Last Updated: 31 August 2026
This Privacy Policy replaces all earlier versions. Previous versions are available on request from privacy@kodekloud.com.
Zaurac Technologies Pte Ltd (“KodeKloud”, “we”, “us” or “our”) is a company providing an online learning proprietary platform called KodeKloud, accessible at: https://kodekloud.com (“E-Learning Platform” or “Website”). The E-Learning Platform hosts a variety of self-paced and on-demand courses within the fields of Development Operations (DevOps) and Information Technology Administration. We are registered in Singapore, with a corporate registered address at Robinson Road #08-01A, Singapore 048545. We own, operate and manage the Website, mobile applications and all the services provided therein (“Service”).
KodeKloud is the data controller of your personal data processed for purposes set forth herein and, unless expressly specified otherwise, is responsible for the collection, use, disclosure, retention, and protection of your personal data in accordance with our privacy standards, this Privacy Policy, and applicable laws (including the General Data Protection Regulation (EU) 2016/679 (“GDPR”)).
Our privacy policy (“Privacy Policy”) is designed to inform you about our policies and procedures for collecting, using, retaining, processing, transferring, and disclosing your information in connection with your use of the Website and the Service. It also explains what data we collect when you use the Service, why we collect the data, how it is used, and your rights and choices.
This Privacy Policy applies to your use of our website at kodekloud.com and our mobile applications. Some data practices described below – such as cookies used for marketing and interest-based advertising – apply only to our website. Our mobile applications (including the KodeKloud iOS app) do not display third-party advertising and do not use your data for tracking across apps and websites owned by other companies.
This Privacy Policy applies to all users of the Website and Service (together “you” or “Users”).
This Website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Website, we encourage you to read the privacy policy of every website you visit.
This Privacy Policy explains how we process your personal data. Our legal bases for processing are described in Section 6. Where we require your consent to process your personal data, we will ask for your consent to the collection, use, and disclosure of your personal data as described further below. We may provide additional “just-in-time” disclosures or information about the data processing practices of a specific Service. These notices may supplement or clarify our privacy practices or may provide you with additional choices about how we process your data.
Our Privacy Policy applies to all Users as defined in our standard Terms, unless the context indicates otherwise. Our Terms of Service are accessible at https://kodekloud.com/terms-of-service/
If you do not agree with or you are not comfortable with any aspect of this Privacy Policy, you should immediately discontinue access or use of our Website and Service.
“Personal data” (in the context of this Privacy Policy) means any information identifying or describing an identifiable individual, including, but not limited to, information relating to their name, age, gender, email address, username, IP address and any identifying number, address or contact information of the individual.
The following terms “controller”, “processor”, “data subject”, “processing activity/ies”, “pseudonymisation”, “cross-border processing of personal data”, “supervisory authority” used in this document shall have the same meaning as in the GDPR unless relevant to a different law or regulation.
Any other terms which are used throughout this Privacy Policy shall have their respective meanings, as defined in our standard Terms, unless the context indicates otherwise.
In this Privacy Policy, “EEA” means the European Economic Area; “UK GDPR” means the General Data Protection Regulation as it forms part of the law of the United Kingdom; “sub-processor” means a third party we engage to process personal data on our behalf; and “PDPA” means the Singapore Personal Data Protection Act 2012.
Personal data has the meaning given in Section 2. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
We also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity.
We do not seek to collect special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data), and we do not seek to collect information about criminal convictions and offences. We do not use any of these categories of data to make decisions about you, we do not use AI or other technologies to infer emotion or biometric characteristics from you, and we do not build profiles based on them.
Because our AI features and Playgrounds accept free-text prompts, files and code, it is technically possible for you to submit special category data — inside a log file, a sample dataset or a screenshot, for example. We ask you not to. We operate automated filters that seek to block such content before it reaches the model, but these are best-effort and will not catch everything. Content that passes through is retained for the periods set out in Section 9 and then deleted automatically. We do not use it to train models or profile individuals; a limited number of authorised personnel may access it for troubleshooting, security and abuse investigation. If you believe you have submitted special category data, contact privacy@kodekloud.com and we will delete it where technically feasible, unless required by law to retain it.
