Last Updated: August 27, 2026
1. Introduction and Scope
Welcome to our website. Data Fiduciary (as defined under the Digital Personal Data Protection Act, 2023 (“DPDP Act”)) respects your privacy and is committed to protecting your personal data in accordance with the DPDP Act and other applicable laws.
This Privacy Policy constitutes the notice required under Section 6(1) of the DPDP Act and explains how we collect, use, store, disclose, and safeguard your personal data when you interact with our website and services.
By using our website and voluntarily submitting your personal data, you acknowledge that you have read, understood, and consent to the practices described in this policy.
2. Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings assigned to them under the DPDP Act, 2023:
- “Data Fiduciary” refers to Ekadant Assessment Labs Pvt Ltd, the entity that determines the purpose and means of processing your personal data.
- “Data Principal” refers to you, the individual to whom the personal data relates.
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data, including your name, surname, email address, and message content.
- “Processing” means any operation performed on personal data, including collection, storage, use, disclosure, sharing, or erasure.
- “Consent” means free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s wishes.
3. Data Fiduciary Details
Table
| Field | Details |
|---|---|
| Data Fiduciary Name | Ekadant Assessment Labs Pvt Ltd |
| Registered Address | Ground Floor, Wework Raheja Woods, Yerwada, Pune City, Pune- 411006, Maharashtra. |
| Contact Email | ekadantlabs@outlook.com |
| Grievance Officer | CEO |
| Data Protection Officer (if applicable) | N/A |
Note: Under the DPDP Act, Significant Data Fiduciaries are required to appoint a Data Protection Officer. If we fall under this category, the DPO’s contact details will be provided above.
4. Personal Data We Collect
In accordance with the principle of data minimization under the DPDP Act, we collect only such personal data as is necessary for the specified purposes.
4.1 Categories of Personal Data
Table
| Data Element | Description | Purpose of Collection |
|---|---|---|
| First Name | Your given name | To identify you and personalize our communication |
| Surname / Last Name | Your family name | To identify you and personalize our communication |
| Email Address | Your electronic mail address | To respond to your inquiries and communicate with you |
| Message Content | The text of your inquiry/feedback | To understand your request and provide an appropriate response |
4.2 Manner of Collection
- Direct Collection: We collect personal data directly from you when you voluntarily fill out and submit forms on our website (e.g., contact forms, inquiry forms).
- Voluntary Basis: All data collection is entirely voluntary. You may browse our website without providing any personal data.
4.3 Data We Do NOT Collect
We do not collect:
- Sensitive personal data (as defined under the DPDP Act) including passwords, financial data, health data, biometric data, genetic data, transgender status, intersex status, caste or tribe status, religious or political beliefs, or official identifiers (except where expressly required by law).
- Tracking or behavioral data across other websites.
- Location data or GPS information.
5. Legal Basis and Consent
5.1 Consent as Legal Basis
Under Section 6 of the DPDP Act, we process your personal data based on your free, specific, informed, unconditional, and unambiguous consent, evidenced by your voluntary submission of information through our website forms.
5.2 Consent Requirements
Before you submit your personal data, we provide you with:
- Clear notice of the personal data we propose to collect.
- The purpose for which such personal data will be processed.
- The manner in which you may exercise your rights as a Data Principal.
- The contact details of the Grievance Officer.
5.3 Consent Management
- Granularity: You consent to the processing of each category of personal data for the specific purposes stated.
- Withdrawal: You may withdraw your consent at any time by contacting our Grievance Officer. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
- No Conditional Service: We do not make the provision of our services conditional upon consent to the processing of personal data not necessary for those services.
5.4 Consent for Children (Under 18 Years)
In compliance with Section 9 of the DPDP Act:
- Our website is not directed at children under the age of 18.
- We do not knowingly collect personal data from individuals under 18 years of age.
- If we discover that we have inadvertently collected personal data from a child under 18, we will delete such data immediately.
- If you are a parent or guardian and believe your child has provided us with personal data, please contact our Grievance Officer immediately.
6. Purpose of Processing
We process your personal data only for the purposes for which it was collected, as notified to you at the time of collection (Section 6(1)(c) of the DPDP Act).
