Privacy Policy

Effective and last updated: August 2, 2026

This Privacy Policy explains how Leap10x Training Private Limited, doing business as Leap10x (“Leap10x,” “we,” “us,” or “our”), handles personal information. It also explains the choices and rights available to individuals.

1. Scope and who we are

This Policy applies to personal information processed through leap10x.in, our applications, dashboards, APIs, AI tools, support, sales and marketing activities, and frontline learning, communications, knowledge-assistance, assessment, messaging, and voice services (collectively, the “Services”). It does not govern a third party's own services or practices, even where the Services link to or interoperate with them.

2. Our privacy roles

We act as the data fiduciary, controller, or similar responsible entity when we decide why and how personal information is processed—for example, website visits, sales enquiries, account administration, billing, and our direct communications.

For learner and workforce information submitted by or for an enterprise customer, Leap10x generally acts as that customer's data processor or service provider. The customer controls the programme, recipients, content, and purposes of processing. Learners should normally direct requests about this information to the employer, client, or organization that invited them; we will assist that customer as required by applicable law and contract.

3. Information we collect

  • Contact and professional information: name, work email, phone number, organization, job title, location, and information submitted in a demo, contact, event, or sales form.
  • Account and administration information: login identifiers, authentication information, permissions, preferences, organization settings, and administrator activity.
  • Customer and learner information: employee or learner identifiers, phone number, language, team, role, location, manager, cohort, and other information selected by the customer.
  • Learning and engagement records: assigned content, delivery and read status, clicks, responses, quiz answers and scores, completion, certificates, feedback, survey responses, and engagement history.
  • Content and communications: documents, SOPs, prompts, questions, messages, support requests, chatbot interactions, and other content provided through the Services.
  • Voice and assessment information: where enabled, call metadata, audio or voice recordings, transcripts, language, responses, rubric scores, and quality or assessment results. Customers are responsible for providing any recording notices or obtaining consent required by law.
  • Transaction information: subscription, invoice, payment status, billing contact, tax, and transaction details. Payment providers may collect payment-card or banking details directly; we ordinarily do not receive complete card details.
  • Device, usage, and log information: IP address, browser and device type, operating system, pages and features used, dates and times, referring URL, approximate location derived from IP, diagnostic events, performance data, and security logs.
  • Cookie and marketing information: cookie identifiers, consent choice, campaign and referral details, and site interaction data as described in our Cookie Policy.

Please do not submit sensitive personal information unless it is necessary for an agreed use case and appropriate safeguards have been arranged with us.

4. Sources of information

We obtain information:

  • directly from you when you visit, submit a form, create an account, communicate with us, or use the Services;
  • from our customers, administrators, employers, partners, or authorized users who enrol learners or configure programmes;
  • automatically through the Services, logs, cookies, and similar technologies;
  • from connected services such as WhatsApp/Meta, telecommunications providers, identity services, calendar tools, or customer-selected integrations; and
  • from lawful public and commercial sources, event organizers, referrals, and business-contact providers for B2B sales and fraud prevention.

5. How we use information

  • provide, configure, personalize, support, and maintain the Services;
  • deliver training and communications, conduct assessments, generate reports, and provide customer-requested integrations;
  • create, translate, summarize, score, retrieve, or otherwise process content using AI-assisted features;
  • authenticate users, administer accounts, process billing, and manage our customer relationship;
  • respond to enquiries and send service, security, support, and administrative communications;
  • send marketing communications where permitted, and measure campaigns and website performance subject to your choices;
  • monitor reliability, troubleshoot, secure the Services, prevent fraud and abuse, and enforce our agreements;
  • analyze and improve features, usability, and performance, including with aggregated or de-identified information;
  • comply with legal obligations, respond to lawful requests, establish or defend legal claims, and protect people, rights, and property; and
  • carry out another purpose disclosed when information is collected or with your direction or consent.

