Skip to main content

Legal & Privacy

Privacy Policy

Artix Solutions Inc

Effective date: 2025-01-01

Scope of This Policy

This Privacy Policy (“Policy”) is issued by Artix Solutions and applies to all websites, web applications, APIs, and digital services operated under the Artix Solutions brand (“Services”). It describes how we collect, use, store, share, and protect personal information when you interact with any of our Services.

This Policy covers the following service types:

  • Corporate / Software Website โ€” our public-facing marketing and product information sites.
  • Education Platform โ€” e-learning courses, assessments, career tools, and CV/profile management, including LinkedIn OAuth sign-in.

Where a specific Service has supplemental privacy terms โ€” for example, our Trading Platform โ€” those terms are presented alongside this Policy and should be read together with it. In case of conflict, the supplemental terms prevail for that Service.

This Policy does not apply to third-party websites or services that may be linked from our Services. We are not responsible for the privacy practices of those third parties and encourage you to review their policies directly.

Information We Collect

Information You Provide Directly

  • Identity data โ€” full name, username, date of birth.
  • Contact data โ€” email address, telephone number, postal address.
  • Account credentials โ€” hashed password; security questions (where applicable).
  • Communications โ€” messages you send via contact forms, support tickets, live chat, or email.
  • Profile & preference data โ€” professional background, interests, newsletter preferences.

Information We Collect Automatically

  • Device & browser data โ€” IP address, browser type and version, operating system, screen resolution, time zone.
  • Usage data โ€” pages viewed, links clicked, features used, session duration, referring URL.
  • Log data โ€” server access logs including request path, response codes, and timestamps.
  • Cookies & tracking technologies โ€” see our Cookie Policy for full details.

Education & Career Data (Education Platform)

  • CV / Rรฉsumรฉ โ€” uploaded document (PDF, DOCX) containing work history, education, and skills.
  • LinkedIn profile data โ€” when you authenticate via LinkedIn OAuth: public profile, name, email, profile picture, and headline (scope limited to what you authorise).
  • Academic records โ€” courses enrolled, grades, certificates earned (where applicable).
  • Assessment responses โ€” quiz answers, assignment submissions, feedback.

Information from Third Parties

  • Social login providers โ€” identity attributes (name, email, profile picture) shared when you authenticate via LinkedIn, Google, or similar providers.
  • Analytics providers โ€” aggregated, de-identified behavioural data.
  • Credit reference / KYC agencies โ€” identity verification results (Trading Platform only).
  • Business partners โ€” contact details where you have separately consented to sharing.

How We Use Your Information

Purpose Examples Legal Basis
Provide and operate our Services Creating your account, authenticating your identity, displaying your dashboard, processing transactions. Contract
Personalisation Recommending courses, tailoring content, remembering your preferences and language settings. Legitimate interest Consent
Communications & Support Responding to enquiries, sending service-critical notifications, providing customer support. Contract Legitimate interest
Marketing & Promotions Sending newsletters, product updates, and offers you have opted in to receive. Consent
Analytics & Improvement Understanding how our Services are used, identifying bugs, improving user experience. Legitimate interest Consent
Security & Fraud Prevention Detecting suspicious activity, preventing unauthorised access, protecting user accounts. Legitimate interest Legal obligation
Legal & Regulatory Compliance Maintaining records required by law, responding to lawful requests from authorities, filing statutory reports. Legal obligation
CV Processing & Job Matching Parsing and indexing CV content to match candidates with relevant opportunities; presenting your profile to authorised recruiters (with your consent). Consent Contract

Sharing & Disclosure of Your Information

Artix Solutions does not sell personal data. We do not share your personal information with third parties except in the circumstances described below.

Recipient Category Examples Safeguard Transfer Location
Service Providers (Processors) Cloud hosting (AWS/Azure/GCP), email delivery, payment processors, analytics platforms, customer support software. Data Processing Agreement (DPA); contractually bound to process data only on our instructions. May be outside EEA โ€” see International Transfers
Professional Advisers Lawyers, auditors, accountants, insurance brokers. Bound by professional confidentiality obligations and, where applicable, a DPA. Primarily within EEA/UK
Regulatory & Law Enforcement Authorities ICO, FCA, HMRC, police forces, courts. Disclosed only where required or permitted by law; we challenge overly broad requests. Jurisdiction-dependent
Business Transferees Acquirers, merger partners, investors in due diligence. Covered by NDA; post-completion, acquiring entity assumes this Policy or notifies you of changes. N/A
Recruitment Partners (Education Platform) Employers and recruiters who have signed our recruiter terms and may view your CV profile. Recruiter Agreement; you control visibility through your privacy settings. EEA/UK; international with adequacy or SCCs

Third-Party Authentication (LinkedIn OAuth 2.0)

On our Education Platform you may choose to sign in or register using your LinkedIn account via the OAuth 2.0 protocol. This is an optional convenience โ€” you can always register with an email and password instead.

