Privacy Policy
Last updated: [CONFIRM: date of publication]
Who we are
This service is operated by Varuni Systems Pvt Ltd , of D-1110, The First, Nyay Marg, Ahmedabad, India . Questions about this policy, or requests concerning your data, go to support@trainez.live.
Two kinds of data, and who is responsible for each
We hold information about our customers — the institutes who subscribe — and, separately, information their staff enter about their candidates.
For candidate records, the institute decides what is collected and why; we only store and process it on their instructions. In data-protection terms the institute is the controller and we are the processor. If you are a candidate asking about your own records, contact the institute that trained you — they can correct or remove them, and we act on their instruction.
What we collect about our customers
- Account details: name, work email, workspace name, and a password we store only as a hash.
- Billing details, once payment is available:[CONFIRM: what your payment provider will store, and where]
- Operational logs: IP address, browser, and the pages requested, kept to run and secure the service.
What institutes store about candidates
This is entered by the institute and typically includes name, contact details, date of birth, and training history. For maritime institutes it also includes documents required by the regulator — passport number, seafarer identity numbers such as INDoS, certificates of competency, and uploaded scans of those documents.
We do not use candidate data for our own purposes. We do not sell it, and we do not use it to train models.
Where it is held
Data is stored on servers in[CONFIRM: hosting region, e.g. Linode Mumbai]. Each institute's records are isolated at the database level so that one customer's queries cannot return another's rows.
How long we keep it
While a subscription is active, and for[CONFIRM: retention period after cancellation, e.g. 90 days]afterwards, so that an account can be restored. After that,[CONFIRM: what happens: deletion, or return of an export, and how a customer requests one]
Your rights
Under[CONFIRM: applicable law — e.g. the Digital Personal Data Protection Act 2023 (India); add GDPR if selling into the EU]you may ask us to give you a copy of your data, correct it, or delete it. We respond within[CONFIRM: response window, e.g. 30 days]. Complaints may be directed to[CONFIRM: supervisory authority, if one applies]
Sub-processors
We use third parties to deliver parts of the service — currently[CONFIRM: list: hosting provider, email provider, SMS provider, payment provider once chosen]. We will give notice before adding a new one that processes customer data.
Security
Traffic is encrypted in transit. Passwords are hashed. Access to production systems is limited to[CONFIRM: who has access, and how it is controlled]. If a breach affects your data we will tell you within[CONFIRM: notification window]and explain what happened.
Cookies
We set a session cookie so you stay signed in, a language cookie, and a currency preference on the pricing page. There is no advertising or third-party tracking.
Changes
We will post changes here and, for anything material, tell subscribers by email before it takes effect.