Skip to content
Brand Vantage Academy

Privacy policy

What personal data we collect, why we collect it, who we share it with, how long we keep it, what rights you have, and how to complain.

Last updated
2026-08-14
Contracting party
Brand Vantage Marketing Private Limited

This Privacy Policy also serves as the notice required under Section 5 of the Digital Personal Data Protection Act, 2023 and Rule 3 of the Digital Personal Data Protection Rules, 2025. Please read it carefully. If you do not agree with it, please do not use this website or enrol in any Programme.

This Policy forms an integral part of our Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms and Conditions.

01Who we are

Brand Vantage Academy ("the Academy", "we", "us", "our") is a brand and business division of Brand Vantage Marketing Private Limited, a company incorporated under the Companies Act, 2013.

CINU73100KA2023PTC176608
PANAALCB8059L
GSTIN29AALCB8059L1ZW
Principal place of business11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066
Registered officeregistered office as per MCA records
Websitewww.brandvantageacademy.com
Privacy / grievance contactsupport@brandvantageacademy.com
Telephone+91 8073707619

We act as the Data Fiduciary in respect of the personal data described in this Policy — meaning we determine the purpose and means of processing your personal data and are accountable for it under the DPDP Act.

Where we deliver a Programme on behalf of a partner Institution or a Corporate Client, that Institution or Corporate Client may be an independent Data Fiduciary in respect of the student or employee data it holds and shares with us, and we may act as a Data Processor on its instructions in respect of that data. In such cases, the Institution's or Corporate Client's own privacy policy will also apply to you.

02Scope of this policy

This Policy applies to personal data we process in relation to:

  • visitors to and users of the Website and our learning portals;
  • prospective learners who submit enquiries, registration forms, or download brochures;
  • enrolled Learners, including students enrolled through a partner Institution;
  • parents and lawful guardians of Learners under 18 years of age;
  • participants nominated by Corporate Clients;
  • representatives of Institutions, Corporate Clients, Delivery Partners, trainers, mentors, and vendors;
  • applicants for employment or trainer engagement with the Academy; and
  • attendees at our webinars, workshops, campus events, seminars, and hiring drives.

This Policy does not apply to third-party websites, platforms, or services that we link to or that you use during a Programme. Those are governed by their own privacy policies (see Clause 15).

03Definitions

TermMeaning
Personal DataAny data about an individual who is identifiable by or in relation to such data.
ProcessingAny wholly or partly automated operation performed on personal data — including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, alignment, restriction, erasure, or destruction.
Data PrincipalThe individual to whom the personal data relates. Where the individual is a child, it includes the parent or lawful guardian. Where the individual is a person with disability having a lawful guardian, it includes that guardian.
Data FiduciaryThe person who alone or with others determines the purpose and means of processing personal data.
Data ProcessorAny person who processes personal data on behalf of a Data Fiduciary.
ChildAn individual who has not completed eighteen (18) years of age.
Consent ManagerA person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.
Sensitive Personal Data or InformationAs defined under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — including passwords, financial information, physical, physiological or mental health condition, sexual orientation, medical records, and biometric information.
DPDP ActThe Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025, as amended.
BoardThe Data Protection Board of India.

04The personal data we collect

We collect only the personal data that is necessary for the specified purposes set out in Clause 6.

4.1 Identity and contact data

Full name; date of birth and age; gender (optional); photograph; email address; mobile and alternate telephone numbers; postal address, city, state, PIN code, and country; WhatsApp number; emergency contact name and number.

4.2 Guardian data (where the Learner is under 18)

Parent or lawful guardian's name, relationship to the Learner, email address, mobile number, address, and identity or age verification token where required to obtain verifiable consent under Section 9 of the DPDP Act.

4.3 Academic and professional data

Institution or college name; stream, course, branch, semester, and year of study; university registration or roll number; academic qualifications, marks, percentages, CGPA, and transcripts; backlog or arrear status where relevant to eligibility; prior work experience; current employer and designation; resume or curriculum vitae; LinkedIn, GitHub, or portfolio URLs; skills, certifications, and language proficiency.

