← Back to home

Privacy Policy

10x Technologies (“10x Technologies”, “we”, “us”, or “our”) provides a learning platform that helps people and organizations build technology and AI capability. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the rights you can exercise over it.

We are a Canadian company and handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). Where they apply, we also honour the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).

1. Who this policy covers

This policy applies to visitors to our website, individuals who create an account, and learners who are enrolled by an organization (for example, an employer) that licenses our platform. Where an organization enrols you and manages your training, that organization is the controller of your learning records and we act as its processor — see “Organization (business) accounts” below.

2. Information we collect

We collect only what we need to run the platform:

  • Account and identity data. When you sign in, our identity provider passes us your name and email address, and a stable account identifier. You may add optional profile details such as a display name and a short bio.
  • Learning activity. Learning paths you enrol in, modules you open, quiz attempts and scores, completions, certificates issued, streaks and points, and skill self-assessments.
  • Content you submit. Discussion comments, ratings and their comments, workshop/session notes, organization and team names, and messages you send us (for example, through the contact form).
  • Organization membership. The organizations and teams you belong to, your role, and assignments given to you.
  • Technical and usage data. Information needed to operate and secure the service, such as your IP address, request logs, and general device/browser information. We store a small amount of state in your browser (see “Cookies”).

We do not intentionally collect special categories of data (such as health, biometric, or government-ID data) and ask that you not submit them in free-text fields.

3. How we use your information

  • To create and maintain your account and authenticate you.
  • To deliver learning paths, track progress, grade quizzes, and issue and verify certificates.
  • To provide organization dashboards, assignments, and aggregate reporting to the administrators of an organization you belong to.
  • To send transactional and service messages (for example, invitations, assignment notifications, and certificate confirmations).
  • To respond to your enquiries and support requests.
  • To secure the service, prevent abuse and fraud, debug, and enforce our terms.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use it for third-party advertising.

4. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases: performance of a contract (to provide the service you or your organization requested); legitimate interests (to secure, improve, and operate the platform, balanced against your rights); consent (for optional communications, where required, which you may withdraw at any time); and legal obligation (to meet our compliance and record-keeping duties).

5. Cookies and similar technologies

We use only the storage necessary to run the platform — for example, a sign-in session cookie set by our identity provider and small values kept in your browser’s local storage to remember preferences such as your selected theme and current organization. We do not use advertising or cross-site tracking cookies. You can clear this storage in your browser at any time, though doing so may sign you out or reset preferences.

6. How we share your information

We share personal information only as described here:

  • Service providers (processors). We host the platform and its database on Microsoft Azure, and we send email through Microsoft Azure Communication Services. These providers process data on our behalf under contractual data-protection commitments.
  • Your organization. If you are enrolled by an organization, its administrators can see your learning records (enrolments, progress, quiz outcomes, completions, and certificates) and identity within that organization.
  • Legal and safety. We may disclose information where required by law, to respond to lawful requests, or to protect the rights, safety, and security of our users, the public, or us.
  • Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

We maintain a current list of sub-processors and will make it available to enterprise customers on request.

7. International data transfers

Our providers may process and store data in data centres located outside your province or country, including in Canada, the United States, and the European Union. Where personal information is transferred across borders, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses, where applicable) and take reasonable steps to ensure it remains protected consistent with this policy.

8. How long we keep your information

We keep personal information for as long as your account is active and as needed to provide the service. Learning records and issued certificates may be retained by your organization to evidence training and compliance for as long as that organization requires. When information is no longer needed, we delete or anonymize it, unless a longer retention period is required by law. When you exercise a valid deletion request, we erase or anonymize your personal information as described below.

9. How we protect your information

We use technical and organizational safeguards appropriate to the sensitivity of the data, including encryption in transit, access controls, managed cloud infrastructure, request rate-limiting, and least-privilege access to production systems. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any security incident.

10. Your privacy rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you and receive a copy.
  • Correct information that is inaccurate or incomplete.
  • Delete / erase your personal information (GDPR Art. 17; CCPA right to delete). We will erase or anonymize your profile and associated personal information, subject to records your organization or the law requires us to retain.
  • Port your data by receiving it in a structured, commonly used, machine-readable format.
  • Restrict or object to certain processing, and withdraw consent where processing is based on consent.
  • Non-discrimination — we will not deny you service or charge you differently for exercising your privacy rights.

To exercise any of these rights, email privacy@10xtechnologies.ca or use our contact form. We will verify your request and respond within the timeframe required by applicable law (generally 30 days under PIPEDA and the CCPA, and one month under the GDPR). You may authorize an agent to make a request on your behalf. If your account is managed by an organization, we may direct or coordinate your request with that organization as the controller of your records.

11. Organization (business) accounts

When an organization licenses our platform for its people, that organization decides who is enrolled, what training is assigned, and how long records are kept. For those learning records the organization is the controller and 10x Technologies is the processor acting on its documented instructions. If you are an enrolled learner, please direct requests about your records to your organization’s administrator; we will assist the organization in responding. Enterprise customers can request a Data Processing Agreement (DPA).

12. Children’s privacy

The platform is intended for use in professional and workplace learning and is not directed to children. We do not knowingly collect personal information from children under the age of 16. If you believe a child has provided us personal information, please contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the platform after an update means you accept the revised policy.

14. Contact us

For privacy questions, requests, or complaints, contact our privacy team:

If you are in Canada and are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada. If you are in the EU/UK, you may lodge a complaint with your local data protection supervisory authority. If you are a California resident, you may exercise the rights described in Section 10.