AlphaSploit AcademyAlphaSploit

Privacy Policy

GDPR & SaaS ComplianceLast Updated: May 3, 2026

AlphaSploit (“we”, “us”, “our”) operates an online cybersecurity learning platform available at https://academy.alphasploit.com/ (“Service”). This Privacy Policy explains how we process personal data in compliance with applicable data protection laws, including the GDPR. By using our Service, you acknowledge and agree to this Privacy Policy.


1. Data Controller

AlphaSploit acts as the Data Controller for personal data processed through the platform.

Email: support@alphasploit.com

2. Personal Data We Collect

We only collect data necessary to operate and secure the Service:

2.1 Account Data

  • Full name
  • Email address
  • Username and profile information

2.2 Learning & Usage Data

  • Course enrollments
  • Progress tracking
  • Lab activity and submissions
  • Quiz results
  • Certificates and achievement history

2.3 Subscription & Billing Data

We process subscription status information such as:

  • Active / expired subscription status
  • Access entitlements
  • Billing cycle metadata

Payment details are processed by third-party payment providers. We do not store full card or banking details.

2.4 Technical & Security Data

  • IP address
  • Device information
  • Browser type
  • Login timestamps
  • Security and audit logs

3. Legal Basis for Processing (GDPR Article 6)

We process personal data under the following legal bases:

  • Contractual necessity – to provide access to the platform and deliver purchased services
  • Legitimate interests – to secure, improve, and maintain platform functionality
  • Legal obligation – to comply with applicable laws and financial/accounting regulations
  • Consent – for optional communications where required

4. Purpose of Data Processing

We use personal data for:

  • Providing access to courses, labs, and learning content
  • Managing subscriptions and access control
  • Tracking learning progress and issuing certificates
  • Authenticating users and securing accounts
  • Preventing fraud, abuse, and unauthorized access
  • Improving system performance and user experience
  • Sending essential service communications

5. Account Security & Acceptable Use

To ensure platform integrity:

  • Accounts are strictly personal and non-transferable
  • Account sharing or credential sharing is prohibited
  • Users are responsible for maintaining account confidentiality

We reserve the right to:

  • Suspend or terminate accounts violating these terms
  • Revoke access to services or content at our discretion in case of abuse, fraud, or policy violation

6. Content Ownership & License

All content provided through AlphaSploit (including courses, labs, videos, text, and assessments) is owned or licensed by AlphaSploit.

Users are granted a Limited, Non-exclusive, Non-transferable, and Revocable license for personal educational use only.

Users may NOT:

  • Copy or redistribute content
  • Share materials outside the platform
  • Resell or commercialize content
  • Claim ownership of platform content

7. Subscription Model & Access Control

AlphaSploit operates on a subscription-based access model.

  • Access to paid content is granted only during an active subscription period
  • Upon subscription expiration, access may be automatically restricted or revoked
  • We may enforce access rules dynamically based on subscription status, usage policies, or violations

We reserve the right to manage, suspend, or revoke access where subscription is inactive, misuse or policy violations occur, or system integrity requires enforcement.

8. Data Sharing & Processors

We do not sell personal data. We share limited data only with data processors necessary for Service operation, including authentication and database infrastructure providers, hosting providers, and payment processors.

These processors act on our instructions, are bound by confidentiality obligations, and are not permitted to use data for independent purposes.

9. International Data Transfers

Personal data may be processed outside your jurisdiction depending on infrastructure providers. Where applicable, we ensure appropriate safeguards are in place in accordance with GDPR requirements (e.g., Standard Contractual Clauses).

10. Data Retention

We retain personal data only as long as necessary:

  • Active accounts: retained during service use
  • Learning records: retained for certification and academic history
  • Technical logs: retained for limited security and audit purposes
  • Deleted accounts: removed or anonymized within a reasonable period unless legally required to retain

11. Security of Processing (GDPR Article 32)

We implement appropriate technical and organizational measures, including encryption in transit (TLS/SSL), role-based permissions, secure authentication, and database-level restrictions (Row-Level Security). Despite safeguards, no system is fully secure.

12. Data Subject Rights

Under GDPR, you have the right to access your personal data, rectify inaccurate data, request erasure (“right to be forgotten”), restrict processing, data portability, object to processing, and withdraw consent. Requests can be submitted via our support email.

13. Cookies & Tracking Technologies

We use cookies for authentication, session management, security, fraud prevention, and platform performance analytics. You may disable cookies in your browser settings; however, some features may not function properly.

14. Data Breach Notification

In the event of a personal data breach, we will assess and contain the incident promptly, notify affected users and relevant authorities where legally required under GDPR, and take corrective measures to prevent recurrence.

15. Communications

We send only service-related communications, including account notifications, subscription and billing updates, security alerts, and course-related updates. Non-essential communications may be opted out of where applicable.

16. Children’s Data

The Service is not intended for individuals below the minimum legal age in their jurisdiction. We do not knowingly collect personal data from minors without appropriate consent.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted with a revised “Last Updated” date.

18. Contact

For privacy-related inquiries:

support@alphasploit.com

academy.alphasploit.com