Privacy Policy
We collect the minimum personal data needed to respond to you and deliver our services. This policy explains exactly what we collect, why, how long we keep it, and the rights you have over it under Indian law.
Data Fiduciary
Bahadurgarh, Haryana 124507, India
1. Who We Are
Webphiser Software & Education Services ("WebPhiser", "we", "us", "our") is a Sole Proprietorship registered in India, operating the website webphiser.com and providing software development services and education programs.
For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act), we act as the Data Fiduciary for the personal data described in this policy. Where we process a client's end-user data as part of a development engagement, we act as a Data Processor on that client's instructions, governed by the relevant agreement rather than this policy.
This policy applies to webphiser.com and all of its subpages, including our education section at webphiser.com/edu.
2. Data We Collect
We collect only what we actually need. In practice, that is:
2.1 Information you give us directly
| Where | What we collect |
|---|---|
| Project enquiry form (homepage) | Name, work email address, and the project description you choose to write |
| Course enrolment form (Education page) | Name, email address, WhatsApp/phone number, city, program of interest, preferred format (group or 1-on-1), and any goals or skill-level notes you add |
| Newsletter form (footer) | Email address only |
| Email, phone or WhatsApp | Whatever you choose to share in your message, plus your contact details |
| Enrolment & billing | Billing name and address, GSTIN if you need a GST invoice, and payment reference/transaction ID |
| During a program | Attendance, submitted assignments and project work, and instructor feedback |
None of our forms require you to provide sensitive personal data. Please do not include passwords, financial account details, health information, government ID numbers or other sensitive information in a free-text message field.
2.2 Information collected automatically
- IP address, approximate location derived from it, browser type and version, operating system, device type;
- Pages visited, time spent, referring URL and basic navigation behaviour;
- Date and time of access.
This is standard web-server log data, recorded by our hosting provider as an unavoidable part of serving any web page. We do not run analytics or tracking scripts on this site — see our Cookie Policy. We use these logs in aggregate to keep the site secure and understand which pages are useful — not to build a profile of you as an individual.
2.3 Information we do not collect
- We do not collect your card number, CVV, UPI PIN, or net-banking credentials — see section 6;
- We do not buy personal data from data brokers or third-party lists;
- We do not collect biometric data;
- We do not run advertising trackers or sell data to advertisers.
3. Why We Collect It
We use your personal data only for these purposes:
- To respond to you — answering enquiries, scheduling the free intro call, and sending you a proposal or quote;
- To deliver our services — enrolling you in a batch, sharing session links and recordings, running the engagement, and providing support;
- To handle payments — raising invoices, confirming payments, processing refunds and meeting GST/accounting obligations;
- To communicate about your service — schedule changes, batch updates, milestone updates and other transactional messages;
- To send updates you asked for — our newsletter, only if you subscribed, with an unsubscribe link in every message;
- To improve — understanding aggregate site usage and course feedback to make both better;
- To stay secure and lawful — preventing fraud and abuse, and complying with legal obligations and lawful requests.
We have never sold, rented or traded personal data, and we do not do so. We also do not share your contact details with any third party for their own marketing.
4. Lawful Basis for Processing
Under the DPDP Act, 2023, we process personal data on these bases:
- Your consent — given when you submit a form, subscribe to the newsletter, or enrol. Consent is free, specific, informed and unambiguous, and you may withdraw it at any time;
- Performance of a contract — where processing is necessary to deliver the service you have engaged and paid for;
- Legitimate uses and legal obligation — where we must retain records for tax, accounting or statutory compliance, or to establish or defend a legal claim.
Withdrawing consent is as easy as giving it — email contact@webphiser.com. Withdrawal does not affect processing already carried out, and where the data is necessary to continue delivering a service you have paid for, withdrawal may mean we can no longer provide it.
5. Children & Minors
Our Tech Explorers program is designed for students aged 10 to 16, and other programs may include students under 18. We take this seriously and apply additional protections.
- Verifiable parental consent is mandatory. A parent or legal guardian must complete the enrolment and provide consent before we process any personal data belonging to a student under 18. We confirm this consent directly with the parent or guardian during the intro call and in writing at enrolment.
- The parent or guardian is our point of contact. Enrolment records, fee communication, progress updates and all account correspondence go to the parent or guardian, not the child.
- We do not direct advertising or marketing at minors. We do not send promotional email to a student under 18, and we do not use their data for behavioural tracking, profiling or advertising of any kind.
- We collect the minimum. For a minor we collect only the name, the parent's or guardian's contact details, the program, and learning progress. Nothing more.
- Parents have full control. A parent or guardian may request access to, correction of, or erasure of their child's data at any time by writing to contact@webphiser.com.
If we discover we have collected a minor's personal data without proper parental consent, we will delete it promptly. If you believe this has happened, please contact us immediately.
6. Payment Information
Payments are processed by RBI-authorised third-party payment gateways. When you pay, your card, UPI or bank details are submitted directly to that gateway over an encrypted connection.
We never see, receive or store your full card number, CVV, UPI PIN, net-banking password or any equivalent credential. What we retain is limited to what we need to reconcile and support the transaction:
- Transaction ID or payment reference number
- Amount, currency, date and payment status
- The payment method type used (for example "UPI" or "credit card")
- The last four digits of the instrument, where the gateway supplies it
- Billing name, billing address and GSTIN where a tax invoice is required
Your payment is additionally governed by the gateway's own privacy policy and terms. We retain invoices and transaction records for the period required under Indian tax law — see section 9.
7. Who We Share Data With
We share personal data only where necessary, and only with parties bound to protect it. We share with:
- Payment gateways — to process payments, refunds and chargebacks;
- Hosting and infrastructure providers — who host the website and store our data;
- Communication and video-conferencing tools — to deliver live sessions, share recordings and send transactional email;
- Instructors and contractors — strictly limited to the students and projects they are assigned to, and bound by confidentiality obligations;
- Accountants, auditors and legal advisers — where required for compliance or to establish or defend a legal claim;
- Government or law-enforcement authorities — where we are legally compelled by a valid order, notice or statutory requirement.
We require every service provider to process data only on our instructions, apply reasonable security safeguards, and not use the data for their own purposes.
If our business is ever transferred or restructured, personal data may transfer as part of that transaction. We would notify you beforehand, and the recipient would remain bound by this policy.
8. Cookies & Tracking
Our website uses a minimal set of cookies and loads web fonts from Google Fonts, which involves a request to Google's servers carrying your IP address.
The full breakdown of what is set, why, and how to disable it is in our dedicated Cookie Policy.
9. How Long We Keep Your Data
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires.
| Data | Retention period |
|---|---|
| Enquiry that did not convert | Up to 12 months from last contact, then deleted |
| Client and student records | Duration of the engagement, plus 3 years |
| Invoices, payment and tax records | 8 years, as required under Indian tax and accounting law |
| Newsletter subscription | Until you unsubscribe, then removed within 30 days |
| Session recordings | Up to 12 months after the batch ends, unless a longer access period was agreed |
| Server and security logs | Up to 12 months |
Once a retention period expires, data is securely deleted or irreversibly anonymised. Where a legal claim or investigation is active, we retain the relevant data until it concludes.
10. How We Protect Your Data
We apply reasonable security safeguards appropriate to the sensitivity of the data:
- HTTPS/TLS encryption for all traffic between your browser and our website;
- Access limited strictly to personnel who need it to do their job;
- Strong authentication and, where supported, multi-factor authentication on our accounts and tools;
- Reputable service providers with their own recognised security certifications;
- Payment data handled entirely by PCI-DSS compliant gateways, never by us;
- Confidentiality obligations binding every instructor and contractor;
- Periodic review of access rights and of the data we hold.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under the DPDP Act.
11. Your Rights
Under the DPDP Act, 2023, you have the right to:
- Access — obtain a summary of the personal data we hold about you and how we process it;
- Correction — have inaccurate or incomplete data corrected or completed;
- Erasure — have your data deleted where it is no longer needed and no legal obligation requires us to keep it;
- Withdraw consent — at any time, as easily as you gave it;
- Grievance redressal — a readily available means to raise a complaint with us, described in section 12;
- Nominate — appoint another individual to exercise your rights on your behalf in the event of your death or incapacity.
To exercise any of these, email contact@webphiser.com with the subject line "Data Request". We may ask you to verify your identity before acting, to make sure we are not disclosing your data to someone else. We respond within 30 days.
These rights are free to exercise. If a request is manifestly excessive or repetitive, we may explain why we cannot act on it in full.
12. Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made thereunder, the contact details of our Grievance Officer are:
- Name: Pankaj Jha
- Designation: Grievance Officer, Webphiser Software & Education Services
- Email: contact@webphiser.com
- Phone: +91 9205823124
- Address: House No 623, Bahadurgarh, Haryana 124507, India
- Hours: Monday to Saturday, 9:00 AM – 7:00 PM IST
We acknowledge every grievance within 48 hours and aim to resolve it within 30 days of receipt. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.
13. International Data Transfers
We are based in India and our data is primarily stored in India. Some of the service providers we rely on — hosting, email delivery and video conferencing — may store or process data on servers located outside India.
Where that happens, we take reasonable steps to ensure the provider offers a comparable standard of protection to that required under Indian law, through contractual commitments and by choosing providers with recognised security certifications. We do not transfer personal data to any territory restricted by the Government of India.
14. Third-Party Links
Our website may link to third-party websites, tools and platforms. Once you follow such a link, you are on a site we do not control and this policy no longer applies. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their policies before sharing anything.
15. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, our services or the law. The current version always sits on this page with its "Last updated" date at the top.
If we make a material change to how we use your personal data, we will notify you by email where we hold a valid address for you, and where required we will seek fresh consent. We encourage you to review this page periodically.
16. Contact Us
For any question about this policy or about how we handle your personal data:
- Entity: Webphiser Software & Education Services
- Email: contact@webphiser.com
- Phone: +91 9205823124
- Address: House No 123, Sector 6, Bahadurgarh, Haryana 124507, India
See our Contact Us page for full details.