Privacy Policy
Last updated: 2026-04-16
1. Who we are
TAL Corp ("we", "us") operates the SANCTUM training platform at lab.texasagilabs.com. This policy explains how we collect and use your personal data.
2. What data we collect
- Account data: name, email address, hashed password
- Training data: module enrollment, stage progression (T1-T7), MCQ attempts, capstone submissions, grades, XP, badges, streak
- Payment data: processed by Stripe (cards) and Razorpay (India) — we never store card numbers. We store provider-issued payment IDs and amounts for audit purposes.
- Usage data: pages visited, clicks, video watch time (only with analytics consent)
- Technical data: IP address, browser type, device type (for fraud detection and logs)
3. Legal basis for processing (GDPR Art. 6)
- Contract performance: to deliver training you paid for
- Legitimate interest: fraud prevention, service improvement, security logs
- Consent: analytics cookies, marketing emails (opt-in only)
- Legal obligation: tax records, audit logs
4. Your rights
Under GDPR, CCPA, and India DPDP, you have the right to:
- Access: download all data we hold about you at /account/export
- Delete: request account deletion at /account/delete (processed within 30 days)
- Portability: receive your data in machine-readable JSON format
- Rectification: update incorrect data via your account settings
- Object: withdraw analytics consent any time via the cookie banner
- Complain: lodge a complaint with your national data protection authority
5. Data retention
- Account + training data: kept while your account is active, deleted within 30 days of account deletion
- Payment records: kept 7 years (legal/tax requirement)
- Fraud prevention logs: kept 12 months
- Anonymized analytics: kept indefinitely
6. Sub-processors
We use these third-party services to deliver SANCTUM. Each has signed a Data Processing Agreement with us.
- Vercel (hosting) — Privacy
- Upstash (Redis cache) — Privacy
- Neon (Postgres database) — Privacy
- Stripe (payments worldwide) — Privacy
- Razorpay (payments India) — Privacy
- Anthropic (AI tutor and content) — Privacy
- OpenAI (voice + practice) — Privacy
- HeyGen (AI avatar videos) — Privacy
- Resend (transactional email) — Privacy
- Microsoft Graph (Office 365 account provisioning) — Privacy
- Sentry (error monitoring) — Privacy
7. International transfers
Your data is processed primarily in the United States. For EU users, we rely on Standard Contractual Clauses (SCCs) with our sub-processors to ensure GDPR-equivalent protection during cross-border transfer.
8. Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Passwords are hashed. Sessions use signed JWT tokens. We run daily secret scans (gitleaks), weekly SAST scans (Semgrep), and continuous dependency audits.
9. Contact
Privacy questions or data requests: privacy@texasagilabs.com
We respond within 72 hours and fulfill requests within 30 days (GDPR requirement).