ATC Quest ("Quest", "the Platform", "we", "us", or "our") is an enterprise learning platform operated by Aarna Tech Consultants Private Limited. This Privacy Policy explains how we collect, use, store, disclose, and protect personal data across our web, mobile, and admin interfaces, including the Learner Portal, the Client Administrator Portal, and the System Administrator Portal (collectively, the "Services"). By accessing or using the Services, you acknowledge that you have read and understood this Policy.
Table of Contents
- 1Who We Are
- 2Scope and Applicability
- 3Data We Collect
- 4How We Collect Data
- 5How We Use Your Data
- 6Legal Bases for Processing
- 7Cookies and Similar Technologies
- 8How We Share Your Data
- 9Data Security and Safeguards
- 10Data Retention
- 11International Data Transfers
- 12Your Rights
- 13Children's Privacy
- 14Third-Party Services and Integrations
- 15Data Breach Notification
- 16DPDP Act Compliance and Grievance Redressal
- 17Changes to this Privacy Policy
- 18Contact Us
Who We Are
This Privacy Policy applies to ATC Quest (the "Platform"), operated by Aarna Tech Consultants Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at 72 G Road, Kadma, Jamshedpur, Jharkhand 831005, India (CIN: U72900JH2021PTC017144). References to "we", "us", or "our" in this Policy refer to Aarna Tech Consultants Private Limited and its authorized affiliates.
Quest is primarily an enterprise (B2B) learning platform. Organizations ("Client Organizations") purchase licenses to enrol and train their employees, contractors, and associated learners on the Platform. In that arrangement, the Client Organization acts as the Data Fiduciary for its learners, and we act as Data Processor, processing learner data on the Client Organization's instructions in accordance with our service agreement. Where Quest is accessed directly by an individual without an enrolling organization, we act as the Data Fiduciary for that individual.
For any data protection inquiry, you may contact our Grievance Officer at [email protected] or +91 8986860088.
Scope and Applicability
This Privacy Policy applies to all users of Quest, including:
- Learners โ individuals enrolled in courses through their employer's license or directly on the Platform.
- Client Administrators and Single Points of Contact (SPOCs) โ authorized representatives of Client Organizations who manage learners, groups, licenses, reports, and reminders.
- System Administrators โ internal Quest operators with elevated privileges over the Admin Panel.
- Committee members, reviewers, and instructors associated with specific courses, feedback forms, or certification workflows.
- Visitors to our public pages, login screens, support pages, and help resources.
This Policy does not cover third-party websites or services that may be linked from the Platform. Please review those third parties' own privacy policies before sharing personal data with them.
Data We Collect
We collect data that you provide directly, data generated as you interact with the Services, and data received from third parties such as identity providers and Client Organizations.
| Category | What it includes |
|---|---|
| Account & Authentication | Full name, email address, password (bcrypt hash only), phone number, user type, unique user ID, Azure AD identifiers (SSO), MFA secrets, JWT session tokens. |
| Profile Data | Profile photo, designation, department, city, country, preferred language, date of birth (optional), company/organization. |
| Client Organization | Organization name, logo, industry, registered address, billing contact, GSTIN, group structure, SPOCs, license counts, activation/expiry dates. |
| Learning Activity | Courses enrolled/completed, HLS video watch timestamps (144pโ4K), quiz responses, scores, retakes, feedback submissions, certificates, badges, activity logs. |
| Certificate & Credential | Certificate templates, serial numbers, issue dates, expiry, renewal history, verification metadata. |
| Support & Ticketing | Ticket content, attachments, related order/course IDs, conversation history, status change audit trail. |
| Device & System | IP address, browser type/version, OS, device type, screen resolution, approximate location (from IP), referrer URL, login/logout events. |
| Usage & Interaction | Pages visited, features used, navigation paths, search queries, video playback events, idle-session events, error/diagnostic logs. |
| Audit & Security | Admin action logs (create/update/delete), permission changes, login attempts, rate-limiting events, sensitive configuration changes. |
| Communication | Emails sent (OTPs, confirmations, reminders, certificates, license notices), delivery status, DND preferences. |
| Payment & License | Order IDs, invoice references, billing address, GSTIN, license purchase amount, license count, approval status. We do not store card numbers, CVV, UPI PINs, or net banking credentials. |
How We Collect Data
We collect personal data through the following channels:
- Direct input โ when you register, log in, complete your profile, take a course, submit a quiz, file a support ticket, or request a report.
