PRIVACY POLICY
1. Definitions
For the purposes of this Privacy Policy, the following terms carry the meanings set out below, which reflect the statutory meanings under the Digital personal data Protection Act 2023 and the Digital personal data Protection Rules 2025 where applicable.
‘Company’, ‘QuintEdge’, or ‘Data Fiduciary’ means the registered partnership firm QuintEdge having its registered office at 2/3, West Patel Nagar, New Delhi, Delhi 110008, being the entity that determines the purpose and means of processing personal data as a Data Fiduciary under Section 2(i) of the DPDPA.
‘Consent’ means free, specific, informed, unconditional, and unambiguous consent given by a Data Principal through a clear affirmative action, as defined under Section 6 of the DPDPA. The right to withdraw such consent always exists and its withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
‘Consent Manager’ means a registered person under Rule 4 of the DPDP Rules through whom a Data Principal may give, manage, review, and withdraw consent for the processing of their personal data across multiple data fiduciaries.
‘Cookies and Similar Technologies’ means small data files, web beacons, pixel tags, local storage objects, and device fingerprinting techniques placed on or accessed from a user's device, which may directly or indirectly identify a user and therefore constitute personal Data.
‘Data Processor’ means a person who processes personal data on behalf of and under the instructions of QuintEdge, as understood under the DPDPA and the DPDP Rules.
‘Data Protection Board of India’ means the adjudicatory body established under Section 18 of the DPDPA for the purpose of determining non-compliance with the provisions of the DPDPA and the DPDP Rules.
‘Legitimate Use’ means one of the purposes for which personal data may be processed without consent under Section 5 of the DPDPA, which must be identified and documented before processing commences.
‘Minor’ means a person below the age of eighteen years, as defined under Section 2(n) of the DPDPA. Where a user is a Minor, all rights and obligations under this policy vest in and are exercisable by the parent or legal guardian, and verifiable parental consent is mandatory before any personal data of the Minor is processed.
‘Personal Data’ means any data about an individual who is identifiable by or in relation to such data, in digital form, as defined under Section 2(t) of the DPDPA.
‘Platform’ means the Company website at www.quintedge.com, the learning management system at learn.quintedge.com, the mobile application, and any other digital interface through which Services are delivered.
‘Processing’ means a wholly or partially automated operation or set of operations performed on digital personal data and includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, and erasure, as understood under Section 2(x) of the DPDPA.
‘Services’ means all educational and training programmes, live and recorded courses, study materials, mentorship, placement assistance, and any ancillary services offered by the Company.
‘User’ or ‘Data Principal’ means any individual who accesses the platform, enrols in a Course, submits an enquiry, or otherwise interacts with QuintEdge, being the Data Principal under Section 2(j) of the DPDPA.
2. Scope and Applicability
This policy governs the collection and processing of personal data by QuintEdge in connection with the following activities.
Enrolment in, or enquiry about, any course offered by QuintEdge, whether through the platform, by telephone, or in person at the Company's physical centres.
Use of the platform, including browsing the website, logging into the learning management system, or using the mobile application, where cookies and tracking technologies are deployed.
Submission of any form, enquiry, feedback, complaint, or communication to the Company.
Participation in webinars, free demo sessions, workshops, boot camps, or promotional events.
Placement assistance, resume building, mock interview, and career counselling services.
This policy applies to the processing of digital personal data within India and, outside India, where such processing is in connection with any activity related to offering goods or services to Data Principals within India, in accordance with Section 3 of the DPDPA.
This policy is to be read alongside the Company's Terms and Conditions, Refund and Cancellation Policy, Minor Student Enrolment Policy, and Cookie Notice. In the event of a conflict between this policy and any other document, this policy shall prevail in respect of data protection matters.
QuintEdge is committed to collecting and processing only such personal data as is necessary for a specified and lawful purpose, and to implementing appropriate technical and organisational measures to protect personal data from the point of collection.
3. Categories of Personal Data collected
QuintEdge collects personal data only to the extent necessary for the specified and legitimate purposes described in Clause 5 of this policy. The following categories of data may be collected.
Identity and Contact Data includes full name, date of birth, gender, nationality, residential and billing address, email address, mobile number, and photograph, collected for the purposes of account creation, enrolment, identity verification, and communication.
Academic and Professional Data includes educational qualifications, institution name, CFA, FRM, and ACCA examination registration details, employment status, and professional certifications, collected for the purposes of course eligibility assessment, personalised learning, and placement support.
Financial Data includes payment method type, last four digits of card number where applicable, transaction identifiers, and billing address, collected for the purposes of fee collection, refund processing, and fraud prevention. Full payment card data is not stored by the Company and is processed by compliant payment gateway operators.
