Legal

Privacy Policy

We take your privacy seriously. This policy explains exactly what data we collect, why we collect it, how we protect it, and your rights over it.

Effective: 1 January 2026
Version: 1.0
Governing Law: India (DPDP Act 2023)
Contact: meduvita17@gmail.com
🔒
We never sell your data
Your personal information is never sold or rented to any third party, ever.
Marketing is opt-in only
We will never use your data for marketing without your explicit prior consent.
🗑️
You can delete your data
Request deletion of your personal data at any time by emailing us.

Who we are: Meduvita is an independent UCAT and medical school application preparation service operated from India. We are the data controller for personal data collected through this website and our educational services. Our contact for all data-related queries is meduvita17@gmail.com.

Contents
Section 1

What Data We Collect

1.1 Data You Give Us Directly

When you contact us, book a consultation, or enrol in a course, we collect:

Data TypeExamplesWhen Collected
Identity dataFirst name, last nameContact form, enrolment
Contact dataEmail addressContact form, enrolment
Academic dataYear of study, course interest, current stageContact form, enrolment
Payment dataTransaction confirmation (we do not store card details)At point of payment
CommunicationsMessages you send us, optional notes in contact formContact form, email
1.2 Data Generated Through Use of Our Services

Once you are enrolled, we also collect:

Data TypeExamplesPurpose
Performance dataAI Q-Bank scores, practice test results, progress metricsPersonalising your learning
Participation dataSession attendance, questions asked, engagementDelivering the service
Feedback dataPersonal statement drafts submitted for reviewProviding feedback
1.3 Data We Collect Automatically

When you visit this website, we may automatically collect basic technical data including your IP address, browser type, device type, and pages visited. This is used solely for website security and to understand how visitors use the site. We do not build personal profiles from this data.

1.4 Data We Do NOT Collect

We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or financial account details beyond payment transaction confirmation. We do not store credit or debit card numbers.


Section 2

Why We Collect It — Legal Basis

Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the IT (Reasonable Security Practices) Rules 2011, we must have a lawful basis for processing your personal data. We rely on the following:

PurposeLegal Basis
Delivering the educational service you enrolled forPerformance of contract
Responding to enquiries via the contact formLegitimate interest / pre-contractual steps
Sending you booking confirmations and service updatesPerformance of contract
Marketing communications, testimonials, or promotional useExplicit consent only — you must opt in
Preventing fraud and ensuring platform securityLegitimate interest
Complying with legal obligationsLegal obligation

We will never use your data for marketing without first obtaining your separate, explicit, written consent. You can withdraw consent at any time — see Section 7.


Section 3

How We Use Your Data

We use your personal data only for the following purposes:

What we will never do: We will never use your data to make automated decisions that significantly affect you, build profiles for sale to third parties, contact you with unsolicited marketing without your prior consent, or share your identifiable data with any third party for their own marketing purposes.


Section 4

Who We Share Your Data With

4.1 We Do Not Sell Your Data

Your personal data is never sold, rented, or traded to any third party. Full stop.

4.2 Limited Service Providers

We may share the minimum necessary data with trusted service providers who help us operate our services. These providers are contractually bound to process your data only on our instructions and not for their own purposes:

CategoryPurposeData Shared
Payment processorProcessing course fees securelyName, email, transaction amount
Video conferencing platformHosting live sessionsName, email (for session access)
Email service providerSending booking confirmations and updatesName, email
Cloud storage providerStoring course materials and recordings securelyAnonymised or encrypted content only
4.3 Legal Disclosure

We may disclose your data if required to do so by law, court order, or government authority. We will notify you of any such request wherever legally permitted to do so.


Section 5

How Long We Keep Your Data

We do not keep your data for longer than necessary. Our retention periods are:

Data TypeRetention PeriodReason
Enquiry and contact form data (non-enrolled)12 monthsTo follow up and handle queries
Enrolment and course data3 years after course endContract records, dispute resolution
Payment transaction records7 yearsLegal and tax obligations under Indian law
AI Q-Bank performance dataDuration of enrolment + 12 monthsService delivery and improvement
Marketing consent recordsUntil consent is withdrawn + 12 monthsDemonstrating lawful basis
Website technical data (logs)90 daysSecurity monitoring

After the applicable retention period, personal data is securely deleted or permanently anonymised. You may request earlier deletion at any time — see Section 7.


