TAL Corp Sanctum

Privacy Policy

Last updated: 2026-04-16

1. Who we are

TAL Corp ("we", "us") operates the SANCTUM training platform at lab.texasagilabs.com. This policy explains how we collect and use your personal data.

2. What data we collect

  • Account data: name, email address, hashed password
  • Training data: module enrollment, stage progression (T1-T7), MCQ attempts, capstone submissions, grades, XP, badges, streak
  • Payment data: processed by Stripe (cards) and Razorpay (India) — we never store card numbers. We store provider-issued payment IDs and amounts for audit purposes.
  • Usage data: pages visited, clicks, video watch time (only with analytics consent)
  • Technical data: IP address, browser type, device type (for fraud detection and logs)

3. Legal basis for processing (GDPR Art. 6)

  • Contract performance: to deliver training you paid for
  • Legitimate interest: fraud prevention, service improvement, security logs
  • Consent: analytics cookies, marketing emails (opt-in only)
  • Legal obligation: tax records, audit logs

4. Your rights

Under GDPR, CCPA, and India DPDP, you have the right to:

  • Access: download all data we hold about you at /account/export
  • Delete: request account deletion at /account/delete (processed within 30 days)
  • Portability: receive your data in machine-readable JSON format
  • Rectification: update incorrect data via your account settings
  • Object: withdraw analytics consent any time via the cookie banner
  • Complain: lodge a complaint with your national data protection authority

5. Data retention

  • Account + training data: kept while your account is active, deleted within 30 days of account deletion
  • Payment records: kept 7 years (legal/tax requirement)
  • Fraud prevention logs: kept 12 months
  • Anonymized analytics: kept indefinitely

6. Sub-processors

We use these third-party services to deliver SANCTUM. Each has signed a Data Processing Agreement with us.

  • Vercel (hosting) — Privacy
  • Upstash (Redis cache) — Privacy
  • Neon (Postgres database) — Privacy
  • Stripe (payments worldwide) — Privacy
  • Razorpay (payments India) — Privacy
  • Anthropic (AI tutor and content) — Privacy
  • OpenAI (voice + practice) — Privacy
  • HeyGen (AI avatar videos) — Privacy
  • Resend (transactional email) — Privacy
  • Microsoft Graph (Office 365 account provisioning) — Privacy
  • Sentry (error monitoring) — Privacy

7. International transfers

Your data is processed primarily in the United States. For EU users, we rely on Standard Contractual Clauses (SCCs) with our sub-processors to ensure GDPR-equivalent protection during cross-border transfer.

8. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Passwords are hashed. Sessions use signed JWT tokens. We run daily secret scans (gitleaks), weekly SAST scans (Semgrep), and continuous dependency audits.

9. Contact

Privacy questions or data requests: privacy@texasagilabs.com

We respond within 72 hours and fulfill requests within 30 days (GDPR requirement).