Privacy Policy
Last updated: June 23, 2026
Welcome to Devopstick ("we", "us", or "our"). We operate the website at devopstick.cloudplatformlabs.dev (the "Platform"), a DevOps learning platform. We are committed to protecting your personal data and being transparent about how we collect and use it. This Privacy Policy applies to all users worldwide and complies with:
- The General Data Protection Regulation (GDPR) — EU/EEA residents
- The UK GDPR — UK residents
- The Information Technology Act, 2000 and IT (SPDI) Rules, 2011 — India residents
- The California Consumer Privacy Act (CCPA) — California residents
1. Data Controller
The data controller responsible for your personal data is Devopstick. For any privacy-related queries, contact us at: ychandra0405@gmail.com or via our Contact page.
2. Data We Collect
We collect the following categories of personal data:
- Identity Data: First name, last name, username, profile picture.
- Contact Data: Email address, phone number (optional).
- Learning Data: Courses enrolled in, lessons completed, quiz results, bookmarks, badges earned, and learning progress history.
- Technical Data: IP address, browser type and version, device identifiers, operating system, time zone, and session data via JWT authentication tokens stored in cookies.
- Content Data: Lessons, blog posts, or comments you submit.
- Usage Data: Pages visited, search queries, click patterns, time on page.
- Communication Data: Messages you send via our Contact form and any support correspondence.
We do not collect sensitive personal data such as financial information, health data, biometric data, or government identification numbers.
We do not knowingly collect data from children under the age of 13. If you believe a minor has provided us with personal data, please contact us immediately.
3. Lawful Basis for Processing (GDPR)
| Purpose | Lawful Basis |
|---|---|
| Account registration and management | Contract performance |
| Delivering learning content and tracking progress | Contract performance |
| Sending important service notifications | Contract performance / Legitimate interest |
| Improving platform features via analytics | Legitimate interest |
| Cookie consent management | Consent |
| Responding to contact/support enquiries | Legitimate interest |
| Preventing fraud and abuse | Legitimate interest / Legal obligation |
| Maintaining audit and security logs | Legal obligation |
4. Cookies
We use the following types of cookies:
- Strictly Necessary: Authentication token (
token) stored as an HTTP cookie to keep you logged in. This cookie is essential and cannot be disabled. - Functional: Cookie consent preference (
cookie_consent_v1) stored in localStorage to remember your choice. - Analytics: We may use anonymised, aggregate usage analytics. No personally identifiable tracking cookies are used without your explicit consent.
You can manage or withdraw your cookie consent at any time by clearing your browser cookies and localStorage. For EU/EEA/UK residents, a consent banner is displayed on first visit.
5. How We Use Your Data
- To create and manage your user account.
- To deliver course content, track lesson progress, and award badges.
- To personalise your learning experience and surface relevant content.
- To send you service-related notifications (e.g., account changes).
- To investigate abuse, enforce our Terms of Service, and maintain security logs.
- To improve our platform through aggregated, anonymised analytics.
- To respond to your support or contact queries.
We do not sell your personal data to third parties. We do not use your data for automated profiling or decision-making that produces legal or similarly significant effects.
6. Data Sharing & Third Parties
We may share your data with the following categories of third-party service providers:
- Hosting & Infrastructure: Vercel (Next.js deployment, Blob storage).
- Database: PostgreSQL hosting provider for user and learning data.
- Email Services: Used only for transactional notifications, not marketing, without your consent.
All third-party processors are bound by data processing agreements. We do not share personal data with advertisers or marketing partners.
7. Data Security
We apply the following technical and organisational security measures:
- Passwords are hashed using industry-standard algorithms (bcrypt).
- Authentication uses signed JWT tokens transmitted over HTTPS only.
- Access to production databases is restricted to authorised personnel only.
- Security and audit logs are retained to detect and investigate breaches.
- Account deletion removes personal data from production databases.
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours as required by GDPR.
8. Data Retention
We retain personal data only as long as necessary. See our full Data Retention Policy for specific timeframes.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data. You can also do this directly via Profile → Delete Account.
- Right to Restrict Processing: Ask us to pause processing your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right Not to be Subject to Automated Decision-Making: We do not use automated profiling with legal effects.
To exercise any of these rights, contact us at ychandra0405@gmail.com. We will respond within 30 days (as required by GDPR). There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.
You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or CNIL in France) if you believe we have not handled your data lawfully.
10. International Data Transfers
Our platform is hosted on Vercel infrastructure which may process data in the United States and other regions. Where data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) in accordance with GDPR requirements.
11. Children's Privacy
Our platform is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at ychandra0405@gmail.com and we will delete such data promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects when the policy was last revised. For material changes, we will notify registered users via email or a prominent notice on the platform. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
13. Grievance Officer (India — IT Act 2000)
In accordance with the Information Technology Act, 2000 and the IT (SPDI) Rules, 2011, the designated Grievance Officer for Indian residents is reachable at:
- Email: ychandra0405@gmail.com
- Response time: Within 1 month of receipt of grievance.