1. Who We Are
VAPTIC ("we", "us", "our") is a cybersecurity training academy based in India. We operate the learning management system at vaptic.com, where students attend live instructor-led classes, access recorded sessions, and practice on cloud-based hacking labs.
For the purposes of applicable data protection law, VAPTIC is the Data Controller — we determine why and how your personal data is processed.
VAPTIC · info@vaptic.com
2. Data We Collect
We collect only what is necessary to deliver our training services.
2.1 Account & Enrolment Data
- Full name, email address, phone number
- Course interest and enrolment records
- Account status and approval history
- Password (stored as a cryptographic hash by Firebase Authentication — we never see your plain-text password)
2.2 Learning & Progress Data
- Modules completed, quiz results, time spent per module
- Module notes you write inside the platform
- Resources opened and live-class attendance records
- Certificates of completion
2.3 Payment Data
- Transaction IDs, order amounts, payment timestamps
- Card or bank details are processed directly by Razorpay — VAPTIC never receives or stores raw payment instrument data
2.4 Technical & Usage Data
- IP address and browser user-agent (logged by Firebase Authentication for abuse prevention)
- Pages visited and time on site (Google Analytics, if enabled — see §8)
2.5 Workshop Booking Data (Colleges)
- College name, department, city, preferred date
- Contact person's name, email and phone number
- Student headcount and payment details
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Create and manage your student account | Contract performance |
| Deliver courses, unlock modules, track progress | Contract performance |
| Process and verify payments | Contract performance |
| Send transactional emails (enrolment confirmation, password reset, approval notice) | Contract performance |
| Prevent fraud, abuse and unauthorised access | Legitimate interest |
| Maintain immutable audit logs for admin actions | Legitimate interest / legal obligation |
| Issue completion certificates | Contract performance |
| Respond to your support queries | Legitimate interest |
| Comply with tax and legal record-keeping obligations | Legal obligation |
We do not sell your personal data. We do not use your data to train AI models. We do not send marketing emails without your explicit consent.
4. Third-Party Processors
We share your data with the following sub-processors, solely to deliver our services:
5. Data Retention
- Account & learning data — Retained for the duration of your active account. If you request deletion, your account data is removed within 30 days, except where retention is required by law.
- Payment records — Retained for 7 years to comply with Indian income tax and GST record-keeping obligations.
- Audit logs — Retained for 2 years for security and compliance purposes. Immutable — cannot be deleted by students or admins.
- Certificates — Retained indefinitely so you can verify your credentials at any time.
- Workshop booking records — Retained for 7 years for tax compliance.
6. Security Measures
We implement security in layers:
- Encryption in transit — All traffic is served over HTTPS with HSTS enforced.
- Encryption at rest — All Firestore and Storage data is encrypted at rest by Google Cloud.
- Authentication — Passwords are cryptographically hashed by Firebase Auth. We check new passwords against HaveIBeenPwned to block known-compromised credentials.
- Access control — Firestore and Storage have server-side security rules. Sensitive operations (enrolment, payments) are handled exclusively by Cloud Functions with server-side validation.
- App Check — Firebase App Check (reCAPTCHA v3) is enforced on Firestore and Storage, blocking automated API abuse.
- Rate limiting — Email operations and data writes are rate-limited at the server level.
- HTTP headers — Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are set on all responses.
Despite these measures, no system is 100% secure. If you discover a vulnerability, please report it responsibly to info@vaptic.com.
7. Your Rights
You have the following rights over your personal data:
To exercise any of these rights, email info@vaptic.com with the subject line "Data Rights Request". We will respond within 30 days.
9. EU Residents & GDPR
If you are located in the European Economic Area (EEA), the UK, or Switzerland, the General Data Protection Regulation (GDPR) gives you additional rights and imposes specific obligations on us:
- Legal basis — Every processing activity described in §3 has a lawful basis (contract, legitimate interest, or legal obligation).
- International transfers — Your data is processed on Google Cloud infrastructure, which may involve transfers outside the EEA. Google's Data Processing Terms include Standard Contractual Clauses (SCCs) to ensure adequate protection.
- Supervisory authority — You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data lawfully.
- Data Protection Officer — VAPTIC does not currently meet the threshold requiring a mandatory DPO (we do not conduct large-scale systematic monitoring of EU residents). If our EU user base grows significantly, we will appoint one.
To exercise your GDPR rights, contact us at info@vaptic.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify enrolled students by email. Continued use of the platform after a change constitutes acceptance of the updated policy.
11. Contact Us
For any privacy-related questions, data rights requests, or to report a security vulnerability:
Governing law: This policy is governed by the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDPA).