Responsive image

 

General terms and conditions of use

 

By using the SpotLMS.com website ('Service'), you acknowledge that you accept the following terms and conditions ('Terms of Use').

The Terms of Use, available in the customer account creation form, must be read and validated before creating a Customer account in the SpotLMS service, and constitute the Agreement between Cyrus RH ("We," "Provider" or "SpotLMS"), and “You” (the “Customer”) ordering the “Services.” Cyrus RH means the company Cyrus RH SAS, party to this Agreement, being a company based in FRANCE and having its registered office at 21 rue Marc Donadille, 13013 Marseille, FRANCE, SIREN 447 803 354. “Services” means the learning management solution accessible via the Internet and hosted by SpotLMS, made available to you on a SAAS basis through a website URL (“Portal”). An Authorized User means any employee, contractor, agent or any other person of the Customer authorized by the Customer to access and use the Services, via the subscriptions purchased or free by the Customer, for the purposes specified herein. The Customer is responsible for ensuring that Authorized Users comply with this Agreement.

Cyrus RH reserves the right to update and modify the 'Terms of Use' without prior notice. Any new features that increase or improve the current service, including the availability of new tools or resources, will be subject to the Terms of Service. Continued use of the Service after such changes constitutes user consent to those changes. You can review the latest version of the Terms of Service by visiting 'Terms of Use'.

Failure to comply with any of the terms below will result in termination of your account. Although SpotLMS prohibits such conduct and such content on the Service, you understand and agree that SpotLMS cannot be held responsible for Content displayed on the Service and that you may nonetheless be exposed to such information. You agree to use the Service at your own risk.

Account Conditions

  1. You must be a human being. Accounts created by bots or other automated methods are not permitted.
  2. You must provide your real first and last name, a valid email address, and any other information requested in order to complete the registration process.
  3. Your login may be used by only one person — a single login shared by multiple people is prohibited. You may create separate logins for as many people as your plan allows.
  4. You are responsible for maintaining the security of your account and password. Cyrus RH cannot and will not be responsible for any loss or damage resulting from your failure to comply with this security obligation.
  5. You are responsible for all Content posted on the site and for any activity that occurs under your account (even when Content is posted by other people who have accounts under your account).
  6. An individual or legal entity may not maintain more than one free account.
  7. You may not use the Service for any illegal or unauthorized purpose. You may not, through your use of the Service, violate the laws of your jurisdiction (including but not limited to copyright laws).

Payments, Refunds, Plan Changes

  1. A valid credit card or PayPal account is required for payments. It is not necessary to provide a credit card number or other means of payment for free accounts.
  2. The service is billed in advance on a monthly or annual basis and is non-refundable. There will be no refunds or credits for use during any partial month or year. To ensure equal treatment for all customers, no exceptions will be made.
  3. Prices do not include taxes, fees, or duties imposed by tax authorities; you will be responsible for paying any such tax, fee, or duty.
  4. Any change to your plan requires a credit card or PayPal account.
  5. Downgrading your service may result in the loss of content, features, or capacity in your account. Cyrus RH disclaims any responsibility for such loss.
  6. Upgrading from a paid plan to a more complete plan is possible at any time. The cost of the new plan will be reduced by the unused amount of the current plan in proportion to the remaining time.
  7. Switching from a paid plan to a lower or free plan will not give rise to a refund. It will take effect immediately if conditions permit. If the number of courses/users exceeds the number allowed in the new plan selected, the change cannot occur until the account administrator removes the courses/users necessary to activate the new plan.
  8. At the end of a paid plan that is not renewed, the account will be changed to the free plan. If the conditions do not allow this (too many courses or users) the account will be blocked; the account administrator must contact a Cyrus RH representative by email to proceed with unblocking.

