Who we are
We operates Chadura Academy at our Musiri campus, Tamil Nadu, India.
Under the Digital Personal Data Protection Act 2023, we are a data fiduciary in respect of the personal data described in this policy. That means we decide why and how your data is processed, and we are accountable for it.
This policy applies to applicants, enrolled students, and visitors to our website. It should be read together with our Terms & Conditions.
What data we collect
We collect only what we need to admit you, teach you, assess you, and support you.
| Category | What it includes |
|---|---|
| Enquiry data | Name, phone / WhatsApp number, town you commute from, educational background, the programme you're interested in. |
| Admission data | Entry assessment results, interview notes, identity and education documents you provide. |
| Account data | Login credentials for the LMS (passwords are stored in hashed form, never in plain text). |
| Learning data | Attendance, lesson progress, assignments, project submissions, assessment marks, certification status. |
| Examination data | Proctoring records — see Section 5, which explains this in detail. |
| Payment data | Fee payment records and receipts. We do NOT store full card/bank details. |
| Technical data | IP address, device and browser type, and usage logs when you use our website or LMS. |
We collect this data directly from you — through the enquiry form, the application process, your use of the LMS, and your participation in the programme.
Why we use it
We process your personal data for these specific purposes, and no others without telling you:
- To respond to your enquiry — to call you back and book your free entry assessment.
- To assess and admit you — to evaluate your application and communicate the outcome.
- To deliver the programme — LMS access, attendance, trainer support, and scheduling.
- To assess and certify you — to mark your work, run proctored examinations, calculate your score out of 1,200, and issue certificates.
- To administer internships and hiring consideration — for students in the top eight of a cohort.
- To meet legal and financial obligations — receipts, tax records, and statutory requirements.
- To improve the programme — using aggregated, de-identified data about how students learn.
- To send you marketing about our programmes — only if you have separately consented. This is never a condition of enrolment.
We do not sell your personal data to anyone, ever.
Consent & withdrawal
We process your data on the basis of your consent, or where processing is necessary for a legitimate purpose permitted by law.
We ask for consent separately for each distinct purpose. We do not bundle everything into a single "I agree" checkbox. Consenting to enrolment processing is separate from consenting to marketing communications, and refusing marketing does not affect your admission or your place on the programme.
You can withdraw consent at any time by contacting our Grievance Officer (Section 14). Withdrawal takes effect going forward — it does not undo processing already carried out lawfully. Note that withdrawing consent for processing essential to delivering the programme may mean we can no longer provide it to you.
Examination & proctoring data
Our certification is earned through proctored examinations, which means examinations are monitored to protect the integrity of the certificate. This is the most sensitive data we handle, so we explain it separately and plainly.
Our proctoring system captures,
- Identity verification (photo ID check before an exam)
- Webcam images or continuous video recording
- Screen recording or screen capture
- Browser lockdown and tab-switch detection
- Keystroke, timing, or activity logs
- Automated flagging of suspected malpractice
For each of the above, the policy must also state: how long the recording is kept, who inside Chadura can view it, whether any third-party proctoring service processes it, and how a student can challenge an automated malpractice flag.
Students must give specific, informed consent to proctoring before their first examination, separately from general enrolment consent. Proctoring recordings are used solely for examination integrity — never for marketing, never for training AI systems, and never shared with employers.
Who we share data with
We share personal data only with parties who need it to deliver the programme, and only under contract.
Typical categories to map and disclose:
- Cloud hosting provider — where the LMS and CRM run.
- Communication tools — e.g. WhatsApp Business, SMS gateway, email service used to contact you.
- Form or CRM tools — if enquiry data passes through any third-party form or spreadsheet service.
- Payment gateway — for fee collection.
- Proctoring service — if any part of proctoring is provided by a third party.
- Professional advisers — accountants and lawyers, where required.
We may also disclose data where required by law or a court order.
We do not share your data with employers without your consent. If you are placed forward for a job, we tell you first.
Where your data is stored
[DECIDE] — State where data is hosted. Our recommended position, and the simplest to explain: student data is hosted in India.
If any processor stores or processes data outside India — which is common with widely used communication, email, or analytics tools — that cross-border transfer must be identified here. Failing to map overseas transfers is a specific and frequently cited DPDP compliance gap. List each such transfer, the country involved, and the safeguards applied.
How long we keep it
We keep personal data only as long as we need it for the purposes in Section 3, or as long as the law requires. [DECIDE — set a real period for each row below]
| Data | Suggested retention |
|---|---|
| Enquiries that don't convert | Short — e.g. 12 months, then deleted |
| Student records & certification results | Longer — you must be able to verify a certificate years later |
| Proctoring recordings | Shortest possible — delete after results are final |
| Payment & tax records | As required by Indian tax law |
| Marketing contact data | Until you withdraw consent |
When a retention period ends, we delete the data or irreversibly anonymise it.
How we protect it
We apply reasonable security safeguards, including encrypted connections (HTTPS), hashed password storage, role-based access so staff see only what their job requires, regular backups, and access logging.
Only authorised Chadura staff — admissions, trainers, and administrators — can access student data, and only for the purposes described here.
No system is perfectly secure. If something does go wrong, Section 13 explains what we do.
Your rights
Under the Digital Personal Data Protection Act 2023, you have the right to:
- Access — ask what personal data we hold about you and how we use it.
- Correction — have inaccurate or incomplete data corrected or updated.
- Erasure — ask us to delete your data, where we're not required to keep it.
- Withdraw consent — at any time, as described in Section 4.
- Nominate — nominate another person to exercise your rights if you are unable to.
- Grievance redressal — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board of India if unresolved.
To exercise any of these, contact our Grievance Officer (Section 14). We will verify your identity before acting, and respond within a reasonable period. These rights are free to exercise.
Children's data
[DECIDE] — The DPDP Rules require verifiable parental consent before processing the personal data of anyone under 18. Two options:
- Simpler: state that the programme is open only to applicants aged 18 and above, and don't knowingly collect data from under-18s.
- If you accept under-18 applicants: you must build a verifiable parental consent flow before they enrol, and this section must describe it.
Given that some final-year students may be 17, decide this deliberately rather than by omission.
Cookies & website analytics
[DECIDE — list what your site actually uses]
Our website uses cookies necessary for it to function (for example, keeping you logged in). If we use analytics or advertising tools — such as website analytics or advertising pixels — we will name them here and obtain consent where required.
If you run ads pointing at the landing page, any advertising pixel must be disclosed in this section.
Data breaches
If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by law, within the timelines the DPDP Rules prescribe.
We maintain an internal breach response procedure so this can be done quickly. If you believe your data has been compromised, contact our Grievance Officer immediately.
Grievance Officer
Publishing these contact details is a specific requirement under the DPDP Rules.
Email: [DECIDE]
Phone: [DECIDE]
Address: [DECIDE — Musiri campus address]
We will acknowledge your grievance and respond within a reasonable period. If you are not satisfied with our response on a data protection matter, you may escalate to the Data Protection Board of India.
Changes to this policy
We may update this policy as our practices, systems, or the law change. The "last updated" date at the top will always reflect the current version.
Where a change materially affects how we use your data, we will notify enrolled students directly rather than relying on you to check this page.