Legal & Privacy
Artix Solutions Inc
Effective date: 2025-01-01
This Privacy Policy (“Policy”) is issued by Artix Solutions and applies to all websites, web applications, APIs, and digital services operated under the Artix Solutions brand (“Services”). It describes how we collect, use, store, share, and protect personal information when you interact with any of our Services.
This Policy covers the following service types:
Where a specific Service has supplemental privacy terms โ for example, our Trading Platform โ those terms are presented alongside this Policy and should be read together with it. In case of conflict, the supplemental terms prevail for that Service.
This Policy does not apply to third-party websites or services that may be linked from our Services. We are not responsible for the privacy practices of those third parties and encourage you to review their policies directly.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Provide and operate our Services | Creating your account, authenticating your identity, displaying your dashboard, processing transactions. | Contract |
| Personalisation | Recommending courses, tailoring content, remembering your preferences and language settings. | Legitimate interest Consent |
| Communications & Support | Responding to enquiries, sending service-critical notifications, providing customer support. | Contract Legitimate interest |
| Marketing & Promotions | Sending newsletters, product updates, and offers you have opted in to receive. | Consent |
| Analytics & Improvement | Understanding how our Services are used, identifying bugs, improving user experience. | Legitimate interest Consent |
| Security & Fraud Prevention | Detecting suspicious activity, preventing unauthorised access, protecting user accounts. | Legitimate interest Legal obligation |
| Legal & Regulatory Compliance | Maintaining records required by law, responding to lawful requests from authorities, filing statutory reports. | Legal obligation |
| CV Processing & Job Matching | Parsing and indexing CV content to match candidates with relevant opportunities; presenting your profile to authorised recruiters (with your consent). | Consent Contract |
We are required by data protection law to identify a lawful basis for each processing activity. The bases we rely on are explained below.
Where we process special categories of personal data (e.g. health information disclosed in a CV, or biometric data used for KYC verification on the Trading Platform), we rely on one of the additional conditions in Article 9 GDPR / Schedule 1 DPA 2018 โ typically explicit consent or substantial public interest. We will identify the applicable condition clearly at the point of collection.
Artix Solutions does not sell personal data. We do not share your personal information with third parties except in the circumstances described below.
| Recipient Category | Examples | Safeguard | Transfer Location |
|---|---|---|---|
| Service Providers (Processors) | Cloud hosting (AWS/Azure/GCP), email delivery, payment processors, analytics platforms, customer support software. | Data Processing Agreement (DPA); contractually bound to process data only on our instructions. | May be outside EEA โ see International Transfers |
| Professional Advisers | Lawyers, auditors, accountants, insurance brokers. | Bound by professional confidentiality obligations and, where applicable, a DPA. | Primarily within EEA/UK |
| Regulatory & Law Enforcement Authorities | ICO, FCA, HMRC, police forces, courts. | Disclosed only where required or permitted by law; we challenge overly broad requests. | Jurisdiction-dependent |
| Business Transferees | Acquirers, merger partners, investors in due diligence. | Covered by NDA; post-completion, acquiring entity assumes this Policy or notifies you of changes. | N/A |
| Recruitment Partners (Education Platform) | Employers and recruiters who have signed our recruiter terms and may view your CV profile. | Recruiter Agreement; you control visibility through your privacy settings. | EEA/UK; international with adequacy or SCCs |
On our Education Platform you may choose to sign in or register using your LinkedIn account via the OAuth 2.0 protocol. This is an optional convenience โ you can always register with an email and password instead.
r_liteprofile and r_emailaddress scopes. We do not request access to your connections, messages, or activity feed.You can revoke our access to your LinkedIn account at any time through your LinkedIn permitted services settings. Revoking access will not delete your account on our platform but will require you to set a password to continue logging in. You may also request deletion of all LinkedIn-sourced data by contacting us.
Our Education Platform allows you to upload your CV or rรฉsumรฉ to enhance your profile and be considered for relevant opportunities. By uploading a CV you are providing us with data under your explicit consent.
CVs sometimes contain special category personal data such as health information, disability disclosures, political opinions, or religious beliefs. We do not actively collect this data and do not use it in automated decision-making. If your CV contains such information and you wish us to redact it, please contact our Privacy team. We rely on your explicit consent as the legal basis for processing any special category data incidentally contained in your CV.
