K
learn.kamaljits

Legal

Privacy Policy

Version 2026-04-26. We'll notify you by email of any material change.

Who we are

learn.kamaljits.com is operated by Kamaljit Singh ("we", "us"). For privacy questions, our grievance officer is reachable at [email protected].

What data we collect

  • Account: name, email, hashed password (or Google profile info if you sign up via Google), role.
  • Enrollments & payments: course/batch you enrolled in, amount paid, currency, payment provider order ID, coupon used.
  • Marketing consent: a record of whether you opted in to non-essential emails.
  • Technical: IP address (for security + rate limiting), user agent, currency cookie derived from your browser locale.
  • Communication: if you reply to an email or contact support, we keep that thread.

We do not collect: government IDs, payment card numbers (those go directly to Dodo Payments), location beyond country, sensitive personal data.

Why we collect it (lawful basis)

  • Contract performance: running your account, delivering courses you paid for, issuing certificates.
  • Legal obligation: retaining payment records for tax compliance.
  • Legitimate interest: rate-limiting auth endpoints to prevent abuse.
  • Consent: sending marketing emails. You can withdraw at any time.

Under India's DPDPA, we rely on consent for personal data and the "legitimate use" of contract performance for paid services.

Who we share it with

  • Dodo Payments — to process payments. They receive your name, email, and billing country.
  • Amazon Web Services (SES) — to deliver email. They process the recipient address and message body.
  • Cloudflare — for DDoS protection and CDN. They process your IP and request metadata.
  • Google — only if you sign in with Google. They share your email + name with us.

We do not sell your personal data. Ever.

Where it's stored

Our database runs on infrastructure hosted in the United States. Email is sent via AWS SES in us-east-1. EU and Indian users' data may therefore cross borders.

For EU residents: we rely on Standard Contractual Clauses with our sub-processors. For Indian residents: we comply with the cross-border restrictions notified under the DPDPA from time to time.

How long we keep it

  • Active accounts: as long as you have an account.
  • Deleted accounts: 30 days in a soft-deleted state, then permanently erased — except payment records, which we keep for 7 years for tax compliance, with PII removed.
  • Server logs: 30 days, then deleted.
  • Consent log: retained as long as the account exists, plus 3 years.

Your rights

You can ask us at any time to:

  • Access a copy of your data (right to access / data portability).
  • Correct anything wrong (right to rectification).
  • Delete your account and data (right to erasure / right to be forgotten).
  • Stop processing your data for marketing.
  • Withdraw consent for anything you previously agreed to.

Most of these are self-serve from your profile page. For anything else, email us at [email protected]and we'll respond within 30 days (or sooner — we usually reply within a few days).

EU residents have the right to lodge a complaint with their local supervisory authority.Indian residentscan escalate to India's Data Protection Board if we don't respond satisfactorily within 90 days.

Children

We do notknowingly collect personal data from anyone under 18. Account creation requires confirming you are 18 or older. If you believe a child has signed up, email us and we'll delete the account.

Cookies

We use a minimal number of cookies:

  • learn_session — strictly necessary for authentication.
  • user_currency — strictly necessary for showing prices in your local currency.
  • consent_choices — records your cookie banner preferences.

We don't currently use analytics or advertising cookies. If we ever do, they will be off by default and require your explicit opt-in via the cookie banner.

Security

Passwords are hashed with bcrypt. All traffic is HTTPS. Webhook payloads are signed and verified. We rate-limit auth endpoints to deter brute force.

If you discover a vulnerability, please tell us at [email protected]. See our security page for details.

In the unlikely event of a personal data breach, we'll notify the EU supervisory authority within 72 hours, India's Data Protection Board without delay, and any affected user as soon as we've assessed the impact.

Grievance officer (DPDPA requirement)

Kamaljit Singh
Email: [email protected]
We acknowledge grievances within 7 days and resolve them within 90 days.

Changes to this policy

When we make material changes, we bump the version at the top of this page and email all active users at least 14 days before the change takes effect.

Terms of Service · Security · Home