Last updated
This document is a template and must be reviewed by qualified legal counsel before launch.
At a glance
- We collect what we need to run your account, your courses and our services – nothing more.
- We do not sell personal data and we do not use advertising or cross-site tracking cookies.
- AI tutor questions are sent to an AI provider only when the tutor is enabled – never with your name or email address – and you can clear your tutor history at any time.
- Certificates can be verified publicly by anyone who has the certificate code.
- The newsletter only starts once you confirm your email address, and every newsletter has a link to unsubscribe.
- You can access, correct or delete your data, or object to its use, by emailing us.
Summary only. The full text below applies.
Who we are
CyberX8T ("CyberX8T", "we", "us") is a cybersecurity services and training company based in Kampala, Uganda. We provide security audits, penetration testing and corporate security training, and we operate the CyberX8T learning platform, including its AI tutor.
For the personal data described in this policy, CyberX8T is the data controller within the meaning of Uganda's Data Protection and Privacy Act, 2019 (the "DPPA") and its regulations. Where the law requires it, we register with the Personal Data Protection Office (PDPO).
You can contact us about anything in this policy at hello@cyberx8t.com.
What this policy covers
This policy applies to personal data we process when you:
- visit our website or contact us through it;
- create an account and use the learning platform, including courses, quizzes, certificates, reviews, messages and the AI tutor;
- subscribe to our newsletter; or
- enquire about, or communicate with us during, a security engagement.
Client engagement data. During audits and penetration tests we may encounter personal data held in a client's systems. That data is processed on the client's behalf under a separate signed agreement, non-disclosure agreement and rules of engagement, which take precedence over this policy for that data.
Information we collect
Information you give us
- Account information – your full name, email address and password. Passwords are never stored in readable form; we keep only a salted hash (bcrypt).
- Profile information (optional) – phone number, organisation and a short bio, if you choose to add them.
- Service inquiries – your name, email address, optional company and phone number, the service you are interested in and your message.
- Support messages – conversations with our team through the student portal.
- Course reviews – your star rating and comment.
- AI tutor conversations – the questions you ask, the tutor's replies, the lesson you asked from, the sources shown and any thumbs-up or thumbs-down feedback you give.
- Newsletter – your email address, the form you signed up with and, if you unsubscribe and choose to tell us, why.
Information created as you learn
- Course progress – enrolments, lessons completed, progress percentages, wishlist items and learning activity dates.
- Quiz attempts – the answers you submit, your scores, pass or fail results and attempt dates.
- Certificates – the name printed on the certificate, the course, issue date, score and a unique verification code.
Information collected automatically
- Account activity – when your account was created and when you last signed in.
- Newsletter records – whether your address is waiting for confirmation, subscribed or unsubscribed, and since when; and for each newsletter, whether it was sent to your address or failed to send.
- Technical data – IP address, browser and device information and request timestamps, recorded in server and security logs and used for rate limiting and abuse prevention.
- Password reset codes – a one-time code sent to your email address, which expires after 10 minutes.
We do not ask for sensitive personal data (such as health, religious or biometric data) and ask you not to include it in messages, reviews or tutor questions.
How we use your information
We use personal data to:
- Provide the platform – create and secure your account, enrol you in courses, record progress and quiz results, and issue certificates.
- Run the AI tutor – answer your questions using the course material and improve answer quality using your feedback.
- Respond to you – reply to inquiries, support messages and data protection requests.
- Deliver services – scope, propose, deliver and report on security engagements you request.
- Keep things secure – detect and prevent fraud, abuse, cheating and attacks on the platform, including through rate limiting and logging.
- Communicate – send service emails such as password reset codes and, if you subscribed and confirmed your address, our newsletter (see "The newsletter" below).
- Improve – understand how courses are used (for example, completion rates) so we can improve content. Where practical we use aggregated or de-identified data.
- Meet legal obligations – comply with applicable laws, lawful requests from authorities, and tax and accounting requirements.
We do not sell personal data, and we do not use it for advertising or to make automated decisions that have legal or similarly significant effects on you.
Legal basis under the DPPA 2019
We process personal data in line with the principles of the DPPA – including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, limited retention and security – and only where the Act allows it, namely:
- Consent – for example when you subscribe to the newsletter (and confirm your address), add optional profile details or use the AI tutor. You can withdraw consent at any time; this does not affect processing that has already taken place.