6.1 Specified Purposes
- Communication: To read, understand, and respond to your messages, inquiries, and requests.
- Customer Support: To provide assistance, address concerns, and resolve issues raised by you.
- Record Keeping: To maintain accurate records of our communications for internal business purposes.
- Service Improvement: To analyze feedback patterns and improve our products, services, and user experience.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
- Security: To protect our website, services, and users from fraud, abuse, unauthorized access, or security threats.
6.2 Purpose Limitation
We do not process your personal data for any purpose that is not compatible with the above-specified purposes. If we need to process your data for a new purpose, we will seek fresh consent or provide prior notice as required by law.
7. Data Sharing and Disclosure
7.1 Internal-Only Access
Your personal data — including your name, surname, email address, and message content — is strictly internal and is not accessible by common users, other Data Principals, or the general public. Access is restricted to authorized personnel of the Data Fiduciary who require such access to perform their designated functions.
7.2 No Sale of Personal Data
We do not sell, rent, trade, or otherwise transfer your personal data to any third party for monetary or other valuable consideration.
7.3 Permitted Disclosures
We may disclose your personal data only in the following limited circumstances, as permitted under the DPDP Act:
Table
| Scenario | Basis | Safeguards |
|---|---|---|
| Service Providers | Necessary for performing functions on our behalf | Bound by confidentiality and data protection obligations; processing limited to specified purposes |
| Legal Obligation | Compliance with any law, court order, or direction from government agencies | Limited to the extent required by law |
| Business Transfers | Merger, amalgamation, or reorganization | Data Principals notified; new entity bound by this policy |
| Protection of Rights | To enforce terms, protect rights, property, or safety | Proportionate and necessary |
7.4 Cross-Border Data Transfers
Currently, your personal data is stored and processed within India. If we need to transfer your personal data outside India in the future, such transfer will only be made to countries or territories notified by the Central Government under Section 17 of the DPDP Act, and you will be notified prior to such transfer.
8. Data Security and Integrity
8.1 Reasonable Security Safeguards
In compliance with Section 8(5) of the DPDP Act, we implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption: All data transmitted between your browser and our servers is protected using industry-standard SSL/TLS encryption.
- Access Controls: Personal data is accessible only to authorized personnel on a need-to-know basis, protected by role-based access controls and authentication mechanisms.
- Secure Storage: Data is stored on secure servers with firewalls, intrusion detection systems, and regular security patching.
- Data Integrity: We maintain procedures to ensure that personal data is accurate, complete, and updated where necessary.
- Incident Response: We have procedures in place to detect, respond to, and notify affected Data Principals and the Data Protection Board of India in the event of a personal data breach, as required under Section 8(6) and Section 10 of the DPDP Act.
8.2 Security Limitations
While we employ reasonable security safeguards appropriate to the nature of the personal data processed, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.
9. Data Retention and Storage Limitation
9.1 Retention Period
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:
- Active Communication Period: Retained while we are actively corresponding with you or addressing your inquiry.
- Post-Resolution Period: Retained for a reasonable period thereafter to maintain business records and comply with legal obligations.
- Legal Requirements: Certain data may be retained for longer periods if required by law, regulation, or for ongoing legal proceedings.
9.2 Storage Limitation
In accordance with Section 8(1)(d) of the DPDP Act, we do not retain personal data beyond the period necessary to satisfy the purpose for which it was collected. Once the purpose is fulfilled and retention is no longer necessary, your personal data will be securely deleted or anonymized.
9.3 Right to Erasure
You may request deletion of your personal data at any time (see Section 11). Upon verification of your identity, we will erase your data unless retention is required by law.
10. Rights of Data Principals
Under Chapter III of the DPDP Act, you have the following rights as a Data Principal:
10.1 Right to Access (Section 12)
You have the right to obtain from us confirmation of whether we are processing your personal data, and if so, access to such personal data and a summary of the processing activities.
10.2 Right to Correction and Erasure (Section 13)
You have the right to request:
- Correction of inaccurate or misleading personal data.
- Completion of incomplete personal data.
- Updating of personal data that is out of date.
- Erasure of personal data that is no longer necessary for the purpose for which it was collected.
