Purpose

Nvidya is committed to protecting the confidentiality, integrity, and availability of all information collected, stored, and processed through its e-learning platform. This policy establishes the framework to safeguard user data, course materials, and platform resources from security threats, ensuring a secure learning environment for all users.

 

Scope

This policy applies to all Nvidya employees, contractors, third-party service providers, and users who access or manage data, content, or systems associated with the Nvidya platform

 

Data Protection

  • Personal Data: All personal information of learners, instructors, and employees is collected and processed in compliance with applicable data protection laws. Sensitive data such as payment information and identity documents are handled with heightened security measures.
  • Data Minimization: Only data essential for platform functionality and service delivery is collected.
  • Encryption: Sensitive data is encrypted both at rest and in transit using industry-standard protocols such as TLS for data transmission and AES-256 for stored data.
  • Anonymization: Where possible, user data used for analytics and reporting is anonymized to protect privacy.
 

Access Control

  • Role-Based Access: Access to platform resources and user data is controlled by role-based permissions. Users, instructors, administrators, and support staff are granted the minimum necessary access based on their roles.
  • Authentication: Strong authentication mechanisms including mandatory Multi-Factor Authentication (MFA) are enforced for all administrative and instructor accounts, as well as for users accessing sensitive sections of the platform.
  • Session Management: User sessions are monitored and automatically timed out after periods of inactivity to prevent unauthorized access.
 

Platform Security

  • Secure Development: Nvidya’s platform is developed following secure coding practices, including regular code reviews and security testing to identify and fix vulnerabilities.
  • Vulnerability Management: Regular vulnerability scanning and penetration testing are performed to detect and remediate potential security weaknesses.
  • Third-Party Components: All third-party software libraries and plugins used are vetted for security compliance and kept up to date to avoid exploitation.
 

Network & Infrastructure Security

  • Firewall and IDS/IPS: Network traffic is protected by firewalls and Intrusion Detection and Prevention Systems (IDS/IPS) to block unauthorized access and detect malicious activities.
  • DDoS Protection: Systems are equipped with Distributed Denial of Service (DDoS) mitigation to maintain service availability during attack attempts.
  • Data Backups: Regular backups of critical data and course content are performed, encrypted, and stored securely to enable recovery in the event of data loss or ransomware attacks.
 

Incident Response and Reporting

  • Monitoring: Continuous monitoring tools track platform activity and logs to identify suspicious behavior or breaches.
  • Incident Handling: A formal incident response plan guides the detection, containment, investigation, mitigation, and communication of security incidents.
  • User Notification: In case of a data breach involving user information, affected individuals will be notified promptly in accordance with legal requirements.
 

Users Responsibilities

  • Users must protect their login credentials and notify Nvidya immediately of any suspected account compromise.
  • Users should avoid sharing accounts and ensure their devices are secured with up-to-date software and antivirus protection.
  • All users are encouraged to follow best practices in password management and privacy settings.
 

Employee Training & Awareness

  • Nvidya conducts regular security awareness training for all employees and contractors, covering topics such as phishing prevention, data handling, and incident reporting. Training materials are updated to reflect the latest security trends and regulatory requirements.
 

Third Party and Vendor Security

All vendors and service providers with access to Nvidya’s data or infrastructure must comply with this security policy and undergo regular security assessments. Data sharing agreements and confidentiality clauses are in place to ensure third parties maintain the same level of protection.

 

Physical Security

  • Access to Nvidya’s physical offices and data centres is controlled by security protocols such as badge access, visitor logs, and surveillance systems to prevent unauthorized entry.
  • Devices storing sensitive data are secured in locked environments with restricted access.
 

Data Retention & Disposal

Data retention periods comply with legal and operational requirements; data no longer needed is securely deleted or anonymized to prevent unauthorized recovery. Secure disposal methods such as shredding of physical documents and data wiping of electronic storage devices are enforced.

 

Compliance and Legal Requirements

Nvidya complies with applicable data protection laws such as GDPR, CCPA, and other relevant regulations based on user location. Regular audits and assessments ensure ongoing adherence to legal and industry standards.

 

Policy Review

This security policy is reviewed at least annually or when significant changes occur in technology, operations, or regulations. Updates will be communicated to employees and stakeholders promptly.

Contact and Reporting
For any security concerns, questions, or to report a suspected security incident, please contact:
Security Team
Email: getintouch@nvidya.net