PRIVACY POLICY
1. Introduction
PrashantAdvait Foundation (“Foundation”, “PAF”, “we”, “us” or “our”) recognises the importance of protecting the privacy and dignity of individuals and is committed to handling personal data responsibly, lawfully and transparently.
This Privacy Policy (“Policy”) explains how the Foundation collects, uses, stores, shares, protects and erases personal data in connection with:
(b) the mobile application “Acharya Prashant” (“Application”);
(c) Wisdom Sessions, HIDP, events, programmes, reflective exercises, communities and related activities;
(d) donations, subscriptions, purchases and merchandise; and
(e) other services offered or administered by the Foundation (collectively, the “Services”).
This Policy should be read with the Foundation’s Terms and Conditions and any collection-specific, event-specific, feature-specific or consent notice supplied to the individual.
(g) “HIDP” means Holistic Individual Development Programme and the educational, reflective or self-inquiry exercises forming part of that programme.
(h) “Foundation Activities” means Wisdom Sessions, HIDP, events, retreats, workshops, reflective exercises, community activities and other programmes organised, facilitated or supported by PAF, whether physically, digitally or in hybrid form.
2. Applicable law and role of the Foundation
This Policy has been prepared having regard to applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), the Information Technology Act, 2000 and applicable rules made under it.
PAF acts as the Data Fiduciary for personal data in relation to which it determines the purpose and means of processing. Certain third-party platforms, payment providers or other independently operated services may act as separate Data Fiduciaries for processing governed by their own privacy policies. The individual to whom the personal data relates is the “Data Principal.”
Obligations under the DPDP Act and DPDP Rules shall apply from their respective commencement dates. The Foundation may implement relevant privacy safeguards before their statutory commencement.
3. No consent merely by visiting or using the Services
Reading this Policy, visiting the Website, downloading an Application, accepting the Terms, remaining silent or continuing to use a Service does not, by itself, constitute consent to an optional personal-data processing purpose.
Where consent is required, the Foundation shall seek it through a separate notice and clear affirmative action. Where processing is undertaken without consent, the Foundation shall identify and document the applicable legal basis, including any “certain legitimate use” expressly available under the DPDP Act.
4. Personal data we may collect
Depending upon the Service used, the Foundation may collect the following categories of personal data.
4.1 Account and identity information
• name;
• username, account identifier or display name;
• email address;
• telephone number;
• login credentials in protected form;
• age or age-range information;
• language and communication preferences;
• profile photograph; and
• country, state, city or general location.
4.2 Child and parent information
Where a Service is expressly available to a Child, the Foundation may collect:
• the Child’s name, age or age range and account information;
• parent or lawful-guardian contact information;
• information necessary to verify that the person giving consent is an identifiable adult;
• a token or confirmation received from an entity authorised to provide age or identity verification; and
• records of parental consent and withdrawal.
The Foundation shall seek to minimise the identity information collected for verification.
4.3 Transaction and contribution information
• donation or payment amount;
• transaction reference, status, date and time;
• subscription, purchase, programme or event details;
• invoicing, tax and receipt information;
• refund or dispute information; and
• limited payment-related information supplied by a payment processor.
PAF does not ordinarily store complete card numbers, CVV values, UPI PINs or banking passwords. Such information is processed by the applicable payment service provider.
4.4 Community Content
• posts, reflections, questions, comments and testimonials;
• photographs, audio recordings and videos;
• reactions and community interactions;
• display name, image, likeness and voice associated with the content; and
• moderation, reporting and content-preference information.
4.5 Wisdom Session information
• registration and attendance information;
• audio and video recordings;
• display name, face, voice, questions and interactions;
• chat messages or reactions forming part of a Session;
• face-visibility or de-identification preferences; and
• records concerning privacy requests relating to recordings.
4.6 Event and HIDP information
• event registration and attendance;
• eligibility and logistical information;
• dietary, accessibility or accommodation requests;
• emergency contact information, where reasonably necessary;
• limited health or safety information voluntarily supplied for an accommodation or identified safety concern; and
• information concerning an accompanying Child where Children are permitted.
