Learning Legacy Infinite logo Learning Legacy Infinite Contact

Security & Trust

Learning Legacy Infinite (LLI) is a Singapore-based learning design studio. We run an online store at learning-legacy.org and deliver custom learning projects for clients. This page explains, in plain language, how we protect the information you share with us — across both the store and our studio work.

Reflects our setup as of September 2026, and is our own account of our practices, not a formal third-party audit.

Where your data lives

Your data is hosted on Amazon Web Services (AWS) in its Singapore region, so it stays within Singapore. It is hosted on AWS infrastructure, which holds ISO 27001, SOC 2, and MTCS-SG Level 3 certifications. Our systems run in isolated containers on a private network, reached only through a managed gateway. Every page is served over HTTPS — the secure, encrypted connection shown by the padlock in your browser — with certificates that renew automatically.

What we collect

For the store, we collect only what an account and an order need: your email address, a password you set, and your order details. Your learning materials and progress are linked to your account so that you — and only you — can pick up where you left off. We don't store your home or billing address on our own systems (see Payments below), and we don't collect more than we need.

Payments

All card payments are handled by Stripe, a global payment provider used by millions of businesses. Your card details go straight to Stripe over an encrypted connection — they are never stored on our systems, and we never see your full card number. Stripe may collect a billing address to process your payment; that is held by Stripe, not by us.

Access & sign-in security

Access to our systems is tightly limited. Administrator sign-in requires multi-factor authentication — a password plus a second code — so a password alone is never enough. Our server accepts connections only with a secure digital key rather than a password, which shuts out password-guessing attacks. Sensitive areas sit behind authenticated admin dashboards, reachable only by specific authorised accounts.

Encryption & passwords

Connections to our sites are encrypted in transit using HTTPS, so information moving between you and us can't be read along the way. Account passwords are never kept in plain text — they are stored as a one-way scramble (a "hash") that cannot be reversed. And as above, card data is encrypted and handled by Stripe, not held by us.

Backups

We back up the site every week, so your account and learning data can be restored if something goes wrong. For custom client projects, we can arrange more frequent backups to suit the project.

AI and third-party services

Some of our learning tools use AI. Our primary AI model host is Alibaba Cloud (Singapore); conversational agents are provided by Anthropic; voice features use ElevenLabs. Learners are referenced by an internal user ID; no personal identifiers are transmitted to AI providers. Where these providers process data outside Singapore, such transfers are handled in line with the Personal Data Protection Act (Section 26).

Our store runs on WordPress and WooCommerce, with spam protection and email verification in place to keep accounts genuine.

If something goes wrong

If a security incident affected your personal data, we would investigate promptly, act to contain it, and notify you and Singapore's Personal Data Protection Commission where the law requires. You can raise a concern with us at any time at contactadmin@learning-legacy.org.

Your data and your rights

We handle personal data in line with Singapore's Personal Data Protection Act (PDPA). You can ask what personal data we hold about you, ask us to correct it, or ask us to delete it. We keep order and payment records for five years, as tax law requires; account and learning data is kept while your account is active and for 24 months after your last sign-in, then deleted or anonymised. The Data Protection Officer is contactable at contactadmin@learning-legacy.org.

Product design guidance, not legal advice.

Keeping this current

Security is ongoing, not a one-time task. We review our setup regularly and continue to strengthen it as our services grow.