Skip to content

Legal

Privacy policy

How Ubinex Technologies Private Limited collects, uses, shares and protects personal data in connection with UbiLearn. Written to be read, not to be survived.

Last updated 14 August 2026

1. Who this policy covers

UbiLearn is a multi-tenant, white-label learning management platform operated by Ubinex Technologies Private Limited (“UbiLearn”, “we”, “us”). This policy applies to this website, to the UbiLearn web application, to the UbiLearn Android application, and to the emails we send in connection with them.

Three kinds of people are covered by it:

  • Visitors — anyone browsing this website or contacting us through it.
  • Customers — the individual or organization that subscribes to a plan and runs a workspace, and the owners, admins and instructors within it.
  • Learners — people invited into a customer’s workspace to take courses.

We process personal data in accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made under it.

2. Our role: customer data vs learner data

The distinction below decides who you should ask about your data, so it is worth thirty seconds.

  • For customer and account data — the person who signs up, workspace settings, billing details, support conversations — we decide why and how the data is processed. We are the data fiduciary, and you deal with us directly.
  • For learner data inside a workspace — enrolments, lesson progress, quiz attempts, assignment submissions, certificates — the workspace that invited the learner decides why and how it is processed. We process it on that workspace’s instructions, as its processor.

If you are a learner

Your progress, results and certificates belong to the workspace that enrolled you. Ask that organization first to access, correct or delete them — they control those records and can act immediately. If you cannot reach them, write to us at privacy@ubilearn.com and we will help, within what our agreement with that customer permits.

3. What we collect

Categories of personal data UbiLearn collects
CategoryExamplesWhere it comes from
Account dataName, email address, hashed password, email-verification and login OTP records, Google account identifier if you use Google Sign-In, roles and workspace memberships.You, at signup and in settings
Workspace dataWorkspace name, subdomain, logo and favicon, brand colours, email sender name, timezone and language.The workspace owner or admin
Learning dataEnrolments, lesson completion and playback position, quiz attempts and scores, assignment submissions and grades, certificates issued.Learner activity, on behalf of the workspace
Content you uploadCourse videos, articles, PDFs and attachments, and any personal data you choose to include in them.Instructors and admins
Billing dataBilling name, billing address, GSTIN, plan, subscription and invoice history, payment status and the last four digits and method reported back by the payment gateway.You and Razorpay
Technical dataIP address, browser and device information, timestamps, request identifiers, error reports, and audit records of sensitive actions such as logins and role changes.Automatically, when you use the service
CommunicationsMessages you send through the contact form or by email, and our replies.You

We never see your card number. Card, UPI and net-banking details are collected and stored by Razorpay on their own systems; we receive only a payment reference, the amount, the status and the method.

4. Why we use it

  • To create and operate your account and workspace, and to authenticate you — including sending one-time codes and enforcing multi-factor authentication.
  • To deliver the service: hosting your courses, streaming lessons, grading quizzes, recording progress and issuing certificates.
  • To take payment, calculate GST, issue invoices, manage renewals and handle refunds under our refund policy.
  • To send transactional email you need — verification codes, invitations, enrolment and completion notices, billing notices and service announcements.
  • To provide support, and to investigate and fix faults you or our monitoring report.
  • To keep the platform secure: rate limiting, abuse and fraud prevention, audit logging, and backups.
  • To understand aggregate product usage so we can improve it. This is done on aggregated and de-identified data wherever it can be.
  • To comply with law, including tax and accounting obligations, and to establish or defend legal claims.

We process this data because it is necessary to provide a service you asked for, because you consented (for example, to optional communications), or because we have a legal obligation. We do not sell personal data, we do not share it with advertising networks, and we do not use your content or your learners’ data to train machine-learning models.

5. Cookies and similar technologies

We use a small number of cookies, almost all of them strictly necessary — the session cookie that keeps you signed in, and a security cookie used for cross-subdomain authentication. We do not run advertising or cross-site tracking cookies.

The categories, names and how to control them are set out in the cookie policy.

6. Who else processes it

We use a short list of sub-processors, each for a specific job. Every one of them is bound by contract to process data only on our instructions and to protect it.