PAF does not require disclosure of an entire medical history. Participants should provide only the information reasonably necessary for the requested accommodation or safety purpose.
Where health, medical or other information constitutes sensitive personal data or information under applicable law, PAF shall collect it only for a lawful and necessary purpose, provide the applicable notice, obtain the form of consent required by law, restrict access to authorised persons and apply the required security and retention safeguards. Refusal to provide optional health information shall not affect unrelated Services, although PAF may be unable to provide the requested accommodation or permit participation in an exercise where necessary safety information is unavailable.
4.7 Communications and support information
• emails, messages and support requests;
• grievance and rights-request records;
• call or correspondence details;
• communication preferences and opt-out records; and
• feedback and survey responses.
4.8 Technical and usage information
• IP address;
• device type and device identifiers;
• browser, operating system and language;
• date and time of access;
• pages, screens and features accessed;
• application performance and crash information;
• security, authentication and access logs;
• cookie or similar technology identifiers; and
• approximate location inferred from technical information, where applicable.
4.9 Information from other sources
The Foundation may receive information from payment processors, communication service providers, event-registration providers, authorised age-verification services, social-media platforms or other service providers where permitted by law and necessary for the relevant Service.
5. How personal data is collected
Personal data may be collected:
(a) directly from the Data Principal;
(b) from a parent or lawful guardian;
(c) automatically through the Website or Application;
(d) during a Wisdom Session, event, HIDP or other Foundation Activity;
(e) through a Data Processor acting for the Foundation;
(f) through a Consent Manager recognised under Applicable Data Protection Law; or
(g) from another source where receipt and use of the information are lawful.
6. Purposes of processing
The Foundation may process personal data for the following specified purposes, as applicable:
(a) creating, authenticating and administering accounts;
(b) supplying requested content, programmes and Services;
(c) administering Wisdom Sessions, HIDP, events and community activities;
(d) processing donations, purchases, subscriptions and refunds;
(e) providing support and responding to requests;
(f) protecting accounts, participants, systems and Foundation Activities;
(g) preventing, detecting and investigating fraud, misuse and security incidents;
(h) moderating Community Content and enforcing applicable terms;
(i) recording and making Wisdom Sessions available as described in section 10;
(j) operating the Public Content Programme described in section 11;
(k) providing necessary transactional, operational, safety and legal communications;
(l) sending optional newsletters, fundraising, awareness, outreach or promotional communications where the applicable legal basis and consent or preference exist;
(m) maintaining records required by tax, accounting, charitable, regulatory or other applicable law;
(n) establishing, exercising or defending legal claims where permitted by law;
(o) analysing and improving functionality, security and user experience using data reasonably necessary for that purpose;
(p) creating and using genuinely anonymised information for research, analytics, statistical, educational and service-improvement purposes; and
(q) complying with applicable legal obligations.
A more specific notice may apply where the nature of a particular Service requires additional detail.
7. Data minimisation and accuracy
The Foundation shall collect and process personal data reasonably necessary for the specified purpose.
The Foundation shall make reasonable efforts to ensure that personal data is complete, accurate and consistent where it is used to make a decision affecting the Data Principal or disclosed to another Data Fiduciary.
Users may request correction, completion or updating of their personal data.
8. Communications and preferences
The Foundation may send communications necessary for account administration, authentication, transactions, registered programmes, support, security, fraud prevention, safety, legal notices or material Service updates.
Optional educational newsletters, fundraising appeals, promotional messages, awareness or outreach communications and information about other offerings shall be sent only where the applicable legal basis and required communication preference or consent exist.
Where consent is relied upon:
(a) relevant communication categories and channels may be offered separately;
(b) optional choices shall not be pre-selected;
(c) refusal shall not prevent access to an unrelated Service; and
(d) the User may withdraw consent through the unsubscribe facility, preference centre, account setting or other method stated in the relevant notice.
