On this page
- Purpose of this statement
- The legal framework
- Our role and our data footprint
- The principles we work to
- Notice and consent in practice
- Exercising your rights
- Security safeguards
- Retention and erasure schedule
- Processors and vendors
- Breach response plan
- Children and persons with a guardian
- Significant Data Fiduciary status
- Cross-border transfers
- Governance and review
- Grievance and escalation
1. Purpose of this statement
Our Privacy Policy tells you what personal data we collect and why. This Data Protection Statement sits alongside it and describes how we actually operate — the controls, schedules and procedures we have put in place to meet our obligations as a Data Fiduciary under Indian data protection law.
We publish it because we think a small educational institute should be able to show its working, and because payment partners, platforms and prospective students increasingly ask for it during verification.
2. The legal framework
We process personal data in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the Digital Personal Data Protection Rules, 2025, notified in November 2025;
- the Information Technology Act, 2000 and the rules made under it, including the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021;
- directions issued by CERT-In on cyber-security incident reporting; and
- the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020.
The DPDP Rules follow a phased implementation. The Data Protection Board of India and the definitional framework came into force on notification; the consent-manager registration regime follows at the twelve-month mark; and the full set of substantive operational obligations becomes enforceable on 13 May 2027. We are not waiting for that deadline — the measures described below are in effect now, and will be reviewed and tightened as the remaining provisions come into force.
3. Our role and our data footprint
WeTraders Institute is a Data Fiduciary. Our data footprint is deliberately small:
| What we hold | Roughly |
|---|---|
| Enquiry records (name, phone, email, interest) | Contact details only |
| Student records (enrolment, batch, attendance, access) | Contact details plus learning records |
| Payment references (UPI/bank transaction IDs, invoices) | Transaction metadata only |
| Correspondence (email, WhatsApp, support threads) | As generated |
| Website technical logs | IP, device, pages viewed |
What we deliberately do not hold: trading account or demat credentials, portfolio or holdings data, card numbers, CVVs, UPI PINs, net-banking passwords, Aadhaar numbers, biometric data, health data, or any special-category data. Reducing what we collect is our primary security control — data we never hold cannot be breached.
4. The principles we work to
- Lawfulness — we process only with consent or under a legitimate use permitted by Section 7 of the DPDP Act. We do not rely on a general “legitimate interests” test, which Indian law does not provide.
- Purpose limitation — data collected to answer an enquiry is not silently repurposed for marketing. Each purpose is consented to separately.
- Data minimisation — our forms ask for the fewest fields that will do the job. Optional fields are marked optional and are never a condition of service.
- Accuracy — you can correct your details at any time by writing to us.
- Storage limitation — we hold data against the published schedule in Section 8, then delete or anonymise it.
- Security — reasonable safeguards, proportionate to the sensitivity and volume of what we hold.
- Accountability — a named Grievance Officer owns this statement and answers for it.
5. Notice and consent in practice
Rule 3 of the DPDP Rules requires notice to be given in clear and plain language, independently of any other information. Our practice:
- every form that collects personal data carries a standalone notice at the point of collection, itemising what is collected, for what purpose, how to withdraw consent and how to complain;
- consent is captured by an affirmative action — an unticked checkbox that you tick. We do not use pre-ticked boxes, implied consent or consent bundled across unrelated purposes;
- marketing consent is separate from enrolment consent, and declining marketing never blocks enrolment;
- we keep a record of what was consented to and when, so that consent can be evidenced and versioned;
- the notice is available in English, and we will provide it in any of the languages listed in the Eighth Schedule to the Constitution of India on request to support@ciyindia.com;
- withdrawal is as easy as giving consent — one email, one reply of STOP, or one click on an unsubscribe link, with no retention call and no friction.
6. Exercising your rights
| Right | How to exercise it | Our timeline |
|---|---|---|
| Access — a summary of your data and processing | Email support@ciyindia.com, subject “Access request” | Acknowledge 48 hours; respond 30 days |
| Correction, completion, updating | Email support@ciyindia.com with the correct details | Acknowledge 48 hours; corrected within 7 working days |
| Erasure | Email support@ciyindia.com, subject “Erasure request” | Acknowledge 48 hours; erased within 30 days, except records we must retain by law |
| Withdraw consent | Email, reply STOP, or unsubscribe link | Actioned within 3 working days |
| Nomination | Email support@ciyindia.com naming your nominee | Recorded within 7 working days |
| Grievance | Email support@ciyindia.com | Acknowledge 48 hours; resolve 30 days |
We verify identity proportionately — normally by confirming the request came from the email or phone number already on our records. We do not demand government identity documents to process a rights request unless it is strictly necessary. There is no charge. If we cannot act on a request, we will explain why and tell you how to escalate.
