Privacy-first, scenario-based training

Privacy Policy Overview

CyberHubEdu operates cyber awareness training programs designed around practical cases and scenarios. This policy explains how we collect, use, share and protect personal data when organizations and individuals use our services, attend training, or access materials online. Examples throughout this document show typical data flows: an HR manager uploading employee lists to enroll staff, a learner completing a phishing simulation that records click behaviour for debriefing, and an administrator viewing aggregate engagement reports. We aim to be transparent about processing purposes, retention practices tied to training records, and choices available to participants. Our contact details and the effective date are provided below for any inquiries or requests related to privacy.

  • 2026-02-05
  • CyberHubEdu, Business ID 181779363
Privacy Policy Overview

We collect data needed to deliver training, manage accounts, measure outcomes and improve scenario content. The following sections detail the categories of data we receive directly from users, data collected automatically, and data shared by third parties in typical implementation scenarios.

01

Key definitions

This section explains terms used in the policy with practical examples so readers can match definitions to real training scenarios and system interactions.

Personal data means information that identifies or can be linked to an identifiable person. Examples include a learner's name and email used to enroll in a course, and behavioral indicators such as whether a user clicked a simulated phishing link during a training exercise.
Processing covers any operation performed on personal data, such as collecting a roster from an HR administrator, storing training completion records, analyzing phishing simulation results to create a debrief, or deleting test accounts after a course ends.
User refers to individuals interacting with CyberHubEdu services: learners, administrators, training managers, and auditors who access reports. A typical user scenario is a training manager uploading employee data to schedule a mandatory course.
Service means CyberHubEdu's suite of cyber awareness offerings: online modules, live workshops, simulated phishing campaigns, reporting dashboards, and support services used by organizations to improve security behavior.
Cookies are small files placed on a user's device to support functions such as session management, remembering preferences, or measuring engagement with training material — for example, tracking progress through a module.
02

What data we collect

We collect data needed to deliver training, manage accounts, measure outcomes and improve scenario content. The following sections detail the categories of data we receive directly from users, data collected automatically, and data shared by third parties in typical implementation scenarios.

03

Data you provide us

When organizations enroll staff or learners register, we collect information needed to provide the service and contextualize training scenarios.

  • Identity and contact details: full name, work email, job title and department used for enrollment and role-based scenario assignment.
  • Organization and account data: company name, administrator contact, billing contact and purchase orders required to manage corporate accounts.
  • Training responses and assessment results: answers to quizzes, simulation interaction logs (e.g., clicks on simulated phishing content) used to generate debriefs and aggregate reporting.
  • Support and communications: messages platform with our support team, feedback forms and case notes tied to troubleshooting or course customization.
  • Optional profile information: time zone, language preference and accessibility needs that help personalize learning experiences.
  • Payment and invoicing information: billing contact, invoicing address and transaction records when organizations purchase services.
04

Data collected automatically

Some information is collected automatically when users access online materials or interact with our systems; this helps operate and improve services and analyze scenarios.

  • Usage data: pages visited, module completion timestamps, duration of sessions and interaction events within training exercises.
  • Technical data: IP address, device type, browser version and operating system to diagnose issues and optimize delivery.
  • Analytics and performance data: aggregated metrics from simulations and dashboards used to refine scenario content and measure program effectiveness.
  • Cookies and tracking identifiers: identifiers stored in cookies or local storage for session continuity and preference management.
  • Security logs: authentication events, failed login attempts and other logs used to detect misuse and support incident response.
  • Geolocation (approximate): inferred from IP address for localization of content and compliance with regional requirements.
05

Data from third parties

In some deployments, customers or third-party services provide data to us or integrate with our platform. Below are common third-party data sources and examples of typical uses.

  • Identity providers and HR systems: organizations may sync employee lists from SSO providers or HR platforms to enroll users into role-based scenarios.
  • Payment processors and invoicing tools: third-party payment services process billing information when organizations purchase training subscriptions.
  • Analytics and reporting services: external analytics tools may receive anonymized or pseudonymized engagement metrics to support product improvement and benchmarking.
06

Why we collect data

We process personal data to deliver training, operate accounts, measure outcomes and maintain service quality. The bullets below match each purpose to a practical example.

