1. Information Collection and Processing
Mumbai Academy ("we," "our," "us," or "the Company"), a duly registered educational institution operating under the laws of India, hereby establishes this comprehensive Privacy Policy to govern the collection, processing, storage, and utilization of personal information obtained from users ("you," "your," or "User") of our digital platform and services.
In accordance with applicable data protection regulations, including but not limited to the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we collect, process, and maintain the following categories of personal information:
1.1 Personally Identifiable Information (PII)
We collect comprehensive personal identification data including, but not limited to:
- Full legal name as it appears on government-issued identification documents
- Primary and secondary email addresses for communication purposes
- Contact telephone numbers (mobile and landline) for urgent communications
- Residential and correspondence addresses for official documentation
- Date of birth for age verification and eligibility assessment
- Government-issued identification numbers for verification purposes
1.2 Professional and Educational Information
Our platform collects extensive professional and educational data including:
- Comprehensive curriculum vitae (CV) or resume documents
- Educational qualifications, certifications, and academic transcripts
- Professional work experience and employment history
- Skills assessments and competency evaluations
- Professional references and recommendation letters
- Portfolio materials and project documentation
1.3 Financial and Transactional Information
For payment processing and financial compliance, we collect:
- Payment method details and transaction identifiers
- Billing addresses and financial institution information
- Transaction history and payment confirmation records
- Refund processing information and financial reconciliation data
1.4 Technical and Usage Information
We automatically collect technical data to enhance user experience:
- Internet Protocol (IP) addresses and geolocation data
- Browser type, version, and operating system information
- Device identifiers and hardware specifications
- Website usage patterns and interaction analytics
- Session data and user behavior metrics
2. Legal Basis and Purpose of Data Processing
We process your personal information under the following legal bases and for the specified purposes:
2.1 Contractual Performance
Processing is necessary for the performance of our contractual obligations to you, including:
- Application processing and eligibility assessment
- Service delivery and educational program administration
- Payment processing and financial transaction management
- Communication regarding service status and updates
- Quality assurance and service improvement initiatives
2.2 Legitimate Business Interests
We process data to pursue our legitimate business interests, including:
- Service optimization and user experience enhancement
- Fraud prevention and security measures
- Business analytics and market research
- Product development and innovation
- Regulatory compliance and legal obligations
2.3 Legal Compliance
Processing is necessary to comply with applicable laws and regulations:
- Tax reporting and financial record-keeping requirements
- Educational institution regulatory compliance
- Data protection and privacy law obligations
- Consumer protection and fair business practice requirements
3. Data Sharing and Third-Party Disclosure
We maintain strict protocols regarding the sharing and disclosure of your personal information:
3.1 Internal Processing
Your information is processed internally by authorized personnel for legitimate business purposes only.
3.2 Service Providers and Business Partners
We may share information with carefully selected third-party service providers who assist in our operations:
- Payment processing partners for secure transaction handling
- Cloud storage providers for data backup and security
- Communication service providers for email and SMS delivery
- Analytics providers for service improvement and optimization
- Educational technology partners for learning platform support
3.3 Legal and Regulatory Disclosures
We may disclose your information when required by law or in response to:
- Valid legal process, including court orders and subpoenas
- Government investigations and regulatory inquiries
- Emergency situations involving public safety
- Intellectual property protection and enforcement actions
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction, subject to appropriate privacy protections.
4. Data Security and Protection Measures
We implement comprehensive security measures to protect your personal information:
4.1 Technical Security Measures
- Advanced encryption protocols (AES-256) for data transmission and storage
- Secure Socket Layer (SSL) and Transport Layer Security (TLS) implementation
- Multi-factor authentication and access control systems
- Regular security audits and vulnerability assessments
- Intrusion detection and prevention systems
- Data backup and disaster recovery procedures
4.2 Organizational Security Measures
- Employee training on data protection and privacy practices
- Strict access controls and role-based permissions
- Regular security policy reviews and updates
- Incident response and breach notification procedures
- Vendor security assessments and contractual obligations
5. Data Retention and Disposal
We maintain your personal information only for as long as necessary to fulfill the purposes outlined in this policy:
5.1 Retention Periods
- Active user accounts: Duration of service plus 7 years for legal compliance
- Financial records: 7 years as required by tax and financial regulations
- Educational records: 10 years for academic and professional verification
- Marketing communications: Until consent withdrawal or account deletion
5.2 Secure Disposal
When data is no longer required, we employ secure disposal methods including permanent deletion, degaussing, and physical destruction of storage media.
6. Your Rights and Data Subject Protections
You possess comprehensive rights regarding your personal information:
6.1 Access and Portability Rights
- Right to access and review your personal information
- Right to receive a copy of your data in a portable format
- Right to verify the accuracy and completeness of your information
- Right to request information about data processing activities
6.2 Correction and Update Rights
- Right to correct inaccurate or incomplete information
- Right to update personal details and preferences
- Right to supplement information with additional details
- Right to request verification of corrections made
6.3 Deletion and Restriction Rights
- Right to request deletion of personal information
- Right to restrict processing in certain circumstances
- Right to object to specific processing activities
- Right to withdraw consent for consent-based processing
7. Cookies and Tracking Technologies
We utilize various tracking technologies to enhance your experience:
7.1 Types of Cookies Used
- Essential Cookies: Required for basic website functionality
- Performance Cookies: Analyze website usage and performance
- Functional Cookies: Remember preferences and settings
- Marketing Cookies: Deliver relevant advertisements
7.2 Third-Party Analytics
We use third-party analytics services to understand user behavior and improve our services. These services may collect information about your online activities across different websites.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws.
9. Children's Privacy Protection
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected such information, we will take immediate steps to delete it.
10. Policy Updates and Modifications
We reserve the right to modify this Privacy Policy at any time. Material changes will be communicated through:
- Email notifications to registered users
- Prominent website announcements
- Updated policy posting with effective dates
- Consent renewal for significant changes
11. Contact Information and Complaints
For questions, concerns, or complaints regarding this Privacy Policy or our data practices, please contact us:
Email: support@mumbai.academy
Response Time: We will acknowledge your inquiry within 48 hours and provide a substantive response within 30 days.
Last Updated: August 5, 2025
Version: 2.0