HackXium

Legal

Privacy Policy

Effective 24 July 2026Version 1.0Xium Labs Ltd

1. Introduction

HackXium is a cohort-based executive training platform in artificial intelligence and cybersecurity, built for senior professionals at banks, development finance institutions and large enterprises. It is operated by Xium Labs Ltd, a company registered in England and Wales under Company No. 16702035 (referred to in this policy as “Xium Labs”, “we”, “us” or “our”).

We take the privacy of our participants seriously. Our audience works in regulated, security-conscious institutions, and we hold ourselves to the standard that audience expects. This policy explains what personal data we collect, why we collect it, the legal grounds on which we rely, who we share it with, how long we keep it, and the rights you have over it.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Xium Labs Ltd is the data controller of the personal data described in this policy. That means we decide how and why your personal data is processed in connection with HackXium, and we are responsible to you for that processing.

This policy should be read alongside our Terms of Service, which govern your use of the platform, and our Cookie Policy, which explains the small number of essential cookies we set.

2. Scope of this policy

This policy applies to personal data we process about visitors to hack.xiumlabs.com, people who create an account, participants enrolled in our programmes, people who contact us, and anyone who views a public certificate verification page. It covers data collected through the platform itself, through our enrolment and payment flows, through the emails we send and receive, and through the certificate verification service.

This policy does not apply to third-party websites or services that we link to but do not operate. If you follow a link away from HackXium, the privacy practices of the destination site govern what happens there, and you should review that site’s own policy.

Many participants join HackXium through their employer, for example where a bank or institution sponsors seats on a cohort. In that case your employer may hold its own records about your participation (such as who it nominated and whether it paid for your seat) and acts as a separate controller of those records. This policy covers only the processing that Xium Labs carries out; it does not govern what your employer does with information it holds independently.

3. Information you provide to us

Most of the personal data we hold is information you give us directly in the course of using the platform. It falls into five broad categories.

Account details

When you sign up, we collect your name, email address and a password. Your password is never stored in readable form; it is held only as a protected cryptographic value that cannot be reversed into the original password.

Professional profile

You may add professional details to your profile, such as your job title, organisation, sector, country and a short biography. Some of this information helps us tailor cohort composition and discussion to the seniority and sector mix of each intake. Optional fields are exactly that: you choose whether to provide them.

Enrolment details

When you enrol in a programme we record which programme and cohort you have joined, your seat status, the billing name and billing details needed to raise a receipt, and any information you provide about your eligibility or professional background where a programme asks for it.

Communications

If you contact us, for example with a support enquiry, a question about an invoice or feedback on a programme, we keep a record of the correspondence so that we can respond, resolve the matter and maintain an accurate history of the relationship.

Submitted coursework

Our programmes are practical. Each week you submit deliverables, which may include written responses, files and project work. We process this material to assess your progress, provide feedback and determine completion. Please do not include in your coursework any confidential information belonging to your employer, or personal data about other people, unless you are authorised to share it. Coursework should demonstrate your thinking, not expose your institution’s internal data.

4. Information collected automatically

When you use the platform, certain information is generated automatically as a normal consequence of operating a secure web service.

  • Device and usage data. We collect technical information about the device and browser you use, such as browser type and version, operating system and screen characteristics, together with usage information such as the pages you visit, the materials you access and the timestamps of that activity. We use this to make sure the platform works properly across devices and to understand which learning materials are being used.
  • Log data. Our servers keep request logs that include your IP address, the resources requested and related metadata. Logs exist to keep the service secure: they let us detect unauthorised access attempts, investigate incidents and diagnose faults.
  • Essential cookies. We set only essential cookies, which are strictly necessary to sign you in, keep your session active and protect the platform against abuse. We do not set advertising cookies and we do not use third-party analytics cookies. Our Cookie Policy lists the cookies we use and explains each one.

Because we use no advertising or third-party analytics cookies, we do not present you with a cookie consent banner asking you to accept tracking: there is no tracking to accept. If that position changes, we will update the Cookie Policy and seek any consent the law requires before setting non-essential cookies.

5. How we use your information

UK GDPR requires us to have a lawful basis for each purpose for which we process personal data. The purposes below are grouped by the basis on which we rely.

Performance of a contract (Article 6(1)(b))

Where processing is necessary to deliver the service you have signed up for, we rely on our contract with you. This covers:

  • creating and administering your account;
  • processing your enrolment, allocating your seat in a cohort and managing fixed start dates and limited-capacity intakes;
  • delivering weekly learning materials, receiving and assessing your deliverables, and providing feedback;
  • issuing your certificate on completion, operating its verification page and recording the CPE hours attributable to the programme;
  • sending transactional emails about your account, enrolment, payments and course progress.

Legitimate interests (Article 6(1)(f))

Where we have a genuine business need that does not override your rights and interests, we rely on legitimate interests. This covers:

  • securing the platform, monitoring for fraud and abuse, and investigating incidents;
  • improving our programmes and platform by analysing, at an appropriately aggregated level, how learning materials are used and where participants encounter difficulty;
  • maintaining records of enquiries, complaints and disputes so that we can establish, exercise or defend legal claims;
  • administering our business, including internal reporting and planning cohort capacity.

Whenever we rely on legitimate interests we balance our interest against the potential impact on you, and we do not proceed where your interests override ours. You can object to processing based on legitimate interests as described in section 12.

Legal obligation (Article 6(1)(c))

We process personal data where the law requires it, including keeping accounting and tax records of transactions, responding to lawful requests from courts, regulators and law enforcement, and complying with our obligations under data protection law itself.

Consent (Article 6(1)(a))

We rely on consent only where the law requires it or where processing is genuinely optional, principally for marketing communications (see section 13) and for optional profile information you choose to provide. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

6. Payments

Programme fees are priced in US dollars and are collected by accredited external payment processors. When you pay, you provide your card or other payment details directly to the processor through its secure payment interface. The processor handles those details under its own terms and privacy policy and in accordance with the security standards applicable to the payment industry.

We never receive or store full card numbers. What we receive from the processor is confirmation of the outcome of a payment together with limited reference information, such as a transaction identifier, the amount and currency, the payment method type and, where provided, a truncated card reference used to help you recognise the payment. That is sufficient for us to activate your enrolment, issue a receipt and handle any refund due under our Terms of Service.

We retain records of transactions, including receipts, refunds and related correspondence, for accounting and audit purposes and for as long as the law requires us to keep financial records (see section 10).

7. Certificates and public verification

On successful completion of a programme you earn a verifiable digital certificate. Each certificate has a public verification page so that an employer, regulator or professional body can confirm that the credential is genuine without contacting us. Verifiability is a core feature of the certificate: it is what gives the credential its value in professional settings, and we operate the verification service as part of delivering the programme to you.

A verification page displays only what is needed to validate the credential:

  • the name of the certificate holder as it appears on the certificate;
  • the title of the programme completed;
  • the cohort and the date of completion;
  • the unique certificate identifier;
  • the current validity status of the certificate, including whether it has been revoked.

A verification page does not display your email address, your coursework or deliverables, any assessment detail or feedback, your employer or profile information, or anything relating to payment. It cannot be browsed as a directory: a visitor needs the certificate identifier or the verification link you choose to share.

If you would prefer your verification page not to be publicly accessible, contact us at [email protected] and we will discuss the options with you. Be aware that disabling public verification limits the ability of third parties to confirm your credential independently.

8. Who we share information with

We do not sell personal data, and we do not share it with third parties for their own marketing. We share personal data only in the limited circumstances below, and only to the extent necessary in each case.

