Privacy Policy

Effective Date: 14-August-2026 

This document (“Policy”) outlines the approach to privacy of Soulscale Consulting Private Limited (CIN: U74999KA2021PTC156148), a company incorporated under the Companies Act, 2013 and having its registered office in Bengaluru, Karnataka (“Soulscale”), in fulfilment of its obligations under applicable privacy laws, including the Digital Personal Data Protection Act, 2023 (the “DPDP Act”). The GRI Learning & Resource Hub is owned and operated by Soulscale Consulting Private Limited. 

This Policy explains what information we collect, how we use it, how we protect it, and the choices and rights available to you regarding your personal data. 

By creating an account on the Platform, you acknowledge that you have read and understood this Policy and agree to the collection, storage, use, and processing of your Personal Data for the purposes described herein. Where processing relies on your consent, that consent is free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, as required under Section 6 of the DPDP Act. The itemised notice required under Section 5 of the DPDP Act is presented to you at the time of account creation, separately from this Policy. You may access that notice and this Policy in English. 


Definitions 

For the purposes of this Policy: 

Personal Data means any data about an individual who is identifiable by or in relation to such data. 

Data Fiduciary means the person or entity that alone or in conjunction with others determines the purpose and means of processing Personal Data. For the purposes of this Policy, Soulscale Consulting Private Limited acts as the Data Fiduciary. 

Data Principal means the individual to whom the Personal Data relates. 

Processing means a wholly or partly automated operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, use, adaptation, retrieval, disclosure, sharing, transfer, dissemination, restriction, erasure, or destruction. 

Consent Manager means a person registered with the Data Protection Board of India under Section 6(9) of the DPDP Act, acting as a single point of contact to enable a Data Principal to give, manage, review, or withdraw consent through an accessible, transparent, and interoperable platform, in accordance with applicable law. 

Platform means the GRI Learning & Resource Hub, including its website, learning management system, applications, services, features, content, and related digital resources operated by Soulscale Consulting Private Limited. 

Personal Data Breach means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. 

 

Please note that this policy is applicable to all instances where we play the role of a Data Fiduciary of your Personal Data, when we collect and process personal data about you based on your access through the Platform or any other information or intimations or services that you subscribe to on the Platform.

 

Soulscale is committed to keeping your Personal Data private. We process any Personal Data we collect from you in accordance with the applicable laws and regulations and the provisions of this document. Please read the following carefully to understand our views and practices regarding your Personal Data and how we treat it. 


Throughout this document, the terms “we”, “us”, “our” and “ours” refer to Soulscale; the terms “Platform”, “GRI” and “Learning & Resource Hub” refer to the GRI Learning & Resource Hub operated by Soulscale; and the terms “you”, “your” and “yours” refer to you, as the Data Principal. 


What Personal Data do we Collect & Process? 

Categories of Personal Data that we collect, and process are as follows: 

  • Identity and Contact Data (for e.g.First Name, Last Name, Email Address, Phone Number, Username and Password) 

  • Demographic Information (For e.g. Gender (where voluntarily provided), City, State, Country) 

  • Professional and Educational Information (For e.g. Professional category, Organization or institution name, Organization or institution address, Sector of work) 

  • Learning and Engagement Information (For e.g. Course enrolments, Course completion status, Assessment scores, Certificates issued, Webinar participation, Discussion forum participation, Feedback and survey responses) 

  • Technical Data (For e.g. IP Address, Browser type, Device information, Access logs, Session information) 

We do not intentionally collect financial account information, government identity numbers, biometric data, or health data through the Platform. If this changes, this Policy will be updated before any such collection begins. 

Where do we obtain your Personal Data from? 

Most of the Personal Data we process is provided directly by you when you create an account on the Platform, enrol in courses, participate in webinars, complete assessments, provide feedback, contact us, or otherwise use the services available through the Learning & Resource Hub. We also collect certain Personal Data automatically through your use of the Platform, including technical information such as device information, browser type, IP address, and usage logs. 


How do we use your Personal Data? 

We use your Personal Data for the following purposes: 

  • To verify your identity 

  • To deliver our services 

  • To communicate with you regarding our services availed by you, including notifications of any alerts or updates 

  • To evaluate, develop and improve our services 

  • For analysis and research 

  • To handle enquiries and complaints 

  • To comply with legal or regulatory requirements 

  • To investigate, prevent, or take action regarding illegal activities, suspected fraud and situations involving potential threats to the safety of any person 

  • Learning Data - We may collect and process information relating to your learning journey on the Platform, including courses accessed, progress made, assessments completed, certificates issued, and participation in webinars, discussion forums, surveys, and learning activities. This information enables us to deliver learning services, improve content quality, measure engagement, and generate anonymous insights regarding platform usage. 