4.4 Enrolment and programme data

Programme and Cohort enrolled in; enrolment date and status; attendance records; assignment and project submissions; assessment responses, scores, grades, and feedback; capstone and live project outputs; certificates issued; trainer and mentor feedback; learning-platform activity such as modules accessed, time spent, video progress, and quiz attempts; support tickets and queries raised.

4.5 Internship and placement data

Placement preferences (role, location, sector, salary expectation); resume versions prepared with us; mock interview recordings and evaluations; profiles shared with prospective employers and internship hosts; interview schedules, feedback, and outcomes; offer letters, joining status, employer name, designation, and stipend or salary details where you disclose them; internship host feedback and completion certificates.

4.6 Financial and transaction data

Fee amount, invoice number, GSTIN (for business enrolments), billing name and address, transaction reference and identifier, payment method type, payment status, date and time of payment, refund or transfer records, and the last four digits and card network of a payment card as reported back to us by the payment aggregator.

We do not collect, store, or have access to your full card number, CVV, card PIN, UPI PIN, net banking username or password, or any OTP. These are captured directly by the payment aggregator on its own secure infrastructure. See Clause 8.

4.7 Identity and verification documents

Where required for enrolment verification, certification, examination proctoring, scholarship eligibility, campus access, or statutory compliance, we may collect a copy of a government-issued identity document (for example Aadhaar, PAN, passport, driving licence, or student identity card), a bonafide certificate, or an income or category certificate.

Where an Aadhaar number is furnished, we collect it only where lawfully permitted, we mask all but the last four digits in our records, and we do not use it as a general identifier. You may furnish an alternative identity document instead.

4.8 Technical and usage data

IP address; device type, model, and unique device identifier; operating system and version; browser type, version, and language; screen resolution; referring and exit URLs; pages viewed and time spent; clickstream and navigation paths; date and time stamps; approximate location derived from IP address; crash logs and diagnostic data; cookie and similar-technology identifiers (see Clause 9).

4.9 Audio-visual data

Recordings of live online sessions (audio, video, chat, screen share, and on-screen contributions); photographs and video captured at classroom sessions, campus events, workshops, hiring drives, and seminars; mock interview recordings; CCTV footage at Academy premises and training centres. See Clause 10.

4.10 Communications data

Emails, WhatsApp messages, SMS, call records and call recordings (where a call is recorded and you are informed at the outset), chat transcripts, enquiry form submissions, feedback forms, survey responses, testimonials, and social media interactions with our official accounts.

4.11 Marketing and preference data

Your consent status for marketing communications; channel preferences; areas of interest; event registrations and attendance; brochure downloads; engagement with our emails and campaigns.

4.12 Sensitive personal data

We do not ordinarily seek sensitive personal data. We may collect limited health or accessibility information only where you voluntarily provide it so that we can make reasonable accommodations (for example, extra assessment time, accessible seating, or dietary requirements at an event), or in a medical emergency during an on-campus or in-person session. Such data is processed strictly for that purpose, on a need-to-know basis, and deleted when no longer required.

4.13 Data we do not want

Please do not send us your passwords, full card details, bank account credentials, medical records, caste or religious details, political opinions, or biometric data unless we have specifically and lawfully asked for them. If you send unsolicited sensitive data, we will delete it.

05How we collect personal data

5.1 Directly from you

Through enquiry and registration forms; enrolment and admission forms; account creation; payment checkout; assessments and assignments; feedback and survey forms; email, telephone, and WhatsApp correspondence; event and webinar registrations; resume and profile submissions; and consent forms.

5.2 Automatically

Through cookies, pixels, tags, SDKs, server logs, and analytics tools when you visit the Website or use the learning portal. See Clause 9.

5.3 From partner institutions

Where you are enrolled through a school, pre-university college, degree college, engineering college, or university, that Institution may share your name, contact details, academic details, stream, semester, roll number, attendance, and — where you are under 18 — evidence of parental or guardian consent. The Institution is responsible for having a lawful basis for that disclosure.

5.4 From corporate clients

Where you are nominated for corporate training, your employer may share your name, official email, employee identifier, designation, department, and training history.

5.5 From delivery partners and trainers

Attendance, assessment scores, project evaluations, and progress feedback recorded by trainers, mentors, and Delivery Partners including Bluink360 Solutions.

