Privacy Policy

Privacy Policy

Last Updated: July 14, 2026

Effective Date: January 30, 2026  |  Version 2.0

This Privacy Policy (“Policy”) describes the privacy practices of Vidyaro Education Private Limited (“Vidyaro”, “we”, “us”, or “our”) regarding the collection, use, storage, processing, and disclosure of personal data of users (“you”, “your”, or “Data Principal”) of our website www.vidyaro.com, mobile applications, and related services (collectively, “Platform”).

This Policy is read with our Terms and Conditions. By creating an account and explicitly ticking the consent checkbox at registration, you provide free, specific, informed, unconditional, and unambiguous consent to the processing of your personal data as required under the Digital Personal Data Protection Act, 2023.

If you do not agree with this Policy, please do not use our Platform.

1. Compliance with Indian Data Protection Law

Vidyaro is committed to full compliance with the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), the Information Technology (SPDI) Rules, 2011, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

As a Data Fiduciary under the DPDP Act, Vidyaro:

  • Collects and processes only personal data necessary for the specified purpose
  • Obtains explicit, affirmative consent via a mandatory checkbox before collecting personal data at registration
  • Maintains an immutable audit log of every consent: name, phone, IP address, timestamp, and policy version
  • Provides rights to access, correct, and erase your data
  • Does not transfer personal data outside India except as specified in Section 5
  • Maintains technical and organisational security safeguards per SPDI Rules, 2011

2. Personal Data We Collect

2.1 Data You Provide Directly

  • Identity: Full name, gender
  • Contact: Mobile phone number; email address (optional)
  • Academic: Class/grade, competitive exam preference (e.g., JEE, NEET, WBCHSE)
  • Profile: Profile photo (if uploaded)
  • Payment: Order amounts, payment method type, transaction IDs, coupon codes. We do NOT store card or UPI credentials.
  • Communications: Doubt/support messages, feedback

2.2 Data Collected Automatically & Device Permissions

  • Device & Technical: IP address, browser type and version, OS, device identifiers, FCM push notification token
  • Location: Approximate location (city, state) from IP address — for security monitoring and geo-access controls only
  • Camera & Microphone (Mobile App): Accessed ONLY with your explicit runtime permission to participate in Live interactive classes (WebRTC video/audio). Video/audio feeds are processed in real-time and not used for any other purpose.
  • Storage & Photos (Mobile App): Accessed ONLY to allow you to upload a profile picture, download study materials, or submit doubts.
  • Alarms & Notifications (Mobile App): Exact alarm permissions are used strictly to deliver time-sensitive class reminders locally on your device.
  • Session & Login History: Login timestamps, session IDs, IP at login, device/app type, last online timestamp
  • Learning & Usage Data: Lectures watched, watch time, study progress, quiz/test scores and answers, XP points, pages visited

2.3 Consent & Verification Data

  • Consent Log: At registration we record: name, phone number, IP address, browser/device info, policy version consented to, and exact timestamp — as required by Section 6 of the DPDP Act, 2023. This record is immutable.
  • OTP Verification: Your phone number is shared with Fast2SMS solely to deliver a one-time verification password. OTPs are short-lived and not permanently stored.

2.4 Data We Do NOT Collect

  • We do NOT collect biometric data (fingerprints, facial recognition)
  • We do NOT store credit/debit card numbers or UPI credentials on our servers
  • We do NOT collect Aadhaar or government-issued ID numbers (except where users sign agreements via Digio — applicable only to Mitra/Ambassador partners)

3. How We Use Your Personal Data

We process personal data only for the following specified purposes:

  • Account Creation & Authentication: Register your account and verify identity via OTP
  • Service Delivery: Access to courses, live classes, recorded lectures, tests, and study materials
  • Personalisation: Tailor learning based on class, exam preference, and study patterns
  • Communications: Course updates, class schedules, results, and announcements via SMS, email, and push notifications
  • Payment Processing: Process and reconcile fees through payment partners
  • Security & Fraud Prevention: Enforce single-device restrictions, detect unauthorised access, prevent account sharing
  • Legal Compliance: Maintain consent records (DPDP Act, 2023); comply with court orders and regulations; maintain financial records per tax law
  • Analytics & Improvement: Analyse usage to improve the Platform
  • Customer Support: Respond to queries and resolve disputes

Class Recordings: Live classes are recorded and stored securely. Recordings are accessible only to enrolled students of the relevant batch.

4. Marketing Use of Student Information

With your separate, explicit opt-in consent, Vidyaro may use your name, profile photo, testimonials, and academic achievements for promotional purposes including social media posts, website testimonials, videos, and marketing materials.

You are NOT automatically enrolled in marketing use by creating an account. You may withdraw marketing consent at any time by writing to [email protected].

5. Sharing Your Personal Data

We share personal data with the following third-party processors, only to the extent necessary:

ProcessorPurposeData Shared
Cashfree PaymentsPayment processing & payoutsName, phone, email, order amount
Fast2SMSOTP delivery via SMSPhone number only
Firebase / FCM (Google)Push notificationsFCM device token
Mux Inc.Live video streamingStream metadata only; no personal identifiers
Bunny.netVideo & content delivery (CDN)IP address (CDN routing)
Cloudflare / R2File storage, security, CDNIP address, stored files/media
Digioe-Signing (Mitra/Ambassador agreements only)Name, email, phone of contracting party
Google AnalyticsPlatform usage analyticsAnonymised usage data, IP address

We do NOT sell, rent, or trade your personal data to any third party for marketing. All processors are contractually bound to use data only for the specified purpose.