Cancellation and Termination

  1. You are solely responsible for properly canceling your account. A request by email or by phone to cancel your account is not considered “cancellation.” A page within the Service provides a simple cancellation link.
  2. If you cancel the Service before the end of the current paid period, your termination will take effect immediately. You permanently forfeit any possibility of a refund for the remaining period.
  3. Cyrus RH has the right to suspend or terminate your account and refuse any current or future use of the Service for any reason, at any time and without notice, in the following cases: (a) fraud, hacking, criminal act, gross negligence, deliberate or unintentional misconduct, violation of a law or regulation, in the performance of your obligations hereunder, and/or (b) demonstrated use having a negative impact on Service performance and/or (c) violation of the terms and conditions of this Service. Such termination of the Service will result in the deactivation or deletion of your account or your access to your account, and the forfeiture and abandonment of all content in your account.
  4. For a paid subscription, SPOT LMS proceeds with immediate performance of the service upon validation of your order and, as such, you expressly waive your right of withdrawal in accordance with the provisions of Article L.221-28 1° of the French Consumer Code.

Service Modifications and Pricing

  1. Prices of all services, including, but not limited to, monthly/annual subscription fees for the Service, may be changed with 30 days’ notice initiated by Cyrus RH. Such notice may be provided at any time by posting pricing changes on the site.
  2. Cyrus RH will not be liable to you or to any third party for any modification, price change, suspension, or discontinuance of the Service.

Content and Personal Data

  1. You own all content (including personal data) that you and Authorized Users have entered for the purpose of using the Services, and you are solely responsible for the legality, reliability, integrity, accuracy, and quality of the content. SpotLMS may suspend or terminate the use of the Services and this Agreement immediately upon receipt of a notice alleging that You and/or the Authorized User used the Services for purposes that violate any local, state, governmental, or other nations’ laws, including, but not limited to, posting information that may violate the rights of third parties, may defame a third party, may be obscene or pornographic, may harass or assault others, or may violate computer hacking laws or other criminal regulations, etc. You acknowledge and agree that our performance of this Agreement requires us to process, transmit, and store Personal Data in compliance with the constraints described in the “Personal Data Protection Policy,” which forms an integral part of this Agreement.
  2. You also acknowledge and agree that We process data relating to Your users that are collected and used by Us, as well as connection data created by the use and operation of the Services, in order to administer or manage Our provision of Services on Your account. Such data may include personal data and information on contractual engagements between Us and You, whether collected at the time of initial registration or thereafter in the context of providing, managing, or administering the Services, including billing and payment collection. You acknowledge and agree that We also process Personal Data that We collect when You submit a request for support or troubleshooting services, including information about the Service, Your Portal, and other details relating to the support incident, such as authentication information, Service status information, and error logs. We process this Personal Data to respond to the request and resolve the reported issue.
  3. We will process the aforementioned Personal Data for the duration of our business relationship in compliance with legal obligations.
  4. You hereby acknowledge and agree that we will use your name and email address to communicate with you for the purposes of Service delivery and the promotion of new services. You may, at any time and at no cost, unsubscribe from these electronic communications by clicking the “unsubscribe” button contained in the electronic communication. You acknowledge that certain priority messages cannot be subject to unsubscribe, such as an alert prior to account deletion, a payment required to avoid Service suspension, etc.

Cookies

  1. We use cookies to ensure persistent login sessions to the Service. By continuing to browse, you agree to the use of cookies. It is not possible to use the Service without cookies.

Copyright and Content Ownership

  1. We do not claim any intellectual property rights over the content you provide to the Service. Your profile and uploaded content remain yours.
  2. Cyrus RH does not pre-review your content, but Cyrus RH has the right (but not the obligation), at its sole discretion, to refuse or remove any content available via the Service.
  3. The following is considered inappropriate content in the context of sending, uploading, sharing, submitting, or using content: a) content that infringes SpotLMS’s or a third party’s intellectual property, property rights or other rights, including copyrights, trademarks, patents, trade secrets, intellectual property rights, publicity rights, or any other proprietary right, b) content you do not have the right to use, c) content that is misleading, fraudulent, illegal, obscene, defamatory, threatening, harmful to minors, pornographic (including pedophilia, which we will remove and report to the police), indecent, harassing, hateful, encouraging illegal or criminal behavior, or otherwise inappropriate, d) attacks on others based on race, ethnicity, national origin, religion, gender, sexual orientation, disability, or medical condition, e) content containing viruses, bots, worms, scripts, exploits, cryptocurrency mining or other similar items, f) content intended to be provocative, g) content that could otherwise cause damage to SpotLMS or a third party.
  4. The visual identity, look and feel, and SPOT LMS logo of the Service are protected by copyright. You may not reproduce, copy, or reuse any part of the HTML/CSS, JavaScript, or graphic elements without the express written authorization of Cyrus RH.