Platform Usage and Technical Data includes IP address, device type, operating system, browser type and version, pages visited, session duration, clickstream data, and login timestamps, collected through automated means for the purposes of platform security, analytics, and service improvement.
Cookie and Tracking Data includes cookie identifiers, device identifiers, browsing preferences, and consent records with timestamps, collected and managed in accordance with Clause 6 of this policy.
Learning Progress Data includes attendance records, assignment results, test scores, course completion data, and learning management system activity logs, collected for the purposes of progress tracking, performance reporting, and placement support.
Communication Data includes emails, support tickets, call records where disclosed, and feedback submissions, collected for the purposes of customer support, quality assurance, and dispute resolution.
Minor Student Data includes name, date of birth, educational details, and guardian contact information, collected strictly for the purposes of enrolment under the Minor Student Enrolment Policy and subject to the heightened protections set out in Clause 12 of this policy.
Marketing Preferences includes programme interests, referral source, survey responses, and newsletter subscription status, collected for the purposes of targeted communication with prior consent.
QuintEdge does not intentionally collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, biometric data, health data, or data concerning a person's sex life or sexual orientation. If such data is inadvertently received, it shall be promptly deleted or anonymised.
QuintEdge collects only data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed, in accordance with the purpose limitation and data minimisation obligations under the DPDPA.
4. Sources and methods of collecting personal data
QuintEdge collects personal data through the following means.
QuintEdge collects personal data directly from the user through enrolment forms, registration pages, payment portals, free demo sign-up pages, counselling request forms, and contact pages on the platform.
Personal data is also collected automatically through the platform, through cookies, server logs, analytics tools, and similar tracking technologies deployed on the website and learning management system, as further described in Clause 6.
Personal data may also be collected from third parties, through affiliated examination bodies such as the CFA Institute, ACCA, etc. for the purposes of registration verification, or through placement partners with the user's separate written consent.
Personal data may also be collected in person, through physical forms completed at the Company's Delhi or Mumbai centres.
Where any personal data is collected from a source other than the user directly, the Company shall take reasonable steps to inform the user of the categories of data collected and the purposes of processing at the earliest practicable opportunity.
5. Purposes of data processing
QuintEdge processes personal data for the following specified purposes, each of which is supported by either the user's consent or a Legitimate Use under Section 5 of the DPDPA. QuintEdge processes personal data :
for the delivery of Services and performance of its contract with the user, to process enrolment, grant access to courses and study materials, maintain the user's learning management system account, issue certificates of completion, and provide placement assistance, being necessary for the performance of the agreement between QuintEdge and the user.
for payment processing and financial compliance, to collect and process course fees, issue invoices and receipts, process refunds, and maintain financial records required under the Income Tax Act 1961 and GST legislation.
for communication and customer support, to send enrolment confirmations, batch update notices, examination reminders, and responses to support queries, being necessary communications in connection with the Services.
for platform security and fraud prevention, to monitor login activity, detect and prevent unauthorised access, investigate suspicious activity, and protect the integrity of the platform, being a Legitimate Use under Section 5 of the DPDPA.
for analytics and service improvement, to analyse platform usage patterns, improve content and user experience, and develop new features, using anonymised or aggregated data where practicable.
for legal and regulatory compliance, to retain records as required by applicable law, respond to lawful requests from regulatory authorities or courts, and enforce the Company's contractual rights, being a Legitimate Use under Section 5 of the DPDPA.
for marketing and promotional communications, to send information about new courses, promotional offers, events, and industry updates, based solely on the user's prior, separate, and freely given consent, which may be withdrawn at any time in accordance with Clause 14 of this policy.
to provide placement assistance, to share academic profiles and course completion certificates with prospective employers or placement bureaus, based solely on the user's separate written or electronic consent.
QuintEdge shall not process personal data for any purpose that is incompatible with the purposes specified at the time of collection without obtaining fresh consent or establishing a separate Legitimate Use.
6. Cookie policy and tracking technologies
The platform uses cookies and similar technologies to enable core functionality, analyse usage, and, with consent, deliver personalised content and marketing. The following categories of cookies are used.
Strictly Necessary Cookies are essential for the platform to function and cannot be disabled. These include session management, login authentication, and security tokens. No consent is required for these cookies.
Performance and Analytics Cookies are used to measure how users interact with the platform, identify errors, and improve performance. Tools such as Google Analytics may be used. These cookies are deployed only with the user's consent.
Functionality Cookies are used to remember user preferences such as language settings and login details, deployed with the user's consent.
