This section applies if you are located in California. California Civil Code Section 1798.83 permits customers who are California residents to request and obtain from us, once a year and free of charge, information about the categories of personal information (if any) we disclosed to third parties for direct marketing purposes, and the names and addresses of all third parties with which we shared personal information in the preceding calendar year. To make such a request, please submit it in writing using the contact details below.
If you are under 18 years of age, reside in California and have a registered account on our website, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal, please contact us using the contact details below, and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that it may not be completely or comprehensively removed from our systems.
Under the California Consumer Privacy Act (CCPA), we are required to inform you about the information we may collect, the purposes for which we collect it, the sources of that information, and the categories of third parties with whom we share it. Please see the “What Personal Information Do We Collect?” section above.
If you are a resident of Nevada, you have the right to opt out of the sale of certain personal information to third parties who intend to license or sell it. You can exercise this right by emailing [email protected] with your name and the email address associated with your account. Please note that we do not currently sell your personal information as “sale” is defined in Nevada Revised Statutes Chapter 603A.
As required by law, we respond to all claims of intellectual property infringement. We promptly investigate notices of alleged infringement and take the actions required under the Digital Millennium Copyright Act, 17 U.S.C. § 512(c)(2) (“DMCA”), and other applicable intellectual property laws.
Under the DMCA, notifications of claimed copyright infringement must be sent to the service provider’s Designated Agent:
Name: Pavel Yosifovich
Address: 95 Newcomb Rd., Tenafly, NJ 07670, USA
Email: [email protected]
From time to time, we may update this Privacy Policy. If we make a material change, we will notify you by email, through a notice posted on the Services, or as required by applicable law, and we will include a summary of the key changes. Unless stated otherwise, changes take effect on the day they are posted.
Where permitted by applicable law, if you continue to use the Services after a change takes effect, your access or use will be deemed acceptance of, and agreement to be bound by, the revised Privacy Policy. The revised Privacy Policy supersedes all previous versions.