General Conditions

  1. Your use of the Service is at your own risk. The Service is provided on an “as is” and “as available” basis.
  2. Technical support is provided only to paying account holders and is available solely via email or chat.
  3. You understand that Cyrus RH uses third parties, distributors, and providers to supply the hardware, software, networks, storage, hosting, and related technologies required to operate the Service.
  4. You must not modify, adapt, or hack the Service or modify another site for the purpose of falsely implying that the site is associated with the Service.
  5. You agree not to make false statements about yourself, nor to conceal the origin of content (including by “spoofing,” “phishing,” header manipulation or other identifiers, impersonating someone else, or falsely implying sponsorship or association with SpotLMS or any third party).
  6. You agree not to reproduce, duplicate, copy, sell, resell, or exploit any part of the Service, the use of the Service, or access to the Service without the express written authorization of Cyrus RH.
  7. You agree not to violate the privacy of others, including their posts or private and confidential discussions without their express permission, and not to collect personal information about other people (including account names or usernames) from the SpotLMS Service.
  8. We may, but are under no obligation to, remove content and accounts containing content that we determine, at our sole discretion, to be illegal, offensive, threatening, defamatory, pornographic, obscene or objectionable, or that violates intellectual property or any part of the Terms of Service.
  9. We reserve the right to contact you from time to time by email. You may easily remove yourself from the corresponding mailing list.
  10. Any verbal, physical, written or other abuse (including threats of violence) of any customer, employee, or member of Cyrus RH will result in immediate account termination.
  11. SpotLMS will not permit: (a) compromising the integrity of our systems. This may include probing, scanning or testing the vulnerability of any system or network that hosts our services; (b) tampering with the Services or their data, reverse-engineering or hacking our services, unauthorized modification of Service data, bypassing any security or authentication measure, or attempting to obtain unauthorized access to the services, systems, networks or related data; (c) altering, disabling or compromising the integrity or performance of the services, systems, network or data or related services; (d) decrypting or tampering with transmissions to or from the servers used to operate the Services; (e) overloading or attempting to overload our infrastructure by creating an unreasonably large load on our systems and resources (CPU, memory, disk space, bandwidth, etc.).
  12. You must not upload, display, host, or transmit unsolicited emails, SMS, or “Spam” messages.
  13. You must not transmit computer viruses or any malicious code.
  14. You must not use meta-tags or any other “hidden text,” including the names and trademarks of SpotLMS or its providers.
  15. You must not access SpotLMS services, tools, features, data, etc., by any means other than ours, via the web interface or the Service’s standard API.
  16. Cyrus RH does not warrant that (i) the Service will meet your specific needs, (ii) the Service will be uninterrupted, secure, or error-free, (iii) the results that may be obtained from the use of the Service will be accurate or reliable, (iv) the quality of any products, services, information, or other materials purchased or obtained by you through the Service will meet your expectations, and (v) errors in the Service will be corrected.
  17. You expressly understand and agree that Cyrus RH shall not be liable for any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to damages for loss of profits, goodwill, use, data or other intangible losses resulting from: (i) your use of or inability to use the Service; (ii) the cost of acquiring substitute goods and services resulting from any goods, data, information or services purchased or obtained through the Service; (iii) unauthorized access to or alteration of your transmissions or data; (iv) statements or conduct of any third party on the Service; or (v) any other matter relating to the Service.
  18. The failure of Cyrus RH to exercise or enforce any right or provision of the Terms of Service shall not constitute a waiver of such right or provision. The Terms of Service constitute the entire agreement between you and Cyrus RH and govern your use of the Service, superseding any prior agreement between you and Cyrus RH (including, but not limited to, all previous versions of the Terms of Service).
  19. SpotLMS (in its sole discretion) determines that a user has violated these Terms of Use.
  20. Questions regarding the Terms of Service should be sent to: contact at spotLMS dot com

Online Storage Space and SpotDrive

The online storage space is intended for all data related to your Spot LMS account, including your course resources, user data, dedicated videos, virtual class recordings, shared documents, as well as files uploaded and organized via SpotDrive.

