WeTraders logoWeTraders ← Back to site
Legal

Data Protection Statement

Our DPDP compliance practice, in the open  ·  Last updated: 18 August 2026

Effective date: 18 August 2026
Statement owner: Grievance Officer
Next review: February 2027

1. Purpose of this statement

Our Privacy Policy tells you what personal data we collect and why. This Data Protection Statement sits alongside it and describes how we actually operate — the controls, schedules and procedures we have put in place to meet our obligations as a Data Fiduciary under Indian data protection law.

We publish it because we think a small educational institute should be able to show its working, and because payment partners, platforms and prospective students increasingly ask for it during verification.

2. The legal framework

We process personal data in accordance with:

  • the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
  • the Digital Personal Data Protection Rules, 2025, notified in November 2025;
  • the Information Technology Act, 2000 and the rules made under it, including the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021;
  • directions issued by CERT-In on cyber-security incident reporting; and
  • the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020.

The DPDP Rules follow a phased implementation. The Data Protection Board of India and the definitional framework came into force on notification; the consent-manager registration regime follows at the twelve-month mark; and the full set of substantive operational obligations becomes enforceable on 13 May 2027. We are not waiting for that deadline — the measures described below are in effect now, and will be reviewed and tightened as the remaining provisions come into force.

3. Our role and our data footprint

WeTraders Institute is a Data Fiduciary. Our data footprint is deliberately small:

What we holdRoughly
Enquiry records (name, phone, email, interest)Contact details only
Student records (enrolment, batch, attendance, access)Contact details plus learning records
Payment references (UPI/bank transaction IDs, invoices)Transaction metadata only
Correspondence (email, WhatsApp, support threads)As generated
Website technical logsIP, device, pages viewed

What we deliberately do not hold: trading account or demat credentials, portfolio or holdings data, card numbers, CVVs, UPI PINs, net-banking passwords, Aadhaar numbers, biometric data, health data, or any special-category data. Reducing what we collect is our primary security control — data we never hold cannot be breached.

4. The principles we work to

  • Lawfulness — we process only with consent or under a legitimate use permitted by Section 7 of the DPDP Act. We do not rely on a general “legitimate interests” test, which Indian law does not provide.
  • Purpose limitation — data collected to answer an enquiry is not silently repurposed for marketing. Each purpose is consented to separately.
  • Data minimisation — our forms ask for the fewest fields that will do the job. Optional fields are marked optional and are never a condition of service.
  • Accuracy — you can correct your details at any time by writing to us.
  • Storage limitation — we hold data against the published schedule in Section 8, then delete or anonymise it.
  • Security — reasonable safeguards, proportionate to the sensitivity and volume of what we hold.
  • Accountability — a named Grievance Officer owns this statement and answers for it.

5. Notice and consent in practice

Rule 3 of the DPDP Rules requires notice to be given in clear and plain language, independently of any other information. Our practice:

  • every form that collects personal data carries a standalone notice at the point of collection, itemising what is collected, for what purpose, how to withdraw consent and how to complain;
  • consent is captured by an affirmative action — an unticked checkbox that you tick. We do not use pre-ticked boxes, implied consent or consent bundled across unrelated purposes;
  • marketing consent is separate from enrolment consent, and declining marketing never blocks enrolment;
  • we keep a record of what was consented to and when, so that consent can be evidenced and versioned;
  • the notice is available in English, and we will provide it in any of the languages listed in the Eighth Schedule to the Constitution of India on request to support@ciyindia.com;
  • withdrawal is as easy as giving consent — one email, one reply of STOP, or one click on an unsubscribe link, with no retention call and no friction.

6. Exercising your rights

RightHow to exercise itOur timeline
Access — a summary of your data and processingEmail support@ciyindia.com, subject “Access request”Acknowledge 48 hours; respond 30 days
Correction, completion, updatingEmail support@ciyindia.com with the correct detailsAcknowledge 48 hours; corrected within 7 working days
ErasureEmail support@ciyindia.com, subject “Erasure request”Acknowledge 48 hours; erased within 30 days, except records we must retain by law
Withdraw consentEmail, reply STOP, or unsubscribe linkActioned within 3 working days
NominationEmail support@ciyindia.com naming your nomineeRecorded within 7 working days
GrievanceEmail support@ciyindia.comAcknowledge 48 hours; resolve 30 days

We verify identity proportionately — normally by confirming the request came from the email or phone number already on our records. We do not demand government identity documents to process a rights request unless it is strictly necessary. There is no charge. If we cannot act on a request, we will explain why and tell you how to escalate.

7. Security safeguards

ControlWhat we do
Encryption in transitThe whole Website is served over HTTPS/TLS. Administrative access to all systems is over encrypted connections.
Encryption at restProvided by our managed cloud and email providers as part of their platform.
Access controlLeast-privilege access. Only named staff who need student data to do their job have it, and access is removed the day a person leaves.
AuthenticationUnique, strong credentials, with multi-factor authentication enforced on all administrative, hosting, email and payment-reconciliation accounts.
Managed infrastructureWe use reputable managed providers rather than self-hosted servers, so patching and platform hardening are handled by specialists.
LoggingHosting and access logs are retained for 12 months to support detection and investigation.
BackupsRegular backups of student and financial records, with restoration tested periodically.
Device hygieneStaff devices used for student data are password-protected, kept patched and run current anti-malware.
Vendor diligenceProcessors are engaged under written terms requiring them to act on our instructions only, apply reasonable safeguards, and delete or return data at the end of the engagement.
Staff instructionEveryone handling personal data is briefed on confidentiality, phishing and this statement before being given access.

