Examiverse Logo Examiverse
Solutions How it works
Product tour
Product tourThe real software, screen by screen How it worksOne policy in, certified people out Watch a walkthroughA two-minute recorded tour Sample coursesFinished training films, no sign-up
Pricing
Resources
Learn: product guideSet-up, people, courses, languages, LMS export Help CentreAnswers for admins and employees Worked examplesHow real teams roll it out PresentersThe faces and voices in your films
Company
About UsWhy attendance is not proof Our TeamThe people behind Examiverse Trust & securityData protection, DPA, sub-processors Contact SalesPilots, pricing and procurement Contact UsSupport and general questions
Sign In Sign Up
Home
Product tour
Product tour How it works Watch a walkthrough
Solutions Pricing Learn: product guide Help Centre Worked examples About Us Our Team Trust & security Contact Sales Presenters
English
Sign In Sign Up
Home/Legal/Privacy Policy

Privacy Policy

Last updated 26 September 2026·Effective 26 September 2026

Examiverse is AI-native workforce compliance training automation. Organisations use it to turn their own policies into training, test their people in the languages they speak, and keep a record of who is trained for which job. This policy explains what personal data that involves, who is responsible for it, and the choices you have.

On this page

  1. 01Who we are and what this policy covers
  2. 02Our two roles: fiduciary and processor
  3. 03Information we collect
  4. 04How we use it
  5. 05AI processing and your content
  6. 06Public certificate verification
  7. 07Cookies and similar technologies
  8. 08How we share data
  9. 09Where data is stored and processed
  10. 10Security
  11. 11How long we keep data
  12. 12Your rights
  13. 13Children
  14. 14Security incidents
  15. 15Grievance Officer
  16. 16Changes to this policy
  17. —Contact

The short version

  • Your documents, recordings and photographs are used to build your training — never to train any AI model, ours or anyone else’s.
  • For employee records an organisation enters, that organisation is in charge; we process them on its instructions.
  • We do not sell personal data, and we use no advertising cookies or cross-site trackers.
  • Data is stored in the Asia-Pacific region, encrypted in transit and at rest, and isolated per organisation.
  • You can reach our named Grievance Officer at admin@examiverse.com; we acknowledge within 24 hours.

This summary is for convenience. The sections below are the policy.

01Who we are and what this policy covers

Examiverse Technologies Private Limited (CIN U62011KA2026PTC214753), with its registered office in Bengaluru, India ("Examiverse", "we", "us") provides the Examiverse platform.

This policy applies to:

  • The website: examiverse.com and its pages, forms and support chat.
  • The platform: app.examiverse.com, including the admin workspace and the pages employees use to sign in, learn and sit assessments.
  • Certificate verification: the public pages and QR codes that let a third party check a certificate.
  • Communications: sales, onboarding and support conversations by email, phone or chat.

It does not cover the separate practices of the organisations that use Examiverse to train their people. Those organisations publish their own employee privacy notices.

02Our two roles: fiduciary and processor

Data protection law distinguishes between the party that decides why and how personal data is used and the party that handles it on that decision-maker’s behalf. We are each of these in different situations.

  • As Data Fiduciary (controller): for the accounts of administrators and customer contacts, for visitors to our website, for sales and support conversations, and for billing. We decide how this data is used, and this policy is the notice for it.
  • As Data Processor: for the workforce data an organisation enters or syncs about its own employees, and for the training content it uploads. The organisation is the Data Fiduciary for that data; we process it only on its documented instructions, as set out in our Data Processing Agreement.

If you are an employee who was trained through Examiverse, your employer decides what data about you is held and for how long. Please send requests about that data to your employer first. If you contact us directly we will pass your request on promptly and help your employer respond.

03Information we collect

Account and administrator data

  • Identity and contact: name, work email address, job title and, if you choose to give it, a phone number.
  • Organisation details: company name, country, sites, and optional tax or registration identifiers used on invoices.
  • Sign-in: identifiers from our identity provider. We never receive or store an administrator’s password.

Workforce data (processed for the organisation)

  • Employee records: name, employee number, job or role, site, preferred language, joining date and similar fields the organisation chooses to enter or sync from its HR system.
  • Employee sign-in: a PIN chosen for each person, stored only as a salted hash.
  • Training activity: lessons watched, answers given, scores, attempts, knowledge-check results and the dates of each.
  • Certificates: the certificate record, including the course and version, the language it was earned in, its status, and the name, job title and signature image of the person the organisation nominates to sign it.

Content

  • Source documents: policies, SOPs, handbooks, slide decks and other files uploaded to build training.
  • Generated material: lesson plans, courses, films, narration and assessments produced from those documents.
  • Likeness and brand assets: a photograph supplied to create a custom trainer, and company logos.

Payments

  • Card and bank details are entered directly with our PCI-DSS compliant payment processor and never reach our systems. We receive a transaction reference, the amount, the plan and the billing contact.

