Policy
Privacy
In plain words
- AspireACE must state what it collects and the purpose for every item before asking for it.
- Private learning records, account data, family relationships, and payment records do not belong on public pages.
- You may request access information, correction, completion, erasure where applicable, and grievance redressal under the DPDP framework.
- The approved retention schedule, processor list, cross-border posture, named grievance officer, and statutory address are not yet published.
Publication status
DPDP rights are acknowledged; the complete policy remains withheld. The named grievance officer, postal address, retention schedule, processors, and legal approval are still required.
Data and purpose
The final policy must map each collected item to a stated learning, account, safety, payment, support, or legal purpose. Data collected for one purpose must not silently become advertising or unrelated profiling data.
Retention and sharing
Retention periods, deletion timing, service providers, disclosures, and any cross-border processing must be published from approved operational records. They are not inferred from source code or vendor defaults.
Your DPDP rights
Subject to applicable law, a data principal may seek information about processing, correction and completion, erasure, grievance redressal, and nomination. Account export and deletion requests must use the authenticated support path so another person cannot obtain or erase a learner's data.
Children
Because learners may be minors, consent, guardian authority, tracking, profiling, advertising, contact, and safety controls require a specific child-safety posture. Read the separate child-safety publication record.