Privacy Policy
Eccetra Career Counseling Pvt. Ltd. — www.eccetra.com
Effective Date: 19 May 2026|Last Reviewed: 19 May 2026
1. Introduction and Scope
Eccetra Career Counseling Pvt. Ltd. ("Eccetra", "we", "our", or "us") operates eccetra.com, an online platform providing career counseling and guidance services. This Privacy Policy describes how we collect, use, store, disclose, and protect personal data when you access or use our website, platform, and associated services (collectively, the "Services").
This Policy applies to all users of our Services worldwide, including parents or guardians acting on behalf of minor users. By accessing or using our Services, you agree to the practices described in this Policy.
We serve users internationally and therefore comply with multiple data protection frameworks including, but not limited to:
- India: Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- European Union / EEA: General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679
- United Kingdom: UK GDPR and Data Protection Act, 2018
- United States: Children's Online Privacy Protection Act (COPPA) – where applicable to users under 13 in the US
- Other applicable international data protection and children's privacy laws
2. Definitions
For the purposes of this Privacy Policy, the following terms have the meanings assigned to them below:
- "Personal Data" means any information relating to an identified or identifiable natural person, including name, contact details, usage data, or any combination thereof that can identify an individual.
- "Minor User" means any individual below the age of 18 years who accesses or uses our Services. For users between the ages of 10 and 17 years, access is conditioned upon verified parental or guardian consent.
- "Parent/Guardian" means the parent, legal guardian, or any adult legally responsible for the care and custody of a Minor User.
- "Sensitive Personal Data" means data as defined under applicable law, including financial information, health data, biometric data, and data revealing religious or political beliefs.
- "Processing" means any operation performed on Personal Data, whether automated or manual, including collection, recording, storage, use, disclosure, or deletion.
- "Data Fiduciary" means Eccetra Career Counseling Pvt. Ltd., who determines the purposes and means of processing Personal Data.
3. Data We Collect
3.1 Data Collected from Adult Users
When an adult (18 years or older) registers for or uses our Services, we may collect:
- Identity Data: full name, date of birth, gender
- Contact Data: email address, phone number, postal address
- Account Data: username, password hash, account preferences
- Academic and Career Data: educational qualifications, career interests, aptitude assessment responses, session notes
- Payment Data: transaction reference numbers processed via Razorpay; we do not store full card numbers, CVV, or bank account details on our servers
- Device and Usage Data: IP address, browser type, operating system, pages visited, session duration, referring URL
- Communication Data: messages exchanged with our counselors, emails sent to our support addresses
3.2 Data Collected for Minor Users (Age 10–17)
We take a strongly privacy-protective approach to minors. Our policy is to collect the minimum data necessary, and we require that all contact and identifying information for a Minor User be provided exclusively by and through the parent or legal guardian.
- Parent/Guardian Identity: full name of parent or legal guardian
- Parent/Guardian Contact: email address and phone number of parent or guardian ONLY – we do not request or collect the email address or phone number of the Minor User
- Minor's Profile Data: first name only, age range, grade/class, general academic interests (sufficient for counseling purposes)
- Session Data: counseling session notes and assessment responses pertaining to the Minor User, accessible only to the parent/guardian and assigned counselor
We expressly instruct parents and guardians not to provide the personal email address, personal phone number, or government-issued identification numbers of Minor Users when registering on their behalf. Accounts found to have been registered with a Minor's direct contact details will be flagged for parental verification and may be suspended pending review.
