1. Introduction
We, at eLearnPOSH.com, powered by Succeed Technologies Private Limited, respect your privacy and are
committed to protecting your personal data in accordance with applicable privacy laws, including the
Digital Personal Data Protection Act, 2023.
This privacy notice explains what personal data we collect, why we collect it, how we use it, how long we
keep it, and the rights available to you. By using our website or services, you agree to the terms
described here.
Contact Permission
We’d love to contact you by email to understand more about what you are looking for in our courses,
so we help you make the best decision. We would also like to keep you informed about any new offers or
services. We’ll always treat your personal details with the utmost care and will never sell them to
other companies for marketing purposes.
2. Information We Collect
a) For Individual Users
- Your name, email address, and a password of your choice (password may not be stored if the user chooses
OAuth).
- Mobile number (if WhatsApp based services are selected)
- System-generated data such as your sign-in and sign-out date and time and IP address.
Information related to your learning activities, such as courses viewed, progress, and completion details
b) For Organizational Users
- All data collected for individual users, along with optional details such as Designation, Department,
Employee ID, and Manager ID, depending on your course or subscription requirements, especially for
assignments, reporting, or certification purposes.
c) For Online Purchasers of eLearning Courses
When you buy or subscribe to our courses directly from our website, we may collect and securely process:
- Your billing name, payment method details, invoicing address and other details as stored by the payment
service provider.
- Company name, address, GST number and billing name is collected by us to generate invoice.
- We use Stripe and RazorPay as our payment gateways. These gateways collect and process payment data in
accordance with their respective privacy policies.
- We do not store or have access to any payment-related data on our systems; these details are handled
solely by PCI-DSS compliant payment providers.
d) For Visitors to Our Website and Portals
When you visit our website or any of our learning portals, we collect limited technical and interaction
data, including:
- Your referring link source, browsing behaviour, and form submissions. This information helps us analyse
site performance, enhance usability, and optimize the learning experience.
3. How We Collect Information
We collect information through:
- Registration and contact forms on our website
- Cookies and analytics tools (for example, Google Analytics)
- Learning management system activity logs
- Communication channels such as email or chat support
4. How We Use Your Information
We use your information only to deliver our services, improve user experience, and meet contractual or legal
obligations.
Your data is used to:
- Track, analyse, and report learning progress.
- Recommend courses based on usage patterns.
- Update or develop new courses and features.
- Manage user accounts and fulfil service agreements.
- Enhance platform performance, security, and reliability.
- For organisational users, enable reporting and insights as required by your organisation.
- Send product updates or marketing communications only if you have opted in to receive them.
- Issue completion reports, certificates, sharable verification links and badges for social media platforms
like LinkedIn, X and Facebook.
We do not sell or use your personal information for unsolicited marketing.
5. Cookies Policy
Cookies contain information that is transferred by our portal to your computer or device storage. We use
cookies to enhance your experience and improve our services.
We may use the following cookies:
- Essential Cookies: Required for secure access, session management, cart management, billing,
and payment services.
- Performance Cookies: Help us improve website performance by analysing usage patterns.
- Preference Cookies: Store personalisation preferences such as language selection.
- Third-Party Cookies: eLearnPOSH.com may use third-party tools such as Google Analytics to
track user behaviour on or related to our portal. We do not control the operation of third-party cookies.
Please refer to Google’s privacy policy at: https://policies.google.com/privacy
You can block cookies by disabling them in your browser settings. Disabling essential cookies may make some
parts of the website unavailable.
6. Data Security
ELearn POSH places the highest importance on safeguarding your personal data. We implement a combination of
technical, organizational, and administrative measures to protect the data we collect against unauthorized
access, disclosure, alteration, or destruction.
Security Standards and Certifications
Our information security practices are aligned with internationally recognized standards, including:
- ISO 27001:2022 – Information Security Management System (ISMS)
- SOC 2 Type II – Service Organization Control for Security, Availability, and Confidentiality
These frameworks ensure that our infrastructure, internal controls, and vendor relationships maintain strong
protection for all data processed within our systems.
