The displayed legal identity is authorized for controlled non-public staging only.

English Privacy Policy

Gradex Privacy Policy

Version: 2026-08-09-v1
Effective date: 9 August 2026

Gradex Courses operates the Gradex educational platform. Its legal registration/license number is STAGING-NOT-REGISTERED, and its registered address is STAGING ONLY — LEGAL ENTITY DETAILS PENDING (“Gradex”, “we”, “us”, or “our”).

This Privacy Policy explains how we collect, use, store, disclose, protect, and otherwise process personal data when you create an account, access courses, use protected learning materials, communicate with us, or otherwise use Gradex.

For privacy enquiries and requests, contact ahmedhazem232425@gmail.com. For general support, contact ahmedhazem232425@gmail.com.

1. Personal data we collect

We may collect account and identity information such as your name, email address, account identifiers, email-verification status, role and authentication information.

We collect learning and service information including courses associated with your account, invitations, approvals, enrollments, access entitlements and expiry dates, lesson activity, video-access events and learning progress.

We collect technical and security information necessary to operate and protect Gradex, such as IP address, browser or device information, request identifiers, authentication events, security events, timestamps and server logs.

If you contact support, we may retain the information contained in your communication and information necessary to investigate and respond to your request.

At the current launch stage, Gradex does not collect or store payment-card numbers through the Gradex platform. Where a course is obtained through a separately approved payment or sales channel, Gradex may receive information necessary to confirm that access should be granted, but payment-card credentials should remain with the applicable payment provider.

2. Passwords and credential security

Gradex does not store your plaintext password. Passwords are processed through the security mechanisms used by the platform and stored only in protected derived form.

When a new password must be checked against known compromised passwords, Gradex may use the Have I Been Pwned Pwned Passwords service. Gradex sends only the first five hexadecimal characters of a SHA-1 digest derived from the password. The plaintext password, complete digest, remaining digest suffix, email address, username and student identity are not sent to that service. Matching is performed by Gradex.

3. Why we process personal data

We process personal data as necessary to create and secure accounts, verify email addresses, authenticate users, provide course access, administer invitations and approvals, maintain enrollments and entitlements, provide protected learning content, save progress, provide support, detect and prevent abuse, maintain service reliability and security, comply with applicable legal obligations and establish or defend legal rights.

Where consent is legally required, we request it before the relevant processing.

4. Course access information

Creating a Gradex account does not by itself grant access to a course.

Where the current course-access model applies, an authorized course invitation must be issued to the intended student, the student must accept it, and an authorized administrator must approve access before the applicable entitlement becomes active.

We maintain relevant access, enrollment, invitation and approval records to operate the service, protect against unauthorized access and maintain an auditable record of course-access decisions.

5. Cookies and local technologies

Gradex may use cookies or equivalent technologies that are necessary for authentication, session security, language preferences, security and operation of the platform.

At launch, we do not use such technologies to sell personal data or permit third parties to build advertising profiles from your Gradex learning activity.

If optional analytics, advertising or similar non-essential technologies are introduced later, this Policy and any required consent mechanism will be updated before their use.

6. Service providers and disclosure

We do not sell personal data.

We may provide limited information to service providers that assist us in operating Gradex, such as hosting and infrastructure providers, object-storage and content-delivery providers, email-delivery providers, security providers and other processors acting on our behalf.

Our planned or current infrastructure providers may include services such as Hostinger for computing infrastructure, Cloudflare for infrastructure, DNS, security or object storage, Resend for transactional email, and Have I Been Pwned for compromised-password screening.

Each provider receives only the information reasonably required for the service it performs.

We may also disclose information where required by applicable law, a lawful governmental request or legal process, or where reasonably necessary to protect users, Gradex or the rights and safety of others.

7. International processing

Gradex infrastructure and service providers may store or process personal data outside the State of Kuwait.

By operating an internet-based service with international infrastructure providers, some information may therefore be transmitted to or processed in other jurisdictions.

We take reasonable technical, organizational and contractual measures appropriate to the nature of the information and applicable requirements when using such providers.

8. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the service, maintaining account and course-access records, security, dispute resolution, audit and compliance with applicable law.

Account, entitlement, enrollment and learning records may be retained while your account or course relationship remains active and for an appropriate period afterward where necessary to establish access history, resolve disputes, satisfy legal requirements or protect Gradex and its users.

Security and audit records may be retained for a limited period appropriate to investigation, security and compliance needs.

Where information is no longer required, we delete, anonymize or otherwise securely dispose of it, subject to information that must legitimately be retained for legal, security, judicial or financial obligations.

9. Your rights

Subject to applicable law and legitimate exceptions, you may request access to personal data we hold about you, correction of inaccurate information, deletion of information, restriction of certain processing, objection to certain processing, withdrawal of consent where processing depends on consent, or a copy/transfer of applicable personal data.

Requests may be submitted to ahmedhazem232425@gmail.com.

We may need to verify your identity before fulfilling a request.

Withdrawal of consent does not invalidate processing lawfully undertaken before withdrawal. Where information is necessary to provide a requested service, deletion or withdrawal may mean that we can no longer provide some or all of that service.

10. Account closure and deletion

You may request account closure through ahmedhazem232425@gmail.com.

Where deletion is required and no lawful reason for retention remains, we will delete or anonymize the applicable personal data.

Certain information may continue to be retained when necessary for security, legal claims, compliance, fraud prevention, audit or other lawful obligations.

11. Security

We use technical and organizational measures intended to protect personal data against unauthorized access, alteration, disclosure, destruction or loss.

These measures include access controls, authentication protections, encryption where appropriate, protected storage, private media access, logging and monitoring, controlled administrative permissions, backups and security testing.

No internet service can guarantee absolute security, but we continually work to maintain safeguards appropriate to the nature of the information we process.

12. Personal-data incidents

If a security incident affects personal data, we will investigate and take appropriate containment and remediation measures.

We will make regulatory and affected-user notifications where required by applicable law and regulation.

13. Users under 18

Gradex's launch service is intended for persons 18 years of age or older.

By creating an account, you confirm that you are at least 18.

We do not knowingly permit a person under 18 to create a Gradex account during this launch phase. If we learn that personal data relating to a person under 18 has been collected contrary to this requirement, we may suspend the account and take appropriate steps regarding deletion or lawful guardian authorization.

14. Marketing

We do not sell personal data or provide it to unrelated third parties for their own direct marketing purposes without the consent required by applicable law.

Transactional messages required for account verification, security, course access, service operation and support are not promotional marketing.

15. Changes to this Policy

We may update this Policy when Gradex, our processing activities or applicable requirements change.

Material changes will receive a new policy version and effective date. Where renewed consent or acceptance is legally or contractually required, we will request it before proceeding.

16. Complaints and contact

Gradex Courses
Registration/license number: STAGING-NOT-REGISTERED
Registered address: STAGING ONLY — LEGAL ENTITY DETAILS PENDING
Privacy: ahmedhazem232425@gmail.com
Support: ahmedhazem232425@gmail.com

You may also have the right to complain to the relevant competent authorities in the State of Kuwait.


Registration/license number
STAGING-NOT-REGISTERED
Registered address
STAGING ONLY — LEGAL ENTITY DETAILS PENDING
Privacy
ahmedhazem232425@gmail.com
Support
ahmedhazem232425@gmail.com
Security
ahmedhazem232425@gmail.com

gradex-legal-2026-08-09-v1 · 2026-08-09-v1 · 2026-08-09

Gradex Privacy Policy · Gradex