Definitions
The terms used in this policy are defined to make it easier to understand the scope and types of processing we perform. Definitions are written with practical examples and scenarios to illustrate typical platform interactions.
This Privacy Policy explains how cyberixyx collects, uses, discloses and protects personal data in connection with our educational platform for AI and chatbot training. The policy covers students, instructors, visitors and business contacts interacting with cyberixyx.digital from Thailand and internationally. We describe practical scenarios and cases — for example, enrolling in a course, submitting assignments that include example prompts, joining live workshops, or contacting support — to make clear what data is involved and why it is processed. Where specific legal frameworks apply, we identify relevant rights and procedures to help you manage your data.
The terms used in this policy are defined to make it easier to understand the scope and types of processing we perform. Definitions are written with practical examples and scenarios to illustrate typical platform interactions.
We collect data directly from users, automatically through technical systems, and from trusted third parties to support platform operations. Below are concrete examples tied to common platform activities such as registration, payment, course participation, and technical support.
Data provided by users is collected when you register, enroll in courses, complete assignments, communicate with support, or set up a profile. Below are representative items and practical cases illustrating when each type is used.
We collect technical and usage data automatically to operate the platform, diagnose problems, and improve educational content. These items are generally collected through server logs, cookies, and analytics tools under strict data handling agreements.
We may receive information about you from trusted third parties to enable payments, hosting, analytics, identity verification, or to assist with course delivery. Such integrations are governed by written data processing agreements and limited to necessary data.
We process personal data for clear, defined purposes tied to platform functionality and improvement. Each purpose lists concrete examples and case uses to clarify why the data is necessary.
Depending on the processing activity and the laws that apply to your location, we rely on one or more lawful bases for processing personal data. Below are the common legal bases used by cyberixyx.
Where European data protection rules apply, individuals have rights to access and control their personal data. We describe the common rights and how to exercise them. Similar principles are applied as appropriate under other regional laws.
Cookies and similar technologies help run the platform, remember preferences, secure sessions, and provide analytics. We describe types of cookies used and how they relate to platform features and learning scenarios.
We use session cookies to keep you logged in during a visit, persistent cookies to remember choices over time, first-party cookies to support core functionality, and third-party cookies for analytics when you consent to such tools.
Cookie categories: strictly necessary (login and session), preferences (language and display settings), analytics (usage metrics to improve courses), and marketing (with consent for outreach about related programs).
You can manage cookie preferences through browser settings or our cookie banner. Blocking cookies may affect functionality such as saved progress in interactive labs or automatic login to live sessions.
Full cookie policy available at https://cyberixyx.digital/cookie-policy
We share personal data only for specific purposes and with safeguards in place. Sharing is limited to trusted partners and circumstances necessary to deliver or improve services.
cyberixyx.digital operates globally and may transfer data across borders for hosting, support, or partner services. Transfers occur in line with applicable data protection standards and only where appropriate safeguards are in place.
Safeguards include contractual data processing agreements, application of recognized transfer mechanisms where applicable, technical protections such as encryption, and limiting data access to authorized personnel. Specific measures depend on the destination and type of data.
We retain personal data only as long as necessary for the purposes set out in this policy, for legal or regulatory obligations, and to resolve disputes. Retention is guided by practical cases and operational needs.
Account information and enrollment records are retained for the active period of the account and typically for up to five years after deactivation for operational, billing and record-keeping purposes unless a longer retention period is required by law.
Support conversations, forum posts and direct messages are retained for up to two years to preserve learning histories and enable ongoing support, unless longer storage is necessary for legal compliance or dispute resolution.
Technical logs and diagnostic records used for security and troubleshooting are generally retained for up to twelve months, with critical security incident logs preserved longer as needed to contribute and remediate incidents.
When personal data is deleted following a valid request or expiration of the retention period, we remove it from active systems. Residual copies may remain in backups for a limited time and will be overwritten as part of routine backup cycles.
We implement administrative, technical and physical safeguards designed to protect personal data appropriate to the risk. Security measures are assessed regularly and are designed around the practical needs of securing course content, student records and payment data.
You can exercise your rights in relation to personal data we process. Below are practical examples and steps to help you understand how rights apply to common platform interactions.
To exercise any privacy rights or to ask questions about this policy, contact our privacy team: email [email protected] or send a letter to Soi Tiwanon 3, Talat Khwan Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand. You can also call +66965770836 for general inquiries. When making a request, include sufficient information to identify yourself and describe the request. We generally aim to respond within 30 days, and may request reasonable information to verify your identity before processing the request. Effective date of this policy is 15-01-2026.
We aim to respond to privacy rights requests within 30 calendar days. Complex requests that require coordination with third parties or extended verification steps may take up to 60 days. If additional time is necessary, we will notify the requester with an explanation and an estimated completion date. Responses will describe actions taken and any data we will not disclose due to applicable legal exemptions.
We may contact learners with course updates, recommended learning paths, and event invitations based on their stated interests and activity on cyberixyx. Marketing messages are sent by email and optionally by SMS where the user has explicitly opted in. Examples: (1) course progress reminders for an ongoing AI chatbot workshop; (2) tailored suggestions after completing a conversational design module; (3) announcements about hands-on labs and local meetups in Thailand.
You may opt out of promotional messages at any time by clicking the unsubscribe link in any marketing email or adjusting notification settings in your account. Transactional messages about course enrollments, billing, or account security will still be sent to manage your access and safety.
cyberixyx does not target services to children under 13. Accounts and course content on cyberixyx are intended for adult learners or those with parental consent. If we become aware that we have collected personal data from a child without required parental consent, we will take steps to promptly delete that data. Examples of actions may include account suspension and removal of identifiable information from our systems.
Our platform links to and integrates with third-party tools for payment processing, learning management, and analytics. These third parties have their own privacy practices. Practical scenario: when you enroll in a paid specialization, a payment processor receives billing information to complete the transaction. We recommend reviewing third-party privacy policies before using integrations.
We review and may update this policy to reflect changes in legal or operational requirements. When we make significant changes that affect how we use personal data, we will provide notice via email and in-platform notifications at least 14 days before the change takes effect. Example: introducing a new analytics provider would trigger an update describing data flows and opt-out options.
For privacy inquiries, data requests, or to report a concern, contact: cyberixyx Digital, Soi Tiwanon 3, Talat Khwan Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand. Email: [email protected]. Phone for general business inquiries: +66965770836. Business ID: 6714436199137.