3.3 Automated Data Collection
When any user visits our platform, we automatically collect certain technical data through cookies and similar technologies:
- Log files recording server requests, error logs, access timestamps
- Cookies (see Section 12 on our Cookie Policy)
- Session identifiers and authentication tokens
- Approximate geographic region derived from IP address (country/state level only)
4. How We Use Your Data
4.1 Purposes of Processing
We process Personal Data for the following purposes and on the legal bases indicated:
| Purpose of Processing | Categories of Data Used | Legal Basis |
|---|---|---|
| To create and manage user accounts | Identity, Contact, Account Data | Performance of contract; Consent (minors) |
| To deliver career counseling services | Academic/Career Data, Session Data | Performance of contract; Legitimate interest |
| To process payments | Payment Data via Razorpay | Performance of contract; Legal obligation |
| To communicate with users/guardians | Contact Data, Communication Data | Performance of contract; Consent |
| To send service updates and notifications | Email, Device Data | Legitimate interest; Consent |
| To improve platform quality and safety | Usage Data, Log Data (anonymized) | Legitimate interest |
| To conduct AI-assisted analysis | Academic/Career Data, Session inputs | Consent; Legitimate interest |
| To comply with legal obligations | All categories as required | Legal obligation |
| To detect and prevent fraud or misuse | Device, Account, Log Data | Legitimate interest; Legal obligation |
4.2 AI-Assisted Services
Our platform uses artificial intelligence tools including third-party APIs and proprietary in-house AI modules to assist with career assessment analysis, content generation, and counseling support. The following conditions apply to AI processing:
- Data submitted through AI-powered features may be transmitted to third-party AI servers outside India, subject to their respective data processing terms and privacy policies.
- We do not transmit personally identifiable information to AI APIs beyond what is strictly necessary for the requested function.
- We do not use Minor User data to train or fine-tune any AI model.
- AI-generated outputs are subject to periodic quality review and monitoring by Eccetra; individual outputs are not manually reviewed prior to delivery and do not constitute standalone professional career counseling.
- Users may request that their interactions not be processed through third-party AI APIs by contacting info@eccetra.com.
5. Children's Privacy and Parental Consent
5.1 Minimum Age
Our Services are available to users aged 10 years and above. We do not knowingly permit access to children below 10 years of age.
5.2 Mandatory Parental Consent for Minor Users
Access by any individual under 18 years of age requires verifiable parental or legal guardian consent before an account is created or any Services are accessed. By registering a Minor User, the parent or guardian:
- Confirms they are the parent or legal guardian of the Minor User
- Provides their own (not the minor's) contact information for all account communications
- Consents to the collection and use of the Minor User's limited profile and session data for the purpose of delivering career counseling services
- Accepts this Privacy Policy on behalf of the Minor User
- Agrees to supervise and remain responsible for the Minor User's use of the platform
5.3 Contact Information Restriction
We explicitly instruct parents and guardians not to provide the following for any Minor User during registration or in any form submitted through our platform:
- The Minor User's personal email address
- The Minor User's personal mobile or telephone number
- The Minor User's government-issued ID, Aadhaar, passport, or similar document numbers
All account communication will be directed exclusively to the parent or guardian's registered contact details. If we discover that contact information belonging to a Minor User has been submitted directly, we will take immediate steps to delete such data and notify the guardian.
5.4 Parental Rights
Parents and guardians have the right to:
- Review all personal data held in relation to their Minor User's account by contacting info@eccetra.com
- Withdraw consent at any time, which will result in account suspension and scheduled deletion of the Minor User's data within 30 days
- Request correction or deletion of inaccurate data
- Restrict processing to essential service delivery only
5.5 Compliance with Children's Privacy Laws
For users in the United States under the age of 13, we comply with the requirements of the Children's Online Privacy Protection Act (COPPA). For users in the European Union or European Economic Area under the age of 16 (or the applicable age in their member state), we require parental consent as mandated by GDPR Article 8. For all users in India below 18 years of age, we comply with the DPDP Act 2023 and applicable IT Act rules concerning minors.
6. Data Storage and Infrastructure
6.1 Cloud Infrastructure
All primary user data is hosted on cloud infrastructure located within the territory of India. This includes:
- User databases and account data
- Session and counseling records
- Application logs
- Email and messaging infrastructure
Our cloud infrastructure provider is independently certified to leading international information security standards and complies with applicable Indian data localisation requirements.
6.2 International Data Transfers
Certain service components may involve transfer of data outside India, including to third-party AI service providers. Such transfers are governed by the data processing agreements and usage policies of the respective providers.
For EU/UK users, Standard Contractual Clauses (SCCs) are relied upon as the transfer mechanism where required. For Indian users, cross-border data transfers are conducted in accordance with applicable provisions of the DPDP Act 2023 and any rules or regulations notified thereunder. We maintain contractual data protection obligations with all third-party processors regardless of jurisdiction.
