EdOpen Solutions — Master Privacy Policy, Regulatory Appendix & Operational Clauses
Section 1: Introduction and Organizational Mandate
1.1 Organizational Background & Scope
EdOpen Solutions (“EdOpen”, “we”, “our”, “us”), headquartered in Bhilai, Chhattisgarh, India, operates as an advanced educational, institutional advisory, and technology-enabled learning ecosystem. We facilitate digital transformation, academic consulting, research partnerships, and capacity-building programs for students, educators, and institutional partners across India and international jurisdictions.
1.2 Commitment to Data Privacy
At EdOpen, we recognize that privacy is a fundamental human right and a cornerstone of digital trust. In an era where data is increasingly vulnerable to exploitation, we have built our organizational architecture around the principles of Privacy by Design and Privacy by Default.
1.3 Acceptance of Policy Terms
By accessing, browsing, registering on, or otherwise utilizing any service provided by EdOpen Solutions, you acknowledge that you have read, understood, and agreed to the practices outlined in this Master Privacy Policy.
Appendix & Clauses for Section 1
- Clause 1.1 (Scope of Governance): This policy governs all interactions across www.edopen.in, mobile applications, and physical/virtual consultation channels.
- Clause 1.2 (Binding Nature): Use of EdOpen platforms constitutes unconditional acceptance of these operational clauses and appendices.
Section 2: Definitions and Interpretations
2.1 Core Terminologies
- “Personal Data” refers to any information relating to an identified or identifiable natural person.
- “Institutional Data” encompasses proprietary academic, administrative, and collaborative documents shared by partner institutions.
- “Processing” means any operation performed on personal data, such as collection, recording, structuring, storage, or destruction.
- “User” or “Data Subject” denotes any individual interacting with EdOpen.
Appendix & Clauses for Section 2
- Clause 2.1 (Statutory Alignment): All definitions shall be interpreted in line with applicable information technology and data protection statutes in India.
- Clause 2.2 (Data Controller Status): EdOpen acts as the Data Controller for all direct platform interactions and primary user profiles.
Section 3: Principles of Data Protection & Governance
3.1 Core Principles
EdOpen strictly governs all data processing activities based on international standards:
- Lawfulness, Fairness, and Transparency
- Purpose Limitation & Data Minimization
- Accuracy & Storage Limitation
- Integrity and Confidentiality
Appendix & Clauses for Section 3
- Clause 3.1 (Compliance Mandate): Any internal data handling that violates these foundational principles is subject to immediate disciplinary and corrective administrative action.
Section 4: Data Collection Framework & Categories of Information
4.1 Information Provided Directly by Users
When you interact with EdOpen, you may provide:
- Identity & Demographic Data: Name, date of birth, gender, nationality, and IDs.
- Contact Information: Email, telephone numbers, and addresses.
- Academic & Professional Records: Transcripts, resumes, and career objectives.
- Financial & Transactional Data: Billing records processed via PCI-DSS compliant gateways.
Appendix & Clauses for Section 4
- Clause 4.1 (Voluntary Submission): Users warrant that all data submitted is accurate, authentic, and belongs either to them or to individuals for whom they hold legal representation rights.
Section 5: Telemetry, Technical Data, and Device Information
5.1 Automated Metadata Capture
When visitors navigate www.edopen.in, our servers capture:
- Device & Hardware Information: OS version, browser type, and device identifiers.
- Network & Connection Data: IP address, ISP, and geographic routing data.
- Usage Telemetry: Pages visited, duration, clickstream data, and crash reports.
Appendix & Clauses for Section 5
- Clause 5.1 (Diagnostic Use): Technical telemetry is strictly siloed and used exclusively for cybersecurity diagnostics, traffic optimization, and UI enhancement.
Section 6: Third-Party Data Sources and Integrations
6.1 Collaborative Workflows
We may receive information from verified third parties:
- Institutional Partners: Partner schools and corporate sponsors referring clients.
- Single Sign-On (SSO): Authenticated profile data from Google or Microsoft when elected by the user.
Appendix & Clauses for Section 6
- Clause 6.1 (Verification Standard): EdOpen requires all third-party referrers to certify that appropriate data collection consent has been legally secured prior to data transfer.
Section 7: Legal Basis and Purposes of Data Processing
7.1 Processing Grounds
- Contractual Necessity: Fulfilling advisory bookings and mentorship agreements.
- Legitimate Business Interests: Securing platforms and optimizing user experience.
- Explicit Consent: Marketing communications and session recordings.
- Statutory Compliance: Retaining tax and financial records.
Appendix & Clauses for Section 7
- Clause 7.1 (Revocability): Users may withdraw consent for optional processing activities at any time without impacting core contractual fulfillment.
Section 8: Data Sharing, Disclosure, and Zero-Monetization Guarantee
8.1 Zero-Data Monetization Policy
- Absolute Prohibition: EdOpen maintains a strict zero-sale policy. Personal data is never sold, traded, or rented to data brokers or advertisers.
- Authorized Processors: Cloud infrastructure providers, CRM tools, WhatsApp Business API, and PCI-DSS payment gateways bound by strict NDAs.
- Legal Mandates: Disclosures executed strictly in response to valid judicial orders.
