The short version. We collect what we need to sell you a course, give you access to it, and support you โ your name, email, billing details and progress through lessons. We never see your full card number. We do not sell your data to anyone. You can ask us to show you, correct or delete your data at any time by emailing info@meritchapter.com.
1. Who we are
This policy explains how [Legal Entity Name], a company incorporated in India with its registered office at [Registered Address] ("NeuraLearn", "we", "us"), collects and handles personal data when you use neuralearn.in, enrol in a course, or contact us.
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as the Data Fiduciary in respect of the personal data described here, and you are the Data Principal. Where the laws of your own country also apply to you, we aim to meet the standards set out below regardless of where you are located.
2. What personal data we collect
2.1 Data you give us
- Account data โ name, email address, password (stored only as a salted hash), and optionally a profile photo and short bio.
- Billing data โ billing name, billing address, country, state, phone number, and GSTIN where you supply one for a business invoice.
- Communications โ the content of messages you send us through the contact form, email, or community channels, including any attachments.
- Submitted work โ projects, code, prompts or files you voluntarily submit for instructor review or share in community spaces.
- Testimonials โ where you choose to give one, your name, role and the words you provide.
2.2 Data collected automatically
- Usage data โ lessons viewed, video watch position, completion status, quiz and exercise results, downloads, and certificate issuance.
- Device and log data โ IP address, browser type and version, operating system, device type, screen size, referring URL, pages visited, and timestamps.
- Cookie identifiers โ as described in section 6.
2.3 Data we receive from others
- Payment processors โ transaction status, the last four digits and brand of your card, and a payment reference. We never receive your full card number, CVV or PIN.
- Analytics and infrastructure providers โ aggregated traffic and performance information.
- Affiliates or partners โ where you reach us through a referral link, the identifier of the referrer.
3. Why we use your data
| Purpose | Data used |
|---|---|
| Create and administer your account | Account data |
| Process your order, issue a GST invoice and grant course access | Account data, billing data, payment reference |
| Deliver course content and track your progress and certificates | Account data, usage data |
| Provide support and answer your questions | Account data, communications |
| Process a refund request | Billing data, usage data, payment reference |
| Send service emails โ access links, receipts, course updates, security notices | Account data |
| Send marketing emails about new courses and offers, where you have opted in | Account data |
| Improve our courses and identify lessons where learners get stuck | Usage data, aggregated and where possible pseudonymised |
| Detect fraud, credential sharing, chargeback abuse and security incidents | Device and log data, usage data, payment reference |
| Comply with tax, accounting and other legal obligations | Billing data, transaction records |
We do not sell your personal data. We do not share it with third parties for their own independent marketing purposes. We do not use your submitted projects or community posts to train machine-learning models.
4. Our legal basis for processing
We process your personal data on the following bases:
- Consent โ for marketing communications, non-essential cookies, and public use of any testimonial you provide. You may withdraw consent at any time, and withdrawal is as easy as giving it.
- Performance of a contract โ to deliver the course you purchased and to provide support.
- Legitimate uses and legal obligation โ to keep tax and accounting records, respond to lawful requests from authorities, prevent fraud, and protect the security of the Platform.
Withdrawing consent does not affect processing carried out before withdrawal, and does not entitle you to a refund where the course has already been delivered.
5. Payment data
Payments are processed by third-party payment gateways that are certified to PCI-DSS standards. When you pay, your card or banking details are transmitted directly to the gateway and are not stored on our servers. We retain only the transaction reference, amount, currency, status, and the masked card details the gateway returns to us โ enough to reconcile accounts, issue invoices and process refunds.
Each gateway is an independent data controller in respect of the payment information it collects, and handles that data under its own privacy policy.
6. Cookies and similar technologies
We use a small number of cookies and comparable browser storage:
| Category | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Keeping you signed in, remembering cart contents, security and fraud prevention, load balancing | No โ the site cannot function without these |
| Preferences | Remembering settings such as playback speed, volume and last lesson position | No |
| Analytics | Understanding which pages and lessons are used, in aggregate, so we can improve them | Yes |
| Marketing | Measuring the performance of advertising and attributing referrals | Yes |
You can accept or reject non-essential cookies through the consent banner shown on your first visit, and change your choice at any time. You can also block or delete cookies through your browser settings, though strictly necessary cookies cannot be disabled without breaking core functionality such as signing in.
7. Who we share your data with
We share personal data only with the categories of recipient listed below, and only to the extent needed:
- Payment gateways โ to take payment and process refunds.
- Cloud hosting and content delivery providers โ to store data and stream video.
- Email service providers โ to send transactional and, where you have opted in, marketing email.
- Video hosting platforms โ to deliver lesson video securely.
- Community platform providers โ where community access forms part of your course.
- Analytics providers โ subject to your cookie consent.
- Professional advisers โ accountants, auditors and lawyers, bound by confidentiality.
- Authorities โ where disclosure is required by law, court order, or to establish, exercise or defend legal claims.
- An acquirer โ if we are involved in a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.
Every processor we engage is bound by a written agreement requiring them to process personal data only on our instructions, to keep it confidential, and to apply appropriate security measures.
8. International transfers
Some of our service providers operate infrastructure outside India. Where personal data is transferred outside India, we transfer it only to countries not restricted by the Central Government under the DPDP Act, and we require contractual safeguards obliging the recipient to protect the data to a standard consistent with this policy.
9. How long we keep your data
| Data | Retention period |
|---|---|
| Account and profile data | For as long as your account is active, then 12 months after your deletion request or last activity |
| Course access and progress records | For the duration of your lifetime licence, so that access and certificates can be restored |
| Invoices, transaction and tax records | 8 years, as required by Indian tax and companies legislation |
| Support correspondence | 3 years from the date the matter is closed |
| Marketing consent records | 3 years from withdrawal of consent, as evidence of compliance |
| Server and security logs | Up to 180 days, as required under Indian cyber-security rules |
When a retention period expires, we delete the data or irreversibly anonymise it so it can no longer be linked to you.
10. How we protect your data
- All traffic to and from the Platform is encrypted in transit using TLS.
- Passwords are stored only as salted hashes and are never recoverable in plain text โ not even by us.
- Access to production systems is restricted to authorised personnel, protected by multi-factor authentication and reviewed periodically.
- We apply the principle of least privilege and log administrative access.
- We take regular encrypted backups and test restoration.
- We keep dependencies patched and review our security posture as our systems change.
No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security, and you share information with us at your own risk. Choose a strong, unique password and do not reuse it elsewhere.
11. Your rights
Subject to the conditions and exemptions in the DPDP Act, you have the right to:
- Access โ obtain confirmation of whether we process your data, a summary of that data, and the identities of parties with whom it has been shared.
- Correction โ have inaccurate or misleading data corrected, and incomplete data completed.
- Erasure โ have your data deleted where it is no longer necessary for the purpose it was collected for, unless retention is required by law.
- Withdraw consent โ for any processing based on consent, at any time.
- Grievance redressal โ raise a complaint with us and receive a response.
- Nominate โ appoint another individual to exercise your rights on your behalf in the event of your death or incapacity.
To exercise any of these, email info@meritchapter.com from the address registered on your account, or use the contact form. We will verify your identity before acting and respond within 30 days. These rights are free to exercise; we may charge a reasonable fee only for manifestly unfounded or repetitive requests.
If you are dissatisfied with our response, you may escalate to our grievance officer (section 15) and, thereafter, complain to the Data Protection Board of India.
To unsubscribe from marketing email, use the unsubscribe link in any such email. We will continue to send essential service messages โ receipts, access links and security notices โ because they form part of the service you purchased.
12. Children's data
Our courses are intended for adults. We do not knowingly collect personal data from children under 18 without verifiable parental consent, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us with personal data without appropriate consent, contact us and we will delete it promptly.
13. Breach notification
If a personal data breach occurs that is likely to affect you, we will notify the Data Protection Board of India and each affected Data Principal without undue delay, in the manner and within the timeframes prescribed under the DPDP Act. Our notice will describe what happened, the categories of data involved, the likely consequences, the measures we have taken, and what you should do.
14. Changes to this policy
We may update this policy to reflect changes in our practices, technology or the law. The "Last updated" date above shows the current version. Where a change materially affects how we use your data, we will notify you by email or a prominent notice on the Platform before it takes effect, and where required we will seek fresh consent.
15. Contact and grievance redressal
| Privacy queries | info@meritchapter.com |
|---|---|
| Grievance officer | [Grievance Officer Name] |
| Grievance email | info@meritchapter.com |
| Postal address | [Registered Address] |
| Acknowledgement | Within 48 hours of receipt |
| Resolution | Within 30 days of receipt |
If your complaint is not resolved to your satisfaction, you may approach the Data Protection Board of India in accordance with the DPDP Act.