The Foundation may retain a minimal suppression record to ensure that an opt-out continues to be honoured.
9. Consent records
Where processing is based upon consent, the Foundation may retain appropriate evidence including:
• the applicable notice and its version;
• the specified purpose;
• the personal-data categories covered;
• the affirmative action taken;
• the date and time;
• the account or other relevant identifier; and
• the date and scope of any withdrawal.
Consent may apply to recurring processing involving the same categories of personal data, purpose and manner of use. Fresh consent shall be sought where required by law or where a material change introduces a new consent-dependent purpose.
Each consent notice shall provide the particular link or other means through which the Data Principal may withdraw consent, exercise applicable rights, use PAF’s grievance mechanism and make a complaint to the Data Protection Board of India.
10. Recording and use of Wisdom Sessions
Wisdom Sessions are recorded as part of the Foundation’s educational activities. Recordings may capture participants’ display names, faces, voices, questions, chat messages and interactions.
Recordings, including participant questions and related responses, may be edited, translated, subtitled, excerpted, archived and made available through the Application for educational, learning and archival purposes.
Where consent is the applicable basis, the Foundation may obtain consent once when a participant registers for or first joins the continuing Wisdom Sessions. The consent may apply to later Sessions involving the same categories of personal data, purposes and manner of availability through the Application.
A short reminder that recording is active may be displayed at the beginning of or during each Session without requiring consent to be collected again.
A participant who does not want their face displayed may:
(a) keep their camera switched off; or
(b) notify the Foundation through the mechanism communicated for the Session.
The Foundation shall take reasonable steps to apply the preference by not displaying the participant or by blurring, cropping or otherwise obscuring the participant’s face in the recording made available through the Application.
Questions and responses form an integral part of a Wisdom Session. A request to hide a participant’s face shall not ordinarily require removal of the participant’s question, voice, related response or substance of the interaction. Where required to address a valid privacy request, the Foundation may preserve the educational substance while obscuring unnecessary identifying details.
Participants should avoid disclosing passwords, government identifiers, financial information, exact addresses, unnecessary health information or private information about another person during a Session.
Recordings shall not be used for a materially unrelated purpose or published through an unrestricted public platform without an appropriate additional notice and any consent required under Applicable Data Protection Law.
11. Community Content and public publication
Community Content submitted to the participant-only Application may be processed to operate the community feature, including hosting, formatting, moderating, translating, subtitling and displaying it within the participant community.
Separately, PAF may operate a “Public Content Programme” under which selected posts, reflections, testimonials, photographs, audio, videos, questions or comments are edited and published through PAF’s public websites, social-media handles, video platforms, newsletters, publications or other identified public channels.
Where consent is relied upon, PAF may obtain consent for the Public Content Programme once when the User first logs in or first accesses the relevant community feature. The consent may apply to Community Content subsequently submitted without separate consent for every post, provided that the purposes, content categories and public channels remain materially unchanged.
Public Content Programme consent shall:
(a) be separate from general acceptance of the Terms;
(b) be expressed through clear affirmative action;
(c) explain that selected content may become publicly accessible;
(d) identify whether the User’s name, display name, image, voice, likeness or statements may appear;
(e) explain the editing and adaptation contemplated; and
(f) explain how consent may be withdrawn.
Subject to the applicable consent, PAF may edit, crop, resize, excerpt, compile, translate, subtitle, dub, adapt, reformat or combine Community Content for the disclosed purposes. PAF shall not knowingly edit content in a materially false or misleading manner or use it in a manner likely to cause a detrimental effect upon the User.
Unless separately agreed, the User is not entitled to payment or royalty merely because Community Content is selected or published. PAF shall not present the content as a commercial endorsement unless separately authorised.
Refusal to participate in the Public Content Programme shall not prevent access to an unrelated participant-only feature.
