Last updated 2 August 2026
This policy explains what we collect, how we use it, and the choices you have. It applies to everyone who uses StrikeOps Academy.
StrikeOps Academy is an online offensive-security learning and certification platform operated by StrikeOps Inc., a company incorporated in the United States (“StrikeOps Academy”, “we”, “us”). This policy covers strikeopsacademy.com and the StrikeOps Academy learning platform.
For the purposes of the UK and EU GDPR, StrikeOps Inc. is the data controller for the personal data described here. You can reach our privacy team at privacy@strikeopsacademy.com.
Account and profile data you provide: your name, email address, password or sign-in method, organisation, and country or region (which drives applicable terms and tax).
Billing data: subscriptions and certification exams are processed by our payment provider, Stripe. Stripe handles your card details directly; we receive limited billing metadata (for example, the last four digits, plan, and transaction status) and never store full card numbers.
Learning data: your enrolments, module progress, knowledge-check and lab activity, exam attempts, and issued credentials.
Communications: messages you send us through the contact form, support requests, and related correspondence.
Technical data: IP address, device and browser information, approximate location derived from IP, and usage collected through cookies and privacy-respecting analytics.
We use strictly necessary cookies to keep you signed in and to remember preferences such as your theme. We use privacy-respecting, aggregate analytics (including Vercel Web Analytics and Speed Insights) to understand traffic and performance; these do not build advertising profiles of you.
You can control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the platform, such as sign-in, from working.
To deliver the courses, labs, and assessments; process payments; issue, display, and verify credentials; personalise and improve the content; communicate with you about your account and the service; secure the platform and prevent abuse; and meet our legal and regulatory obligations.
Where the GDPR applies, we rely on: performance of our contract with you (to provide the courses, labs, exams, and credentials); our legitimate interests (to secure, maintain, and improve the platform, and to prevent abuse), balanced against your rights; your consent (for optional marketing, which you can withdraw at any time); and compliance with legal obligations (such as tax and accounting).
With service providers who process data on our behalf under contract (see Sub-processors below). When you choose to display or share a credential, the linked verification page is public by design so that others can confirm it.
In connection with a corporate transaction such as a merger or acquisition, and where required by law, legal process, or to protect the rights, safety, and security of the platform and its users.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
We use a small set of vetted providers to run the service: cloud hosting and delivery (Vercel), our application database (Neon, Postgres), authentication (WorkOS), payments and tax (Stripe), and analytics (Vercel). Each processes personal data only on our instructions and under appropriate data-protection terms.
We operate across the Five Eyes markets (Australia, Canada, New Zealand, the United Kingdom, and the United States) and our providers may process data in those and other countries. Where data leaves your region, we rely on appropriate safeguards, such as the UK/EU Standard Contractual Clauses or an adequacy decision, as applicable.
We keep personal data only as long as needed for the purposes above or as the law requires. Account and learning data are retained while your account is active and for a reasonable period afterwards. Credential records are retained so that issued badges remain verifiable. Billing records are kept for the periods required by tax law.
Subject to applicable law, you can request access to, correction of, deletion of, or a portable copy of your personal data; object to or restrict certain processing; and withdraw consent where processing is based on it.
We honour rights under the UK and EU GDPR, the Australian Privacy Act 1988 (and the Australian Privacy Principles), Canada’s PIPEDA, New Zealand’s Privacy Act 2020, and US state privacy laws including the California Consumer Privacy Act, where they apply to you.
To exercise any right, email privacy@strikeopsacademy.com. We will respond within the timeframe your law requires and may need to verify your identity first. We will not discriminate against you for exercising a right.
We send account and service messages that are necessary to provide the platform. Any optional marketing is sent only with your consent or where otherwise permitted, and every marketing message includes an unsubscribe link. Opting out of marketing does not stop essential service messages.
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and managed authentication. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security. If you believe you have found a vulnerability, please contact security@strikeopsacademy.com.
The platform is intended for professionals and is not directed to children. You must meet the age of digital consent in your jurisdiction to create an account. If we learn that we have collected a child’s data without a lawful basis, we will delete it.
If you have a concern, contact us first at privacy@strikeopsacademy.com and we will try to resolve it. You also have the right to complain to your data-protection authority. Examples include the UK Information Commissioner’s Office (ICO), the Office of the Australian Information Commissioner (OAIC), the Office of the Privacy Commissioner of Canada, or the Office of the Privacy Commissioner in New Zealand.
We may update this policy from time to time and will post the revised version here with a new date; material changes will be highlighted. Questions or requests can be sent to privacy@strikeopsacademy.com.