Privacy Policy
1. Controller and Data Protection Officer
Controller within the meaning of the GDPR:
XR-AGENCY PTE. LTD.
2 Venture Drive, #19-21, Vision Exchange
Singapore 608526
Registration number (UEN): 202425407R
E-mail: office@basix.market
Data Protection Officer: No DPO has been appointed.
2. Overview
This policy explains which personal data we process when you use BASIX Omniversity at basix.market, including the website, the Dev LMS, live cohorts and hackathons ("Service"), why we process it, who receives it, and which rights you have.
3. Purposes and Legal Bases of Processing
We process personal data on the following legal bases (Art. 6 GDPR):
- providing your account, courses, cohorts, hackathons, projects, badges and certificates – performance of contract, Art. 6(1)(b);
- keeping the Service secure, preventing abuse, measuring the reach of the Service (see section 8) and letting mentors support learners (see section 5) – legitimate interests, Art. 6(1)(f);
- where we ask for your consent – Art. 6(1)(a), revocable at any time with effect for the future;
- complying with legal obligations – Art. 6(1)(c).
4. Categories of Data Processed
- account data: e-mail address, password (handled by our authentication provider Clerk; we never see or store it), name, institution or organisation, role on the platform;
- profile data (optional): profile picture, short bio, Telegram handle;
- learning data: course enrolments and cohorts, lesson progress, quiz scores, badges and certificates, an activity log of these steps, and the time you were last active;
- community and project data: cohort chat messages, projects and co-ownership shares, IP assets you list, repository links, hackathon teams, project ideas, submissions, placements and prizes, event sign-ups, hackathon check-in times, and prize-money balances;
- notes: notes that mentors and staff write about your learning progress;
- communication data: e-mails we send to you;
- usage data: page views and clicks recorded by our reach measurement (see section 8);
- terms acceptance: the version of the Terms & Conditions you accepted and when.
We do not ask for your date of birth, gender, phone number or postal address.
Your e-mail address, a password and your institution or organisation are required to create an account; without them we cannot provide one. Taking part in a hackathon requires an organisation on your profile. All other profile details are optional.
5. Who Can See Your Data
Other users of the Service
- Members of your cohort see your name, profile picture, role and the messages you post in the cohort chat.
- Hackathon teammates see each other's names and e-mail addresses. A team lead can add a registered user to their team by e-mail address; that user is then registered for the hackathon and receives a confirmation e-mail.
- Logged-in users can see project pages and marketplace listings, including the names, profile pictures and ownership shares of owners and co-owners. A project lead can add co-owners by e-mail address, and can import a repository's contributors, who are matched to users by name or e-mail.
- The e-mail address, institution, profile picture and bio of mentors and instructors are shown to all logged-in users.
The public (no login required)
- Badge and certificate pages show your full name, the course, the issue date and the credential ID to anyone who has the link. The machine-readable badge (Open Badges v2) contains only a salted hash of your e-mail address, not the address itself.
- Hackathon result pages show the names of participants who submitted an entry, together with the entry's title, link, placement and prize.
- A progress tracker for the MeTTa Challenges course shows participants' names, their progress and links to their repositories.
Mentors, instructors and administrators
- Staff can see hackathon registrations, including names, e-mail addresses, organisation, Telegram handle, team, project idea, notes and check-in time, and can export them as a spreadsheet.
- Staff can see the progress, quiz scores and last activity of the learners they support, can see indicators such as "quiet for 7+ days" or "quiz below 70%", and can write notes about a learner.
- Staff can read the chats of all cohorts. Administrators can export the list of users (name, e-mail, role, institution, sign-up date), send e-mails to users and hackathon participants, and view the reach-measurement dashboard.
Integrations
- Partners we work with, such as partner universities, can be given access to a programming interface protected by an access key. It provides enrolments, grades and badges, including learners' names and e-mail addresses. We only give such access to partners who need it to run a programme with us.
- When a badge is issued, we can notify a credential service that records or issues the credential; it receives your user ID, the course and the badge ID, but not your name or e-mail address.
6. Processors and Other Recipients
To provide the Service we use carefully selected providers who process data on our behalf (Art. 28 GDPR):
- Clerk (Clerk, Inc., USA) – sign-up, login, e-mail verification codes, bot protection and session management; stores your e-mail address, password, institution, your terms acceptance and, where provided, your name;
- Neon (Neon, Inc., USA) – database hosting;
- Vercel (Vercel Inc., USA) – hosting of the Service and storage of profile pictures and hackathon banners; these images are publicly reachable by anyone who has their address;
- Resend (Resend, Inc., USA) – sending e-mails;
- hosting and content-delivery (CDN) providers – operating the servers and networks that deliver the Service.
