cyberixyx (cyberixyx.digital), Business ID 6714436199137

Privacy Policy

This Privacy Policy explains how cyberixyx collects, uses, discloses and protects personal data in connection with our educational platform for AI and chatbot training. The policy covers students, instructors, visitors and business contacts interacting with cyberixyx.digital from Thailand and internationally. We describe practical scenarios and cases — for example, enrolling in a course, submitting assignments that include example prompts, joining live workshops, or contacting support — to make clear what data is involved and why it is processed. Where specific legal frameworks apply, we identify relevant rights and procedures to help you manage your data.

15-01-2026
cyberixyx (cyberixyx.digital), Business ID 6714436199137
Soi Tiwanon 3, Talat Khwan Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand

Definitions

The terms used in this policy are defined to make it easier to understand the scope and types of processing we perform. Definitions are written with practical examples and scenarios to illustrate typical platform interactions.

Personal data means any information that can identify an individual, directly or indirectly. Examples on cyberixyx include name, email address, phone number, account identifiers, profile photos, billing details, and content submitted during coursework such as example prompts or project files.
Processing means any operation performed on personal data such as collection, recording, storage, retrieval, use, disclosure, erasure or destruction. On cyberixyx processing includes creating student accounts, delivering course materials, analyzing engagement to improve lessons, and handling payment transactions.
User refers to anyone who accesses or uses cyberixyx.digital services, including prospective students, enrolled learners, instructors, partners, and administrators. Example scenario: a user signs up for a hands-on AI prompt engineering course and uploads sample prompts for feedback.
Service means the educational platform and related services provided under the cyberixyx.brand, including course enrollment, learning management, live workshops, mentorship, progress tracking, and customer support delivered via cyberixyx.digital.
Cookies are small text files or similar technologies stored on a user device to recognize the device, remember preferences, enable session management, and collect analytics. On cyberixyx cookies may support course progress tracking, login sessions, and usage analysis to refine course content.

Data Collection

We collect data directly from users, automatically through technical systems, and from trusted third parties to support platform operations. Below are concrete examples tied to common platform activities such as registration, payment, course participation, and technical support.

Data You Provide

Data provided by users is collected when you register, enroll in courses, complete assignments, communicate with support, or set up a profile. Below are representative items and practical cases illustrating when each type is used.

  • Full name and display name: collected during account creation and shown to instructors and peers in course forums and project reviews (example case: group assignment submissions).
  • Email address and contact details: used to send enrollment confirmations, course updates, workshop links, and support replies (example case: receiving a link to a live coaching session).
  • Phone number and billing address: used for payment processing, fraud prevention, and essential account recovery communications when requested by the user (example case: verifying a payment or completing a refund).
  • Payment and transaction information: limited payment details required by payment processors to complete course purchases and handle refunds; full card details are handled by the payment provider, not stored by cyberixyx.digital.
  • Profile data and educational records: profile photo, biography, course progress, grades, certificates and examples of your AI prompts or project files uploaded as part of coursework (example case: instructor feedback on a submitted chatbot scenario).
  • Communications and support content: messages you send to support, feedback, and survey responses used to resolve issues and improve course scenarios.

Automatic Data Collection

We collect technical and usage data automatically to operate the platform, diagnose problems, and improve educational content. These items are generally collected through server logs, cookies, and analytics tools under strict data handling agreements.

  • Device and browser information (device type, operating system version, browser type) used to ensure compatibility of interactive training tools and hands-on labs.
  • IP address and approximate geolocation used for security monitoring, preventing fraud, and adapting live session times to regional audiences in scenario-based scheduling.
  • Usage and engagement data (pages visited, modules completed, time on task, click paths) used to analyze learning scenarios and improve course workflows based on observed student behavior.
  • Error reports, crash logs and diagnostic data captured when technical issues occur in practical labs or simulations to reproduce and fix problems.
  • Cookie identifiers and local storage keys used to maintain session state during interactive exercises and to remember user preferences for UI and course settings.
  • Aggregated analytics events used to produce anonymized case studies on course effectiveness and to refine real-world training scenarios without identifying individual students.

Third-Party Data Sources

We may receive information about you from trusted third parties to enable payments, hosting, analytics, identity verification, or to assist with course delivery. Such integrations are governed by written data processing agreements and limited to necessary data.

  • Payment processors: transaction status, invoicing identifiers and fraud screening results needed to complete purchases and refunds for courses.
  • Hosting and infrastructure providers: logs and operational metrics that allow secure delivery of course materials and live sessions.
  • Analytics and research partners: aggregated, pseudonymized metrics used to evaluate course scenarios and improve educational outcomes.