Sub-processors used by UbiLearn
ProcessorWhat it doesWhere
Amazon Web ServicesHosting, database, object storage for media, content delivery and transactional email (SES).Mumbai, India (ap-south-1)
RazorpayPayment processing, subscriptions, invoices and refunds. Razorpay is the recipient of your payment credentials, not us.India
Google (Sign-In)Optional Google Sign-In. Used only if you choose to sign in with Google; we receive your email address, name and Google account identifier.Global
SentryApplication error reporting so we can find and fix crashes. Reports may contain your user identifier, workspace identifier and request details.Global

If we add or replace a sub-processor we update this list and, for material changes, tell workspace owners by email before the change takes effect.

7. When we disclose data

We disclose personal data only in these situations:

  • To the sub-processors listed above, for the purposes listed above.
  • Within a workspace, to the owners, admins and instructors of that workspace — this is how the product works, and it is why learner records are visible to the organization that enrolled the learner.
  • To our professional advisers (auditors, lawyers) under a duty of confidentiality.
  • Where we are required to by law, by a court, or by a lawful request from a government authority. Where we are permitted to tell you about such a request, we will.
  • To a successor entity in the event of a merger, acquisition or sale of assets — with notice to you, and with this policy continuing to apply until it is replaced by one no less protective.

We never disclose one workspace’s data to another. Isolation between workspaces is enforced in the database layer and tested automatically on every change we ship.

8. How we protect it

  • Passwords are hashed with Argon2id. One-time codes are stored hashed, expire in ten minutes and are rate-limited by attempts.
  • Sessions use short-lived access tokens with rotating refresh tokens; a reused refresh token revokes the whole family. Owners and admins have multi-factor authentication always on.
  • All traffic is encrypted with TLS. Data is encrypted at rest in the database and in object storage.
  • Media is served only through short-lived signed URLs, so a link copied out of a browser stops working quickly.
  • Every request is scoped to a single workspace at the database layer; automated cross-workspace access tests run in our build pipeline and block a release if they fail.
  • Sensitive actions — logins, role changes, member removal, course publishing and billing changes — are written to an append-only audit log.
  • Databases are backed up nightly, and restores are tested.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required by law, without undue delay.

9. How long we keep it

  • While your subscription is active — for as long as your workspace exists.
  • After cancellation — your workspace data is retained for 90 days so you can reactivate or export it, and is then permanently deleted from our production systems. Encrypted backups containing it age out on their own retention cycle shortly afterwards.
  • If you ask sooner — write to privacy@ubilearn.com during those 90 days and we will delete it earlier.
  • Billing records — invoices, payments and tax records are retained for as long as Indian tax and companies law requires, currently eight years, regardless of account deletion.
  • Audit and security logs — retained for up to 12 months for security investigation.
  • Support emails — retained for up to 24 months so we have the history of an issue.

10. Your rights

Subject to the Digital Personal Data Protection Act, 2023, you have the right to:

  • Obtain confirmation of whether we process your personal data, and a summary of that data and the processing.
  • Have inaccurate or incomplete data corrected or completed, and have data updated.
  • Have your personal data erased, where it is no longer needed for the purpose it was collected for and we are not required by law to keep it.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Withdraw consent, where our processing rests on consent. Withdrawing consent does not affect processing that already happened.
  • Have a grievance heard and answered by our grievance officer, and to escalate to the Data Protection Board of India if you are not satisfied.

To exercise any of these, email privacy@ubilearn.com from the address on your account. We respond within 30 days, and usually much sooner. We may need to verify your identity before we act, and if you are a learner in someone else’s workspace we will normally direct the request to that workspace, which controls those records.

You also have obligations under the Act — chiefly, not to impersonate someone else and not to file frivolous or false complaints.

11. Children

UbiLearn is sold to businesses and to adults. You must be 18 or older to create an account or subscribe to a plan.

A workspace may enrol learners under 18 — a school or a coaching institute, for example. Where it does, that workspace is responsible for obtaining verifiable consent from a parent or guardian as required by law, and for ensuring its own use of the platform is lawful. We do not knowingly collect personal data from a child directly, and we do not do behavioural tracking or targeted advertising to any user of any age.

12. Changes to this policy

We update this policy when the product or the law changes. The date at the top of this page always reflects the current version. For changes that materially affect how we handle your personal data, we email workspace owners at least 14 days before the change takes effect.

13. Contact and grievance officer

For any privacy question or request: privacy@ubilearn.com.

Grievances under the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules:

Grievance Officer (name to be published on appointment)

Ubinex Technologies Private Limited

grievance@ubilearn.com

We acknowledge grievances within 24 hours and resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.