5.6 From third parties and public sources

Payment aggregators (transaction confirmations and status); learning platform and video conferencing providers (attendance and engagement logs); prospective employers and internship hosts (interview feedback and outcomes); referral sources; and publicly available professional profiles that you have made public, where relevant to placement assistance.

5.7 From referrals

Where an existing Learner or partner refers you, we may receive your name and contact details. If you do not wish to be contacted, tell us at support@brandvantageacademy.com and we will delete the referral record.

06Purposes of processing and lawful basis

We process personal data for the following specified purposes. For each, we identify the lawful basis under the DPDP Act — either your consent under Section 6, or a legitimate use under Section 7.

PurposeLawful basis
Responding to enquiries, sending brochures, and counselling you on Programme optionsConsent; voluntarily provided data (S.7(a))
Processing your enrolment, verifying eligibility and prerequisites, and forming the contractConsent; performance of contract
Collecting Fees, issuing GST-compliant invoices, and processing refunds or cohort transfersConsent; legal obligation (S.7(b))
Delivering the Programme — providing access to the learning portal, content, live sessions, mentoring, and supportConsent; performance of contract
Recording attendance and administering assessments, projects, and proctoringConsent; performance of contract
Issuing, verifying, and where necessary revoking certificatesConsent; performance of contract
Providing career readiness services — resume building, LinkedIn optimisation, mock interviews, counsellingConsent
Sharing your profile and resume with prospective employers and internship hosts for placement assistanceConsent (separate and specific — see Clause 11.3)
Reporting attendance, progress, and outcomes to your partner Institution or Corporate ClientConsent; contractual arrangement with the Institution or Corporate Client
Quality assurance, trainer development, curriculum improvement, and learning analyticsConsent; legitimate use
Providing learner support and resolving grievancesConsent; performance of contract
Security, fraud prevention, credential-sharing detection, and protection of our systems and contentLegitimate use; legal obligation
Marketing, newsletters, event invitations, and promotional communicationsConsent (withdrawable at any time)
Publishing testimonials, success stories, photographs, and case studiesSeparate specific written consent (see Clause 10.4)
Statutory and regulatory compliance — GST, income tax, TDS, company law, POSH, and responses to lawful requestsLegal obligation (S.7(b)); compliance with judgment or order (S.7(e))
Establishing, exercising, or defending legal claimsLegitimate use; legal proceedings
Responding to a medical emergency, epidemic, or threat to safety during an in-person sessionMedical emergency / public health (S.7(f), S.7(g))
Corporate transactions such as merger, acquisition, restructuring, or transfer of businessLegitimate use; legal obligation

6.1 Purpose limitation

We will not process your personal data for any purpose other than those listed above, or a purpose compatible with them, without first obtaining your consent.

6.2 Data minimisation

We collect only what is necessary for the stated purpose. Optional fields are clearly marked as optional and declining to complete them will not prevent your enrolment, though it may limit certain services (for example, we cannot provide placement assistance without a resume).

08Payment data

8.1 Payment aggregator

Payments are processed by third-party payment aggregators authorised by the Reserve Bank of India under the Payment Aggregators and Payment Gateways Directions. When you pay, you are redirected to, or served a secure frame hosted by, the aggregator.

8.2 What we receive

We receive only the transaction outcome — success or failure, amount, transaction reference, payment method type, timestamp, and (for cards) the last four digits and network. We never receive or store your full card number, CVV, PIN, or OTP.

8.3 Tokenisation

Card details, where saved, are tokenised by the aggregator in accordance with RBI's card-on-file tokenisation framework. Tokens are held by the aggregator, not by us, and cannot be used outside the authorised merchant context.

8.4 PCI DSS

Our payment aggregators represent that they maintain PCI DSS compliance for the handling of cardholder data.

8.5 Aggregator privacy policies

Your interaction with a payment aggregator is governed by that aggregator's own privacy policy and terms, which we encourage you to review.

8.6 Financial records retention

Invoices, payment records, and GST records are retained for the period required under the Income-tax Act, 1961, the Central Goods and Services Tax Act, 2017, and the Companies Act, 2013 — see Clause 13.

09Cookies and similar technologies

9.1 What cookies are

Cookies are small text files placed on your device. We also use pixels, web beacons, local storage, and software development kits, all referred to here as "cookies".

