Privacy Policy
Last updated: August 27, 2026
At Tolarai.com, we are committed to protecting the privacy and personal data of our users and their members. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and services (collectively, the "Services"). This policy applies to Organization administrators who register for accounts and the Members whose data is managed within those accounts. Please read this policy carefully to understand our data practices.
1. Information We Collect
1.1 Information You Provide Directly
We collect information that you and your Organization provide when registering for and using the Services, including:
- Account information: Organization name, your name, email address, phone number, and role/title.
- Member data: Names, contact details, membership status, payment information, event registrations, CPD records, credentials, and other data your Organization enters to manage its members.
- Billing information: Payment method details (processed securely through our payment partners), billing address, and transaction history.
- Communication data: Content of support requests, feedback, and other communications you send to us.
1.2 Information Collected Automatically
We and our service providers may automatically collect certain technical and usage data when you interact with the Services:
- Device and usage data: IP address, browser type, device information, operating system, access times, pages viewed, and navigation paths.
- Cookies and similar technologies: Session identifiers, authentication tokens, and analytics cookies used to maintain sessions, remember preferences, and understand how the Services are used.
- Log data: Server logs, error reports, and system event logs used for security, troubleshooting, and service improvement.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Services: To create and manage your account, process transactions, deliver subscription features, and provide customer support.
- Member management: To enable your Organization to store, organize, and manage member data, including memberships, events, billing, communications, and reporting.
- Communication: To send account-related notifications, renewal reminders, security alerts, and service updates. With your consent, we may also send marketing and promotional communications, which you can opt out of at any time.
- Improvement and development: To analyze usage patterns, diagnose technical issues, develop new features, and enhance the performance, security, and usability of the Services.
- Security and compliance: To detect, prevent, and respond to fraud, abuse, security incidents, and other violations of our Terms, and to comply with legal obligations.
- Aggregated analytics: To generate anonymized, aggregated statistics about usage trends that do not identify individual users or members.
3. Legal Basis for Processing (GDPR & Data Protection)
Where the General Data Protection Regulation (GDPR) or other data protection laws apply, we process personal data on the following legal bases:
- Contractual necessity: Processing necessary to provide the Services under our Terms of Service and fulfill our contractual obligations to you.
- Legal obligation: Processing required to comply with applicable laws, regulations, or government requests.
- Legitimate interests: Processing necessary for our legitimate business interests, such as security, fraud prevention, and service improvement, balanced against your rights and freedoms.
- Consent: Processing based on your explicit consent for activities such as marketing communications or optional analytics, which you may withdraw at any time.
4. Data Sharing & Disclosure
We do not sell your personal data or member data to third parties. We may share information in the following circumstances:
- Service providers: We engage trusted third-party vendors and subprocessors (e.g., cloud hosting providers, payment processors, email delivery services, analytics providers) who process data on our behalf under written agreements requiring confidentiality and data protection.
- Organization administrators: Your Organization's administrators have access to the member data stored within their account. Tolarai.com acts as a data processor on behalf of your Organization, which acts as the data controller for its member data.
- Legal requirements: We may disclose information when required by law, court order, or government authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or security incidents.
- Business transfers: In connection with a merger, acquisition, reorganization, or sale of all or part of our business, information may be transferred to the successor entity, subject to the protections of this policy.
- With your consent: We may share information with third parties when you authorize or request us to do so, such as through third-party integrations you connect to your account.
5. International Data Transfers
The Services are hosted on cloud infrastructure that may process and store data in countries other than your own, including the United States and other regions where our service providers operate. We ensure that international transfers of personal data are conducted in compliance with applicable data protection laws, including through appropriate safeguards such as Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms. Your use of the Services constitutes acknowledgment that your data may be transferred to and processed in these jurisdictions.
6. Data Retention
We retain your personal data and member data only for as long as necessary to fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Active accounts: Data is retained for the duration of your subscription and any associated grace or transition period.
- Terminated accounts: Upon account termination, we provide a limited period (typically 30-90 days) for data export before permanently deleting Your Data, unless retention is required by law.
- Transaction records: Billing and financial records may be retained for up to seven (7) years to comply with tax and accounting requirements.