Appendix & Clauses for Section 8
- Clause 8.1 (Sub-Processor Audits): All third-party sub-processors undergo periodic security evaluations to ensure compliance with EdOpen privacy standards.
Section 9: Cookies, Analytics, and Tracking Technologies
9.1 Cookie Management
- Essential Cookies: Required for core site navigation and security.
- Analytics & Marketing Cookies: Google Analytics and preference trackers deployed strictly with user consent via banner controls.
Appendix & Clauses for Section 9
- Clause 9.1 (Opt-Out Preference): Users retain the absolute right to reject non-essential tracking cookies via browser configurations or the site cookie settings manager.
Section 10: Data Security Architecture and Technical Safeguards
10.1 Cybersecurity Framework
- Encryption: 256-bit SSL/TLS in transit and AES-256 encryption at rest.
- Access Control: Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA).
- Monitoring: Continuous intrusion detection systems (IDS) and web application firewalls (WAF).
Appendix & Clauses for Section 10
- Clause 10.1 (Breach Notification Protocol): In the event of a confirmed security incident affecting personal data, affected users and authorities will be notified within statutory timeframes.
Section 11: Data Retention and Archival Lifecycle
11.1 Retention Schedule
- Active Profiles: Maintained during service delivery and up to 3 years post-inactivity.
- Financial Records: Preserved for 5 to 8 years as mandated by Indian corporate and tax laws.
Appendix & Clauses for Section 11
- Clause 11.1 (Secure Purging): Expired data records are permanently deleted, overwritten, or cryptographically anonymized to prevent recovery.
Section 12: Data Subject Rights and Enforcement Procedures
12.1 User Rights Overview
Registered users, students, institutional partners, and website visitors retain comprehensive rights:
- Rights to Access, Rectification, Erasure (Right to be Forgotten), Restriction, and Portability.
Appendix & Clauses for Section 12
- Clause 12.1 (Request Execution Window): Formal requests must be sent to business@edopen.in and will be processed within 30 calendar days of identity verification.
Section 13: Children’s Privacy and Minor Protection
13.1 Age Limitations
Services are designed for individuals aged 18 and above, or minors under parental/institutional supervision. We do not knowingly collect data from children under 13 without verification.
Appendix & Clauses for Section 13
- Clause 13.1 (Immediate Removal): Any accidental submissions by children under 13 will be purged immediately upon discovery or notification.
Section 14: International Users and Cross-Border Transfers
14.1 Global Accessibility
Data may be processed across secure cloud servers located in India and global data centers utilizing strict encryption protocols.
Appendix & Clauses for Section 14
- Clause 14.1 (Transfer Safeguards): Cross-border transfers comply with international data protection standards and robust contractual safeguards.
Section 15: Policy Modifications and Version Control
15.1 Updates & Amendments
EdOpen reserves the right to modify this policy. Material changes will be announced via website banners or direct email notices 15 days prior to implementation.
Appendix & Clauses for Section 15
- Clause 15.1 (Archival History): Previous versions of this privacy policy are archived and available to registered users upon formal request.
Section 16: Third-Party Links and External Websites
16.1 External Repositories
Platforms may link to external websites or partner portals. EdOpen assumes no liability for third-party privacy practices.
Appendix & Clauses for Section 16
- Clause 16.1 (Independent Review): Users are strongly advised to review the respective privacy policies of any external third-party sites they visit.
Section 17: User Responsibilities and Account Security
17.1 Credential Management
Users are responsible for maintaining account credential confidentiality and must report suspected security breaches immediately.
Appendix & Clauses for Section 17
- Clause 17.1 (Liability Waiver): EdOpen disclaims liability for unauthorized access resulting from user negligence in safeguarding login credentials.
Section 18: Artificial Intelligence and Automated Processing Disclosures
18.1 Automated Tools
AI-driven recommendation systems may assist in suggesting academic pathways, backed always by human administrative oversight.
Appendix & Clauses for Section 18
- Clause 18.1 (Human Review Right): Users may request a manual human review of any critical automated decision affecting their institutional onboarding or program placement.
Section 19: Dispute Resolution and Governing Law
19.1 Legal Framework
Governed by the laws of India. Exclusive jurisdiction for all legal disputes is vested in the competent courts of Bhilai, Chhattisgarh.
Appendix & Clauses for Section 19
- Clause 19.1 (Mandatory Mediation): Prior to initiating formal court litigation, parties agree to attempt good-faith mediation through EdOpen’s designated grievance cell.
Section 20: Administrative Contact, Grievance Redressal, and Official Support
20.1 Official Support Channels
- Publishing Entity: EdOpen Solutions
- Official Web Portal: www.edopen.in
- Compliance & Legal Email: business@edopen.in
- Dedicated Phone Support / WhatsApp: +91 92433 47427
- Headquarters: Bhilai, Chhattisgarh, India
Appendix & Clauses for Section 20
- Clause 20.1 (Grievance Officer Mandate): The compliance desk serves as the designated Grievance Cell, acknowledging complaints within 48 hours and resolving valid tickets within 30 calendar days.
End of Master Privacy Policy, Regulatory Appendix & Operational Clauses — EdOpen Solutions (Document ID: EDP-PP-2026-V2)