Important note on AI features: When you use our AI features, the inputs you submit are transmitted to and processed by third-party AI model providers (see Section 8). You should not submit confidential company information, source code from proprietary systems, real credentials (such as API keys, passwords, or contents of .env files), personal data of third parties, or other sensitive information into our AI features or Playgrounds.
Personal data about other people. If you submit personal data about someone else into our AI features or Playgrounds — a colleague's name in a configuration file, or customer records in a sample dataset — it is processed to generate your response and retained for the periods set out in Section 9, where a limited number of authorised personnel may access it for troubleshooting, security and abuse investigation. We will not use it to build a profile of that person and we will not use it to contact them. Because we have no relationship with that person, and no practical way to give them the information Article 14 GDPR requires, we ask you not to submit third-party personal data at all. If you are using the Service in the course of your employment, your employer decides as controller whether submitting such data is lawful (see Section 16).
When you sign-in via a third party (Google, Facebook, LinkedIn), we do not store any of your passwords.
You are not required to provide the requested personal data. However, if you choose not to do so, we will not be able to provide you with our products or services or respond to requests you may have. Thus, where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you.
When you use our mobile applications (such as the KodeKloud iOS or Android apps), we collect and use the following categories of information in addition to the data listed above:
Our mobile applications do not collect your precise GPS location, your contacts, or your photos, microphone or camera content, unless we clearly explain the purpose and ask for your permission in the app.
For our iOS app, we do not use your data for “tracking” as that term is defined by Apple (linking your data or device identifiers with data from other companies’ apps, websites or offline sources for targeted advertising, or sharing it with data brokers). Therefore, our iOS app does not display third-party ads and does not request the App Tracking Transparency (ATT) permission. If we ever decide to use your data for tracking in this sense, we will update this Privacy Policy and request your permission through the ATT framework first.
We use different methods to collect data from and about you including through:
Where you have given your consent, we and our advertising partners may use cookies and similar technologies to understand your interests and to show you advertising for our courses on other websites. Section 7 explains how to give, refuse and withdraw that consent.
We do not use identity-resolution or data-matching services to link your activity on our Website to your email address or postal address for marketing purposes if you are located in the EEA or the United Kingdom.
We use the gathered personal data to provide you with our Service and to ensure our legitimate interests. More specifically, we will use your personal data for the following purposes:
Providing our E-Learning Platform and Service
We use User Account-related data provided by Users in connection with the sign-up, use, or support of the User Account (such as usernames, email address and billing information) to provide you with access to the Service, contact you regarding your use of the Service, or to notify you of important changes to the Service. Such use is necessary for the performance of the contract between you and us (Legal Basis: Performance of Contract).
Provide Information; Respond to Requests
When you ask for information about the Service (for example, when you request a demo or ask us to send you offers or price information), we will use your contact information to respond to your request (Legal Basis: Pre-Contractual Necessity or Legitimate Interest).
Sending Marketing Communications
Where required by applicable law (for example, if you are an EU data subject), we will only send you marketing information by email, or contact you by phone, if you consent to us doing so at the time you provide us with your personal data (Legal Basis: Consent).
When you provide us with your consent to be contacted for marketing purposes, you have the right to withdraw your consent at any time by following the instructions to “opt-out” of receiving marketing communication in each marketing email we send you. In addition, if at any time you do not wish to receive future marketing communications or wish to have your name deleted from our mailing or calling lists, please contact us at privacy@kodekloud.com.
Please note that if you opt-out from marketing communications, we may still contact you regarding issues related to our Service and to respond to your requests.
