Tyscorpa Academy

Privacy Policy

Last updated: September 2026

Who we are

Tyscorpa Academy ("we", "the Service") provides practice tests and study material for cybersecurity certification exams at academy.tyscorpa.com.

Data controller: Giovanni Coronado (ABN 22 961 262 569), 13 Alan Street, Kings Park, Victoria, Australia. Privacy contact: info@tyscorpa.com.

We are based in Australia and handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Because the Service is available internationally, we also apply the UK and EU General Data Protection Regulation to users in those regions, and we extend the same rights to everyone regardless of where they live.

What we collect and why

DataWhyLawful basis (GDPR)
UsernameIdentifies your account and is shown in the interfacePerformance of a contract
Email addressAccount confirmation, password reset, and essential service noticesPerformance of a contract
Full name (optional)Personalises the interface. You may leave it blankConsent
PasswordStored only as a bcrypt hash. We cannot read or recover your passwordPerformance of a contract
Test activityYour answers, scores, timing and per-domain results, used to produce your progress and weakness analysisPerformance of a contract
Practice streaksCounts the days you have practisedPerformance of a contract
IP address and sign-in attemptsRate limiting, to protect accounts against brute-force attacks and to prevent bulk creation of fake accountsLegitimate interests — keeping accounts secure

We do not collect payment card details. We do not use advertising trackers, we do not profile you for marketing, and we do not sell or rent personal data to anyone.

Storage on your device

We do not use tracking cookies. After you sign in, the Service stores an authentication token in your browser's localStorage so you stay signed in. It expires after 24 hours, and signing out removes it. Installing the app to your home screen also caches interface files locally so it can open without a connection; that cache never contains your test data or personal information.

Who else processes your data

ProviderRoleLocation
HostingerHosting and database storageSingapore (backups in India)
Google (Workspace)Delivers confirmation and password-reset emailGlobal
jsDelivr, unpkgContent delivery networks serving interface libraries. Because your browser fetches files from them directly, they may observe your IP address and browser typeGlobal

Where your data goes

Our servers are in Singapore, with backups in India. Your information is therefore stored outside Australia, and outside the UK and EEA.

Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles. For users in the UK or EEA, these transfers rely on the standard contractual clauses offered by the providers listed above.

How long we keep it

Your rights

You may ask us to:

Write to info@tyscorpa.com. We will respond within 30 days. Exercising these rights is free, and we will not treat you differently for doing so.

If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). Users in the UK or EEA may instead complain to their own supervisory authority.

Security

All traffic is encrypted with HTTPS. Passwords are hashed with bcrypt. Access to the API requires a signed, expiring token, and both sign-in and registration are rate limited. Server-side files, database credentials and application secrets are kept outside the public web directory. No system is perfectly secure, but we do not store payment details, and we keep the personal data we hold to what the Service actually needs.

Data breaches

If a breach occurs that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner as required by Australia's Notifiable Data Breaches scheme. Where the UK or EU GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of it.

Children

The Service is not directed at children under 16, and we do not knowingly collect their data. Contact us if you believe a child has created an account and we will remove it.

Changes

If we make a significant change, we will update the date at the top of this page and, where the change materially affects you, notify you by email.