Key definitions
This section explains terms used in the policy with practical examples so readers can match definitions to real training scenarios and system interactions.
CyberHubEdu operates cyber awareness training programs designed around practical cases and scenarios. This policy explains how we collect, use, share and protect personal data when organizations and individuals use our services, attend training, or access materials online. Examples throughout this document show typical data flows: an HR manager uploading employee lists to enroll staff, a learner completing a phishing simulation that records click behaviour for debriefing, and an administrator viewing aggregate engagement reports. We aim to be transparent about processing purposes, retention practices tied to training records, and choices available to participants. Our contact details and the effective date are provided below for any inquiries or requests related to privacy.
We collect data needed to deliver training, manage accounts, measure outcomes and improve scenario content. The following sections detail the categories of data we receive directly from users, data collected automatically, and data shared by third parties in typical implementation scenarios.
This section explains terms used in the policy with practical examples so readers can match definitions to real training scenarios and system interactions.
We collect data needed to deliver training, manage accounts, measure outcomes and improve scenario content. The following sections detail the categories of data we receive directly from users, data collected automatically, and data shared by third parties in typical implementation scenarios.
When organizations enroll staff or learners register, we collect information needed to provide the service and contextualize training scenarios.
Some information is collected automatically when users access online materials or interact with our systems; this helps operate and improve services and analyze scenarios.
In some deployments, customers or third-party services provide data to us or integrate with our platform. Below are common third-party data sources and examples of typical uses.
We process personal data to deliver training, operate accounts, measure outcomes and maintain service quality. The bullets below match each purpose to a practical example.
For users in jurisdictions that require legal bases for personal data processing, we rely on the bases listed below depending on context and the type of processing.
We use cookies and similar technologies to enable core functionality, remember preferences, and analyze usage. Below we describe types, categories and how to manage them.
Common cookie types we use include session cookies for authentication, persistent cookies for preferences and analytics cookies for measuring engagement with training materials and simulations.
Categories include: essential cookies required for the platform to function; functional cookies that store preferences; analytics cookies that measure usage; and optional advertising cookies only used with consent.
Users can control cookie settings via their browser or device preferences. For optional cookies that require consent, CyberHubEdu provides a consent tool during initial site visits where choices are recorded and respected.
View our cookie details and management options
We share personal data with third parties only as necessary to provide services, comply with legal obligations, and support legitimate business activities. Typical sharing relationships are listed below with practical examples.
CyberHubEdu operates with vendors and partners in multiple countries. When personal data is transferred outside Canada, we apply appropriate safeguards and contractual protections to align with applicable privacy laws. Transfers are based on documented agreements, standard contractual clauses where appropriate, or other lawful mechanisms.
Safeguards include encryption in transit, data processing agreements with subprocessors, vendor assessments, and contractual clauses that require recipients to protect personal data to standards comparable to those described in this policy.
We retain personal data only as long as necessary for the purposes described and to meet legal, tax, or contractual obligations. Retention periods vary by data type and customer arrangement.
Account records and subscription information are retained for the duration of the contractual relationship and for up to seven years after termination to meet bookkeeping and legal obligations or as required by the customer contract.
Support tickets, correspondence and case notes are retained for up to three years after resolution to enable effective customer support and dispute resolution unless a longer period is required by the client agreement.
Security logs and technical diagnostics are retained for a limited period (typically 90 to 360 days) depending on the type of log, to support incident detection, contribute and remediation.
Data deletion requests are handled in accordance with contractual terms and applicable law. When data is no longer required, we remove it from active systems and overwrite or securely delete backups in line with documented retention schedules.
Protecting data is central to our operations. CyberHubEdu uses a combination of technical and organizational measures tailored to the sensitivity of the data and the risk of processing. We conduct regular security reviews, maintain access controls, and require subprocessors to meet minimum security standards. Examples: encryption of stored reports, two-factor authentication for administrative access, and quarterly penetration testing for platform components.
Depending on your jurisdiction, you may have rights relating to your personal data. Below are common rights and how they apply to typical training scenarios.
This section explains how we address GDPR obligations for individuals in the European Economic Area and the United Kingdom, especially when training involves cross-border deployments.
If you are located in the EEA or UK, GDPR may apply. CyberHubEdu implements measures such as Data Processing Agreements and supports data subject requests consistent with GDPR principles. For scenario examples, we provide customers options for pseudonymizing learner data in benchmarking exports and configuring data retention to meet regional expectations.
If you believe CyberHubEdu has mishandled your personal data, you may submit a complaint by email or mail describing the issue and attaching supporting documentation. We review complaints through a documented case management process and use case examples to determine corrective steps. For complex matters we log the incident, perform root-cause analysis and respond with findings or suggested mitigations based on the scenario.
You can request access, correction, deletion, portability, or restriction of processing for personal data we hold. When you submit a request, include factual context (for example: course enrolment ID, date of interaction, or a sample record) to help our team locate the relevant records. We use scenario-based workflows to handle typical requests — e.g., account data retrieval for a former learner, correction of contact details after enrollment, or export of training completion history for HR archives.
We aim to respond to straightforward data rights requests within 30 days of receipt. Complex requests requiring verification or coordination with third parties may take longer; in such cases CyberHubEdu will provide a status update within 30 days and an estimated completion timeframe.
CyberHubEdu uses marketing communications to share case studies, course schedules, and security scenario briefs that may interest learners and organizational clients. We send promotional emails only to users who opt in, and we tailor messaging using role-based segments (for example: IT manager, HR administrator, front-line employee) based on the enrollment scenarios you provide.
To stop marketing emails, click the unsubscribe link at the bottom of any CyberHubEdu promotional message or contact our support team. Unsubscribing removes you from promotional lists but will not remove transactional messages such as account notifications or billing receipts.
CyberHubEdu's core services target adult learners and organizational clients. We do not knowingly collect personal information from individuals under 16 without verifiable parental consent. If an account or request indicates a user is a minor, we follow a documented scenario-driven verification process and will suspend or delete the record pending confirmation from a parent or guardian.
Our website and training modules may contain links to third-party resources, platforms, or case-study partners. These links are provided for convenience and contextual learning scenarios; CyberHubEdu is not responsible for the privacy practices or content of third-party sites. We advise reviewing the privacy policy of any external site you visit from our platform.
We share personal data with third parties only as necessary to provide services, comply with legal obligations, and support legitimate business activities. Typical sharing relationships are listed below with practical examples.
View our cookie details and management options
CyberHubEdu updates privacy notices to reflect new services, regulatory changes, or improvements to our handling of learner data. When changes are material we provide a clear summary and the effective date. For example, when adding a new case-based reporting feature we document how logs are retained and provide a scenario-driven FAQ to explain operational impacts.