Camblish Training Institute
Privacy Policy
This policy explains how Camblish Training Institute processes personal information through the public Camblish website, Camblish LMS, the Xcelerate Android application and related training, workplace and support services.
1. Who we are
Camblish Training Institute is a South African training provider and the operator of the Camblish public website, Camblish LMS and the Xcelerate learning and monitoring platform.
51 Harrison Street, Johannesburg, 2001
Email: [email protected]
Telephone: 011 024 9246
Mobile: 061 035 8120
Depending on the programme, Camblish may act as the responsible party or process information on behalf of an employer, programme sponsor, training provider or other authorised programme administrator. Questions about that relationship can be sent to the contact details above.
2. Scope of this policy
This policy applies when a person visits the Camblish website, submits an enquiry or application, uses Camblish LMS, signs in to the Xcelerate Android app, participates in training, records attendance, uploads evidence, communicates with support or uses another linked Camblish service.
Programme-specific notices, consent forms, employment policies or contractual terms may also apply. If a more specific notice applies to a particular activity, it should be read with this policy.
3. Personal information we may collect
Account, identity and programme information
- Name, surname, username, email address and telephone number.
- Moodle or Xcelerate user ID, role, account status and authentication records.
- Employer, provider, project, programme, department, learner-group, workplace and assigned-contact details.
- Application, enrolment, course, module, assessment, competency, progress, certificate and completion information.
Device and technical information
- App-generated device UUID, platform, device and operating-system metadata, app version and supported capabilities.
- Firebase or similar push-notification token, last-seen time, availability and security or diagnostic events.
- IP address, browser information, server logs, session records and security events where generated by the website or LMS.
Camblish does not require the Android client to provide an authoritative caller, learner or staff identity. Identity and permissions are determined from the authenticated Camblish or Moodle account and server-side scope.
4. Attendance, workplace and location information
Xcelerate may process clock-in and clock-out times, attendance status, schedules, session and workplace records, attendance exceptions, corrections, supporting documents and audit evidence.
Where a programme enables location-based attendance, the app may collect precise location, accuracy, timestamp and geofence events. Background location may be used only when an enabled attendance or geofence function requires it, such as authorised automatic attendance, entry or exit monitoring, workplace verification or attendance alerts.
- Location is not collected for advertising.
- Location controls are determined by the active programme, session, site and attendance policy.
- Loss of location permission may prevent location-dependent attendance functions from working.
- Manual, documentary, supervisor or other approved fallback methods may be available depending on programme policy.
See the Location, Attendance and Biometric Notice for additional detail.
5. Camera, face attendance and phone biometrics
Where enabled and lawfully authorised, the camera may be used for face enrolment, face attendance, evidence photos, paper-register uploads, support attachments or document capture. Face attendance may create and compare a mathematical face descriptor or protected biometric template rather than storing the comparison as a normal photograph.
Phone biometric confirmation uses the security mechanism supplied by the device operating system. Camblish generally receives a success or failure confirmation and does not receive the phone fingerprint, device face template or device passcode.
Biometric functions are subject to role, programme and policy controls. Camblish applies additional protection to biometric information and supports privacy and deletion requests, subject to legal, audit, fraud-prevention and training-record obligations.
6. Messages, support, files and calling
Messages and support
Camblish may process direct chat messages, message delivery and read status, reactions, typing or presence indicators, support tickets, cases, tasks, comments, review decisions and related audit history. Access is limited by account permissions and project or organisational scope.
Files and uploads
Uploaded information may include learner evidence, assignments, assessments, identity or programme documents, photographs, certificates, paper registers, attendance evidence, support attachments and employer or provider records. Users should upload only information required for the authorised purpose.
Audio and calling
If secure in-app calling is enabled, the app uses microphone audio for a one-to-one internet voice call. WebRTC carries live audio. Camblish does not intentionally store call audio. Camblish may retain call metadata such as participants, project scope, call status, initiation and end times, duration, failure information and blocking events. Push notifications may carry a minimal incoming-call invitation. Calling remains unavailable unless the required permission, security and infrastructure checks have passed.
7. Why Camblish uses personal information
- To create and manage accounts and authenticate users.
- To receive applications, enrol learners and deliver courses, modules, assessments and assignments.
- To record, verify, correct and report attendance and workplace participation.
