Privacy policy
What personal data we collect, why we collect it, who we share it with, how long we keep it, what rights you have, and how to complain.
- Last updated
- 2026-08-14
- Contracting party
- Brand Vantage Marketing Private Limited
This Privacy Policy also serves as the notice required under Section 5 of the Digital Personal Data Protection Act, 2023 and Rule 3 of the Digital Personal Data Protection Rules, 2025. Please read it carefully. If you do not agree with it, please do not use this website or enrol in any Programme.
This Policy forms an integral part of our Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms and Conditions.
01Who we are
Brand Vantage Academy ("the Academy", "we", "us", "our") is a brand and business division of Brand Vantage Marketing Private Limited, a company incorporated under the Companies Act, 2013.
| CIN | U73100KA2023PTC176608 |
| PAN | AALCB8059L |
| GSTIN | 29AALCB8059L1ZW |
| Principal place of business | 11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066 |
| Registered office | registered office as per MCA records |
| Website | www.brandvantageacademy.com |
| Privacy / grievance contact | support@brandvantageacademy.com |
| Telephone | +91 8073707619 |
We act as the Data Fiduciary in respect of the personal data described in this Policy — meaning we determine the purpose and means of processing your personal data and are accountable for it under the DPDP Act.
Where we deliver a Programme on behalf of a partner Institution or a Corporate Client, that Institution or Corporate Client may be an independent Data Fiduciary in respect of the student or employee data it holds and shares with us, and we may act as a Data Processor on its instructions in respect of that data. In such cases, the Institution's or Corporate Client's own privacy policy will also apply to you.
02Scope of this policy
This Policy applies to personal data we process in relation to:
- visitors to and users of the Website and our learning portals;
- prospective learners who submit enquiries, registration forms, or download brochures;
- enrolled Learners, including students enrolled through a partner Institution;
- parents and lawful guardians of Learners under 18 years of age;
- participants nominated by Corporate Clients;
- representatives of Institutions, Corporate Clients, Delivery Partners, trainers, mentors, and vendors;
- applicants for employment or trainer engagement with the Academy; and
- attendees at our webinars, workshops, campus events, seminars, and hiring drives.
This Policy does not apply to third-party websites, platforms, or services that we link to or that you use during a Programme. Those are governed by their own privacy policies (see Clause 15).
03Definitions
| Term | Meaning |
|---|---|
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Processing | Any wholly or partly automated operation performed on personal data — including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, alignment, restriction, erasure, or destruction. |
| Data Principal | The individual to whom the personal data relates. Where the individual is a child, it includes the parent or lawful guardian. Where the individual is a person with disability having a lawful guardian, it includes that guardian. |
| Data Fiduciary | The person who alone or with others determines the purpose and means of processing personal data. |
| Data Processor | Any person who processes personal data on behalf of a Data Fiduciary. |
| Child | An individual who has not completed eighteen (18) years of age. |
| Consent Manager | A person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. |
| Sensitive Personal Data or Information | As defined under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — including passwords, financial information, physical, physiological or mental health condition, sexual orientation, medical records, and biometric information. |
| DPDP Act | The Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025, as amended. |
| Board | The Data Protection Board of India. |
04The personal data we collect
We collect only the personal data that is necessary for the specified purposes set out in Clause 6.
4.1 Identity and contact data
Full name; date of birth and age; gender (optional); photograph; email address; mobile and alternate telephone numbers; postal address, city, state, PIN code, and country; WhatsApp number; emergency contact name and number.
4.2 Guardian data (where the Learner is under 18)
Parent or lawful guardian's name, relationship to the Learner, email address, mobile number, address, and identity or age verification token where required to obtain verifiable consent under Section 9 of the DPDP Act.
4.3 Academic and professional data
Institution or college name; stream, course, branch, semester, and year of study; university registration or roll number; academic qualifications, marks, percentages, CGPA, and transcripts; backlog or arrear status where relevant to eligibility; prior work experience; current employer and designation; resume or curriculum vitae; LinkedIn, GitHub, or portfolio URLs; skills, certifications, and language proficiency.
