Legal
Privacy policy
How Ubinex Technologies Private Limited collects, uses, shares and protects personal data in connection with UbiLearn. Written to be read, not to be survived.
Last updated 14 August 2026
1. Who this policy covers
UbiLearn is a multi-tenant, white-label learning management platform operated by Ubinex Technologies Private Limited (“UbiLearn”, “we”, “us”). This policy applies to this website, to the UbiLearn web application, to the UbiLearn Android application, and to the emails we send in connection with them.
Three kinds of people are covered by it:
- Visitors — anyone browsing this website or contacting us through it.
- Customers — the individual or organization that subscribes to a plan and runs a workspace, and the owners, admins and instructors within it.
- Learners — people invited into a customer’s workspace to take courses.
We process personal data in accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made under it.
2. Our role: customer data vs learner data
The distinction below decides who you should ask about your data, so it is worth thirty seconds.
- For customer and account data — the person who signs up, workspace settings, billing details, support conversations — we decide why and how the data is processed. We are the data fiduciary, and you deal with us directly.
- For learner data inside a workspace — enrolments, lesson progress, quiz attempts, assignment submissions, certificates — the workspace that invited the learner decides why and how it is processed. We process it on that workspace’s instructions, as its processor.
If you are a learner
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, email address, hashed password, email-verification and login OTP records, Google account identifier if you use Google Sign-In, roles and workspace memberships. | You, at signup and in settings |
| Workspace data | Workspace name, subdomain, logo and favicon, brand colours, email sender name, timezone and language. | The workspace owner or admin |
| Learning data | Enrolments, lesson completion and playback position, quiz attempts and scores, assignment submissions and grades, certificates issued. | Learner activity, on behalf of the workspace |
| Content you upload | Course videos, articles, PDFs and attachments, and any personal data you choose to include in them. | Instructors and admins |
| Billing data | Billing name, billing address, GSTIN, plan, subscription and invoice history, payment status and the last four digits and method reported back by the payment gateway. | You and Razorpay |
| Technical data | IP address, browser and device information, timestamps, request identifiers, error reports, and audit records of sensitive actions such as logins and role changes. | Automatically, when you use the service |
| Communications | Messages you send through the contact form or by email, and our replies. | You |
We never see your card number. Card, UPI and net-banking details are collected and stored by Razorpay on their own systems; we receive only a payment reference, the amount, the status and the method.
4. Why we use it
- To create and operate your account and workspace, and to authenticate you — including sending one-time codes and enforcing multi-factor authentication.
- To deliver the service: hosting your courses, streaming lessons, grading quizzes, recording progress and issuing certificates.
- To take payment, calculate GST, issue invoices, manage renewals and handle refunds under our refund policy.
- To send transactional email you need — verification codes, invitations, enrolment and completion notices, billing notices and service announcements.
- To provide support, and to investigate and fix faults you or our monitoring report.
- To keep the platform secure: rate limiting, abuse and fraud prevention, audit logging, and backups.
- To understand aggregate product usage so we can improve it. This is done on aggregated and de-identified data wherever it can be.
- To comply with law, including tax and accounting obligations, and to establish or defend legal claims.
We process this data because it is necessary to provide a service you asked for, because you consented (for example, to optional communications), or because we have a legal obligation. We do not sell personal data, we do not share it with advertising networks, and we do not use your content or your learners’ data to train machine-learning models.
6. Who else processes it
We use a short list of sub-processors, each for a specific job. Every one of them is bound by contract to process data only on our instructions and to protect it.
| Processor | What it does | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, object storage for media, content delivery and transactional email (SES). | Mumbai, India (ap-south-1) |
| Razorpay | Payment processing, subscriptions, invoices and refunds. Razorpay is the recipient of your payment credentials, not us. | India |
| Google (Sign-In) | Optional Google Sign-In. Used only if you choose to sign in with Google; we receive your email address, name and Google account identifier. | Global |
| Sentry | Application error reporting so we can find and fix crashes. Reports may contain your user identifier, workspace identifier and request details. | Global |
If we add or replace a sub-processor we update this list and, for material changes, tell workspace owners by email before the change takes effect.
8. How we protect it
- Passwords are hashed with Argon2id. One-time codes are stored hashed, expire in ten minutes and are rate-limited by attempts.
- Sessions use short-lived access tokens with rotating refresh tokens; a reused refresh token revokes the whole family. Owners and admins have multi-factor authentication always on.
- All traffic is encrypted with TLS. Data is encrypted at rest in the database and in object storage.
- Media is served only through short-lived signed URLs, so a link copied out of a browser stops working quickly.
- Every request is scoped to a single workspace at the database layer; automated cross-workspace access tests run in our build pipeline and block a release if they fail.
- Sensitive actions — logins, role changes, member removal, course publishing and billing changes — are written to an append-only audit log.
- Databases are backed up nightly, and restores are tested.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required by law, without undue delay.
9. How long we keep it
- While your subscription is active — for as long as your workspace exists.
- After cancellation — your workspace data is retained for 90 days so you can reactivate or export it, and is then permanently deleted from our production systems. Encrypted backups containing it age out on their own retention cycle shortly afterwards.
- If you ask sooner — write to privacy@ubilearn.com during those 90 days and we will delete it earlier.
- Billing records — invoices, payments and tax records are retained for as long as Indian tax and companies law requires, currently eight years, regardless of account deletion.
- Audit and security logs — retained for up to 12 months for security investigation.
- Support emails — retained for up to 24 months so we have the history of an issue.
10. Your rights
Subject to the Digital Personal Data Protection Act, 2023, you have the right to:
- Obtain confirmation of whether we process your personal data, and a summary of that data and the processing.
- Have inaccurate or incomplete data corrected or completed, and have data updated.
- Have your personal data erased, where it is no longer needed for the purpose it was collected for and we are not required by law to keep it.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Withdraw consent, where our processing rests on consent. Withdrawing consent does not affect processing that already happened.
- Have a grievance heard and answered by our grievance officer, and to escalate to the Data Protection Board of India if you are not satisfied.
To exercise any of these, email privacy@ubilearn.com from the address on your account. We respond within 30 days, and usually much sooner. We may need to verify your identity before we act, and if you are a learner in someone else’s workspace we will normally direct the request to that workspace, which controls those records.
You also have obligations under the Act — chiefly, not to impersonate someone else and not to file frivolous or false complaints.
11. Children
UbiLearn is sold to businesses and to adults. You must be 18 or older to create an account or subscribe to a plan.
A workspace may enrol learners under 18 — a school or a coaching institute, for example. Where it does, that workspace is responsible for obtaining verifiable consent from a parent or guardian as required by law, and for ensuring its own use of the platform is lawful. We do not knowingly collect personal data from a child directly, and we do not do behavioural tracking or targeted advertising to any user of any age.
12. Changes to this policy
We update this policy when the product or the law changes. The date at the top of this page always reflects the current version. For changes that materially affect how we handle your personal data, we email workspace owners at least 14 days before the change takes effect.
13. Contact and grievance officer
For any privacy question or request: privacy@ubilearn.com.
Grievances under the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules:
Grievance Officer (name to be published on appointment)
Ubinex Technologies Private Limited
We acknowledge grievances within 24 hours and resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.