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. The table below summarises our standard retention periods. At the end of each retention period, data is securely deleted or anonymised.
| Data Category | Examples | Retention Period | Legal Basis | Platform |
|---|---|---|---|---|
| Account & Profile Data | Name, email, password hash, preferences | 3 years after last login, or on deletion request | Contract Legitimate interest | All |
| CV / Rรฉsumรฉ Data | Uploaded CV file, skills, work history | 2 years from upload, or on deletion request | Consent Contract | Education |
| LinkedIn OAuth Tokens | Access token, profile snapshot at auth time | Session + 90 days for refresh token | Consent | Education |
| Analytics & Usage Data | Page views, session data, device info | 26 months | Consent Legitimate interest | All |
| Server & Security Logs | IP address, request path, error traces | 90 days | Legitimate interest Legal obligation | All |
| Marketing Communications | Email opt-in, campaign clicks, unsubscribes | Until withdrawal of consent + 1 year audit trail | Consent | All |
| Support & Contact Records | Ticket history, chat transcripts, call logs | 3 years from closure | Contract Legitimate interest | All |
Retention periods may be extended where required to defend legal claims, comply with regulatory investigations, or fulfil ongoing contractual obligations. You may request early deletion of your data (see Your Rights below), subject to overriding legal obligations.
Depending on your location, you have the following rights regarding your personal data. We aim to respond to all legitimate requests within 30 days. We will not charge a fee for exercising your rights unless a request is unfounded, excessive, or repetitive.
Request a copy of the personal data we hold about you, together with information about how and why we process it.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data where there is no compelling reason for us to continue processing it.
Request that we limit the way we use your data while a dispute about accuracy or lawfulness is resolved.
Receive your personal data in a structured, commonly used, machine-readable format (e.g. JSON, CSV) and transmit it to another controller.
Object to processing based on legitimate interests or for direct marketing purposes. Marketing objections are always honoured immediately; other objections are assessed case by case.
Where processing is based on consent, withdraw it at any time without affecting prior processing.
Not to be subject to a decision based solely on automated processing (including profiling) that produces significant legal or similar effects.
To exercise any of these rights, or to raise a concern about our data handling, please contact our Privacy team (see the Contact section below). You also have the right to complain to your local data protection supervisory authority โ in the UK, this is the Information Commissioner's Office (ICO).
Some of our service providers and business partners are located outside the UK and European Economic Area (EEA). When we transfer personal data internationally, we ensure that an appropriate safeguard is in place.
You may request a copy of the specific transfer mechanism used for any given transfer by contacting us.
We implement a layered programme of technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure.
Despite these measures, no system is completely secure. If you believe your account has been compromised, please contact us immediately.
We use cookies and similar tracking technologies (web beacons, pixels, local storage) to operate our Services and, with your consent, to analyse usage and deliver personalised content. Our full Cookie Policy details every cookie we use, its purpose, provider, and duration.
You can manage your cookie preferences at any time via the Cookie Consent Manager. Withdrawing consent for non-essential cookies will not affect your ability to use our core Services.
Our Services are not directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction โ 13 in the US under COPPA). We do not knowingly collect personal data from children without verifiable parental or guardian consent.
If you believe we have inadvertently collected data from a child, please contact us immediately. We will delete such data promptly upon verification.
Educational institutions deploying our Education Platform on behalf of students who may be under 16 must obtain appropriate consents and have a signed Data Processing Agreement with us in place before granting student access.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following additional rights:
To submit a verifiable consumer request, email us with “California Privacy Request” in the subject line. We will respond within 45 days (extendable by a further 45 days with notice). We may need to verify your identity before processing your request.
This Policy is designed to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as well as the EU GDPR where applicable. Our Services are governed by the laws of England and Wales.
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Artix Solutions will notify you of material changes by:
We will update the “Effective Date” at the top of this Policy whenever it changes. Where a change requires your fresh consent (e.g. a new purpose for processing), we will seek that consent before the change takes effect.
We encourage you to review this Policy periodically. Continued use of our Services after the effective date of a revised Policy constitutes your acceptance of the changes, to the extent permitted by applicable law.
If you have any questions, concerns, or requests regarding this Privacy Policy or how Artix Solutions processes your personal data, please contact our Privacy team:
We aim to respond to all privacy enquiries within 30 days. Where your request is complex or numerous, we may extend this period by a further two months, in which case we will notify you.