4.4 Enrolment and programme data
Programme and Cohort enrolled in; enrolment date and status; attendance records; assignment and project submissions; assessment responses, scores, grades, and feedback; capstone and live project outputs; certificates issued; trainer and mentor feedback; learning-platform activity such as modules accessed, time spent, video progress, and quiz attempts; support tickets and queries raised.
4.5 Internship and placement data
Placement preferences (role, location, sector, salary expectation); resume versions prepared with us; mock interview recordings and evaluations; profiles shared with prospective employers and internship hosts; interview schedules, feedback, and outcomes; offer letters, joining status, employer name, designation, and stipend or salary details where you disclose them; internship host feedback and completion certificates.
4.6 Financial and transaction data
Fee amount, invoice number, GSTIN (for business enrolments), billing name and address, transaction reference and identifier, payment method type, payment status, date and time of payment, refund or transfer records, and the last four digits and card network of a payment card as reported back to us by the payment aggregator.
We do not collect, store, or have access to your full card number, CVV, card PIN, UPI PIN, net banking username or password, or any OTP. These are captured directly by the payment aggregator on its own secure infrastructure. See Clause 8.
4.7 Identity and verification documents
Where required for enrolment verification, certification, examination proctoring, scholarship eligibility, campus access, or statutory compliance, we may collect a copy of a government-issued identity document (for example Aadhaar, PAN, passport, driving licence, or student identity card), a bonafide certificate, or an income or category certificate.
Where an Aadhaar number is furnished, we collect it only where lawfully permitted, we mask all but the last four digits in our records, and we do not use it as a general identifier. You may furnish an alternative identity document instead.
4.8 Technical and usage data
IP address; device type, model, and unique device identifier; operating system and version; browser type, version, and language; screen resolution; referring and exit URLs; pages viewed and time spent; clickstream and navigation paths; date and time stamps; approximate location derived from IP address; crash logs and diagnostic data; cookie and similar-technology identifiers (see Clause 9).
4.9 Audio-visual data
Recordings of live online sessions (audio, video, chat, screen share, and on-screen contributions); photographs and video captured at classroom sessions, campus events, workshops, hiring drives, and seminars; mock interview recordings; CCTV footage at Academy premises and training centres. See Clause 10.
4.10 Communications data
Emails, WhatsApp messages, SMS, call records and call recordings (where a call is recorded and you are informed at the outset), chat transcripts, enquiry form submissions, feedback forms, survey responses, testimonials, and social media interactions with our official accounts.
4.11 Marketing and preference data
Your consent status for marketing communications; channel preferences; areas of interest; event registrations and attendance; brochure downloads; engagement with our emails and campaigns.
4.12 Sensitive personal data
We do not ordinarily seek sensitive personal data. We may collect limited health or accessibility information only where you voluntarily provide it so that we can make reasonable accommodations (for example, extra assessment time, accessible seating, or dietary requirements at an event), or in a medical emergency during an on-campus or in-person session. Such data is processed strictly for that purpose, on a need-to-know basis, and deleted when no longer required.
4.13 Data we do not want
Please do not send us your passwords, full card details, bank account credentials, medical records, caste or religious details, political opinions, or biometric data unless we have specifically and lawfully asked for them. If you send unsolicited sensitive data, we will delete it.
05How we collect personal data
5.1 Directly from you
Through enquiry and registration forms; enrolment and admission forms; account creation; payment checkout; assessments and assignments; feedback and survey forms; email, telephone, and WhatsApp correspondence; event and webinar registrations; resume and profile submissions; and consent forms.
5.2 Automatically
Through cookies, pixels, tags, SDKs, server logs, and analytics tools when you visit the Website or use the learning portal. See Clause 9.
5.3 From partner institutions
Where you are enrolled through a school, pre-university college, degree college, engineering college, or university, that Institution may share your name, contact details, academic details, stream, semester, roll number, attendance, and — where you are under 18 — evidence of parental or guardian consent. The Institution is responsible for having a lawful basis for that disclosure.
5.4 From corporate clients
Where you are nominated for corporate training, your employer may share your name, official email, employee identifier, designation, department, and training history.
5.5 From delivery partners and trainers
Attendance, assessment scores, project evaluations, and progress feedback recorded by trainers, mentors, and Delivery Partners including Bluink360 Solutions.
5.6 From third parties and public sources
Payment aggregators (transaction confirmations and status); learning platform and video conferencing providers (attendance and engagement logs); prospective employers and internship hosts (interview feedback and outcomes); referral sources; and publicly available professional profiles that you have made public, where relevant to placement assistance.
5.7 From referrals
Where an existing Learner or partner refers you, we may receive your name and contact details. If you do not wish to be contacted, tell us at support@brandvantageacademy.com and we will delete the referral record.
06Purposes of processing and lawful basis
We process personal data for the following specified purposes. For each, we identify the lawful basis under the DPDP Act — either your consent under Section 6, or a legitimate use under Section 7.
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries, sending brochures, and counselling you on Programme options | Consent; voluntarily provided data (S.7(a)) |
| Processing your enrolment, verifying eligibility and prerequisites, and forming the contract | Consent; performance of contract |
| Collecting Fees, issuing GST-compliant invoices, and processing refunds or cohort transfers | Consent; legal obligation (S.7(b)) |
| Delivering the Programme — providing access to the learning portal, content, live sessions, mentoring, and support | Consent; performance of contract |
| Recording attendance and administering assessments, projects, and proctoring | Consent; performance of contract |
| Issuing, verifying, and where necessary revoking certificates | Consent; performance of contract |
| Providing career readiness services — resume building, LinkedIn optimisation, mock interviews, counselling | Consent |
| Sharing your profile and resume with prospective employers and internship hosts for placement assistance | Consent (separate and specific — see Clause 11.3) |
| Reporting attendance, progress, and outcomes to your partner Institution or Corporate Client | Consent; contractual arrangement with the Institution or Corporate Client |
| Quality assurance, trainer development, curriculum improvement, and learning analytics | Consent; legitimate use |
| Providing learner support and resolving grievances | Consent; performance of contract |
| Security, fraud prevention, credential-sharing detection, and protection of our systems and content | Legitimate use; legal obligation |
| Marketing, newsletters, event invitations, and promotional communications | Consent (withdrawable at any time) |
| Publishing testimonials, success stories, photographs, and case studies | Separate specific written consent (see Clause 10.4) |
| Statutory and regulatory compliance — GST, income tax, TDS, company law, POSH, and responses to lawful requests | Legal obligation (S.7(b)); compliance with judgment or order (S.7(e)) |
| Establishing, exercising, or defending legal claims | Legitimate use; legal proceedings |
| Responding to a medical emergency, epidemic, or threat to safety during an in-person session | Medical emergency / public health (S.7(f), S.7(g)) |
| Corporate transactions such as merger, acquisition, restructuring, or transfer of business | Legitimate use; legal obligation |
6.1 Purpose limitation
We will not process your personal data for any purpose other than those listed above, or a purpose compatible with them, without first obtaining your consent.
6.2 Data minimisation
We collect only what is necessary for the stated purpose. Optional fields are clearly marked as optional and declining to complete them will not prevent your enrolment, though it may limit certain services (for example, we cannot provide placement assistance without a resume).
07Consent and withdrawal
7.1 Nature of consent
Where we rely on consent, that consent will be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. We do not use pre-ticked boxes, and we do not bundle unrelated purposes into a single consent.
7.2 Consent notice
At or before the point of collection, we will give you a notice stating the personal data sought, the purpose, how to exercise your rights under Clause 17, and how to complain to the Board. That notice will be made available in English and, where required, in any language specified in the Eighth Schedule to the Constitution of India.
7.3 Separate consents
We seek separate, granular consent for:
- sharing your profile with prospective employers and internship hosts;
- marketing and promotional communications;
- use of your name, photograph, video, or testimonial in marketing material; and
- processing of any health or accessibility information.
You may consent to some and not others.
7.4 Withdrawing consent
You may withdraw your consent at any time, and it must be as easy to withdraw as it was to give. To withdraw, write to support@brandvantageacademy.com, use the unsubscribe link in any marketing email, or use the preference controls in your account where available.
7.5 Consequences of withdrawal
Withdrawal takes effect prospectively and does not affect the lawfulness of processing carried out before withdrawal. On withdrawal, we will cease processing for the affected purpose within a reasonable time and will cause our Data Processors to do the same, unless retention is required by law (Clause 13).
Important: Withdrawing consent for processing that is essential to delivery of a Programme — for example, attendance recording, assessment, or platform access — will make continued participation impossible. Withdrawal of consent does not entitle you to a refund of Fees, which remain governed by Clause 8 of the Terms and Conditions.
7.6 Consent managers
Where the framework under the DPDP Rules, 2025 becomes operational, you may give, manage, review, and withdraw consent through a Consent Manager registered with the Data Protection Board of India. We will honour instructions received through a registered Consent Manager as if received directly from you.
7.7 Data collected before this policy
Where we hold personal data collected before the DPDP Act came into force, we will, as required by Section 5(2), give you notice of that processing as soon as reasonably practicable. You may withdraw consent in respect of that data at any time.
08Payment data
8.1 Payment aggregator
Payments are processed by third-party payment aggregators authorised by the Reserve Bank of India under the Payment Aggregators and Payment Gateways Directions. When you pay, you are redirected to, or served a secure frame hosted by, the aggregator.
8.2 What we receive
We receive only the transaction outcome — success or failure, amount, transaction reference, payment method type, timestamp, and (for cards) the last four digits and network. We never receive or store your full card number, CVV, PIN, or OTP.
8.3 Tokenisation
Card details, where saved, are tokenised by the aggregator in accordance with RBI's card-on-file tokenisation framework. Tokens are held by the aggregator, not by us, and cannot be used outside the authorised merchant context.
8.4 PCI DSS
Our payment aggregators represent that they maintain PCI DSS compliance for the handling of cardholder data.
8.5 Aggregator privacy policies
Your interaction with a payment aggregator is governed by that aggregator's own privacy policy and terms, which we encourage you to review.
8.6 Financial records retention
Invoices, payment records, and GST records are retained for the period required under the Income-tax Act, 1961, the Central Goods and Services Tax Act, 2017, and the Companies Act, 2013 — see Clause 13.
10Recordings, photography, proctoring and CCTV
10.1 Session recordings
Live online sessions may be recorded for quality assurance, trainer development, learner support, and revision access. You will be informed at the start of a session that recording is in progress. Recordings capture audio, video where your camera is on, chat messages, and shared screens. If you prefer not to appear on video, you may keep your camera off, subject to any attendance verification requirement notified for that session.
10.2 Assessment proctoring
Certain assessments may be proctored. Where proctoring involves camera monitoring, screen monitoring, or recording, you will be told in advance, told what is captured, and told how long it is retained. Proctoring data is used solely for assessment integrity and is not used for any other purpose.
10.3 Photography and videography at events
We may photograph or film classroom sessions, workshops, campus events, hiring drives, and seminars for internal records and, subject to Clause 10.4, for promotional use. Signage or verbal notice will be given at the venue. If you do not wish to be photographed, tell the event coordinator and we will take reasonable steps to exclude you.
10.4 Promotional use — separate consent required
We will use your name, photograph, video, testimonial, achievement, or placement outcome in marketing material only with your prior separate written consent — or the written consent of your parent or lawful guardian if you are under 18. That consent is revocable at any time by writing to support@brandvantageacademy.com. On revocation we will stop further use and remove the material from our digital channels within a reasonable period, although we may be unable to recall printed material already distributed or content already reshared by third parties.
10.5 CCTV
Academy premises and training centres may be monitored by CCTV for safety and security. Footage is retained for a limited period (ordinarily 30 to 90 days) and accessed only for security, incident investigation, or where required by law.
10.6 Call recording
Counselling, support, or sales calls may be recorded for quality and training. You will be informed at the start of the call and may ask that the call not be recorded.
12Children and persons with disability
12.1 Verifiable parental consent
Where a Learner is under eighteen (18) years of age, we process personal data only after obtaining verifiable consent from the parent or lawful guardian, in accordance with Section 9 of the DPDP Act and the DPDP Rules, 2025.
12.2 How we verify
We verify parental identity and status by one or more of the following, proportionate to the risk:
- confirmation from a verified parent or guardian email address and mobile number, authenticated by OTP;
- a signed consent form (physical or electronic) accompanied by a copy of a government-issued identity document with sensitive fields masked;
- where the Learner is enrolled through a school or pre-university college, a consent record collected and certified by the Institution in the form prescribed by us; or
- a virtual token or verified digital identity issued or mapped by an authorised digital locker service provider, where available.
12.3 Prohibited processing in respect of children
We do not, in respect of any Learner under 18:
- undertake tracking, behavioural monitoring, or profiling;
- serve targeted or behavioural advertising;
- process personal data in any manner likely to cause a detrimental effect on the child's well-being; or
- deploy analytics, advertising, or retargeting cookies.
12.4 No independent accounts
Learners under 18 may not independently create an account, enrol, or make a payment. Enrolment must be completed by the parent or lawful guardian, who is the contracting party under the Terms and Conditions.
12.5 Institution's responsibility
Where enrolment is routed through a school or pre-university Institution, that Institution is responsible for obtaining, recording, and furnishing evidence of parental or guardian consent in the form prescribed by us, and for confirming the accuracy of the ages it reports to us.
12.6 Discovery of unverified child data
If we discover that we hold the personal data of a child without verifiable parental consent, we will suspend processing, seek consent, and if consent is not obtained within a reasonable period, delete the data.
12.7 Persons with disability
Where a Learner is a person with disability who has a lawful guardian appointed under applicable law, we process personal data on the basis of the guardian's consent, and the guardian may exercise all rights under Clause 17 on the Learner's behalf.
12.8 Exemptions
Certain obligations under Section 9 may be relaxed for specified classes of Data Fiduciary or specified purposes as notified by the Central Government. We will apply any such exemption only where it lawfully applies and will update this Policy accordingly.
13Data retention
13.1 Principle
We retain personal data only for as long as is necessary for the purpose for which it was collected, or for as long as required by law, whichever is longer. Once the purpose is served and no legal retention obligation applies, we erase the data or de-identify it irreversibly.
13.2 Indicative retention periods
| Data category | Retention period | Reason |
|---|---|---|
| Enquiry and prospect data (not converted) | 24 months from last interaction, or until consent withdrawn | Follow-up and re-engagement |
| Enrolment, academic and assessment records | 7 years from Programme completion | Certificate verification, disputes, quality audit |
| Certificate issuance records | Indefinitely, in a minimised form (name, Programme, dates, certificate ID) | Lifelong certificate verification for employers |
| Attendance records | 7 years from Programme completion | Certification eligibility and audit |
| Financial, invoice, GST and tax records | 8 years from the end of the relevant financial year | Income-tax Act 1961; CGST Act 2017; Companies Act 2013 |
| Payment transaction logs | 8 years | Statutory and audit |
| Placement and employer-sharing records | 3 years from last placement activity | Outcome tracking and dispute resolution |
| Session recordings | 12 months from the session date, unless a longer access period is stated for the Programme | Revision access and quality assurance |
| Proctoring data | 6 months from the assessment date | Assessment integrity challenges |
| Mock interview recordings | 6 months, or until you ask us to delete them | Coaching feedback |
| CCTV footage | 30 to 90 days | Security and incident investigation |
| Call recordings | 12 months | Quality, training, dispute resolution |
| Marketing consent and preference records | Duration of consent plus 3 years | Evidence of consent and opt-out honouring |
| Website analytics and server logs | 12 months | Security and performance |
| Security and access logs | 1 year (minimum) | DPDP Rules, 2025 security safeguards |
| Grievance and complaint records | 3 years from closure | Regulatory and audit |
| Job applicant data (unsuccessful) | 12 months from decision, unless you consent to a longer talent-pool retention | Future opportunities |
| Data subject to legal hold or ongoing proceedings | Until the matter is finally concluded | Legal claims |
These periods are indicative. Where a longer or shorter period is required by law or by a specific contractual arrangement with an Institution or Corporate Client, that period applies.
13.3 Erasure on withdrawal
Where you withdraw consent, we will erase the affected personal data, and cause our Data Processors to do the same, unless retention is necessary for compliance with law or for legal proceedings.
13.4 Backups
Data deleted from live systems may persist in encrypted backups for a limited period until those backups are cycled out in the ordinary course. Backup data is not used for any active purpose.
14Security safeguards
14.1 Our commitment
We implement reasonable security safeguards to prevent personal data breach, as required by Section 8(5) of the DPDP Act, the DPDP Rules, 2025, and Rule 8 of the SPDI Rules, 2011.
14.2 Technical measures
- encryption of personal data in transit using TLS, and at rest for sensitive fields;
- role-based access control on the principle of least privilege;
- multi-factor authentication for administrative and privileged accounts;
- hashing and salting of account passwords — we cannot see your password in plain text;
- masking of identity document numbers and financial identifiers;
- firewalls, intrusion detection, endpoint protection, and vulnerability patching;
- logging and monitoring of access to personal data, with logs retained for at least one year to enable detection and investigation of unauthorised access;
- encrypted, tested backups with defined recovery objectives;
- segregation of production, staging, and test environments, with no live personal data used in testing.
14.3 Organisational measures
- written contracts with all Data Processors imposing DPDP-compliant obligations;
- confidentiality undertakings from employees, trainers, mentors, and contractors;
- periodic privacy and security awareness training for staff and trainers;
- documented access review, joiner-mover-leaver, and offboarding procedures;
- an incident response and breach management plan;
- periodic review of this Policy and of our processing activities;
- privacy-by-design review of new systems, integrations, and vendor onboarding.
14.4 Physical measures
Access-controlled premises, visitor logging, secure storage of physical records, and secure shredding of documents at end of life.
14.5 No absolute guarantee
While we take these measures seriously, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security. You share information with us at your own risk, and you are responsible for keeping your own credentials confidential and your own devices secure.
15Third-party links and platforms
The Website and our Programmes may link to or require use of third-party websites, tools, cloud consoles, code repositories, developer accounts, generative AI services, and social media platforms. We do not control these and are not responsible for their privacy practices. Their processing of your data is governed by their own privacy policies, which you should read before use. Where a Programme requires you to create a third-party account, we will tell you before enrolment.
16Cross-border data transfers
16.1 Where data is stored
We primarily store personal data on servers located in India. Some of our service providers — particularly cloud hosting, video conferencing, email, analytics, and CRM providers — may store or process data on servers located outside India.
16.2 Legal position
Under Section 16 of the DPDP Act, transfer of personal data outside India is permitted except to a country or territory notified as restricted by the Central Government. We monitor such notifications and will not transfer personal data to a restricted territory.
16.3 Additional sectoral restrictions
Where any other law imposes a stricter localisation requirement on a category of data, that stricter requirement prevails and we will comply with it.
16.4 Safeguards
Where personal data is transferred outside India, we require the recipient by contract to (a) process it only on our instructions and only for the specified purpose, (b) apply security safeguards no less protective than those in Clause 14, (c) assist us in responding to your rights requests, and (d) notify us promptly of any breach.
16.5 Global group locations
Brand Vantage operates from Melbourne, Boston, Sharjah, and Bengaluru. Personal data collected through the Academy is not routinely shared with other group locations. Where it is necessary to do so — for example for a global corporate training engagement — Clause 16.4 applies.
17Your rights as a data principal
Subject to the DPDP Act, you have the following rights.
17.1 Right to access information (Section 11)
You may request a summary of the personal data we are processing about you, the processing activities undertaken, and the identities of all other Data Fiduciaries and Data Processors with whom your data has been shared, together with a description of the data shared.
17.2 Right to correction, completion, updating and erasure (Section 12)
You may request that we:
- correct inaccurate or misleading personal data;
- complete incomplete personal data;
- update out-of-date personal data; and
- erase personal data that is no longer necessary for the purpose for which it was processed.
We may decline erasure where retention is necessary for a specified purpose or for compliance with law — for example, financial records, certificate verification records, or data subject to legal hold. We will tell you if we decline and why.
17.3 Right of grievance redressal (Section 13)
You have the right to a readily available means of grievance redressal in respect of any act or omission of ours regarding your personal data. See Clause 20. You must exhaust this mechanism before approaching the Data Protection Board.
17.4 Right to nominate (Section 14)
You may nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity. To register a nomination, write to support@brandvantageacademy.com with the nominee's name, relationship, and contact details.
17.5 Right to withdraw consent
See Clause 7.4.
17.6 Right to opt out of marketing
You may opt out of marketing communications at any time using the unsubscribe link or by writing to us. You cannot opt out of essential service communications while you are enrolled in a Programme.
17.7 How to exercise your rights
Send a written request to support@brandvantageacademy.com, or by post to the address in Clause 20, stating:
- your full name and the email address or mobile number registered with us;
- your enrolment or transaction reference, if any;
- the right you wish to exercise; and
- sufficient detail for us to locate the data.
17.8 Verification
To protect your data, we will verify your identity before acting on a request. We may ask for additional information for this purpose only. Where the request is made by a parent, guardian, or nominee, we will also verify their authority.
17.9 Timelines
We will acknowledge your request within forty-eight (48) hours and respond substantively within thirty (30) days of receipt of a verified request. Where a request is complex or numerous, we may extend this period and will tell you the reason for the extension.
17.10 No fee
We do not charge a fee for exercising your rights. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to act, giving reasons.
18Your duties as a data principal
Section 15 of the DPDP Act imposes duties on you. You must:
- comply with applicable law when exercising your rights;
- not impersonate another person when providing personal data for a specified purpose;
- not suppress any material information when providing personal data for any document, identifier, proof of identity, or proof of address issued by the State;
- not register a false or frivolous grievance or complaint; and
- furnish only information that is verifiably authentic when exercising your right to correction or erasure.
Breach of these duties may attract a penalty under the DPDP Act, and may also constitute a breach of our Terms and Conditions.
19Marketing communications and telecom consent
19.1 Service communications
While you are enrolled, we will send you essential service communications by email, SMS, WhatsApp, and telephone — session reminders, schedule changes, assessment notices, fee receipts, certificate issuance, and support responses. You cannot opt out of these while enrolled.
19.2 Promotional communications
We send promotional communications — new Programme launches, webinars, events, offers, and newsletters — only with your consent.
19.3 DND and TRAI registers
By providing your contact details and consenting, you authorise us and our authorised representatives to contact you notwithstanding any registration on the National Do Not Call Registry, the National Customer Preference Register, or any DND list, for the purposes set out above. This authorisation is revocable.
19.4 Opting out
Use the unsubscribe link in any marketing email, reply STOP to a marketing SMS, use the block or opt-out control on WhatsApp, or write to support@brandvantageacademy.com. We will action your opt-out within 7 Business Days.
20Grievance redressal and data protection contact
20.1 Grievance Officer
In compliance with the DPDP Act, 2023, the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Consumer Protection (E-Commerce) Rules, 2020:
| Name | grievance officer name |
| Designation | Grievance Officer, Brand Vantage Academy |
| support@brandvantageacademy.com | |
| Telephone | +91 8073707619 |
| Address | Brand Vantage Academy, 11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066 |
| Working hours | Monday – Friday | 8:30 AM – 5:30 PM IST (excluding public holidays) |
20.2 Data Protection Officer
We are not presently notified as a Significant Data Fiduciary under Section 10 of the DPDP Act. If we are so notified, we will appoint a Data Protection Officer based in India, publish the DPO's contact details on this page, conduct periodic Data Protection Impact Assessments, and undergo independent data audits as required.
20.3 How to complain
Write to the Grievance Officer with your name, contact details, enrolment or transaction reference, a clear description of the complaint, and the outcome sought. We will acknowledge within 48 hours and redress within 30 days (or such shorter period as the law prescribes for the category of complaint).
20.4 Escalation to the Board
If you are not satisfied with our response, or if we fail to respond within the prescribed period, you may lodge a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act. An appeal against an order of the Board lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
20.5 Consumer forums
Nothing in this Policy restricts your rights under the Consumer Protection Act, 2019.
21Personal data breach
21.1 Our response
In the event of a personal data breach, we will activate our incident response plan, contain the breach, assess its scope and impact, and take remedial action.
21.2 Notification to you
We will inform each affected Data Principal without delay, in a concise, clear, and plain manner, through the user account or the registered mode of communication, describing the nature, extent, and timing of the breach, the likely consequences, the measures we have taken or are taking to mitigate risk, safety measures you may take, and our contact details for further information.
21.3 Notification to the Board
We will intimate the Data Protection Board of India without delay on becoming aware of the breach, and will furnish detailed particulars — including the events and circumstances leading to the breach, the mitigation measures taken, the findings on the person who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals — within seventy-two (72) hours, or such longer period as the Board may allow on request.
21.4 CERT-In
Where applicable, we will also report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within the timelines prescribed under its directions.
22Automated processing and artificial intelligence
22.1 Where we use automation
We may use automated tools to score objective assessments, flag potential plagiarism or assessment irregularities, generate learning analytics and progress dashboards, match learner profiles to internship or placement opportunities, and detect credential sharing or fraudulent activity.
22.2 Human oversight
We do not make decisions that produce significant adverse effects on you — such as withholding certification, revoking a certificate, terminating enrolment, or withdrawing placement support — on the basis of automated processing alone. Such decisions are reviewed by a qualified member of our team before they take effect, and you may contest the outcome through Clause 20.
22.3 AI tools in delivery
Programmes may involve the use of generative AI tools as part of the curriculum. Where you input data into a third-party AI tool, that input is governed by the tool provider's own terms and privacy policy. Do not input personal data of others, confidential information, or client data into any AI tool during a Programme.
22.4 We do not train models on your data
We do not use your personal data, submissions, or session recordings to train, fine-tune, or evaluate any commercial machine learning or artificial intelligence model, and we contractually prohibit our Data Processors from doing so.
23Job applicants and trainers
Where you apply for employment, a trainer role, or a mentor engagement with the Academy, we process your name, contact details, resume, qualifications, work history, references, interview notes, and assessment outcomes for the purpose of evaluating your application. We retain unsuccessful applicant data for 12 months unless you consent to longer retention in our talent pool. Background verification, where conducted, will be carried out with your prior consent and by a verification agency bound by confidentiality.
24Changes to this policy
We may update this Policy to reflect changes in law, technology, or our practices. The revised Policy will be posted here with an updated "Last updated" date and takes effect from the date of posting.
Where a change materially affects how we process your personal data or the rights available to you, we will give you not less than fifteen (15) days' prior notice by email, and where the change requires it, we will seek fresh consent.
We encourage you to review this page periodically. Continued use of the Website or participation in a Programme after the effective date constitutes acceptance of the revised Policy, save where fresh consent is required.
25Governing law
This Policy is governed by the laws of India. Disputes arising out of or in connection with it are subject to the dispute resolution and jurisdiction provisions in Clause 27 of our [Terms and Conditions](/terms) — arbitration seated at Bengaluru under the Arbitration and Conciliation Act, 1996, with the courts at Bengaluru, Karnataka having exclusive jurisdiction — without prejudice to your statutory right to approach the Data Protection Board of India or a consumer commission.
26How to contact us
| Privacy, data protection and grievances | support@brandvantageacademy.com |
| General enquiries | info@brandvantageacademy.com |
| Partnerships | partnerships@brandvantageacademy.com |
| Telephone | +91 8073707619 |
| Address | 11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066 |
| Website | www.brandvantageacademy.com |