6. Legal bases

Depending on the context and applicable law, we process personal information to perform a contract or take requested pre-contract steps; with consent; for legitimate uses or interests such as providing and securing a B2B service, responding to enquiries, and improving operations; to comply with law; or to protect vital interests. Where we rely on consent, it may be withdrawn for future processing. Where processing is performed for a customer, that customer determines the applicable legal basis.

7. How we disclose information

We may disclose information to:

  • Customers and authorized users: administrators, managers, and other authorized customer personnel according to configured permissions.
  • Vendors and subprocessors: hosting, database, security, communications, WhatsApp/Meta, telecommunications, AI, translation, analytics, sales, scheduling, support, billing, and professional-service providers that process information for us.
  • Customer-directed integrations: third parties when a customer enables an integration or instructs us to transfer information.
  • Professional advisers: auditors, insurers, lawyers, accountants, and advisers subject to appropriate duties of confidentiality.
  • Authorities and affected parties: where reasonably necessary to comply with law or legal process; enforce agreements; detect or prevent fraud, security incidents, or harm; or protect rights, safety, and property.
  • Business transaction participants: actual or prospective buyers, investors, lenders, or advisers in a financing, merger, acquisition, reorganization, or sale, subject to appropriate safeguards.
  • Others at your direction: where you ask us to disclose information or provide valid consent.

We do not sell personal information for monetary payment. We do not use Customer Content to advertise to learners. Optional website analytics and marketing technologies are used only according to the consent choice presented on our site.

7A. Service providers and subprocessors

The following providers are used for our public website, lead handling, or related business operations. A provider is a “subprocessor” only when it processes Customer personal data on Leap10x's behalf; not every provider below performs that role for every Customer or Service.

Provider Purpose Relevant information
VercelWebsite hosting, delivery, and operational analyticsNetwork, device, page, performance, and diagnostic data
SupabaseDatabase and form-submission infrastructureContact, enquiry, attribution, and related submitted information
GoogleGoogle Analytics and Google Tag Manager, subject to optional-cookie consentCookie, device, usage, approximate-location, referral, and event data
MicrosoftClarity interaction analytics; cookieless by default, cookies set only after optional-cookie consentCookie, device, page-interaction, heatmap, and session-replay data
Microsoft AzureCloud hosting, storage, application infrastructure, security, and related platform servicesCustomer Content, account and learner data, message or assessment data, and technical logs as required by the deployed Service
Google Cloud Platform (GCP)Cloud hosting, storage, application infrastructure, data processing, and AI-related platform servicesCustomer Content, account and learner data, message or assessment data, prompts and outputs, and technical logs as required by the deployed Service
ApolloB2B website attribution and sales intelligence, subject to optional-cookie consentBusiness-contact, cookie, device, network, and visit data
CalendlyDemo and meeting scheduling initiated by a visitorContact, availability, scheduling, device, and interaction data
Meta / WhatsAppCustomer-requested WhatsApp messaging and deliveryPhone number, message and delivery metadata, and message content as needed to provide the channel
ElevenLabsAI voice generation, text-to-speech, speech processing, or related voice features where enabledText, prompts, selected voice settings, generated audio, and related technical metadata; voice recordings only where required by the enabled feature
HeyGenAI-generated presenter, avatar, localization, or video features where enabledScripts, prompts, source media, voice or avatar selections, generated media, and related metadata
JioHaptikWhatsApp Business Solution Provider (BSP) used to provide the WhatsApp credit line and related billing enablementLearner mobile number and limited account, billing, or transaction metadata required for that function. JioHaptik does not receive message content from Leap10x.

Product deployments may use additional hosting, communications, telephony, translation, support, security, or AI providers depending on the Customer's configuration and region. The applicable Order, data processing agreement, or current subprocessor register supplied to the Customer identifies those product subprocessors and any agreed notice or objection process. We require subprocessors to protect personal data consistently with our contractual and legal obligations and remain responsible for their processing to the extent required by law and contract.