No system is perfectly secure. These controls reduce risk proportionately to what we hold; they are not a guarantee.

8. Retention and erasure schedule

RecordRetained forThen
Enquiry data (no enrolment followed)24 months from last contactDeleted
Student and enrolment recordsAccess period + 3 yearsDeleted or anonymised
Invoices, receipts, books of account6 years from the end of the financial yearDeleted — statutory minimum under the Income-tax Act, 1961
Marketing contactsUntil consent withdrawn, or 24 months inactiveDeleted
Website and security logs12 monthsDeleted
Grievance and dispute files3 years from closureDeleted, unless a claim is live
Consent recordsFor as long as the related data is held, + 3 yearsDeleted

Erasure means deletion from live systems, with backups aged out on their normal cycle. Where full deletion is not technically possible immediately, the data is put beyond use and deleted at the next backup rotation. Aggregated statistics that cannot identify any individual may be kept indefinitely.

9. Processors and vendors

CategoryUsed for
Cloud hosting — Google Firebase HostingServing the Website; access and security logs
Email and productivity providerStudent correspondence, invoices, document storage
Messaging — WhatsApp, TelegramEnquiries and community groups, under those platforms' own terms
Video conferencingLive classes and mentorship sessions
Banking and UPI channelsReceiving and reconciling fees
Accountant / auditorStatutory accounts and filings

10. Breach response plan

If we become aware of a personal data breach, we follow this sequence:

  1. Contain — immediately, by revoking credentials, isolating the affected account or system and stopping further exposure.
  2. Assess — within 24 hours, establishing the nature and extent of the breach, the categories and approximate number of Data Principals affected, and the likely consequences.
  3. Notify you — without delay, in clear and plain language, describing what happened, the likely consequences, what we have done, and the steps you can take to protect yourself.
  4. Notify the Data Protection Board of India — an initial intimation without delay and a detailed report within 72 hours of becoming aware, or such longer period as the Board allows.
  5. Notify CERT-In — where the incident falls within its reportable categories, within the timeline set by its directions (currently 6 hours of noticing the incident).
  6. Remediate and record — fix the root cause, log the incident, and update controls so it does not recur.

You can report a suspected breach or vulnerability to us at support@ciyindia.com. We will not pursue action against anyone who reports a genuine security issue to us in good faith and gives us reasonable time to fix it.

11. Children and persons with a guardian

Our programmes are for adults aged 18 and over. We do not knowingly process the personal data of a child.

Where the DPDP Act applies to a child or to a person with a disability who has a lawful guardian, it requires verifiable consent from the parent or guardian, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children. We meet this by not enrolling minors and by not carrying out behavioural advertising or tracking of any kind. If we learn that a minor has enrolled, we cancel the enrolment, refund the fee and delete the associated personal data.

12. Significant Data Fiduciary status

The Central Government may designate an entity a Significant Data Fiduciary based on the volume and sensitivity of the personal data it processes and the risk it poses. Given the small volume and low sensitivity of the data we hold, we do not consider ourselves to fall within that class and we have not been so designated.

If we are designated in future, we will appoint an India-based Data Protection Officer, carry out Data Protection Impact Assessments and independent audits, and publish those details here.

13. Cross-border transfers

Some of our providers store data on servers outside India. Under Rule 15 of the DPDP Rules, transfers outside India are permitted except to a country or territory restricted by notification of the Central Government. We track any such notification and will relocate storage or change providers if a restriction affects us. Contractual and technical protections described in this statement apply wherever the data is held.

14. Governance and review

  • The Grievance Officer named below owns this statement and our data-protection practice.
  • We review this statement, our retention schedule and our vendor list at least every six months, and sooner if the law changes, if we adopt a new tool, or if an incident occurs.
  • New staff, trainers and contractors are briefed before being given access to student data, and their access is revoked on the day they stop working with us.
  • Before adopting any new tool that touches personal data, we check what it collects, where it stores it and whether it can be configured to collect less.

15. Grievance and escalation

Grievance OfficerArjun Sahu
Emailsupport@ciyindia.com
Phone / WhatsApp+91 75859 59653
Postal addressInda South, Inda, Kharagpur, West Bengal 721305, India
AcknowledgementWithin 48 hours
ResolutionWithin 30 days

If we do not resolve your complaint to your satisfaction, you may escalate it to the Data Protection Board of India constituted under the DPDP Act, 2023, using the mechanism it publishes. Complaints about the Website or our content may also be raised with the Grievance Officer under our Terms & Conditions.

Note. This statement describes our practices and is provided for transparency. It is not legal advice and does not create rights beyond those given by the DPDP Act, 2023 and other applicable law.