Marketing and Targeting Cookies are used to deliver advertisements and promotional content relevant to the user's interests, deployed only with the user's prior and explicit consent.
Users may manage cookie preferences at any time through the Cookie Preferences Centre accessible on the platform. Consent for non-essential cookies may be withdrawn at any time without affecting access to Services.
Strictly necessary cookies are not subject to the consent requirement and will remain active regardless of the user's preference settings for other cookie categories.
Where a user is identified as a Minor, only strictly necessary cookies will be deployed on that user's device. No analytics, functionality, or marketing cookies will be placed without verifiable parental consent.
7. Lawful grounds for processing
QuintEdge processes personal data on one or more of the following bases as provided under the DPDPA.
Processing may be based on the user's consent under Section 6 of the DPDPA, given freely, specifically, and in an informed, unconditional, and unambiguous manner through a clear affirmative action. Consent is obtained separately for each distinct purpose and may be withdrawn at any time.
Processing may also be necessary for the performance of a contract under Section 5 of the DPDPA, where it is necessary for the performance of the enrolment agreement or for steps taken at the request of the user prior to entering into such an agreement.
Processing may be necessary for compliance with legal obligations under Section 5 of the DPDPA, where it is necessary to comply with a court order, statutory requirement, or lawful demand from a regulatory authority.
Processing may also rely on a Legitimate Use under Section 5 of the DPDPA, where it is necessary for the purposes of preventing fraud, ensuring platform security, or other legitimate uses recognised under the DPDPA, provided such use does not override the rights and interests of the Data Principal.
8. Disclosure and sharing of personal data with third parties
QuintEdge does not sell personal data to any third party. personal data is shared only in the following circumstances and to the extent strictly necessary for the specified purpose.
Data processors, being third party service providers who process personal data on behalf of and under the instructions of QuintEdge pursuant to written data processing agreements, include payment gateway operators, cloud hosting providers, learning management system and video streaming platforms, email, SMS and notification service providers, analytics providers subject to consent, and video conferencing platforms for live sessions.
Placement partners, such as prospective employers, internship providers, or placement bureaus, may receive academic profiles, course completion certificates, and professional data only upon specific, separately obtained, written or electronic consent of the user. Such consent may be withdrawn at any time without affecting other processing or access to Services.
Registration and verification data may be shared with affiliated examination bodies, such as the CFA Institute, ACCA, or other examining bodies, to the extent required for the user's enrolment in or exemption from professional examinations.
Personal data will be disclosed to legal and regulatory authorities if required to do so by a court order, statutory obligation, regulatory demand, or law enforcement request. Where legally permissible, the Company will endeavour to notify the affected user prior to disclosure.
In the event of a business restructuring, such as a merger, acquisition, demerger, or sale of the Company's business or assets, personal data may be transferred to the successor entity, who shall be required to process such data in accordance with this policy or an equivalent policy offering equivalent or higher protection.
The Company may also share aggregated and anonymised data, such as overall pass rates or enrolment numbers, with the public, media, or research partners. Such data cannot be used to identify any individual user.
9. Data retention and erasure
QuintEdge retains personal data only for as long as is necessary for the purposes set out in this policy, or for as long as required by applicable law. The following retention periods are ordinarily applied.
Enrolment and identity records are retained for the duration of the enrolment plus five years thereafter, to account for the limitation period applicable to contractual disputes.
Financial and payment records are retained for eight years from the date of transaction, in compliance with the Income Tax Act 1961 and GST legislation.
Cookie consent records are retained for three years from the date of consent, as evidence of the consent obtained.
Platform usage and analytics data is retained for up to 24 (twenty four) months from collection, after which data is anonymised and no longer capable of identifying an individual.
Communication and support records are retained for three years from the date of last interaction, to address potential consumer complaints.
Minor Student data is retained until the Minor attains eighteen years of age or for three years after course completion, whichever is later, and subject to withdrawal of parental consent in accordance with Clause 12 of this policy.
Marketing consent records are retained until consent is withdrawn and for three years thereafter, as evidence of the consent obtained.
Placement related data is retained until placement is completed or the user's consent for placement is withdrawn.
Upon expiry of the applicable retention period, or upon receipt of a valid erasure request, personal data shall be securely deleted or anonymised using industry-standard data destruction methods that prevent re-identification.
Under Section 8(7) of the DPDPA, where a Data Principal withdraws consent or the purpose of processing is fulfilled and no legal obligation requires continued retention, the Company shall cease processing and delete the personal data without undue delay.