Storage capacity: The available volume depends on the subscribed plan. As an indication, for shared hosting (excluding dedicated servers), the distribution is as follows:

  • 100 GB: chats and shared documents (chat server),
  • Plan-dependent: dedicated videos (streaming server),
  • 100 GB: virtual class recordings,
  • 100 GB: video conferences,
  • 100 GB: course resources, user data and SpotDrive documents.
  • Access rights: SpotDrive allows you to upload, organize and share your training documents, with fine-grained access rights management by user profile.
  • Quota overage: When the allocated quota is reached, adding new content may be restricted or suspended until space is freed or additional storage is purchased.
  • Responsibility: The Customer remains solely responsible for the legality, compliance and relevance of stored and shared documents. Cyrus RH disclaims any liability in the event of data loss, unauthorized access or misuse of documents.
  • Scalability: Cyrus RH reserves the right to adapt, limit or suspend SpotDrive or any other storage service for technical, security or legal compliance reasons, without compensation to the Customer.

For dedicated server plans, the storage volume is adapted to your needs by sizing servers according to your resources.

Virtual Class Capacity

Virtual classes make it possible to organize synchronous training sessions with a group of learners, simulating an in-person classroom setup. The number of virtual classes is limited to a certain number per month depending on the subscribed plan. The reset occurs at the beginning of the calendar month. Virtual classes are very resource-intensive in terms of CPU and bandwidth. Excessive use of virtual classes by a single customer on a shared server could prevent other customers from using this service, thereby causing prejudice. To avoid this situation, the number of concurrent virtual classes is limited. The limitation depends on the subscribed plan. Example: if the plan limits parallel launches of virtual classes to 2, it will not be possible to launch a third virtual class if 2 virtual classes are already in progress. We recommend properly closing a virtual class to free up a slot for launching another one; otherwise, a virtual class will automatically close 6 hours after it starts. If your need exceeds the limits of existing plans, you can request a plan tailored to intensive use by setting up a dedicated virtual class server.

REST API Transaction Limits

The SPOT LMS course server is used by many users. We impose limits on API requests to protect the system from receiving more data than it can handle and to ensure a fair distribution of resources among users.
Limits depend on server characteristics, its load as determined by the number of users present on the server, their activities, etc.
The limit is defined as the maximum number of API transactions possible during the last 10 seconds. It is specific to each server. It is returned during a Token-type API call.
If you need to make more API requests than the imposed limit, you must use a more powerful server within an appropriate commercial plan.

Use of Artificial Intelligence (AI) Services

As part of certain commercial plans, Spot LMS provides features based on Artificial Intelligence, including the generation of course modules, advanced progress logs with archiving in reports and availability to learners, as well as the automatic creation of multiple-choice questionnaires (MCQs) and Q&A content.

  • Monthly quota: Use of these features is strictly limited to a monthly volume of requests, varying according to the subscribed plan. Exceeding the quota results in temporary suspension of said features until the reset at the beginning of the calendar month, unless an add-on is purchased.
  • Customer responsibility: AI-generated content and reports are produced automatically and provided as assistance tools. The Customer is solely responsible for verifying their accuracy, relevance and compliance before any pedagogical use or distribution to learners.
  • No warranty: Cyrus RH does not guarantee the reliability, completeness or suitability of the generated content with respect to the Customer’s pedagogical or legal objectives. Use of such content is at the Customer’s own risk.
  • Disclaimer of liability: Under no circumstances shall Cyrus RH be held liable, on any grounds whatsoever, for direct or indirect consequences resulting from the use of AI features, including but not limited to any error, omission, regulatory non-compliance, infringement of third-party rights, or any material, immaterial, commercial or reputational damage.
  • Compliant use: The Customer undertakes to use AI features only in compliance with applicable laws and regulations, intellectual property rights and legitimate pedagogical practices. Any abusive, diverted or non-compliant use may result in suspension or termination of the account.
  • Scalability: Cyrus RH reserves the right to modify, limit or interrupt all or part of the AI features at any time, in particular for reasons of legal compliance, security or technical performance, without giving rise to any right to compensation for the Customer.
Last updated: 03/10/2025

 

Privacy Policy

 

Introduction

SPOT LMS is committed to a continuous process of compliance with the General Data Protection Regulation of 27 April 2016. With this new regulation SPOT LMS reinforces its policy of personal data protection so that the data of our customers is protected. users are collected and used in a transparent, confidential and secure manner.

Personal data protection policy from 25 May 2018

Our Personal Data Protection Policy describes the how SPOT LMS processes the personal data of visitors and users (hereinafter referred to as "SPOT LMS"). after the "Users") when browsing our site www.spotlms.com (hereinafter the "Site"). The Personal Data Protection Policy is an integral part of the General Conditions of Use of the Site.

SPOT LMS pays constant attention to our Users' data. We can thus be to modify, supplement or update the Privacy Policy. We're here to help We invite you to regularly consult the latest version in force, accessible on our Site. If any major changes are made, we will inform you by email or by our services for you allow these amendments to be reviewed before they take effect. If you continue to use our Services Following Publication or Notification of Changes to the protection of personal data, this means that you accept updates.

What personal data is collected and for what purposes?

When you use our platform and/or during your registration, we collect and process personal data concerning you such as:  your surnames and forenames.

We will also ask you to send us your email address in order to use this data for the creation of an account, sending emails for information and notifications, as well as for the newsletter.

We also collect your nickname, avatar, mailing address, sex, phone number, email address, phone number, e-mail address, and email address. IP address, and some information available on your social networks. We will also ask you to send us a mini biography, or a biography, on an optional basis.

SPOT LMS uses Learning Analytics methods to analyze the courses taken, the quizzes and controls, routes, etc... We use this data for the analysis and the display. This data is used for various purposes, including gathering your experience user and track your progress, set up a follow-up and statistics according to your motivation.

When you register on the platform, you can register thanks to the form of creation of account and/or user.

As part of satisfaction surveys, we can use a satisfaction measurement tool for clients (Net Promoter Score). You will be asked via this tool to write an opinion on the use of the service SPOT LMS.

Why do we use cookies?

Definition of "cookie" and its utilization. A "cookie" is a text file that is placed on your computer at the time of the visit our platform. In your computer, cookies are managed by your internet browser.

We use cookies on our Site for the purposes of your browsing, optimization and marketing. personalization of our Services on our platform by memorizing your preferences. Cookies us also show how our platform is used. We automatically collect your IP address and information relating to the use of our Site. Our platform can thus be remember your identity when a connection has been established between the server and the web browser. The information previously provided in a web form can thus be kept.

Different types of cookies are used on our Site:

  • Cookies that are strictly necessary for the operation of our platform. They allow you to to use the main features of our platform (for example access to your account). Without these cookies, you will not be able to use our platform normally.
  • Analytical" cookies: in order to improve our services, we use cookies from audience measurements such as the number of pages viewed, the number of visits, the activity of Users and their return frequency, notably thanks to Google Analytics services. These cookies allow only the establishment of statistical studies on the traffic of Users on our platform, the results of which are completely anonymous to allow us to know the use and the performance of our platform and improve its operation. Accepting these cookies is a necessary condition for the use of our platform. If you refuse them, we can't give you guarantee normal use on our platform.
  • Functional Cookies: These are cookies that allow us to personalize your experience on our platform by memorizing your preferences. These cookies may be placed by a third party party on our behalf, but it is not authorized to use them for purposes other than those described.

Types of cookies used. The following types of cookies are used on this Site:

  • Temporary" Cookies: This type of cookie is active in your browser until you leave our platform and expire if you do not access the Site for a certain period of time.
  • Permanent" or "tracking" cookies: this type of cookie remains in your browser's cookie file. browser for a longer period, depending on your web browser settings. The Permanent cookies are also called tracker cookies.

Use of third-party cookies. We may use third party partners, such as Google Analytics, to track visitor activity on our platform or to identify your interests on our platform and customize the offer that is addressed to you on our platform or outside our platform. Information that may thus be collected by third party advertisers may include data such as geo-location data or contact information, such as e-mail addresses. The privacy policies of these third party advertisers provide privacy protection to advertisers. additional information on how cookies are used.

We ensure that partner companies agree to process the information collected on our website. platform exclusively for our needs and in accordance with our instructions, in compliance with the European regulations and undertake to implement appropriate safety and security measures. data privacy protection.

Disabling cookies. You can deactivate cookies at any time by selecting ` the appropriate settings in your browser to disable cookies (the section of the browser used specifies the procedure to follow).

We draw your attention to the fact that disabling cookies can reduce or prevent accessibility to all or part of certain functions.

With regard to promotional emails: You may withdraw your consent at any time by (i) unchecking the relevant box in your account, (ii) clicking the unsubscribe link provided in each of our communications or (iii) by contacting us.

With regard to targeted advertising on third-party sites (only for free accounts): you can refer to our Policy about Cookies to understand how to withdraw your consent.

We collect the information you provide to us, including when:

  • you navigate on our platform and applications
  • you create, modify and access your personal account
  • you fill in a contact form
  • you use notifications
  • contact our Customer Service

Is your data shared with third parties?

The personal data concerning you collected on our platform are intended for own use by SPOT LMS and can be transmitted to companies subcontractors that SPOT LMS may use in the performance of its services.

SPOT LMS does not sell or rent your personal information to third parties for marketing purposes, in any manner whatsoever. case.

We also work closely with third party companies who may have access to your personal data, in particular:

  • When you expressly request it;
  • When we use search engine and analytical solutions providers to improve and optimize our platform;
  • When we have a legal obligation to do so or if we believe in good faith that it is necessary to (i) respond to any claim against SPOT LMS, (ii) comply with the SPOT LMS (iii) to enforce any contract entered into with our members, such as the Terms of Use and this Privacy Policy (iv) in the event of an emergency involving the public health or physical integrity of a person, (v) in the (vi) to ensure rights, property and safety; or SPOT LMS, its members and more generally any third party;
  • In addition, SPOT LMS does not disclose your personal data to third parties, except if (1) you (or your account administrator acting on your behalf) make the request or authorize the disclosure; (2) disclosure is required to process transactions or provide services that you have (3) SPOT LMS is required to do so by a government authority or a regulation, in case of judicial requisition, subpoena or any other requirement or to establish or defend a legal claim; or (4) the acts as agent or subcontractor for SPOT LMS in the performance of the Services (by For example, SPOT LMS uses the services of a telecommunications company).

If SPOT LMS or all or part of its assets are acquired by a third party, the data in our possession will, where applicable, be transferred to the new owner.

Upon request, we can provide you with a list of the countries where we keep your data and those where we do not. they transit occasionally.

We keep your data in the European Union but we also transfer them outside the Union European to the United States. The U.S. entities to which we transfer your data have Privacy Shield or we have entered into specific contracts and clauses with them established by the European Commission to supervise and secure the transfer of your data. data to these providers. We may use the services of U.S. companies to whom we have access. subcontract your data to respond to your requests, provide online payment tools, we will provide commercial and advertising services or emailing and SMS services.

How are your personal data protected?

SPOT LMS applies technological security measures generally recognized so that the personal data collected are not, lost, misused, accessed, altered or disclosed by unauthorized third parties unless the communication of such data is imposed by the regulations in force, in particular at the request of an authority judicial, police, gendarmerie or any other authority empowered by law.

The security of personal data also depends on the Users. Users who are members SPOT LMS are committed to maintaining the confidentiality of their login and password. The members also agree not to share their account and to declare to SPOT LMS any use of their account. unauthorized use of said account as soon as they become aware of it.

How long do SPOT LMS users keep their personal data?

The personal data provided by the SPOT LMS users will be deleted after a certain period and depending on the data processed.

1 year after your last use of our platform, the customer account and all user accounts of the account customer are deleted without the possibility of restoration.

We do not retain any of your data after the customer account is deleted.

Are you a minor?

Our goal being to make education accessible to all, minors can access the Site to search for information.

Before accessing the Site, the consent of minors under 16 years of age must be given by the owner of the Site. parental authority.

Our platform does not provide for the registration, collection or storage of information relating to any person 13 years of age or younger.

You should read this Privacy Policy with your parents or guardian. legal representative to ensure that you and your parents or legal representative understand it.

When you have given your consent when you were minors, personal data you were collected.

You will be able to exercise your right to forget if you no longer wish your personal data to be stored. in our databases.