- Client Organization upload โ when your employer uploads learner data in bulk (CSV/Excel) to assign courses, groups, or licenses.
- Single Sign-On (SSO) โ when you sign in via Microsoft Azure AD, we receive name, email, tenant ID, and object ID from the identity provider.
- Automatic collection โ our servers log device, usage, system, and session data through server logs, cookies, and local/session storage.
- Third-party integrations โ where enabled, we may receive data from Zoho CRM, Google APIs, and our email/storage providers.
- Offline interactions โ correspondence, onboarding forms, MSAs, and license purchase orders submitted to our teams.
How We Use Your Data
5.1 Service delivery
- Authenticate you and maintain your session using JWT tokens, Azure AD, and optional MFA.
- Deliver course content including adaptive-bitrate HLS video streams, quizzes, assessments, and downloadable resources.
- Track progress, evaluate quiz responses, issue certificates and badges, and power the learner dashboard.
- Enforce role-based access control across Admin, Client Admin, SPOC, and Learner roles.
5.2 Client Organization reporting
- Generate progress, completion, engagement, and compliance reports for Client Administrators and SPOCs.
- Provide dashboards, master reports, and entity-wise reports in the Admin Panel.
5.3 Communication
- Send transactional emails (account creation, password reset, OTP, enrolment confirmations, certificate issuance, reminders). You cannot opt out of these.
- Send optional notifications and learning nudges configured by your organization; manage DND preferences in account settings.
- Respond to support tickets and facilitate conversations between learners, SPOCs, committees, and support.
5.4 Platform security and integrity
- Detect and prevent fraud, account takeover, brute-force attempts using rate limiting, encrypted payloads, and audit logging.
- Automatically log out idle sessions to protect accounts on shared devices.
- Investigate suspicious activity, policy violations, and incidents.
5.5 Service improvement
- Analyse aggregated and de-identified usage patterns to improve course delivery and UX.
- Debug issues, monitor uptime and latency, and roll out new features.
5.6 Legal and compliance
- Comply with applicable laws including the DPDP Act 2023, IT Act 2000, tax and accounting laws, and respond to lawful requests.
- Enforce our Terms of Service, Refund & Cancellation Policy, and Enterprise Agreements.
5.7 What we do not do
- โWe do not sell, rent, or trade your personal data.
- โWe do not use learner quiz responses, course content, or support tickets to train third-party AI models.
- โWe do not run third-party advertising trackers on the learner or admin portals.
Legal Bases for Processing
Depending on the context, we process personal data on one or more of the following legal bases under the DPDP Act:
- Performance of contract โ to provide the Services you or your Client Organization have signed up for.
- Consent โ where you have explicitly agreed to a specific processing activity. You may withdraw consent at any time.
- Legitimate interests โ for platform security, fraud prevention, aggregated analytics, and service improvement.
- Legal obligation โ for tax, audit, record-keeping, and regulatory requirements.
- Public interest or vital interest โ in exceptional circumstances, such as legally binding requests or protecting safety.
Cookies and Similar Technologies
We use cookies, local storage, session storage, and server-side session identifiers strictly for functionality, security, and performance โ not for advertising.
| Type | Purpose |
|---|---|
| Strictly necessary | Authenticated sessions, JWT tokens, CSRF protection, rate limits. Cannot be disabled. |
| Functional | Language, theme, last-watched video position, HLS resume points. |
| Performance | Page performance, load times, error rates for reliability improvement. |
| Security & audit | Login attempts, idle-logout triggers, admin action audit logs. |
You can control cookies through your browser settings. Blocking strictly-necessary cookies will prevent you from signing in.
How We Share Your Data
We share limited personal data with the following recipients, on a need-to-know basis with contractual safeguards:
- Client Organizations and their authorized Administrators/SPOCs โ for learner progress and compliance reports.
- Cloud infrastructure providers โ including AWS S3 for file/media storage, hosting, and database providers.
- Identity and SSO providers โ Microsoft Azure AD, Google identity services, and configured SSO tenants.
