Legal
Privacy Policy
Last updated: 17 September 2026
Collection of Information
The Provider may receive, collect and store information voluntarily provided by the Receiver/s through the Website, Application, registration forms,program enrollment, course enrollment, assessments, communications, transactions, scholarship quizzes, digital marketing processes, support interactions or any other permitted means of using the Services.
The information collected may include, as applicable:
- Name, age/date of birth, gender and contact details;
- Email address, mobile number and communication details;
- Login and account information;
- Address, city, state, country or general location;
- School, college, class, academic and educational information;
- Past and current academic, career and relevant life-related information;
- Course, assessment and programme participation details;
- Payment and transaction-related information;
- Feedback, comments, reviews, recommendations and communications;
- Information voluntarily submitted through services (Program and/or course) tasks, worksheets, activities, forms and assessments; and
- Other information reasonably required to provide, administer, secure and improve the Services.
The Provider may also automatically collect certain technical and usage information, including IP address, device type, browser, operating system, connection information, access times, pages visited, session information, page-response times, duration of visits, interaction with webpages and methods used to navigate away from webpages.
The Provider may use cookies and similar technologies for website functionality, security, analytics, performance monitoring and other permitted purposes.
Academic, Career and Personal Development Information
For providing career-development, mentoring, Skill-Build courses, assessments and related Services, the Provider may collect information concerning the Receiver's academic background, interests, aspirations, career preferences, experiences, habits, routines, goals, challenges and other relevant educational or developmental information voluntarily shared by the Receiver.
Such information may be used to understand the Receiver/s background and requirements and to provide more relevant educational, career-development and personalised guidance.
The Provider does not represent that any guidance, recommendation, assessment or output constitutes a guarantee of admission, employment, career success, academic performance or any particular or any specific targeted future outcome.
Course Tasks, Responses and User-Generated Information
During Skill-Build courses and related Services, the Receiver may voluntarily provide information through daily tasks, worksheets, questions, activities, assessments, reflections, feedback and other course interactions.
Such information may include the Receiver's:
- Answers and inputs;
- Ideas and opinions;
- Experiences and observations;
- Goals and aspirations;
- Personal reflections;
- Emotions or perceptions;
- Real-life situations;
- Images/ videos of their daily life and development;
- Images/ videos and feedbacks of trusted people;
- Facts and assumptions; and
- Other information voluntarily shared during participation.
Such information may be used for providing the relevant Services, personalised feedback, course administration, improving course quality, developing better learning material, improving systems and processes, and enhancing the overall User experience.
The Provider shall take reasonable measures to protect such information and shall not intentionally disclose identifiable personal information to unrelated persons except where permitted or required under this Privacy Policy, applicable law, or necessary for providing the Services.
Use of Course and Assessment Information for Service Improvement
Information generated through the use of the Services may be analysed in individual and/or aggregated form to:
- Improve course content and formats;
- Develop better learning activities and resources;
- Improve internal processes and systems;
- Improve customer and technical support;
- Train and improve the direct and indirect team members, third party agencies working for the Provider, where applicable
- Train and improve the permitted technology systems, including learning-management systems, automated tools, bots and machine-learning systems, where applicable;
- Identify common learning and engagement patterns;
- Develop improved educational and career-development approaches; and
- Maintain and improve the quality, relevance and effectiveness of the Services.
Where information is used in aggregated, anonymised or de-identified form, the Provider may use such information for research, analytics, business planning, product development, service improvement and other lawful purposes without intending to identify an individual Receiver.
Personalisation of Services
The Provider may use information provided by the Receiver, together with information generated through the Receiver's continued use of the Services, to improve the Receiver's experience and provide more relevant content, responses, feedback, guidance and support.
The Provider may also use aggregated and appropriately de-identified information from multiple Receivers to identify common patterns and improve automated or technology-assisted responses, suggestions, feedback and support available through the Services.
Any automated or technology-assisted response is intended as an educational or developmental aid and may not always be accurate, complete or suitable for every individual circumstance.
Analytics and Marketing
The Provider may analyse aggregated, statistical, anonymised or de-identified information to understand general User behaviour, preferences, engagement and requirements.
Such analysis may be used to plan and improve the Provider's online and offline marketing, communication and service offerings, including relevant courses, programmes, services, discounts, offers, launches, updates, additions and other initiatives.
Where marketing communication requires consent under applicable law, such communication shall be undertaken subject to the applicable consent and opt-out requirements.
