Privacy Policy FLN
Privacy Policy
Introduction and Scope
EKSAQ India Private Limited (CIN: U85302TS2024PTC181617), operating under the brand “EKSAQ”, is the creator, owner, and publisher of the FLN (the “App”). The App is an educational technology platform designed to enhance learning and development through digital means.
This Privacy Policy (“Policy”) applies to:
- All users of the FLN app, including students, parents, guardians, and educators
- Visitors to our website at eksaq.in
- Any person who contacts us or provides personal information in any form
This Policy is incorporated into and forms part of the Terms of Use of the App and must be read in conjunction with those Terms.
This Privacy Policy governs the collection, processing, storage, and sharing of personal data by EKSAQ India Private Limited (“EKSAQ,” “we,” “us,” or “the Company”) through EKSAQ’s mobile application FLN and related digital platforms. By using the App, you consent to the practices described herein. Please read this document carefully before using our Services.
Data We Collect
Name, email, phone, device IDs & app activity. No financial or location data.
We Never Sell Data
Your personal data is never sold to third parties under any circumstances.
Children’s Safety
Strict parental consent required for users under 18. Children’s data never used for advertising.
Table of Contents
- Introduction and Scope
- Key Definitions
- Categories of Personal Data Collected
- Methods of Data Collection
- Legal Basis for Processing
- How We Use Your Personal Data
- Sharing of Personal Data
- Cookies and Tracking Technologies
- Data Security
- Data Retention
- Children’s Privacy and Parental Controls
- Your Rights as a Data Principal
- Data Breach Notification
- Cross-Border Data Transfers
- Changes to This Privacy Policy
- Governing Law and Dispute Resolution
- Contact & Grievance Officer
Key Definitions
| Term | Definition |
|---|---|
| Personal Information | Any data that identifies or can identify an individual, including Sensitive Personal Data or Information (SPDI) as defined under the SPDI Rules. |
| SPDI | Passwords, financial information, health data, biometric data, sexual orientation, and other categories specified under Rule 3 of the SPDI Rules. |
| Services | All educational content, courses, study materials, tutorials, assessments, and features made available through the App. |
| User | Any person who downloads, accesses, or uses the App, including registered and unregistered users. |
| Child / Minor | Any person under the age of 18 years, or such other age as defined under applicable law. |
| Data Fiduciary | EKSAQ India Pvt Ltd, in its capacity as the entity that determines the purpose and means of processing personal data. |
| Data Principal | The individual to whom personal data relates. |
Categories of Personal Data Collected
We collect the following categories of personal data in the course of providing our Services. All data is transmitted using encrypted connections. We do not collect data in ways not described in this Policy.
3.1 Personal Information
Core identity and contact details collected during account registration: name, email address, username and password, phone number, and mailing address. Gender and profile photograph may also be collected to personalise your experience.
3.2 Media and Files
Where users choose to upload content as part of their educational activities, we may collect photos, videos, audio recordings, and other documents. All such media uploads are entirely voluntary and user-initiated.
3.3 App Activity Data
Data about how you interact with the App, including in-app search history and content you engage with. User-generated content such as notes, responses, or submissions may also be collected.
3.4 Health and Fitness Information
Where relevant to particular educational programmes, we may collect health or fitness-related information that you voluntarily provide. This is optional and used only in direct support of the specific programme.
3.5 Device and Technical Identifiers
Device identifiers and similar technical information to identify the device on which you are using the App, necessary for platform security, account management, and fraud prevention.
3.6 Automatically Collected Data
When you access the App, our servers automatically record: IP address, browser type, device configuration, date and time of requests, pages viewed, session duration, cookie identifiers, and internet connection information.
3.7 Data We Do NOT Collect
Methods of Data Collection
4.1 Information You Provide Directly
- Account registration forms (name, email, phone number, password)
- Profile setup and customisation
- Contact forms, chat sessions, and customer support interactions
- Surveys, feedback forms, and promotional campaigns
- Content uploaded by users (photos, videos, documents, assignments)
- Payment forms where applicable (processed by secure third-party payment gateways)
4.2 Information Collected Automatically
- Log files generated by your interactions with the App
- Cookies, clear GIFs (web beacons), and flash cookies
- Device identifiers and session tracking technologies
- Analytics SDKs embedded in the App
4.3 Information from Third Parties
- Authentication providers (e.g., SIM binding or service subscription)
- Educational institutions and employers who provide access credentials
- Publicly available sources for verification purposes
Legal Basis for Processing
We process your personal data only when we have a valid legal basis to do so.
5.1 Consent
Where you have given clear, informed, and voluntary consent to process your data for a specific purpose β for example, receiving marketing communications or processing sensitive personal data you have chosen to provide. You may withdraw consent at any time.
5.2 Performance of Contract
Processing required to deliver the Services you have requested, such as creating and maintaining your account and providing access to course content.
5.3 Legal Obligation
Where we are required by applicable Indian law or regulation to collect, retain, or disclose certain personal data, including obligations under tax law, anti-fraud regulations, the IT Act, and the DPDPA.