What are your rights ?

In accordance with the regulations in force, the Users of our platform have the following rights following :

  • right of access and rectification ;
  • update, user data completeness ;
  • right to block or delete the personal data of Users, when they are is inaccurate, incomplete, ambiguous, out of date, or whose collection, use, disclosure or storage is prohibited;
  • right to withdraw consent at any time ;
  • right to limit the processing of Users' data ;
  • right to object to the processing of personal data ;
  • the right to the portability of the data that the Users will have provided, when these data make the object of automated processing based on their consent or a contract.

If you wish to know how SPOT LMS uses this personal data, ask to rectify it or to oppose a treatment you can send an email to the address data-protection@spotlms.com or send to a letter to the following address: Cyrus HD - Data Protection Officer, 21 rue marc donadille, 13013 Marseille France. Finally, SPOT LMS Users can file a complaint with the authorities of control, and in particular CNIL)

Your requests will be processed within 30 days. In addition to your request, we will ask you to contact a photocopy of a proof of identity so that SPOT LMS can verify your identity.

How to contact us - contact details data protection officer

If you have any questions or complaints, or if you have any questions wish to provide SPOT LMS with recommendations or comments to improve our Policy of personal data protection you can send an email to the address data-protection@spotlms.com or send to a letter to the following address: Cyrus HD - Data Protection Officer, 21 rue marc donadille, 13013 Marseille France.

 

Security at SPOT LMS

Protecting your data is our highest priority

 

Overview

As users of our own product, we understand how important the security and privacy of your data is.
We are committed to providing our customers with a highly secure and reliable environment for its cloud-based application. We have therefore developed a security model that covers all aspects of cloud-based SPOT LMS systems.

The security model and controls are based on international protocols and standards and industry best practices, such as ISO/IEC 27001, the standard for information security management systems (ISMS) and ISO/IEC 27018 , Security techniques - Code of practice for protection of personally identifiable information in public clouds.

As part of the company’s focus on security issues, the company security team performs on a regular basis:
  • Monitoring and analyzing the infrastructure for suspicious activities and potential threats.
  • Issuing periodic security internal review.
  • Dynamically updating the security model and addressing new security threats.
  • Systematically examining the organization's information security risks, taking into account threats and vulnerabilities.
  • Designing and implementing a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address the risks that are deemed unacceptable.
  • Adopting an overarching management process to ensure that the information security controls continue to meet the organization's evolving information security needs.

Protecting Customer Data

Our systems are hosted on OVH infrastructure. They've devoted an entire portion of their site to explaining their security measures, which you can find in the following links:
https://www.ovh.com/world/about-us/security

No one other than our directors can access the data of clients and this is only done by a director if it is necessary to solve client-related issues.

Authorizing Access

Customer data is stored only in the production environment. Directors only have approval to access user data in order to solve client requests, issues or bugs. All logs of SSH connections to our production environment are saved and archived. Attachments in your account are encrypted and delivered on a per-user-access controlled basis.
We know the data you share in SPOT LMS is private and confidential. We have strict controls over our directors' access to internal data and we are committed to ensuring that your data is never seen by anyone who should not see it.

Secure Software Design

Any new feature or code that will be implemented into our system starts with an in-depth analysis of security and privacy risks. All code is saved into a version control repository and evaluated in a test environment before deploying it into our production environment. All code is reviewed by a second developer to ensure code quality.

Physical Security Protocols

Security controls at OVH data centers are based on standard technologies and follow the industry’s best security practices. The physical security controls are constructed in such a way as to eliminate the effect of single points of failure and retain the resilience of the computing center.

Environmental Controls

A variety of environmental controls are implemented at the data center facilities.
  • Servers are locked inside the infrastructure in a designated area.
  • The server area is cooled by a separate air conditioning system, which keeps the climate at the desired temperature to prevent service outage.
  • The facilities are protected by a fire suppression system, which protects the computing equipment and has built-in fire, water, and smoke detectors.
  • The facilities have on-site generators, which serve as an alternative power source.
  • There is 24-hour video surveillance of all entrances and exits, lobbies, and ancillary rooms. The videos are recorded and monitored, and retained for later use.

