Last updated September 2026 · TROVIQ (OPC) PRIVATE LIMITED, Vadodara, Gujarat, India
TROVIQ (OPC) PRIVATE LIMITED ("Troviq", "we", "us", or "our") is the Data Fiduciary for the personal data described here, within the meaning of India's Digital Personal Data Protection Act, 2023. This policy explains what we collect when you use our platform at troviq.in, why we collect each item, who else sees it, and how you can take it back. It also reflects our obligations under the Information Technology Act, 2000 and the rules made under it.
You give us, when you register:
You give us, as you use the platform:
We generate or record automatically:
We do not ask for and do not want your Aadhaar number, PAN, bank details, card details, caste, religion, health information or biometrics. Please do not send them to us.
The DPDP Act requires us to tell you the specific purpose of each use rather than a general one. We use your data only for these:
We do not sell your personal data, we do not share it with advertisers, and we do not use it to build advertising profiles or to make automated decisions that produce legal effects for you. Every certificate decision is made by a human mentor.
When you register, you tick a box confirming that you have read and agree to this Privacy Policy, the Terms of Service and the Refund Policy. We record the moment you did so. You cannot create an account without that affirmative step.
WhatsApp updates are a separate, optional tick-box that is off by default. We will not message you on WhatsApp unless you have turned it on, and turning it off in your dashboard profile stops it immediately. We will still email you about anything that affects your enrolment, because those messages are part of the service you bought rather than marketing.
Withdrawing consent. You may withdraw your consent at any time, as easily as you gave it, by writing to support@troviq.in. Withdrawal is not retrospective: it does not undo processing that was lawful before you withdrew. If you withdraw the consent your account depends on, we will close the account, and we may be unable to continue providing the course or internship.
We do not sell your personal data. We rely on the following processors to run the platform. Each receives only what that function needs:
Beyond these, we share data only in two situations: publicly verifiable certificate details (name, certificate ID, track, completion date) shown to whoever you give a certificate ID or QR code to; and disclosures to courts, regulators or law enforcement where Indian law compels them.
Transfers outside India. Some of these providers operate infrastructure outside India, so your data may be processed abroad. Section 16 of the DPDP Act permits such transfers except to countries the Central Government has restricted, and we will stop transferring to any provider that falls under such a restriction. Our email is sent through ZeptoMail's Indian endpoint.
We keep your account data for as long as your account is open. If you ask us to delete your account, we erase it and instruct our processors to do the same.
Two things survive deletion, and you should know this before you ask:
Server logs are retained only as long as our hosting providers hold them in the ordinary course, and are not used to build any profile of you.
Traffic to the site and the API travels over HTTPS. Passwords are stored only as bcrypt hashes, which means we cannot read them and cannot tell you what your password is. Session cookies are httpOnly, Secure and SameSite=Lax, so page scripts cannot read them. Certificate PDFs live in a private bucket and are streamed through an authenticated endpoint rather than a public link. Access to production data is restricted to the company's own administrators.
No system is completely secure. If a personal data breach occurs, the DPDP Act requires us to notify the Data Protection Board of India and every affected person. We will do so without undue delay, telling you what happened, what data was involved, and what you should do about it. Please use a strong, unique password and tell us at once if you think your account has been accessed by someone else.
As a Data Principal under the DPDP Act, 2023 you have the right to:
Access, nomination and erasure are self-service, so you do not have to ask us or wait for us. For anything else, email support@troviq.in from the address registered on your account and we will respond within the timelines in section 12. The Act also requires you to exercise these rights in good faith and not to file false or frivolous complaints.
Section 9 of the DPDP Act treats anyone under 18 as a child and does not allow us to process a child's data without verifiable consent from a parent or legal guardian. That is why the date of birth on the registration form is mandatory.
If the date you enter makes you under 18, the form asks for your parent or legal guardian's full name and email address and for their explicit consent before the account can be created. We then email that guardian to tell them the consent has been recorded, and give them a direct route to withdraw it — at which point we delete the account and the data held with it.
The Act also forbids tracking, behavioural monitoring and targeted advertising directed at children. We do none of these for any user, of any age.
If you believe a child has registered without their guardian's consent, write to support@troviq.in and we will act on it.
We set a single essential cookie of our own, trv_token, when you log in. It holds your session and is required for the platform to work. It is an httpOnly cookie, so it cannot be read by JavaScript running in your browser; it is marked SameSite=Lax and Secure, and it expires 7 days after login or immediately when you log out.
We do not use advertising cookies, and we do not run Google Analytics or any similar product that profiles you across sites. Our website is served through Cloudflare, which adds its own privacy-focused traffic measurement to pages it serves and may set cookies for security and bot protection. That measurement reports aggregate traffic to us; it does not identify you to us and we do not combine it with your account.
Our platform may contain links to external websites. We are not responsible for their privacy practices and encourage you to review their policies.
We may update this policy from time to time. Where a change materially affects how we handle your data, we will email registered users before it takes effect, and where the law requires it we will ask for your consent again rather than assume it. The date at the top of this page always shows the current revision.
In accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under it, and the Consumer Protection (E-Commerce) Rules, 2020, the following officer may be contacted for any complaint about your personal data or your use of this platform:
A grievance raised through the contact form is given a reference number of the form TRV-C-XXXXXXXX the moment it is recorded, shown on screen and repeated in the acknowledgement we email you. Quote it in any follow-up. We acknowledge every grievance within 48 hours of receiving it, and resolve it within one month. If you are not satisfied with the outcome, you may escalate a data protection complaint to the Data Protection Board of India, or a consumer complaint to the National Consumer Helpline or the appropriate consumer forum.
The Data Fiduciary for your personal information is TROVIQ (OPC) PRIVATE LIMITED, a One Person Company incorporated in India and registered with the Registrar of Companies, Gujarat, Dadra & Nagar Haveli.
For any privacy-related questions or requests, including access, correction or deletion of your data, contact us at the email or postal address above.