Festival Season Offer15% off on all our programmes — claim it before you enrol

Data Compliance Policy

Skill IT Education Pvt Ltd · Last updated: September 20, 2026

This Data Compliance Policy explains how Skill IT Education Pvt Ltd ("Skill IT", "we", "us" or "our") stores, maintains, shares and protects personal data, and the Indian laws and regulations we follow. It works together with our Privacy Policy, which explains what we collect and why.

Our students trust us with their careers, and we hold their data to the same standard: lawful, fair, secure and respectful. This Policy applies to everyone who handles personal data for us, including employees, instructors, contractors and vendors.

Ethical by designFairness, transparency and respect for students guide every decision about data.
Aligned with Indian lawWe follow the DPDP Act, the IT Act and its rules, CERT-In directions and related laws.
Stored and protectedEncrypted, access-controlled, backed up, and kept only as long as needed.
Shared only when neededWith contracts, minimum data and, for hiring partners, your consent.
AccountableA named Grievance Officer, clear timelines and a way to escalate.

1. Purpose, scope and status

This Policy sets the rules Skill IT follows when it collects, stores, uses, shares, maintains and deletes personal data. It covers the personal data of prospective students, students, parents and guardians, website visitors and the contacts of our partners, in any form: electronic, paper or spoken.

It explains our practices and commitments. It is not legal advice. If any part of it conflicts with the law, the law prevails.

2. Our ethical data principles

Beyond what the law requires, we hold ourselves to these principles:

  • Lawful, fair and transparent: we tell you clearly what we do with your data, in plain language.
  • Purpose limitation: we use data only for the purposes we told you, and ask again before using it for anything new.
  • Data minimisation: we do not collect data "just in case".
  • Consent that means something: free, specific, informed, never bundled or pre-ticked, and as easy to withdraw as to give.
  • Accuracy: we keep data correct and fix errors when you tell us.
  • Storage limitation: we do not keep data longer than needed.
  • Security: we protect data with safeguards that match its sensitivity.
  • Respect for students: we never sell data, never use it to pressure or mislead, and never publish a student's name, results or photograph without consent.
  • No dark patterns: sign-up, opt-out and deletion are simple and honest.
  • Accountability: we can show how we comply, we review our practices, and we answer to you.

3. Indian laws and regulations we follow

Law or regulationWhat it coversHow we apply it
Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (as they come into force)Consent and notice; duties of a Data Fiduciary; rights of Data Principals; children's data; breach intimation; the Data Protection Board of IndiaNotice and consent at every form; purpose limitation; erasure when the purpose is served; rights process; grievance mechanism; verifiable parental consent for under-18s; breach notification
Information Technology Act, 2000 (including sections 43, 43A and 72A)Liability for failing to protect sensitive personal data; penalties for unauthorised access and for disclosing information in breach of contractReasonable security practices; access control; confidentiality undertakings; no unauthorised disclosure
IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011A published privacy policy; written consent for sensitive data; limits on disclosure; a Grievance Officer; reasonable security standardsPublished Privacy Policy; consent before collecting financial information; named Grievance Officer with a one-month redress window; documented security programme
CERT-In Directions of 28 April 2022 (section 70B(6) of the IT Act)Reporting of cyber incidents to CERT-In within six hours; keeping ICT logs for 180 days within IndiaIncident response plan with a six-hour reporting step; logs kept for at least 180 days
Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020Fair dealing and disclosure to consumers; a grievance officer; acknowledgement in 48 hours and redress within one monthClear programme information and fees; grievance handling within those timelines
TRAI Telecom Commercial Communications Customer Preference Regulations, 2018Consent and preferences for commercial calls and messages; the Do Not Disturb registerConsent before promotional messages; DND respected; easy opt-out
Payment and Settlement Systems Act, 2007 and RBI directions on storage of payment system data and card tokenisationPayment data stored in India; merchants may not store card numbersPayments handled by RBI-authorised gateways; we do not store card numbers, CVV codes or UPI PINs
Aadhaar Act, 2016 and UIDAI guidelinesLimits on collecting, using and storing Aadhaar numbersWe do not ask for Aadhaar for enrolment; any copy received is masked or deleted
Companies Act, 2013; CGST Act, 2017; income-tax lawKeeping books of account, invoices and tax records for prescribed periodsFinancial records kept for the period the law requires, generally six to eight years
Right to privacy, Article 21 of the Constitution (K.S. Puttaswamy v. Union of India, 2017)Privacy as a fundamental right, subject to lawful limitsThe foundation of the principles above

Laws and rules change, and some provisions of the DPDP Act and Rules come into force in stages. We follow the provisions that are in force, prepare for those that are coming, and update this Policy when the position changes.

4. Governance and accountability

  • Our management is responsible for data protection and reviews this Policy at least once a year and after any significant incident or change in the law.
  • Our Grievance Officer receives and resolves privacy complaints and rights requests, and their contact details are published in our Privacy Policy.
  • We keep a record of the personal data we process, why, where it is stored and who can access it, and we review it regularly.
  • We assess privacy and security before we adopt a new tool, provider or way of using data.
  • Everyone who handles personal data signs a confidentiality undertaking and is trained on this Policy when they join and at least once a year.

6. How we store data

  • Personal data is stored in access-controlled systems, and data in transit is protected with encryption.
  • Access is on a need-to-know basis, by role, with strong authentication for systems that hold personal data.
  • Backups are kept and protected in the same way as live data.
  • Where practicable, data is kept in India. Payment system data is stored in India.
  • Paper records, such as forms and any documents you hand in, are kept in locked storage and shredded when no longer needed.
  • Personal data is not kept in open chat groups, personal accounts or unmanaged devices, and devices used for work are protected.

