Scope & Applicability
This Data Protection Policy applies to all personal data processed by Disha Education Pvt. Ltd. β whether collected from students, professionals, institutions, employers, or visitors β across all our digital products and services. It applies to all employees, contractors, and third-party processors who handle personal data on our behalf.
Core Data Protection Principles
Lawfulness, Fairness & Transparency
We process personal data only on lawful grounds β consent, contract, legal obligation, or legitimate interest β and always inform users about how their data is used.
Purpose Limitation
Data collected for a specific purpose is not used for any other purpose without fresh consent or a compatible legal basis.
Data Minimisation
We collect only the data that is strictly necessary to deliver our services. We do not collect data "just in case".
Accuracy
We take reasonable steps to ensure personal data is accurate and up to date. Users can correct their data at any time via their account settings.
Storage Limitation
Personal data is retained only as long as necessary for the stated purpose or as required by law, after which it is securely deleted or anonymised.
Integrity & Confidentiality
We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, destruction, or damage.
Accountability
Disha Education Pvt. Ltd. is responsible for and can demonstrate compliance with all data protection principles.
Technical Measures
- AES-256 encryption for data at rest
- TLS 1.3 for all data in transit
- Role-based access control (RBAC) with least-privilege principle
- Multi-factor authentication for all administrative accounts
- Regular automated vulnerability scans and annual penetration tests
- Intrusion detection and real-time security monitoring
- Automated data backup with geo-redundant storage
- Secure software development lifecycle (SSDLC) practices
Organisational Measures
- Mandatory data protection training for all staff
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- Vendor due diligence and Data Processing Agreements (DPAs) with all processors
- Incident response plan with 72-hour breach notification capability
- Regular internal audits and compliance reviews
- Appointed Data Protection Officer (DPO)
Data Breach Notification
In the event of a personal data breach that poses a risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by the DPDP Act 2023.
Affected individuals will be notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed.
Data Protection Officer
For any data protection queries, DPIAs, or to exercise your rights, contact our DPO:
dpo@disha.in
Disha Education Pvt. Ltd., 4th Floor, Tech Hub, BKC, Mumbai β 400 051