Usage and device data

  • Service logs: IP address, browser and device type, pages requested, timestamps and error reports, used to run and secure the service.
  • First-party analytics: aggregate page-view counts on our website. We do not use advertising cookies, cross-site trackers or third-party analytics tags.

Communications

  • Enquiries and support: messages you send us through forms, chat, email or phone, and our replies.

04How we use it

We use personal data only for the following purposes:

  • Providing the platform: building courses and assessments, delivering them in each person’s language, marking attempts, issuing and verifying certificates, and sending the reminders an organisation has switched on.
  • Keeping records current: reopening expired certificates, flagging people trained on a superseded version of a policy, and assigning training to new starters by their job.
  • Accounts and billing: creating and administering accounts, collecting payment and issuing tax invoices.
  • Support: answering questions and fixing problems, including viewing an account when you ask us to.
  • Security and integrity: detecting abuse, fraud and unauthorised access, and keeping audit logs.
  • Improving the service: measuring reliability, speed and usage in aggregate. This never involves training an AI model on your content.
  • Legal obligations: tax, accounting, and responding to lawful requests.

We send marketing emails only to people who have agreed to receive them. Agreeing to our Terms is not treated as consent to marketing, and declining marketing never affects your access to the platform.

05AI processing and your content

Examiverse is built on AI, so we state precisely how it touches your data.

  • No training on your content: we do not use uploaded documents, recordings, photographs, answers or workforce records to train, fine-tune or improve any model — ours or any third party’s.
  • Where generation runs: narration, imagery, motion and presenter generation run on models we operate on infrastructure we control.
  • Enterprise AI services: some planning and writing stages call enterprise AI services under terms that prohibit training on customer data and limit how long inputs are retained. They process the text needed for the task and return the result.
  • Custom trainers: a photograph is used only to draw that organisation’s trainer. It is processed with the consent of the person pictured, which the organisation confirms, and it is never used for any other customer.
  • Automated marking: assessments are marked automatically against the lesson they test, and administrators can see each attempt. We do not make employment decisions; any action an employer takes on a result is the employer’s decision.
  • Human access: our staff do not read your content except to provide support you have asked for, to investigate a security or abuse report, or where the law requires it.

06Public certificate verification

Every certificate carries a unique link and QR code so that an auditor, client or regulator can check it without an account. That page shows the person’s name, the course and version, the language, the date, the certificate’s current status, the issuing organisation and its signatory.

  • Only people who hold the link or code can open it; the pages are not listed anywhere and ask search engines not to index them.
  • The organisation controls issuance and can supersede or withdraw a certificate, which the page then reflects.
  • Verification pages remain available after a plan ends, because their purpose is to be checked later, and are removed when the organisation deletes the record or its account.

07Cookies and similar technologies

We keep cookies to the minimum the service needs.

  • Essential: session cookies that keep administrators and employees signed in, and security tokens that protect forms.
  • Preferences: a cookie that remembers the language you chose on our website.
  • Analytics: first-party, aggregate page-view measurement on our website only. No advertising or cross-site tracking cookies are set, so no consent banner is needed for them.

08How we share data

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

We share data only with:

  • Sub-processors that help us run the service, bound by written contracts that require confidentiality, security and use only on our instructions: cloud hosting and storage, edge network and security, compute for rendering and inference, enterprise AI services, identity and sign-in, transactional email, payment processing and customer-support tooling.
  • The organisation you belong to, for workforce data it controls.
  • Anyone you or your organisation choose to show a certificate to, through its verification link.
  • Authorities, when we are legally required to and after checking the request is valid.
  • A successor, if Examiverse is merged or acquired, under the same commitments as this policy.

Customers receive the current named list of sub-processors with our Data Processing Agreement, and we give notice before adding one that processes customer content.

09Where data is stored and processed

We distinguish between where data is stored and where it is briefly processed.

  • Storage: our databases and object storage — accounts, workforce records, certificates, source documents and generated material — are hosted in the Asia-Pacific region.
  • Processing: rendering and inference run on compute in India, Singapore, the United States and Europe. Content is held there only for the duration of a job and then written back to storage.
  • Restricted territories: we do not transfer personal data to any country or territory restricted by the Government of India under section 16 of the Digital Personal Data Protection Act, 2023.
  • Safeguards: where the GDPR applies, transfers outside the European Economic Area are made under appropriate safeguards, as set out in our Data Processing Agreement.
  • Region-pinned processing: available under an enterprise agreement. Please raise it before onboarding.

10Security

We protect data with measures appropriate to its sensitivity, including:

  • Encryption: TLS 1.3 for every connection, and AES-256 encryption at rest.
  • Isolation: every record is keyed to its organisation, and authorisation is checked on each request rather than trusted from the browser.
  • Credentials: no administrator passwords are held by us; employee PINs are stored only as salted hashes.
  • Media: training films are delivered through short-lived signed links, so a copied link stops working.
  • Access: administrative tools are restricted to named staff, deny access by default, and are logged.