For our Legitimate Business Interests
We use data relating to your use of and interaction with the Service for certain legitimate business interests, which are the following:
This use of your personal data is necessary for our legitimate interests in understanding how our services are being used by you and to improve your experience on it.
Artificial Intelligence (AI), algorithms and profiling
We utilize Artificial Intelligence (AI) and Machine Learning (ML) technologies to enhance your learning experience. Specifically, we process your Usage Data and Profile Data to:
Some of this constitutes “profiling” under the GDPR. None of it involves automated decision-making of the kind described in Article 22 GDPR. Our AI features produce feedback, recommendations and suggested learning paths; they do not decide whether you pass an assessment, whether a certificate is issued to you, or whether you may access any part of the Service. Decisions of that kind, and any decision to suspend or close an account, are taken by our staff. All AI-generated feedback and recommendations are advisory and you are free to disregard them.
Legal Basis for AI Processing: Where AI is used to deliver the Service you have subscribed to (for example generating feedback on a lab), we rely on Performance of Contract. For personalization and recommendations, we rely on Legitimate Interest. You have the right to object to this profiling as detailed in Section 11.
Any information stored on KodeKloud, or any third-party service that we use, is encrypted and kept securely on the cloud. Access to such information, even at KodeKloud, is done through the best practices while keeping privacy and security of the information.
Generative AI Features (KodeKey, AI Assistant, AI Tutor, AI Playgrounds)
In addition to internal ML algorithms, we offer generative AI features powered by large language models. These include:
When you use these features, the following data is processed:
This data is transmitted to our AI model providers (described in Section 8) for the sole purpose of generating a response. We do not use your AI interaction content to train our own AI models, and we instruct our providers, where possible, not to use this content to train theirs. Where provider defaults already restrict training use (for example, Anthropic and OpenAI’s API tiers), we rely on those defaults.
Legal Basis for Generative AI Processing: We rely on Performance of Contract where the AI feature is part of the Service you have subscribed to. For optional personalization (such as profile-aware AI Tutor responses), we rely on Legitimate Interest, balanced against your right to object.
When browsing the Website (and not the mobile application), we use cookies and similar tracking technologies to collect and use personal data about you and, where you have consented, to serve interest-based advertising. Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
Cookies are typically stored on your computer’s hard drive. Information collected from cookies is used by us to evaluate the effectiveness of our Website, analyze trends and administer our Service. The information collected from cookies allows us to determine such things as which parts of our Website are most visited and what difficulties our users may experience in accessing our Website. With this knowledge, we can improve the quality of your experience by recognizing and delivering more of the most desired features and information, as well as by resolving access difficulties. We also use cookies and/or a technology known as web bugs or clear gifs, which are typically stored in emails to help us confirm your receipt of, and response to, our emails and to provide you with a more personalized experience when using our Website.
We may use one or more third-party service providers, to assist us in better understanding the use of our Website. Our service provider(s) will place cookies on the hard drive of your computer and will receive information that we select that will educate us on such things as how visitors navigate around our Website. Our service provider(s) will analyze this information and provide us with aggregate reports. The information and analysis provided by our service provider(s) will be used to assist us in better understanding our visitors’ interests in our Website and the Service and how to better serve those interests. The information collected by our service provider(s) may be linked to and combined with information that we collect about you while you are using our Service. Our service provider(s) is/are contractually restricted from using the information they receive from our Website for any other purpose than to assist us.
Your cookie choices
Cookies that are strictly necessary for the Website to work — to keep you signed in, to route your session, or to remember the cookie choices you have made — are set without your consent, because you have asked for a service we cannot deliver without them.
Every other cookie and similar technology, including those used for analytics, personalisation and interest-based advertising, is set only if you consent. When you first visit the Website we show you a consent banner that lets you accept all, reject all, or choose category by category. Refusing is as easy as accepting, and we set no non-essential cookie before you have made your choice.
You can change or withdraw your consent at any time, and just as easily, through the cookie settings link in the footer of every page. Withdrawing your consent does not affect the lawfulness of any processing we carried out before you withdrew it.