- Log and usage data: Technical logs are retained for a shorter period (typically 12 months) for security and troubleshooting purposes.
When data is no longer needed, we securely delete or anonymize it in accordance with our data retention and deletion policies.
7. Data Security
We implement industry-standard technical, organizational, and physical security measures designed to protect your data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest where applicable;
- Role-based access control and least-privilege principles for internal staff and service providers;
- Regular security assessments, vulnerability scanning, and penetration testing;
- Audit logging and monitoring of system activity for suspicious behavior;
- Secure development practices and regular software updates;
- Data backup and disaster recovery procedures.
Despite these measures, no system is completely secure. In the event of a data breach affecting your personal data, we will notify affected users and relevant authorities as required by applicable law, typically within 72 hours of becoming aware of the breach.
8. Your Privacy Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete personal data.
- Erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Restriction: Request that we limit the processing of your personal data under certain circumstances.
- Data portability: Request a copy of your personal data in a structured, machine-readable format for transfer to another service.
- Objection: Object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
- Withdrawal of consent: Withdraw consent for processing based on consent at any time, without affecting the lawfulness of processing prior to withdrawal.
- Lodge a complaint: Lodge a complaint with your local data protection authority if you believe your rights have been violated.
To exercise any of these rights, please contact us through the methods described in Section 11. We will respond to your request within the timeframe required by applicable law (typically 30 days). Please note that certain rights may be limited where compliance would adversely affect the rights of others, conflict with legal obligations, or compromise the security of the Services.
9. Cookies & Tracking Technologies
We use cookies and similar technologies (e.g., web beacons, local storage) to operate and improve the Services, maintain sessions, remember preferences, and analyze usage. Types of cookies we use include:
- Essential cookies: Required for the basic functionality of the Services, such as authentication and session management. These cannot be disabled if you wish to use the Services.
- Functional cookies: Remember your preferences, such as language and theme selections.
- Analytics cookies: Help us understand how the Services are used, so we can improve performance and usability.
- Marketing cookies: Used, with your consent, to deliver relevant content and advertising.
You can manage or disable non-essential cookies through your browser settings or our cookie preferences tool where available. Disabling certain cookies may affect the functionality of the Services. For more details, please review our cookie notice or contact us.
10. Your Organization's Responsibilities
As an Organization administrator, you are the data controller for the member data you store within the Services, and Tolarai.com acts as your data processor. You are responsible for:
- Obtaining valid consent from your Members for the collection, processing, and storage of their personal data;
- Ensuring that you have a lawful basis for processing Member data and that your use of the Services complies with applicable data protection laws;
- Maintaining a privacy policy or notice for your Members that accurately describes how their data is used;
- Responding to your Members' data rights requests and providing necessary information about the processing of their data;
- Ensuring the accuracy and lawfulness of the data you upload to the Services.
Tolarai.com provides tools to help you manage data, including export, deletion, and audit features. We recommend using these tools to fulfill your data protection obligations.
11. Children's Privacy
The Services are not designed for or directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe that a child has provided us with personal data, please contact us so we can promptly delete it. Organizations that manage youth members are responsible for obtaining parental or guardian consent as required by applicable law before collecting or processing any personal data of minors.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the Services we offer. We will notify you of material changes by posting the updated policy on this page and, where appropriate, by email or in-app notification. The effective date at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically. Your continued use of the Services after any changes take effect constitutes your acceptance of the updated policy.
13. Third-Party Links & Services
The Services may contain links to third-party websites, services, or integrations that are not operated by us. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party services you access through or in connection with our Services. This Privacy Policy does not apply to data collected by third parties.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection Officer or support team through:
- Email: privacy@tolarai.com
- Support portal: Available within the Tolarai.com application under Help & Support
We are committed to working with you to resolve any privacy concerns and will make every effort to respond to your inquiries promptly and transparently.
15. Governing Law
This Privacy Policy is governed by the laws of Papua New Guinea, without regard to its conflict of law provisions. Any disputes arising from or relating to this policy shall be resolved in accordance with the dispute resolution provisions set out in our Terms of Service.