6.3 Data Retention
We retain Personal Data only for as long as necessary for the purposes stated in this Policy, or as required by applicable law:
- Active account data: retained for the duration of the account
- Session and counseling records (adult users): retained for 5 years from the date of the last session for audit and continuity purposes
- Session and counseling records (minor users): retained for 2 years from account closure or attainment of age of majority, whichever is earlier, except where retention is required by law
- Payment transaction records: retained for 8 years as required under Indian financial and tax law
- Communication logs: retained for 3 years
- Minor User data: upon withdrawal of parental consent or closure of account, scheduled for deletion within 30 days, except where retention is required by law
- Anonymized, aggregated analytics data: may be retained indefinitely
7. Sharing and Disclosure of Personal Data
7.1 We Do Not Sell Your Data
We do not sell, rent, or trade Personal Data to third parties for their independent commercial purposes.
7.2 Service Providers and Data Processors
We engage the following categories of third-party processors who act on our documented instructions:
- Cloud infrastructure provider: hosting, email, and messaging infrastructure
- Razorpay Software Pvt. Ltd.: payment processing
- Third-party AI service providers: AI-assisted career analysis features
- Communication service providers: SMS and notification delivery
- Analytics tools: anonymized usage analytics for platform improvement
All third-party processors are contractually bound by data processing agreements requiring them to maintain appropriate security measures and to process data only in accordance with our instructions.
7.3 Legal Disclosure
We may disclose Personal Data where required to do so by applicable law, regulation, court order, or government authority, including but not limited to disclosure under the Information Technology Act, 2000, or orders from competent Indian judicial or regulatory authorities.
7.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a substantial part of our assets, Personal Data may be transferred to the acquiring entity, subject to equivalent privacy protections. Affected users will be notified in advance where practicable.
8. Security of Personal Data
We implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, disclosure, alteration, or destruction, including:
- Industry-standard encryption of data in transit
- Industry-standard encryption of sensitive data at rest
- Access controls and role-based permissions on our infrastructure
- Regular vulnerability assessments and security reviews
- Staff training on data privacy and information security
- Incident response and breach notification procedures
Notwithstanding these measures, no method of electronic transmission or storage is completely secure. In the event of a data breach that poses a risk to users' rights and freedoms, we will notify affected users and relevant regulatory authorities within the timelines prescribed by applicable law (72 hours under GDPR; as prescribed under India's DPDP Act and CERT-In guidelines).
9. Your Rights as a Data Principal
9.1 Rights Under Indian Law (DPDP Act, 2023)
If you are a user in India, you have the following rights as a Data Principal:
- Right to Access: to obtain a summary of Personal Data processed and the processing activities undertaken
- Right to Correction: to have inaccurate or incomplete Personal Data corrected or completed
- Right to Erasure: to have Personal Data erased when it is no longer required for the stated purpose
- Right to Grievance Redressal: to have grievances addressed by our Grievance Officer within prescribed timelines
- Right to Nominate: to nominate another individual to exercise rights on your behalf in case of death or incapacity
9.2 Rights Under GDPR (EU/EEA and UK Users)
If you are a user in the European Union, European Economic Area, or United Kingdom, you additionally have the right to:
- Data portability: to receive your data in a structured, machine-readable format
- Restriction of processing: to request that processing be restricted in certain circumstances
- Object to processing: to object to processing based on legitimate interests
- Withdraw consent: without affecting the lawfulness of prior processing
- Lodge a complaint with a supervisory authority in your country of residence
9.3 How to Exercise Your Rights
To exercise any of your rights, contact our Grievance Officer at:
- Email: info@eccetra.com (for all data-related requests and grievances)
- Post: Data Grievance Officer, Eccetra Career Counseling Pvt. Ltd., Door No. 6/671, Eden Plaza, 4/920, Opposite Bharat Matha College, Judgemukku, Thrikkakara, Kochi, Kerala – 682021
We will respond to verifiable requests within 30 days. In complex cases, we may extend this by a further 30 days, with notice. We may require identity verification before processing a request.
