Legal
Privacy Policy
What we collect, why we collect it, who else handles it and how long we keep it.
Last updated: 4 September 2026
Who we are
AutoSec Academy is the training and capability brand of AutoSecurity Innovations Private Limited, trading as AutoSec Innovation — company identification number U30911UP2024PTC201613, Bengaluru, India.
We are the controller of the personal data described in this notice. For anything in it, including any request about your rights, write to info@autosecacademy.com.
Our parent company website, autosecinnovation.com, publishes its own privacy notice covering that site. This one covers autosecacademy.com.
What this notice covers
This website: the pages you read, the enquiry and newsletter forms, and booking a place on a training course.
It does not cover the learning platform. Signing in, course progress and the hands-on lab environment run on a separate system with its own accounts and sessions. When that opens to learners it will publish its own notice, and we will link it here rather than quietly stretch this one to cover it.
What we collect
Nothing is collected automatically as you browse. There is no account, no login and no tracking on this website. Everything below is something you type and send us.
When you submit an enquiry
Your name, company, email address, country, which training you are interested in and your message — and optionally a phone number. We also record which page you submitted from, so we can answer you in context.
When you subscribe to updates
Your email address, optionally your first name, and any topics you select.
When you book a place on a training course
Your name and email address, optionally a phone number and any remarks you add. If you arrived from a campaign link we record which one, because knowing which channel reaches practitioners is the point of running the campaign.
Alongside the booking we store the session you booked, the amount charged and its reference from our payment provider, and — for abuse triage only — the IP address and browser user agent the booking came from. Those two are never used to identify or profile a learner.
Payment details, which we never see
Card numbers, UPI handles and every other payment credential go directly to Razorpay and are never sent to us or stored by us. Our booking record says that a payment succeeded and what it was for. It cannot reconstruct how you paid.
What we do not do
Stated plainly, because it is unusual enough to be worth saying:
- We run no analytics and no tracking anywhere on this website.
- We set no cookies of our own — see the Cookie Policy for the two third-party exceptions on the booking page.
- We do not sell, rent or share your data with advertisers or data brokers.
- We do not profile you or make automated decisions about you.
- We do not track you across other websites.
Why we use it, and on what basis
- To answer your enquiry and discuss training that fits — because it is in our legitimate interests to respond to someone who contacted us about our services, and because it is a step towards a contract where the enquiry is about enrolling.
- To take a booking, confirm your place, send your receipt and joining details, and deliver the session — to perform the contract you entered when you booked.
- To send you updates you asked for — on your consent, which you can withdraw at any time.
- To keep the site and the booking form working and free of automated abuse — our legitimate interest in a service that is not being attacked.
- To keep the financial records the law requires us to keep, and to respond to lawful requests — our legal obligations.
Who else handles it
We keep the chain deliberately short.
| Who | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | Hosts this website and our API, protects the booking form against automated abuse (Turnstile) and routes mail sent to our addresses | United States company, delivered from edge locations worldwide |
| Razorpay Software Private Limited | Processes course payments. Razorpay collects your payment details directly — we never see or store them | India |
| Resend (Plaintext Tools, Inc.) | Delivers enquiry and booking notifications to our inbox | United States company, sending infrastructure in the EU |
We add a processor only when we need one, and we update this notice when we do. Beyond these, we share personal data only with professional advisers where reasonably required, or with authorities where the law requires it.
Where it goes
Bookings and payments are handled in India. Two of our processors are United States companies, so some data — the notification email telling us you got in touch, and the delivery of this website itself — is handled outside India and outside the European Economic Area. Where the law requires safeguards for those transfers we rely on the standard contractual clauses in our agreements with those providers.
How long we keep it
- Enquiries and newsletter subscriptions — 24 months from our last contact with you, or until you unsubscribe or ask us to delete them.
- Course bookings and payment records — 8 years from the end of the financial year the booking falls in. These are financial records and we are required to retain them, so we cannot delete them on request before that period ends.
- Technical and abuse-triage data — a short operational period, unless needed for a security investigation.
Your rights
Subject to the law that applies to you, you can ask us for a copy of your data, ask us to correct or delete it, ask us to restrict or stop a particular use, or ask for it in a portable form. Where we rely on your consent you can withdraw it at any time, which does not affect anything done before you withdrew it.
Write to info@autosecacademy.com with enough detail for us to find your record. We will respond within one month. If you are not satisfied with how we have handled a request, you can complain to the data protection authority in your country.
Security
This site is served over HTTPS only, with a content security policy and other protective headers. Enquiry and booking data is handled server-side and never sent to any analytics service. No payment credentials are collected anywhere on this site, which keeps them out of our systems entirely rather than merely protecting them within.
The enquiry form is not a secure channel for confidential material. If you need to send us something sensitive, ask first and we will arrange an appropriate route.
Children
This site is aimed at engineers, students in higher education and organisations. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will remove it.
Changes
We update this notice when what we do changes, and revise the date at the top. Where a change is material we will say so on this page rather than let it pass silently.