Our Trust Centre at examiverse.com/security sets out our controls in detail, including what we are not yet certified for.

11How long we keep data

We keep personal data only as long as the purpose needs it, and our deletion jobs run on a schedule whether or not anyone signs in again.

  • Workforce records and certificates: for as long as the organisation keeps its account, because a certificate is only useful if it can be checked later. Organisations can delete individual people or records at any time.
  • Source documents and generated courses: kept with the course so it can be revised and re-issued; deleted when the course or the account is deleted.
  • Temporary production files: automatically deleted within 72 hours of a job finishing.
  • Service logs: kept for short, fixed periods for security and troubleshooting, then deleted.
  • Account deletion: on request, the account is deactivated at once and can be restored for 30 days. After that, its personal data, content and verification pages are permanently purged.
  • Invoices and financial records: kept for up to eight years, as Indian company and tax law requires. These cannot be deleted on request.

12Your rights

Depending on where you live, you have rights over your personal data under the Digital Personal Data Protection Act, 2023 (India), the GDPR (European Union and United Kingdom), the CCPA (California) and similar laws. They include the right to:

  • Access: obtain a summary of the personal data we process about you and who it has been shared with.
  • Correction: have inaccurate or incomplete data corrected or updated.
  • Erasure: have your data deleted, subject to legal retention duties.
  • Withdraw consent: at any time, as easily as you gave it, without affecting processing already carried out.
  • Portability: receive data you provided in a structured, commonly used format.
  • Objection and restriction: object to certain processing, or ask us to limit it.
  • Nomination: nominate someone to exercise your rights if you die or become incapacitated.
  • Grievance: have a complaint heard and answered, and escalate it to the Data Protection Board of India or your local supervisory authority.

To exercise a right, email admin@examiverse.com. We will verify your identity before acting and respond within the time the law allows. We will never discriminate against you for exercising a right. Employees of our customers should contact their employer first, as explained above.

13Children

Examiverse is a workplace service and is not directed at children. We do not knowingly collect personal data from anyone under 18. Organisations must not enrol a minor without a lawful basis and any verifiable parental consent the law requires. If you believe a child’s data has been provided to us, contact us and we will delete it.

14Security incidents

We maintain an incident response process covering detection, containment, assessment, notification and review.

  • Regulators and individuals: in the event of a personal data breach we will notify the Data Protection Board of India and each affected person as the Digital Personal Data Protection Act, 2023 requires.
  • Customers: we will notify affected organisations without undue delay, and in any case within 72 hours of becoming aware, with the information they need to meet their own obligations.
  • Researchers: report a suspected vulnerability to admin@examiverse.com with “Security” in the subject. We do not pursue researchers who act in good faith, give us reasonable time to fix the issue, and do not access or destroy other people’s data.

15Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and its rules, our Grievance Officer is:

  • Name: Darshan A C
  • Designation: Grievance Officer and Co-founder
  • Email: admin@examiverse.com
  • Address: Examiverse Technologies Private Limited, 73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India

We acknowledge every grievance within 24 hours and aim to resolve it within 30 days.

16Changes to this policy

We will update this policy when our practices or the law change. The date at the top shows when it was last revised. If a change materially affects how we use personal data, we will tell account administrators by email or in the platform before it takes effect.

—Contact

Company

Examiverse Technologies Private Limited

CIN U62011KA2026PTC214753

Grievance Officer

Darshan A C

admin@examiverse.com

Registered office

Examiverse Technologies Private Limited, 73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060, Karnataka, India

Related documents

Trust Centre Controls, residency, retention and our certification position.Data Processing Agreement Our standard DPA for organisations.Terms of Service The agreement for using Examiverse.
Examiverse

AI-native workforce compliance training automation

Upload one policy — every employee is trained, tested and certified in a language they actually speak, and the records keep themselves up to date as people join, move on and fall due again.

Start free Talk to sales

Platform

Product tour How it works Pricing Watch a walkthrough Presenters Sample courses

Who it is for

Government & public services Banks & financial services Hospitals & life sciences Offices & corporate teams Plants, sites & field crews All solutions

Resources

Learn: product guide LMS Studio guide Help Centre Worked examples Start a pilot HR partner programme

Company

About Examiverse Our Team Contact Sales Contact Us

Trust & legal

Trust Centre & security Security whitepaper Data Processing Agreement Privacy Policy Terms of Service Refund Policy
  • DPIIT Recognised Startup · Startup India
  • NVIDIA Inception member
  • DPDP Act 2023 aligned · Grievance Officer named
  • 64 languages

© 2026 Examiverse Technologies Pvt Ltd. All rights reserved.

CIN U62011KA2026PTC214753 · Bengaluru, Karnataka, India