  • Trusted service providers. We use carefully selected providers to run the platform, including hosting providers, email delivery providers, payment processors and support tooling. Each provider processes personal data only on our documented instructions, under a written contract containing confidentiality and data protection obligations that meet the requirements of UK GDPR, and only for the purpose of providing its service to us.
  • Professional advisers. We may share information with our lawyers, accountants, auditors and insurers where necessary to obtain advice, prepare accounts, complete an audit or manage a claim. Advisers are bound by professional or contractual duties of confidentiality.
  • Authorities and legal process. We will disclose personal data where we are required to do so by law, by a court order or by a regulator with proper authority, or where disclosure is necessary to establish, exercise or defend legal claims or to protect the rights, property or safety of Xium Labs, our participants or others.
  • Corporate transactions. If Xium Labs is involved in a merger, acquisition, reorganisation or sale of assets, personal data may be transferred as part of that transaction. Any successor will be bound to handle your personal data in a manner consistent with this policy, and we will notify you of any transaction that changes who controls your data.

Where your seat is sponsored by your employer, we may confirm to the sponsor whether you enrolled and whether you completed the programme, since that is inherent in the sponsorship arrangement. We do not share your individual coursework with a sponsor without your knowledge.

9. International transfers

Some of the service providers we use process data in countries outside the United Kingdom. Whenever personal data leaves the UK, we ensure the transfer is protected by safeguards recognised under UK data protection law.

Depending on the destination, we rely on one or more of the following:

  • UK adequacy regulations, where the Secretary of State has determined that the destination country provides an adequate level of protection for personal data;
  • the International Data Transfer Agreement (IDTA)issued by the Information Commissioner’s Office;
  • the UK Addendumto the European Commission’s standard contractual clauses, used alongside those clauses;
  • supplementary technical and organisational measures, such as encryption and access restrictions, where our assessment of the destination indicates they are needed.

You can ask us for more information about the safeguards applied to a specific transfer by contacting [email protected].

10. How long we keep information

We keep personal data only for as long as we need it for the purposes set out in this policy, to comply with our legal obligations, or to establish, exercise or defend legal claims. When data is no longer needed, we delete it or irreversibly anonymise it. Where deletion from active systems is immediate but residual copies persist briefly in backups, those copies are overwritten in the ordinary backup cycle and are not used for any other purpose.

Our main retention periods are:

  • Account and profile data: kept while your account is active, and for a limited period after closure so that we can handle follow-up queries, after which it is deleted or anonymised.
  • Transaction records: kept for the statutory periods applicable to accounting and tax records, typically six years from the end of the financial year to which they relate.
  • Certificate records: the minimal record needed to operate verification (holder name, programme, cohort, completion date, certificate identifier and validity status) is retained for as long as we operate the verification service, because a certificate that can no longer be verified loses its value to the holder.
  • Coursework and deliverables: kept for the duration of your programme and a reasonable period afterwards to support completion decisions, appeals and quality assurance, then deleted or anonymised.
  • Support correspondence: kept for as long as reasonably necessary to manage the relationship and any related dispute.
  • Security logs: kept for a short rolling period sufficient to detect and investigate incidents, then deleted.

If you ask us to delete your data under the rights described in section 12, we will do so except where the law requires or permits us to retain specific records, for example transaction records within their statutory retention period.

11. How we protect information

We apply organisational and technical measures appropriate to the nature of the data we hold and the risks involved in processing it. Our participants work in institutions where security is not optional, and we design our own practices accordingly.

  • all data in transit between your browser and the platform is encrypted;
  • access to personal data within Xium Labs is restricted to those who need it for their role, on a least-privilege basis, and access is revoked when no longer required;
  • passwords are stored only in protected, non-reversible form, and authentication sessions are protected against common attack techniques;
  • production systems are separated from development and testing environments;
  • we assess the security practices of service providers before engaging them and hold them to contractual security obligations;
  • we maintain procedures for identifying, containing and, where required by law, notifying personal data breaches to the Information Commissioner’s Office and to affected individuals.

