Privacy statement, learning portal
Last updated: August 2026 · In het Nederlands
This is the privacy statement for learning.itkaro.com, the learning portal of ITKaro. The website itkaro.com and its contact form have a separate statement.
The portal uses no trackers, no analytics and no external fonts. There is therefore no cookie banner: there is nothing to accept.
Who is responsible
ITKaro, sole proprietorship of Jacob Poot.
Chamber of Commerce 87602075 · VAT NL004448441B78
Email: learning@itkaro.com
What the portal stores
Only what is needed to let you follow the course:
- Your name and email address, as entered when you register, and whether you confirmed that address.
- Your password, hashed. Not the password itself but an irreversible fingerprint of it. I cannot read it back either.
- Which group you belong to, and the client organisation it belongs to. That link is created by the course code you enter.
- Which modules you have read, and when.
- Your test attempts: the mark, and per question the answer you gave and whether it was correct.
- Your request for a course date, and whether it was approved.
- When you last signed in, and the time of failed sign-in attempts together with the address that was tried. The latter only to slow down abuse; those records disappear by themselves.
If you add a passkey
The portal stores the public key of your device and the name you gave it. Your fingerprint or face never leaves your device and therefore never reaches this portal; that is exactly why passkeys are safer than a password.
Why, and on what basis
Your data is processed to deliver the course you were enrolled in: giving access to the material, showing your progress and results, and producing a certificate of attendance. That is performance of the agreement.
The sign-in attempts and security measures rest on legitimate interest: without that brake the portal is open to abuse.
Who sees what
- Other participants see nothing of yours. Not your progress and not your marks. That is enforced in the software, not merely agreed.
- The instructor (Jacob Poot) sees the participants per group, their progress and their marks. That is needed to tell whether the material lands.
- Your employer or client organisation receives the attendance list for their own records: name, email address, and whether you enrolled and completed. Your marks are not in it and are not shared with them. For organisations enrolling employees, ITKaro signs a data processing agreement on request; ask via learning@itkaro.com.
Where it is held, and who else can reach it
- fly.io — the portal and its database run on a server in Amsterdam. Fly.io is a US company; the data is held in their European region.
- Microsoft 365 — mail sent by the portal (confirmation, password reset, confirmation of a course date) goes through my own Microsoft environment in the EU. If you reply to such a mail it arrives at learning@itkaro.com and in my own Teams environment.
- Anthropic, for the exercises. Some modules contain an exercise powered by a real AI model (Claude Haiku by Anthropic, a US company). What you type into such an exercise window is sent to that service to produce the answer, and the portal stores none of it. This is also stated on each exercise itself, with the request not to type real client or personal data into it. One exercise type asks you to upload a screenshot to be checked; that image is likewise sent to Anthropic and not stored, and the exercise asks you to use a test environment or redact sensitive values. If you do not use the exercises, nothing is sent. The service runs in the United States; Anthropic does not use what comes in over this commercial connection to train its models, and a data processing agreement with Anthropic is available for business use. If you want the AI exercises disabled entirely for a group, that is possible on request.
- Notifications to the instructor. When you create an account, the instructor is notified in his own Microsoft environment, including your name and email address. The same happens when you request a course date. If you delete your account, a message is sent with only your name and the group, so the attendance list can be corrected; your email address is not in it.
- Nobody else. There is no marketing platform, no third-party learning platform and no analytics in between.
Video
A module may contain a film. Nothing is retrieved from YouTube until you click play yourself; until that moment your browser talks to nobody outside this portal. If you do click, your browser connects to YouTube (Google) and data travels outside the EU. If you would rather not, do not click play; the text of the module stands on its own and is complete.
Cookies
The portal sets two cookies, both technically necessary and neither of them for tracking: a session cookie so you stay signed in, and while adding or using a passkey a short-lived cookie that expires after five minutes. There is no tracker and no advertising cookie.
How long it is kept
You are in control: on my details you can delete your account at any time. That immediately and permanently erases your account, your progress, your results and your passkeys.
If you do not, the portal clears it automatically: twelve months after you last signed in, your account and everything attached to it is removed. Nobody has to remember; it happens by itself.
Your rights
On my details you can see what is held about you, download all of it in a readable file, and delete your account. To correct something or ask anything else, mail learning@itkaro.com.
If you disagree with something, you can lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Security
Traffic with the portal is encrypted. Passwords are stored as an irreversible fingerprint, sign-in attempts are rate limited, and the portal loads nothing from outside itself except a film you start yourself. Spotted something odd? Let me know and I will look into it.