Legal

Privacy Policy

Last updated: 4 August 2026

1. Who we are

This Privacy Policy explains how Innoryx Global Learning ("Innoryx", "we", "us") handles personal data when you visit our websites (innoryx.com, innoryx.ae), submit an enquiry or registration, enrol in a course, or message us on WhatsApp or Instagram.

Innoryx Global Learning Pvt. Ltd., Nehru Institute of Engineering & Technology, Nehru Gardens, Thirumalayampalayam, Coimbatore – 641105, India. UAE operations: FutureX Global Learning, SPARK, University City, Sharjah – 66636, United Arab Emirates.

2. Data we collect

  • Contact details — name, email address, phone/WhatsApp number, country or city, and the organisation or institution you belong to.
  • Enquiry and learning data — courses you are interested in, qualifications previously completed, counselling notes, enrolment records, batch and attendance records, assessment and certification results.
  • Payment records — invoice, instalment, and receipt details. Card and bank credentials are handled by our payment providers (Razorpay in India, Omnispay in the UAE) and are never stored by us.
  • Messaging data — when you contact us through WhatsApp or Instagram, we receive your profile name, messaging ID/phone number, and the content of the messages you send us, including any attachments.
  • Technical data — device, browser, and usage information needed to operate and secure our platform.

3. How we use your data

  • Respond to enquiries and provide course counselling.
  • Process enrolments, fees, invoices, and certificates.
  • Deliver training, track attendance and assessments, and issue verifiable certificates.
  • Send service messages about your batch, schedule, payments, and results.
  • Send course updates or webinar invitations where you have opted in.
  • Meet legal, accreditation, and audit obligations, and prevent fraud or misuse.

4. WhatsApp and Instagram messaging

We use official Meta business messaging channels (WhatsApp Business Platform and Instagram Messaging) through our messaging provider to communicate with enquirers and learners. Conversations are stored in our internal CRM so that our counselling and support team can continue the conversation and maintain an accurate record.

We only send you messages after you contact us, submit a form requesting contact, or otherwise opt in. We do not sell messaging data, do not use it for advertising, and do not share message content with third parties other than the service providers listed below. You may ask us to stop messaging you at any time by replying "STOP" or by emailing us; you may also request deletion of your conversation history.

Message data received via Meta platforms is used strictly to provide the support, admissions, and learning services you requested, and is retained only as long as needed for those purposes or as required by law.

5. Legal basis

We process personal data on the basis of your consent (enquiries, marketing, messaging), performance of our contract with you (enrolment and training delivery), our legitimate interests (service improvement, security, fraud prevention), and compliance with legal obligations.

6. Sharing and service providers

We share data only as necessary with:

  • Cloud hosting, database, and email infrastructure providers that operate our platform.
  • Meta Platforms and our messaging provider, to deliver WhatsApp and Instagram conversations.
  • Payment providers (Razorpay, Omnispay) to process fees.
  • Awarding and accreditation bodies, such as Highfield Qualifications, where you are registered for their qualification and registration data must be submitted.
  • Professional advisors, auditors, or authorities where required by law.

We do not sell personal data, and we do not share it for third-party advertising.

7. International transfers

We operate in India and the United Arab Emirates and use service providers that may process data in other countries. Where data is transferred internationally, we rely on appropriate safeguards and contractual protections with those providers.

8. Retention

Enquiry records are retained while your interest is active and for a reasonable follow-up period thereafter. Enrolment, assessment, certification, and financial records are retained for as long as required by accreditation and statutory requirements. Messaging conversations are retained for the period needed to support you, unless you request earlier deletion.

9. Account Security and Brute-Force Protection

We implement strong protection against brute-force attacks, credential stuffing, automated signup attempts, and account enumeration across learner signup, login, and password-reset endpoints.

Rate limiting

We enforce limits on the backend to track attempts by account identifier and IP address. Limits are initially set to a maximum of 5 failed attempts per account within 15 minutes, 20 attempts per IP within 10 minutes, and 50 attempts per IP across different accounts within one hour. Repeated failures apply exponential delays up to one hour. Resetting occurs atomically and counters are reset after a successful login.

Bot protection

Suspicious activity or repeated failures trigger a server-validated bot challenge (Cloudflare Turnstile). We validate every challenge token on the backend to ensure validity and prevent bypass.

Account-enumeration protection

We use generic responses for auth failures ("The information provided is incorrect or the request cannot be completed") to ensure that email, phone, or ID existence is never revealed through the interface or response timing.

Security controls

Access to learner and enquiry data is restricted by role, protected by authenticated accounts and database-level access controls, and transmitted over encrypted connections. Financial actions such as payment approvals require authorized sign-off and are logged. We require strong passwords, use secure HTTP-only cookies, and enforce MFA for Super Admin accounts.

Password-reset protection

Rate limits apply to reset requests and token submissions. Approved reset links are random, single-use, and valid for exactly 12 hours. Completing a reset clears lockout counters and revokes previous sessions.

10. Your rights

You may request access to, correction of, or deletion of your personal data, withdraw consent, object to marketing, or ask for a copy of your data. To exercise any of these rights, email info@innoryx.com. We will respond within a reasonable period and may need to verify your identity first. Some records must be retained where accreditation or legal obligations apply.

11. Cookies

We use only the cookies and local storage necessary to keep you signed in, remember preferences, and keep the platform secure. You can clear or block cookies in your browser, though signed-in features may stop working.

12. Children

Our courses are intended for students, graduates, and working professionals. We do not knowingly collect data from children under 13. If you believe a child has provided data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as our services or legal obligations change. The revised version will be published on this page with a new "last updated" date.

14. Contact us