Privacy Policy

How StudyAML collects, uses, and protects personal information across our website and platform.

Last updated: June 2026

01 Introduction

This Privacy Policy explains how StudyAML collects, uses, stores, shares, and protects personal data when you visit our website, request a demonstration, communicate with us, use our platform, or otherwise interact with our services.

StudyAML provides compliance training, regulatory learning solutions, platform functionality, reporting tools, and related services for regulated organisations.

We are committed to handling personal data lawfully, fairly, transparently, and securely.

This Privacy Policy should be read together with our Cookie Policy, Terms of Use, Accessibility Statement, Demo Confidentiality and Limited Use Terms, and any applicable customer agreement, data processing agreement, platform terms, or service terms.


02 Who We Are

StudyAML is owned and operated by VYKN UK LTD.

VYKN UK LTD is a company incorporated in England and Wales under company uichemy-faqs-parte-1-3-u2__section-numer 17214840, incorporated on 12 May 2026, with its registered office at:

9 Greyfriars Road, Reading, England, RG1 1NU

StudyAML intellectual property is owned by VYKN IP LTD and licensed to VYKN UK LTD for commercial operation.

VYKN IP LTD is a company incorporated in England and Wales under company uichemy-faqs-parte-1-3-u2__section-numer 17215244, incorporated on 12 May 2026, with its registered office at:

9 Greyfriars Road, Reading, England, RG1 1NU

VYKN IP LTD does not operate the StudyAML website or platform unless expressly stated otherwise. Its role is as owner and licensor of StudyAML intellectual property, including platform concepts, training methodologies, course content, learning designs, reporting structures, product designs, trade marks, copyright materials, proprietary systems, and related rights.

For the purposes of this Privacy Policy, references to “StudyAML”, “we”, “us”, or “our” mean VYKN UK LTD trading as StudyAML, unless the context requires otherwise.

Contact details:

StudyAML VYKN UK LTD, 9 Greyfriars Road, Reading, England, RG1 1NU.

Company uichemy-faqs-parte-1-3-u2__section-numer: 17214840 · Email: contact@vykn.com · Website: www.StudyAML.com

03 Our Role Under Data Protection Law

For the purposes of applicable data protection laws, including the UK General Data Protection Regulation, the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation, VYKN UK LTD may act as either a data controller or a data processor.

We act as a data controller where we determine the purposes and means of processing personal data. This may include processing personal data relating to website visitors, business contacts, demo requests, prospective clients, marketing contacts, suppliers, partners, professional advisers, and general enquiries.

We may act as a data processor where we process personal data on behalf of a client organisation using the StudyAML platform. This may include learner accounts, training assignments, course progress, assessment results, certificates, and training records.

Where VYKN UK LTD acts as a processor, the relevant client organisation will usually be the controller of the personal data processed through the platform. In those circumstances, the client organisation is responsible for determining the lawful basis for processing and for providing appropriate privacy information to its employees, contractors, directors, officers, or other learners.

04 Scope of This Privacy Policy

This Privacy Policy applies to personal data processed in connection with:
  • our website
  • enquiries submitted through website forms
  • demo bookings and scheduling tools
  • sales and commercial discussions
  • newsletters, marketing communications, and events
  • client onboarding
  • use of the StudyAML platform
  • learner accounts and training records
  • training assignments, assessments, certificates, and reporting
  • customer support
  • bespoke training development
  • white label training arrangements
  • supplier, partner, adviser, and professional relationships
  • protection of StudyAML proprietary systems and intellectual property; and
  • legal, regulatory, security, contractual, and administrative purposes

This Privacy Policy does not apply to third party websites, services, or platforms that we do not control.


05 Personal Data We Collect

The personal data we collect depends on how you interact with StudyAML.
Website Visitors

When you visit our website, we may collect:

  • IP address
  • browser type and version
  • device information
  • operating system
  • pages visited
  • referral source
  • approximate location
  • date and time of visit
  • cookie identifiers
  • website usage information
  • analytics data; and
  • technical logs

Further information about cookies and similar technologies is set out in our Cookie Policy.


