Legal
Privacy Policy
How Seedqura Technologies LLP collects, uses, stores, and protects your personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act).
Seedqura Technologies LLP · Last updated 2026-08-22
1. Introduction
This Privacy Policy explains how Seedqura Technologies LLP (“Seedqura”, “we”, “us”, “our”), operating the Seedqura website, Academy, and related services, handles your personal data.
We are committed to processing personal data lawfully, fairly, and transparently in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules thereunder.
By using our website, creating an account, submitting forms, enrolling in courses, or otherwise interacting with us, you acknowledge that you have read this Privacy Policy.
2. Data Fiduciary
For the purposes of the DPDP Act, Seedqura Technologies LLP is the Data Fiduciary responsible for determining the purpose and means of processing your personal data.
Registered office: India.
General contact: [email protected]
Privacy and grievance contact: [email protected]
3. Scope
This policy applies to personal data collected through:
- Our website at seedqura.com and seedqura.in (including subdomains and related pages)
- Seedqura Academy — course catalog, enrollment, and student accounts
- Contact, partnership, and application forms
- Account registration, login, and password recovery
- Payment processing for Academy courses
- Transactional and service-related email communications
- Live session scheduling (Google Meet / Google Calendar invitations where applicable)
4. Personal Data We Collect
The personal data we collect depends on how you interact with us. Categories may include:
- Identity & contact: full name, email address, phone number (where provided)
- Account data: login credentials (stored securely by our authentication provider; we do not store plaintext passwords)
- Profile data: role (student/admin), institution, academic year, portfolio or LinkedIn/GitHub URLs
- Communication data: messages sent via contact forms, application statements, subject lines
- Transaction data: course purchased, payment status, order identifiers, enrollment records (payment card details are processed directly by Razorpay — we do not store full card numbers)
- Technical data: IP address (for rate limiting and security), browser type, session cookies required for authentication
- Session data: Google Meet links and calendar metadata when you are enrolled in live cohort sessions
5. Purposes of Processing
We process personal data for specific, explicit, and legitimate purposes, including:
- Creating and managing your account on our platform
- Processing Academy enrollments, payments, and access to purchased courses
- Scheduling and delivering live teaching sessions
- Responding to inquiries, partnership requests, and applications
- Sending transactional emails (welcome, payment confirmation, session reminders)
- Maintaining security, preventing fraud, and enforcing rate limits
- Complying with legal obligations and responding to lawful requests
- Improving our services (using aggregated or anonymised data where possible)
6. Lawful Grounds for Processing
Under the DPDP Act, we rely on the following grounds as applicable:
Where consent is the basis, you may withdraw consent at any time (see Section 12). Withdrawal does not affect processing already performed lawfully before withdrawal.
- Consent — when you tick acceptance boxes, submit forms, register an account, or opt in to optional communications
- Performance of a contract — to provide Academy courses and services you purchase or register for
- Legitimate uses — as permitted under the DPDP Act for certain processing that is necessary and proportionate (e.g., security, fraud prevention)
- Legal obligation — where we must retain or disclose data to comply with applicable law
8. Third-Party Processors
We use trusted service providers who process personal data on our behalf under contractual safeguards:
These providers may process data on servers located outside India. Where personal data is transferred internationally, we take reasonable steps to ensure appropriate safeguards consistent with applicable law.
- Supabase — authentication, database, and account storage
- Razorpay — payment processing (PCI-DSS compliant payment gateway)
- Resend — transactional email delivery
- Google (Calendar / Meet) — scheduling live Academy sessions and sending meeting invitations
- Vercel — website hosting and content delivery
- Render — backend API hosting (where applicable)
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer period is required by law.
- Account data: retained while your account is active and for a reasonable period thereafter (typically up to 3 years) for legal, accounting, or dispute resolution purposes
- Payment and enrollment records: retained as required for tax, accounting, and consumer protection obligations (typically 7 years or as mandated by law)
- Contact and application submissions: retained for up to 24 months unless a longer period is needed for ongoing correspondence
- Server logs and security data: retained for up to 90 days unless needed for incident investigation
10. Security Measures
We implement reasonable technical and organisational measures to protect personal data, including encrypted connections (HTTPS), access controls, authentication via industry-standard providers, and rate limiting on public forms.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at [email protected].
11. Children’s Data
Our services are intended primarily for adults and students aged 18 and above. We do not knowingly collect personal data from children under 18 without verifiable parental or guardian consent.
If you are a parent or guardian and believe your child has provided personal data without consent, contact us at [email protected] and we will take steps to delete such data.
12. Your Rights as a Data Principal
Under the DPDP Act, you have the right to:
To exercise these rights, email [email protected] with sufficient detail to verify your identity. We will respond within the timelines prescribed under applicable law.
- Access — request information about the personal data we hold about you
- Correction — request correction of inaccurate or incomplete personal data
- Erasure — request deletion of personal data where applicable (subject to legal retention requirements)
- Withdraw consent — where processing is based on consent
- Grievance redressal — raise a complaint with our Grievance Officer
- Nominate — nominate another individual to exercise your rights in the event of death or incapacity, as permitted under the DPDP Act
13. Grievance Redressal
If you have concerns about how we handle your personal data, contact our Grievance Officer:
Email: [email protected]
We will acknowledge and endeavour to resolve grievances within 30 days of receipt, or within the period prescribed under the DPDP Act and applicable rules, whichever is shorter.
If you are not satisfied with our response, you may have the right to approach the Data Protection Board of India as provided under the DPDP Act.
14. Data Breach Notification
In the event of a personal data breach that is likely to affect you, we will take reasonable steps to notify affected Data Principals and relevant authorities as required under the DPDP Act and applicable rules.
15. Marketing Communications
We do not send unsolicited marketing email without your consent. Transactional and service-related messages (account, payment, session reminders) are sent as part of the services you use.
You may opt out of optional marketing communications at any time by using the unsubscribe link (if provided) or contacting [email protected].
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date. Where required by law, we will seek renewed consent.
Last updated: 22 August 2026.