7. Security safeguards
| Control | What we do |
|---|---|
| Encryption in transit | The whole Website is served over HTTPS/TLS. Administrative access to all systems is over encrypted connections. |
| Encryption at rest | Provided by our managed cloud and email providers as part of their platform. |
| Access control | Least-privilege access. Only named staff who need student data to do their job have it, and access is removed the day a person leaves. |
| Authentication | Unique, strong credentials, with multi-factor authentication enforced on all administrative, hosting, email and payment-reconciliation accounts. |
| Managed infrastructure | We use reputable managed providers rather than self-hosted servers, so patching and platform hardening are handled by specialists. |
| Logging | Hosting and access logs are retained for 12 months to support detection and investigation. |
| Backups | Regular backups of student and financial records, with restoration tested periodically. |
| Device hygiene | Staff devices used for student data are password-protected, kept patched and run current anti-malware. |
| Vendor diligence | Processors are engaged under written terms requiring them to act on our instructions only, apply reasonable safeguards, and delete or return data at the end of the engagement. |
| Staff instruction | Everyone handling personal data is briefed on confidentiality, phishing and this statement before being given access. |
No system is perfectly secure. These controls reduce risk proportionately to what we hold; they are not a guarantee.
8. Retention and erasure schedule
| Record | Retained for | Then |
|---|---|---|
| Enquiry data (no enrolment followed) | 24 months from last contact | Deleted |
| Student and enrolment records | Access period + 3 years | Deleted or anonymised |
| Invoices, receipts, books of account | 6 years from the end of the financial year | Deleted — statutory minimum under the Income-tax Act, 1961 |
| Marketing contacts | Until consent withdrawn, or 24 months inactive | Deleted |
| Website and security logs | 12 months | Deleted |
| Grievance and dispute files | 3 years from closure | Deleted, unless a claim is live |
| Consent records | For as long as the related data is held, + 3 years | Deleted |
Erasure means deletion from live systems, with backups aged out on their normal cycle. Where full deletion is not technically possible immediately, the data is put beyond use and deleted at the next backup rotation. Aggregated statistics that cannot identify any individual may be kept indefinitely.
9. Processors and vendors
| Category | Used for |
|---|---|
| Cloud hosting — Google Firebase Hosting | Serving the Website; access and security logs |
| Email and productivity provider | Student correspondence, invoices, document storage |
| Messaging — WhatsApp, Telegram | Enquiries and community groups, under those platforms' own terms |
| Video conferencing | Live classes and mentorship sessions |
| Banking and UPI channels | Receiving and reconciling fees |
| Accountant / auditor | Statutory accounts and filings |
10. Breach response plan
If we become aware of a personal data breach, we follow this sequence:
- Contain — immediately, by revoking credentials, isolating the affected account or system and stopping further exposure.
- Assess — within 24 hours, establishing the nature and extent of the breach, the categories and approximate number of Data Principals affected, and the likely consequences.
- Notify you — without delay, in clear and plain language, describing what happened, the likely consequences, what we have done, and the steps you can take to protect yourself.
- Notify the Data Protection Board of India — an initial intimation without delay and a detailed report within 72 hours of becoming aware, or such longer period as the Board allows.
- Notify CERT-In — where the incident falls within its reportable categories, within the timeline set by its directions (currently 6 hours of noticing the incident).
- Remediate and record — fix the root cause, log the incident, and update controls so it does not recur.
You can report a suspected breach or vulnerability to us at support@ciyindia.com. We will not pursue action against anyone who reports a genuine security issue to us in good faith and gives us reasonable time to fix it.
11. Children and persons with a guardian
Our programmes are for adults aged 18 and over. We do not knowingly process the personal data of a child.
Where the DPDP Act applies to a child or to a person with a disability who has a lawful guardian, it requires verifiable consent from the parent or guardian, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children. We meet this by not enrolling minors and by not carrying out behavioural advertising or tracking of any kind. If we learn that a minor has enrolled, we cancel the enrolment, refund the fee and delete the associated personal data.
12. Significant Data Fiduciary status
The Central Government may designate an entity a Significant Data Fiduciary based on the volume and sensitivity of the personal data it processes and the risk it poses. Given the small volume and low sensitivity of the data we hold, we do not consider ourselves to fall within that class and we have not been so designated.
If we are designated in future, we will appoint an India-based Data Protection Officer, carry out Data Protection Impact Assessments and independent audits, and publish those details here.
13. Cross-border transfers
Some of our providers store data on servers outside India. Under Rule 15 of the DPDP Rules, transfers outside India are permitted except to a country or territory restricted by notification of the Central Government. We track any such notification and will relocate storage or change providers if a restriction affects us. Contractual and technical protections described in this statement apply wherever the data is held.
14. Governance and review
- The Grievance Officer named below owns this statement and our data-protection practice.
- We review this statement, our retention schedule and our vendor list at least every six months, and sooner if the law changes, if we adopt a new tool, or if an incident occurs.
- New staff, trainers and contractors are briefed before being given access to student data, and their access is revoked on the day they stop working with us.
- Before adopting any new tool that touches personal data, we check what it collects, where it stores it and whether it can be configured to collect less.
15. Grievance and escalation
| Grievance Officer | Arjun Sahu |
|---|---|
| support@ciyindia.com | |
| Phone / WhatsApp | +91 75859 59653 |
| Postal address | Inda South, Inda, Kharagpur, West Bengal 721305, India |
| Acknowledgement | Within 48 hours |
| Resolution | Within 30 days |
If we do not resolve your complaint to your satisfaction, you may escalate it to the Data Protection Board of India constituted under the DPDP Act, 2023, using the mechanism it publishes. Complaints about the Website or our content may also be raised with the Grievance Officer under our Terms & Conditions.
Note. This statement describes our practices and is provided for transparency. It is not legal advice and does not create rights beyond those given by the DPDP Act, 2023 and other applicable law.