Demo Requests and Enquiries

When you submit an enquiry or request a demo, we may collect:

  • name
  • job title
  • organisation name
  • business email address
  • telephone uichemy-faqs-parte-1-3-u2__section-numer
  • website address
  • industry or sector
  • jurisdiction or jurisdictions of operation
  • estimated uichemy-faqs-parte-1-3-u2__section-numer of users
  • training interests
  • timing of consideration
  • current training challenges
  • reasons for interest in StudyAML
  • preferred contact method
  • meeting availability
  • information relating to whether your organisation provides competing or related services
  • confidentiality and limited use acknowledgements; and
  • any additional information you provide through forms, emails, calls, video meetings, or other communications

Demo Scheduling Information

Where we use a third party scheduling tool, such as Calendly or a similar service, we may collect or receive:

  • meeting date and time
  • time zone
  • attendee name
  • email address
  • organisation
  • meeting notes
  • responses to booking questions
  • cancellation or rescheduling information; and
  • technical or usage data generated by the scheduling tool

The scheduling provider may also process personal data in accordance with its own privacy policy.


Client and Prospect Contacts

When we communicate with prospective clients, clients, partners, suppliers, advisers, and other business contacts, we may collect:

  • name
  • role
  • organisation
  • business contact details
  • correspondence records
  • meeting notes
  • commercial requirements
  • procurement information
  • contract information
  • billing and payment information
  • proposal history
  • account management information; and
  • records of communications, approvals, negotiations, and decisions

Platform Users and Learners

Where individuals use the StudyAML platform, we may process:

  • name
  • business email address
  • employer or organisation
  • department or business unit
  • role or learner category
  • jurisdiction or training assignment category
  • user account details
  • course enrolments
  • assigned learning pathways
  • course progress
  • training completion records
  • assessment answers and scores
  • pass or fail status
  • certificates
  • login activity
  • learning activity
  • system usage data
  • technical logs
  • support communications; and
  • administrator notes or configuration data, where applicable

Depending on the platform features enabled, StudyAML may also generate learning analytics, engagement indicators, completion trends, training effectiveness indicators, and reporting outputs for compliance oversight and training management purposes.


Client Administrators

Where an individual acts as a client administrator or manager within the StudyAML platform, we may process:

  • name
  • job title
  • business email address
  • organisation
  • administrator role
  • permissions
  • login records
  • user management activity
  • training assignment activity
  • reporting activity; and
  • support communications

Bespoke Training Projects

Where we develop bespoke training, we may process:

  • business contact information
  • project correspondence
  • internal policies and procedures provided by the client
  • training objectives
  • governance structures
  • remediation themes
  • role descriptions
  • case studies or scenarios
  • stakeholder comments
  • review notes; and
  • other project materials provided by the client

Clients should avoid providing personal data in bespoke training materials unless it is necessary and lawful to do so.


Marketing and Events

If you subscribe to updates, attend an event, download a resource, or engage with our marketing, we may collect:

  • name
  • business email address
  • organisation
  • job title
  • sector
  • jurisdiction
  • preferences
  • engagement history
  • resource download activity
  • event attendance information; and
  • marketing consent or opt out records

Suppliers, Contractors, and Professional Advisers

Where we engage or communicate with suppliers, contractors, consultants, advisers, and service providers, we may process:

  • business contact details
  • professional details
  • contractual information
  • payment information
  • correspondence
  • due diligence information; and
  • service delivery records

06 How We Collect Personal Data

We may collect personal data:
  • directly from you when you complete a form, request a demo, schedule a meeting, contact us, attend a meeting, or use the platform
  • from your employer or organisation when it creates or manages learner accounts
  • from client administrators who assign training or manage reporting
  • automatically through cookies, logs, analytics, and platform usage
  • from scheduling tools, CRM systems, email platforms, video meeting tools, and other business systems
  • from public sources, such as professional websites, company websites, business directories, regulatory registers, and Companies House records
  • from referrals, partners, advisers, consultants, or other lawful sources; and
  • from documents or materials provided to us in connection with a client engagement or prospective engagement

This Privacy Policy does not apply to third party websites, services, or platforms that we do not control.

07 How We Use Personal Data

We may use personal data for the following purposes:
Website Operation

To operate, maintain, secure, monitor, and improve our website.


Responding to Enquiries

To respond to enquiries, demo requests, contact forms, emails, calls, and other communications.