6. Data Security

We implement reasonable security practices as mandated by the SPDI Rules, 2011:

  • TLS/SSL encryption for all data in transit
  • Secure cloud storage via Cloudflare R2 with strict access controls
  • JWT-based authentication with short-lived tokens and refresh token rotation
  • OTP-based phone verification before account creation
  • Single-device session enforcement against account sharing
  • IP-based login history monitoring with geo-lookup for security alerts
  • Rate limiting and bot protection on all authentication endpoints

Payment Security: We do not store card or UPI credentials. All transactions are processed by Cashfree (PCI-DSS compliant). We retain only transaction ID, amount, and status.

7. Cookies and Tracking Technologies

  • Authentication Cookies: Secure, HTTP-only cookies store session tokens. These are essential and cannot be disabled.
  • Analytics Cookies: Google Analytics tracks anonymised usage. Opt out via browser settings or the Google Analytics Opt-out Add-on.
  • Preference Cookies: Store UI settings for a better experience.

8. Data Retention

  • Account & Profile Data: 10 years from collection or until deletion request
  • Consent Records: For the duration of data processing plus a minimum of 7 years (DPDP Act audit requirement)
  • Login History: 2 years (security audit)
  • Payment Records: 7 years (Income Tax Act, 1961 & GST regulations)
  • Learning Progress Data: Duration of account plus 2 years post-deletion (dispute resolution)

After the retention period, data is securely deleted or irreversibly anonymised.

9. Your Rights & Account Deletion

Under the DPDP Act, 2023 and Google Play Data Safety policies:

  • Account Deletion: You may permanently delete your account and all associated data directly within the app by navigating to Profile > Danger Zone > Request Deletion, or by emailing [email protected]. Data will be erased within 30 days of the request.
  • Right to Access (§11 DPDP): Request a summary of your personal data and processing activities
  • Right to Correction & Erasure (§12 DPDP): Request correction or erasure of data — contact [email protected]
  • Right to Grievance Redressal (§13 DPDP): File a grievance with our Grievance Officer (Section 14). Unresolved grievances may be escalated to the Data Protection Board of India
  • Right to Nominate (§14 DPDP): Nominate an individual to exercise your rights in case of death or incapacity
  • Right to Withdraw Consent (§6 DPDP): Withdraw consent at any time; withdrawal does not affect prior processing but will cease the applicable service
  • Right to Opt-Out of Marketing: Email [email protected] to withdraw marketing consent

Data Export: Request a copy of your personal data by contacting support. We respond within 30 days.

10. Children's Privacy

Our Platform serves students of all ages. Users under 18 must use the Platform under parental or guardian supervision. By allowing a minor to use our Platform, the parent/guardian consents to this Policy on the minor's behalf and takes full responsibility for their use.

11. Geographic Scope and Data Localisation

India Only: Our services are available only in India. Personal data is stored and processed in India. Data is not transferred outside India except as necessary for services in Section 5 (e.g., Mux and Bunny.net CDN), and only as permitted by applicable law.

12. Changes to This Privacy Policy

We may update this Policy periodically. Material changes will be posted with a new “Last Updated” date, and fresh consent will be sought where required by the DPDP Act. The consent version in your consent log corresponds to the Policy version in force at registration.

13. Governing Law and Dispute Resolution

This Policy is governed by the laws of West Bengal, India, including the IT Act, 2000, SPDI Rules, 2011, and the DPDP Act, 2023.

Disputes shall be resolved through arbitration under the Arbitration and Conciliation Act, 1996. Seat: Kolkata, West Bengal. Language: English.

Subject to the Data Principal's right to escalate to the Data Protection Board of India (DPDP Act §27), courts of Kolkata, West Bengal shall have exclusive jurisdiction.

14. Grievance Officer

In accordance with the IT Act, 2000, IT (Intermediary Guidelines) Rules, 2021, and the DPDP Act, 2023:

Grievance Officer — Vidyaro Education Pvt Ltd

For data protection complaints, access/erasure requests, and DPDP Act grievances

Response Time:

Acknowledgement within 24 hours; Resolution within 30 days

Address:

Vidyaro Education Pvt Ltd, Unit No. 706, Om Tower, 7th Floor, 32 Chowringhee Road, Park Street, Kolkata – 700 071, West Bengal, India

Escalation:

Unresolved grievances may be escalated to the Data Protection Board of India at meity.gov.in

15. Contact Us

Vidyaro Education Pvt Ltd

Unit No. 706, Om Tower, 7th Floor, 32 Chowringhee Road, Park Street, Kolkata – 700 071, West Bengal, India

Customer Support:

[email protected]

Grievance Officer:

[email protected]

✓ Your Explicit Consent

By ticking the consent checkbox during account registration, you acknowledge that you have read, understood, and provided free, specific, informed, unconditional, and unambiguous consent to the processing of your personal data as described in this Privacy Policy, in accordance with Section 6 of the Digital Personal Data Protection Act, 2023. A timestamped and versioned record of this consent is maintained by Vidyaro as part of its DPDP compliance obligations.