Animate Solution logoAnimate Solution

Privacy Policy

What we collect, why we collect it, who can see it, and how you get it removed.

Last updated: August 2026

This policy explains how Animate Solution (“we”, “us”, “our”) handles your personal data when you use our website, our mobile application, or the learning platform behind them (together, the “Platform”). It is written to be read, not skimmed past — where something about our handling might surprise you, we have said so plainly rather than burying it.

We are the Data Fiduciary for your personal data under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). That means we decide why and how your data is processed, and we are accountable to you for it.

1. The data we collect

1.1 Information you give us

  • Required to create an account — your full name, email address, and a password. Your password is never stored in readable form; we keep only a one-way bcrypt hash, which cannot be reversed back into your password.
  • Optional profile details — phone number, postal address, date of birth, gender, and a profile photo. The Platform works without these; you choose whether to provide them.
  • Payment proof you upload — if you pay by UPI, QR or bank transfer, you submit a transaction reference and, optionally, a screenshot of your payment. Please note that such screenshots often contain your bank or UPI details. We store the image on our server so an administrator can verify your payment, and we ask you not to upload anything beyond what is needed to prove the transaction.
  • Messages you send us — anything you write through our contact form or by email, including the contents of a support or refund request.

1.2 Information created as you learn

  • Which courses you enrol in, when you purchased, and when your access expires.
  • Which chapters you have completed and your overall progress percentage.
  • Every quiz attempt: your score, whether you passed, how long the attempt took, and when you took it.
  • Certificates issued to you, including a unique certificate number.

1.3 Information about payments

We record the amount, currency, status, our invoice number, and the reference supplied by the payment gateway or by you. We never see or store your card number, CVV, UPI PIN, or net-banking credentials — those are handled entirely by the payment gateway on its own systems.

1.4 Technical information

Our servers keep standard web logs (IP address, browser or app version, the pages or endpoints requested, and timestamps) for security, abuse prevention and debugging. We use browser storage on your device to keep you signed in; this is described in our Cookie Policy.

2. Why we process it, and on what basis

Under the DPDP Act we process your data either with your consent or for “legitimate uses” permitted by the Act. In plain terms:

  • To give you what you paid for — creating your account, unlocking the courses you bought, tracking progress, marking quizzes, and issuing certificates. Without this data the service cannot function.
  • To take and verify payment — including manual review of the reference and screenshot you submit for UPI, QR and bank transfers.
  • To contact you about your account — sign-in codes, password resets, payment confirmations, and notices about a course you are enrolled in. These are service messages and are not marketing.
  • To keep the Platform secure — detecting fraud, abuse, and unauthorised sharing of paid content.
  • To meet legal and tax obligations — retaining transaction records for the periods Indian law requires.

We do not sell your personal data, and we do not use it to build advertising profiles.

3. Who else can see your data

This section describes real visibility inside the Platform. Please read it before you enrol.

3.1 Course leaderboards are visible to other learners

If you attempt a quiz in a course, your name and score may appear on that course’s leaderboard, which is visible to other students enrolled in the same course. Your email address, phone number and other profile details are never shown there. If you would rather not appear, do not take the optional quizzes, or write to us and we will exclude you.

3.2 Certificates can be verified publicly

Every certificate carries a unique number and a QR code so that an employer or institution can confirm it is genuine. Anyone who has that certificate number can look it up and will see the name on the certificate, the course, and the issue date. This is the point of a verifiable certificate, but it does mean the certificate number should be shared only with people you want to be able to check it.

3.3 Instructors see their own students

An instructor can see the students enrolled in their own courses — name, email, enrolment date, progress and quiz results — because they need it to teach and to assess. An instructor cannot see students of other instructors’ courses, and cannot see your payment method details.

3.4 Our staff

Administrators can access account, enrolment and payment records in order to run the Platform — for example to verify a UPI payment or process a refund. Access is role-based and enforced on the server, not merely hidden in the interface.

3.5 Service providers

  • Payment gateway — Razorpay Software Private Limited, to take and verify payments. Razorpay’s own privacy policy governs what it collects.
  • Hosting — our application, database and uploaded files run on a private virtual server rented from our hosting provider. Files you upload (payment screenshots, profile photos) are stored on that server’s disk, not on a public file service.
  • Email delivery — to send sign-in codes and service notices.

3.6 Legal disclosure

We may disclose data where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim, or to prevent harm.

4. Where your data is stored

Your data is stored on our hosting provider’s infrastructure. If data is processed outside India, we do so in accordance with the DPDP Act and any restrictions notified by the Central Government. We will update this section if our hosting arrangements change.

5. How long we keep it

  • Account and learning records — for as long as your account is open, and then deleted or anonymised after you close it, except where we must retain something (below).
  • Payment and invoice records — retained for the period required by Indian tax and accounting law, even after account closure. These cannot be deleted on request while that obligation lasts.
  • Payment screenshots — kept while the payment may still be queried or disputed, then deleted.
  • Issued certificates — retained so that verification keeps working. If you want a certificate record removed, tell us and we will explain the effect on its verifiability before acting.
  • Security logs — kept for a short period and then rotated out.

6. Your rights under the DPDP Act

You have the right to:

  • Know what personal data of yours we hold and who we have shared it with.
  • Correct or complete inaccurate data. Most of it you can edit yourself from your profile; write to us for anything you cannot.
  • Erase your data where we no longer need it for the purpose it was collected for and no law requires us to keep it.
  • Withdraw consent at any time, as easily as you gave it. Be aware that withdrawing consent for data we need to run your account means we can no longer provide the service.
  • Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
  • Grievance redressal — raise a complaint with us first (section 9). If we do not resolve it, you may escalate to the Data Protection Board of India.

To exercise any of these, email us from the address registered on your account so we can confirm it is you. We will respond within a reasonable period and in any case as required by law.

7. Security

We protect your data with: HTTPS on every connection; bcrypt password hashing; role-based access enforced on the server; short-lived, single-purpose links for course material and certificate downloads; and access to paid course files gated behind an enrolment check on every request. Payment credentials never reach our servers.

No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board as the DPDP Act requires.

8. Children

Under the DPDP Act, anyone under 18 years of age is a child. We do not knowingly create accounts for children without verifiable consent from a parent or legal guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you are under 18, ask your parent or guardian to register and manage the account. If you believe a child has registered without such consent, contact us and we will remove the account and its data.

9. Contact and grievance officer

For any question about this policy, or to exercise a right or raise a complaint, contact our Grievance Officer:

We aim to acknowledge grievances within 2–3 business daysand resolve them within 30 days.

10. Changes to this policy

We may revise this policy. When a change materially affects how we handle your data, we will notify you through the Platform or by email before it takes effect, and update the date at the top of this page.

Questions about this policy? Email us at hello@animatesolution.com or visit our Contact page.