1. Purpose, scope and status
This Policy sets the rules Skill IT follows when it collects, stores, uses, shares, maintains and deletes personal data. It covers the personal data of prospective students, students, parents and guardians, website visitors and the contacts of our partners, in any form: electronic, paper or spoken.
It explains our practices and commitments. It is not legal advice. If any part of it conflicts with the law, the law prevails.
2. Our ethical data principles
Beyond what the law requires, we hold ourselves to these principles:
- Lawful, fair and transparent: we tell you clearly what we do with your data, in plain language.
- Purpose limitation: we use data only for the purposes we told you, and ask again before using it for anything new.
- Data minimisation: we do not collect data "just in case".
- Consent that means something: free, specific, informed, never bundled or pre-ticked, and as easy to withdraw as to give.
- Accuracy: we keep data correct and fix errors when you tell us.
- Storage limitation: we do not keep data longer than needed.
- Security: we protect data with safeguards that match its sensitivity.
- Respect for students: we never sell data, never use it to pressure or mislead, and never publish a student's name, results or photograph without consent.
- No dark patterns: sign-up, opt-out and deletion are simple and honest.
- Accountability: we can show how we comply, we review our practices, and we answer to you.
3. Indian laws and regulations we follow
| Law or regulation | What it covers | How we apply it |
|---|---|---|
| Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (as they come into force) | Consent and notice; duties of a Data Fiduciary; rights of Data Principals; children's data; breach intimation; the Data Protection Board of India | Notice and consent at every form; purpose limitation; erasure when the purpose is served; rights process; grievance mechanism; verifiable parental consent for under-18s; breach notification |
| Information Technology Act, 2000 (including sections 43, 43A and 72A) | Liability for failing to protect sensitive personal data; penalties for unauthorised access and for disclosing information in breach of contract | Reasonable security practices; access control; confidentiality undertakings; no unauthorised disclosure |
| IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 | A published privacy policy; written consent for sensitive data; limits on disclosure; a Grievance Officer; reasonable security standards | Published Privacy Policy; consent before collecting financial information; named Grievance Officer with a one-month redress window; documented security programme |
| CERT-In Directions of 28 April 2022 (section 70B(6) of the IT Act) | Reporting of cyber incidents to CERT-In within six hours; keeping ICT logs for 180 days within India | Incident response plan with a six-hour reporting step; logs kept for at least 180 days |
| Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020 | Fair dealing and disclosure to consumers; a grievance officer; acknowledgement in 48 hours and redress within one month | Clear programme information and fees; grievance handling within those timelines |
| TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 | Consent and preferences for commercial calls and messages; the Do Not Disturb register | Consent before promotional messages; DND respected; easy opt-out |
| Payment and Settlement Systems Act, 2007 and RBI directions on storage of payment system data and card tokenisation | Payment data stored in India; merchants may not store card numbers | Payments handled by RBI-authorised gateways; we do not store card numbers, CVV codes or UPI PINs |
| Aadhaar Act, 2016 and UIDAI guidelines | Limits on collecting, using and storing Aadhaar numbers | We do not ask for Aadhaar for enrolment; any copy received is masked or deleted |
| Companies Act, 2013; CGST Act, 2017; income-tax law | Keeping books of account, invoices and tax records for prescribed periods | Financial records kept for the period the law requires, generally six to eight years |
| Right to privacy, Article 21 of the Constitution (K.S. Puttaswamy v. Union of India, 2017) | Privacy as a fundamental right, subject to lawful limits | The foundation of the principles above |
Laws and rules change, and some provisions of the DPDP Act and Rules come into force in stages. We follow the provisions that are in force, prepare for those that are coming, and update this Policy when the position changes.
4. Governance and accountability
- Our management is responsible for data protection and reviews this Policy at least once a year and after any significant incident or change in the law.
- Our Grievance Officer receives and resolves privacy complaints and rights requests, and their contact details are published in our Privacy Policy.
- We keep a record of the personal data we process, why, where it is stored and who can access it, and we review it regularly.
- We assess privacy and security before we adopt a new tool, provider or way of using data.
- Everyone who handles personal data signs a confidentiality undertaking and is trained on this Policy when they join and at least once a year.
5. How we collect data: notice and consent
- Every form tells you what we collect, why, how to withdraw consent and how to reach our Grievance Officer.
- Marketing consent is separate from the consent to answer your enquiry or provide a service.
- We keep a record of consent: what you agreed to, when and which version of the notice you saw.
- Withdrawing consent is as easy as giving it, and we act on it promptly.
- For anyone under 18 we obtain verifiable parental or guardian consent first.
6. How we store data
- Personal data is stored in access-controlled systems, and data in transit is protected with encryption.
- Access is on a need-to-know basis, by role, with strong authentication for systems that hold personal data.
- Backups are kept and protected in the same way as live data.
- Where practicable, data is kept in India. Payment system data is stored in India.