The Provider shall not intentionally use a child's personal data for targeted advertising or other prohibited purposes where such processing is restricted under applicable law
Purposes for Which Personal Data May Be Used
Personal information collected from the Receiver may be used for the following purposes:
a. Providing and operating the Services: To register the Receiver, process enrolments, deliver courses and assessments, administer accounts, provide reports, track participation and provide related Services.
b. Customer and technical support: To provide ongoing customer assistance, resolve technical issues, respond to enquiries and support the Receiver before, during and after provision of the Services.
c. Personalised support: To provide relevant educational, developmental, career-related and course-related guidance based on information voluntarily provided by the Receiver.
d. Communication: To send account, course, assessment, payment, security, service and other necessary communications and, where permitted, promotional communications.
e. Analytics and improvement: To create aggregated, statistical, anonymised or de-identified information for improving Services, technology, systems, processes, courses and User experience.
f. Business administration: To maintain records, process payments, manage subscriptions/enrolments, cancellations, refunds, complaints, grievances and other administrative requirements.
g. Legal and regulatory compliance: To comply with applicable laws, regulations, lawful directions, taxation, accounting, security and other legal requirements and to establish, exercise or defend legal rights.
Payment and Transaction Information
When the Receiver conducts a transaction through the Website or other authorised payment mechanism, the Provider may collect information necessary to process and record the transaction, including:
- Name;
- Contact details;
- Age/class, where relevant to the Service;
- Billing or address information, where required;
- Service/course purchased;
- Transaction amount;
- Transaction reference;
- Payment status; and
- Other information reasonably required for payment administration.
Payment-card, banking, UPI and other financial credentials may be processed directly by the applicable payment gateway or financial institution.
The Provider shall not intentionally request or retain payment credentials that it does not reasonably require for processing or administering the transaction.
AWS – Hosting and Data Infrastructure
The Provider uses Amazon Web Services (AWS) for hosting and supporting portions of its online infrastructure and digital Services.
The Website, Skill-Build courses and related digital systems may use AWS infrastructure for hosting, storage, databases, computing and other technical functions.
Personal data may therefore be processed or stored through AWS infrastructure as required for providing the Services.
AWS and its applicable infrastructure are subject to their own contractual, technical, security and privacy frameworks. The Provider shall use reasonable measures to configure and manage its systems and access controls appropriately.
The use of AWS does not mean that the Provider guarantees that information is completely immune from every possible cyberattack, technical failure or security incident.
Payment Gateway – Cashfree
The Provider uses Cashfree Payments and/or its applicable payment-processing infrastructure for processing online transactions.
Cashfree may process payment-related information required to complete transactions through applicable payment methods, including cards, UPI, net banking and other supported payment mechanisms.
Payment links may also be generated for individual or bulk transactions where applicable.
Where supported, payments may be made through UPI applications, banks or other payment methods made available through the payment gateway.
Financial and payment information transmitted through the payment gateway is subject to the security, privacy, compliance and processing practices applicable to Cashfree and the relevant financial institutions.
The Provider does not guarantee that any electronic payment environment is completely free from security risks, and the Receiver should also review the applicable terms and privacy practices of the relevant payment service provider.
Sharing of Personal Data with Service Providers
The Provider may provide relevant personal data to third-party service providers where reasonably necessary to provide, operate, administer, secure or improve the Services.
Such service providers may include providers of:
- Website hosting and cloud infrastructure;
- Payment processing;
- Psychometric and assessment services;
- Learning-management systems;
- Software and technology development;
- Customer support;
- Communication services;
- Analytics;
- Cybersecurity;
- Webinar or virtual-event infrastructure; and
- Other operational or technical services.
Such information shall be limited, where reasonably practicable, to the information necessary for the relevant service or purpose.
The Provider shall not treat personal data as a commodity for unrestricted sale or disclosure.
Personal data may also be disclosed where required or permitted by applicable law, lawful governmental or regulatory directions, court orders, dispute resolution, fraud prevention, security requirements or protection of the Provider's legal rights
Communication with the Receiver
The Provider may contact the Receiver through email, telephone, SMS, WhatsApp, postal communication or other available communication channels for purposes including:
- Account administration;
- Course and assessment updates;
- Technical support;
- Payment and transaction matters;
- Resolving disputes or complaints;
- Collection of legitimate outstanding amounts;
- Surveys and feedback;
- Service updates;
- Security-related notifications;
- Changes to Services or policies;
- Enforcement of applicable agreements; and
- Other communications reasonably necessary for providing or administering the Services.