Purposes of Processing

We process personal data for clear, defined purposes tied to platform functionality and improvement. Each purpose lists concrete examples and case uses to clarify why the data is necessary.

  • Provision of educational services: creating accounts, enrolling in courses, delivering e-learning modules, and providing certificates following completion (example: enabling access to a hands-on lab environment).
  • Payment and billing: processing course fees, managing invoices and refunds, and maintaining business records tied to enrollment.
  • Support and communications: responding to questions, resolving technical issues, and sending administrative messages about course schedules or changes.
  • Personalization: tailoring course recommendations, suggesting modules, or adjusting difficulty based on past performance and preferences in practice scenarios.
  • Platform improvement and research: analyzing anonymized engagement data to refine case studies, improve lab exercises, and update curriculum content.
  • Security and fraud prevention: detecting and preventing unauthorized access, misuse of the service, and protecting accounts during live assessments.
  • Legal compliance and record keeping: retaining records as required by applicable law or to defend legal claims (example case: maintaining transaction records for tax reporting).
  • Marketing and outreach (where consent is provided): sharing course news, upcoming events, and targeted offers relevant to past interests and completed scenarios.

Legal Basis for Processing

Depending on the processing activity and the laws that apply to your location, we rely on one or more lawful bases for processing personal data. Below are the common legal bases used by cyberixyx.

  • Consent: where you have given clear consent for a specific purpose, such as receiving marketing emails or optional research participation.
  • Contract performance: processing necessary to perform our contract with you, such as delivering courses you have purchased or managing your account.
  • Legal obligation: processing required to comply with applicable laws, regulatory requests, or tax obligations in Thailand or other jurisdictions where we operate.
  • Legitimate interests: processing necessary for our legitimate interests such as platform security, fraud prevention and improving educational content, balanced against your rights and expectations.

Data Protection Rights

Where European data protection rules apply, individuals have rights to access and control their personal data. We describe the common rights and how to exercise them. Similar principles are applied as appropriate under other regional laws.

  • Right of access: you can request a copy of personal data we hold about you and details about how it is processed (example case: a student requests all records related to a completed course).
  • Right to rectification: you may ask us to correct inaccurate or incomplete personal data (example case: updating a billing address before a certificate is issued).
  • Right to erasure: in certain situations you may request deletion of personal data we hold, subject to applicable retention requirements and legal obligations.
  • Right to restrict processing: you may request limits on how your personal data is used while a dispute or verification is pending.
  • Right to data portability: where applicable, you can request a machine-readable copy of data you provided to transfer to another service (example case: exporting course completion records).
  • Right to object and withdraw consent: if processing is based on consent or legitimate interests, you may object to specific uses or withdraw consent for optional processing.

Cookies and Tracking

Cookies and similar technologies help run the platform, remember preferences, secure sessions, and provide analytics. We describe types of cookies used and how they relate to platform features and learning scenarios.

We use session cookies to keep you logged in during a visit, persistent cookies to remember choices over time, first-party cookies to support core functionality, and third-party cookies for analytics when you consent to such tools.

Cookie categories: strictly necessary (login and session), preferences (language and display settings), analytics (usage metrics to improve courses), and marketing (with consent for outreach about related programs).

You can manage cookie preferences through browser settings or our cookie banner. Blocking cookies may affect functionality such as saved progress in interactive labs or automatic login to live sessions.

Full cookie policy available at https://cyberixyx.digital/cookie-policy

Data Sharing

We share personal data only for specific purposes and with safeguards in place. Sharing is limited to trusted partners and circumstances necessary to deliver or improve services.

  • Service providers and vendors who operate and maintain the platform (hosting, payment processors, analytics) under data processing agreements.
  • Educational or research partners when collaborating on anonymized or pseudonymized case studies to improve training scenarios and curriculum quality.
  • Legal and regulatory authorities when required by applicable law, court order, or to respond to lawful requests and protect safety and rights.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction with notice to users where required.
  • External mentors or instructors engaged to deliver specific course modules, limited to the data necessary for course delivery and feedback.
  • Aggregated and anonymized data used freely for internal analysis and shared externally for research or reporting without identifying individuals.

International Data Transfers

cyberixyx.digital operates globally and may transfer data across borders for hosting, support, or partner services. Transfers occur in line with applicable data protection standards and only where appropriate safeguards are in place.

Safeguards include contractual data processing agreements, application of recognized transfer mechanisms where applicable, technical protections such as encryption, and limiting data access to authorized personnel. Specific measures depend on the destination and type of data.

Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy, for legal or regulatory obligations, and to resolve disputes. Retention is guided by practical cases and operational needs.

Account information and enrollment records are retained for the active period of the account and typically for up to five years after deactivation for operational, billing and record-keeping purposes unless a longer retention period is required by law.

Support conversations, forum posts and direct messages are retained for up to two years to preserve learning histories and enable ongoing support, unless longer storage is necessary for legal compliance or dispute resolution.

Technical logs and diagnostic records used for security and troubleshooting are generally retained for up to twelve months, with critical security incident logs preserved longer as needed to contribute and remediate incidents.

When personal data is deleted following a valid request or expiration of the retention period, we remove it from active systems. Residual copies may remain in backups for a limited time and will be overwritten as part of routine backup cycles.

Security Measures

We implement administrative, technical and physical safeguards designed to protect personal data appropriate to the risk. Security measures are assessed regularly and are designed around the practical needs of securing course content, student records and payment data.

  • Encryption in transit and at rest for sensitive data used in payments and account management.
  • Role-based access controls and least-privilege principles to limit staff access to personal data necessary for their role.
  • Regular security assessments, patch management, incident response plans and staff training focused on protecting learner data during live labs and practical exercises.

Your Rights

You can exercise your rights in relation to personal data we process. Below are practical examples and steps to help you understand how rights apply to common platform interactions.

  • Access: request a copy of data we hold about you, such as enrollment records or submitted assignments.
  • Correction: ask us to correct inaccurate details like an email address used to receive course certificates.
  • Deletion: request removal of certain personal data, subject to legal and operational retention requirements.
  • Restriction: request temporary limits on processing while a dispute or verification is in progress.
  • Portability: request a structured copy of data you provided, for example to transfer course completion records to another platform.
  • Objection: object to processing based on legitimate interests or to direct marketing where applicable.
  • Withdraw consent: withdraw any consent you previously provided for optional processing like marketing or research participation.
  • Complain: lodge a complaint with a data protection authority if you believe your rights were not respected in line with applicable law.

Making a Rights Request

To exercise any privacy rights or to ask questions about this policy, contact our privacy team: email [email protected] or send a letter to Soi Tiwanon 3, Talat Khwan Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand. You can also call +66965770836 for general inquiries. When making a request, include sufficient information to identify yourself and describe the request. We generally aim to respond within 30 days, and may request reasonable information to verify your identity before processing the request. Effective date of this policy is 15-01-2026.

[email protected]

We aim to respond to privacy rights requests within 30 calendar days. Complex requests that require coordination with third parties or extended verification steps may take up to 60 days. If additional time is necessary, we will notify the requester with an explanation and an estimated completion date. Responses will describe actions taken and any data we will not disclose due to applicable legal exemptions.

Marketing Communications and Preferences

We may contact learners with course updates, recommended learning paths, and event invitations based on their stated interests and activity on cyberixyx. Marketing messages are sent by email and optionally by SMS where the user has explicitly opted in. Examples: (1) course progress reminders for an ongoing AI chatbot workshop; (2) tailored suggestions after completing a conversational design module; (3) announcements about hands-on labs and local meetups in Thailand.

You may opt out of promotional messages at any time by clicking the unsubscribe link in any marketing email or adjusting notification settings in your account. Transactional messages about course enrollments, billing, or account security will still be sent to manage your access and safety.

Children's Privacy

cyberixyx does not target services to children under 13. Accounts and course content on cyberixyx are intended for adult learners or those with parental consent. If we become aware that we have collected personal data from a child without required parental consent, we will take steps to promptly delete that data. Examples of actions may include account suspension and removal of identifiable information from our systems.

Third-Party Links and Integrations

Our platform links to and integrates with third-party tools for payment processing, learning management, and analytics. These third parties have their own privacy practices. Practical scenario: when you enroll in a paid specialization, a payment processor receives billing information to complete the transaction. We recommend reviewing third-party privacy policies before using integrations.

Changes to This Privacy Policy

We review and may update this policy to reflect changes in legal or operational requirements. When we make significant changes that affect how we use personal data, we will provide notice via email and in-platform notifications at least 14 days before the change takes effect. Example: introducing a new analytics provider would trigger an update describing data flows and opt-out options.

Contact Information

For privacy inquiries, data requests, or to report a concern, contact: cyberixyx Digital, Soi Tiwanon 3, Talat Khwan Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand. Email: [email protected]. Phone for general business inquiries: +66965770836. Business ID: 6714436199137.

+66965770836
Soi Tiwanon 3, Talat Khwan Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand