Effective Date: 18 June 2026 · Version: 1.1 · Replaces: Version 1.0 dated 01 March 2026
Violet InfoSystems Pvt. Ltd. ("Violetinfo.ai", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use any product across the Violetinfo.ai platform, visit any of our websites, or interact with us in any other way.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy applies to all Violetinfo.ai products and services, including:
It also applies to:
violetinfo.ai, violetlms.com, and any subdomain (e.g., customer.violetinfo.ai)learn.yourcompany.com)If you access any Violetinfo.ai product through your employer, educational institution, or another organization, your administrator's contract with us also governs how your data is handled.
Violet InfoSystems Pvt. Ltd. (corporate brand: Violetinfo.ai) is an Indian company registered under the Companies Act 2013, with its registered office at:
1106, Quantum Tower, Chincholi Phatak, S.V. Road, Malad (West), Mumbai – 400064, India
Violet InfoSystems Pvt. Ltd. is the Data Fiduciary (under India's DPDPA 2023) and the Data Controller (under the EU/UK GDPR) for personal data processed in connection with the Violetinfo.ai platform, unless your organization has separately agreed to act as the controller under a data-processing agreement.
For privacy queries, contact our DPO at dpo@violetinfo.ai or privacy@violetinfo.com.
Where you access a Violetinfo.ai product through your employer or institution, your administrator may provide us with your name, email, employee/student ID, department, location, designation, reporting manager, and other details required to provision your account or assign learning.
We may process special categories of data only where strictly necessary for the Service and only with appropriate safeguards:
We use personal data to:
We rely on the following legal bases, depending on jurisdiction and processing activity:
| Basis | When we use it |
|---|---|
| Contractual necessity | To deliver the Services under your account agreement or your employer's subscription |
| Legitimate interests | Security, fraud prevention, analytics, platform improvement – balanced against your rights |
| Legal obligation | Tax records, CERT-In log retention, court orders, regulator requests |
| Consent | Marketing communications, optional cookies, biometric features. You may withdraw consent at any time without affecting prior processing |
| Public interest / vital interest | Where applicable under specific local laws |
We may aggregate and anonymize personal data so that it can no longer reasonably be linked to you, and use that aggregated data for benchmarking, research, analytics, and product development. Aggregated data is not personal data.
We share personal data only with the following categories of recipients:
We do not sell your personal data. We do not share your personal data with advertisers. California residents – see Section 11.
Under India's DPDPA 2023, you may interact with us through a registered Consent Manager. Where the Government of India operationalizes Consent Managers, we will support consent-management requests routed through them.
If you receive marketing communications from us:
We use a small set of trusted sub-processors to operate the Services. All sub-processors are bound by written Data Processing Agreements, are required to maintain equivalent security and privacy protections, and process data only on our documented instructions.
| Category | Sub-processor | Purpose | Data location |
|---|---|---|---|
| Cloud infrastructure | Amazon Web Services | Hosting, storage, databases | AWS Mumbai (ap-south-1) primary; backups within India |
| Payments | Razorpay / Stripe | Payment processing for paid subscriptions | India / US (PCI-DSS) |
| Transactional email | Amazon SES / SendGrid | Account emails, notifications, password resets | Region-specific |
| AI inference | Anthropic, OpenAI, AWS Bedrock | AI features (VAuthor, VGen, VConverse, VInsights) – see Section 9 for what we do and do not send | US / regional endpoints |
| Customer support | Zoho | Support ticketing | Region-specific |
| Analytics | First-party analytics + GA4 (cookie-consent gated) | Usage analytics | Region-specific |
We implement administrative, technical, and physical safeguards aligned to ISO 27001, SOC 2 Type II, and DPDPA-grade controls:
If we become aware of a security incident affecting your personal data, we will:
While we take significant measures, no internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
Violetinfo.ai products use AI features (VAuthor AI, VGen AI, VConverse AI, VInsights AI, VCoach, VTest AI proctoring, and others). Here is what that means for your data:
You may exercise your right under GDPR Article 22 and CCPA to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. Email dpo@violetinfo.ai.
Your personal data is primarily stored and processed within India on Amazon Web Services infrastructure in the AWS Mumbai (ap-south-1) region.
Where we transfer personal data outside its country of origin, we rely on one or more of the following safeguards:
If you are a California resident, you have the following rights:
To exercise these rights, submit a request at email privacy@violetinfo.com. We may verify your identity before responding.
You may also designate an authorized agent to act on your behalf.
Different ages of consent apply in different countries:
| Region | Threshold | What it means |
|---|---|---|
| India (DPDPA) | Under 18 | Verifiable parental consent required for processing |
| EU (GDPR) | Under 16 (some member states 13–15) | Parental consent required for online services |
| US (COPPA) | Under 13 | Federal verifiable parental consent required |
| California (CCPA) | Under 16 | Opt-in required for any sale/sharing |
Where Violetinfo.ai products are deployed for an audience that includes children below the applicable age, we require the deploying institution (school, training partner, or parent) to obtain all necessary parental consents before deployment and to confirm this in writing to us.
We do not knowingly collect personal data directly from children without verifiable parental consent. If you believe a child has provided us data without consent, please email privacy@violetinfo.com and we will delete the data without undue delay.
See our internal Violetinfo Children's Data Policy for the full operating procedure. (refer to our Command Center commandcentre.violetcloud.io)
We use cookies and similar technologies in four categories:
| Category | Required? | What it does | How to control |
|---|---|---|---|
| Strictly necessary | Always on | Session, security, load balancing | Cannot be disabled; required for the Service to function |
| Functional | Opt-in | Remembers language, theme, preferences | Cookie banner |
| Analytics | Opt-in | Matomo + GA4 + Hotjar + Violetinfo Analytics to measure usage patterns | Cookie banner |
| Marketing | Opt-in | None on logged-in product surfaces; limited on violetinfo.ai marketing pages with consent | Cookie banner |
You can manage your preferences through our cookie banner or your browser settings. Details are in our separate Cookie Policy, which forms part of this Privacy Policy.
| Data category | Retention period | Why |
|---|---|---|
| Active account data | Duration of your subscription + 3 years | Reactivation, dispute resolution, regulatory |
| Transaction and financial records | 8 years | Indian tax law |
| Security and system logs | 12 months active + 24 months archive | Security investigations, CERT-In direction |
| AI proctoring video/screen capture (when enabled) | 90 days unless dispute | Test integrity, audit |
| Marketing data | Until you unsubscribe + 1 year | Suppression list maintenance |
| Anonymized/aggregated data | Indefinitely | No longer personal data |
On request, account closure, or end of contract, we will delete or anonymize your personal data within 90 days, subject to legal retention obligations.
See our internal Data Restoration and Destruction Policy for the disposal procedure. (refer to our Command Center commandcentre.violetcloud.io)
Our websites and products may contain links to third-party websites or integrate with third-party services (e.g., LinkedIn for SSO, YouTube for video, Razorpay for payments). This Privacy Policy applies only to the Violetinfo.ai-operated services. We are not responsible for the privacy practices of third parties and encourage you to review their policies.
Subject to applicable law, you have these rights:
We will respond to verified requests within 30 days (DPDPA / India / most jurisdictions) or 1 month (GDPR), extendable by 2 further months for complex requests. We may need to verify your identity before responding.
| Role | Contact |
|---|---|
| Data Protection Officer (DPO) | dpo@violetinfo.ai |
| Privacy Contact | privacy@violetinfo.com |
| Grievance Officer (DPDPA 2023) | grievance@violetinfo.ai |
| General Support | support@violetinfo.ai |
| Registered Office | Violet InfoSystems Pvt. Ltd., 1106, Quantum Tower, Chincholi Phatak, S.V. Road, Malad (West), Mumbai – 400064, India |
If you have a concern about our handling of your personal data, please contact our DPO first at dpo@violetinfo.ai. We will work with you to resolve the matter within 30 days.
If unresolved, you may lodge a complaint with the supervisory authority in your jurisdiction:
| Region | Authority |
|---|---|
| India | Data Protection Board of India (DPDPA 2023) · CERT-In for cyber incidents |
| EU / EEA | Your local data protection authority (list: edpb.europa.eu) |
| UK | Information Commissioner's Office – ico.org.uk |
| California (US) | California Privacy Protection Agency – cppa.ca.gov · California Attorney General |
| United States (Federal) | Federal Trade Commission |
| KSA | Saudi Data and Artificial Intelligence Authority (SDAIA) |
| UAE | UAE Data Office (Federal Law 45 of 2021) |
| Oman | Ministry of Transport, Communications and Information Technology |
| Bahrain | Personal Data Protection Authority |
| Singapore | Personal Data Protection Commission – pdpc.gov.sg |
| Australia | Office of the Australian Information Commissioner (OAIC) – oaic.gov.au |
| Malaysia | Personal Data Protection Commissioner |
| South Africa | Information Regulator |
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. We will notify you of material changes by email and through a notice on the Violetinfo.ai platform at least 30 days before the changes take effect.
| Version | Date | Summary |
|---|---|---|
| 1.0 | 01-Mar-2026 | Initial public privacy policy for VioletLMS |
| 1.1 | 18-Jun-2026 | Expanded to full Violetinfo.ai product suite. Added CCPA/CPRA, AI processing, sub-processors, breach timelines, supervisory authorities, cookie categories, version log. Updated entity branding to Violetinfo.ai and contacts to violetinfo.ai domain. |