We do not treat your continued use of the Website, scrolling, or your browser configuration as consent.
We do not disclose or sell your information to third parties or other websites without your consent, except to those necessary to deliver services for us and except as required by law. These third parties and their functions are listed below.
Employees, Service Providers, Business Partners, and Others
We will disclose your personal data to our employees as necessary to deliver the Service, and we may use certain third-party companies and individuals to help us provide, support, analyze, and improve the Service (such as providers of data storage services, maintenance services, payment processing, database management, digital business services, providers of analytics services who help us understand how you use and interact with the Service, providers of digital advertising services, providers of CRM, marketing, sales software solutions, and providers of AI/Large Language Model infrastructure). These third parties may have access to your personal data for the purpose of performing these tasks on our behalf and pursuant to our instructions.
Where we make use of third-party service providers to help us provide the Service to you, including for the purposes of retrieving or delivering information, records, notifications or other messages to you or any users or for hosting or providing any component of our Service, we require such third parties to maintain the confidentiality of any personal data we provide to them for these purposes. Third-party service providers are contractually bound to protect and use such information only for the purposes for which it was disclosed, except as otherwise required or permitted by law. We ensure that such third parties will be bound by terms complying with applicable law.
Our mobile applications do not share personal data with third parties for their own advertising or marketing purposes, and we do not permit third parties to use data from our mobile apps to track you across other companies’ apps or websites.
Sub-Processors for AI and Cloud Services
To deliver our AI features and cloud-based Playgrounds, we share specific categories of your data with certain sub-processors. Each of these sub-processors is contractually bound to process your data only on our instructions and consistent with this Privacy Policy. The categories of recipients we use, and the countries in which they process personal data, are set out below.
A current list naming each sub-processor, the service it provides and the countries in which it processes personal data is available upon request through privacy@kodekloud.com.
International Transfers
As Zaurac Technologies Pte Ltd is headquartered in Singapore, your personal data will be transferred to, and processed in, Singapore and potentially other jurisdictions where our service providers are located. Singapore has not yet been recognized by the European Commission as providing an “adequate” level of data protection.
Where we transfer personal data out of the EEA or the United Kingdom, we assess each recipient and rely on one of the following:
AI and Playground features. If you are located in the EEA or the United Kingdom, prompts you submit to our AI features are routed only to model providers and regions that we have identified in advance and covered by an adequacy decision or by Standard Contractual Clauses. AI models that route to jurisdictions we cannot cover on that basis — currently those hosted in China — are not available to learners in the EEA or the United Kingdom, and we configure our AI gateway to prevent that routing. We publish the current routing position on our sub-processor page.
We engage only with reputed third-party service providers who have security and privacy policies and procedures providing at least the same level of protection as we do ourselves.
Compliance with Laws and Law Enforcement Requests
We may disclose to any competent law enforcement body, regulatory body, government agency, court or other third party the data stored in your User Account and information about you that we collect when we have a good faith belief that disclosure is reasonably necessary to (a) comply with a law, regulation, or compulsory legal request; (b) protect the safety of any person from death or serious bodily injury; (c) prevent fraud or abuse of KodeKloud or its Users; (d) protect KodeKloud’s legal rights; (e) report suspected illegal activity; or (f) investigate violations of this Privacy Policy or our Terms of Service.
Business Transfers
If we are involved in a merger, acquisition, consolidation, liquidation, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction, but we will notify you of any change in control or use of your personal data or Content, or if either become subject to a different Privacy Policy. We will notify you either by sending you an email or posting a notice on our Website. We will also notify you of choices you may have regarding the information.
If you are a registered User, you may review, update or correct the personal data in your User Account. If you would like to delete your User Account, please contact us as indicated below. If your personal data has been shared outside of our Service by other Users or any third parties and not directly by us, we cannot change or delete this personal data out of our control.