Other recipients, which process data under their own responsibility:
- GitHub – when a project is linked to a repository, we request the repository's public list of contributors; only the repository name is sent;
- YouTube (Google), Vimeo and other video hosts – see section 9;
- Google Fonts – the MeTTa Challenges progress tracker loads its fonts from Google, which receives your IP address;
- Telegram, WhatsApp, Google Meet and Google Forms – we only link to these services; their own privacy policies apply once you open them.
7. Transfers to Third Countries
The controller is seated in Singapore, and several providers listed in section 6, including Clerk, Neon, Vercel and Resend, process data in the USA. Where required, transfers rely on adequacy decisions (including the EU-U.S. Data Privacy Framework for certified providers) and/or the EU Standard Contractual Clauses (SCCs). You can request a copy of the relevant safeguards from office@basix.market.
8. Cookies, Local Storage and Reach Measurement
We use the following cookies and browser storage:
- Clerk session cookies – keep you logged in (strictly necessary);
- lms_flash and hack_notice – show a one-time confirmation message after an action; deleted after 20 seconds (strictly necessary);
- basix-lms-theme (local storage) – remembers whether you chose the light or dark theme;
- bxa_vid (1 year) and bxa_sid (30 minutes) – reach measurement, as described below.
Reach measurement. We measure the use of the Service with our own analytics, which runs on our servers and is not shared with third parties. For each page view we record the page, the referring website's domain, campaign tags (utm_source, utm_medium, utm_campaign), browser, operating system, device type, screen size, language, and an approximate location (country, region and city) that our hosting provider derives from your IP address. We also record clicks on certain buttons, such as "Partner with us". Your IP address itself is not stored, and this data is not linked to your account. If your browser sends a "Do Not Track" or "Global Privacy Control" signal, no data is recorded and no analytics cookies are set.
We base this reach measurement on our legitimate interest in understanding how the Service is used so that we can improve it (Art. 6(1)(f) GDPR). You can object at any time by turning on "Do Not Track" or "Global Privacy Control" in your browser; from then on, no data is recorded. You can also delete the bxa_vid and bxa_sid cookies in your browser settings at any time.
9. Embedded Videos
Some pages and lessons embed videos from YouTube (in privacy-enhanced mode, youtube-nocookie.com), Vimeo or other video hosts. When such a video loads, your browser connects to that provider, which receives your IP address and may set its own cookies. The provider's privacy policy applies.
10. Payments
We do not process payments on the Service. Licensing IP assets through BASIXMARKET is subject to BASIXMARKET's own terms and privacy policy.
11. E-mail
We send you e-mails via Resend: a welcome e-mail after sign-up, confirmations when you register for a hackathon or a teammate adds you to a team, and announcements from the BASIX Omniversity team, which administrators send to users or to hackathon participants. We keep a record of each e-mail sent, including its recipients. If you no longer want to receive announcements, write to office@basix.market.
12. Hosting and Security
We apply technical and organisational measures, including transport encryption (TLS), leaving password handling to our authentication provider so that we never store passwords, and role-based access controls that separate what learners, mentors and administrators can see.
13. Retention Period
Personal data is stored only as long as necessary for the purposes above or as required by law.
- Account, learning, community and project data are kept until your account is deleted. You can ask us to delete your account at any time (see section 15).
- Badges and certificates remain verifiable until your account is deleted or you ask us to revoke them.
- Reach-measurement data is kept only as long as it is needed to evaluate the use of the Service, and records of sent e-mails only as long as they are needed to document our communication with you. We review these records regularly and delete data that is no longer needed.
- Server logs are kept by our hosting provider for its standard periods.
14. Minors
If you have not yet reached the age of digital consent in your country of residence (between 13 and 16 in the EU), you may only create an account with the consent of a parent or legal guardian (Art. 8 GDPR; see Terms § 3). If we learn that we hold data of a child without such consent, we delete it.
15. Your Rights
Under the GDPR you have the right to:
- access the data stored about you (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure ("right to be forgotten", Art. 17);
- restriction of processing (Art. 18);
- data portability in a structured, commonly used, machine-readable format (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent given, with effect for the future (Art. 7(3));
- not be subject to a solely automated decision, including profiling, with legal effect (Art. 22).
We do not make solely automated decisions with legal or similarly significant effects. Indicators such as "quiet for 7+ days" only help mentors decide whom to support.
You can change your name, institution, bio, picture and Telegram handle yourself on your profile page. For all other requests, an informal message to office@basix.market is sufficient. We may ask you to write from the e-mail address of your account so that we can verify your identity. We respond within the statutory time limits (generally one month).
16. Right to Lodge a Complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state where you live, work or where the alleged infringement took place.
17. Changes to this Privacy Policy
We adjust this policy when the Service or the law changes; the version published in the Service applies.
As of: 28 September 2026
Omniversity