Legal
Privacy policy
This policy explains what personal data TRANSFORMMI collects, why we collect it, where it is stored, who else can see it, and the rights you have over it under the Digital Personal Data Protection Act 2023.
Who is responsible for your data
TRANSFORMMI is the data fiduciary for the personal data described in this policy. That means we decide what is collected and why, and we are accountable for how it is handled — including by anyone we engage to process it on our behalf.
If you want to raise something about your data, the grievance route is set out at the end of this policy. You do not need to give a reason to ask a question about it.
What we collect
We collect only what the programme actually needs to run. There is no profiling for advertising, no data broking, and nothing is bought in from third-party lists.
- Account data: your name, email address, phone number, discipline, education and work experience, provided by you at registration.
- Enquiry data: anything you send through the contact form or the enquiry routes — your message, your discipline, your career stage and the country you gave.
- Assessment data: your responses to screening and module assessments, and the baseline scores derived from them.
- Programme data: module progress, session attendance, submitted work, and coaching notes recorded by our team.
- Payment metadata: the amount, currency, timestamp and reference of a transaction. Card and bank details never reach our systems — they are handled entirely by the payment provider.
- Technical data: IP address, browser type and pages visited, collected only in aggregate and only for analytics you have consented to.
What we deliberately do not collect
We do not collect card numbers, CVVs or bank credentials at any point. We do not collect caste, religion, political opinion, health data or biometric data. We do not track you across other websites, and we do not run advertising pixels.
If you send us something in an enquiry that we did not ask for and do not need, we delete it rather than file it.
Why we collect it
Each category above maps to a specific purpose. We do not collect anything on the basis that it might be useful later.
- To deliver the programme you enrolled on, which is the contract between us.
- To measure your baseline and produce your gap report, which is the whole method.
- To contact you about your enrolment, your sessions and your results.
- To answer an enquiry you sent us, and to follow it up if you asked us to.
- To meet legal obligations, including retaining financial records for the period Indian tax law requires.
- To improve the programme in aggregate — never by singling out an individual candidate's performance for any purpose other than their own coaching.
Consent, and what happens if you withdraw it
Where we rely on your consent — analytics cookies, and marketing messages that are not about your own enrolment — that consent is asked for plainly, is never pre-ticked, and can be withdrawn at any time without penalty.
Withdrawing consent for analytics changes nothing about your access to the site or the programme. Withdrawing consent for optional messages stops those messages, but we will still send you the operational ones your enrolment depends on, such as session times and assessment results.
Where your data is stored
Candidate personal data is stored in India. Our database and file storage both run in the ap-south-1 (Mumbai) region, and application servers are located in India.
Some processors we rely on operate globally. Where any data is processed outside India, it is limited to what that service strictly requires, and we document it.
If you are outside India
The programme is open to candidates in more than one country. Wherever you are, your data is stored and processed in India, and Indian law — including the DPDP Act — governs how we handle it.
By enrolling or sending an enquiry from outside India, you are asking us to process your data in India. If your own jurisdiction gives you rights beyond those described here, we will honour the stronger of the two rather than the more convenient one.
Who else can see it
We share personal data only with processors who need it to make the service work, and only to the extent they need. Each is bound by contract to use it for nothing else.
- Our cloud hosting and database providers, who store the data.
- Our payment provider, who handles the transaction and holds the card details we never see.
- Our email provider, for the messages we send you.
- Our video and live-session providers, for recorded and live teaching.
- Subject matter experts and coaches engaged by us, who see only the candidate work they are reviewing.
- Employers, but only the specific details you have explicitly approved for a specific introduction. We never circulate a candidate's profile speculatively.
We do not sell your data
We have never sold personal data, we do not sell it now, and the business model does not depend on ever doing so. We are paid by candidates for a programme, not by advertisers for an audience.
Your rights
Under the DPDP Act you have the following rights. Exercising any of them is free, and we will not treat you differently for having done so.
- Access: you can ask what data we hold about you and get a copy of it.
- Correction: you can ask us to fix anything inaccurate, incomplete or out of date.
- Erasure: you can ask us to delete your data. We will, except for financial transaction records, which Indian law requires us to retain — those are anonymised rather than deleted.
- Nomination: you can nominate someone to exercise these rights on your behalf if you become unable to.
- Grievance: if you are not satisfied with how we have handled a request, you can escalate it to our grievance officer, and then to the Data Protection Board of India.
Retention
We keep data only as long as the purpose it was collected for requires, and then we remove it.
- Account and programme data: for as long as your account is open, and for one year after you close it.
- Assessment and baseline score records: retained with your account, because your gap report is only meaningful against your baseline.
- Enquiry messages: two years, so we can pick up a conversation you started, then deleted.
- Financial records are kept for eight years, as Indian tax law requires.
- Analytics data: aggregated and stripped of identifiers within fourteen months.
How we protect it
Data is encrypted in transit and at rest. File storage blocks all public access — uploaded documents are reachable only through short-lived signed links generated for a specific authorised request.
Access inside the company is limited to staff whose role requires it, and administrative actions on candidate records are written to an append-only audit log that cannot be edited after the fact.
No system is perfect. If a breach occurs that puts your data at risk, we will notify you and the Data Protection Board as the DPDP Act requires, and we will tell you what actually happened rather than a sanitised version of it.
Children
The programme is intended for candidates in higher education or in work, and the platform is not directed at children under 18. We do not knowingly collect data from a child. If we learn that we have, we delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects your rights or how your data is used, we will tell you directly rather than relying on you to notice.
We will not apply a materially different use to data we already hold without asking you first.
Contact and grievance
For any question about this policy, a request to exercise a right, or a complaint, email support@transformmi.net or message us on WhatsApp. We acknowledge within two working days and aim to resolve within thirty.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
Something here unclear?
Ask before you enrol rather than after. We would rather explain a clause than argue about it later.