- To provide learner, employer, provider, facilitator, assessor and administrator functionality.
- To send service, learning, attendance, support and security notifications.
- To process messages, support cases, task workflows, documents and evidence.
- To meet contractual, SETA, QCTO, employer, funding, audit, accreditation, legal and regulatory requirements.
- To prevent misuse, investigate incidents, enforce permissions and protect users and systems.
- To maintain service quality, troubleshoot faults and improve authorised Camblish services.
8. Legal grounds and user choices
Camblish processes personal information where necessary to perform an agreement or provide requested training services, comply with legal or regulatory obligations, pursue legitimate operational and security interests, protect a legitimate interest of a user, or act with consent where consent is required.
Some app permissions are optional at operating-system level, but refusing a permission may make the related feature unavailable. Camblish will not treat a device permission as consent for an unrelated purpose.
9. When information may be shared
Information is shared only where reasonably necessary and authorised. Recipients may include:
- Authorised Camblish staff, facilitators, assessors, moderators, support personnel and administrators.
- The learner, employer, supervisor, provider, programme administrator, funder, SETA, QCTO or other authorised party where the programme relationship and applicable rules permit it.
- Hosting, Moodle or Xcelerate infrastructure, email, SMS, push-notification, storage, security, signalling or TURN providers acting under appropriate arrangements.
- Professional advisers, auditors, regulators, law-enforcement bodies or courts where lawfully required.
Camblish does not sell personal information and does not provide Xcelerate learner information to advertising networks for behavioural advertising. See the Subprocessors and Service Providers page.
10. Security
Camblish uses measures appropriate to the information and risk, including HTTPS encryption in transit, authenticated accounts, server-side identity checks, restricted role and scope permissions, protected configuration, audit records and access controls. Device push tokens, private service credentials and temporary call credentials are not intended for public disclosure.
No system can guarantee absolute security. Users must protect passwords and devices, sign out when appropriate and promptly report suspected unauthorised access.
11. Retention and deletion
Camblish retains information only for as long as reasonably required for the purpose for which it was collected and for training, assessment, accreditation, contractual, employment, compliance, audit, dispute, security and legal obligations.
- Core learner, training, attendance, assessment, evidence and audit records may need to be retained for the applicable programme or statutory period.
- Raw location, presence, notification and technical records may have shorter configured retention periods.
- Biometric templates are retained only while needed for an authorised biometric purpose and applicable obligations, subject to deletion controls.
- Call signalling information and ICE candidates are temporary and should not be kept after a call ends; call-history metadata may be retained for support, safety and audit purposes.
- Inactive device registrations and obsolete push tokens may be disabled or removed.
Deletion does not always mean that every record can immediately be erased. Camblish may restrict or retain information where required for legal, audit, accreditation, fraud-prevention, contractual or dispute purposes. See Data Deletion and Privacy Requests.
12. Your privacy rights
Subject to applicable law and verification of identity, a person may request:
- Confirmation of whether Camblish holds personal information about them.
- Access to relevant personal information.
- Correction or completion of inaccurate or incomplete information.
- Deletion or destruction where Camblish is no longer authorised or required to retain it.
- Objection to certain processing or restriction of processing where applicable.
- Withdrawal of consent for future consent-based processing.
- Information about service providers or recipients, where applicable.
Requests can be submitted through an available Xcelerate Privacy Centre or by emailing [email protected]. Include the account email or username, the type of request and enough information to identify the relevant programme. Do not email passwords, full identity documents or biometric data unless Camblish provides a secure method.
A person may also raise a complaint with the Information Regulator of South Africa. Camblish encourages users to contact Camblish first so the concern can be investigated and addressed.
13. Children and learners requiring assistance
Training programmes may include young people. Where a learner cannot lawfully provide the required authorisation, Camblish relies on an authorised parent, guardian, employer, programme administrator or other lawful basis as applicable. Privacy requests may require proof of authority before information is disclosed or changed.
14. Changes, related notices and contact
Camblish may update this policy when services, laws, providers or data practices change. The effective date and version at the top identify the published version. Material changes may also be communicated through the website, LMS, app or account notice where appropriate.
[email protected]
011 024 9246 or 061 035 8120
51 Harrison Street, Johannesburg, 2001
Published by Camblish Training Institute. Effective 29 July 2026. Version 1.0.