9.2 Categories we use

CategoryPurposeConsent required
Strictly necessaryLogin and session management, security, load balancing, fraud prevention, remembering your cookie choicesNo — required for the site to function
FunctionalRemembering language, region, form entries, and display preferencesYes
Analytics / performanceUnderstanding how visitors use the site, which pages are popular, where errors occur, so we can improveYes
Marketing / advertisingMeasuring campaign performance, retargeting, and audience building on advertising platformsYes

9.3 Third-party cookie providers

We may use the following categories of third-party service on the Website: web analytics, tag management, advertising and conversion tracking, live chat, embedded video, and social media plugins. The providers currently in use are: third-party cookie and tracking providers actually deployed.

9.4 Managing cookies

cookie banner and consent controls — not yet built on this site You can block or delete cookies through your browser settings, though blocking strictly necessary cookies may prevent parts of the Website from working.

9.5 Do Not Track

Our Website does not currently respond to browser "Do Not Track" signals, as no common standard has been adopted.

9.6 No tracking of children

We do not deploy analytics, advertising, behavioural monitoring, or retargeting cookies in respect of users we know or reasonably believe to be under 18. See Clause 12.

10Recordings, photography, proctoring and CCTV

10.1 Session recordings

Live online sessions may be recorded for quality assurance, trainer development, learner support, and revision access. You will be informed at the start of a session that recording is in progress. Recordings capture audio, video where your camera is on, chat messages, and shared screens. If you prefer not to appear on video, you may keep your camera off, subject to any attendance verification requirement notified for that session.

10.2 Assessment proctoring

Certain assessments may be proctored. Where proctoring involves camera monitoring, screen monitoring, or recording, you will be told in advance, told what is captured, and told how long it is retained. Proctoring data is used solely for assessment integrity and is not used for any other purpose.

10.3 Photography and videography at events

We may photograph or film classroom sessions, workshops, campus events, hiring drives, and seminars for internal records and, subject to Clause 10.4, for promotional use. Signage or verbal notice will be given at the venue. If you do not wish to be photographed, tell the event coordinator and we will take reasonable steps to exclude you.

10.4 Promotional use — separate consent required

We will use your name, photograph, video, testimonial, achievement, or placement outcome in marketing material only with your prior separate written consent — or the written consent of your parent or lawful guardian if you are under 18. That consent is revocable at any time by writing to support@brandvantageacademy.com. On revocation we will stop further use and remove the material from our digital channels within a reasonable period, although we may be unable to recall printed material already distributed or content already reshared by third parties.

10.5 CCTV

Academy premises and training centres may be monitored by CCTV for safety and security. Footage is retained for a limited period (ordinarily 30 to 90 days) and accessed only for security, incident investigation, or where required by law.

10.6 Call recording

Counselling, support, or sales calls may be recorded for quality and training. You will be informed at the start of the call and may ask that the call not be recorded.

11Sharing and disclosure

We do not sell your personal data. We do not rent, trade, or barter it. We do not share it with data brokers. We share personal data only as set out below, and only to the extent necessary.

11.1 Delivery partners, trainers and mentors

Name, contact details, Programme, attendance, and assessment data are shared with trainers, mentors, and Delivery Partners — including Bluink360 Solutions — strictly for delivery, assessment, and support. They are bound by contractual confidentiality and data protection obligations and may not use the data for their own purposes.

11.2 Partner institutions

Where you are enrolled through an Institution, we share attendance, progress, assessment outcomes, certification status, and placement outcomes with that Institution for programme monitoring and reporting.

11.3 Prospective employers and internship hosts

Only with your separate specific consent, we share your name, contact details, resume, academic details, skills, certifications, assessment scores, and placement preferences with prospective employers and internship hosts for the purpose of placement assistance.

You may withdraw this consent at any time, in which case we will stop sharing your profile going forward. We cannot recall a profile already shared with an employer — once shared, that employer becomes an independent Data Fiduciary in respect of the data and its own privacy policy governs. You may contact the employer directly to exercise your rights against it.

11.4 Corporate clients

Where your employer nominated you, we share attendance, completion status, assessment results, and feedback with your employer as agreed in the corporate training agreement.

11.5 Service providers and data processors

We engage service providers who process personal data on our behalf under written contracts containing DPDP-compliant obligations. Categories include:

CategoryPurpose
Cloud hosting and storageHosting the Website, learning portal, and databases
Learning management system providersCourse delivery, content hosting, progress tracking
Video conferencing platformsDelivery and recording of live sessions
Assessment and proctoring platformsTests, quizzes, and integrity monitoring
Payment aggregatorsFee collection and refunds
Email, SMS, and WhatsApp gatewaysTransactional and (with consent) marketing communications
CRM and marketing automationEnquiry management, learner lifecycle, campaigns
Analytics providersWebsite and platform usage measurement
Accounting, tax, audit, and legal advisersStatutory compliance and professional advice
Certificate issuance and verification platformsGenerating and verifying certificates
IT support and security vendorsMaintenance, backup, and security monitoring

We remain responsible to you for personal data processed by our Data Processors.

11.6 Legal and regulatory disclosures

We may disclose personal data where required to do so by law, by a court order, or by a lawful request from a government authority, regulator, law enforcement agency, or the Data Protection Board of India, or where necessary to establish, exercise, or defend legal claims, prevent fraud, or protect the safety of any person.

11.7 Corporate transactions

If the Academy or Brand Vantage Marketing Private Limited undergoes a merger, acquisition, restructuring, financing, or sale of assets, personal data may be transferred to the counterparty or successor, subject to that party being bound to honour this Policy. You will be notified of any such transfer that materially affects how your data is handled.

11.8 With your direction

We will share your data with any third party you specifically direct us to share it with.

11.9 Aggregated and de-identified data

We may create and publish aggregated or de-identified statistics — for example, "82% of the March cohort completed the capstone project" — which cannot reasonably be used to identify you. This is not personal data and is not subject to this Policy.

12Children and persons with disability

12.1 Verifiable parental consent

Where a Learner is under eighteen (18) years of age, we process personal data only after obtaining verifiable consent from the parent or lawful guardian, in accordance with Section 9 of the DPDP Act and the DPDP Rules, 2025.

12.2 How we verify

We verify parental identity and status by one or more of the following, proportionate to the risk:

  • confirmation from a verified parent or guardian email address and mobile number, authenticated by OTP;
  • a signed consent form (physical or electronic) accompanied by a copy of a government-issued identity document with sensitive fields masked;
  • where the Learner is enrolled through a school or pre-university college, a consent record collected and certified by the Institution in the form prescribed by us; or
  • a virtual token or verified digital identity issued or mapped by an authorised digital locker service provider, where available.

12.3 Prohibited processing in respect of children

We do not, in respect of any Learner under 18:

  • undertake tracking, behavioural monitoring, or profiling;
  • serve targeted or behavioural advertising;
  • process personal data in any manner likely to cause a detrimental effect on the child's well-being; or
  • deploy analytics, advertising, or retargeting cookies.

12.4 No independent accounts

Learners under 18 may not independently create an account, enrol, or make a payment. Enrolment must be completed by the parent or lawful guardian, who is the contracting party under the Terms and Conditions.

12.5 Institution's responsibility

Where enrolment is routed through a school or pre-university Institution, that Institution is responsible for obtaining, recording, and furnishing evidence of parental or guardian consent in the form prescribed by us, and for confirming the accuracy of the ages it reports to us.

12.6 Discovery of unverified child data

If we discover that we hold the personal data of a child without verifiable parental consent, we will suspend processing, seek consent, and if consent is not obtained within a reasonable period, delete the data.

12.7 Persons with disability

Where a Learner is a person with disability who has a lawful guardian appointed under applicable law, we process personal data on the basis of the guardian's consent, and the guardian may exercise all rights under Clause 17 on the Learner's behalf.

12.8 Exemptions

Certain obligations under Section 9 may be relaxed for specified classes of Data Fiduciary or specified purposes as notified by the Central Government. We will apply any such exemption only where it lawfully applies and will update this Policy accordingly.

13Data retention

13.1 Principle

We retain personal data only for as long as is necessary for the purpose for which it was collected, or for as long as required by law, whichever is longer. Once the purpose is served and no legal retention obligation applies, we erase the data or de-identify it irreversibly.

13.2 Indicative retention periods

Data categoryRetention periodReason
Enquiry and prospect data (not converted)24 months from last interaction, or until consent withdrawnFollow-up and re-engagement
Enrolment, academic and assessment records7 years from Programme completionCertificate verification, disputes, quality audit
Certificate issuance recordsIndefinitely, in a minimised form (name, Programme, dates, certificate ID)Lifelong certificate verification for employers
Attendance records7 years from Programme completionCertification eligibility and audit
Financial, invoice, GST and tax records8 years from the end of the relevant financial yearIncome-tax Act 1961; CGST Act 2017; Companies Act 2013
Payment transaction logs8 yearsStatutory and audit
Placement and employer-sharing records3 years from last placement activityOutcome tracking and dispute resolution
Session recordings12 months from the session date, unless a longer access period is stated for the ProgrammeRevision access and quality assurance
Proctoring data6 months from the assessment dateAssessment integrity challenges
Mock interview recordings6 months, or until you ask us to delete themCoaching feedback
CCTV footage30 to 90 daysSecurity and incident investigation
Call recordings12 monthsQuality, training, dispute resolution
Marketing consent and preference recordsDuration of consent plus 3 yearsEvidence of consent and opt-out honouring
Website analytics and server logs12 monthsSecurity and performance
Security and access logs1 year (minimum)DPDP Rules, 2025 security safeguards
Grievance and complaint records3 years from closureRegulatory and audit
Job applicant data (unsuccessful)12 months from decision, unless you consent to a longer talent-pool retentionFuture opportunities
Data subject to legal hold or ongoing proceedingsUntil the matter is finally concludedLegal claims

These periods are indicative. Where a longer or shorter period is required by law or by a specific contractual arrangement with an Institution or Corporate Client, that period applies.

13.3 Erasure on withdrawal

Where you withdraw consent, we will erase the affected personal data, and cause our Data Processors to do the same, unless retention is necessary for compliance with law or for legal proceedings.

13.4 Backups

Data deleted from live systems may persist in encrypted backups for a limited period until those backups are cycled out in the ordinary course. Backup data is not used for any active purpose.

14Security safeguards

14.1 Our commitment

We implement reasonable security safeguards to prevent personal data breach, as required by Section 8(5) of the DPDP Act, the DPDP Rules, 2025, and Rule 8 of the SPDI Rules, 2011.

14.2 Technical measures

  • encryption of personal data in transit using TLS, and at rest for sensitive fields;
  • role-based access control on the principle of least privilege;
  • multi-factor authentication for administrative and privileged accounts;
  • hashing and salting of account passwords — we cannot see your password in plain text;
  • masking of identity document numbers and financial identifiers;
  • firewalls, intrusion detection, endpoint protection, and vulnerability patching;
  • logging and monitoring of access to personal data, with logs retained for at least one year to enable detection and investigation of unauthorised access;
  • encrypted, tested backups with defined recovery objectives;
  • segregation of production, staging, and test environments, with no live personal data used in testing.

14.3 Organisational measures

  • written contracts with all Data Processors imposing DPDP-compliant obligations;
  • confidentiality undertakings from employees, trainers, mentors, and contractors;
  • periodic privacy and security awareness training for staff and trainers;
  • documented access review, joiner-mover-leaver, and offboarding procedures;
  • an incident response and breach management plan;
  • periodic review of this Policy and of our processing activities;
  • privacy-by-design review of new systems, integrations, and vendor onboarding.

14.4 Physical measures

Access-controlled premises, visitor logging, secure storage of physical records, and secure shredding of documents at end of life.

14.5 No absolute guarantee

While we take these measures seriously, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security. You share information with us at your own risk, and you are responsible for keeping your own credentials confidential and your own devices secure.

16Cross-border data transfers

16.1 Where data is stored

We primarily store personal data on servers located in India. Some of our service providers — particularly cloud hosting, video conferencing, email, analytics, and CRM providers — may store or process data on servers located outside India.

16.2 Legal position

Under Section 16 of the DPDP Act, transfer of personal data outside India is permitted except to a country or territory notified as restricted by the Central Government. We monitor such notifications and will not transfer personal data to a restricted territory.

16.3 Additional sectoral restrictions

Where any other law imposes a stricter localisation requirement on a category of data, that stricter requirement prevails and we will comply with it.

16.4 Safeguards

Where personal data is transferred outside India, we require the recipient by contract to (a) process it only on our instructions and only for the specified purpose, (b) apply security safeguards no less protective than those in Clause 14, (c) assist us in responding to your rights requests, and (d) notify us promptly of any breach.

16.5 Global group locations

Brand Vantage operates from Melbourne, Boston, Sharjah, and Bengaluru. Personal data collected through the Academy is not routinely shared with other group locations. Where it is necessary to do so — for example for a global corporate training engagement — Clause 16.4 applies.

17Your rights as a data principal

Subject to the DPDP Act, you have the following rights.

17.1 Right to access information (Section 11)

You may request a summary of the personal data we are processing about you, the processing activities undertaken, and the identities of all other Data Fiduciaries and Data Processors with whom your data has been shared, together with a description of the data shared.

17.2 Right to correction, completion, updating and erasure (Section 12)

You may request that we:

  • correct inaccurate or misleading personal data;
  • complete incomplete personal data;
  • update out-of-date personal data; and
  • erase personal data that is no longer necessary for the purpose for which it was processed.

We may decline erasure where retention is necessary for a specified purpose or for compliance with law — for example, financial records, certificate verification records, or data subject to legal hold. We will tell you if we decline and why.

17.3 Right of grievance redressal (Section 13)

You have the right to a readily available means of grievance redressal in respect of any act or omission of ours regarding your personal data. See Clause 20. You must exhaust this mechanism before approaching the Data Protection Board.

17.4 Right to nominate (Section 14)

You may nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity. To register a nomination, write to support@brandvantageacademy.com with the nominee's name, relationship, and contact details.

17.5 Right to withdraw consent

See Clause 7.4.

17.6 Right to opt out of marketing

You may opt out of marketing communications at any time using the unsubscribe link or by writing to us. You cannot opt out of essential service communications while you are enrolled in a Programme.

17.7 How to exercise your rights

Send a written request to support@brandvantageacademy.com, or by post to the address in Clause 20, stating:

  • your full name and the email address or mobile number registered with us;
  • your enrolment or transaction reference, if any;
  • the right you wish to exercise; and
  • sufficient detail for us to locate the data.

17.8 Verification

To protect your data, we will verify your identity before acting on a request. We may ask for additional information for this purpose only. Where the request is made by a parent, guardian, or nominee, we will also verify their authority.

17.9 Timelines

We will acknowledge your request within forty-eight (48) hours and respond substantively within thirty (30) days of receipt of a verified request. Where a request is complex or numerous, we may extend this period and will tell you the reason for the extension.

17.10 No fee

We do not charge a fee for exercising your rights. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to act, giving reasons.

18Your duties as a data principal

Section 15 of the DPDP Act imposes duties on you. You must:

  • comply with applicable law when exercising your rights;
  • not impersonate another person when providing personal data for a specified purpose;
  • not suppress any material information when providing personal data for any document, identifier, proof of identity, or proof of address issued by the State;
  • not register a false or frivolous grievance or complaint; and
  • furnish only information that is verifiably authentic when exercising your right to correction or erasure.

Breach of these duties may attract a penalty under the DPDP Act, and may also constitute a breach of our Terms and Conditions.

20Grievance redressal and data protection contact

20.1 Grievance Officer

In compliance with the DPDP Act, 2023, the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Consumer Protection (E-Commerce) Rules, 2020:

Namegrievance officer name
DesignationGrievance Officer, Brand Vantage Academy
Emailsupport@brandvantageacademy.com
Telephone+91 8073707619
AddressBrand Vantage Academy, 11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066
Working hoursMonday – Friday | 8:30 AM – 5:30 PM IST (excluding public holidays)

20.2 Data Protection Officer

We are not presently notified as a Significant Data Fiduciary under Section 10 of the DPDP Act. If we are so notified, we will appoint a Data Protection Officer based in India, publish the DPO's contact details on this page, conduct periodic Data Protection Impact Assessments, and undergo independent data audits as required.

20.3 How to complain

Write to the Grievance Officer with your name, contact details, enrolment or transaction reference, a clear description of the complaint, and the outcome sought. We will acknowledge within 48 hours and redress within 30 days (or such shorter period as the law prescribes for the category of complaint).

20.4 Escalation to the Board

If you are not satisfied with our response, or if we fail to respond within the prescribed period, you may lodge a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act. An appeal against an order of the Board lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

20.5 Consumer forums

Nothing in this Policy restricts your rights under the Consumer Protection Act, 2019.

21Personal data breach

21.1 Our response

In the event of a personal data breach, we will activate our incident response plan, contain the breach, assess its scope and impact, and take remedial action.

21.2 Notification to you

We will inform each affected Data Principal without delay, in a concise, clear, and plain manner, through the user account or the registered mode of communication, describing the nature, extent, and timing of the breach, the likely consequences, the measures we have taken or are taking to mitigate risk, safety measures you may take, and our contact details for further information.

21.3 Notification to the Board

We will intimate the Data Protection Board of India without delay on becoming aware of the breach, and will furnish detailed particulars — including the events and circumstances leading to the breach, the mitigation measures taken, the findings on the person who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals — within seventy-two (72) hours, or such longer period as the Board may allow on request.

21.4 CERT-In

Where applicable, we will also report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within the timelines prescribed under its directions.

22Automated processing and artificial intelligence

22.1 Where we use automation

We may use automated tools to score objective assessments, flag potential plagiarism or assessment irregularities, generate learning analytics and progress dashboards, match learner profiles to internship or placement opportunities, and detect credential sharing or fraudulent activity.

22.2 Human oversight

We do not make decisions that produce significant adverse effects on you — such as withholding certification, revoking a certificate, terminating enrolment, or withdrawing placement support — on the basis of automated processing alone. Such decisions are reviewed by a qualified member of our team before they take effect, and you may contest the outcome through Clause 20.

22.3 AI tools in delivery

Programmes may involve the use of generative AI tools as part of the curriculum. Where you input data into a third-party AI tool, that input is governed by the tool provider's own terms and privacy policy. Do not input personal data of others, confidential information, or client data into any AI tool during a Programme.

22.4 We do not train models on your data

We do not use your personal data, submissions, or session recordings to train, fine-tune, or evaluate any commercial machine learning or artificial intelligence model, and we contractually prohibit our Data Processors from doing so.

23Job applicants and trainers

Where you apply for employment, a trainer role, or a mentor engagement with the Academy, we process your name, contact details, resume, qualifications, work history, references, interview notes, and assessment outcomes for the purpose of evaluating your application. We retain unsuccessful applicant data for 12 months unless you consent to longer retention in our talent pool. Background verification, where conducted, will be carried out with your prior consent and by a verification agency bound by confidentiality.

24Changes to this policy

We may update this Policy to reflect changes in law, technology, or our practices. The revised Policy will be posted here with an updated "Last updated" date and takes effect from the date of posting.

Where a change materially affects how we process your personal data or the rights available to you, we will give you not less than fifteen (15) days' prior notice by email, and where the change requires it, we will seek fresh consent.

We encourage you to review this page periodically. Continued use of the Website or participation in a Programme after the effective date constitutes acceptance of the revised Policy, save where fresh consent is required.

25Governing law

This Policy is governed by the laws of India. Disputes arising out of or in connection with it are subject to the dispute resolution and jurisdiction provisions in Clause 27 of our [Terms and Conditions](/terms) — arbitration seated at Bengaluru under the Arbitration and Conciliation Act, 1996, with the courts at Bengaluru, Karnataka having exclusive jurisdiction — without prejudice to your statutory right to approach the Data Protection Board of India or a consumer commission.

26How to contact us

Privacy, data protection and grievancessupport@brandvantageacademy.com
General enquiriesinfo@brandvantageacademy.com
Partnershipspartnerships@brandvantageacademy.com
Telephone+91 8073707619
Address11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066
Websitewww.brandvantageacademy.com

This policy is issued by Brand Vantage Marketing Private Limited, GSTIN 29AALCB8059L1ZW, registered at 11th Floor, Gamma Block, Sigma Soft Tech Park, Ramagondanahalli, Whitefield, Bengaluru, Karnataka 560066. Brand Vantage Academy is a brand of that company and is not a separate legal entity.

Questions about this policy