01Who we are
iLeap is a training administration platform built for training institutions in Mauritius. It supports the full training lifecycle — training registration, client bookings, attendee management, attendance tracking, compliance documentation and certificate generation.
The website ileap.app and the iLeap platform are operated by Red Peach Ltd, a company registered in Mauritius under business registration number C25229658, with its registered office at No 98, Royal Road, Morc Ashviva, Trou aux Biches, Mauritius ("iLeap", "we", "us", "our").
We are registered with the Data Protection Office of Mauritius as a controller and processor under the Data Protection Act 2017 (the "Act")
Our designated officer responsible for data protection compliance can be reached at contact@ileap.app.
02Scope of this policy
This policy explains how we handle personal data when you:
- Visit ileap.app or join our launch waitlist;
- Contact us by email or through the website;
- Use the iLeap platform as a training institution administrator, trainer, or client HR user; or
- Are a training participant whose details are entered on the platform by a training institution or your employer.
It applies to processing of personal data wholly or partly by automated means, and to non-automated processing forming part of a filing system, as provided under section 3 of the Act.
03Our role: controller and processor
Under the Act, our responsibilities depend on the context in which your data is processed.
Where iLeap is the controller
We determine the purposes and means of processing — and are the controller — for:
- The ileap.app website, waitlist and marketing communications;
- Account registration and authentication for all platform users;
- Platform usage, security and audit data.
Where iLeap is the processor
When a training institution or a client organisation enters personal data about trainers, contact persons or training participants into the platform, that organisation is the controller of the data and iLeap processes it on the organisation's behalf and on its instructions, under a written agreement as required by section 31(4) of the Act.
04Personal data we collect
| Context | Personal data | Supply |
|---|---|---|
| Website & waitlist | Name and email address you submit to join the waitlist or contact us | Voluntary |
| Platform accounts | Name, email address, phone number, role, organisation, login credentials | Mandatory to use the platform |
| Training institution & client profiles | Contact person name, business email and phone number, organisation details | Mandatory for bookings and compliance |
| Trainer profiles | Name, contact details, CV, qualifications, references, identity document | Mandatory for trainer registration |
| Training participants | First name, last name, national identity number, email address, phone number, attendance records, certificates issued | Provided by the booking organisation; required for compliance documentation |
| Training feedback | Questionnaire responses linked to a training session; anonymised where required | Voluntary |
| Technical data | IP address, browser and device information, log and audit trail data | Collected automatically |
We do not collect personal data beyond what is adequate, relevant and necessary for the purposes described in this policy, in line with section 21 of the Act.
05Why we process personal data
We process personal data only where a lawful basis under section 28 of the Act applies:
| Purpose | Lawful basis |
|---|---|
| Managing the launch waitlist and sending you updates about iLeap | Your consent, which you may withdraw at any time |
| Creating and administering platform accounts; delivering the platform's features (bookings, attendance, certificates, documentation) | Performance of a contract |
| Generating compliance and refund documentation required by Mauritian training authorities on behalf of training institutions and their clients | Performance of a contract; compliance with legal obligations of the controller organisation |
| Sending service notifications (booking confirmations, expiry reminders, feedback forms) | Performance of a contract; legitimate interests |
| Securing the platform, maintaining audit trails, preventing fraud and misuse | Legitimate interests; compliance with legal obligations |
| Improving the platform through aggregated, anonymised usage analysis | Legitimate interests |
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
We do not sell personal data, and we do not use personal data for direct marketing without your consent. Where data is processed for direct marketing, you have the right to object at any time and we will stop.
06Special categories of data
We do not intentionally collect special categories of personal data as defined in the Act — such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, or genetic and biometric data.
Identity documents and CVs uploaded by trainers should not contain such data beyond what appears on standard identity documents. Where any special category data is incidentally processed, we apply the safeguards required by section 29 of the Act and restrict access to authorised personnel only.
