Who we are
HexaLabs runs the website at hexalabs.online and the lab portal at labsoncloud.online. Through them we provide cloud lab machines, cloud sandboxes, official course labs and official certification exam vouchers to training companies, corporate learning and development (L&D) teams and individual learners, mostly in India.
In this policy, “HexaLabs”, “we”, “us” and “our” mean HexaLabs. “You” means anyone who visits the website, contacts us or uses the portal, including learners, trainers and organisation administrators.
When a training company or employer enrols you, that organisation decides why your lab access is set up and receives reports about it. Under the Digital Personal Data Protection Act, 2023 (DPDP Act), the organisation is usually the Data Fiduciary for that data, and we process it on its behalf under our contract with it. For data we collect for our own purposes, such as enquiries sent from the website, we are the Data Fiduciary.
What we collect
We collect only what we need to run the service. The data falls into these groups.
- Enquiry details. When you use the Book a demo form or email us: your name, work email, company, batch size, the labs you are interested in, a preferred demo date and your message.
- Account details. When an organisation or our team sets up portal access for you: your name, email address, organisation, training or batch, role (such as learner, trainer or administrator) and sign-in details.
- Lab usage and activity. The lab machines and sandboxes assigned to you, when they start and stop, hours used, sign-in times and actions you take in the portal, such as starting a machine or raising a support request.
- Sandbox activity. The cloud resources created in a sandbox, and the usage and cost figures the cloud provider reports for them.
- Support messages. Questions you send to us or to the Ask Hexa assistant in the portal, and the machine details attached to a support request.
- Exam voucher details. The learner’s name, email address and the exam a voucher is for, so that the voucher can be issued to the right person and tracked.
- Billing details. For organisations and individuals who buy from us: billing name and address, GSTIN where provided, quotes, orders, invoices and payment records.
- Technical data. IP address, browser and device type, and the server logs created when you load the website or use the portal.
We do not ask for sensitive information such as bank account or card details, health information, biometric data or government identity numbers. Please do not send it to us.
Why we use your data
- To provide labs and sandboxes: create your account, assign and start lab machines and sandboxes, apply time and usage limits, and end access on the agreed date.
- To support you: answer questions, fix problems with a lab and follow up on support requests.
- To report to your organisation: show the organisation that enrolled you which labs were used, by whom and for how long, and completion records where they are part of the service.
- To issue exam vouchers: send each voucher to the right learner and keep a record of it.
- To keep the service secure: detect misuse such as crypto-mining or attacks launched from a lab, protect accounts and investigate incidents.
- To bill and keep records: prepare quotes, orders and invoices, and meet tax and accounting rules.
- To reply to enquiries: arrange a demo and send you the information you asked for.
- To send service messages: for example account set-up, lab start dates, expiry reminders and changes to our policies.
We do not sell personal data.
Legal basis and consent
We process personal data in line with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under them. We rely on the following grounds.
- Consent. When you send us an enquiry or create an account yourself, you consent to us using your data for the purposes in this policy. You can withdraw consent at any time by writing to us. Withdrawal does not affect processing already done, but we may then be unable to keep providing the service to you.
- Your organisation’s basis. When a training company or employer enrols you, it is responsible for having a valid basis under the law, such as your consent or a purpose connected with your employment, to share your details with us. We use that data only to provide the service to that organisation.
- Data given for a specific purpose. Information you give us voluntarily for a particular purpose, such as billing details for an order, is used for that purpose.
- Legal obligations. We may process data to comply with a law, a court order or a lawful request from a government authority, and in other cases the DPDP Act permits.
How long we keep it
- Lab machines and sandboxes are deleted, with everything stored in them, when the access period ends. A lab may also be reset or rebuilt from its starting image before then, for example to fix a fault.
- Account and activity records are kept for as long as needed for the contract with you or your organisation, for the reports the organisation needs and to resolve disputes. After that we delete or anonymise them.
- Invoices and billing records are kept for the periods set by tax and accounting laws.
- Website enquiries are kept while we discuss your request and for a reasonable time afterwards, unless you ask us to delete them sooner.
- Security and system logs are kept for as long as needed to investigate incidents and for the minimum periods set by Indian law, including directions issued by CERT-In under the IT Act, 2000.
Once the purpose is served and no law requires us to keep the data, we delete it.
How we protect it
We use reasonable security practices suited to the data we handle, in line with the IT Act, 2000 and its rules. These include:
- encrypted connections (HTTPS) to the website and the portal;
- access to personal data limited to people who need it for their work;
- network and access controls on lab machines and sandboxes, and limits on what they can be used for;
- monitoring for misuse and security incidents.
No system is completely secure. If a personal data breach affects you, we will inform you and the relevant authorities as the law requires.
Data inside lab machines
Lab machines and sandboxes are for training. Do not store personal data, customer data, passwords for your real accounts or other sensitive information in them.
Do not use your employer’s production credentials, real customer data or your personal cloud accounts in a lab, unless your trainer has asked you to and your organisation allows it.
We do not routinely look at the files or work inside your lab. We may access a lab machine or sandbox to give support you asked for, to fix a fault, or to investigate misuse or a security incident.
Anything left in a lab when access ends is deleted and cannot be recovered.
Your rights
Subject to the DPDP Act and other applicable law, you have the right to:
- Access: get a summary of the personal data we hold about you, how we use it and who we have shared it with.
- Correction: ask us to correct, complete or update inaccurate or incomplete data.
- Erasure: ask us to delete data we no longer need, unless the law requires us to keep it.
- Withdraw consent: where we rely on your consent, withdraw it at any time.
- Nominate: name another person to exercise your rights if you die or become unable to do so.
- Grievance redressal: raise a complaint with us about how your data is handled and receive a response.
To use these rights, email support@hexalabs.online from the address linked to your account. We may ask you to confirm your identity before we act. We will respond within the period the law sets.
If an organisation enrolled you, we may pass your request to it, because it decides what data the training needs. We will tell you when we do this.
If you are not satisfied with our response to a grievance, you may complain to the Data Protection Board of India.
Children
The website and the portal are meant for organisations and adult learners. They are not directed at children under 18.
A learner under 18 may use the portal only when enrolled by a school, college, training company or employer that supervises the training and has obtained verifiable consent from a parent or lawful guardian where the DPDP Act requires it. We do not knowingly collect personal data from children in any other way, and we do not track children or target advertising at them.
If you believe a child has given us personal data without that consent, write to us and we will delete it.
Changes to this policy
We may update this policy when our services or the law change. The date at the top of this page shows the current version. If a change materially affects how we use your data, we will tell account holders by email or in the portal before it takes effect.
Contact and Grievance Officer
For questions about this policy, to use your rights or to raise a grievance, contact our Grievance Officer.
- Email: support@hexalabs.online
- Subject line: Privacy request or Grievance
Please include your name, the email address linked to your account, the organisation that enrolled you (if any) and a short description of your request.
Our Terms of service explain the rules for using the website and the portal.
