- We collect only what we need to handle your application, run your training and internship, take payments and issue your certificate.
- Marketing emails and WhatsApp messages are sent only if you opt in separately. Reply STOP or email us to stop them at any time.
- Google Analytics and Meta Pixel load only after you accept cookies.
- Razorpay handles your payment. We never see or store your full card number, CVV or UPI PIN.
- You can ask to see, correct or erase your data, or nominate someone to act for you, by writing to privacy@tectranz.com.
- We share data with partner companies only with your consent, and only what they need for your internship project.
01Who we are and what this policy covers
Tectranz is an AI training and internship programme. In this policy, "we", "us" and "our" mean Tectranz. "You" means anyone who visits https://tectranz.com, applies to a programme, enrolls, or talks to us by email, phone or WhatsApp.
Under the Digital Personal Data Protection Act, 2023 (the DPDP Act), we are the Data Fiduciary for your personal data. This means we decide why and how your data is used, and we are responsible for protecting it. You are the Data Principal: the person the data is about.
- Legal name: Tectranz
- Registered office: [Registered office address], [City], [State] – [PIN], India
- Registration number: [CIN / LLPIN / Udyam registration number]
- Privacy contact: privacy@tectranz.com
This policy is our notice to you in plain language. It covers our website, enquiry and application forms, online and in-office programmes, and our email and WhatsApp conversations with you. It does not cover websites or apps run by others, such as partner companies or Razorpay. They have their own policies.
02The laws we follow
We handle personal data in line with Indian law, including:
- The Digital Personal Data Protection Act, 2023, and the rules made under it.
- The Information Technology Act, 2000.
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the SPDI Rules), to the extent they still apply.
- The Consumer Protection (E-Commerce) Rules, 2020, for how we sell and refund our programmes.
A Data Processor is a company that handles data for us, on our instructions. Examples are our email provider and our website host. They are listed in the section on sharing below.
03What personal data we collect
Most of the data we hold comes directly from you. Each form shows which fields are required.
| Type of data | Examples | Where it comes from |
|---|---|---|
| Contact details | Name, email address, phone or WhatsApp number, city | You, through our forms, email, phone or WhatsApp |
| Academic details | College, branch, year and semester (for example 4.1 or 4.2), graduation year | You |
| Programme interest | The track, plan and mode (online or offline) you are interested in | You |
| Referral and campaign source | UTM tags in the link you clicked, and how you heard about us | Your browser, when you arrive on our website. It reaches us only if you submit a form. |
| Payment details | Razorpay order and payment IDs, amount, payment status, payment method type (such as UPI or card), GST invoice details | Razorpay. We do not receive or store full card numbers, CVV, UPI PIN or net banking passwords. |
| Programme records | Attendance, assessment scores, project submissions, logbook entries, progress reports, mentor feedback | You, your mentors and, for partner projects, partner reviewers |
| Messages | What you write to us by email or WhatsApp, and notes from counsellor calls | You and our team |
| Usage data (only with your consent) | Pages you visit, device and browser type, approximate location from your IP address, cookie IDs | Google Analytics and Meta Pixel, only after you accept cookies |
| Technical logs | IP address, browser type, time of request | Our hosting provider, to keep the website secure and working |
We do not ask for Aadhaar numbers, health information, biometric data, caste, religion or any passwords. Please do not send us such data. Card and bank details, which the SPDI Rules treat as sensitive, are handled only by Razorpay.
04Why we use your data, and on what basis
The DPDP Act lets us use personal data only with your consent, or for certain legitimate uses. A legitimate use includes data you give us yourself for a specific purpose, and data the law requires us to keep. The table shows each purpose and its basis.
| Purpose | Data used | Basis |
|---|---|---|
| Replying to your enquiry and arranging a counsellor call | Contact details, programme interest | Consent, which you give when you submit the form |
| Processing your application and enrollment | Contact and academic details, programme interest | Consent, and legitimate use: you gave us the data to enroll |
| Taking payment and issuing GST invoices | Name, contact details, payment details | Legitimate use, and our legal duties under tax law |
| Running your training: access details, class schedules, attendance and assessments | Contact details, programme records | Legitimate use: we need it to deliver what you paid for |
| Service messages such as class reminders and schedule changes | Contact details | Legitimate use. On WhatsApp, only if you agreed to receive updates there. |
| Matching you with a partner company project | Name, track, and the project work and performance details the partner needs | Consent, which we ask for before sharing |
| Sending progress reports and records to your college | Name, programme records | Consent, or your request |
| Issuing documents and certificates, and letting others verify them | Name, programme, dates, certificate ID | Legitimate use |
| Marketing emails and WhatsApp messages about programmes and offers | Name, email, WhatsApp number, programme interest | Separate opt-in consent only |
| Measuring website use and ad performance | Usage data, cookie IDs | Consent, through our cookie banner |
| Keeping our systems secure, preventing fraud and meeting legal duties | Technical logs, payment records | Legal obligation and legitimate use |
We will not use your data for a new, unrelated purpose without telling you first and, where the law needs it, asking for your consent.
05Your consent and how to withdraw it
When we ask for consent, we ask in plain words, for a specific purpose, and we need a clear action from you, such as ticking a box or pressing a button. Marketing consent is always a separate choice. Saying no to marketing does not affect your application or enrollment.
You can withdraw consent at any time. It is as easy as giving it:
- WhatsApp: reply STOP to any of our WhatsApp messages.
