Data Protection and Cybersecurity Statement DATA PROTECTION AND CYBERSECURITY STATEMENTEnigma Business School (EBS) is committed to ensuring the privacy, security, and protection of all data entrusted to us by students, faculty, staff, alumni, partners, and website visitors. As a global online institution, EBS upholds rigorous standards in safeguarding personal information and maintaining a secure digital learning environment.This statement outlines EBS’s principles, responsibilities, and technological measures for protecting data and ensuring cybersecurity across all platforms, including the Virtual Campus, Student Portal, Tutor LMS Pro, and official communication systems.OUR COMMITMENT TO DATA PROTECTIONEBS adheres to internationally recognized data protection principles, including:Lawfulness, fairness, and transparencyPurpose limitation (data used only for legitimate academic or administrative purposes)Data minimization (collecting only what is necessary)Accuracy and regular updatesStorage limitation with controlled retention periodsIntegrity and confidentiality through strong security measuresEBS respects the privacy rights of all users and does not share personal data with third parties except as required for academic delivery, payment processing, legal compliance, or student-requested services.TYPES OF DATA WE COLLECTEBS may collect and process the following categories of personal data:1. Academic DataEnrollment recordsAssignments, quizzes, and exam submissionsTranscript and certification informationLearning progress through LMS2. Personal Identification DataName, nationality, date of birthContact details (email, phone number)Identification documents submitted for verification3. Financial DataTuition paymentsTransaction informationBilling details (processed securely via payment gateways)4. Technical & Usage DataIP address and device informationLogin activitiesInteraction data within LMSBrowser and system performance logs5. Communication RecordsEmails, support tickets, and academic correspondenceAll data is processed for academic, administrative, and operational purposes only.DATA STORAGE AND SECURITY CONTROLSEBS employs advanced security measures to protect stored data, including:EncryptionAll data transmitted between user devices and EBS servers is encrypted using SSL/TLS protocols.Sensitive information is stored using industry-standard encryption methods.Secure ServersAcademic and administrative data are hosted on secure cloud platforms with restricted access.Regular vulnerability assessments are performed.Access ControlRole-based access ensures data is only accessible to authorized staff.Multi-factor authentication (MFA) may be required for specific administrative functions.Backups and RecoveryRedundant backups ensure data continuity.Disaster recovery protocols allow rapid restoration in case of system failure.Monitoring and Threat DetectionReal-time monitoring tools detect unusual login behavior, brute-force attempts, or suspicious activities.Automated alerts notify administrators of potential threats.CYBERSECURITY IN THE LEARNING ENVIRONMENTTo maintain a secure virtual academic ecosystem, EBS implements:Protected LMS environment with secure loginRestricted exam access and identity verificationAI-based plagiarism and integrity monitoring toolsSecure portals for certificate and degree verificationAuthenticated communication channels using official institutional domainsEBS continuously upgrades its systems to counter emerging cybersecurity risks.STUDENT AND USER RESPONSIBILITIESWhile EBS provides strong protection mechanisms, users share responsibility for maintaining security by:Keeping login credentials confidentialChanging passwords regularlyAvoiding file-sharing or unauthorized accessEnsuring personal devices are protected with antivirus softwareReporting suspicious activity immediatelyUsers must refrain from:Hacking or attempting unauthorized system accessSharing academic or confidential data without permissionUsing VPNs or anonymizers to manipulate exam conditionsEngaging in fraudulent digital activitiesViolations may lead to disciplinary or legal consequences.THIRD-PARTY SERVICES AND DATA PROCESSINGEBS partners with trusted third-party providers for:Payment processing (PayPal, Wise, Stripe, credit card gateways)LMS infrastructureCloud hostingVerification systemsAll partners comply with international data security standards and are contractually obligated to protect EBS data.EBS does not sell, trade, or disclose personal data to unauthorized third parties.DATA RETENTION POLICYData is retained only for as long as necessary to:Fulfill academic and administrative requirementsSatisfy legal obligationsMaintain academic records for verificationCertain records, such as transcript data, may be stored indefinitely to support alumni verification.INCIDENT RESPONSE AND BREACH MANAGEMENTIn the event of a data breach or cybersecurity incident, EBS will:Immediately investigate the breachContain and mitigate the impactNotify affected users promptlyTake corrective action to prevent recurrenceReport serious incidents to regulatory authorities (if applicable)EBS maintains a formal Cybersecurity Response Protocol for rapid resolution.USER RIGHTS REGARDING PERSONAL DATAStudents and users may request:Access to their personal dataCorrection of inaccurate informationDeletion of data (where applicable)Restriction of processingExplanation of how their data is usedRequests can be made through Academic Services or Data Protection Support.INSTITUTIONAL STATEMENTEBS is fully committed to upholding the highest standards of data protection and cybersecurity. As a global online business school, maintaining a secure digital environment is essential to academic integrity, institutional credibility, and student trust.Through proactive governance, continuous technological improvement, and a shared commitment to responsibility, EBS ensures that every member of its global community can learn, work, and grow in a safe and secure digital space.Enigma Business School (EBS)