Network Security

Firewalls: Applications in the hosting and cloud have firewalls installed to shield them from attack and prevent the loss of valuable customer data. The firewalls are configured to serve as perimeter firewalls to block ports and protocols.
DDoS mitigation: All application access, including direct application access and API access, are protected by a DDoS mitigation service to ensure high availability at all times, as well as prevent attacks and malicious activities.

Encryption in Transit and at Rest

SPOT LMS ensures the security and privacy of user information by encrypting data on all servers at rest and in transit.
Our systems are designed to ensure data is protected at all times. Specifically, we're using TLS v1.2 with strong ciphers to protect data in transit, and AES-256 to encrypt data at rest. User passwords are hashed and salted with a modern hash function.
SPOT LMS’s cloud-based solution is deployed using dedicated servers of OVH, enabling us to guarantee high security through utilizing a series of high tech, best in the industry solutions that work to ensure the safety of all user data on the OVH network.

External Security Audits and Penetration Tests

We work closely with industry leaders in web app and infrastructure security who perform penetration tests and audits of SPOT LMS. We monitor our product for security vulnerabilities automatically as the product grows.

System Monitoring, Logging and Alerting

SPOT LMS monitors servers to retain and analyze a comprehensive view of the security state of its production infrastructure. SPOT LMS collects and stores production servers logs for analysis. Logs are stored and indexed in a separate network.

Backup

All of the data is backed up daily to multiple disks. Backups are encrypted and distributed to various locations. Backups are saved for a period of 30 days.

Incident Management

To handle security incidents effectively, SPOT LMS has constructed incident response and notification procedures. SPOT LMS employs an Incident Handling team that responds to security incidents and mitigates risks. The team uses monitoring and tracking tools and performs real-time analysis. Additionally, the team has clear procedures in place for communicating the incidents to any involved party and for handling escalations. Every incident is forwarded to the security team leader for assessment and analysis.The level of severity is a measure of its impact on, or threat to, the operation or integrity of the institution and its information. It determines the priority for handling the incident, who manages the incident, and the timing and extent of the response.

Personnel Security

SPOT LMS realizes that the malicious activities of an insider could have an impact on the confidentiality, integrity, and availability of all types of data and has therefore formulated policies and procedures concerning the hiring of IT administrators or others with access to important and crucial systems. SPOT LMS has also formulated policies and procedures for the ongoing periodic evaluation of IT administrators or others with system access. User permissions are continuously updated and adjusted so when a user's job no longer involves infrastructure management, the user's console access rights are immediately revoked.

Security Awareness and Training

In order to help ensure that SPOT LMS employees are aligned with the security practices and aware of their duties, SPOT LMS conducts multiple information security awareness campaigns. In addition, the security obligations of users and the entity’s security commitments to users are communicated on an annual basis through the company policy.
Our engineering and operation teams keep their skills up to date regarding security best practices. We have coded many different online systems and are experienced in infrastructure security and systems security.

PCI DSS, ISO 27001 and SOC1/2

OVH's data centers have a PCI DSS certification, ISO/IEC 27001 certification, SOC 1 Type II and SOC 2 Type II certifications, service auditor’s report as the result of an indepth audit of the centers’ control objectives and control activities, including controls over information technology and all other related processes. Please visit the following links:
https://www.ovh.com/world/about-us/certifications

 

Legal Mentions

 

Legal Mentions

Cyrus RH is a simplified joint stock company (SAS) with a capital of 113600 € registered in France under the SIREN 447 803 354 and whose registered office is located at 21 rue marc donadille, 13013 Marseille, France. Cyrus RH is represented by Mr Léopold COHEN, its Chairman.

Cyrus RH is an application software company and we provide our services as a SAAS platform.

The Director of Publication of the platform is Mr Laurent MICHEL.

The site is hosted by OVH whose address is the following : OVH - 2 rue Kellermann - 59100 Roubaix - France

Contact us

  • By email : contact@spotlms.com
  • By mail : Cyrus RH, 21 rue marc donadille, 13013 Marseille, France

You have the right to access and rectify information concerning you, which you may exercise by email at the address data-protection@spotlms.com or by mail (address above). You may also, for legitimate reasons, object to the processing of your personal data. data you concerning.

For more information on all your rights you can refer to our "Privacy Policy".