Demo Scheduling and Delivery

To arrange, manage, and deliver personalised demonstrations, including scheduling meetings, assessing demo suitability, tailoring the discussion, and following up after the demo.


Protecting Proprietary Materials

To assess whether access to proprietary platform functionality, non public content, learning methodologies, reporting structures, product concepts, or roadmap features should be granted, restricted, or subject to additional confidentiality protections.


Sales and Client Relationship Management

To manage prospective client relationships, prepare proposals, negotiate terms, onboard clients, and provide account management.


Platform Services

To create accounts, assign training, deliver courses, record progress, assess knowledge, issue certificates, generate reports, and provide platform functionality.


Compliance Reporting and Oversight

To support reporting to authorised client administrators, compliance teams, HR teams, managers, senior management, boards, or governance committees, where applicable.


Customer Support

To respond to support requests, troubleshoot issues, manage incidents, maintain service quality, and improve user experience.


Bespoke Training Development

To scope, design, develop, review, approve, and deliver bespoke training programmes.


White Label and Enterprise Services

To configure branded portals, custom learning pathways, reporting structures, client specific content, and enterprise deployment arrangements.


Marketing and Communications

To send newsletters, updates, event invitations, product information, insights, resources, and other communications where permitted by law.


Analytics and Service Improvement

To understand how users interact with our website, platform, content, and services, and to improve functionality, usability, training design, reporting, content, and user experience.


Security and Fraud Prevention

To protect our website, platform, systems, intellectual property, confidential information, users, and clients from misuse, unauthorised access, security threats, fraud, unlawful activity, and competitive misuse.


Legal, Regulatory, and Contractual Purposes

To comply with legal obligations, enforce agreements, manage disputes, preserve evidence, respond to lawful requests, and protect our legal rights and commercial interests.

08 Lawful Bases for Processing

Where VYKN UK LTD acts as a controller, we rely on one or more lawful bases depending on the purpose of processing.
Purpose Lawful Basis
Operating and securing the website Legitimate interests
Responding to enquiries and demo requests Legitimate interests, and where applicable, steps prior to entering into a contract
Scheduling and delivering demos Legitimate interests, and where applicable, steps prior to entering into a contract
Assessing demo access and protecting proprietary materials Legitimate interests
Managing client and prospect relationships Contract performance, legitimate interests, and legal obligations
Preparing proposals and negotiating agreements Steps prior to entering into a contract and legitimate interests
Providing platform services directly to clients Contract performance and legitimate interests
Supporting learner accounts and training records where we act as controller Contract performance, legitimate interests, and legal obligations, depending on the circumstances
Processing learner data on behalf of clients Processor activity carried out under client instructions
Sending service communications Contract performance and legitimate interests
Sending marketing communications Consent or legitimate interests, depending on the circumstances
Website analytics and non essential cookies Consent, where required
Customer support and troubleshooting Contract performance and legitimate interests
Bespoke training development Contract performance and legitimate interests
Maintaining security and preventing misuse Legitimate interests and legal obligations
Complying with law and regulatory requests Legal obligations
Establishing, exercising, or defending legal claims Legitimate interests and legal obligations

Where we rely on legitimate interests, we consider whether our interests are overridden by the rights and freedoms of affected individuals.

Where we rely on consent, you may withdraw consent at any time.

Where we act as a processor for a client, the relevant client determines the lawful basis for processing learner and platform user data.

09 Legitimate Interests

Where we rely on legitimate interests, our interests may include:
  • operating and improving our website and services
  • responding to business enquiries
  • managing commercial relationships
  • delivering demos and sales processes
  • protecting StudyAML proprietary materials and intellectual property
  • preventing misuse, fraud, unauthorised access, and competitive misuse
  • securing our systems and platform
  • maintaining business records
  • developing and improving our content and platform
  • communicating with business contacts
  • enforcing agreements and legal rights; and
  • supporting responsible business administration

We will consider the impact of processing on affected individuals and will not rely on legitimate interests where those interests are overridden by individual rights and freedoms.

10 Special Category Data

StudyAML does not generally seek to collect special category personal data, such as information about health, race, ethnicity, political opinions, religious beliefs, trade union membership, biometric data, genetic data, or sexual orientation.

You should not submit special category data to us unless we specifically request it and there is a lawful basis for doing so.

