Skip to content

Privacy Policy

Last updated

This document is a template and must be reviewed by qualified legal counsel before launch.

  • We collect what we need to run your account, your courses and our services – nothing more.
  • We do not sell personal data and we do not use advertising or cross-site tracking cookies.
  • AI tutor questions are sent to an AI provider only when the tutor is enabled – never with your name or email address – and you can clear your tutor history at any time.
  • Certificates can be verified publicly by anyone who has the certificate code.
  • The newsletter only starts once you confirm your email address, and every newsletter has a link to unsubscribe.
  • You can access, correct or delete your data, or object to its use, by emailing us.

Summary only. The full text below applies.

Who we are

CyberX8T ("CyberX8T", "we", "us") is a cybersecurity services and training company based in Kampala, Uganda. We provide security audits, penetration testing and corporate security training, and we operate the CyberX8T learning platform, including its AI tutor.

For the personal data described in this policy, CyberX8T is the data controller within the meaning of Uganda's Data Protection and Privacy Act, 2019 (the "DPPA") and its regulations. Where the law requires it, we register with the Personal Data Protection Office (PDPO).

You can contact us about anything in this policy at hello@cyberx8t.com.

What this policy covers

This policy applies to personal data we process when you:

  • visit our website or contact us through it;
  • create an account and use the learning platform, including courses, quizzes, certificates, reviews, messages and the AI tutor;
  • subscribe to our newsletter; or
  • enquire about, or communicate with us during, a security engagement.

Client engagement data. During audits and penetration tests we may encounter personal data held in a client's systems. That data is processed on the client's behalf under a separate signed agreement, non-disclosure agreement and rules of engagement, which take precedence over this policy for that data.

Information we collect

Information you give us

  • Account information – your full name, email address and password. Passwords are never stored in readable form; we keep only a salted hash (bcrypt).
  • Profile information (optional) – phone number, organisation and a short bio, if you choose to add them.
  • Service inquiries – your name, email address, optional company and phone number, the service you are interested in and your message.
  • Support messages – conversations with our team through the student portal.
  • Course reviews – your star rating and comment.
  • AI tutor conversations – the questions you ask, the tutor's replies, the lesson you asked from, the sources shown and any thumbs-up or thumbs-down feedback you give.
  • Newsletter – your email address, the form you signed up with and, if you unsubscribe and choose to tell us, why.

Information created as you learn

  • Course progress – enrolments, lessons completed, progress percentages, wishlist items and learning activity dates.
  • Quiz attempts – the answers you submit, your scores, pass or fail results and attempt dates.
  • Certificates – the name printed on the certificate, the course, issue date, score and a unique verification code.

Information collected automatically

  • Account activity – when your account was created and when you last signed in.
  • Newsletter records – whether your address is waiting for confirmation, subscribed or unsubscribed, and since when; and for each newsletter, whether it was sent to your address or failed to send.
  • Technical data – IP address, browser and device information and request timestamps, recorded in server and security logs and used for rate limiting and abuse prevention.
  • Password reset codes – a one-time code sent to your email address, which expires after 10 minutes.

We do not ask for sensitive personal data (such as health, religious or biometric data) and ask you not to include it in messages, reviews or tutor questions.

How we use your information

We use personal data to:

  1. Provide the platform – create and secure your account, enrol you in courses, record progress and quiz results, and issue certificates.
  2. Run the AI tutor – answer your questions using the course material and improve answer quality using your feedback.
  3. Respond to you – reply to inquiries, support messages and data protection requests.
  4. Deliver services – scope, propose, deliver and report on security engagements you request.
  5. Keep things secure – detect and prevent fraud, abuse, cheating and attacks on the platform, including through rate limiting and logging.
  6. Communicate – send service emails such as password reset codes and, if you subscribed and confirmed your address, our newsletter (see "The newsletter" below).
  7. Improve – understand how courses are used (for example, completion rates) so we can improve content. Where practical we use aggregated or de-identified data.
  8. Meet legal obligations – comply with applicable laws, lawful requests from authorities, and tax and accounting requirements.

We do not sell personal data, and we do not use it for advertising or to make automated decisions that have legal or similarly significant effects on you.

The AI tutor

The AI tutor answers questions about the course you are studying. When it is enabled:

  • Only your question, the recent turns of your tutor conversation in that course and the relevant excerpts retrieved from the course lessons are sent to our AI provider – Google (Gemini API) or OpenAI, depending on configuration – to generate an answer. Your question may also be converted into a numerical "embedding" by the same provider to find relevant lessons.
  • Your name, email address, password and other account details are never sent to the AI provider.
  • We use the providers' business APIs and choose settings under which submitted content is not used to train their models, where the provider offers such settings.
  • Conversations are stored in your account so you can review them, and you can clear a course's tutor history at any time from the tutor panel.
  • Feedback (thumbs up or down) is linked to the answer and reviewed to improve answer quality.

Please do not include passwords, personal data about other people, or confidential information about your employer or clients in tutor questions. When no AI provider is configured, questions are answered by a basic built-in responder and nothing is sent to a third party.

The newsletter

You can subscribe to our newsletter – new courses and practical security tips – on our website.

  • Confirmation first – we email a link to the address you enter, and the newsletter starts only once you open it (double opt-in). To stop anyone flooding an inbox through the form, an address gets at most three confirmation emails a day, and none within ten minutes of the last one.
  • Welcome email – the first time you confirm, we send you a welcome email.
  • Unsubscribing – every newsletter has an unsubscribe link, and our newsletters and welcome email also support one-click unsubscribe in email apps that offer it. The unsubscribe page only acts when you press its button, asks (optionally) why you're leaving, and lets you subscribe again if you change your mind. We stop sending to an address as soon as it unsubscribes.
  • What we keep – your address and its status while you're subscribed. An address that unsubscribes, or never confirms, stays on our list marked as such, so it isn't emailed by mistake; ask us and we'll erase it. Records of newsletters already sent keep the address each one went to.

Newsletters are sent through our email service provider (see below).

Who we share information with

We share personal data only with service providers who process it on our behalf, under contracts that require them to protect it and use it only for our instructions:

ProviderPurposeData involved
DigitalOceanCloud hosting for our application and databaseAll platform data described in this policy
CloudflareWebsite hosting, content delivery, DNS, DDoS protection and firewallIP address and request metadata
Google (Gemini API) or OpenAIAI tutor answers and search embeddings – only when the AI tutor is enabledTutor questions, recent conversation turns and course excerpts – never your name or email address
Email service providerPassword reset codes, inquiry replies, newsletter confirmations and newslettersName, email address and message content

An up-to-date list of our processors is available on request.

Information that is public by design

  • Certificate verification – anyone who has a certificate's code can confirm it on our verification page, which shows the recipient's name, the course, issue date and score.
  • Course reviews – reviews are shown publicly with a shortened version of your name (for example, "Ada L.").

Other disclosures – we may disclose personal data when required by law or a valid order of a court or public authority, to protect the rights, property or safety of CyberX8T, our users or the public, or to professional advisers under a duty of confidentiality. If CyberX8T is involved in a merger or acquisition, personal data may be transferred to the new owner, who must continue to honour this policy.

International transfers

Some of our providers store or process data outside Uganda – for example in data centres in Europe or North America, or across Cloudflare's global network. We transfer personal data outside Uganda only where the DPPA allows it: where the recipient country or organisation provides a level of protection at least equivalent to the DPPA, or where you have consented to the transfer.

We choose providers with strong security practices, contractual data protection commitments and, where available, recognised security certifications.