Section 6

How We Protect Your Data

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure, in line with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These measures include:

Data breach notification: In the event of a personal data breach that is likely to result in harm to you, we will notify affected individuals and the relevant authority as required under the DPDP Act 2023, without undue delay.


Section 7

Your Rights

Under India's Digital Personal Data Protection Act, 2023 and applicable data protection law, you have the following rights over your personal data. To exercise any of these rights, email us at meduvita17@gmail.com with the subject line "Data Rights Request". We will respond within 30 days.

👁️
Right to Access
Request a copy of the personal data we hold about you and information on how it is used.
✏️
Right to Correction
Request that we correct any inaccurate or incomplete personal data we hold about you.
🗑️
Right to Erasure
Request deletion of your personal data. We will comply unless we have a legal obligation to retain it.
🚫
Right to Withdraw Consent
Withdraw marketing consent at any time. Withdrawal does not affect the lawfulness of prior processing.
📋
Right to Data Portability
Request your personal data in a structured, machine-readable format so you can transfer it elsewhere.
⚖️
Right to Grieve
If you are unhappy with how we handle your data, you have the right to raise a grievance with us or the relevant data protection authority.

We will respond to all rights requests within 30 days. If a request is complex or we receive multiple requests, we may extend this to 60 days and will inform you. We will not charge a fee for reasonable requests.


Section 8

Cookies & Tracking

8.1 What Are Cookies

Cookies are small text files placed on your device by a website. They help websites function properly and provide information about how the site is used.

8.2 Cookies We Use
Cookie TypePurposeCan You Opt Out?
Essential cookiesRequired for the website to function (e.g. session state, form security)No — required for basic function
Analytics cookiesUnderstanding how visitors use the site (aggregated, anonymous data only)Yes — contact us to opt out
Marketing cookiesWe currently do not use marketing or retargeting cookiesN/A
8.3 Third-Party Embeds

This website embeds fonts from Google Fonts. When your browser loads this page, a request is made to Google's servers. Google may log your IP address in accordance with their own privacy policy. We do not control this processing. We use Google Fonts solely to render the page correctly and receive no data from Google about individual visitors.

8.4 Managing Cookies

You can control and delete cookies through your browser settings. Disabling essential cookies may affect the functionality of this website. For further information on managing cookies visit allaboutcookies.org.


Section 9

Children's Privacy

Our services are primarily intended for individuals aged 18 and over. Where a student under 18 enrols with the consent of a parent or legal guardian, the parent or guardian accepts full responsibility for the student's compliance with our Terms, and for the accuracy of any data provided on the student's behalf.

We do not knowingly collect personal data from children under 13 without verifiable parental consent. If you believe we have inadvertently collected data from a child under 13 without appropriate consent, please contact us immediately at meduvita17@gmail.com and we will delete it promptly.

Under the DPDP Act 2023 (India), children are defined as individuals under 18. Where we are aware we are processing data of an individual under 18, we require verifiable parental consent and will not process their data for any purpose beyond direct service delivery.


Section 10

International Data Transfers

Meduvita operates from India. However, some of the third-party service providers we use (such as video conferencing or cloud storage platforms) may process your data on servers located outside India, including in the European Economic Area or the United States.

Where your data is transferred outside India, we take reasonable steps to ensure it receives a comparable level of protection, including by only using service providers that are bound by appropriate contractual data protection obligations.

By using our services, you acknowledge that your data may be transferred to and processed in countries outside India. We will always act in accordance with applicable Indian data protection law when making such transfers.


Section 11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will:

We encourage you to review this page periodically. Your continued use of our services after the effective date of any update constitutes your acceptance of the revised policy.


Section 12

How to Contact Us

For any questions about this Privacy Policy, to exercise your data rights, to withdraw consent, or to make a complaint about how we have handled your personal data, please contact us using the details below. We aim to respond to all queries within 5 working days and all formal rights requests within 30 days.

Data & Privacy Enquiries

We take every privacy query seriously. Reach out via email and include "Privacy" or "Data Rights" in your subject line so we can route your request correctly.

⏱️ Response time Within 5 working days
📄 Data rights requests Responded to within 30 days
If you are not satisfied with our response to a complaint, you may have the right to lodge a complaint with India's Data Protection Board once it is established under the Digital Personal Data Protection Act, 2023. You can also view our full Terms & Conditions for the complete contractual framework governing your use of Meduvita services.