5.4 Legitimate Interests
Where processing is necessary for our legitimate business interests β improving and securing the App, preventing misuse, and conducting internal analytics β provided those interests are not overridden by your fundamental rights and freedoms.
5.5 Protection of Vital Interests
In rare circumstances, where processing is necessary to protect the vital interests of you or another person, for instance in an emergency involving health or safety.
How We Use Your Personal Data
6.1 Provision and Improvement of Services
- Creating and managing your user account
- Delivering educational content, courses, classes, and study materials
- Personalising your learning experience based on your interests and progress
- Facilitating teacher-student interactions and educational feedback
- Processing registrations for courses, events, and assessments
- Analysing usage patterns to improve App features and content quality
6.2 Communication
- Sending service-related communications (account confirmations, password resets, billing)
- Push notifications and in-app alerts regarding new content or features
- Email, SMS, WhatsApp communications about new courses, promotions, and offers (with consent)
- Responding to your support requests and enquiries
6.3 Safety, Security, and Fraud Prevention
- Verifying user identity and preventing unauthorised access
- Detecting, investigating, and preventing fraudulent activity and abuse
- Complying with legal and regulatory obligations
- Enforcing our Terms of Use and other policies
6.4 Analytics and Research
- Understanding how users interact with the App to improve user experience
- Conducting internal research and analysis on learning outcomes
- Measuring the effectiveness of our educational content
Sharing of Personal Data
7.1 Service Providers and Processors
Trusted third-party service providers who process data on our behalf under strict data processing agreements β such as cloud hosting providers and payment gateway operators. All processors are contractually required to process data only as instructed by us.
7.2 Group Companies and Affiliates
We may share data within the EKSAQ group of companies for the purposes of providing and improving our Services.
7.3 Legal Requirements
We may disclose personal data to government authorities, regulators, courts, or law enforcement agencies where required by law, court order, or regulatory authority. Only the minimum information required to comply will be disclosed.
7.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the acquiring entity, subject to equivalent privacy protections. You will be notified as required by law.
7.5 Fraud Prevention and Credit Risk
We may exchange information with third parties for fraud protection and credit risk reduction purposes, where permitted by law.
7.6 Third-Party Links
The App may contain links to third-party websites and services. EKSAQ is not responsible for the privacy practices of such third parties. We encourage you to review their privacy policies.
Cookies and Tracking Technologies
We use a range of technologies to collect information about your use of the App:
- Session cookies β temporary, expire when you close the App; used to maintain your session during a single visit.
- Persistent cookies β remain on your device for a set period; used to remember your preferences and keep you logged in across sessions.
- Analytics cookies β understand how users navigate and engage with the App; data used in aggregate to improve the platform.
- Clear GIFs (web beacons) β small image files embedded in content or emails to track interactions and measure engagement.
- Device identifiers β recognise your device across sessions to support security and personalisation.
You may manage certain cookie preferences through your device or browser settings. Disabling some cookies may affect the availability or functionality of certain features within the App.
Data Security
We implement comprehensive technical, administrative, and physical security measures to protect your personal data.
9.1 Technical Safeguards
- Standard SSL/TLS encryption for all data transmitted between your device and our servers
- Passwords stored using bcrypt hashing (one-way encryption) β plaintext passwords are never stored
- Firewalls and intrusion detection systems to protect our network infrastructure
- Encrypted data storage on secure servers located in Hyderabad, India
- Regular security audits and vulnerability assessments
- Access controls and role-based permissions limiting staff access to personal data
9.2 Administrative Safeguards
- Staff training on data handling, privacy obligations, and security procedures
- Data processing agreements with all third-party processors
- Internal data governance policies and procedures
- Regular review of security practices and incident response plans
9.3 Physical Safeguards
- Physical access controls to our data centres and office premises
- Secure disposal of physical records containing personal data
Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. Specific retention periods are determined by:
- The nature and purpose of the data collected
- Legal and regulatory obligations (e.g., tax records, legal proceedings)
- The duration of your account and active use of our Services
- Our legitimate business interests in maintaining accurate records
Upon expiry of the applicable retention period, we will securely delete or anonymise your personal data. Where you request deletion of your data, we will fulfil the request subject to any overriding legal obligations.
Children’s Privacy and Parental Controls
EKSAQ is an educational platform that may be used by children. We take the privacy and safety of minors extremely seriously. Our practices comply with the POCSO Act 2012, IT Rules 2023, DPDPA, and the Google Play Families Policy.
11.1 Age Restrictions and Parental Consent
- We do not knowingly collect personal information from children under the age of 13 without verifiable parental or guardian consent.
- For children aged 13 to 17, parental or guardian consent is required prior to account registration.
- Consent may be verified through credit card verification, a signed consent form by email, or a direct call with our customer service team.
11.2 What We Collect from Children
Information collected from children includes: name, age, educational progress data, and content submitted in the course of using the App. This is used solely to provide and improve the educational experience and to provide progress feedback to parents or guardians.
11.3 Parental Rights and Controls
- Parents and guardians have full access to their child’s account settings and can review, manage, and delete their child’s personal data at any time.
- Parents can monitor their child’s educational progress, screen time, and interactions within the App.
- Tools are provided to set usage limits and receive regular activity reports.
- Parents may withdraw consent at any time by contacting our Grievance Officer.
11.4 Safeguards for Children’s Data
- Children’s personal data is never shared with third parties for marketing or advertising purposes.
- Data shared with service providers is subject to strict data protection obligations.
- We employ robust encryption, secure servers, and regular security audits to protect children’s data.
- Staff members who handle children’s data receive specialist training in child data protection compliance.
Your Rights as a Data Principal
Subject to applicable law, including the DPDPA and SPDI Rules, you have the following rights in relation to your personal data:
Right of Access
Request a summary of the personal data we hold about you and how it is being processed.
Right to Correction
Request that inaccurate or incomplete personal data be corrected or updated.
Right to Erasure
Request deletion of your personal data, subject to overriding legal obligations. Note: this will result in termination of your account.
Right to Grievance Redressal
Raise a grievance with our Grievance Officer and receive a response within a reasonable timeframe.
Right to Withdraw Consent
Withdraw consent to the processing of your personal data at any time. This may result in inability to access certain Services.
Right to Nominate
Under the DPDPA, nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
Right to Complain
File a complaint with the Data Protection Board of India if you believe your rights have been infringed.
Data Breach Notification
In the event of a personal data breach, we will:
- Initiate an internal investigation immediately upon becoming aware of the breach.
- Report to the relevant supervisory authority within 72 hours where the breach is likely to result in risk to individuals’ rights and freedoms.
- Notify affected individuals directly if the breach is likely to result in high risk to their rights and freedoms.
- Issue a public notice without undue delay where the severity warrants it.
- Maintain a record of all data breaches, including facts, effects, and remedial action taken.
If you become aware of a potential security issue, please report it immediately to support@eksaq.in.
Cross-Border Data Transfers
Your personal data is stored and processed on servers located in Hyderabad, India. If you access the App from outside India, your data will be transferred to and processed in India. By using the App and accepting this Policy, you consent to such transfer.
Any transfer of personal data outside India will be carried out in compliance with the DPDPA and applicable rules, including the requirement that data be transferred only to countries notified by the Central Government as having adequate data protection standards.
Changes to This Privacy Policy
We review and update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The date of the most recent revision is indicated at the top of this document.
- Registered users will be notified of material changes by email or in-app notification prior to changes taking effect.
- Visitors and non-registered users are advised to review this Policy regularly. Continued use of the App following notification constitutes acceptance of the revised Policy.
- Where changes affect children’s data, parents and guardians will be specifically notified and re-consent will be obtained where required.
Governing Law and Dispute Resolution
This Policy and any dispute arising from it shall be governed by and construed in accordance with the laws of India.
- The parties shall first attempt to resolve any dispute amicably through mutual negotiation.
- If unresolved, the dispute shall be referred to a sole arbitrator under the Arbitration and Conciliation Act, 1996.
- The language of arbitration shall be English. The seat and venue shall be Hyderabad, India.
- The decision of the arbitrator shall be final and binding on both parties.
- Subject to the above, this Policy shall be subject to the exclusive jurisdiction of competent courts in Hyderabad, India.
Contact Information and Grievance Officer
In accordance with the IT Act and SPDI Rules, EKSAQ has appointed a Grievance Officer to address queries, concerns, and complaints relating to this Privacy Policy. The Grievance Officer will address your grievance within 30 days of receipt.
Grievance Officer Contact Details
Appendix A: Google Play Data Safety Summary
The following table summarises our Google Play Data Safety form submission. “Collected” means data is transmitted off the device; “Not Collected” means data remains on the device only.
| Data Category | Status | Notes |
|---|---|---|
| Personal Info (Name, Email, Phone, Address, User IDs, Gender) | Collected | Core identity data required for account registration and management. Encrypted in transit. |
| Photos & Videos | Optional | User-initiated uploads only for profile pictures or educational content submissions. |
| Audio Files (Voice, Music, Other) | Optional | User-initiated uploads only for educational assignments or learning exercises. |
| Files & Documents | Optional | User-initiated uploads only for educational purposes. |
| App Activity (Interactions, Search History, User Content) | Collected | Required for App functionality, personalisation, and analytics. Not shared with third parties. |
| Health & Fitness Info | Optional | Only where voluntarily provided by the user. |
| Device / Other IDs | Collected | Required for security, account management, and personalisation. |
| Financial Info, Location, Messages, Contacts, Calendar, Diagnostics | Not Collected | EKSAQ does not collect these data types through the App. |
| Data Encrypted in Transit | Yes | All user data is encrypted using SSL/TLS during transmission. |
| Data Deletion Request | Via Support | Users may contact the Grievance Officer to request data deletion. A formal in-app deletion tool is planned. |