If special category data is inadvertently provided to us, we will handle it in accordance with applicable data protection laws and may delete it where it is not required.

11 Criminal Offence Data

StudyAML does not generally seek to collect criminal offence data through its website or platform.

If criminal offence data is provided in connection with regulatory training, case studies, remediation materials, or bespoke content development, clients must ensure they are lawfully entitled to provide that information.

Where possible, such information should be anonymised or fictionalised before being provided to StudyAML.

12 Children’s Data

StudyAML is intended for use by organisations and professional users.

Our website and platform are not directed at children, and we do not knowingly collect personal data from children.

If you believe that a child has provided personal data to us, please contact us.

13 Cookies and Similar Technologies

We may use cookies and similar technologies to operate our website, understand website usage, improve user experience, support demo booking functionality, maintain security, and support marketing activity where permitted.

Some cookies may be necessary for website functionality. Others may require consent.

Further information is provided in our Cookie Policy.

14 Sharing Personal Data

We may share personal data with the following categories of recipients where lawful and appropriate:
Client Organisations

Where we provide services to a client organisation, learner data, training records, assessment results, certificates, usage information, and reports may be made available to authorised client administrators, compliance teams, HR teams, managers, senior management, boards, governance committees, or other authorised personnel.


VYKN IP LTD

We may share limited personal data with VYKN IP LTD where necessary to protect, manage, enforce, document, licence, or administer StudyAML intellectual property rights, provided that such sharing is lawful and proportionate.

VYKN IP LTD does not operate the StudyAML website or platform unless expressly stated otherwise.


Service Providers

We may share personal data with trusted service providers who support our business and services, including:

  • website hosting providers
  • platform hosting providers
  • cloud infrastructure providers
  • learning platform providers
  • email and communication providers
  • CRM providers
  • scheduling tools
  • analytics providers
  • customer support tools
  • payment providers
  • IT and security providers
  • video meeting providers
  • cookie consent providers
  • document management providers; and
  • professional service providers

Professional Advisers

We may share personal data with lawyers, accountants, auditors, insurers, consultants, tax advisers, corporate advisers, and other professional advisers.


Legal and Regulatory Authorities

We may disclose personal data where required or permitted by law, including to regulators, courts, law enforcement agencies, government authorities, supervisory bodies, or other competent authorities.


Corporate Transactions

If we are involved in a merger, acquisition, investment, restructuring, financing, sale of assets, transfer of business, insolvency process, or similar transaction, personal data may be disclosed to relevant parties, advisers, investors, funders, insurers, and counterparties, subject to appropriate confidentiality protections.

15 International Transfers

We may transfer personal data to countries outside the United Kingdom or the European Economic Area where our service providers, clients, or business operations require it.

Where required, we will take steps designed to protect personal data in accordance with applicable data protection laws. This may include relying on adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses, or other lawful transfer mechanisms.

Where we use third party tools such as scheduling, analytics, CRM, cloud hosting, video meeting, or communication providers, those providers may process data in jurisdictions outside the United Kingdom or European Economic Area.

16 Data Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction.

These measures may include:
  • access controls
  • authentication controls
  • password protections
  • encryption where appropriate
  • secure hosting arrangements
  • staff confidentiality obligations
  • role based permissions
  • system monitoring
  • logging
  • vendor due diligence
  • backup procedures
  • security review processes; and
  • incident management procedures

No system can be guaranteed to be completely secure.

You are responsible for maintaining the confidentiality of your login credentials and for notifying us promptly of any suspected unauthorised access.

17 Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to provide services, comply with legal obligations, resolve disputes, maintain records, and enforce agreements.

Indicative retention periods include:
Category Indicative Retention Period
Website enquiries and demo requests Up to 24 months from last meaningful interaction, unless a longer period is required
Demo access, confidentiality acknowledgements, and limited use records Up to 6 years from the relevant interaction or longer where required for legal protection
Marketing contact records Until you unsubscribe or object, plus suppression records to respect opt outs
Client contract and account records Duration of the client relationship and up to 7 years thereafter
Platform learner records In accordance with the client agreement or client instructions, and where applicable, regulatory or contractual recordkeeping requirements
Training completion and certificate records In accordance with client requirements, contractual terms, and applicable recordkeeping needs
Support records Up to 6 years, depending on the nature of the issue
Security logs For a limited period appropriate to security, audit, and investigation purposes
Supplier and adviser records Duration of the relationship and up to 7 years thereafter
Legal claims and dispute records As long as necessary to establish, exercise, or defend legal rights

Retention periods may vary depending on legal, regulatory, contractual, operational, or client specific requirements.