- Paper records, such as forms and any documents you hand in, are kept in locked storage and shredded when no longer needed.
- Personal data is not kept in open chat groups, personal accounts or unmanaged devices, and devices used for work are protected.
7. How we maintain data
- We check that data is accurate and complete when we collect it and when we use it, and correct it when you tell us it is wrong.
- We review stored data regularly, remove duplicates and delete data that has passed its retention period.
- We record who accessed sensitive records, and review the records for anything unusual.
- When a student leaves, changes their details or withdraws consent, we update our systems and the partners who hold that data for us.
9. Transfers outside India
The DPDP Act permits transfers of personal data outside India except to countries the Central Government restricts. We use providers outside India only where necessary, never to a restricted country, under a written contract with equivalent protections, and subject to any stricter sectoral rule, such as the RBI's rules for payment data. We tell you in our Privacy Policy when this happens.
10. Security controls
Technical
- Encryption of data in transit, and of data at rest where the system supports it
- Role-based access, least privilege and multi-factor authentication for administrative access
- Logging of access to systems that hold personal data, kept for at least 180 days
- Regular software updates, malware protection and vulnerability checks
- Secure, tested backups
Organisational
- Confidentiality undertakings and regular training for everyone who handles personal data
- Prompt removal of access when someone changes role or leaves
- Due diligence on vendors and written data-protection terms
- Physical security for our centre, records and devices
- A written incident response plan, tested from time to time
11. Incident and breach response
If we suspect a personal data breach or a cyber incident, we:
- contain it and protect the affected systems and data;
- assess what happened, which data and which people are affected, and the risk to them;
- report notifiable cyber incidents to CERT-In within six hours of noticing them, as the CERT-In Directions require;
- inform the Data Protection Board of India and each affected person, in the manner and within the time the DPDP Act and Rules prescribe, telling them what happened and what they can do;
- fix the cause, and record the incident and what we learned.
12. Retention and secure deletion
We keep personal data only as long as it is needed for the purpose or as the law requires. Our usual periods are set out in Section 8 of the Privacy Policy. When the time comes, we delete or irreversibly anonymise the data, remove it from backups on their normal cycle, shred paper records, and ask our providers to do the same. If you withdraw consent or ask for erasure and no law requires us to keep the data, we erase it and confirm to you.
13. Handling your rights requests
- You can write to our Grievance Officer to access, correct, update or erase your data, withdraw consent, or nominate someone to act for you.
- We confirm your identity, acknowledge the request within 48 hours, and aim to complete it within 30 days, and in any case within the period the law prescribes.
- We do not charge for reasonable requests.
- If we cannot act fully, we explain why and what you can do next.
14. Children and minors
We process the personal data of a person under 18 only with the verifiable consent of a parent or lawful guardian, do not track or monitor the behaviour of children, and do not direct targeted advertising at them. Where an enrolment involves a minor, we speak to the parent or guardian.
15. Marketing, calls and messages
We send promotional communications only with consent, honour opt-outs immediately, respect the National Customer Preference Register and TRAI rules, and keep a suppression list so that people who opt out are not contacted again. Service messages that are essential to a programme you have joined are kept separate from marketing.
16. Payments
Fees are collected through RBI-authorised payment gateways and banking channels. We do not store card numbers, CVV codes, card expiry dates or UPI PINs. We keep only the transaction details we need for receipts, reconciliation, refunds and tax records.
17. Student records, certificates and publicity
- Academic records and certificate records are kept accurately and only as long as needed to verify and support your achievement.
- We share a certificate, result or attendance record with a third party only when you ask us to or the law requires it.
- We use a student's name, photograph, testimonial or result in our marketing only with the student's clear consent, which can be withdrawn.
18. Vendors and partners
Before we work with a provider that will handle personal data, we check its security and privacy practices, agree written data-protection terms, and limit the data it can see. We review important providers regularly and make sure data is deleted or returned when the relationship ends.
19. Training, monitoring and audits
We train our people, check that these rules are followed, and review our systems and providers from time to time. We correct any gap we find and keep a record of what we changed.
20. Complaints and escalation
If you think we have not followed this Policy or the law, please tell us first. Our Grievance Officer acknowledges complaints within 48 hours and aims to resolve them within 30 days.
- Grievance Officer
- Attn: Grievance Officer
- Address
- House No. 3-5-35, LR Towers, 3rd Floor, 100 Feet Road, Ayyappa Society, Madhapur, Hyderabad, Telangana 500081
- Phone
- +91 9177715978
- info@skilliteducation.com
- Website
- www.skilliteducation.com
If we do not resolve your complaint, you may approach the Data Protection Board of India as the DPDP Act provides. For consumer matters you may also approach the consumer forums under the Consumer Protection Act, 2019.
21. Review of this Policy
We review this Policy at least once a year and whenever the law or our practices change. The current version is always on this page with its "Last updated" date.