Technical Safeguards
We use multiple layers of technology and encryption to secure user data, including:
- Encryption in transit and at rest using TLS/SSL protocols
- Web application Firewalls to prevent unauthorized access
- Secure authentication mechanisms with role-based access control
- Regular vulnerability assessments and penetration testing
- System monitoring and logging to identify and respond to suspicious activity
- All backups are encrypted and stored in secure, access-controlled environments to ensure data availability
and recovery in case of an incident.
Organizational Safeguards
We have robust internal procedures and privacy governance frameworks that include:
- Restricted data access based on the principle of least privilege.
- Strict confidentiality obligations for all employees, contractors, and third-party vendors
- Mandatory data protection and cybersecurity training for all personnel.
Incident Management and Breach Response
We maintain a documented Incident Response Plan to detect, investigate, and respond promptly to any potential security breaches. In the event of a confirmed data breach, we will:
- Contain and mitigate the impact immediately
- Notify affected users or organizations without undue delay, as required by applicable law
- Cooperate fully with regulators and clients to ensure compliance and resolution
User Responsibility
While we take every reasonable measure to protect your information, data security also depends on your
cooperation. Users are advised to:
- Use strong, unique passwords and update them periodically
- Keep login credentials confidential and avoid sharing accounts
- Sign out after accessing their account on shared or public devices.
Continuous Improvement
We regularly review and update our security practices to adapt to new technologies, emerging threats, and
evolving legal requirements. Periodic external audits and assessments are conducted to verify the effectiveness
of our controls and ensure ongoing compliance with ISO 27001 and SOC 2 Type II standards.
7. Data Retention Policy
eLearn POSH retains personal data only for as long as necessary to provide services, meet legal or contractual
obligations, and maintain business records. Once no longer needed, data is securely deleted or anonymized in
accordance with our data retention policy, ISO 27001 and SOC 2 Type II standards.
Retention periods:
- Account and learning data: Kept for the duration of your account and deleted within 6 months of closure.
- Billing and financial records: Retained for up to 7 years for tax and compliance purposes.
- Support communications: Retained for up to 2 years after resolution.
- Analytics data: Retained only in aggregated or anonymized form.
Extended retention may apply when required by law, regulation, or contractual obligations. All disposal is done
securely and documented for audit purposes.
8. Consent and Withdrawal
Where consent is required, we will collect and process your personal data only after receiving your consent.
You may withdraw your consent at any time by contacting us at privacy@succeedtech.com
Withdrawal of consent will not affect processing already completed before withdrawal. However, it may affect
your access to certain services, courses, or platform features.
9. Request for Erasure
As an individual user, you can request deletion of your personal data from the profile section or by writing to privacy@succeedtech.com
As an organisational user, you may request for early deletion of your information through your organisation’s
authorised point of contact. Such requests will be governed by data retention policy and applicable contractual
requirements.
10. Access & Rectification
As an individual user, you can view and update your information in the profile section. Your email address may be
locked while editing. To update your email address, please send a request to privacy@succeedtech.com.
If you are an organisational user, your details may be controlled by your organisation. Please contact your
organisation’s administrator to update any details.
11. Third Party Access and Disclosure
We share limited data only with trusted service providers who help us operate and improve our services. We do not
share data for marketing or advertising purposes.
Examples include:
- Payment processors for secure transactions
- Hosting and cloud providers for platform performance
- Analytics services such as Google Analytics for usage insights
12. User Rights and Controls
You have the following rights regarding your personal data:
- Access: Request a copy of the information we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete details.
- Erasure: Request deletion of your data when it is no longer required or permitted by law.
- Individual User: you can request complete erasure of your personal information from the Profile section.
- Organisational User: you can request deletion of your information by contacting your Organizational points of
contact.
This will be governed by your organisation’s data retention policy.
- Opt-out: Decline marketing or withdraw consent for optional data use.
Requests can be sent to privacy@succeedtech.com with “Privacy” as subject line.
13. Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations.
When changes are significant, we will notify users through our website or email. Continued use after an update
signifies acceptance of the revised policy.
14. Grievance Redressal Officer Details
For any privacy-related questions, requests, complaints, or grievances, please contact:
Succeed Technologies Private Limited
Email: privacy@succeedtech.com
We will respond to your grievance within the time period required under applicable law.