12. Withdrawal from the Public Content Programme
A User may withdraw Public Content Programme consent by writing to
[email protected]. Withdrawal shall stop the new selection and publication of the User’s Community Content under that consent.
Withdrawal shall not affect the lawfulness of processing completed before withdrawal. For identifiable content already published through a digital channel controlled by PAF, the Foundation shall assess the action required under Applicable Data Protection Law. Depending upon the circumstances, this may include:
• removing the content;
• restricting further use;
• replacing it with a de-identified version; or
• obscuring the User’s face, name, voice or other unnecessary identifier.
PAF may continue to use the non-personal or genuinely anonymised substance of content where it is no longer capable of identifying the User.
PAF cannot guarantee deletion of copies independently downloaded, quoted, recorded, shared or republished by third parties outside its control. This limitation does not reduce PAF’s obligations concerning accounts and channels under its control.
13. Children’s personal data
A “Child” means an individual below eighteen years of age, unless Applicable Data Protection Law provides otherwise.
A Child may use only a Service that PAF has specifically made available to Children. Before processing a Child’s personal data, PAF shall obtain verifiable consent from the Child’s parent or lawful guardian unless a specific legal exemption applies.
PAF may verify that the individual providing consent is an identifiable adult by reference to:
(a) reliable identity and age information already available to PAF; or
(b) identity and age information, or an authorised token mapped to such information, voluntarily supplied through an entity permitted under Applicable Data Protection Law.
PAF shall not knowingly:
(a) process a Child’s personal data in a manner likely to have a detrimental effect on the Child’s well-being;
(b) undertake tracking or behavioural monitoring of Children; or
(c) direct targeted advertising at Children,
except where a specific exemption under Applicable Data Protection Law applies.
Identifiable Community Content or a Wisdom Session recording involving a Child shall not be publicly used without verifiable parental consent specifically covering the relevant use.
Where a Child is brought to a physical or hybrid event without advance registration, PAF may refuse admission or take steps to prevent the Child from being identifiably recorded. Incidental capture shall be removed or obscured where reasonably practicable and required for the applicable purpose.
When a User reaches eighteen years of age, PAF shall provide an appropriate opportunity, where required, for the User to review privacy choices and exercise rights directly.
14. Cookies and similar technologies
The Website and Applications may use cookies or similar technologies for:
(a) essential operation and authentication;
(b) security and fraud prevention;
(c) remembering preferences;
(d) performance and diagnostics; and
(e) analytics or other optional purposes described in the applicable cookie notice.
Where legally required, non-essential cookies or similar technologies shall be activated only after the User’s applicable choice. Users may manage such technologies through the cookie-control mechanism or relevant browser/device settings. Disabling essential technologies may prevent certain features from functioning.
PAF shall not use such technologies to undertake prohibited tracking, behavioural monitoring or targeted advertising relating to Children.
15. Sharing of personal data
PAF may share personal data, to the extent reasonably necessary, with:
• hosting and cloud providers;
• payment processors;
• email, SMS, telephone and messaging providers;
• analytics and technical-service providers;
• event-registration and event-support providers;
• security, fraud-prevention and professional advisers;
• authorised age or identity-verification providers;
• social-media or publication platforms where the User participates in the Public Content Programme;
• government, regulatory, law-enforcement or judicial authorities where legally required; and
• another Data Fiduciary where the Data Principal directs or authorises such sharing or another legal basis applies.
PAF does not sell personal data.
A Data Processor acting for PAF shall process personal data only on documented instructions and under appropriate contractual confidentiality, security, breach-notification, assistance, return or erasure and assurance obligations. Appointment of a Data Processor does not relieve PAF of obligations imposed upon it as Data Fiduciary.
16. Third-party and public platforms
A third-party website, payment provider, social-media service or other independently operated platform may process personal data under its own privacy policy and terms. Users should review those documents before using the relevant service.
Where Community Content is published on a public platform with the User’s consent, members of the public may view, download, quote, record or reshare it. PAF cannot fully control independent processing undertaken by third parties after lawful public publication.
17. Overseas processing and transfers
PAF or its service providers may process or store personal data using infrastructure situated outside India.
Such transfers shall be subject to Applicable Data Protection Law and any restriction or requirement notified by the Central Government. If a transfer becomes legally restricted, PAF may suspend the affected transfer or Service while implementing a lawful alternative.
The relevant collection notice may provide additional information about material categories of overseas recipients or processing.
18. Automated systems and artificial intelligence
PAF may use automated or artificial intelligence-enabled systems for moderation, translation, subtitling, recommendations, customer support, security, analytics or Service delivery.
Where such systems process personal data, PAF shall identify the relevant categories and purposes in the applicable notice and apply proportionate data-minimisation, security and human-oversight measures.
Personal data submitted for one Service shall not be used to train a general-purpose model for an unrelated purpose without an independently valid legal basis and appropriate notice.
19. Information security
PAF shall implement reasonable technical and organisational safeguards appropriate to the nature and risks of the processing. These may include, as applicable:
• encryption, masking, tokenisation or equivalent protection;
• role-based access controls;
• authentication and account-security measures;
• access logs, monitoring and review;
• vulnerability and incident management;
• secure backups and recovery;
• workforce confidentiality and training;
• processor security obligations; and
• retention of security and processing logs for the period required under applicable law.
No method of storage or transmission is completely secure. This statement does not limit PAF’s statutory responsibility to implement reasonable security safeguards.
Users are responsible for keeping their passwords and authentication information confidential and should promptly notify PAF of suspected account misuse.
20. Personal data breaches
Upon becoming aware of a personal data breach, PAF shall activate its incident-response process without delay. From the commencement of the applicable DPDP provisions, PAF shall notify each affected Data Principal without delay in the prescribed manner and shall notify the Data Protection Board of India without delay, followed by the prescribed detailed information ordinarily within seventy-two hours or within such longer period as the Board may permit.
PAF shall notify the Data Protection Board of India and affected Data Principals in the form, manner and timeframe required by Applicable Data Protection Law.
Where notification to an affected Data Principal is required, it shall be concise and clear and shall describe, as applicable:
(a) the nature and extent of the breach;
(b) likely consequences relevant to the individual;
(c) mitigation measures taken or proposed;
(d) steps the individual may take to protect their interests; and
(e) contact information for relevant questions.
21. Retention and erasure
PAF shall retain personal data only for the period necessary to serve the specified purpose or for the period required or expressly permitted under Applicable Data Protection Law.
Retention periods or criteria may differ according to the nature of the information, including:
• account data: while the account remains active and thereafter for the applicable closure, security or legal period;
• transaction, donation, accounting and tax records: for the period required under applicable financial, tax, charitable or accounting law;
• Community Content: while required for the community purpose or Public Content Programme, subject to withdrawal and applicable rights;
• Wisdom Session recordings: while required for the disclosed educational and archival purpose, subject to applicable consent and privacy requests;
• grievance and rights-request records: for the period necessary to respond, demonstrate compliance and address related legal claims;
• consent records and suppression records: while necessary to demonstrate or honour the relevant choice;
• event and accommodation information: until the event-related purpose and applicable safety or legal requirements have ended; and
• security and processing logs: for the minimum or other period required under Applicable Data Protection Law.
PAF shall erase personal data when consent is withdrawn or when it is reasonable to assume that the specified purpose is no longer being served, whichever occurs earlier, unless retention is required or expressly permitted on another documented legal basis.
PAF shall require applicable Data Processors to erase personal data made available to them, subject to the same legal limitations.
Instead of erasure, PAF may irreversibly anonymise information so that it no longer identifies or is capable of identifying the individual. Merely moving identifiable personal data into an archive does not constitute erasure.
PAF shall maintain a documented retention schedule identifying the applicable period or objectively determinable criterion for each material data category. Data retained for an ongoing educational or archival purpose shall be reviewed periodically to determine whether continued identifiable retention remains necessary. “Archival purpose” shall not, by itself, authorise indefinite retention of identifiable personal data.