  • Provision of services: creating and managing accounts, enrolling learners, and delivering scenario-based modules—e.g., assigning a management team phishing simulation.
  • Customer support: diagnosing issues raised by training managers and providing course customization based on case details.
  • Performance measurement and reporting: generating debriefs and aggregate reports that show trends in phishing susceptibility over time for an organization.
  • Payment and billing: processing invoices and recording purchases linked to organizational subscriptions.
  • Service improvement: analyzing anonymized engagement data to refine scenarios and update modules based on observed learner mistakes.
  • Security and fraud prevention: monitoring logs and authentication events to detect misuse or attempts to access accounts improperly.
  • Legal compliance: responding to lawful requests from authorities or retaining records required by law.
  • Communication: sending account notices, training reminders, and administrative messages related to scheduled scenarios or system changes.
07

Legal basis for processing

For users in jurisdictions that require legal bases for personal data processing, we rely on the bases listed below depending on context and the type of processing.

  • Performance of a contract: processing necessary to provide requested training services after an organization subscribes to CyberHubEdu.
  • Consent: where we ask for explicit consent (for example, optional promotional communications or certain cookies), processing is based on that consent.
  • Legitimate interests: for internal analytics, fraud prevention and security monitoring when balanced against user rights and expectations.
  • Legal obligation: processing necessary to meet legal or regulatory requirements, such as responding to lawful requests or maintaining tax records.
08

Cookies and similar technologies

We use cookies and similar technologies to enable core functionality, remember preferences, and analyze usage. Below we describe types, categories and how to manage them.

Common cookie types we use include session cookies for authentication, persistent cookies for preferences and analytics cookies for measuring engagement with training materials and simulations.

Categories include: essential cookies required for the platform to function; functional cookies that store preferences; analytics cookies that measure usage; and optional advertising cookies only used with consent.

Users can control cookie settings via their browser or device preferences. For optional cookies that require consent, CyberHubEdu provides a consent tool during initial site visits where choices are recorded and respected.

View our cookie details and management options

09

Who we share data with

We share personal data with third parties only as necessary to provide services, comply with legal obligations, and support legitimate business activities. Typical sharing relationships are listed below with practical examples.

  • Service providers: cloud hosting, email delivery and analytics vendors that help deliver training modules and reports on behalf of CyberHubEdu.
  • Affiliates and subcontractors: partners who assist with content localization, custom scenario development, or technical support for a client deployment.
  • Legal and regulatory authorities: when required to respond to lawful requests or to protect the rights and safety of others.
  • Mergers and business transfers: in the event of a sale or restructuring, user information may be transferred as part of the transaction with notice to affected customers.
  • Aggregated and anonymized data: we may share non-identifying, aggregated metrics with partners for benchmarking or research into training effectiveness.
  • Customer-authorized services: platforms or tools an organization authorizes to receive reports or training results, for example an LMS that imports completion records.
10

International transfers

CyberHubEdu operates with vendors and partners in multiple countries. When personal data is transferred outside Canada, we apply appropriate safeguards and contractual protections to align with applicable privacy laws. Transfers are based on documented agreements, standard contractual clauses where appropriate, or other lawful mechanisms.

Safeguards include encryption in transit, data processing agreements with subprocessors, vendor assessments, and contractual clauses that require recipients to protect personal data to standards comparable to those described in this policy.

11

How long we retain data

We retain personal data only as long as necessary for the purposes described and to meet legal, tax, or contractual obligations. Retention periods vary by data type and customer arrangement.

Account records and subscription information are retained for the duration of the contractual relationship and for up to seven years after termination to meet bookkeeping and legal obligations or as required by the customer contract.

Support tickets, correspondence and case notes are retained for up to three years after resolution to enable effective customer support and dispute resolution unless a longer period is required by the client agreement.

Security logs and technical diagnostics are retained for a limited period (typically 90 to 360 days) depending on the type of log, to support incident detection, contribute and remediation.

Data deletion requests are handled in accordance with contractual terms and applicable law. When data is no longer required, we remove it from active systems and overwrite or securely delete backups in line with documented retention schedules.

12

How we protect data

Protecting data is central to our operations. CyberHubEdu uses a combination of technical and organizational measures tailored to the sensitivity of the data and the risk of processing. We conduct regular security reviews, maintain access controls, and require subprocessors to meet minimum security standards. Examples: encryption of stored reports, two-factor authentication for administrative access, and quarterly penetration testing for platform components.

  • Encryption in transit and at rest for sensitive records and training results.
  • Access controls and role-based permissions to limit who can view enrollment lists and simulation outcomes.
  • Regular security assessments, vulnerability scanning, and incident response procedures informed by practical scenario exercises.
13

Your rights and choices

Depending on your jurisdiction, you may have rights relating to your personal data. Below are common rights and how they apply to typical training scenarios.

  • Right of access: request a copy of personal data we hold, such as your training completion record and simulation results.
  • Right to rectification: ask us to correct inaccurate or incomplete personal information, such as an incorrect job title used for role-based modules.
  • Right to erasure: request deletion of personal data where applicable, for example when a former employee's profile is no longer needed, subject to retention requirements.
  • Right to restriction: request that processing be limited while a dispute about accuracy or other matters is resolved.
  • Right to object: object to processing based on legitimate interests, for instance if you do not wish your simulation interaction data to be used for benchmarking.
  • Right to data portability: where technically feasible, request an export of your personal data in a structured, commonly used format.
  • Right to withdraw consent: if processing is based on consent (such as optional cookies), you may withdraw consent at any time for future processing.
  • Right to lodge a complaint with a supervisory authority if you consider our processing infringes applicable data protection laws.
14

GDPR and international users

This section explains how we address GDPR obligations for individuals in the European Economic Area and the United Kingdom, especially when training involves cross-border deployments.

If you are located in the EEA or UK, GDPR may apply. CyberHubEdu implements measures such as Data Processing Agreements and supports data subject requests consistent with GDPR principles. For scenario examples, we provide customers options for pseudonymizing learner data in benchmarking exports and configuring data retention to meet regional expectations.

  • We can enter standard contractual clauses or other approved transfer mechanisms when transferring EU data to jurisdictions without an adequacy decision.
  • We assist customers in responding to data subject access requests for training records and simulation outcomes originating from EEA/UK individuals.
  • We document our processing activities related to EU and UK personal data and conduct assessments for high-risk processing, such as large-scale behavioral profiling for benchmarking.
  • Right to lodge a complaint with a supervisory authority: if you believe your data rights under applicable law have been infringed, you may contact the Office of the Privacy Commissioner of Canada or another relevant supervisory authority. CyberHubEdu documents actions taken in response to inquiries and retains records to support regulatory review where required.

If you believe CyberHubEdu has mishandled your personal data, you may submit a complaint by email or mail describing the issue and attaching supporting documentation. We review complaints through a documented case management process and use case examples to determine corrective steps. For complex matters we log the incident, perform root-cause analysis and respond with findings or suggested mitigations based on the scenario.

15

Exercise Your Data Rights

You can request access, correction, deletion, portability, or restriction of processing for personal data we hold. When you submit a request, include factual context (for example: course enrolment ID, date of interaction, or a sample record) to help our team locate the relevant records. We use scenario-based workflows to handle typical requests — e.g., account data retrieval for a former learner, correction of contact details after enrollment, or export of training completion history for HR archives.

[email protected]

We aim to respond to straightforward data rights requests within 30 days of receipt. Complex requests requiring verification or coordination with third parties may take longer; in such cases CyberHubEdu will provide a status update within 30 days and an estimated completion timeframe.

16

Marketing Communications and Preferences

CyberHubEdu uses marketing communications to share case studies, course schedules, and security scenario briefs that may interest learners and organizational clients. We send promotional emails only to users who opt in, and we tailor messaging using role-based segments (for example: IT manager, HR administrator, front-line employee) based on the enrollment scenarios you provide.

To stop marketing emails, click the unsubscribe link at the bottom of any CyberHubEdu promotional message or contact our support team. Unsubscribing removes you from promotional lists but will not remove transactional messages such as account notifications or billing receipts.

17

Children's Privacy

CyberHubEdu's core services target adult learners and organizational clients. We do not knowingly collect personal information from individuals under 16 without verifiable parental consent. If an account or request indicates a user is a minor, we follow a documented scenario-driven verification process and will suspend or delete the record pending confirmation from a parent or guardian.

18

Links to Third-Party Sites

Our website and training modules may contain links to third-party resources, platforms, or case-study partners. These links are provided for convenience and contextual learning scenarios; CyberHubEdu is not responsible for the privacy practices or content of third-party sites. We advise reviewing the privacy policy of any external site you visit from our platform.

Links to Third-Party Sites

We share personal data with third parties only as necessary to provide services, comply with legal obligations, and support legitimate business activities. Typical sharing relationships are listed below with practical examples.

Cookies and similar technologies

View our cookie details and management options

19

Changes to This Privacy Notice

CyberHubEdu updates privacy notices to reflect new services, regulatory changes, or improvements to our handling of learner data. When changes are material we provide a clear summary and the effective date. For example, when adding a new case-based reporting feature we document how logs are retained and provide a scenario-driven FAQ to explain operational impacts.