10. Data Security
As a technical safeguard, the Company deploys appropriate encryption for all data transmissions, encrypted storage for sensitive data including financial records and password hashes, two-factor authentication on all learning management system user accounts, and regular automated vulnerability scanning and penetration testing of the platform.
As an organisational safeguard, role-based access controls ensure that personal data is accessible only to personnel with a legitimate operational need, and all employees and contractors with access to personal data are subject to mandatory data protection awareness training and confidentiality obligations.
To secure personal data handled by third parties, all Data Processors are required under written agreement to implement security measures equivalent to those maintained by the Company and to process personal data only on the Company's documented instructions.
In the event of a personal data breach, the Company shall notify the Data Protection Board of India and affected Data Principals within the timelines prescribed under the DPDP Rules and Section 8(6) of the DPDPA. Notifications will contain a description of the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences of the breach, and the measures taken or proposed to address it.
No system of data transmission or storage over the internet is entirely secure. The Company cannot guarantee the absolute security of personal data and shall not be liable for any breach that occurs despite the Company having taken all reasonable and proportionate security precautions in accordance with applicable law.
11. Rights of data principals
The DPDPA confers the following rights on Data Principals. users may exercise any of these rights by submitting a written request to the Grievance Officer at the contact details set out in Clause 15 of this policy. The Company shall respond within fifteen days of receipt of the request, in accordance with Rule 14 of the DPDP Rules.
Users have the right, under Section 11(1) of the DPDPA, to obtain a summary of the personal data being processed and a summary of the processing activities undertaken by the Company in respect of that data.
Users have the right, under Section 11(2) of the DPDPA, to correction of inaccurate or misleading personal Data, completion of incomplete personal Data, and updating of personal data where necessary. users may also update certain data directly through their account on the platform.
Users have the right, under Section 12(1) of the DPDPA, to erasure of personal data where the purpose for which it was collected is no longer being served or the user has withdrawn consent, subject to any legal obligation of the Company to retain the data.
Users have the right, under Section 6(5) of the DPDPA, to withdraw consent at any time. Withdrawal shall not affect the lawfulness of processing based on consent prior to its withdrawal, but the Company shall cease processing the data for the relevant purpose upon receipt of withdrawal unless a Legitimate Use applies.
Users have the right, under Section 13 of the DPDPA, to nominate another individual to exercise the rights of the Data Principal in the event of the Data Principal's death or incapacity. Nomination forms may be obtained from the Grievance Officer.
Users have the right, under Section 8(10) of the DPDPA, to have grievances redressed by the Company's Grievance Officer within the timelines specified in Clause 15 of this policy, and thereafter to file a complaint with the Data Protection Board of India under Section 28 of the DPDPA if not satisfied with the Company's response.
The Company shall not charge any fee for responding to a rights request unless the request is manifestly unfounded or excessive, in which case a reasonable administrative charge may be levied.
All rights requests must be submitted in writing and must include sufficient information to enable the Company to identify the Data Principal and the specific data or processing activity to which the request relates.
12. Special provisions for minor students
QuintEdge accords the highest level of data protection to Minor Students. Processing of a Minor's personal data is strictly limited to what is necessary for course delivery and educational administration.
Under the DPDPA, a Minor is a person below eighteen years of age, and QuintEdge applies this threshold to all users, irrespective of the jurisdiction from which they access the platform.
Before any personal data of a Minor Student is collected or processed, the Company shall implement reasonable age verification mechanisms to identify whether a user is a Minor, obtain verifiable consent from the parent or legal guardian through the Guardian Consent Form in accordance with Section 9 of the DPDPA and Rule 10 of the DPDP Rules, and maintain a record of such consent.
The Company shall not process a Minor Student's personal data for targeted or behavioural advertising, location tracking, behavioural monitoring or profiling, generating any content that could harm the Minor's wellbeing, or any purpose not directly and necessarily connected with the delivery of the enrolled course, and this restriction on processing is absolute and cannot be overridden.
Where the Company has reason to believe that a user is a Minor, no non-essential cookies shall be placed on that user's device, and only strictly necessary cookies shall operate.
On behalf of the Minor, the parent or legal guardian may exercise all data rights set out in Clause 11 of this policy, including the rights of access, correction, erasure, and withdrawal of consent.
Upon a Minor Student attaining the age of eighteen years, the Company may, upon request, transition the account to an adult account, and the erstwhile Minor may then independently exercise data rights and provide their own consent for future processing.
13. Consent Management
The DPDP Rules 2025 introduce a Consent Manager ecosystem through which a Data Principal may give, manage, review, and withdraw consent for the processing of their personal data across multiple data fiduciaries. QuintEdge shall integrate with registered Consent Managers as required upon the commencement of the full Consent Manager framework.