What data LinkedIn shares with us

  • Basic profile โ€” first name, last name, LinkedIn profile URL, profile picture.
  • Email address โ€” your primary LinkedIn email address.
  • Professional headline โ€” your current title/role as shown on LinkedIn.
  • We request only the r_liteprofile and r_emailaddress scopes. We do not request access to your connections, messages, or activity feed.

How we use LinkedIn data

  • To create or log you in to your account without requiring a separate password.
  • To pre-populate your profile fields (name, email, headline) โ€” you can edit or delete these at any time.
  • We do not post to LinkedIn on your behalf.
  • We do not store your LinkedIn password โ€” authentication is handled entirely by LinkedIn.

Revoking access

You can revoke our access to your LinkedIn account at any time through your LinkedIn permitted services settings. Revoking access will not delete your account on our platform but will require you to set a password to continue logging in. You may also request deletion of all LinkedIn-sourced data by contacting us.

Token handling

  • Access tokens are stored encrypted and are used only to validate your identity at login.
  • Refresh tokens (where issued) are retained for up to 90 days and then purged.
  • Token data is never shared with third parties outside the scope of authentication.

CV / Rรฉsumรฉ Uploads (Education Platform)

Our Education Platform allows you to upload your CV or rรฉsumรฉ to enhance your profile and be considered for relevant opportunities. By uploading a CV you are providing us with data under your explicit consent.

What we do with your CV

  • Parsing & indexing โ€” we use automated tools to extract structured data (skills, job titles, employment history, education) from your document to populate your profile.
  • Profile display โ€” extracted data is shown on your candidate profile within our platform.
  • Matching โ€” your profile data is used by our matching algorithms to identify relevant courses, resources, and (where you opt in) job opportunities.
  • Recruiter visibility โ€” your CV and profile are visible to authorised recruiters only if you switch your profile to “Open to Opportunities” in your privacy settings.

Your controls

  • Download or delete your uploaded CV file at any time from your account settings.
  • Hide your profile from recruiters by switching your visibility to “Private”.
  • Request full erasure of all CV-derived data by contacting us (subject to retention obligations).
  • Withdraw consent for CV-based job matching โ€” this removes your profile from recruiter searches within 48 hours.

Special category data in CVs

CVs sometimes contain special category personal data such as health information, disability disclosures, political opinions, or religious beliefs. We do not actively collect this data and do not use it in automated decision-making. If your CV contains such information and you wish us to redact it, please contact our Privacy team. We rely on your explicit consent as the legal basis for processing any special category data incidentally contained in your CV.

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. The table below summarises our standard retention periods. At the end of each retention period, data is securely deleted or anonymised.

Data Category Examples Retention Period Legal Basis Platform
Account & Profile Data Name, email, password hash, preferences 3 years after last login, or on deletion request Contract Legitimate interest All
CV / Rรฉsumรฉ Data Uploaded CV file, skills, work history 2 years from upload, or on deletion request Consent Contract Education
LinkedIn OAuth Tokens Access token, profile snapshot at auth time Session + 90 days for refresh token Consent Education
Analytics & Usage Data Page views, session data, device info 26 months Consent Legitimate interest All
Server & Security Logs IP address, request path, error traces 90 days Legitimate interest Legal obligation All
Marketing Communications Email opt-in, campaign clicks, unsubscribes Until withdrawal of consent + 1 year audit trail Consent All
Support & Contact Records Ticket history, chat transcripts, call logs 3 years from closure Contract Legitimate interest All

Your Data Protection Rights

Depending on your location, you have the following rights regarding your personal data. We aim to respond to all legitimate requests within 30 days. We will not charge a fee for exercising your rights unless a request is unfounded, excessive, or repetitive.

Right of Access (Subject Access Request)

Request a copy of the personal data we hold about you, together with information about how and why we process it.

How to exercise: Email us with “Subject Access Request” in the subject line. We will respond within 30 days (extendable to 3 months for complex requests).
Limitations: None (first copy free; reasonable fee for subsequent copies).

Right to Rectification

Request correction of inaccurate or incomplete personal data.

How to exercise: Update most data yourself in account settings, or contact us for data you cannot edit directly.
Limitations: We may need to verify accuracy before making changes.

Right to Erasure (“Right to be Forgotten”)

Request deletion of your personal data where there is no compelling reason for us to continue processing it.

How to exercise: Submit a deletion request via your account settings or by email.
Limitations: Does not apply where retention is required by law (e.g. financial records), to defend legal claims, or to exercise freedom of expression.

Right to Restrict Processing

Request that we limit the way we use your data while a dispute about accuracy or lawfulness is resolved.

How to exercise: Contact us; data will be flagged and processing restricted pending resolution.
Limitations: We may still process restricted data for storage, legal claims, or with your consent.

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format (e.g. JSON, CSV) and transmit it to another controller.

How to exercise: Request a data export from your account settings or by email.
Limitations: Applies only to data processed by automated means on the basis of consent or contract.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes. Marketing objections are always honoured immediately; other objections are assessed case by case.

How to exercise: Use the unsubscribe link in any marketing email, or contact us.
Limitations: For non-marketing objections, we may override your objection if we have compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent, withdraw it at any time without affecting prior processing.