We will retain your personal data for as long as is necessary for the purposes set out in this Privacy Policy or for our Service, for as long as your User Account is active, and after it is closed only for as long as we need it to comply with a legal obligation, to resolve a dispute, or to establish, exercise or defend a legal claim. If you wish to delete your User Account please contact us at privacy@kodekloud.com and raise a formal request. Please note that we may retain, use or disclose your information as necessary to comply with our legal obligations, to resolve disputes or enforce our agreements, and legitimate business interest (such as for analytics purposes, safety, and security).
We retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including for legal, accounting, or reporting requirements. Specific retention periods depend on the type of data and purpose.
Retention of AI Interaction Data
AI interaction data is retained as follows:
Where you exercise your right to deletion under Section 11, we will purge AI interaction data associated with your user account from both systems within one month of a verified request, except where retention is required for legal compliance, dispute resolution, or fraud prevention.
You have the right to request the deletion of your personal data or closure of your User Account, subject to applicable laws and any retention requirements outlined in this Privacy Policy (e.g., for legal, accounting, or security purposes). Deleting your data may limit or prevent your access to certain features of the Service. To submit a deletion request:
If we deny your request (e.g., due to legal obligations), we will explain the reasons. For EU data subjects or California residents, additional details on your rights are provided in Sections 11 and 13, respectively. If you have questions about the process, contact us at privacy@kodekloud.com.
If a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee to cover our administrative costs or decline to act on it. If we decline, we will tell you why, and explain that you may seek a judicial remedy.
The security of your information is important to us. We follow generally accepted standards to protect the personal data submitted to us, both during transmission and once we receive it.
The measures we apply include encryption of personal data in transit using TLS and encryption at rest for our production databases; role-based access control, so that access to personal data is limited to those staff who need it for their role; multi-factor authentication for administrative access; logging and monitoring of access to production systems; separation of lab and Playground environments from our production databases; vulnerability scanning and patching; backup and restore testing; and contractual security obligations on our sub-processors.
Taking into account relevant developments in technology including telecommunications and web services, technical limitations associated with different telecommunications protocols, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we shall in relation to the personal data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk.
We use a variety of security measures to ensure the confidentiality of your personal data, and to protect your personal data from loss, theft, unauthorized access, misuse, alteration or destruction. No method of electronic transmission or storage is 100% secure, however. Therefore, we cannot guarantee its absolute security.
Please always check that any website on which you are asked for financial or payment information in relation to our reservations or Service is operated by us or by third-party service providers authorized by us. If you do receive a suspicious request, do not provide your information and report it as set out in this Privacy Policy.
However, we cannot guarantee that loss, misuse, unauthorized acquisition, or alteration of your data will not occur. Please recognize that you play a vital role in protecting your own personal data. You are responsible for keeping your User Account passcode, membership numbers and pin numbers safe and secure. Do not share those with anyone. If there is unauthorized use or any other breach of security involving your information, you must notify us as soon as possible.
Furthermore, we cannot ensure or warrant the security or confidentiality of information you transmit to us or receive from us by internet or wireless connection, including email since we have no way of protecting that information once it leaves and until it reaches us. If you have reason to believe that your data is no longer secure, please contact us using the contact information provided in this Privacy Policy.
Scope
KodeKloud has appointed Buxton Data Solutions Ltd of Despot Slav No. 14 Street, Sofia, Bulgaria as its representative in the European Union. You may contact our EU representative on any matter relating to our processing of personal data of EEA data subjects, in any official language of the European Union, by email to privacy@kodekloud.com or by writing to the address above.This section applies solely to data subjects as defined by the General Data Protection Regulation (“GDPR”) (“EU data subjects”). For these purposes, reference to the EU also includes the European Economic Area countries of Iceland, Liechtenstein and Norway and, where applicable, Switzerland.
This section applies equally to data subjects in the United Kingdom, and references to the GDPR should be read as including the UK GDPR, except where we say otherwise.