7. How we maintain data

  • We check that data is accurate and complete when we collect it and when we use it, and correct it when you tell us it is wrong.
  • We review stored data regularly, remove duplicates and delete data that has passed its retention period.
  • We record who accessed sensitive records, and review the records for anything unusual.
  • When a student leaves, changes their details or withdraws consent, we update our systems and the partners who hold that data for us.

8. How we share data

We never sell personal data. We share it only where there is a clear reason, with only the data needed, and under safeguards:

WhoWhySafeguards
Payment gatewaysTo take fees and issue receiptsRBI-authorised providers; we do not store card details
Email, SMS and WhatsApp providersTo send confirmations, schedules and (with consent) updatesWritten contract; use only on our instructions; opt-out honoured
Hosting, CRM and learning-platform providersTo run our website, records and classesWritten contract; security assessment; no use for their own purposes
Instructors and academic partnersTo deliver and certify trainingNeed-to-know access; confidentiality undertakings
Certification bodiesTo register you for an external exam you chooseOnly with your request; only the details required
Hiring and internship partnersTo introduce you to opportunitiesOnly with your consent and only the profile details you approve
Auditors and legal advisersTo meet audit and legal dutiesProfessional confidentiality
Courts and authoritiesWhere the law or a lawful order requires itOnly what is required; we record the request

Any organisation that handles personal data for us must protect it at least as well as we do, use it only for the purpose we set, tell us promptly of any incident, and delete or return it when the work ends.

9. Transfers outside India

The DPDP Act permits transfers of personal data outside India except to countries the Central Government restricts. We use providers outside India only where necessary, never to a restricted country, under a written contract with equivalent protections, and subject to any stricter sectoral rule, such as the RBI's rules for payment data. We tell you in our Privacy Policy when this happens.

10. Security controls

Technical

  • Encryption of data in transit, and of data at rest where the system supports it
  • Role-based access, least privilege and multi-factor authentication for administrative access
  • Logging of access to systems that hold personal data, kept for at least 180 days
  • Regular software updates, malware protection and vulnerability checks
  • Secure, tested backups

Organisational

  • Confidentiality undertakings and regular training for everyone who handles personal data
  • Prompt removal of access when someone changes role or leaves
  • Due diligence on vendors and written data-protection terms
  • Physical security for our centre, records and devices
  • A written incident response plan, tested from time to time

11. Incident and breach response

If we suspect a personal data breach or a cyber incident, we:

  • contain it and protect the affected systems and data;
  • assess what happened, which data and which people are affected, and the risk to them;
  • report notifiable cyber incidents to CERT-In within six hours of noticing them, as the CERT-In Directions require;
  • inform the Data Protection Board of India and each affected person, in the manner and within the time the DPDP Act and Rules prescribe, telling them what happened and what they can do;
  • fix the cause, and record the incident and what we learned.

12. Retention and secure deletion

We keep personal data only as long as it is needed for the purpose or as the law requires. Our usual periods are set out in Section 8 of the Privacy Policy. When the time comes, we delete or irreversibly anonymise the data, remove it from backups on their normal cycle, shred paper records, and ask our providers to do the same. If you withdraw consent or ask for erasure and no law requires us to keep the data, we erase it and confirm to you.

13. Handling your rights requests

  • You can write to our Grievance Officer to access, correct, update or erase your data, withdraw consent, or nominate someone to act for you.
  • We confirm your identity, acknowledge the request within 48 hours, and aim to complete it within 30 days, and in any case within the period the law prescribes.
  • We do not charge for reasonable requests.
  • If we cannot act fully, we explain why and what you can do next.

14. Children and minors

We process the personal data of a person under 18 only with the verifiable consent of a parent or lawful guardian, do not track or monitor the behaviour of children, and do not direct targeted advertising at them. Where an enrolment involves a minor, we speak to the parent or guardian.

15. Marketing, calls and messages

We send promotional communications only with consent, honour opt-outs immediately, respect the National Customer Preference Register and TRAI rules, and keep a suppression list so that people who opt out are not contacted again. Service messages that are essential to a programme you have joined are kept separate from marketing.

16. Payments

Fees are collected through RBI-authorised payment gateways and banking channels. We do not store card numbers, CVV codes, card expiry dates or UPI PINs. We keep only the transaction details we need for receipts, reconciliation, refunds and tax records.

17. Student records, certificates and publicity

  • Academic records and certificate records are kept accurately and only as long as needed to verify and support your achievement.
  • We share a certificate, result or attendance record with a third party only when you ask us to or the law requires it.
  • We use a student's name, photograph, testimonial or result in our marketing only with the student's clear consent, which can be withdrawn.

18. Vendors and partners

Before we work with a provider that will handle personal data, we check its security and privacy practices, agree written data-protection terms, and limit the data it can see. We review important providers regularly and make sure data is deleted or returned when the relationship ends.

19. Training, monitoring and audits

We train our people, check that these rules are followed, and review our systems and providers from time to time. We correct any gap we find and keep a record of what we changed.

20. Complaints and escalation

If you think we have not followed this Policy or the law, please tell us first. Our Grievance Officer acknowledges complaints within 48 hours and aims to resolve them within 30 days.

Skill IT Education Pvt Ltd
Grievance Officer
Attn: Grievance Officer
Address
House No. 3-5-35, LR Towers, 3rd Floor, 100 Feet Road, Ayyappa Society, Madhapur, Hyderabad, Telangana 500081
Phone
+91 9177715978
Email
info@skilliteducation.com
Website
www.skilliteducation.com

If we do not resolve your complaint, you may approach the Data Protection Board of India as the DPDP Act provides. For consumer matters you may also approach the consumer forums under the Consumer Protection Act, 2019.

21. Review of this Policy

We review this Policy at least once a year and whenever the law or our practices change. The current version is always on this page with its "Last updated" date.