Data Processing Addendum
Effective Date: May 7, 2026
Version: 1.0
This Data Protection Addendum ("Addendum" or "DPA") forms part of the Terms of Service ("ToS") entered into between: (1) The Customer ("Data Controller") accessing or using the Learnyst LMS platform; and (2) Learnyst Insight Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at #110, Krishna Garden Main Road, Rajarajeshwari Nagar, Bangalore – 560 098, Karnataka, India ("Learnyst" or "Data Processor").
This Addendum is incorporated into and forms an integral part of the Terms of Service between the Parties. All capitalised terms not defined in this Addendum shall have the meanings ascribed to them in the Terms of Service or the Privacy Policy, as applicable. In the event of any conflict between this Addendum and the Terms of Service with respect to data protection matters, the terms of this Addendum shall prevail.
This Addendum applies to the extent that Learnyst processes Personal Data on behalf of the Data Controller in connection with the provision of the Learnyst Platform and associated services. It is intended to ensure that all processing activities are conducted in compliance with applicable Data Protection Laws, including, where applicable, the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”), the California Privacy Rights Act (“CPRA”), and other applicable United States state privacy laws.
Definitions And Interpretation
1.1 Definitions
In this Addendum, the following terms shall have the meanings set out below:
Addendum / DPA: This Data Protection Addendum, including all Annexures attached hereto, as amended or updated from time to time.
Agreement Personal Data: Any Personal Data processed by Learnyst on behalf of the Data Controller in connection with providing the Platform and Services, as described in Annexure A.
Data Controller: The Customer who determines the purposes and means of processing Personal Data, as more particularly described in the Terms of Service.
Data Processor: Learnyst Insight Private Limited, which processes Personal Data on behalf of, and under the instructions of, the Data Controller.
Data Protection Laws: All applicable laws and regulations relating to data protection and privacy, including the DPDPA 2023, EU GDPR (Regulation 2016/679), UK GDPR, CCPA/CPRA, Swiss FADP, and any other applicable national or state data protection legislation, together with all related subordinate legislation, guidance, and codes of practice.
Data Security Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Agreement Personal Data. This does not include unsuccessful attempts or activities that do not compromise Personal Data.
Data Subject: An identified or identifiable natural person to whom the Agreement Personal Data relates, including learners, instructors, administrators, and other end users of the Platform.
Data Subject Request: An actual or purported request, complaint, or notice from or on behalf of a Data Subject exercising their rights under applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, or objection.
Documented Instructions: Written directives issued by the Data Controller to Learnyst specifying the purposes, means, scope, and conditions under which Learnyst is authorised to process Agreement Personal Data.
DPDPA: The Digital Personal Data Protection Act, 2023, enacted by the Parliament of India, and its rules and regulations made thereunder, as amended from time to time.
EEA: The European Economic Area, comprising the Member States of the European Union together with Iceland, Liechtenstein, and Norway.
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data, as amended, supplemented, or replaced from time to time.
Personal Data: Any information relating to an identified or identifiable natural person. This includes, but is not limited to, name, email address, phone number, location data, IP address, device identifiers, learning activity data, and any other data that can directly or indirectly identify an individual. The term includes equivalent concepts under applicable Data Protection Laws, including 'personal information' under the CCPA.
Platform / Services: The Learnyst Learning Management System (LMS) platform, applications, tools, and related services provided by Learnyst under the Terms of Service.
Restricted Transfer: Any transfer of Agreement Personal Data to a country or territory that does not provide an adequate level of protection for Personal Data as determined under applicable Data Protection Laws, including transfers outside India, the EEA, or the UK.
SCCs: The Standard Contractual Clauses for the transfer of Personal Data to third countries as established by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 under the GDPR, and incorporated into this Addendum by reference.
Sensitive Personal Data: Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning a person's sex life or sexual orientation, financial account details, official identifiers (such as Aadhaar or passport numbers), and any other category of data designated as sensitive under applicable Data Protection Laws.
Sub-Processor: Any third party engaged by Learnyst, or by any Learnyst group company, to process Agreement Personal Data in connection with providing the Platform and Services.
Technical and Organisational Measures (TOMs): The security and organisational safeguards implemented to protect Agreement Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
UK Addendum: The International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner under section 199A(1) of the UK Data Protection Act 2018.
1.2 Interpretation
In this Addendum:
(a) Headings are for convenience only and shall not affect interpretation;
(b) References to statutes or legislation include any amendment or re-enactment thereof;
(c) The singular includes the plural and vice versa;
(d) The word 'including' shall be construed without limitation; and
(e) References to 'Clauses' or 'Annexures' are to those in this Addendum unless otherwise specified.
Roles And Relationship Of The Parties
2.1 Controller and Processor
The Parties acknowledge and agree that, in relation to the processing of Agreement Personal Data:
The Data Controller determines the purposes and means of processing Agreement Personal Data and is responsible for ensuring that its instructions to Learnyst comply with all applicable Data Protection Laws.
Learnyst acts as the Data Processor and processes Agreement Personal Data only on behalf of, and in accordance with the Documented Instructions of, the Data Controller, except to the extent required to do otherwise by applicable law.
2.2 Independent Controllership
Notwithstanding Section 2.1, Learnyst may process certain Personal Data as an independent Data Controller for its own legitimate business purposes, such as account management, billing, fraud prevention, platform improvement, and compliance with applicable laws. In such cases, Learnyst's Privacy Policy governs the processing.
Learnyst may additionally process business contact information of the Data Controller’s representatives as an independent controller for account administration, billing, legal compliance, fraud prevention, and business relationship management purposes.
2.3 Data Controller Warranties
The Data Controller represents and warrants that:
It has a lawful basis for processing and for disclosing Agreement Personal Data to Learnyst.
It has provided all necessary notices and obtained all required consents from Data Subjects in connection with the processing contemplated by this Addendum.
Its instructions to Learnyst will at all times comply with applicable Data Protection Laws.
It will not instruct Learnyst to process Personal Data in a manner that would cause Learnyst to violate any applicable Data Protection Law.
The Data Controller is solely responsible for obtaining all necessary parental consents, school authorisations, and lawful permissions required for the processing of Personal Data relating to minors or children under applicable laws.
The Data Controller shall be solely responsible for determining, documenting, and maintaining the lawful basis for processing Personal Data under applicable Data Protection Laws.
Learnyst's Processing Obligations
3.1 Processing in Accordance with Instructions
Learnyst shall:
Process Agreement Personal Data only on the Documented Instructions of the Data Controller, including with regard to international transfers of Agreement Personal Data, unless otherwise required by applicable law, in which case Learnyst shall promptly notify the Data Controller (to the extent permitted by law);
Not sell, rent, or otherwise commercially exploit Agreement Personal Data received in connection with providing the Services for any purpose other than the performance of the Services;
Not retain, use, or disclose Agreement Personal Data outside the scope of its direct business relationship with the Data Controller;
Not combine Agreement Personal Data with Personal Data obtained from any other source, except as necessary for the provision of the Services and as permitted under applicable Data Protection Laws;
Promptly notify the Data Controller if, in Learnyst's reasonable opinion, any Documented Instruction infringes applicable Data Protection Laws.
3.2 Confidentiality
Learnyst shall ensure that all personnel authorised to process Agreement Personal Data are bound by appropriate obligations of confidentiality with respect to such data, and that access to Agreement Personal Data is limited to those personnel who require access for the purpose of providing the Services.
3.3 No Sale of Personal Data
Learnyst confirms that it does not and will not sell Agreement Personal Data. Learnyst shall not share Agreement Personal Data for cross-context behavioral advertising or for any purpose that constitutes a 'sale' or 'share' under the CCPA/CPRA or any other applicable Data Protection Law.
3.4 Notification Obligations
If Learnyst becomes aware that a Documented Instruction would cause it to violate applicable Data Protection Laws, Learnyst shall promptly notify the Data Controller. In such case, Learnyst shall be entitled to suspend the relevant processing until the Data Controller provides modified instructions that are lawful.
3.5 CCPA/CPRA Service Provider Status
To the extent applicable under the CCPA/CPRA, Learnyst acts as a “Service Provider” and/or “Contractor” and shall process Personal Data solely for the limited and specified purposes set out in this Addendum and the Terms of Service.
3.6 HIPAA and Protected Health Information
The Services are not intended for the processing or storage of Protected Health Information (“PHI”) regulated under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), unless expressly agreed by the Parties in writing under a separate agreement. The Data Controller shall not upload, submit, or otherwise process PHI through the Services without Learnyst’s prior written consent.
3.7 Educational and Children’s Data Compliance
Where the Services are used in connection with educational institutions or minors, the Data Controller shall be solely responsible for ensuring compliance with all applicable educational and children’s privacy laws, including FERPA, COPPA, and equivalent laws in other jurisdictions.
Technical And Organisational Security Measures
4.1 Security Obligations
Learnyst shall implement and maintain appropriate Technical and Organisational Measures (TOMs) to ensure a level of security appropriate to the risk presented by the processing of Agreement Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures include, without limitation:
Encryption of Personal Data in transit and at rest using industry-standard protocols (TLS 1.2 or higher for data in transit; AES-256 or equivalent for data at rest);
Ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
Ability to restore the availability and access to Agreement Personal Data in a timely manner in the event of a physical or technical incident;
Regular testing, assessment, and evaluation of the effectiveness of technical and organisational measures for ensuring the security of processing;
Role-based access controls, multi-factor authentication, and audit logging for systems that process Agreement Personal Data;
Regular vulnerability assessments and penetration testing;
Employee training and awareness programmes on data protection and information security;
Business continuity and disaster recovery procedures.
4.2 Annexure B
A more detailed description of Learnyst's current Technical and Organisational Measures is set out in Annexure B to this Addendum. Learnyst may update these measures from time to time, provided that any updates shall not materially diminish the overall level of protection afforded to Agreement Personal Data.
Severity
P0
P1
P2
P3
P4
Data Security Breaches
5.1 Notification
In the event that Learnyst becomes aware of a confirmed Data Security Breach affecting Agreement Personal Data, Learnyst shall:
Notify the Data Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach, to the extent this is reasonably practicable;
Provide the Data Controller with sufficient information to allow it to meet its obligations to notify the relevant supervisory authority and/or affected Data Subjects, including: (a) a description of the nature of the breach; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate number of records concerned; (d) the likely consequences of the breach; and (e) the measures taken or proposed to address the breach.
Take all reasonable steps to investigate, remediate, and mitigate the effects of the Data Security Breach;
Cooperate fully with the Data Controller and provide any information reasonably requested to assist the Data Controller in complying with its legal obligations.
5.2 No Admission
Learnyst's notification of or response to a Data Security Breach shall not be construed as an admission of fault or liability by Learnyst. Learnyst shall not make any public statement or communication regarding a Data Security Breach relating to Agreement Personal Data without the prior written consent of the Data Controller, except as required by applicable law.
5.3 Government Disclosure Requests
Unless prohibited by applicable law, Learnyst shall make commercially reasonable efforts to notify the Data Controller prior to disclosing Agreement Personal Data in response to any legally binding request from a governmental authority, law enforcement agency, or regulatory body.
Data Subject Rights
6.1 Assistance with Data Subject Requests
Learnyst shall, taking into account the nature of the processing, assist the Data Controller by implementing appropriate technical and organisational measures, insofar as this is possible, to fulfil the Data Controller's obligations to respond to Data Subject Requests. Such requests may include, but are not limited to:
Right of access to Personal Data (Article 15, GDPR; Section 11, DPDPA);
Right to rectification or correction of inaccurate data (Article 16, GDPR; Section 12, DPDPA);
Right to erasure or deletion ('right to be forgotten') (Article 17, GDPR; Section 13, DPDPA);
Right to restriction of processing (Article 18, GDPR);
Right to data portability (Article 20, GDPR);
Right to object to processing (Article 21, GDPR);
Rights in relation to automated decision-making (Article 22, GDPR);
Right to opt out of sale or sharing (CCPA/CPRA).
6.2 Forwarding Requests
Where Learnyst receives a Data Subject Request directly from a Data Subject, Learnyst shall promptly forward such request to the Data Controller without responding to the Data Subject, unless the Data Controller has authorised Learnyst in writing to respond on its behalf, or unless Learnyst is required by applicable law to respond directly. Learnyst shall provide all reasonable assistance to enable the Data Controller to respond to Data Subject Requests within applicable statutory time limits.
Sub-Processors
7.1 General Authorisation
The Data Controller hereby provides a general written authorisation to Learnyst to engage Sub-Processors in connection with the provision of the Services, subject to the conditions set out in this Section 7. A list of current Sub-Processors is set out in Annexure C to this Addendum and is available at Learnyst's website at www.learnyst.com/legal.
7.2 Obligations Regarding Sub-Processors
Learnyst shall:
Enter into a written agreement with each Sub-Processor imposing data protection obligations equivalent to those placed on Learnyst under this Addendum, to the extent required by applicable Data Protection Laws;
Remain fully liable to the Data Controller for the acts and omissions of its Sub-Processors to the same extent as if Learnyst had performed the processing itself;
Conduct appropriate due diligence on Sub-Processors prior to engagement and on an ongoing basis to ensure their capability to maintain appropriate security and data protection standards.
7.3 Changes to Sub-Processors
Learnyst shall provide the Data Controller with prior notice of any intended changes concerning the addition or replacement of Sub-Processors ("Sub-Processor Notice") by updating the Sub-Processor list on its website and/or by direct notification. The Data Controller may object to any new or replacement Sub-Processor on reasonable grounds relating to data protection within fourteen (14) calendar days of receipt of the Sub-Processor Notice. If the Parties are unable to resolve the Data Controller's objection within thirty (30) days, the Data Controller may terminate the relevant Services upon written notice, subject to the terms of the ToS.
International Data Transfers
8.1 Restricted Transfers
Learnyst shall not transfer Agreement Personal Data to any country or territory outside India, the EEA, or the UK (each a "Restricted Transfer") unless one of the following conditions is met:
The transfer is to a country or territory that has been designated as providing an adequate level of protection for Personal Data by the competent authority (e.g., European Commission adequacy decision, or Indian government notification);
Appropriate safeguards have been implemented in accordance with applicable Data Protection Laws, including the execution of SCCs and/or the UK Addendum; or
Another derogation or exception under applicable Data Protection Laws applies.
8.2 Standard Contractual Clauses
To the extent that any Agreement Personal Data from the EEA, Switzerland, or the UK is transferred to Learnyst or its Sub-Processors in a country not providing adequate protection, the Parties agree to execute the Standard Contractual Clauses as set out in Commission Implementing Decision (EU) 2021/914 (Module Two: Controller to Processor), which are incorporated into this Addendum by reference. For transfers from the UK, the UK Addendum shall apply in addition. The Annexures to the SCCs shall be populated with the information set out in Annexures A, B, and C of this Addendum, as applicable.
The SCCs and any applicable UK Addendum shall be deemed executed and incorporated by reference automatically upon commencement of any Restricted Transfer subject to applicable Data Protection Laws.
8.3 India Cross-Border Transfers
For transfers of Personal Data of Indian Data Principals outside India, the Parties shall comply with Section 16 of the DPDPA 2023 and any rules or notifications issued thereunder. Learnyst shall only transfer such data to countries or territories permitted by the Government of India or in accordance with applicable transfer mechanisms.
8.4 Remote Access and Global Infrastructure
The Data Controller acknowledges and agrees that the provision of the Services may involve remote access to Agreement Personal Data and the use of globally distributed cloud infrastructure, support systems, and Sub-Processors located in multiple jurisdictions, subject to the safeguards set out in this Addendum.
Audits And Compliance Assistance
9.1 Audit Rights
Learnyst shall make available to the Data Controller all information reasonably necessary to demonstrate compliance with the obligations set out in this Addendum and shall allow for and contribute to audits and inspections conducted by the Data Controller or its appointed auditor, subject to the following conditions:
The Data Controller shall provide Learnyst with at least thirty (30) days prior written notice of any intended audit;
Audits shall be conducted during normal business hours, in a manner that minimises disruption to Learnyst's operations;
The Data Controller (or its auditor) shall execute a confidentiality agreement satisfactory to Learnyst prior to commencing any audit;
The Data Controller shall bear all costs associated with any audit, unless the audit reveals a material non-compliance by Learnyst, in which case Learnyst shall bear reasonable audit costs;
The frequency of audits shall not exceed once per calendar year, unless a Data Security Breach or regulatory investigation requires more frequent audits.
Audits shall primarily be conducted through the review of existing third-part certifications, audit reports, and security documentation made available by Learnyst, unless otherwise required by applicable law or a competent supervisory authority.
9.2 Third-Party Certifications
Learnyst may satisfy its audit obligations under Section 9.1 by providing the Data Controller with relevant third-party certifications, audit reports, or attestations (e.g., ISO 27001, SOC 2 Type II) that are subject to confidentiality obligations, provided such reports are reasonably current and address the scope of Learnyst's data processing activities.
9.3 Regulatory Assistance
Learnyst shall, at the Data Controller's cost, provide all reasonable assistance to enable the Data Controller to conduct data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, as required by applicable Data Protection Laws.
Any assistance requested by the Data Controller beyond Learnyst’s standard obligations under this Addendum may be subject to reasonable additional fees and resource availability.
Data Retention And Deletion
10.1 Retention During Services
Learnyst shall retain Agreement Personal Data for no longer than is necessary for the provision of the Services, unless a longer retention period is required by applicable law or agreed between the Parties in writing.
10.2 Return or Deletion on Termination
Upon the termination or expiry of the Terms of Service, or upon the Data Controller's written request at any time during the term of the Services, Learnyst shall, at the Data Controller's election:
Securely return to the Data Controller a complete copy of all Agreement Personal Data in a commonly used, machine-readable format; or
Securely delete and destroy all Agreement Personal Data and all copies thereof (including data stored by Sub-Processors), and provide the Data Controller with a written certification of deletion.
10.3 Retention for Legal Obligations
Notwithstanding Section 10.2, Learnyst may retain Agreement Personal Data to the extent, and for the period, required by applicable law, provided that Learnyst shall ensure the confidentiality of such data and shall not process it for any other purpose.
Liability And Indemnification
11.1 Mutual Compliance
Each Party shall be liable for its own violations of applicable Data Protection Laws. Where a Party is held liable for any infringement of Data Protection Laws by the other Party, the latter Party shall indemnify the former to the extent that it is liable for the relevant infringement, in accordance with and subject to the limitations in the Terms of Service.
11.2 Limitation of Liability
The Parties' liability to each other under or in connection with this Addendum shall be subject to the limitations and exclusions set out in the Terms of Service, except to the extent that such limitations or exclusions are not permitted by applicable Data Protection Laws.
11.3 Indemnification by Data Controller
The Data Controller shall indemnify, defend, and hold harmless Learnyst and its officers, directors, employees, and agents from and against any claims, damages, penalties, fines, or expenses arising from: (a) the Data Controller's breach of this Addendum; (b) any processing of Personal Data carried out by the Data Controller outside the scope of this Addendum or in violation of applicable Data Protection Laws; or (c) any failure by the Data Controller to provide lawful Documented Instructions.
TERM AND TERMINATION
This Addendum shall commence on the Effective Date and shall remain in force for the duration of the Terms of Service, unless earlier terminated in accordance with its terms. Termination of the Terms of Service shall automatically terminate this Addendum, subject to those provisions which by their nature survive termination, including without limitation Sections 4 (Security), 5 (Data Security Breaches), 10 (Data Retention and Deletion), and 11 (Liability and Indemnification).
The obligations relating to confidentiality, security, international transfers, audit rights, liability, indemnification, and deletion of Agreement Personal Data shall survive termination of this Addendum for so long as Learnyst retains Agreement Personal Data.
Feature
Monthly Active Users
(MAU)
Encrypted Courses
Mock Test
Cohort/Batches
Bundles
Course Certificates
Bandwidth (GB)
Video Hours (Yearly)
Storage in GB (Yearly)
DRM Tokens
Sub Admins & Instructors
Telegram community sales
GOVERNING LAW AND DISPUTE RESOLUTION
13.1 Governing Law
This Addendum shall be governed by and construed in accordance with the laws of India, without prejudice to the mandatory requirements of applicable Data Protection Laws in other jurisdictions. For Data Subjects in the EEA, the provisions of the GDPR and applicable EU Member State legislation shall apply to the extent required by law.
13.2 Jurisdiction
Any disputes arising out of or in connection with this Addendum shall be subject to the exclusive jurisdiction of the courts of Bangalore, Karnataka, India, subject to any mandatory provisions of applicable law regarding jurisdiction for data protection matters.
13.3 Dispute Resolution
Prior to initiating any legal proceedings, the Parties shall attempt in good faith to resolve any dispute arising from this Addendum through escalation to senior management of each Party within thirty (30) days of written notice of the dispute.
14. General Provisions
14.1 Entire Agreement
This Addendum, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, and representations relating to data processing.
14.2 Amendments
Learnyst reserves the right to amend this Addendum from time to time to reflect changes in applicable Data Protection Laws, regulatory guidance, or business practices. Learnyst shall provide the Data Controller with at least thirty (30) days' notice of any material amendments. The Data Controller's continued use of the Platform following the effective date of any amendment shall constitute acceptance of the amended Addendum.
14.2 Amendments
Learnyst reserves the right to amend this Addendum from time to time to reflect changes in applicable Data Protection Laws, regulatory guidance, or business practices. Learnyst shall provide the Data Controller with at least thirty (30) days' notice of any material amendments. The Data Controller's continued use of the Platform following the effective date of any amendment shall constitute acceptance of the amended Addendum.
Non-Renewal and Subscription Expiry
In the event a subscription is not renewed, Learnyst reserves the right to suspend access to the account after 2 days from the subscription expiry date and may permanently delete all associated Data after thirty (30) days from the subscription expiry date.
Learnyst is under no obligation to retain, archive, recover, or restore any Data after subscription expiry. Data deletion may occur at any time after the expiry date and may be irreversible.
Customers are solely responsible for backing up any Data they wish to retain before subscription expiry.
Data Export and Backup
Customers requiring a backup of their Data should take the backup directly from the platform using the course backup feature. You can find it in the Manage section. Credit charges are applied for the same. Where a subscription has already expired, additional charges may apply for any backup, restoration, export, or data recovery services, if such services are available. For any recovery post subscription expiry, users should reach support@learnyst.com within 30 days. Learnyst does not guarantee the availability of backup or recovery services after subscription expiry.
Storage & Learner Usage Optimisation
Learnyst is primarily a Learning Management System (LMS) and is intended to store content and learner data that is actively used for learning purposes, not as a backup or storage service. Dormant Content are the videos or course content uploaded on the platform but not accessed by Learners from the last 30 days.
An Active Learner is a unique learner who performs at least one learning event within the last 30 days. Any learner who does not meet the above criteria is considered an Inactive Learner. Removing dormant content and inactive learners can help optimize storage usage and avoid additional storage charges.
For this purpose, we have the following two features available:
Dormant Content Report
This report highlights content that is not being accessed by any active learner and is currently occupying storage. This may include unpublished courses or courses that do not have any active learners. By deleting such content, you can free up storage and reduce additional storage charges.
Inactive Learners Report
We also provide reports that show inactive learners on the platform. Learners who are no longer actively using the platform can be archived using the Archive Learner feature. This can help keep your learner usage within the prescribed plan limits.
In both of the above cases, you will receive system notifications or the Success Team will reach out to you. We encourage you to delete such inactive learners and dormant storage to optimise app performance & to keep the usage under limits, and prevent overusage.
Account Termination
Upon account cancellation, termination, or prolonged non-renewal, Learnyst may permanently delete all associated Data, content, learner records, configurations, and account information.
Once deleted, Data cannot be recovered. Learnyst shall not be liable for any loss of revenue, business interruption, learner information, content, records, or any other damages arising from such deletion.
Legal and Regulatory Retention
Notwithstanding the above, Learnyst may retain certain billing, tax, legal, security, and audit records, transaction data, invoices, logs, or other information where required by applicable law, regulation, audit requirements, legal process, or legitimate business purposes.
Any such retained information will be handled in accordance with applicable laws and Learnyst's privacy and security practices.
Data Disposal
We retain the data for inactive or non-subscribed accounts (accounts without a paid plan) for 30 days. After 30 days, we will delete the data. Once deleted, Data cannot be recovered. Learnyst shall not be liable for any loss of revenue, business interruption, learner information, content, records, or any other damages arising from such deletion.
Learnyst may permanently delete all associated Data after thirty (30) days from the subscription expiry date.
Learnyst is under no obligation to retain, archive, recover, or restore any Data after subscription expiry. Data deletion may occur at any time after the expiry date and may be irreversible.
Customers are solely responsible for backing up any data. For any recovery post subscription expiry, users should reach support@learnyst.com within 30 days from subscription expiry.







