Security Policy

Last Updated: August 28, 2026

Kykadai is committed to maintaining the security, integrity, and confidentiality of all information processed through our platform at kykadai.com. This Security Policy describes the technical and organisational measures we implement to protect our systems and the data entrusted to us by our users.

By using our services, you acknowledge that you have read and understood this policy. If you have questions or concerns, please contact us at info@kykadai.com.


1. Scope

This policy applies to all systems, networks, applications, and data assets operated or managed by Kykadai, including our website, online learning platform, administrative infrastructure, and any third-party services integrated into our operations. It applies to all staff, contractors, and service providers who access our systems.


2. Information We Protect

We apply security controls to all categories of information we collect and process, including but not limited to:

Category Examples
Account credentials Usernames, hashed passwords, authentication tokens
Personal information Names, email addresses, contact details
Payment data Transaction references handled by certified payment processors
Usage data Session logs, learning progress, interaction records
Communications Support messages, feedback submissions

3. Technical Security Measures

3.1 Encryption

All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS 1.2 or higher). Sensitive data stored in our systems is encrypted at rest using industry-standard encryption algorithms. We do not store payment card details directly; all payment processing is delegated to certified third-party processors that maintain their own security standards.

3.2 Access Controls

Access to production systems and sensitive data is restricted on a least-privilege basis. Only authorised personnel with a documented operational need are granted access. All administrative access requires multi-factor authentication. Access rights are reviewed periodically and revoked promptly upon role change or termination.

3.3 Authentication

User accounts are protected by password hashing using modern, computationally expensive algorithms. We enforce minimum password complexity requirements and provide mechanisms for users to reset credentials securely. Session tokens are generated with sufficient entropy and expire after defined periods of inactivity.

3.4 Network Security

Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation. Public-facing services are isolated from internal administrative networks. Unnecessary ports and services are disabled. We apply rate limiting and abuse detection mechanisms to reduce the risk of automated attacks.

3.5 Vulnerability Management

We conduct regular vulnerability assessments of our systems and applications. Software dependencies are monitored for known vulnerabilities and updated promptly when patches are available. Critical patches are applied on an expedited basis. We maintain a process for tracking and remediating identified weaknesses.

3.6 Logging and Monitoring

System events, authentication attempts, and administrative actions are logged and retained for a defined period. Logs are reviewed for anomalous activity. Alerts are configured for events that may indicate a security incident. Log data is protected from unauthorised modification or deletion.


4. Organisational Security Measures

4.1 Personnel Security

All staff and contractors with access to sensitive systems or data receive security awareness training relevant to their role. Personnel are required to adhere to internal security guidelines and acceptable use policies. Confidentiality obligations are established through employment and contractor agreements.

4.2 Third-Party Service Providers

We evaluate the security practices of third-party service providers before engagement. Providers who process personal data or access our systems are required to maintain appropriate security standards. We enter into data processing agreements where applicable and review third-party security posture periodically.

4.3 Physical Security

Our services are hosted in data centre facilities that maintain physical access controls, environmental protections, and redundant power and connectivity. Physical access to server infrastructure is restricted to authorised data centre personnel.

4.4 Change Management

Changes to production systems and applications follow a controlled process that includes review, testing, and approval before deployment. Emergency changes are documented and reviewed retrospectively. Version control is used for all application code.


5. Data Integrity and Availability

We implement measures to protect the accuracy and completeness of data we hold. Regular backups are performed and stored securely. Backup restoration is tested periodically to verify recoverability. We maintain redundancy in critical system components to support continuity of service.


6. Incident Response

6.1 Detection and Response

We maintain an incident response process for identifying, containing, and resolving security incidents. Incidents are classified by severity and escalated accordingly. Response actions are documented and reviewed after resolution to improve future preparedness.

6.2 Notification

In the event of a security incident that affects user data, we will notify affected users and relevant authorities as required by applicable law and within the timeframes mandated. Notifications will describe the nature of the incident, the data involved, and the steps we are taking in response.

6.3 Post-Incident Review

Following any significant security incident, we conduct a post-incident review to identify root causes and implement corrective measures to reduce the likelihood of recurrence.


7. Responsible Disclosure

We welcome responsible reporting of potential security vulnerabilities in our systems. If you believe you have identified a security issue, please contact us promptly at info@kykadai.com with a description of the issue and steps to reproduce it. We ask that you:

Do provide sufficient detail for us to understand and reproduce the issue.

Do not access, modify, or delete data belonging to other users.

Do not disclose the vulnerability publicly before we have had a reasonable opportunity to address it.

We will acknowledge receipt of your report, investigate the matter, and keep you informed of our progress. We do not currently operate a formal bug bounty programme, but we appreciate and recognise good-faith security research.


8. User Responsibilities

Security is a shared responsibility. Users of our platform are expected to:

Protect account credentials: Use a strong, unique password for your Kykadai account and do not share it with others.

Report suspicious activity: Notify us immediately if you suspect unauthorised access to your account or observe unusual behaviour on the platform.

Keep contact information current: Maintain an accurate email address on your account to ensure you can receive security notifications.

Use secure connections: Access our platform from trusted networks and devices. Avoid using public or shared computers for accessing your account where possible.


9. Cookies and Tracking Technologies

We use cookies and similar technologies to support platform functionality, maintain sessions, and analyse usage patterns. Security-related cookies are marked as Secure and HttpOnly where applicable to reduce the risk of interception or client-side access. For full details on our use of cookies, please refer to our Cookie Policy.


10. Data Retention and Deletion

We retain data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal obligations. When data is no longer required, it is securely deleted or anonymised. Users may request deletion of their personal data in accordance with our Privacy Policy.


11. Security of Communications

Official communications from Kykadai will be sent from our verified domain kykadai.com. We will never ask you to provide your password via email, telephone, or any other channel. If you receive a communication purporting to be from us that requests sensitive information or appears suspicious, do not respond and contact us directly at info@kykadai.com or by telephone at +353 94 936 5504.


12. Compliance and Auditing

We periodically review our security controls and practices to assess their effectiveness and alignment with recognised security frameworks. Internal and external assessments are conducted to identify areas for improvement. We maintain documentation of our security programme to support accountability and continuous improvement.


13. Updates to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date shown at the top of this page and, where appropriate, notify users through the platform or by email. We encourage you to review this policy periodically.


14. Contact Us

If you have any questions, concerns, or requests relating to this Security Policy or our security practices, please contact us using the details below:

Kykadai
Cuan Mhuire, Rathmore, Four Mile House
Co. Roscommon, F42 W326, Ireland

Email: info@kykadai.com
Phone: +353 94 936 5504
Website: www.kykadai.com