In relation to the rights and obligations of EU data subjects, this Privacy Policy should be interpreted in a way that assures maximum compliance with GDPR. Thus, regarding EU data subject, the terms of this Privacy Policy are to be understood in accordance with the meaning given to them by GDPR.
Data Controller
KodeKloud is the data controller for processing of your personal data processed for purposes set forth herein. As we are located outside the EEA, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs), to protect your data during transfer.
Your Rights
Subject to applicable EU law, you have the following rights in relation to your personal data:
You may exercise your rights by contacting us as indicated under the “Contact us” section below. We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection law. We may ask you to verify your identity in order to help us respond efficiently to your request.
Data Protection Officer. We have designated a Data Protection Officer, who is responsible for overseeing our compliance with this Privacy Policy and with applicable data protection law, and who acts independently in performing that role. You can contact the Data Protection Officer at privacy@kodekloud.com, or by writing to us at our registered address marked for the attention of the Data Protection Officer.
Legal Basis for Processing Personal Data and Legitimate Interest
Our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the specific context in which we collect it. If you are an EU resident, we will only process your personal data when one (or more) of the following requirements is met:
If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal data is mandatory or not, as well as of the possible consequences if you do not provide your personal data.
Security and Breach
Security measures: Appropriate technical and organizational measures are implemented to ensure that, by default, the only personal data processed are those which are necessary for each specific purpose of processing. This applies to the quantity, the extent of the processing, the period of storage and the accessibility of the collected personal data. With such measures, we try to ensure that personal data are not made accessible to an indefinite number of persons without your intervention.
In case of a personal data breach: If a personal data breach occurs we shall without undue delay, where feasible, not later than 72 hours after having become aware of it, notify the supervisory authority. This does not apply when the personal data breach is unlikely to result in a risk to your rights and freedoms. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will also inform you without undue delay. This does not apply to situations where we have implemented appropriate technical and organizational protection measures that were applied to the personal data affected by the breach or if our subsequent measures ensure that the risk is no longer likely to materialize. It also does not apply when it would involve disproportionate effort. In the described cases we shall inform you through public communication or similar way in an equally effective manner.
If you are a non-EU User of our Services your personal data may be processed for the purposes described in this Privacy Policy in accordance with the rights described above. The data protection law of your country may give you fewer rights than the GDPR. Where that is so, we will apply the standard required by the law that applies to you. Nothing in this Section limits any right you have under the GDPR or the UK GDPR if you are in the EEA or the United Kingdom.
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), and the California Online Privacy Protection Act (CalOPPA) require us to disclose the categories of Personal Information (as defined in the acts) we collect and how we use it, the categories of sources from whom we collect Personal Information, and the third parties with whom we share it, which we have explained above. We are also required to communicate information about rights California residents have under California law. You may exercise the following rights:
Under California’s “Shine the Light” law, California residents who provide personal information in obtaining products or services for personal, family, or household use are entitled to request and obtain from us once a calendar year information about the customer information we shared, if any, with other businesses for their own direct marketing uses. If applicable, this information would include the categories of customer information and the names and addresses of those businesses with which we shared customer information for the immediately prior calendar year (e.g., requests made in 2026 will receive information regarding 2025 sharing activities).
If you would like to exercise any of these rights or if you would like to receive any further information about these rights, please contact us at any time via email disclosed below. To obtain this information, contact us specifying that you want a “Request for California Privacy Information” on the subject line and in the body of your message. You must include sufficient information regarding your identification as the data subject and a detailed request with the declaration, under the penalty of perjury, that you are exercising your rights for lawful purposes. We will do our best to respond to your valid request (one that meets the described criteria) within 45 days of receiving it. Please be aware that only the required information will be included in our response.
Our Service is intended for users aged 16 and over. In the United Kingdom, and in those EEA Member States that have set a lower age under Article 8(1) GDPR, the applicable threshold may be as low as 13.