 

Lawful Bases of processing your Personal Data 

Under Section 4 of the DPDP Act, personal data may be processed only for a lawful purpose and only on one of two grounds - your consent, or certain legitimate uses. We rely on the following: 

  • Your consent (Section 6, DPDP Act) - you have given free, specific, informed, unconditional and unambiguous consent, through a clear affirmative action, to our processing of your Personal Data for a specified purpose. This includes creating and administering your account and delivering the courses, webinars and assessments you enrol in. 

  • Compliance with law (Sections 7(d) and 7(e), DPDP Act) — the processing is necessary to fulfil an obligation under law to disclose information to the State, or to comply with a judgment, decree or order 

  • Voluntarily provided data — where you have voluntarily provided your Personal Data for a specific purpose (e.g. a discussion-forum post) and have not indicated that you do not consent to its use, in line with Section 7(a) of the DPDP Act; and 

  • The processing is necessary for other reasonable purposes. Other legitimate uses specifically recognized under Section 7 of the DPDP Act (e.g. for a subsidized benefit, service or license from the State, medical emergencies, or employment-related purposes), applied only where genuinely relevant to the Platform. 

Where the processing is based on your consent, you have the right to withdraw your consent at any point in time, including, where such a facility is available, through a Consent Manager registered with the Data Protection Board of India. Please note that should the withdrawal of consent result in us not being able to continue offering our products and services to you, we reserve the right to withdraw or cease our products and services to you upon your withdrawal. You may withdraw your consent by written request to the contact details specified below in the ‘Contact Us’ section. In accordance with Section 6(4) of the DPDP Act, withdrawing consent will be as easy as giving it. Upon withdrawal, we will cease, and cause our Data Processors to cease, processing your Personal Data, unless retention or processing is required under applicable law. Upon receipt of your request to withdraw your consent, we will acknowledge it within 7 business days and communicate the consequences of withdrawal within 15 business days.  


When do we share your Personal Data with third parties? 

We may use third-party technology and cloud-based service providers, including Learning Management System (LMS) providers, hosting services, analytics providers, and communication platforms, to operate and maintain the Platform and deliver learning services. Such providers may process Personal Data solely for the purposes authorized by us and are required to implement appropriate security and confidentiality measures. 

1. Reasons for sharing your Personal Data with third parties: 

We may disclose your Personal Data to third parties only where it is lawful to do so. This includes instances where we or they: 

  • need to provide you with services 

  • have asked you for your consent to share it, and you have agreed 

  • have a reasonable ground for doing so 

  • have a legal obligation to do so. For e.g., to assist with detecting and preventing fraud 

  • have a requirement in connection with regulatory reporting, litigation or asserting or defending legal rights and interests 

We may also disclose your Personal Data to appropriate authorities if we believe that it is reasonably necessary to comply with a law, regulation, legal process; protect the safety of any person; address fraud, security, or technical issues; or protect our rights or the rights of those who use our products & services. 

2. With whom your Personal Data may be shared: 

We may disclose your Personal Data to the following third parties: 

  • Our technology vendors, LMS hosting providers, cloud storage providers, webinar platforms, analytics providers, learning partners, trainers, facilitators, and other service providers who support delivery of the Platform and its services. 

  • We may use anonymized and aggregated information regarding platform usage, course participation, completion rates, geographic reach, sector representation, and learning outcomes for internal reporting and reporting to our clients, and programme partners. Such reports will not identify individual users unless separate consent has been obtained. 

 

Cross-border data transfer 

Personal Data we hold about you may be transferred to other countries outside India for any of the purposes described in this Policy. 

Such transfers will be made in accordance with Section 16 of the DPDP Act. As of the effective date of this Policy, the Central Government has not restricted transfer of Personal Data to any country; if such a restriction is notified in future, we will not transfer Personal Data to the restricted country or, where applicable, will only do so on the terms permitted. 

Any Personal Data will be protected in accordance with this Policy as well as with adequate protections in place in compliance with applicable laws and regulations. 

The Platform may be hosted or supported through third-party service providers whose infrastructure, servers, or support operations may be located outside India. Where Personal Data is transferred across jurisdictions, Soulscale shall take reasonable measures to ensure that such transfers are undertaken in accordance with applicable laws and that appropriate safeguards are in place to protect your Personal Data. 


Use of Cookies and other Tracking Mechanisms 

We may use cookies and other tracking mechanisms on our website and other digital properties to collect data about you. 

Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information about your actions to the owners of the website. 

Most web browsers allow you some control of cookies through browser settings. 

Outlined below are the categories of cookies along with a description of what they are used for. 

  • Strictly Necessary Cookies - These cookies are needed to run our website, to keep it secure and to comply with regulations that apply to us. 

  • Functional Cookies – We may use functional cookies on our website. These cookies allow us to remember information you enter or choices you make (such as your username, language, or your region) and provide you with enhanced, more personalised features. 

  • Performance/Analytics Cookies – We may use performance/analytics cookies on our website. These cookies collect information about how visitors use our website and services, including which pages visitors go to most often and if they receive error messages from certain pages. It is used to improve how our website functions and performs. 