10. Payment Processing and Financial Data
All payment transactions on our platform are processed by Razorpay Software Pvt. Ltd., a PCI-DSS Level 1 certified payment service provider registered in India.
- We do not collect, store, or process card numbers, CVV/CVC codes, bank account numbers, or UPI PINs on our servers.
- All financial data is entered directly on Razorpay-hosted secure payment pages.
- We receive only a transaction reference number and payment status confirmation from Razorpay.
- Razorpay's privacy policy governs the processing of payment data and is available at razorpay.com/privacy.
Transaction records (reference numbers, amounts, dates) are retained by us for 8 years in compliance with Indian financial recordkeeping requirements under the Income Tax Act and GST regulations.
11. Communications and Messaging
We use our email and messaging service providers to send service-related communications. These include:
- Account registration and verification messages
- Session booking confirmations and reminders
- Service updates and announcements
- Responses to your support enquiries
Marketing or promotional communications, if any, will only be sent with your explicit prior consent and you may opt out at any time by clicking the unsubscribe link in any such communication or by contacting info@eccetra.com.
All communications with Minor Users' accounts are directed exclusively to the registered parent or guardian email address and/or phone number.
12. Cookies and Tracking Technologies
Our website uses a small number of strictly necessary cookies and browser storage technologies to keep you signed in, remember your language preference, and route you to the correct area of the Platform after login.
We do not currently use cookies for advertising, marketing, or third-party analytics. If we begin using non-essential cookies or similar technologies in the future, we will update this Policy and, where required by law, request your consent.
13. Third-Party Links and Services
Our platform may contain links to third-party websites or integrate with third-party tools. This Privacy Policy does not apply to those third parties' data practices. We encourage you to review the privacy policies of any third-party services before providing personal data to them. We are not responsible for the privacy practices of third-party websites or services.
14. Grievance Redressal
14.1 Internal Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, we have designated a Grievance Officer to address any concerns related to the processing of Personal Data:
| Name | Jhon Arogyaswamy |
| Designation | Grievance Officer — Data Protection |
| Contact Email | info@eccetra.com |
| Alternate Email | jhon@eccetra.com |
| Phone | +91 95674 29638 |
| Postal Address | Door No. 6/671, Eden Plaza, 4/920, Opposite Bharat Matha College, Judgemukku, Thrikkakara, Kochi, Kerala – 682021, India |
| Response Timeframe | Acknowledgement within 48 hours; Resolution within 30 days of receipt |
14.2 Regulatory Authorities
If you are not satisfied with our response, you may escalate your complaint to:
- India: The Data Protection Board of India (once constituted under the DPDP Act, 2023) or the Ministry of Electronics and Information Technology (MeitY)
- EU/EEA: Your national data protection supervisory authority (e.g., CNIL in France, BfDI in Germany, ICO in the UK)
- United States (COPPA matters): The U.S. Federal Trade Commission (FTC)
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or data processing practices. When we make material changes, we will:
- Update the 'Last Reviewed' date at the top of this document
- Notify registered users via the email address registered to their account
- Display a prominent notice on our platform for at least 30 days following any material update
Your continued use of our Services after the effective date of any revised Policy constitutes your acceptance of the updated terms. For Minor User accounts, continued access by the parent or guardian following notification will constitute renewed consent.
We encourage users to review this Policy periodically.
16. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of India, including the Information Technology Act, 2000, the Information Technology (Amendment) Act, 2008, the IT (Reasonable Security Practices) Rules, 2011, and the Digital Personal Data Protection Act, 2023, as amended from time to time.
For users in the European Union or United Kingdom, GDPR and UK GDPR obligations shall apply in addition to the above. For users in the United States in relation to Minor Users below 13 years, COPPA obligations shall apply.
Any disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of Kochi, Kerala, India, without prejudice to the rights of EU and UK users to seek remedies from their local supervisory authorities.
This document was last reviewed on 19 May 2026 and supersedes all prior versions.
© 2026 Eccetra Career Counseling Pvt. Ltd. All rights reserved.