Last updated: 17 June 2026

Data Protection Policy

Our commitment to protecting your personal data through robust technical, organisational, and legal safeguards aligned with the DPDP Act 2023.

Scope & Applicability

This Data Protection Policy applies to all personal data processed by Disha Education Pvt. Ltd. β€” whether collected from students, professionals, institutions, employers, or visitors β€” across all our digital products and services. It applies to all employees, contractors, and third-party processors who handle personal data on our behalf.

Core Data Protection Principles

Lawfulness, Fairness & Transparency

We process personal data only on lawful grounds β€” consent, contract, legal obligation, or legitimate interest β€” and always inform users about how their data is used.

Purpose Limitation

Data collected for a specific purpose is not used for any other purpose without fresh consent or a compatible legal basis.

Data Minimisation

We collect only the data that is strictly necessary to deliver our services. We do not collect data "just in case".

Accuracy

We take reasonable steps to ensure personal data is accurate and up to date. Users can correct their data at any time via their account settings.

Storage Limitation

Personal data is retained only as long as necessary for the stated purpose or as required by law, after which it is securely deleted or anonymised.

Integrity & Confidentiality

We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, destruction, or damage.

Accountability

Disha Education Pvt. Ltd. is responsible for and can demonstrate compliance with all data protection principles.

Technical Measures

  • AES-256 encryption for data at rest
  • TLS 1.3 for all data in transit
  • Role-based access control (RBAC) with least-privilege principle
  • Multi-factor authentication for all administrative accounts
  • Regular automated vulnerability scans and annual penetration tests
  • Intrusion detection and real-time security monitoring
  • Automated data backup with geo-redundant storage
  • Secure software development lifecycle (SSDLC) practices

Organisational Measures

  • Mandatory data protection training for all staff
  • Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Vendor due diligence and Data Processing Agreements (DPAs) with all processors
  • Incident response plan with 72-hour breach notification capability
  • Regular internal audits and compliance reviews
  • Appointed Data Protection Officer (DPO)

Data Breach Notification

In the event of a personal data breach that poses a risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by the DPDP Act 2023.

Affected individuals will be notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed.

Data Protection Officer

For any data protection queries, DPIAs, or to exercise your rights, contact our DPO:

dpo@disha.in

Disha Education Pvt. Ltd., 4th Floor, Tech Hub, BKC, Mumbai β€” 400 051