Trainez

Privacy Policy

Last updated: [CONFIRM: date of publication]

This document is a draft. The highlighted items must be confirmed and the whole text reviewed by a qualified adviser before launch.

Who we are

This service is operated by Varuni Systems Pvt Ltd , of D-1110, The First, Nyay Marg, Ahmedabad, India . Questions about this policy, or requests concerning your data, go to support@trainez.live.

Two kinds of data, and who is responsible for each

We hold information about our customers — the institutes who subscribe — and, separately, information their staff enter about their candidates.

For candidate records, the institute decides what is collected and why; we only store and process it on their instructions. In data-protection terms the institute is the controller and we are the processor. If you are a candidate asking about your own records, contact the institute that trained you — they can correct or remove them, and we act on their instruction.

What we collect about our customers

What institutes store about candidates

This is entered by the institute and typically includes name, contact details, date of birth, and training history. For maritime institutes it also includes documents required by the regulator — passport number, seafarer identity numbers such as INDoS, certificates of competency, and uploaded scans of those documents.

We do not use candidate data for our own purposes. We do not sell it, and we do not use it to train models.

Where it is held

Data is stored on servers in[CONFIRM: hosting region, e.g. Linode Mumbai]. Each institute's records are isolated at the database level so that one customer's queries cannot return another's rows.

How long we keep it

While a subscription is active, and for[CONFIRM: retention period after cancellation, e.g. 90 days]afterwards, so that an account can be restored. After that,[CONFIRM: what happens: deletion, or return of an export, and how a customer requests one]

Your rights

Under[CONFIRM: applicable law — e.g. the Digital Personal Data Protection Act 2023 (India); add GDPR if selling into the EU]you may ask us to give you a copy of your data, correct it, or delete it. We respond within[CONFIRM: response window, e.g. 30 days]. Complaints may be directed to[CONFIRM: supervisory authority, if one applies]

Sub-processors

We use third parties to deliver parts of the service — currently[CONFIRM: list: hosting provider, email provider, SMS provider, payment provider once chosen]. We will give notice before adding a new one that processes customer data.

Security

Traffic is encrypted in transit. Passwords are hashed. Access to production systems is limited to[CONFIRM: who has access, and how it is controlled]. If a breach affects your data we will tell you within[CONFIRM: notification window]and explain what happened.

Cookies

We set a session cookie so you stay signed in, a language cookie, and a currency preference on the pricing page. There is no advertising or third-party tracking.

Changes

We will post changes here and, for anything material, tell subscribers by email before it takes effect.