Privacy policy
What we collect, why, who else sees it, and how to get it removed.
This policy explains how Innovgeist Technologies Pvt. Ltd. handles personal data collected through this website. We are the data fiduciary for that data. It is written to comply with the Digital Personal Data Protection Act, 2023.
What we collect
When you enrol a student in a course, we ask for:
- About the student — full name and current class. Optionally, and only if you choose to give them, the board, school, city and the subject the student wants to work on.
- About the parent or guardian — full name, email address, phone number, and relationship to the student.
- Consent — a record that the guardian agreed, the exact wording they agreed to, and when.
- Payment records — the amount, the enrolment reference, and the identifiers Razorpay returns for the order and the payment.
If you create an account to see your enrolments, we also store your email address and a cryptographic hash of your password. We never store the password itself.
If you use the institutional enquiry form, we store the contact details and the message you send.
What we never collect
We never see or store your card number, CVV, UPI PIN, net-banking credentials or any other payment credential. Payment is handled entirely inside the Razorpay checkout. We receive only a confirmation that a payment succeeded and an identifier for it.
We do not collect government identity numbers, biometric data, or any special category of personal data.
Why we collect it
- To create the enrolment and reserve the seat.
- To send the batch schedule and joining link — by email and on WhatsApp, which is how our joining details go out.
- To run the class: know who is expected, and mark the work.
- To take payment, issue receipts, and process refunds.
- To keep the accounting and tax records the law requires us to keep.
- To answer support requests.
We do not sell personal data. We do not use it for behavioural advertising, and we do not run advertising or tracking directed at children.
Children’s data
Our courses are for school students, most of whom are under 18. A student is always enrolled by a parent or guardian, who confirms that they are the parent or legal guardian and consents on the child’s behalf. We keep that consent, and the version of the wording it was given against, as a record.
We collect the minimum needed to teach the class. We do not profile children, do not track them across sites, and do not show them advertising.
Who else sees your data
We share data only with the service providers who make the site work:
- Razorpay — to take payments and process refunds. Razorpay is the controller of the payment-instrument data you enter in their checkout, under their own privacy policy.
- MongoDB Atlas — the database where enrolments are stored.
- Vercel — hosting for this website.
- Our email provider — to send confirmation and joining emails.
- Google Meet and WhatsApp — for running sessions and sending joining details.
We may also disclose data where the law requires it. Beyond that, we do not share it with anyone.
How long we keep it
- Enrolment and student records — for the duration of the course and up to 3 years afterwards, so we can reissue certificates and answer queries.
- Payment and invoice records — for 8 years, as required by tax and company law. These we cannot delete on request.
- Enquiry messages — up to 2 years.
Your rights
Under the DPDP Act you may ask us to:
- tell you what personal data we hold about you or your child;
- correct anything that is wrong or out of date;
- delete it, except where we are legally required to keep it;
- withdraw consent — although this may mean we can no longer run the course for that student;
- nominate someone to exercise these rights if you are unable to.
Write to support@innovgeist.com from the email address used at enrolment. We respond within 2 working days and complete the request within 30 days. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
Security
The site is served over HTTPS. Passwords are stored only as hashes. Access to the database is restricted to the people who need it to run courses. Payments are verified server-side with a cryptographic signature, so a payment cannot be faked from a browser.
No system is perfectly secure. If a breach occurs that affects your data, we will notify you and the Data Protection Board as the law requires.
Cookies
We use a small number of strictly necessary cookies — to keep you signed in to your account and to keep the enrolment form working across a page load. We do not use advertising or cross-site tracking cookies.
Changes to this policy
We will update this page when our practices change, and the date at the top will change with it. For anything material, we will also email people with an active enrolment.
Contact
Questions about this policy go to support@innovgeist.com or +91 81272 73162. Postal details are on the contact page.