How to exercise: Use in-app consent controls, the cookie manager, or contact us.
Limitations: Withdrawal does not affect lawfulness of processing before withdrawal.

Rights Re: Automated Decision-Making

Not to be subject to a decision based solely on automated processing (including profiling) that produces significant legal or similar effects.

How to exercise: Contact us to request human review of any automated decision affecting you.
Limitations: Exceptions apply where necessary for a contract or authorised by law, with appropriate safeguards.

International Data Transfers

Some of our service providers and business partners are located outside the UK and European Economic Area (EEA). When we transfer personal data internationally, we ensure that an appropriate safeguard is in place.

Adequacy Decisions
Transfers to countries that the UK Government or the European Commission has determined offer an adequate level of protection (e.g. transfers to the EEA from the UK under the UK GDPR).
Standard Contractual Clauses (SCCs)
EU Commission-approved or UK International Data Transfer Agreements (IDTAs) incorporated into our contracts with third-party processors in non-adequate countries such as the United States.
Binding Corporate Rules (BCRs)
Approved internal rules for intra-group transfers where applicable.
Derogations
In limited circumstances (e.g. your explicit consent, performance of a contract in your interest), we may rely on a derogation under Article 49 GDPR.

You may request a copy of the specific transfer mechanism used for any given transfer by contacting us.

Security of Your Information

We implement a layered programme of technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure.

  • Encryption in transit โ€” all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
  • Encryption at rest โ€” databases and file stores containing personal data are encrypted using AES-256.
  • Access controls โ€” role-based access controls (RBAC) ensure that only authorised personnel can access personal data, on a need-to-know basis.
  • Multi-Factor Authentication (MFA) โ€” required for all staff accessing systems containing personal data; available and encouraged for users.
  • Penetration testing โ€” we commission independent security assessments at least annually.
  • Incident response โ€” we maintain a documented data breach response plan; material breaches are reported to the ICO within 72 hours and to affected individuals without undue delay, as required by law.
  • Vendor security โ€” all third-party processors are assessed against our security standards before engagement and periodically thereafter.

Despite these measures, no system is completely secure. If you believe your account has been compromised, please contact us immediately.

Cookies & Tracking Technologies

We use cookies and similar tracking technologies (web beacons, pixels, local storage) to operate our Services and, with your consent, to analyse usage and deliver personalised content. Our full Cookie Policy details every cookie we use, its purpose, provider, and duration.

You can manage your cookie preferences at any time via the Cookie Consent Manager. Withdrawing consent for non-essential cookies will not affect your ability to use our core Services.

Children's Privacy

Our Services are not directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction โ€” 13 in the US under COPPA). We do not knowingly collect personal data from children without verifiable parental or guardian consent.

If you believe we have inadvertently collected data from a child, please contact us immediately. We will delete such data promptly upon verification.

Educational institutions deploying our Education Platform on behalf of students who may be under 16 must obtain appropriate consents and have a signed Data Processing Agreement with us in place before granting student access.

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following additional rights:

Right to Know
Request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting or sharing it, and the categories of third parties with whom we share it.
Right to Delete
Request deletion of personal information we have collected from you, subject to certain exceptions.
Right to Correct
Request correction of inaccurate personal information.
Right to Opt-Out of Sale / Sharing
We do not sell personal information. We do not share personal information for cross-context behavioural advertising without your consent. Should this change, we will update this Policy and provide an opt-out mechanism.
Right to Limit Use of Sensitive Personal Information
Request that we limit our use of sensitive personal information (as defined by CPRA) to purposes strictly necessary to provide the Services.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To submit a verifiable consumer request, email us with “California Privacy Request” in the subject line. We will respond within 45 days (extendable by a further 45 days with notice). We may need to verify your identity before processing your request.

EEA & UK Data Protection

This Policy is designed to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as well as the EU GDPR where applicable. Our Services are governed by the laws of England and Wales.

Data Controller
The entity that determines the purposes and means of processing is Artix Solutions Inc.
Data Protection Officer (DPO)
We have appointed a Privacy Lead responsible for overseeing compliance. Contact details are in the Contact section below.
Supervisory Authority
In the UK, the supervisory authority is the Information Commissioner's Office (ICO). You have the right to lodge a complaint with them if you believe we have infringed your data protection rights.
Representative in the EU
Where required under Article 27 GDPR, we have appointed an EU representative. Please contact us for their details.

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Artix Solutions will notify you of material changes by:

  • Posting a notice on our website homepage or within the relevant Service.
  • Sending an email notification to the address associated with your account (for registered users).
  • Displaying an in-app banner on your next login.

We will update the “Effective Date” at the top of this Policy whenever it changes. Where a change requires your fresh consent (e.g. a new purpose for processing), we will seek that consent before the change takes effect.

We encourage you to review this Policy periodically. Continued use of our Services after the effective date of a revised Policy constitutes your acceptance of the changes, to the extent permitted by applicable law.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how Artix Solutions processes your personal data, please contact our Privacy team:

We aim to respond to all privacy enquiries within 30 days. Where your request is complex or numerous, we may extend this period by a further two months, in which case we will notify you.