- Operational service providers โ email delivery, SMS/OTP, Zoho CRM, analytics/monitoring, and job queue infrastructure.
- Payment and invoicing partners โ card numbers, UPI PINs, and credentials are handled directly by these partners.
- Professional advisors โ legal, accounting, and audit firms, bound by confidentiality.
- Government or regulatory authorities โ where disclosure is required by law.
- A successor entity โ in the event of a merger, acquisition, or reorganization, with notice as required by law.
Data Security and Safeguards
We implement technical and organizational measures to protect personal data:
Despite our best efforts, no method of electronic transmission or storage is completely secure. You are responsible for keeping your credentials confidential and promptly notifying us at [email protected] if you suspect unauthorized access.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Learner account and activity data โ retained for the duration of the license/enrolment, and thereafter as required by agreement or law.
- Issued certificates and badges โ retained for ongoing verification, even after the license term ends, unless revoked.
- Audit logs and security records โ retained per regulatory, forensic, and incident-response requirements.
- Support ticket content โ retained while necessary for support and a reasonable period thereafter.
- Financial records โ invoices, GST credit notes, license purchases retained per Indian tax and accounting laws.
Upon termination of a license or at your lawful erasure request, we delete or anonymize personal data per our deletion workflows, subject to mandatory retention obligations.
International Data Transfers
Quest is primarily operated and hosted in India. Certain infrastructure providers, SSO providers (Microsoft, Google), and support tools may process data outside India. Where such transfers occur, we rely on contractual safeguards, service-provider privacy commitments, and applicable cross-border transfer rules under the DPDP Act.
Your Rights
Under the DPDP Act, 2023, you have the following rights:
- Right to access โ request a summary of personal data we process about you.
- Right to correction and erasure โ request correction of inaccurate data, and erasure where no longer necessary.
- Right to withdraw consent โ withdraw at any time without affecting prior lawful processing.
- Right to grievance redressal โ raise a complaint with our Grievance Officer (Section 16).
- Right to nominate โ nominate another individual to exercise your rights in the event of death or incapacity.
If enrolled through a Client Organization, requests may need to go through your Client Administrator/SPOC. To exercise your rights, contact [email protected].
Children's Privacy
Quest is intended for individuals aged 18 years or older, or minors under the supervision and consent of a parent, lawful guardian, or authorized Client Organization. We do not knowingly collect personal data from children in violation of applicable law. Where we become aware of such collection without verifiable consent, we will promptly delete it.
Third-Party Services and Integrations
Quest integrates with select third-party services, each operating under its own privacy policy:
- Microsoft Azure Active Directory and Microsoft Graph APIs โ for SSO and identity federation.
- Google APIs โ where enabled by your organization for sign-in, calendar, or drive integrations.
- Amazon Web Services โ for object storage (S3), file uploads, and certificate asset hosting.
- Zoho CRM โ for managing license sales, onboarding, and customer records.
- Email delivery and OTP providers โ configured through our back-end mailer and messaging services.
We do not control and are not responsible for the privacy practices of these third parties.
Data Breach Notification
In the event of a personal data breach likely to result in risk to your rights and interests, we will notify the Data Protection Board of India, the affected Client Organization, and affected individuals as required by the DPDP Act. Notifications will contain the nature of the breach, categories of data involved, likely consequences, and measures taken to address and mitigate the breach.
DPDP Act Compliance and Grievance Redressal
We process personal data in accordance with the Digital Personal Data Protection Act, 2023. If you have a grievance, contact our Grievance Officer:
Grievance Officer
Aarna Tech Consultants Private Limited
72 G Road, Kadma, Jamshedpur, Jharkhand 831005, India
Email: [email protected]
Phone: +91 8986860088
Business hours: Monday to Friday, 10:00 AM to 6:00 PM IST
We will acknowledge your grievance within a reasonable period and seek to resolve it in accordance with applicable law. If unsatisfied, you may approach the Data Protection Board of India.
Changes to this Privacy Policy
We may revise this Privacy Policy from time to time. When we make material changes, we will post the updated Policy with a revised "Last updated" date and, where appropriate, notify you by email or in-Platform notice. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Privacy & Data Protection Team
ATC Quest (Aarna Tech Consultants Private Limited)
By accessing or using ATC Quest, you acknowledge that you have read and understood this Privacy Policy.