Privacy Policy

PRIVACY POLICY

Qraft Query

projects.qraftquery.com

Last Updated: 20/06/2026

Drafting note: This document is a comprehensive starting template prepared with reference to India’s Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA), as applicable. It is not a substitute for review by a qualified data privacy lawyer in India (and New Zealand, given your Stripe NZ processing arrangement) before publication, particularly because India’s Digital Personal Data Protection Act, 2023 (DPDPA) rules were still being finalized as of this drafting and may impose additional obligations once notified.

1. Introduction

This Privacy Policy (“Policy”) describes how Qraft Query (“Qraft Query”, “we”, “us”, or “our”), a sole proprietorship registered and operating in India, collects, uses, discloses, and protects information obtained through our website projects.qraftquery.com and related learning platform (collectively, the “Platform”) in connection with our digital training tracks, job simulations, and internship certification programs (collectively, the “Services”).

This Policy is published in compliance with Section 43A of the Information Technology Act, 2000, and the SPDI Rules, which require body corporates handling sensitive personal data or information to maintain a published privacy policy. By accessing or using the Platform, you (“User”, “you”, “your”) acknowledge that you have read and understood this Policy and consent to the collection, use, and disclosure of your information as described herein.

If you do not agree with this Policy, please discontinue use of the Platform.

2. Who We Are

Qraft Query is currently operated as a sole proprietorship registered in India. Payment processing for international transactions is, on a temporary basis, routed through a secondary individual Stripe account held in New Zealand by the founder, who is currently resident in New Zealand. This arrangement exists during a transitional period while the business completes incorporation as a private limited company in India.

We disclose this structure transparently because it affects where and how your payment-related data is processed (see Section 7 – Cross-Border Data Transfers). We intend to update this Policy once the transition to a fully incorporated Indian entity and consolidated payment architecture is complete, and the entity name in this Policy will be updated accordingly at that time.

3. Information We Collect

We collect the following categories of information through our Platform, which is built on WordPress using the LearnDash Learning Management System (LMS) plugin:

3.1 Information You Provide Directly

  • Account Information: name, email address, username, password (stored in encrypted/hashed form), and contact number provided at registration.
  • Profile and Progress Data: course enrollment records, module/track completion status, quiz and assignment scores, points earned, badges, and certificate issuance records, as tracked by the LearnDash LMS.
  • Payment Information: billing name, billing address, email, and transaction metadata. We do not collect or store your full credit/debit card number, CVV, or card expiry date on our own servers — these are captured directly by our payment processors (Stripe and Cashfree) via secure, tokenized API integrations.
  • Communications: information you provide when contacting support, submitting grievances, or corresponding with us.
  • User-Generated Content: code submissions, dashboards (e.g., Power BI files), datasets you upload, and project deliverables submitted as part of simulation tracks.

3.2 Information Collected Automatically

  • Cookies and Similar Technologies: we use the LiteSpeed Cache plugin, which deploys functional browser cookies to verify live user login sessions and optimize content delivery speed. See Section 6 – Cookies for details.
  • Usage and Log Data: IP address, browser type, device identifiers, pages visited, time spent on modules, and similar technical/usage data collected automatically by our hosting and LMS infrastructure.

3.3 Sensitive Personal Data or Information (SPDI)

Under the SPDI Rules, certain data categories (such as passwords and financial information like payment details) are classified as “Sensitive Personal Data or Information.” We collect only the minimum SPDI necessary to operate the Platform (primarily account passwords and payment-related identifiers), and such data is processed using the security practices described in Section 8.

4. How We Use Your Information

We use the information collected for the following purposes:

  • To create and administer your user account and authenticate your login sessions.
  • To deliver course content, track your progress through Data Analytics and Engineering simulation tracks, and calculate completion metrics.
  • To verify course completion data and issue Internship Certificates upon successful completion of a track.
  • To process payments for paid tracks/courses via Stripe (international cards) and Cashfree (domestic Indian transactions).
  • To communicate with you regarding your account, course updates, certificates, support requests, and administrative notices.
  • To detect, investigate, and prevent fraud, cheating, manipulation of completion metrics, or other violations of our Terms & Conditions.
  • To improve, maintain, and secure the Platform, including diagnosing technical issues and optimizing site performance via caching infrastructure.
  • To comply with applicable legal obligations, including tax, accounting, and regulatory requirements in India.

5. Disclosure of Information to Third Parties

We do not sell your personal information. We disclose information only in the following circumstances:

  • Payment Processors: Stripe (New Zealand entity, for international card transactions) and Cashfree Payments (India, for domestic transactions) receive billing and transaction information necessary to process payments. Each processor maintains its own privacy policy and PCI-DSS compliance standards.
  • Hosting and Infrastructure Providers: our WordPress hosting provider and the LiteSpeed Cache plugin infrastructure process technical data necessary to deliver the Platform.
  • Service Providers: email delivery services, analytics tools, and similar vendors engaged to support Platform operations, bound by confidentiality and data protection obligations.
  • Legal and Regulatory Disclosures: where required by Indian law, court order, governmental request, or to protect our legal rights, the rights of users, or public safety.
  • Business Transfers: in connection with the planned incorporation of Qraft Query as a private limited company, or any future merger, acquisition, or sale of assets, your information may be transferred to the successor entity, subject to equivalent privacy protections.

6. Cookies and Tracking Technologies

Our Platform uses cookies set by the LiteSpeed Cache plugin to verify whether a user is logged in and to serve cached page content efficiently. These are primarily functional/strictly necessary cookies required for the Platform to operate correctly (e.g., maintaining your login session as you navigate between course pages).

We may also use cookies or similar technologies for analytics purposes to understand how users interact with course content. You can control or disable cookies through your browser settings; however, disabling strictly necessary cookies may prevent you from logging in or accessing course tracking features.

7. Cross-Border Data Transfers

Because Qraft Query currently processes international card payments through a Stripe account held in New Zealand, while operating principally from India, your payment-related data may be transmitted between, and stored on, systems located in India and New Zealand during the checkout process.

We take the following measures in connection with such cross-border transfers:

  • Payment data is transmitted via encrypted, tokenized connections; we do not transmit or store raw card numbers ourselves.
  • Stripe and Cashfree are established global/regional payment processors that maintain their own regulatory compliance frameworks (including PCI-DSS) in their respective jurisdictions.
  • We limit the data shared with payment processors to what is reasonably necessary to complete and verify transactions.

By using the Platform and submitting payment information, you consent to this cross-border processing arrangement. We intend to consolidate our payment infrastructure under a single incorporated Indian entity in the future, which will reduce the scope of cross-border transfers, and we will update this Policy accordingly.

8. Data Security

In accordance with Section 43A of the IT Act and Rule 8 of the SPDI Rules, we implement reasonable security practices and procedures appropriate to the nature of the information we hold, including:

  • Encrypted password storage (hashed, not stored in plain text).
  • Use of tokenized payment processing so that raw card data never transits or rests on our own servers.
  • Restricted administrative access to the WordPress backend and LMS data.
  • Regular software and plugin updates to address known security vulnerabilities.

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security, and you provide information at your own risk.

9. Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal and tax obligations under Indian law, resolve disputes, enforce our agreements, and maintain accurate records of certificate issuance for verification purposes. Course completion records and certificate data may be retained indefinitely to support future certificate verification requests, unless you request deletion in accordance with Section 11.

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

10.1 Users in India

  • The right to review, correct, and update personal information you have provided to us.
  • The right to withdraw your consent to the processing of your information, subject to applicable terms (note: withdrawal of consent may limit or prevent access to the Platform).

10.2 Users in the European Economic Area / UK (GDPR)

If you are located in the EEA or UK, you have the right to: access your personal data; rectify inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; request data portability; and lodge a complaint with your local supervisory authority. Our legal bases for processing include your consent, performance of our contract with you (course delivery), and our legitimate interests in operating and securing the Platform.

10.3 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to: know what personal information we collect, use, and disclose; request deletion of your personal information; correct inaccurate personal information; and opt out of the sale or sharing of personal information (note: we do not sell or share personal information as defined under the CCPA/CPRA). We will not discriminate against you for exercising these rights.

10.4 Exercising Your Rights

To exercise any of the above rights, please submit a request to [Insert Contact Email]. We may need to verify your identity before processing your request and may take up to [Insert Number] days to respond, or such period as required under applicable law.

11. Children’s Privacy

Our Services are intended for users who are at least 18 years of age, or who have reached the age of majority in their jurisdiction. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a minor without appropriate consent, we will take steps to delete such information.

12. Third-Party Links and Services

Our Platform may contain links to third-party websites or services (including payment gateways) that are not operated by us. We are not responsible for the privacy practices of such third parties, and we encourage you to review their respective privacy policies.

13. Grievance Officer (India – IT Act, 2000)

In accordance with the Information Technology Act, 2000, the SPDI Rules, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer to address any discrepancies, complaints, or grievances relating to the processing of your personal information or use of the Platform.

Grievance Officer Details:

  • Name: Ajil Lal
  • Designation: Founder
  • Email: admin@qraftquery.com
  • Address: Qraft Query, Ruha Building, Kallikkad Mylakkara PO, 695572
  • Response Timeline: We will acknowledge complaints within 24 hours and seek to resolve them within 15 days of receipt, as required under applicable Indian law.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal structure (including our planned incorporation as a private limited company), or applicable law. We will post the revised Policy on this page with an updated “Last Updated” date. Material changes may be communicated to you via email or a notice on the Platform. Your continued use of the Platform after such changes constitutes acceptance of the revised Policy.