Privacy Policy

Last updated: June 23, 2026

Welcome to Devopstick ("we", "us", or "our"). We operate the website at devopstick.cloudplatformlabs.dev (the "Platform"), a DevOps learning platform. We are committed to protecting your personal data and being transparent about how we collect and use it. This Privacy Policy applies to all users worldwide and complies with:

  • The General Data Protection Regulation (GDPR) — EU/EEA residents
  • The UK GDPR — UK residents
  • The Information Technology Act, 2000 and IT (SPDI) Rules, 2011 — India residents
  • The California Consumer Privacy Act (CCPA) — California residents

1. Data Controller

The data controller responsible for your personal data is Devopstick. For any privacy-related queries, contact us at: ychandra0405@gmail.com or via our Contact page.

2. Data We Collect

We collect the following categories of personal data:

  • Identity Data: First name, last name, username, profile picture.
  • Contact Data: Email address, phone number (optional).
  • Learning Data: Courses enrolled in, lessons completed, quiz results, bookmarks, badges earned, and learning progress history.
  • Technical Data: IP address, browser type and version, device identifiers, operating system, time zone, and session data via JWT authentication tokens stored in cookies.
  • Content Data: Lessons, blog posts, or comments you submit.
  • Usage Data: Pages visited, search queries, click patterns, time on page.
  • Communication Data: Messages you send via our Contact form and any support correspondence.

We do not collect sensitive personal data such as financial information, health data, biometric data, or government identification numbers.

We do not knowingly collect data from children under the age of 13. If you believe a minor has provided us with personal data, please contact us immediately.

3. Lawful Basis for Processing (GDPR)

PurposeLawful Basis
Account registration and managementContract performance
Delivering learning content and tracking progressContract performance
Sending important service notificationsContract performance / Legitimate interest
Improving platform features via analyticsLegitimate interest
Cookie consent managementConsent
Responding to contact/support enquiriesLegitimate interest
Preventing fraud and abuseLegitimate interest / Legal obligation
Maintaining audit and security logsLegal obligation

4. Cookies

We use the following types of cookies:

  • Strictly Necessary: Authentication token (token) stored as an HTTP cookie to keep you logged in. This cookie is essential and cannot be disabled.
  • Functional: Cookie consent preference (cookie_consent_v1) stored in localStorage to remember your choice.
  • Analytics: We may use anonymised, aggregate usage analytics. No personally identifiable tracking cookies are used without your explicit consent.

You can manage or withdraw your cookie consent at any time by clearing your browser cookies and localStorage. For EU/EEA/UK residents, a consent banner is displayed on first visit.

5. How We Use Your Data

  • To create and manage your user account.
  • To deliver course content, track lesson progress, and award badges.
  • To personalise your learning experience and surface relevant content.
  • To send you service-related notifications (e.g., account changes).
  • To investigate abuse, enforce our Terms of Service, and maintain security logs.
  • To improve our platform through aggregated, anonymised analytics.
  • To respond to your support or contact queries.

We do not sell your personal data to third parties. We do not use your data for automated profiling or decision-making that produces legal or similarly significant effects.

6. Data Sharing & Third Parties

We may share your data with the following categories of third-party service providers:

  • Hosting & Infrastructure: Vercel (Next.js deployment, Blob storage).
  • Database: PostgreSQL hosting provider for user and learning data.
  • Email Services: Used only for transactional notifications, not marketing, without your consent.

All third-party processors are bound by data processing agreements. We do not share personal data with advertisers or marketing partners.

7. Data Security

We apply the following technical and organisational security measures:

  • Passwords are hashed using industry-standard algorithms (bcrypt).
  • Authentication uses signed JWT tokens transmitted over HTTPS only.
  • Access to production databases is restricted to authorised personnel only.
  • Security and audit logs are retained to detect and investigate breaches.
  • Account deletion removes personal data from production databases.

In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours as required by GDPR.

8. Data Retention

We retain personal data only as long as necessary. See our full Data Retention Policy for specific timeframes.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data. You can also do this directly via Profile → Delete Account.
  • Right to Restrict Processing: Ask us to pause processing your data in certain circumstances.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
  • Right Not to be Subject to Automated Decision-Making: We do not use automated profiling with legal effects.

To exercise any of these rights, contact us at ychandra0405@gmail.com. We will respond within 30 days (as required by GDPR). There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or CNIL in France) if you believe we have not handled your data lawfully.

10. International Data Transfers

Our platform is hosted on Vercel infrastructure which may process data in the United States and other regions. Where data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) in accordance with GDPR requirements.

11. Children's Privacy

Our platform is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at ychandra0405@gmail.com and we will delete such data promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects when the policy was last revised. For material changes, we will notify registered users via email or a prominent notice on the platform. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

13. Grievance Officer (India — IT Act 2000)

In accordance with the Information Technology Act, 2000 and the IT (SPDI) Rules, 2011, the designated Grievance Officer for Indian residents is reachable at: