1. Overview & Data Controller
BlackHatCommando Academy ("we", "our", or "the Academy") is dedicated to protecting the privacy, confidentiality, and security of our students, faculty, and website visitors. This Privacy Policy details how we collect, store, process, and safeguard your personal data in compliance with international privacy benchmarks including GDPR, CCPA, and applicable Digital Personal Data Protection laws.
2. Information We Collect
When interacting with our learning portal, cyber ranges, and services, we collect both actively submitted and automated technical telemetry:
- Identity & Contact Information: Full name, verified email address, mobile phone number, country/region of residence, and billing details provided during account registration.
- Academic & Cyber Range Progress: Course completion rates, hands-on lab telemetry, CTF challenge flags, examination scores, and cryptographic certificate issuances.
- Technical & Session Telemetry: IP address, device fingerprints, browser version, access timestamps, and security audit logs to maintain SOC infrastructure defense and prevent malicious account sharing.
3. Purpose of Data Processing
We process collected data exclusively for legitimate educational and security purposes:
- Provisioning access to structured cybersecurity curriculums, virtual machines, and hands-on lab environments.
- Issuing verifiable, tamper-evident cryptographic certificates of completion.
- Conducting continuous threat monitoring, brute-force mitigation, and maintaining account integrity.
- Delivering critical transactional alerts, security advisories, and administrative notices.
4. Cookie & Local Storage Governance
Our platform uses essential session cookies and local storage tokens strictly required for user authentication, CSRF mitigation, and preserving user interface preferences (such as grid layout modes and theme selections). We do not deploy third-party advertising trackers or sell your personal data to data brokers.
5. Inactive Account & Retention Policy
In accordance with academy storage management standards:
- 90-Day Inactive Threshold: If a student account remains inactive without any login or lab activity for more than 90 consecutive days, active course enrollments are moved to an archival state. Account reactivation may be requested via support or payment of a nominal reactivation administrative fee of ₹1,500/- INR.
- Multi-Notice Enforcement: Accounts accumulating multiple severe policy non-compliance notices may be subject to temporary administrative suspension until verified by our compliance team.
6. Data Subject Rights
Depending on your jurisdiction, you are entitled to exercise the following rights regarding your data:
- The right to request access to and receive a portable copy of your personal data.
- The right to request rectification of inaccurate profile attributes.
- The right to request erasure of your personal data where retention is not required by legal or certification audit obligations.
- The right to object to or restrict processing of specific automated profiling.
7. Data Security & Storage Architecture
All sensitive personal information, cryptographic credentials, and session tokens are encrypted at rest using AES-256 and in transit via TLS 1.3 encryption protocols. System access is strictly restricted through role-based access control (RBAC) and monitored through real-time audit logging.
8. Contacting the Privacy Officer
For inquiries, rights requests, or data protection concerns, contact our Security & Privacy Operations team:
Email: support@blackhatcommando.com | contact@blackhatcommando.com
Hotline: +91 6284101718
Address: BlackHatCommando Academy, Cyber Operations Center, India