22. Rights of Data Principals
Subject to Applicable Data Protection Law, a Data Principal may request:
(a) a summary of personal data being processed and the processing activities undertaken;
(b) information concerning other Data Fiduciaries and Data Processors with whom personal data has been shared, as prescribed;
(c) correction of inaccurate or misleading personal data;
(d) completion of incomplete personal data;
(e) updating of personal data;
(f) erasure of personal data where the specified purpose is no longer being served, subject to lawful retention;
(g) withdrawal of consent;
(h) grievance redressal; and
(i) nomination of another individual to exercise rights in the event of death or incapacity.
The requester may be asked to provide their username, registered email address, registered telephone number, transaction reference or another proportionate identifier reasonably necessary to verify their identity and process the request. PAF shall not request excessive identity information merely because an individual is exercising their statutory right.
23. Withdrawal of consent
Where processing is based upon consent, the Data Principal may withdraw that consent at any time by writing to
[email protected]. or by using any withdrawal mechanism identified in the applicable consent notice.
The request should reasonably identify the Data Principal and the consent or processing purpose to which the withdrawal relates. PAF may seek only such additional information as is reasonably necessary to verify the requester’s identity and implement the request. The Data Principal shall not be required to provide a reason for withdrawing consent.
PAF shall make the withdrawal process reasonably accessible and as easy as the method used to provide consent. Where practicable, the email address shall be provided as a direct link or through a pre-addressed withdrawal facility.
Following valid withdrawal, PAF shall, within a reasonable operational period, cease the relevant consent-dependent processing and require applicable Data Processors to cease such processing, unless continued processing is required or expressly permitted under another applicable legal basis.
Withdrawal shall not affect the lawfulness of processing completed before withdrawal. Depending upon the personal data required for a particular Service, withdrawal may make it necessary to discontinue the affected feature or participation without affecting unrelated Services.
PAF may retain a minimal record of the withdrawal where reasonably necessary to demonstrate compliance and ensure that the withdrawn consent is not acted upon again.
24. Data Principal duties
When exercising rights or providing personal data, a Data Principal shall comply with duties imposed by Applicable Data Protection Law, including not impersonating another person, not furnishing false particulars, not suppressing material information in specified State-issued records and not submitting a grievance known to be false or frivolous.
PAF shall not penalise or retaliate against a User merely for submitting a good-faith privacy request or grievance.
25. Grievance redressal and privacy contact
Questions, rights requests and grievances concerning personal-data processing may be sent to:
Privacy Contact/Grievance Officer: Mr. Devesh Mittal
Organisation: PrashantAdvait Foundation
Email: [email protected]
PAF shall acknowledge and respond to a grievance within the period prominently published on the Website or Application. PAF shall acknowledge a grievance promptly and use reasonable efforts to resolve it within one month from receipt, or within such shorter period as may be required under Applicable Data Protection Law. Following commencement of the applicable DPDP provisions, the published grievance period shall in no event exceed the maximum period prescribed under the DPDP Rules.
After first using PAF’s grievance-redressal mechanism, a Data Principal may approach the Data Protection Board of India in accordance with Applicable Data Protection Law.
The above person is the Foundation’s privacy contact and Grievance Officer. The description “Data Protection Officer” shall be used only where PAF has formally appointed a Data Protection Officer or is required to do so as a Significant Data Fiduciary.
26. Changes to this Policy
PAF may update this Policy to reflect changes in the Services, practices, technology or law. Material changes shall be communicated through an appropriate channel before or when they take effect.
Continued use may constitute acknowledgement of the revised Policy but shall not constitute consent to a new personal-data processing purpose. Where a change introduces a new consent-dependent purpose, PAF shall obtain fresh, specific and affirmative consent before commencing that processing.
27. Contact
For general support enquiries:
For privacy matters, use the contact information and rights-request mechanism specified in section 25.