Privacy Policy
Effective Date: 1 January 2026 · Last Updated: 27 February 2026
This Privacy Policy describes how Jaipal Redhu (Redhu Engineering) ("we", "us", or "our") collects, uses, and protects your personal information when you use our website and services.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, and profile picture when you sign in with Google or Apple.
- Payment Information: Processed securely by Stripe. We do not store your card details.
- Contact Information: Information you provide when contacting us for support.
1.2 Information Collected Automatically
- Usage Data: Pages visited, videos watched, course progress, and interaction data.
- Device Information: Browser type, operating system, and device identifiers.
- Location Data: Country-level geolocation to provide regional pricing and content.
2. How We Use Your Information
- Provide and improve our courses and services
- Process payments and send purchase confirmations
- Track your course progress and provide personalized recommendations
- Send important updates about your enrolled courses
- Respond to your inquiries and support requests
- Analyze usage patterns to improve our platform
- Comply with legal obligations
3. Legal Basis for Processing
Under the Digital Personal Data Protection Act (DPDPA) 2023, we process your data based on:
- Consent: For analytics cookies and optional features (with your explicit, informed consent)
- Contractual Necessity: To fulfill our agreement when you purchase a course or service
- Legal Obligation: To comply with tax, financial, and regulatory requirements under Indian law
- Legitimate Uses: For platform security, fraud prevention, and service improvement as permitted under DPDPA 2023
4. Data Sharing
We share your information only with:
- Payment Processors: Stripe for secure payment processing
- Cloud Services: Google Cloud Platform for hosting and storage
- Analytics: Google Analytics (only with your consent)
- Email Service: Resend, Inc., USA. For transactional emails (purchase confirmations, course access, booking confirmations). Data processed: email address, name, delivery status.
- Call Scheduling: Cal.com for consultation bookings (Global customers only). Cal.com, Inc., USA. Video calls powered by Cal Video.
- Geolocation: Cloudflare Trace API for country detection (regional routing). Cloudflare, Inc., USA. Your browser sends your IP address to Cloudflare to retrieve your country code.
- Authentication (Google): Google OAuth for account login. Google Ireland Ltd., Ireland. Data processed: name, email address, and profile picture.
- Authentication (Apple): Apple Sign In for account login. Apple Inc., USA. Data processed: Apple ID, name, and email address (optionally hidden via Apple's "Hide My Email" feature).
- Rate Limiting: Upstash, Inc., USA. For abuse prevention and DDoS protection. Data processed: hashed IP addresses with automatic expiry (1–60 minutes).
We never sell your personal data to third parties.
5. Data Retention
- Account Data: Retained while your account is active, plus 30 days after deletion request
- Payment Records: Retained for 7 years for tax compliance
- Course Progress: Retained while enrolled in courses
- Support Communications: Retained for 2 years
- Rate Limit Data: Automatically expires after 1–60 minutes (Upstash Redis)
- Email Delivery Logs: Retained per Resend's retention policy
- Analytics Data: 14 months (Google Analytics 4 default)
- Video Access Logs: 90 days
- Document Review Files: 1 year (auto-deleted via GCS lifecycle policy)
6. Your Rights
Under DPDPA 2023, as a data principal you have the right to:
- Access: Obtain a summary of your personal data and processing activities
- Correction: Correct inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Grievance Redressal: Lodge a grievance with our Grievance Officer regarding your data
- Nomination: Nominate another person to exercise your rights in the event of your death or incapacity
- Withdraw Consent: Withdraw previously given consent at any time, without affecting prior processing
To exercise these rights, visit your Profile page or contact us at contact@sunnyredhu.com.
7. Cookies
We use cookies for:
- Essential Cookies: Authentication, session management, region preference
- Payment Cookies: Stripe cookies for secure payment processing and fraud prevention (set only during checkout)
- Analytics Cookies: Google Analytics (only with your consent)
You can manage your cookie preferences through our cookie consent banner or browser settings.
8. Data Security
We implement industry-standard security measures including:
- HTTPS encryption for all data transmission
- Secure cloud infrastructure with Google Cloud Platform
- Regular security audits and updates
- Access controls and authentication
9. International Data Transfers
Your personal data is stored on Google Cloud Platform servers in Belgium (europe-west1 region). In accordance with DPDPA 2023 Section 16(1), we transfer data outside India only to jurisdictions and entities that maintain adequate data protection standards.
We have Data Processing Agreements (DPAs) in place with all third-party processors, including Google Cloud Platform, Resend (email delivery, USA), Upstash (rate limiting, USA), and Cal.com (call scheduling, USA). These agreements include Standard Contractual Clauses (SCCs) and appropriate technical and organisational safeguards.
10. Children's Privacy
Our services are not directed at children under 18. We do not knowingly collect personal data from children under 18.
In accordance with DPDPA 2023 Section 9, processing personal data of a child (under 18 years) requires verifiable consent from the child's parent or lawful guardian before any data is collected or processed. We do not process children's data without such consent.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our website.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. All significant decisions (e.g., course access, payment processing) are handled through standard processes without automated profiling.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: contact@sunnyredhu.com
- Business: Jaipal Redhu (Redhu Engineering)
- Location: #266, Tribune Colony, Kansal, S.A.S. Nagar (Mohali), Punjab, 160103, India
13. Grievance Officer
In accordance with DPDPA 2023 Section 8(1), we have designated the following Grievance Officer to address any concerns or complaints regarding your personal data:
Grievance Officer: Jaipal Redhu
Email: contact@sunnyredhu.com
Address: #266, Tribune Colony, Kansal, S.A.S. Nagar (Mohali), Punjab, 160103, India
The Grievance Officer will acknowledge your complaint within 48 hours and resolve it within 30 days of receipt, in accordance with applicable law.
14. Data Protection Board of India
If you are not satisfied with the Grievance Officer's response, you have the right to escalate your complaint to the Data Protection Board of India (DPBI), established under DPDPA 2023 Section 18. The Board is empowered to hear grievances from data principals and direct remedial action.
For the latest information on filing complaints with the Data Protection Board, visit the Ministry of Electronics and Information Technology website at www.meity.gov.in.