10.3 Right to Grievance Redressal (Section 14)
You have the right to have readily available means of registering a grievance with us regarding our processing of your personal data. Our Grievance Officer details are provided in Section 3 above.
10.4 Right to Nominate (Section 14(2))
You have the right to nominate any other individual who shall, in the event of your death or incapacity, exercise your rights as a Data Principal. To nominate an individual, please contact our Grievance Officer in writing.
10.5 How to Exercise Your Rights
To exercise any of your rights as a Data Principal:
- Submit a Request: Send a written request to our Grievance Officer at ekadantlabs@outlook.com
- Verification: We will verify your identity using the email address associated with your data and may request additional information to confirm your identity.
- Response Timeline: We will respond to your request within 30 days of receipt, as prescribed under the DPDP Act.
- No Fee: We do not charge any fee for exercising your rights unless the request is manifestly unfounded or excessive.
10.6 Right to Approach the Data Protection Board
If you are not satisfied with our response to your grievance, you have the right to approach the Data Protection Board of India as established under the DPDP Act.
11. Cookies and Automated Data Collection
11.1 Essential Cookies
Our website uses only essential cookies necessary for the proper functioning of the site (e.g., session management, security, form submission). These cookies do not collect personal data.
11.2 No Behavioral Tracking
We do not use cookies or tracking technologies to monitor your browsing behavior across other websites or to build behavioral profiles.
11.3 Analytics
We may use anonymized, aggregated analytics to understand website traffic patterns. Such analytics do not identify individual Data Principals.
12. Third-Party Links and Services
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, data protection policies, or content of such external sites. We encourage you to review the privacy policies of any third-party sites you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for operational reasons. When we make material changes:
- We will update the “Last Updated” date at the top of this policy.
- We will post a prominent notice on our website.
- For significant changes, we will notify you directly via email if we have your contact details.
- Where required by the DPDP Act, we will seek fresh consent or provide revised notice before implementing material changes to processing activities.
Your continued use of our website after such changes constitutes your acknowledgment of the modified policy.
14. Grievance Redressal Mechanism
In compliance with Section 14 of the DPDP Act, we have established the following grievance redressal mechanism:
14.1 Grievance Officer
Table
| Detail | Information |
|---|---|
| Name | CEO |
| Designation | CEO |
| [c.vengarai@ekadantlabs.com] | |
| Address | Ground Floor, Wework Raheja Woods, Yerwada, Pune City, Pune- 411006, Maharashtra. |
| Response Time | Within 30 days of receipt of grievance |
14.2 Filing a Grievance
If you have any concerns, complaints, or grievances regarding:
- Our processing of your personal data;
- Violation of any provision of the DPDP Act or this Privacy Policy;
- Exercise of your rights as a Data Principal;
- Any personal data breach;
Please contact our Grievance Officer using the details above. Your grievance should include:
- Your full name and contact details;
- Description of the grievance;
- Relevant dates and supporting information;
- Relief sought.
14.3 Escalation
If your grievance is not resolved satisfactorily, you may escalate the matter to the Data Protection Board of India in accordance with the provisions of the DPDP Act.
15. Acceptance and Consent
By using our website and voluntarily submitting your personal data through our forms, you:
- Confirm that you have read and understood this Privacy Policy.
- Acknowledge that you have been provided with the notice required under Section 6(1) of the DPDP Act.
- Provide your free, specific, informed, unconditional, and unambiguous consent to the collection and processing of your personal data as described herein.
- Confirm that you are 18 years of age or older, or that your parent/legal guardian has provided verifiable consent on your behalf.
- Agree that the provision of your personal data is voluntary and that you may withdraw consent at any time.
If you do not agree with this Privacy Policy or do not consent to the processing described herein, please do not use our website or submit any personal information.
16. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy, your rights as a Data Principal, or our data protection practices, please contact us:
Ekadant Assessment Labs Pvt Ltd
Email: ekadantlabs@outlook.com
Address: Ground Floor, Wework Raheja Woods, Yerwada, Pune City, Pune- 411006, Maharashtra.
This Privacy Policy is effective as of August 27, 2026, and is drafted in compliance with the Digital Personal Data Protection Act, 2023 (India), and other applicable data protection laws.
