Legal

Privacy Policy

Last updated: 9 July 2026  ·  Effective immediately

This policy explains what personal data VAPTIC collects, why we collect it, how we protect it, and the rights you have over it.

1. Who We Are

VAPTIC ("we", "us", "our") is a cybersecurity training academy based in India. We operate the learning management system at vaptic.com, where students attend live instructor-led classes, access recorded sessions, and practice on cloud-based hacking labs.

For the purposes of applicable data protection law, VAPTIC is the Data Controller — we determine why and how your personal data is processed.

Data Controller Contact
VAPTIC  ·  info@vaptic.com

2. Data We Collect

We collect only what is necessary to deliver our training services.

2.1 Account & Enrolment Data

  • Full name, email address, phone number
  • Course interest and enrolment records
  • Account status and approval history
  • Password (stored as a cryptographic hash by Firebase Authentication — we never see your plain-text password)

2.2 Learning & Progress Data

  • Modules completed, quiz results, time spent per module
  • Module notes you write inside the platform
  • Resources opened and live-class attendance records
  • Certificates of completion

2.3 Payment Data

  • Transaction IDs, order amounts, payment timestamps
  • Card or bank details are processed directly by Razorpay — VAPTIC never receives or stores raw payment instrument data

2.4 Technical & Usage Data

  • IP address and browser user-agent (logged by Firebase Authentication for abuse prevention)
  • Pages visited and time on site (Google Analytics, if enabled — see §8)

2.5 Workshop Booking Data (Colleges)

  • College name, department, city, preferred date
  • Contact person's name, email and phone number
  • Student headcount and payment details

3. How We Use Your Data

PurposeLegal Basis
Create and manage your student accountContract performance
Deliver courses, unlock modules, track progressContract performance
Process and verify paymentsContract performance
Send transactional emails (enrolment confirmation, password reset, approval notice)Contract performance
Prevent fraud, abuse and unauthorised accessLegitimate interest
Maintain immutable audit logs for admin actionsLegitimate interest / legal obligation
Issue completion certificatesContract performance
Respond to your support queriesLegitimate interest
Comply with tax and legal record-keeping obligationsLegal obligation

We do not sell your personal data. We do not use your data to train AI models. We do not send marketing emails without your explicit consent.

4. Third-Party Processors

We share your data with the following sub-processors, solely to deliver our services:

Google Firebase & Google Cloud
Authentication, database (Firestore), file storage, cloud hosting, and serverless functions. All data is encrypted at rest and in transit. Google acts as our Data Processor under a formal Data Processing Agreement.
SOC 2 · ISO 27001 · GDPR DPA
Resend
Sends transactional emails on our behalf (password resets, enrolment confirmations, approval notices). Receives your email address and display name only.
GDPR DPA
Razorpay
Processes online course and workshop payments. Razorpay handles all payment instrument data. VAPTIC receives only transaction IDs and status codes.
PCI-DSS Level 1 · RBI compliant
YouTube (Google)
Course videos are hosted as unlisted YouTube embeds. YouTube may set its own cookies when you watch a video. We use youtube-nocookie.com embeds where possible.
Google Privacy Policy applies

5. Data Retention

  • Account & learning data — Retained for the duration of your active account. If you request deletion, your account data is removed within 30 days, except where retention is required by law.
  • Payment records — Retained for 7 years to comply with Indian income tax and GST record-keeping obligations.
  • Audit logs — Retained for 2 years for security and compliance purposes. Immutable — cannot be deleted by students or admins.
  • Certificates — Retained indefinitely so you can verify your credentials at any time.
  • Workshop booking records — Retained for 7 years for tax compliance.

6. Security Measures

We implement security in layers:

  • Encryption in transit — All traffic is served over HTTPS with HSTS enforced.
  • Encryption at rest — All Firestore and Storage data is encrypted at rest by Google Cloud.
  • Authentication — Passwords are cryptographically hashed by Firebase Auth. We check new passwords against HaveIBeenPwned to block known-compromised credentials.
  • Access control — Firestore and Storage have server-side security rules. Sensitive operations (enrolment, payments) are handled exclusively by Cloud Functions with server-side validation.
  • App Check — Firebase App Check (reCAPTCHA v3) is enforced on Firestore and Storage, blocking automated API abuse.
  • Rate limiting — Email operations and data writes are rate-limited at the server level.
  • HTTP headers — Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are set on all responses.

Despite these measures, no system is 100% secure. If you discover a vulnerability, please report it responsibly to info@vaptic.com.

7. Your Rights

You have the following rights over your personal data:

Access Request a copy of the personal data we hold about you.
Correction Update your name or phone number directly in the platform. For other corrections, contact us.
Deletion Request deletion of your account and associated data (subject to legal retention requirements).
Portability Request your learning data (progress, notes, certificates) in a machine-readable format.
Object Object to processing based on legitimate interest. We will stop unless we have compelling grounds.
Withdraw Consent Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email info@vaptic.com with the subject line "Data Rights Request". We will respond within 30 days.

8. Cookies & Tracking

We use the following cookies and client-side storage:

Name / ProviderPurposeType
Firebase Auth sessionKeeps you logged in between browser sessionsStrictly necessary
sessionStorage (vaptic:loader-played)Prevents the page loader from replaying on every tabStrictly necessary
YouTube embed cookiesRemembers playback preferences; may track viewing across sitesFunctional / third-party
reCAPTCHA v3 (Google)Firebase App Check — detects bot traffic to protect our databaseSecurity / strictly necessary

We do not currently use advertising or analytics cookies beyond what Firebase Authentication requires for security. If we add analytics in the future, we will update this policy and obtain consent where required.

9. EU Residents & GDPR

If you are located in the European Economic Area (EEA), the UK, or Switzerland, the General Data Protection Regulation (GDPR) gives you additional rights and imposes specific obligations on us:

  • Legal basis — Every processing activity described in §3 has a lawful basis (contract, legitimate interest, or legal obligation).
  • International transfers — Your data is processed on Google Cloud infrastructure, which may involve transfers outside the EEA. Google's Data Processing Terms include Standard Contractual Clauses (SCCs) to ensure adequate protection.
  • Supervisory authority — You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data lawfully.
  • Data Protection Officer — VAPTIC does not currently meet the threshold requiring a mandatory DPO (we do not conduct large-scale systematic monitoring of EU residents). If our EU user base grows significantly, we will appoint one.

To exercise your GDPR rights, contact us at info@vaptic.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify enrolled students by email. Continued use of the platform after a change constitutes acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, data rights requests, or to report a security vulnerability:

Governing law: This policy is governed by the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDPA).