1. Our role under the Act
Prayogbharti Foundation is a Data Fiduciary under section 2(i) of the DPDP Act: we determine the purpose and means of processing the personal data of our students, their guardians, our staff and our partner employers — each of whom is a Data Principal.
We have not been notified as a Significant Data Fiduciary under section 10. We nevertheless apply several section 10 measures voluntarily, including appointing a Data Protection Officer and maintaining an auditable record of processing, because we handle children's data and financial data.
2. Notice and consent (sections 5 and 6)
Our Privacy Policy is the notice required by section 5. It is written in plain language, is available without signing in, and sets out the personal data we collect, the purpose of each item, how to exercise rights, and how to complain to the Board.
Consent obtained through this platform is:
- Free and specific — given for the stated purposes, not bundled with unrelated permissions;
- Informed — the notice is presented before data is collected;
- Unconditional and unambiguous — recorded by a clear affirmative action;
- Limited — to the data necessary for the stated purpose;
- Withdrawable — by writing to our Data Protection Officer, with the same ease as it was given.
Where consent is withdrawn we stop processing within a reasonable period and delete the data, unless retention is required by law or for the limited purposes in section 7.
Consent records are maintained as a record of processing. Where a scholarship or enrolment form is used to obtain consent, the submitted form is retained as evidence of what was disclosed and agreed.
3. Purpose limitation and data minimisation
Personal data is processed only for the purposes listed in section 3 of our Privacy Policy. It is not repurposed for anything else without fresh consent.
Only name and mobile number are mandatory to register a student. Every other field — including Aadhaar number, category, religion and family income — is optional, and is requested only because it determines eligibility for specific scholarship schemes. A student who leaves those fields blank can still enrol and train.
4. Children's data (section 9)
A material proportion of our students are under 18. Section 9 imposes additional duties, which we meet as follows:
| Section 9 obligation | How we meet it |
|---|---|
| Verifiable consent of parent or lawful guardian before processing | Guardian consent is obtained at enrolment, at the training centre, and the guardian's name and contact number are recorded against the student |
| No processing likely to cause detrimental effect on a child's wellbeing | Data is used only to deliver training, award scholarships and support placement |
| No tracking or behavioural monitoring of children | The platform carries no analytics, advertising pixels, profiling or behavioural tracking of any kind |
| No targeted advertising directed at children | The platform serves no advertising at all |
A parent or guardian may exercise every right in section 9 below on the child's behalf.
5. Accuracy (section 8(3))
Students maintain their own contact details, address and photograph through the student portal, so corrections take effect immediately and at source. Centre staff verify identity, income and academic documents before a scholarship is approved, and the verification outcome is recorded against the application.
Where data is used to make a decision that affects a Data Principal — such as scholarship eligibility — the underlying figures are shown alongside the decision, so an error can be identified and challenged.
6. Storage limitation (section 8(7))
Our retention period is 7 years from a Data Principal's last engagement with a programme. This period is configurable by our administrators and is set to meet the record-keeping obligations imposed on us by funders, auditors and government scheme rules.
Certificate records are retained beyond that period, in minimal form, solely so that an issued certificate remains verifiable by a future employer. Retention is reviewed annually, and data no longer required is erased.
7. Reasonable security safeguards (section 8(5))
The technical and organisational measures in place are:
| Measure | Implementation |
|---|---|
| Encryption in transit | HTTPS is enforced across the whole platform, with HTTP Strict Transport Security |
| Access control | Role-based permissions checked on every request; a trainer cannot reach scholarship bank details, a student cannot reach another student's record |
| Authentication | Passwords stored as one-way hashes; optional two-factor verification; sign-in attempts rate-limited |
| Segregation | Application code, configuration and uploaded documents are held outside the public web directory and are not retrievable over the internet |
| Audit trail | Every state-changing action is logged with the actor, timestamp, IP address and payload. Passwords and uploaded file contents are redacted from the log |
| Secrets | Credentials are held in environment configuration readable only by the application account, never in source control |
| Backups | Database and uploaded documents backed up and held securely, with restoration tested periodically |
8. Personal data breach notification (section 8(6))
We maintain a breach response procedure. In the event of a personal data breach we will:
- Contain the breach and preserve evidence;
- Assess the categories of data and the Data Principals affected;
- Notify the Data Protection Board of India in the form and within the time required by the Act and its rules;
- Notify each affected Data Principal directly, describing the nature of the breach, its likely consequences, the measures taken, and what they should do;
- Record the incident and remediate the underlying cause.
9. Data Principal rights (sections 11 to 14)
| Right | How to exercise it |
|---|---|
| Access (s.11) | Email our DPO. We provide a summary of the data held, the processing carried out, and the recipients it has been shared with |
| Correction and erasure (s.12) | Contact details can be corrected directly in the student portal. For anything else, email our DPO |
| Grievance redressal (s.13) | Contact our Grievance Officer. We acknowledge within 3 working days and resolve within 30 days |
| Nomination (s.14) | Email our DPO nominating a person to exercise your rights in the event of death or incapacity |
We respond to all requests within 30 days. There is no charge. We may ask you to verify your identity before disclosing data, so that we do not release your information to someone else.
Data Principals also have duties under section 15, including not impersonating another person and not furnishing false particulars.
10. Data Processors (section 8(2))
We engage processors only under contract, and they process personal data only on our documented instructions. Our processors are:
- Hosting provider — operates the servers on which the platform and its database run;
- Email gateway — delivers transactional notifications;
- SMS gateway — delivers attendance and scholarship alerts;
- WhatsApp Business (Meta) API — where a Data Principal has opted to receive updates on WhatsApp.
We remain accountable to Data Principals for processing carried out on our behalf.
11. Cross-border transfers (section 16)
Personal data is stored on servers located in India. We do not transfer personal data outside India, except where a message is delivered through a communication gateway that routes internationally, and then only the minimum content required to deliver that message. We do not transfer data to any territory restricted by the Central Government.
12. Officers and accountability
| Data Fiduciary | Prayogbharti Foundation 12 Anna Salai, Chennai, Tamil Nadu, 600002, India |
|---|---|
| Data Protection Officer | The Data Protection Officer info@prayogbharti.org |
| Grievance Officer | The Grievance Officer info@prayogbharti.org |
| Response time | Acknowledged in 3 working days, resolved within 30 days |
13. Complaining to the Data Protection Board
If you have raised a grievance with us and are not satisfied with the outcome, or we have not responded within the period above, you may complain to the Data Protection Board of India established under Chapter V of the DPDP Act. We will cooperate fully with any enquiry the Board makes.
14. Review
This statement is reviewed at least annually, and whenever we materially change how personal data is processed, or when the DPDP Rules are amended. It was last reviewed on 14 September 2026.
Contact us
Prayogbharti Foundation
12 Anna Salai, Chennai, Tamil Nadu, 600002, India
Email: info@prayogbharti.org
Phone: +91 44 4000 1000
Web: https://prayogbharti.org