Privacy Policy


Definitions and Interpretation

In this Privacy Policy, the following terms shall have the meanings ascribed to them hereunder, and words importing the singular shall include the plural and vice versa:

"Academy", "We", "Us", "Our" — Aram IAS Academy, an educational institution registered and operating from II Avenue, Anna Nagar West, Chennai – 600040, Tamil Nadu, India.

"Applicable Law" — Collectively, the Information Technology Act, 2000 ("IT Act"); the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"); the Digital Personal Data Protection Act, 2023 ("DPDP Act"), once notified and in force; and any amendments or successor legislation thereto.

"Data Principal" — The natural person to whom the Personal Data relates, i.e., the User.

"Data Fiduciary" — The Academy, being the entity that, alone or in conjunction with others, determines the purpose and means of processing of Personal Data.

"Personal Data" / "Personal Information" — Any information that identifies, or is capable of identifying, a Data Principal directly or indirectly, including Sensitive Personal Data or Information ("SPDI") as defined under Rule 3 of the SPDI Rules.

"Platform" — Collectively, the Academy's websites at www.aramiasacademy.com and www.aramstudentsportal.com, and any associated mobile applications or digital interfaces.

"Processing" — Any operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, transmission, or deletion.

"Services" — All educational services, online courses, test series, study materials, live classes, and ancillary facilities offered by the Academy through the Platform.

"User", "You", "Your" — Any individual who accesses the Platform, registers an account, enrols in any programme, or otherwise interacts with the Academy.

Applicability and Scope

This Privacy Policy ("Policy") is published in accordance with Rule 4 of the SPDI Rules read with Section 43A of the IT Act, and in anticipation of the provisions of the DPDP Act, 2023. It governs the collection, use, storage, disclosure, and protection of Personal Data submitted by Users in the course of accessing or using the Platform or Services.

This Policy shall be read in conjunction with the Terms and Conditions of the Platform, which are incorporated herein by reference. In the event of any conflict between this Policy and the Terms and Conditions on matters of data privacy, this Policy shall prevail.

Consent: By accessing the Platform, creating an account, submitting a registration form, or enrolling in any programme, You voluntarily provide Your free, specific, informed, and unambiguous consent to the collection and Processing of Your Personal Data in the manner described in this Policy. If You do not consent to the terms herein, You must immediately discontinue use of the Platform.

Categories of Personal Data Collected

3.1 Data Provided by You

The following categories of data are collected when you register, enrol, or otherwise interact with the Platform:

  • Identity Data: Full name, date of birth, gender, and photograph (where voluntarily uploaded).
  • Contact Data: Email address, mobile number, and postal address.
  • Authentication Data: Username and password (passwords are stored in encrypted/hashed form and are not accessible in plain text by Academy personnel).
  • Financial Data: Payment instrument details (including credit/debit card details, UPI handles, or net banking references) processed exclusively through PCI-DSS compliant third-party payment gateways. The Academy does not store or have access to full card numbers or CVV details.
  • Academic Data: Educational qualifications, examination preferences, performance data on tests and mock examinations, and progress records.
  • User-Generated Content: Posts, comments, queries, feedback, and any other content submitted by You on interactive features of the Platform.
  • Identity Verification Documents: Proof of identity or residence, if required for any specific programme or concession.

3.2 Data Collected Automatically

The Academy and its service providers may automatically collect the following technical data when you access the Platform:

  • Device and Browser Data: IP address, browser type and version, operating system, screen resolution, and device identifiers.
  • Usage Data: Pages visited, features accessed, time and date of access, session duration, navigation paths, and clickstream data.
  • Location Data: Approximate geographic location derived from IP address (not precise GPS-level location unless expressly permitted).
  • Log Files: Server-side logs recording access requests, error reports, and diagnostic data.

3.3 Cookies and Similar Tracking Technologies

The Platform employs cookies, web beacons, pixel tags, local storage, and similar technologies ("Tracking Technologies") to enhance functionality, personalise content, and collect usage analytics. Users may manage cookie preferences through their browser settings; however, disabling essential cookies may impair the functionality of the Platform. For details of cookies used, please refer to our Cookie Policy available on the Platform. The use of Tracking Technologies is governed by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 to the extent applicable.

3.4 Data from Third Parties

Where you log in or register using a third-party authentication service (e.g., Google OAuth), we may receive certain profile information from that provider in accordance with your settings on that platform and their respective privacy policies.

Sensitive Personal Data or Information (SPDI)

Certain categories of data collected by the Academy may constitute Sensitive Personal Data or Information ("SPDI") as enumerated under Rule 3 of the SPDI Rules, 2011, including passwords and financial information. The Academy shall:

  • Collect SPDI only to the extent necessary for the stated lawful purpose;
  • Obtain prior written consent (including electronically recorded consent) of the Data Principal before collection of SPDI;
  • Not retain SPDI beyond the period for which it is required for the purpose for which it was collected;
  • Not publish SPDI; and
  • Not transfer SPDI to any third party without prior permission of the Data Principal, except as required by law or as provided in Section 6 of this Policy.

Purpose and Legal Basis of Processing

The Academy processes Personal Data on the following legal bases and for the following purposes:

5.1 Contractual Necessity

  • Creation and management of User accounts;
  • Processing of enrolments, fee payments, and provision of access to purchased Services;
  • Issuance of receipts, invoices, and course completion certificates;
  • Scheduling and delivery of classes, tests, and study resources.

5.2 Legitimate Interests of the Academy

  • Improving the Platform's features, performance, and content quality;
  • Conducting internal data analytics, research, and quality assessments;
  • Detecting, investigating, and preventing fraudulent, unauthorised, or illegal activity;
  • Ensuring network and information security;
  • Enforcing the Terms and Conditions and protecting the Academy's legal rights.

5.3 Consent

  • Sending marketing communications, newsletters, promotional offers, and announcements regarding new courses or programmes (subject to opt-out rights under Section 9);
  • Testimonials or case studies featuring Your academic performance or profile (only with explicit written consent).

5.4 Legal Obligation

  • Compliance with directions, orders, or notices issued by judicial, quasi-judicial, or regulatory authorities including but not limited to courts, the Ministry of Electronics and Information Technology (MeitY), and law enforcement agencies;
  • Maintenance of records required under the IT Act, the Income Tax Act, 1961, the Goods and Services Tax legislation, and other applicable statutory frameworks.

Disclosure and Transfer of Personal Data

The Academy affirms that it does not sell, trade, or otherwise transfer Personal Data to third parties for commercial gain. Disclosure may occur only in the following circumstances:

6.1 Data Processors and Service Providers

The Academy may engage third-party data processors—including payment gateways, cloud hosting providers, email delivery services, analytics platforms, and IT support vendors—who process Personal Data exclusively on behalf of and under the instructions of the Academy pursuant to written data processing agreements that impose obligations equivalent to those under the SPDI Rules.

6.2 Mandatory Disclosure

Where required by any order, decree, summons, or direction of a court, tribunal, or governmental authority having jurisdiction, or under any provision of law, the Academy shall disclose Personal Data to the extent required and shall, where permissible, notify the User of such disclosure.

6.3 Business Succession

In the event of a restructuring, merger, acquisition, amalgamation, or sale of the Academy or its undertaking, Personal Data may be transferred to the successor entity provided that the successor entity undertakes to be bound by obligations equivalent to those in this Policy.

6.4 Cross-Border Transfer

The Academy may transfer Personal Data outside India to cloud servers or service providers located in other jurisdictions. Any such transfer shall be effected in compliance with Section 16 of the DPDP Act, 2023 (upon its operationalisation) and any rules notified thereunder. Until such provisions come into force, transfers shall be subject to adequate contractual safeguards.

Data Retention

The Academy shall retain Personal Data for the period necessary to fulfil the purposes set out in this Policy and for such further period as may be required or permitted by Applicable Law. The following indicative retention periods apply:

  • Account and enrolment data: Duration of active account plus 5 (five) years after account closure, or as required by applicable statutory limitation periods, whichever is longer.
  • Financial and transactional records: 8 (eight) years from the date of transaction, in compliance with the Income Tax Act, 1961 and GST legislation.
  • Log files and technical data: 6 (six) months from the date of collection, unless required for ongoing investigations.
  • Marketing consents and opt-out records: Indefinitely, to demonstrate compliance with consent obligations.

Upon expiry of the applicable retention period, Personal Data shall be securely deleted or irreversibly anonymised in accordance with industry best practices.

Data Security

The Academy shall implement and maintain reasonable security practices and procedures as mandated under Section 43A of the IT Act and Rule 8 of the SPDI Rules. These include, without limitation:

  • Encryption of data in transit using Transport Layer Security (TLS) protocols;
  • Hashing and salting of passwords using industry-standard cryptographic algorithms;
  • Role-based access controls limiting access to Personal Data on a need-to-know basis;
  • Periodic security audits, vulnerability assessments, and penetration testing;
  • Adoption of the ISO/IEC 27001 information security management framework (or an equivalent standard) as a guiding standard.

Data Breach: In the event of a personal data breach that is likely to cause harm to Data Principals, the Academy shall notify the affected Users and the Data Protection Board of India (upon its establishment under the DPDP Act) in accordance with prescribed timelines and procedures.

Notwithstanding the foregoing, no transmission of data over the internet or electronic storage system can be guaranteed to be completely secure. The Academy shall not be liable for any unauthorised access, hacking, or data loss beyond its reasonable control provided it has complied with its obligations under Applicable Law.

Rights of Data Principals

In accordance with the SPDI Rules and the DPDP Act, 2023 (to the extent applicable), Data Principals are entitled to exercise the following rights:

9.1 Right of Access and Confirmation

You have the right to obtain confirmation as to whether Personal Data concerning You is being processed and to receive a copy of such data, subject to legal and technical limitations.

9.2 Right to Correction and Updation

You have the right to require the Academy to correct any inaccurate, incomplete, or outdated Personal Data pertaining to You.

9.3 Right to Erasure

You have the right to request deletion of Your Personal Data where it is no longer necessary for the purpose for which it was collected, provided that such deletion is not precluded by Applicable Law or the Academy's legitimate interests.

9.4 Right to Withdraw Consent

You may withdraw Your consent to Processing at any time by contacting the Academy at the details in Section 13. Withdrawal of consent shall not affect the lawfulness of Processing based on consent prior to its withdrawal. Withdrawal of consent may impair the Academy's ability to continue providing certain Services.

9.5 Right to Grievance Redressal

You have the right to have Your grievance in relation to the Processing of Your Personal Data redressed expeditiously. The Academy has designated a Grievance Officer for this purpose. Any grievance must be addressed in writing to the Grievance Officer at the contact details specified in Section 13, and shall be acknowledged within 24 hours and resolved within 30 (thirty) days of receipt, in accordance with Rule 5(9) of the SPDI Rules.

9.6 Right to Nominate

In accordance with the DPDP Act, 2023, upon its operationalisation, You shall be entitled to nominate another individual to exercise data principal rights on Your behalf in the event of Your death or incapacity.

9.7 Opt-Out of Marketing Communications

You may unsubscribe from marketing communications at any time by clicking the "Unsubscribe" link in any marketing email or by written request to the contact details in Section 13. Transactional and service communications are not subject to opt-out as they constitute an essential part of the Services.

Protection of Minors

The Platform and Services are directed towards individuals who are 18 (eighteen) years of age or above. The Academy does not knowingly collect or process Personal Data of minors below the age of 18 without the prior verifiable consent of a parent or lawful guardian, as required under Section 9 of the DPDP Act, 2023 (upon its operationalisation) and other applicable provisions.

If the Academy discovers that Personal Data of a minor has been collected without requisite parental consent, it shall forthwith delete such data upon receiving notice. Parents or guardians who believe their child's data has been collected without consent are requested to contact the Grievance Officer immediately.

Third-Party Platforms and Links

The Platform may contain hyperlinks to third-party websites, integrated payment portals, or external resources that are not owned, operated, or controlled by the Academy. This Policy does not extend to such third-party platforms. The Academy makes no representation as to the privacy practices or policies of such third parties and expressly disclaims all liability therefor. Users are advised to review the applicable privacy policies of any third-party platform before submitting Personal Data thereon.

Amendments to This Policy

The Academy reserves the right to revise, amend, or substitute this Policy at any time to reflect changes in Applicable Law, regulatory guidance, or the Academy's data practices. Material changes shall be communicated to registered Users via email or a prominent notice on the Platform prior to the changes taking effect, with a minimum notice period of 30 (thirty) days unless a shorter period is required by law. Continued use of the Platform after the effective date of any amendment constitutes acceptance of the revised Policy.

Governing Law and Dispute Resolution

This Policy shall be governed by and construed in accordance with the laws of the Republic of India. Any dispute, claim, or controversy arising out of or relating to this Policy or the breach, termination, enforcement, or interpretation thereof shall be subject to the exclusive jurisdiction of the courts of competent jurisdiction in Chennai, Tamil Nadu.

Without prejudice to the above, Users may also pursue remedies before the Adjudicating Officer under Section 46 of the IT Act and, upon its operationalisation, the Data Protection Board of India under the DPDP Act, 2023.

Statutory Compliance

This Policy is formulated in compliance with the following statutes, rules, and regulatory instruments (as amended from time to time):

  • The Information Technology Act, 2000 (particularly Sections 43A and 72A);
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
  • The Digital Personal Data Protection Act, 2023 (to the extent notified and in force);
  • The Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020;
  • Reserve Bank of India Guidelines on Payment Aggregators and Payment Gateways (to the extent applicable to payment processing).

Contact Details – Grievance Officer

Any request, query, complaint, or grievance pertaining to the Processing of Personal Data under this Policy shall be addressed in writing to the designated Grievance Officer of the Academy:

Grievance Officer (Data Privacy)

Aram IAS Academy

II Avenue, Anna Nagar West, Chennai – 600040, Tamil Nadu, India

Website: www.aramiasacademy.com

E-Learning Platform: www.aramstudentsportal.com

Email: info@aramiasacademy.com

Phone: 8939-69-6868/69