Until such time, consent is obtained and managed directly through the Company's platform. users may manage their consent preferences at any time through the Cookie Preferences Centre for cookie consent, through the account settings on the learning management system for communication preferences, or by submitting a written request to the Grievance Officer.
Records of all consent given, managed, and withdrawn are maintained by the Company and are available to the Data Principal upon request.
14. Marketing communications and right to opt out
QuintEdge may send the following categories of marketing communications by email, SMS, WhatsApp, or other channels: information about new courses, programmes, and certifications; promotional offers, early-bird discounts, and scholarship announcements; webinar and event invitations; and industry updates, study tips, and exam-related news.
Marketing communications are sent only to users who have given their prior, specific, and freely given consent to receive them. Consent for marketing communications is separate from and does not follow from consent to the Terms and Conditions or from enrolment in a course.
Users have the right to opt out of marketing communications at any time without affecting their enrolment or access to Services. Opt-out may be exercised by clicking the unsubscribe link in any marketing email, by replying STOP to any marketing SMS, or by submitting a written request to info@quintedge.com, which shall be actioned within 15 (fifteen) business days.
Transactional communications such as enrolment confirmations, payment receipts, batch update notices, and password resets are sent based on contract performance and are not subject to marketing opt-out.
15. Grievance redressal and contact details
Grievance Officer: in accordance with Section 8(10) of the DPDPA and the Consumer Protection (E-Commerce) Rules 2020, QuintEdge has designated:
Name: Mr. Prayag Mukhi, Grievance Officer, Data Protection, as the Grievance Officer for the purpose of addressing all privacy-related complaints, data rights requests, and other grievances.
Address: 2/3, West Patel Nagar, New Delhi, Delhi 110008
Email: info@quintedge.com
Phone: +91 7303381314
Company shall acknowledge receipt of a written complaint, resolve complaints, and respond to rights requests, in each case within fifteen days of receipt, in accordance with Rule 14 of the DPDP Rules.
Escalation to Data Protection Board of India: if a user is not satisfied with the Company's response to a grievance or rights request, the user may escalate the matter to the Data Protection Board of India through its digital portal and mobile application, in accordance with Section 28 of the DPDPA.
Consumer Disputes: nothing in this Clause shall restrict any user's right to approach the Consumer Disputes Redressal Commission at the appropriate level under the Consumer Protection Act 2019.
16. Amendments to this privacy policy
QuintEdge reserves the right to modify, amend, or update this Privacy Policy at any time, in response to changes in applicable Indian law including the DPDPA and the DPDP Rules, guidance or enforcement decisions from the Data Protection Board of India, or material changes in the Company's data processing practices. Any material change shall be communicated to registered users at least seven days prior to the change taking effect, by a prominent notice on the platform and by email to the user's registered email address, and the user's continued use of the platform or Services after the effective date of the revised Policy shall constitute acceptance of the revised terms.
17. Governing law and Dispute resolution
This policy and all data protection-related disputes are governed by and construed in accordance with the laws of India, including the DPDPA, the DPDP Rules, the Information Technology Act 2000, and the Consumer Protection Act 2019.
Any dispute arising out of or in connection with this policy shall be resolved in accordance with the dispute resolution mechanism set out in the Company's Terms and Conditions, being good-faith negotiation followed by arbitration under the Arbitration and Conciliation Act 1996, with the seat and venue of arbitration at New Delhi.
Nothing in this Clause shall restrict any user's right to approach the Data Protection Board of India or the Consumer Disputes Redressal Commission under applicable law.
18. General provisions
Severability: if any provision of this policy is held invalid or unenforceable in any jurisdiction, such provision shall be severed to the minimum extent necessary, and the remaining provisions shall continue in full force and effect.
No Waiver: any failure by the Company to enforce any provision of this policy shall not constitute a waiver of the Company's right to enforce such provision in the future.
Purpose Limitation and Data Minimisation: QuintEdge commits to processing only the minimum personal data necessary for each specified purpose and to not using personal data for any purpose beyond that for which it was collected without obtaining fresh consent or establishing a separate Legitimate Use.
Language: this policy is made in the English language. In the event of any inconsistency between an English version and any translation, the English version shall prevail.
Entire Framework: this Privacy Policy, together with the Cookie Notice, Terms and Conditions, Refund and Cancellation Policy, and Minor Student Enrolment Policy, constitutes the entire data protection framework of the Company in respect of users.
Effective Date: this policy takes effect on 1 July 2026 and supersedes all prior privacy policies published by the Company.