Promotional communications shall be subject to applicable consent and opt-out requirements.
The Receiver may opt out of promotional communications; however, essential service-related, transactional, security and legally required communications may continue.
Protection of Personal Data
The Provider shall take reasonable technical, administrative and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, misuse or destruction.
Security measures may include access controls, authentication, restricted internal access, secure transmission, backups, monitoring, logging, security updates and other appropriate safeguards.
Where applicable, the Provider and relevant service providers may follow recognised payment-security, information-security and applicable legal requirements.
However, no online platform, electronic transmission, storage system or internet-based service can be guaranteed to be completely secure. Accordingly, the Provider does not guarantee absolute security against every possible cyberattack, system failure, data breach or other security incident.
Where a personal-data breach occurs and notification or other action is required under applicable law, the Provider shall take reasonable steps to contain, investigate, mitigate and address the incident and provide required notifications.
Children's and Minors' Personal Data
The Services may be used by students who are minors.
Where applicable law requires verifiable consent of a parent or lawful guardian before processing a child's personal data, the Provider shall obtain or facilitate such consent in the manner required by applicable law.
The Provider shall take reasonable measures to ensure that children's personal data is processed only for lawful and appropriate purposes connected with the Services.
The Provider shall not knowingly undertake tracking, behavioural monitoring or targeted advertising directed at children where such activities are prohibited by applicable law.
Parents or lawful guardians may contact the Provider regarding the personal data of a child for whom they are legally responsible, subject to reasonable verification of identity and authority.
Retention of Personal Data
The Provider shall retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected, provide the relevant Services, comply with applicable legal, taxation, accounting or regulatory requirements, resolve disputes, prevent fraud, maintain security or establish, exercise or defend legal rights.
When personal data is no longer required for a lawful purpose, the Provider shall take reasonable steps to delete, anonymise or otherwise dispose of such information in accordance with applicable law and operational requirements.
Where information is processed by a third-party service provider, retention may also be subject to the applicable provider's lawful retention requirements.
Receiver's Rights and Requests
Subject to applicable law, the Receiver may request access to, correction of, deletion of or other permitted action concerning their personal data.
Where processing is based on consent, the Receiver may also withdraw such consent in accordance with applicable law.
Requests may be subject to reasonable identity and authority verification.
Withdrawal of consent or deletion of information may affect the Provider's ability to continue providing a Service where the relevant information is necessary for that Service or where retention is required or permitted by law.
The Provider shall process such requests and grievances in accordance with applicable law and its prescribed grievance-redressal process.
Third-Party Websites and Services
The Website may contain links, integrations or references to third-party websites, applications, payment gateways, assessment platforms or other services.
The privacy practices of such third parties are governed by their respective terms and privacy policies.
The Provider is not responsible for the privacy practices, security, content or data-processing activities of third-party services that it does not control.
The Receiver should review the applicable third-party terms and privacy policies before providing information directly to such third parties.
Changes to this Privacy Policy
The Provider reserves the right to modify, update or revise this Privacy Policy from time to time to reflect changes in its Services, technology, data-processing practices, legal requirements or operational practices.
The updated Privacy Policy shall be published on the Website with the revised “Last Updated” date.
Where required by applicable law, the Provider shall provide additional notice or obtain the required consent for material changes.
Unless otherwise required by law, changes shall become effective from the date stated in the updated Privacy Policy or, where no separate date is stated, from the date of publication on the Website.
The Receiver is responsible for reviewing the Privacy Policy periodically to remain informed of applicable changes.
Access, Correction, Deletion and Privacy Requests
A Receiver who wishes to request access to, correction of, amendment to or deletion of their personal information, or who wishes to raise a privacy-related grievance, may contact the Provider at:
Email: admin@svastrino.com
The request should contain sufficient information to identify the Receiver and understand the nature of the request.
The Provider may require reasonable verification before processing the request in order to protect the personal data of the Receiver and prevent unauthorised access, alteration or deletion.
The Provider shall process such requests in accordance with applicable law.
Applicable Privacy Framework
This Privacy Policy shall be interpreted and implemented in accordance with applicable laws and regulations relating to privacy, personal data protection, information technology, electronic transactions, payment processing and cybersecurity in the Republic of India, as applicable from time to time.
Where any provision of this Privacy Policy conflicts with a mandatory requirement of applicable law, the mandatory legal requirement shall prevail to the extent of such conflict.