1. Scope and roles
This policy applies to Hapus websites, marketplace, learner experiences, institute workspaces and support services. Hapus determines how platform account, security, commerce and learning-service data is processed. Institutes may separately determine how they use information they lawfully collect for their own teaching or administration and should provide their own notice where required.
2. Data we collect
- Account data, such as name, verified contact status, authentication provider and security-session metadata.
- Learner data, such as language preferences, enrolments, access rights, progress checkpoints, notes, assessment results, reviews and credential records.
- Institute data, such as organisation profile, team membership, permissions, course drafts, published content, applications and verification status.
- Transaction data, when payments are enabled, such as orders, item snapshots, payment status, refunds, invoices and provider references. Hapus does not intend to store full card credentials.
- Support, safety and audit data, including requests, conversations, reports, decisions and attributable action history.
- Technical data, such as request identifiers, device/browser information, security events and limited network data needed to protect and operate the service.
3. Why we process data
- Create and secure accounts and maintain user-requested sessions.
- Provide discovery, checkout, learning, assessment, review and credential services.
- Operate institute workspaces, moderation, support, safety and finance controls.
- Prevent fraud, abuse, unauthorised access and manipulated marketplace activity.
- Comply with lawful obligations, resolve disputes and maintain necessary records.
- Improve reliability and usability using privacy-safe aggregate analysis; analytics does not become automatic authority for learner or seller decisions.
4. Consent and other permitted processing
Where consent is the appropriate basis, Hapus will request it through a clear, specific notice and provide a supported way to withdraw it. Some processing may be necessary to perform a service you request, protect the platform, respond to emergencies, comply with law or handle other uses permitted by applicable law. Withdrawing consent does not undo lawful processing already completed and may make an optional feature unavailable.
5. How data is shared
- With the institute responsible for a course, only where needed to deliver that course and subject to role and relationship boundaries.
- With infrastructure, authentication, communications, payment, security and support providers acting under appropriate terms.
- With professional advisers, auditors or authorities where lawfully required.
- During a genuine corporate transaction subject to confidentiality and applicable notice requirements.
- Publicly only when a feature is designed for publication—for example, a chosen public review display or credential verification record.
6. What we do not expose
Hapus does not make passwords, authentication tokens, payment instruments, raw private notes, assessment answers, unrestricted learner contact details or private institute evidence publicly available. Institute reporting uses relationship-scoped learner references and permission controls rather than exposing global identity identifiers.
7. Retention
We retain data only for the period needed for the stated service, security, audit, dispute, financial or legal purpose. Different records require different periods: a security session may be short-lived, while an invoice, moderation decision or issued credential may need a longer history. Before full launch, Hapus will publish an approved retention schedule and implement supported export and closure workflows.
8. Security
Hapus uses access controls, separated authentication and application stores, encrypted transport, secret management, audit records and least-privilege role boundaries. No system is perfectly secure. If a personal-data breach creates a notification obligation, Hapus will follow the applicable legal and regulatory process.
9. Your choices and rights
- Access information about personal data processed through supported account and privacy surfaces.
- Correct inaccurate or incomplete profile information through supported workflows.
- Withdraw optional consent and manage communication preferences.
- Request grievance redressal, data export, erasure or account closure where applicable and technically available.
- Nominate another person to exercise applicable rights where the law provides for nomination.
- Appeal or use external remedies available under applicable law.
10. Children
Hapus is not currently designed for unsupervised use by children. Before enabling child-directed learning, Hapus must establish age-appropriate design, verifiable parental-consent handling and restrictions required by applicable law. Institutes must not knowingly enrol children through unsupported workarounds.
11. International processing
Cloud and service providers may process data in more than one location. Hapus will use contractual, security and transfer controls required by applicable Indian law and any notified restrictions. Production provider locations and subprocessors will be documented before full transactional launch.
12. Contact and grievance redressal
Privacy questions, rights requests and grievances may be submitted through Hapus Support. Hapus will publish additional statutory contact and grievance details when they become applicable to the services it enables.