07Children's data
iLeap is a professional platform and is not directed at children. We do not knowingly process the personal data of a child below the age of 16 without the consent of the child's parent or guardian, as required by section 30 of the Act. Organisations entering participant data on the platform are responsible for ensuring this consent exists where a participant is under 16. If you believe a child's data has been provided to us without proper consent, contact us and we will take appropriate action.
09Transfers outside Mauritius
Some of our service providers store data on servers located outside Mauritius. In particular, waitlist and email communication data is processed by MailerLite on servers located in the European Union.
Where personal data is transferred outside Mauritius, we do so in accordance with section 36 of the Act — ensuring appropriate safeguards are in place with respect to the protection of the data, or relying on your explicit consent or another condition permitted by the Act. You may contact us for information on the safeguards applied to any transfer.
10How we protect data
In accordance with section 31 of the Act, we implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, accidental loss and destruction, including:
- Encryption of data in transit and at rest;
- Role-based access control, so users see only the data their role requires;
- Authentication controls on all platform accounts;
- Audit trails recording changes to critical records, which are read-only;
- Regular testing and evaluation of the effectiveness of our security measures;
- Staff awareness of, and contractual commitment to, our security obligations.
For processing likely to present a high risk to the rights and freedoms of data subjects, we carry out data protection impact assessments and consult the Data Protection Office where required by sections 34 and 35 of the Act.
11How long we keep data
We keep personal data only in a form that permits your identification for as long as necessary for the purposes for which it was collected:
- Waitlist data is kept until launch communications conclude or you unsubscribe, whichever is earlier;
- Account data is kept for the duration of your account and deleted or anonymised following closure, subject to any legal retention obligation;
- Training and compliance records are retained for the periods required by the controller organisation's regulatory obligations, after which they are destroyed or anonymised;
- Audit and security logs are retained for as long as needed to secure the platform and demonstrate compliance.
Where the purpose for keeping personal data has lapsed, we destroy the data as soon as reasonably practicable and notify any processor holding it, as required by section 27 of the Act.
12Data breach notification
In the event of a personal data breach, we will notify the Data Protection Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by section 25 of the Act. Where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay, describing the nature of the breach and the measures taken, in accordance with section 26 of the Act.
Where we act as processor, we will notify the controller organisation without undue delay upon becoming aware of a breach.
13Your rights
Under Part VII of the Act, you have the right to:
- Access — obtain confirmation of whether we process your personal data, and receive a copy of it, free of charge at reasonable intervals (section 37);
- Rectification — have inaccurate data corrected and incomplete data completed without undue delay (section 39);
- Erasure — have your data erased where it is no longer necessary, where you withdraw consent, where you object and no overriding grounds exist, or where it was unlawfully processed (section 39);
- Restriction of processing — in the circumstances set out in section 39(5) of the Act;
- Objection — object in writing at any time to processing of your data, including for direct marketing (section 40);
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal (section 24);
- Not be subject to solely automated decisions producing legal or similarly significant effects (section 38).
To exercise any of these rights, write to us at contact@ileap.app. We will respond within one month of receiving your request; this may be extended by a further month for complex or numerous requests, in which case we will inform you. If we refuse a request, we will give you our reasons in writing and inform you of your right to complain.
If you are a minor, or physically or mentally unfit, your rights may be exercised on your behalf by a person with parental authority, a guardian, or a person you have duly authorised in writing.
15Changes to this policy
We may update this policy from time to time to reflect changes to the platform, our practices or the law. The "Last updated" date at the top of this page shows when it was last revised. Where changes are material, we will notify registered users by email or through the platform before they take effect. We encourage you to review this page periodically.
16Contact us
For any question about this policy or how we handle personal data, or to exercise your rights:
- Email: contact@ileap.app
- Post: Data Protection Compliance Officer, Red Peach Ltd, No 98, Royal Road, Morc Ashviva, Trou aux Biches, Mauritius