- Performance of a contract – to provide your account, courses, certificates and any services you have engaged us for.
- Compliance with a legal obligation – for example responding to lawful requests or keeping accounting records.
- Other grounds permitted by law – such as the prevention and detection of crime or fraud, including protecting the security of our platform.
The AI tutor
The AI tutor answers questions about the course you are studying. When it is enabled:
- Only your question, the recent turns of your tutor conversation in that course and the relevant excerpts retrieved from the course lessons are sent to our AI provider – Google (Gemini API) or OpenAI, depending on configuration – to generate an answer. Your question may also be converted into a numerical "embedding" by the same provider to find relevant lessons.
- Your name, email address, password and other account details are never sent to the AI provider.
- We use the providers' business APIs and choose settings under which submitted content is not used to train their models, where the provider offers such settings.
- Conversations are stored in your account so you can review them, and you can clear a course's tutor history at any time from the tutor panel.
- Feedback (thumbs up or down) is linked to the answer and reviewed to improve answer quality.
Please do not include passwords, personal data about other people, or confidential information about your employer or clients in tutor questions. When no AI provider is configured, questions are answered by a basic built-in responder and nothing is sent to a third party.
International transfers
Some of our providers store or process data outside Uganda – for example in data centres in Europe or North America, or across Cloudflare's global network. We transfer personal data outside Uganda only where the DPPA allows it: where the recipient country or organisation provides a level of protection at least equivalent to the DPPA, or where you have consented to the transfer.
We choose providers with strong security practices, contractual data protection commitments and, where available, recognised security certifications.
How long we keep information
We keep personal data only for as long as we need it for the purposes above, or as the law requires:
Where the law requires us to keep records for longer (for example, financial records once payments launch), we keep only what is required.
How we protect your information
As a security company, we hold ourselves to the standards we recommend to our clients. Measures include:
- encryption in transit (HTTPS/TLS) for the website and API;
- passwords stored only as salted bcrypt hashes, short-lived sign-in tokens and time-limited password reset codes;
- rate limiting on sign-in, password reset, inquiry, newsletter and tutor requests;
- role-based access, so only authorised staff can see administrative data, on a need-to-know basis;
- DDoS protection and firewalling through Cloudflare, and regular patching of our systems;
- confidentiality obligations for staff and contractors; and
- backups, logging and an incident response process.
No system is completely secure. If a personal data breach occurs, we will contain it, notify the Personal Data Protection Office as required by the DPPA, and inform affected people where the breach is likely to affect them, with advice on how to protect themselves.
Your rights
Under the DPPA you have the right to:
- be informed about how your personal data is used (this policy);
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data – you can update most profile details yourself in the portal;
- request deletion of data we no longer have a lawful reason to keep;
- object to or restrict processing, including processing for direct marketing;
- withdraw consent where processing is based on consent;
- not be subject to decisions based solely on automated processing that significantly affect you; and
- complain to the Personal Data Protection Office (PDPO) if you believe your data has been mishandled.
How to exercise your rights – email hello@cyberx8t.com with the subject line "Privacy request", from the email address linked to your account where possible. We may need to verify your identity before acting. We will respond within the time required by law and aim to do so within 30 days. We do not charge for reasonable requests.
We would appreciate the chance to resolve any concern directly before you contact the PDPO.
Children
The platform is intended for people aged 18 and over. Under the DPPA, personal data of a child (a person under 18) may only be processed with the consent of a parent or guardian. Learners under 18 may use the platform only with that consent – for example through a school programme organised with their parent or guardian's agreement.
If you believe a child has created an account without appropriate consent, contact us and we will take steps to delete their data.
Changes to this policy
We may update this policy when our services, providers or legal obligations change – for example when paid courses and payment providers launch. We will update the "Last updated" date above and, for significant changes, tell registered users by email or with a notice in the platform before the change takes effect.
Contact us
For questions about this policy or your personal data:
- Email: hello@cyberx8t.com (subject: "Privacy request")
- Location: Kampala, Uganda
- Online: use our contact page, or message us from the student portal if you have an account.