At registration we ask you to confirm your date of birth, and we do not knowingly create a User Account for anyone below the applicable age. Where we rely on your consent — for cookies, or for marketing — and you are below the applicable age in your country, we will not rely on that consent unless it is given or authorised by the holder of parental responsibility for you, and we will make reasonable efforts to verify that authorisation, taking into account available technology.
If you believe that a child below the applicable age has registered, please tell us at privacy@kodekloud.com. Where we find that we hold the personal data of a child below the applicable age without the necessary authorisation, we will delete it promptly and close the account.
Our Website may contain certain links to third-party websites (“Third-party Links”) that are not run by us. These include, but are not limited to Facebook, X (formerly Twitter), LinkedIn, YouTube and others. We are not responsible for personal data about you that is collected and stored by these platforms and similar third parties. They have their own privacy policies so please note that this Privacy Policy does not apply to them. For that reason we recommend you to read their privacy policies carefully before submitting personal data to them.
Some of our customers are organisations that buy KodeKloud subscriptions for their people — an employer enrolling its engineering team on a learning plan, for example. If that is how you came to use the Service, two different relationships apply at the same time.
The organisation that enrolled you decides what learning it requires, what progress information it receives about you, and how long your access lasts. For that information the organisation is the controller and we act as its processor. We process it only on the organisation's documented instructions under a data processing agreement that meets Article 28 GDPR. If you want to know what your employer can see, or you want to exercise your data protection rights in relation to it, contact your employer first; we will support them in responding to you.
For everything else — your account credentials, how you use our Website and AI features, your billing relationship with us if you pay us directly, and our own security and analytics — we remain the controller, and the rest of this Privacy Policy applies to you as it does to any other user.
Where we act as a processor, the sub-processors described in Section 8 are engaged as sub-processors of the organisation, and we notify the organisation of changes to them in accordance with our data processing agreement.
Zaurac Technologies Pte Ltd is incorporated in Singapore and is subject to the Personal Data Protection Act 2012 (the “PDPA”) in addition to the laws described above.
Under the PDPA you may withdraw your consent to our collection, use or disclosure of your personal data; ask for access to the personal data we hold about you and for information about how it has been used or disclosed in the year before your request; and ask us to correct an error or omission. We will respond as soon as reasonably possible, and in any event within the time prescribed under the PDPA; if we cannot respond within 30 days we will tell you when we can.
Our Data Protection Officer, whose contact details are in Section 11, is also our Data Protection Officer for PDPA purposes. Where a data breach is notifiable under Part 6A of the PDPA, we will notify the Personal Data Protection Commission and affected individuals as required. Requests under the PDPA should be sent to privacy@kodekloud.com.
This Privacy Policy may change from time to time. If we make a material change to this Privacy Policy, we will provide you with notice (for example, by email if you have provided your email address to us and your email address is current), and we may provide notice of changes in other circumstances as well. It is therefore important that you register with us and notify us if you change your email address. If you do not provide us with a current email address, you should regularly review this policy to ensure that you are informed of any changes.
We keep a record of earlier versions of this Privacy Policy, and you can ask us for one at privacy@kodekloud.com. Where a change affects processing that relies on your consent, we will ask for your consent again rather than rely on notice alone.
If you have any questions about this Privacy Policy, please contact us at privacy@kodekloud.com.
You can also write to us at Zaurac Technologies Pte Ltd, Robinson Road #08-01A, Singapore 048545. Our Data Protection Officer can be reached at the same email address. The contact details of our EU and UK representatives are in Section 11.
If you are in the EEA or the United Kingdom and you are not satisfied with how we have handled your request, you have the right to complain to your local supervisory authority. In Bulgaria, where our EU representative is established, that is the Commission for Personal Data Protection. In the United Kingdom it is the Information Commissioner's Office. In Singapore you may complain to the Personal Data Protection Commission.