- Email: use the unsubscribe link at the bottom of any marketing email.
- Cookies: use the "Cookie settings" link in the website footer.
- Anything else: write to privacy@tectranz.com.
Withdrawing consent stops future use for that purpose. It does not affect what we did before you withdrew. If you withdraw consent that your programme depends on, such as sharing your project work with a partner company, we will explain what that means for your internship before we act on it.
Even after you withdraw consent, we may keep data that the law requires us to keep, such as payment and invoice records.
07Transfers outside India
Some of our service providers, including Vercel, Brevo, Google and Meta, may store or process your data on servers outside India.
The DPDP Act allows this, except to countries that the Government of India restricts by notification. We will not transfer personal data to a restricted country, and we will stop any transfer that becomes restricted.
We choose providers that commit to security and confidentiality in their contracts with us. The protections in this policy apply to your data wherever it is processed.
08How long we keep your data
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. After that, we delete it or anonymise it so it no longer identifies you.
| Data type | Why we keep it | How long |
|---|---|---|
| Enquiries from people who do not enroll | To follow up on your enquiry | 12 months after our last contact with you, unless you ask us to delete it sooner |
| Application and enrollment records | To run your programme and answer questions about it later | 3 years after your programme ends |
| Attendance, assessments, logbook, progress reports and final report | To issue documents, support your college's credit process and handle disputes | 3 years after your programme ends |
| Project submissions | For review, originality checks and your certificate | 3 years after your programme ends. Work done for a partner may also follow the partner's terms. |
| Certificate records (name, programme, dates, certificate ID) | So employers and colleges can verify your certificate | As long as we run certificate verification. You can ask us to switch off public verification of your certificate. |
| Payment records and GST invoices | Tax and accounting laws | 8 years from the end of the financial year in which you paid |
| Emails, WhatsApp messages and call notes | To answer your questions and keep a record of what we agreed | 2 years after the last message |
| Marketing consent and opt-out records | To show you consented, and to make sure we do not message you after you opt out | While you are subscribed. After you opt out, we keep only the opt-out record, for as long as we need it to respect your choice. |
| Grievance records | To resolve complaints and show how we handled them | 3 years after the complaint is closed |
| Analytics data in Google Analytics | To understand how the website is used | Up to 14 months |
| Technical logs | Security and fixing problems | A short period set by our hosting provider |
If a dispute, investigation or legal claim is ongoing, we may keep the related data until it is resolved.
09Your rights
As a Data Principal under the DPDP Act, you have the right to:
- Access: get a summary of the personal data we hold about you, what we do with it, and who we have shared it with.
- Correction: fix data that is wrong, complete data that is missing, and update data that has changed.
- Erasure: ask us to delete your data once it is no longer needed for the purpose you gave it for. If the law requires us to keep some of it, we will tell you what we kept and why.
- Withdraw consent: at any time, as described above.
- Grievance redressal: have a complaint about your data handled by our Grievance Officer.
- Nominate: name another person who can use these rights for you if you die or become unable to act.
To use any of these rights, email privacy@tectranz.com from the email address you gave us. We may ask you to confirm your identity first, so that we do not hand your data to someone else. There is no charge.
We acknowledge requests within 48 hours and respond within 15 days.
The DPDP Act also gives you some duties: give accurate information, do not impersonate anyone, and do not file false or frivolous complaints.
10How we protect your data
- Our website uses HTTPS, so data is encrypted on its way between your browser and our servers.
- Only team members and mentors who need your data for their work can see it.
- Accounts that hold personal data use strong passwords and two-step verification where the service supports it.
- Payments happen on Razorpay's secure checkout. Card details never reach our systems.
- We review who has access and remove it when someone no longer needs it.
No system is completely secure. If a personal data breach happens, we will inform affected people and the Data Protection Board of India as the DPDP Act requires, and report it to CERT-In where the law requires. We will tell you what happened, what data was involved and what you can do.
If you notice a security problem with our website or messages, please tell us at privacy@tectranz.com.
11Students under 18
Our programmes are meant for people aged 18 and above. Most final-year students and job seekers are already 18 or older.
We do not knowingly enroll anyone under 18 without verifiable consent from a parent or lawful guardian, as the DPDP Act requires. If you are under 18, your parent or guardian must write to admissions@tectranz.com before you enroll.
We do not knowingly track the behaviour of anyone under 18 or target them with advertising.
If we learn that we hold data about someone under 18 without guardian consent, we will stop using it and delete it, except where the law requires us to keep it.
13Changes to this policy
We may update this policy when our services, our providers or the law change. The date at the top of the page shows when it was last updated.
If a change affects how we use your data in a meaningful way, we will email you before it takes effect. If we want to use your data for a new purpose that needs consent, we will ask you again.
14Contact us and raise a grievance
For questions or requests about your personal data, email privacy@tectranz.com.
If you are not happy with our response, or you want to complain about how we handle your data, contact our Grievance Officer:
- Name: [Grievance Officer name]
- Designation: Grievance Officer
- Email: grievance@tectranz.com
- Phone: +91 [00000 00000]
- Address: [Registered office address], [City], [State] – [PIN], India
We acknowledge grievances within 48 hours and aim to resolve them within 15 days.
If you are still not satisfied after using our grievance process, you have the right to complain to the Data Protection Board of India under the DPDP Act.
You can ask for this notice in English or in any language listed in the Eighth Schedule to the Constitution of India by writing to privacy@tectranz.com.