8. AI features and automated processing

When AI features are used, prompts, source documents, messages, responses, and related context may be sent to contracted AI or infrastructure providers solely to produce the requested feature, subject to our agreements and safeguards. Enterprise Customer Content is not used by Leap10x to train public foundation models. If a different arrangement is proposed, it will require express agreement with the customer.

AI may help generate content, translations, answers, transcripts, or scores, but customers remain responsible for appropriate human review. Leap10x does not use AI to make solely automated employment or other legally significant decisions about learners on its own behalf. Customers must assess their own use of outputs and provide required notices, review, and appeal mechanisms.

9. Cookies and similar technologies

We use necessary browser storage for functions such as remembering cookie choices, attribution during a visit, account sessions, preferences, and security. We use Microsoft Clarity to understand how visitors interact with pages; it runs in a cookieless mode until you accept optional cookies. With your permission, we also use Google Analytics and Google Tag Manager and Apollo website tracking to understand site usage, improve experiences, and support B2B marketing. Those optional tools are not loaded, and Clarity does not set cookies, until you select “Accept optional cookies.” See our Cookie Policy for details and controls.

10. International processing

Leap10x is based in India and may use providers or support operations in other countries. Information may therefore be processed outside your state or country, where laws may differ. Where required, we use contractual, organizational, and technical safeguards and comply with applicable transfer restrictions. Customer-specific hosting or residency commitments, including any EU or US data residency election, are stated in the applicable order or data processing agreement.

11. Retention

We retain information only for as long as reasonably necessary for the purposes described here, including to provide the Services, follow customer instructions, maintain security and business records, comply with law, and resolve disputes. Retention depends on the type and sensitivity of the data, contractual requirements, account status, legal limitation periods, and technical backup cycles. Customer Content is ordinarily handled according to the customer's agreement and deletion instructions; after termination, customers may request an export during the period stated in the Terms. We may retain aggregated or de-identified information that no longer identifies an individual.

12. Security

We maintain technical and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. Leap10x is ISO/IEC 27001:2022 certified. Safeguards include access controls, monitoring, encryption where appropriate, vendor review, incident procedures, and staff security practices. No transmission or storage system is completely secure, and we cannot guarantee absolute security. Please notify us promptly if you suspect unauthorized account use.

13. Your rights and choices

Subject to applicable law and exceptions, you may have the right to:

  • request access to or a summary or copy of your personal information;
  • correct, complete, update, or erase personal information;
  • withdraw consent or object to or restrict certain processing;
  • request portability where legally available;
  • opt out of marketing communications using the unsubscribe method provided;
  • nominate another person to exercise rights where applicable;
  • raise a grievance and, where available, complain to the relevant data protection authority; and
  • not face unlawful retaliation for exercising a privacy right.

Send requests to hello@leap10x.in. We may need to verify your identity and authority. If your information is controlled by a Leap10x customer, contact that customer first; if you contact us, we may refer the request to them. You can control optional website cookies through the banner and browser settings. Withdrawing consent does not affect processing already lawfully completed.

14. Children

Our website and customer-administration Services are not directed to people under 18. A customer may use the Services for younger learners only where permitted by law and after providing required notices and obtaining verifiable parental or guardian consent. We do not knowingly collect a child's information for our own marketing. Contact us if you believe a child provided information without appropriate authorization.

15. Changes to this Policy

We may update this Policy as our Services, practices, or legal obligations change. We will post the revised version and update the effective date. If a change materially affects how we use information, we will provide additional notice where required, such as by email or an in-product message.

16. Contact and grievances

For privacy questions, rights requests, complaints, or grievances, contact our privacy and grievance team using the details below. Please write “Privacy Request” or “Grievance” in the subject and describe your request. We will acknowledge and respond within the period required by applicable law.

Leap10x Training Private Limited

Gurugram, Haryana, India

Email: hello@leap10x.in

Phone: +91 89502 23219