No system can be guaranteed to be completely secure, and we do not promise absolute security. What we do promise is that we treat security as an engineering discipline rather than a compliance checkbox, and that if a breach occurs which puts your rights at risk, we will tell you without undue delay. You also play a part: choose a strong, unique password, keep it confidential and tell us promptly at [email protected] if you suspect your account has been compromised.

12. Your rights

UK GDPR gives you a set of rights over your personal data. Briefly, they are:

  • The right to be informed: to be told, clearly and transparently, how your data is used. This policy is how we meet that obligation.
  • The right of access: to obtain confirmation that we process your data and to receive a copy of it, together with information about the processing.
  • The right to rectification: to have inaccurate data corrected and incomplete data completed. You can update most account and profile information yourself from your account settings.
  • The right to erasure: to have your data deleted in certain circumstances, for example where it is no longer necessary for the purpose it was collected for. This right is not absolute; see section 10 for records we must retain.
  • The right to restrict processing: to require us to limit how we use your data in certain circumstances, for example while a dispute about accuracy is resolved.
  • The right to data portability: to receive data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • The right to object: to object to processing based on legitimate interests, and to object at any time to direct marketing, in which case we will stop.
  • Rights relating to automated decision-making: not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make decisions of that kind about participants; completion and certification decisions involve human review.

To exercise any of these rights, email us at [email protected]. We may need to verify your identity before acting on a request, which protects your data from being disclosed to the wrong person. We respond within one month of receiving a valid request. For complex or numerous requests we may extend that period by up to two further months, in which case we will tell you within the first month and explain why. We do not charge for handling requests unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data or a request, we would ask that you contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at ico.org.uk.

13. Marketing and communications

We distinguish between two kinds of email, and we treat them differently.

Transactional communications are messages we must send to run the service: account confirmations, security notices, enrolment and payment confirmations, cohort start reminders, weekly course communications and certificate issuance notices. These are part of delivering the programme you enrolled in, and you cannot opt out of them while you hold an active account or enrolment, although we keep them to what is genuinely necessary.

Marketing communications tell you about new programmes, upcoming cohorts and other offerings we think may interest you, such as those listed on our Discover page. We send marketing only where the law permits, and every marketing email contains a working unsubscribe link. You can opt out at any time by using that link, by adjusting your account settings, or by emailing [email protected]. Opting out of marketing has no effect on transactional communications or on your access to the platform.

We do not share your contact details with third parties for their marketing, and we do not run advertising on the platform.

14. Children

HackXium is a professional training platform for senior practitioners and executives. It is not directed at children, and we do not knowingly offer accounts to, or collect personal data from, anyone under the age of 18. Our programmes assume professional experience that a child would not have, and our Terms of Service require account holders to be at least 18 years old.

If you believe that a person under 18 has created an account or provided us with personal data, please contact us at [email protected]. If we learn that we hold personal data about a child, we will delete it promptly.

15. Changes to this policy

We review this policy periodically and update it when our practices, the platform or the law change. When we make changes, we will revise the effective date shown at the top of this page. If a change is material, for example a new purpose for processing or a new category of recipient, we will give you clearer notice, such as an email to your registered address or a prominent notice on the platform, before the change takes effect.

Earlier versions of this policy are available on request. We encourage you to review this page from time to time so that you always know how your personal data is handled. Your continued use of HackXium after a change takes effect indicates that you have had the opportunity to review the updated policy, but it does not constitute consent where consent is the lawful basis we rely on; in those cases we will ask for consent separately.

16. Contact us

Questions, requests and complaints about this policy or about how we handle personal data should be directed to:

  • Email:[email protected] (marking your message “Data protection” will help us route it quickly)
  • Company: Xium Labs Ltd, registered in England and Wales, Company No. 16702035

We aim to acknowledge every data protection enquiry promptly and to resolve it within the timescales described in section 12. If you remain dissatisfied, you may complain to the Information Commissioner’s Office at ico.org.uk, as described above.