Tyscorpa Academy ("we", "the Service") provides practice tests and study material for cybersecurity certification exams at academy.tyscorpa.com.
Data controller: Giovanni Coronado (ABN 22 961 262 569), 13 Alan Street, Kings Park, Victoria, Australia. Privacy contact: info@tyscorpa.com.
We are based in Australia and handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Because the Service is available internationally, we also apply the UK and EU General Data Protection Regulation to users in those regions, and we extend the same rights to everyone regardless of where they live.
| Data | Why | Lawful basis (GDPR) |
|---|---|---|
| Username | Identifies your account and is shown in the interface | Performance of a contract |
| Email address | Account confirmation, password reset, and essential service notices | Performance of a contract |
| Full name (optional) | Personalises the interface. You may leave it blank | Consent |
| Password | Stored only as a bcrypt hash. We cannot read or recover your password | Performance of a contract |
| Test activity | Your answers, scores, timing and per-domain results, used to produce your progress and weakness analysis | Performance of a contract |
| Practice streaks | Counts the days you have practised | Performance of a contract |
| IP address and sign-in attempts | Rate limiting, to protect accounts against brute-force attacks and to prevent bulk creation of fake accounts | Legitimate interests — keeping accounts secure |
We do not collect payment card details. We do not use advertising trackers, we do not profile you for marketing, and we do not sell or rent personal data to anyone.
We do not use tracking cookies. After you sign in, the Service stores an
authentication token in your browser's localStorage so you stay
signed in. It expires after 24 hours, and signing out removes it. Installing
the app to your home screen also caches interface files locally so it can
open without a connection; that cache never contains your test data or
personal information.
| Provider | Role | Location |
|---|---|---|
| Hostinger | Hosting and database storage | Singapore (backups in India) |
| Google (Workspace) | Delivers confirmation and password-reset email | Global |
| jsDelivr, unpkg | Content delivery networks serving interface libraries. Because your browser fetches files from them directly, they may observe your IP address and browser type | Global |
Our servers are in Singapore, with backups in India. Your information is therefore stored outside Australia, and outside the UK and EEA.
Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles. For users in the UK or EEA, these transfers rely on the standard contractual clauses offered by the providers listed above.
You may ask us to:
Write to info@tyscorpa.com. We will respond within 30 days. Exercising these rights is free, and we will not treat you differently for doing so.
If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). Users in the UK or EEA may instead complain to their own supervisory authority.
All traffic is encrypted with HTTPS. Passwords are hashed with bcrypt. Access to the API requires a signed, expiring token, and both sign-in and registration are rate limited. Server-side files, database credentials and application secrets are kept outside the public web directory. No system is perfectly secure, but we do not store payment details, and we keep the personal data we hold to what the Service actually needs.
If a breach occurs that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner as required by Australia's Notifiable Data Breaches scheme. Where the UK or EU GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of it.
The Service is not directed at children under 16, and we do not knowingly collect their data. Contact us if you believe a child has created an account and we will remove it.
If we make a significant change, we will update the date at the top of this page and, where the change materially affects you, notify you by email.