Where we act as a processor, retention of learner and platform data will usually be governed by the relevant client agreement, data processing agreement, or client instructions.

18 Your Data Protection Rights

Subject to applicable law and certain exemptions, you may have the following rights:
  • the right to be informed about how your personal data is used
  • the right of access to your personal data
  • the right to request correction of inaccurate or incomplete data
  • the right to request erasure of personal data
  • the right to restrict processing
  • the right to object to processing
  • the right to data portability
  • the right to withdraw consent, where processing is based on consent; and
  • rights relating to automated decision making, where applicable

To exercise your rights, please contact us using the details set out in this Privacy Policy.

Where we process your personal data on behalf of your employer or another client organisation, we may need to refer your request to that organisation.

We may ask you to verify your identity before responding to a request.

19 Automated Decision-Making and Learning Analytics

StudyAML may use assessment results, completion data, training activity, and learning analytics to support reporting, oversight, training effectiveness reviews, and training management.

StudyAML does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

Client organisations remain responsible for how they use training records, assessment data, analytics, and reports in their internal governance, HR, compliance, management, regulatory, or employment processes.

20 Marketing Communications

We may send marketing communications to business contacts where permitted by law.

You may unsubscribe from marketing communications at any time by using the unsubscribe link in our emails or contacting us directly at contact@vykn.com.

We may continue to send service related communications that are necessary for the performance or administration of our services.

21 Third Party Links, Tools, and Services

Our website or platform may contain links to third party websites, tools, or services.

These may include scheduling tools, video meeting platforms, analytics providers, CRM tools, social media platforms, payment tools, embedded video providers, or other external services.

We are not responsible for the privacy practices, content, security, or availability of third party websites or services.

You should review the privacy policies of any third party services you use.

22 Client Responsibilities

Where a client organisation provides personal data to StudyAML or uses the StudyAML platform to manage learners, the client is responsible for ensuring that it has a lawful basis for doing so and that relevant individuals receive appropriate privacy information.

Clients are also responsible for ensuring that:
  • learner information is accurate and up to date
  • user access permissions are appropriate
  • training assignments are lawful and appropriate
  • internal reporting structures are appropriate
  • personal data included in bespoke training materials is lawful and necessary; and
  • internal use of training records, assessments, analytics, and reports complies with applicable law

23 Data Processing Agreements

Where VYKN UK LTD processes personal data on behalf of a client organisation, the processing will be governed by appropriate contractual terms, which may include a data processing agreement.

Such terms may address matters including:
  • subject matter and duration of processing
  • nature and purpose of processing
  • categories of personal data
  • categories of data subjects
  • client instructions
  • confidentiality
  • security measures
  • sub processors
  • international transfers
  • assistance with data subject rights
  • personal data breach notification
  • deletion or return of data; and
  • audit and compliance information

24 Complaints

If you have concerns about how we handle your personal data, please contact us first so that we can try to resolve the matter.

Contact:
StudyAML VYKN UK LTD, 9 Greyfriars Road, Reading, England, RG1 1NU.
Email: contact@vykn.com

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection matters.

Information Commissioner’s Office
Website: www.ico.org.uk
Telephone: 0303 123 1113

If you are located outside the United Kingdom, you may also have the right to complain to your local data protection authority.

25 Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

The updated version will be published on our website with a revised “Last updated” date.

Where changes are material, we may take additional steps to notify affected individuals where appropriate.

26 Contact Us

If you have any questions about this Privacy Policy or how we handle personal data, please contact:

StudyAML VYKN UK LTD, 9 Greyfriars Road, Reading, England, RG1 1NU.

Company uichemy-faqs-parte-1-3-u2__section-numer: 17214840 · Email: contact@vykn.com · Website: www.StudyAML.com

Smarter Learning. Stronger Compliance.
Better Decisions.

Questions about your data?

Our team is happy to walk through how StudyAML handles personal information across your training programme.