How long we keep information

We keep personal data only for as long as we need it for the purposes above, or as the law requires:

InformationHow long we keep it
Account and profileWhile your account is open. Deleted or anonymised within 90 days after you ask us to close it.
Course progress and quiz attemptsWhile your account is open, then deleted with the account.
CertificatesFor as long as the certificate may need to be verified. You can ask us to revoke a certificate, after which it can no longer be verified.
AI tutor conversationsUntil you clear them, or until your account is closed.
Support messagesUp to 24 months after the conversation is closed.
Service inquiriesUp to 24 months after our last contact, unless an engagement follows (then as set out in the contract).
Newsletter subscriptionWhile you're subscribed. An address that unsubscribes or never confirms stays on the list, marked as such, until you ask us to erase it; records of newsletters already sent keep the address they went to.
Password reset codesExpire after 10 minutes and cannot be reused.
Server and security logsUp to 90 days, or longer when needed to investigate a security incident.

Where the law requires us to keep records for longer (for example, financial records once payments launch), we keep only what is required.

How we protect your information

As a security company, we hold ourselves to the standards we recommend to our clients. Measures include:

  • encryption in transit (HTTPS/TLS) for the website and API;
  • passwords stored only as salted bcrypt hashes, short-lived sign-in tokens and time-limited password reset codes;
  • rate limiting on sign-in, password reset, inquiry, newsletter and tutor requests;
  • role-based access, so only authorised staff can see administrative data, on a need-to-know basis;
  • DDoS protection and firewalling through Cloudflare, and regular patching of our systems;
  • confidentiality obligations for staff and contractors; and
  • backups, logging and an incident response process.

No system is completely secure. If a personal data breach occurs, we will contain it, notify the Personal Data Protection Office as required by the DPPA, and inform affected people where the breach is likely to affect them, with advice on how to protect themselves.

Cookies and local storage

We keep browser storage to a minimum:

  • Session token – when you sign in, we store a sign-in token in your browser's local storage (under the key cyberx8t.token) so you stay signed in. It expires after 24 hours and is removed when you sign out. It is strictly necessary for the signed-in parts of the platform.
  • Preferences – we may store small, non-identifying preferences in local storage, such as how you like to view the course catalogue.
  • Security cookies – Cloudflare may set strictly necessary cookies to protect the website against bots and attacks.

We do not use advertising cookies, cross-site tracking or third-party marketing pixels. If we introduce privacy-friendly analytics in future, we will update this section first.

You can clear local storage and cookies in your browser settings at any time; doing so will sign you out.

Your rights

Under the DPPA you have the right to:

  • be informed about how your personal data is used (this policy);
  • access the personal data we hold about you and receive a copy;
  • correct inaccurate or incomplete data – you can update most profile details yourself in the portal;
  • request deletion of data we no longer have a lawful reason to keep;
  • object to or restrict processing, including processing for direct marketing;
  • withdraw consent where processing is based on consent;
  • not be subject to decisions based solely on automated processing that significantly affect you; and
  • complain to the Personal Data Protection Office (PDPO) if you believe your data has been mishandled.

How to exercise your rights – email hello@cyberx8t.com with the subject line "Privacy request", from the email address linked to your account where possible. We may need to verify your identity before acting. We will respond within the time required by law and aim to do so within 30 days. We do not charge for reasonable requests.

We would appreciate the chance to resolve any concern directly before you contact the PDPO.

Children

The platform is intended for people aged 18 and over. Under the DPPA, personal data of a child (a person under 18) may only be processed with the consent of a parent or guardian. Learners under 18 may use the platform only with that consent – for example through a school programme organised with their parent or guardian's agreement.

If you believe a child has created an account without appropriate consent, contact us and we will take steps to delete their data.

Changes to this policy

We may update this policy when our services, providers or legal obligations change – for example when paid courses and payment providers launch. We will update the "Last updated" date above and, for significant changes, tell registered users by email or with a notice in the platform before the change takes effect.

Contact us

For questions about this policy or your personal data:

  • Email: hello@cyberx8t.com (subject: "Privacy request")
  • Location: Kampala, Uganda
  • Online: use our contact page, or message us from the student portal if you have an account.