Loading Kurso...
Last updated: September 3, 2026 · Effective from the date of publication on this page
This Privacy Policy describes how Kurso (“Kurso”, “we”, “us”), operated as a sole proprietorship under the trade name KURSO (Udyam Registration No. UDYAM-HR-16-0051480), having its principal place of business at House No. 72, Parawar Road, Maina, Rohtak, Haryana – 124021, India, collects, uses, discloses, and protects personal data in connection with the Kurso platform (the “Platform”), including its website and its Telegram and WhatsApp bot integrations. For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Kurso acts as the Data Fiduciary in respect of the personal data described in this Policy, and you, as a Creator or Student, are a Data Principal.
From Creators:full name, email address, phone number, business/brand name, and, where a Creator connects a payment gateway, gateway account credentials (API keys and webhook secrets), which are encrypted at rest and used solely to process the Creator’s own transactions with their Students.
From Students: full name, email address, phone number, and, where a Student accesses a Product via our Telegram or WhatsApp integrations, their Telegram chat ID or WhatsApp-registered phone number. We also collect enrollment records, payment status (not full card or bank details, which are handled directly by the relevant payment gateway), quiz and assignment submissions, and certificate issuance records.
Anti-piracy and access data:to protect Creator Content, we log which Student accessed which lesson and when, and embed an identifying watermark (the Student’s name and/or identifier) into video playback. This data is used solely to trace unauthorised redistribution of Content and to enforce Section 8 of our Terms & Conditions.
Technical data: IP address, browser and device information, and session identifiers (via a session cookie used to maintain a logged-in state after accessing the Platform through a Telegram or WhatsApp link), collected automatically for security, fraud prevention, and to keep the Platform functioning correctly.
We use personal data to: (a) create and manage Creator and Student accounts; (b) deliver purchased Content to the correct, authorised Student, including via our anti-piracy and watermarking measures; (c) process Creator Subscription Fee payments; (d) issue completion certificates; (e) send transactional communications (enrollment confirmations, lesson notifications, payment receipts, and support responses); (f) investigate and respond to suspected unauthorised redistribution of Content; (g) comply with applicable law and respond to lawful requests from authorities; and (h) improve and maintain the security of the Platform.
We rely on the following categories of third-party service providers to operate the Platform, each of which processes personal data on our behalf and is contractually or by policy restricted from using it for their own purposes:
Supabase (database, authentication, and file storage); Cloudflare (video and ebook file storage and delivery); Upstash (short-lived rate-limiting data, hosted in the Mumbai, India region); Vercel (application hosting); and, where a Creator connects them, Razorpay, Cashfree, or Stripe(payment processing for that Creator’s own transactions). Kurso itself uses Cashfree to process Creator Subscription Fee payments.
Our database, authentication, and file storage (Supabase) and our video/ebook storage (Cloudflare R2) are both hosted in the Asia-Pacific (Mumbai, India) region. Where any other service provider processes personal data outside India, we rely on that provider’s own data protection commitments and take reasonable steps consistent with the DPDP Act.
Some Students on the Platform are under 18 years of age. Where we have actual knowledge that a Data Principal is a child, we do not use their personal data for behavioural monitoring or targeted advertising, in accordance with the DPDP Act. Processing of a child’s personal data is intended to be undertaken only with the verifiable consent of a parent or lawful guardian, obtained at the time of purchase or enrollment.
We are in the process of implementing a dedicated, verifiable parental-consent mechanism as required by the DPDP Act.Until that mechanism is live, the individual completing a purchase or enrollment on behalf of a minor Student is required, under our Terms & Conditions, to confirm that they are the Student’s parent or lawful guardian or are otherwise authorised to act on the guardian’s behalf.
We retain personal data for as long as the relevant account remains active, and thereafter for as long as necessary to comply with our legal obligations (including tax and accounting requirements), resolve disputes, and enforce our agreements. Anti-piracy access logs are retained for a limited period sufficient to investigate reported unauthorised redistribution of Content. A Data Principal may request earlier erasure as described in Section 8, subject to our right to retain data where required by law.
We apply reasonable technical and organisational measures to protect personal data, including encryption of Creator payment gateway credentials at rest, time-limited signed access links for Content (rather than permanent public links), and access controls restricting who can view Student and Creator data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Subject to the DPDP Act, you have the right to: (a) obtain a summary of the personal data we hold about you and the processing activities undertaken; (b) request correction, completion, or updating of your personal data; (c) request erasure of your personal data, unless retention is required for a legal purpose; (d) withdraw any consent previously given, without affecting the lawfulness of processing carried out before withdrawal; (e) nominate another individual to exercise these rights on your behalf in the event of your death or incapacity; and (f) file a grievance with us in the first instance, and thereafter with the Data Protection Board of India if unresolved.
To exercise any of these rights, contact us using the details in Section 11 below.
We use a strictly necessary session cookie to keep you signed in after accessing the Platform through a Telegram or WhatsApp link, and standard authentication cookies for account login on the website. We do not use these cookies for advertising or cross-site tracking.
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act and rules made thereunder.
For any question about this Policy, or to exercise a right described in Section 8, contact our Grievance Officer at support@kurso.in. All requests are personally reviewed by the Platform’s proprietor. See also our Contact page.
We may revise this Policy from time to time to reflect changes in our practices or legal requirements. The “Last updated” date above will be revised accordingly, and material changes will be notified through the Platform.
© 2026 Kurso. All rights reserved.