Legal

Privacy Policy

This Privacy Policy explains how QubiNest ("we", "our", or "us") collects, uses, discloses, and protects information when you use our websites, applications, and related services (collectively, the "Service"). By using the Service, you agree to this Policy.

Effective date

If you use the Service on behalf of an organization, that organization may control certain workspace data and user accounts. For privacy requests about organization-controlled data, you may need to contact your administrator. For questions directed to us, use hello@qubinest.com.

1. Information we collect

We collect information that you provide directly, that is generated when you use the Service, and that we receive from third parties as described below.

a. Account and profile information

Name, email address, phone number (if provided), job title or role, organization name, and similar identifiers you or your administrator provide when creating or managing an account.

b. Usage and technical data

Login timestamps, IP address, device and browser type, approximate location derived from IP, pages or features accessed, diagnostic logs, and performance metrics used to secure and improve the Service.

c. Content and collaboration data

Courses, lessons, assessments, files, messages, comments, and other materials uploaded or generated through the Service, including metadata such as authorship and timestamps.

d. Payment information

When you purchase a paid plan, payment details are collected and processed by third-party payment providers (for example, Razorpay). We do not store full card numbers on our servers. We may receive limited billing metadata (such as transaction status, last four digits where applicable, and subscription identifiers) to administer your account.

e. Communications

Information you provide when contacting support, responding to surveys, or subscribing to product updates.

2. How we use information

We use information to:

  • Provide, operate, maintain, and improve the Service (including authentication, authorization, and multi-tenant isolation).
  • Deliver course content, analytics, notifications, and in-product features you or your organization enable.
  • Detect, prevent, and respond to fraud, abuse, security incidents, and technical issues.
  • Process payments, invoices, taxes (where applicable), and subscription lifecycle events.
  • Communicate about the Service, including transactional messages, service announcements, and (where permitted) marketing.
  • Comply with legal obligations and enforce our terms and policies.
  • Create aggregated or de-identified analytics that do not identify individuals.

Where GDPR or similar laws apply, we rely on appropriate legal bases such as performance of a contract, legitimate interests (for example, securing the Service and understanding product usage), consent where required, and legal obligation.

3. Data storage and security

We use cloud infrastructure and object storage (which may include providers such as Cloudflare R2 or comparable systems) to host data. Access is restricted based on role, least-privilege principles, and tenant isolation controls.

We implement administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

If we become aware of a breach that materially affects personal data, we will notify affected customers and regulators as required by applicable law.

4. Data sharing

We do not sell your personal information. We may share information:

  • With subprocessors that help us host, store, analyze, deliver email, process payments, or support customers, subject to confidentiality and security obligations.
  • With your organization and its authorized administrators, consistent with workspace settings and roles.
  • With professional advisors (for example, lawyers or auditors) where necessary.
  • When required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of us, our users, or others.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards and notice where required.

5. International transfers

Data may be processed in India and in other countries where our subprocessors operate. Where required by applicable law, we implement appropriate safeguards for international transfers (such as standard contractual clauses or equivalent mechanisms).

6. Multi-tenant isolation

The Service is designed so that each organization's data is logically separated. We enforce access controls intended to prevent cross-tenant access. Administrators are responsible for configuring roles, permissions, and invitations within their organization.

7. Data retention

We retain information for as long as necessary to provide the Service, fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce agreements.

When you delete content or close an account, we delete or anonymize data within a reasonable period, subject to backup retention, regulatory requirements, and legitimate business needs (for example, billing records). Deleted data may remain in encrypted backups for a limited period before being overwritten.

8. Your rights and choices

Depending on your location and role, you may have rights to access, correct, update, export, or delete certain personal information, or to object to or restrict certain processing. Organization administrators may control some profile fields for workspace members.

To exercise rights, contact us at the email below. We may need to verify your identity. If you are an end user of an organization's workspace, we may refer certain requests to that organization where they act as controller.

You may opt out of marketing emails by using the unsubscribe link in those messages. Transactional and service-related messages may continue where permitted.

9. Cookies and similar technologies

We and our partners may use cookies, local storage, and similar technologies to keep you signed in, remember preferences, measure performance, and understand how the Service is used. You can control cookies through your browser settings; disabling cookies may affect functionality.

10. Automated decision-making

We do not use personal information for automated decision-making that produces legal or similarly significant effects solely based on automated processing. Certain security systems may use automated signals to detect abuse or fraud.

11. Children's privacy

The Service is intended for organizations and adult users. It is not directed to children under 13 (or the minimum age required in your jurisdiction) without appropriate parental or institutional authorization and supervision. If you believe we have collected information from a child without proper authority, contact us and we will take appropriate steps to delete it.

12. Changes to this Policy

We may update this Policy from time to time. We will post the updated Policy on this page and revise the effective date. Where changes are material, we will provide additional notice as required by law. Continued use of the Service after the effective date constitutes acceptance of the updated Policy, except where your consent is required.

13. Contact

For privacy questions or requests, contact hello@qubinest.com. You may also review our Terms of Use.