We may also use trackers (such as web beacons, tags, pixels) on our website and other digital properties to collect data about you. 

We may also collect Personal Data about you via our mobile app(s) via permissions in the app. This is primarily used to enhance the functionality of the app and to analyse it to serve you better. 


How do we secure your Personal Data? 

We are committed to protecting your Personal Data in our custody. We take reasonable  physical, technical and organizational measures, including access controls, encryption in transit, and logging, to protect your Personal Data  from unauthorized access, alteration, disclosure or deletion. We require third parties who process personal data on our behalf to  take appropriate security measures under binding contracts. If you believe you have identified a security vulnerability or suspicious activity affecting your account, please report it to us immediately at the contact details in the ‘Contact Us’ section. 


Personal Data Breach 

In the event of a personal data breach, we will give intimation of the breach to the Data Protection Board of India and to each affected Data Principal, in the form and manner and within the timelines prescribed under Section 8(6) of the DPDP Act and the rules made thereunder. Our intimation to you will describe the nature and extent of the breach, its likely consequences, the measures we have taken to mitigate it and the steps you may take to protect your interests.

 

How long do we keep your Personal Data? 

We retain the Personal Data only for as long as necessary for the purpose it was collected, generally:  

  1. account and learning data, for the duration of your active account plus 3 years thereafter, to support certificate verification and legal defence of claims 

  1. technical/log data, up to 12 months 

  1. where Personal Data forms part of our books of account or other statutory records, for the period prescribed under the Companies Act, 2013, the Income-tax Act, 1961 and other applicable laws; and any other data we are required to retain for a longer period under applicable law, for that longer period 

 

We take reasonable steps to delete or anonymise Personal Data once these retention periods expire, unless its retention is required for compliance with any law for the time being in force, as contemplated by Section 8(7) of the DPDP Act. 


Links to other Websites 

Our website may contain links to websites of other organizations. This privacy notice does not cover how those organizations process your Personal Data. We encourage you to read the privacy notices on the other websites you visit. 


Notification of changes 

We regularly review and update our Privacy Notice to ensure it is up-to-date and accurate. Any changes we may make to this Privacy Notice in future will be posted on this page. 


Your Privacy rights 

Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you may have the right to: 

  • Obtain a summary of the Personal Data being processed by us and of our processing activities, as per the DPDP law. 

  • Request correction of inaccurate or incomplete personal data 

  • Request erasure of personal data, subject to legal and operational requirements 

  • Withdraw consent for processing based on consent 

  • Nominate another individual to exercise rights in accordance with applicable law 

  • Seek grievance redressal relating to personal data processing 

We will acknowledge a rights request within 7 business days and respond substantively within 30 days, or such other period as prescribed by law. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India. 


Account Closure and Deletion 

You may request deletion of your account by writing to us at the contact details provided below. Upon verification of your request, we will delete or anonymize your personal data unless retention is required by law or for legitimate operational purposes, including maintaining records of course completion and certificates previously issued. 


Child Protection 

The Platform is designed for use by persons aged 18 years and above. Where a person under 18 years of age (a "child" under the DPDP Act) accesses the Platform through an educational institution, we will process the child's Personal Data only after obtaining verifiable consent from the parent or lawful guardian, or from the institution acting in loco parentis where permitted by law, and only to the extent necessary to provide educational services. 

We do not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children, except where such processing is exempted under the DPDP Rules (for example, for platforms used solely for education, subject to the safeguards prescribed). 

 

Changes to Learning Services 

We may periodically add, modify, suspend, or discontinue courses, learning resources, certificates, webinars, and platform features. Such changes shall not affect our obligations regarding the protection of your personal data under this Privacy Policy. 


Notification of changes to this Policy 

We regularly review and update this Policy to keep it accurate and up to date. We will post any changes on this page and update the effective date above. Where a change materially affects the purposes for which we process your Personal Data or the rights available to you, we will also take reasonable steps to notify you directly, such as by email or an in-Platform notice, before the change takes effect.  


Governing law and jurisdiction 

This Policy is governed by the laws of India. Subject to Section 39 of the DPDP Act and to the jurisdiction of the Data Protection Board of India, the courts at Bengaluru, Karnataka shall have jurisdiction over any disputes arising out of or in connection with this Policy, without prejudice to any right you have to approach the Data Protection Board of India or another competent authority. 


Contact us 

For any queries and complaints related to privacy, or to exercise your rights, you may reach us at: 

Grievance officer 

Name: Siji Chacko 

Designation: Grievance Officer 

Email: grc@soulscale.org 

 

Address:  

Soulscale Consulting Private Limited, 3/21,Ground Floor Kaveriappa layout, millers tank bund road, vasantnagar, near Mahaveer Jain Hospital , Bangalore North, Karnataka, India - 560001 

 

We will acknowledge complaints within 7 business days and aim to resolve them within 30 days, in line with this Policy.