1.  Introduction & Your Privacy Commitment

1.1 Brainberg Knowledge Solutions Private Limited (?Brainberg?, ?we?, ?our?, ?us?) recognizes the importance of protecting your personal information. Your privacy is extremely important to us. We invest substantial thought, effort, tools, technology, managerial safeguards, and operational processes to protect your personal data.

1.2 This Privacy Policy explains how we collect, use, process, store, share, disclose, and protect your information when you access or use our platforms, websites, assessments, tools, and services (collectively, the ?Platform?).

1.3 By accessing or using the Platform, you:?(i) confirm that you have read and understood this Privacy Policy;?(ii) acknowledge that this Privacy Policy forms an integral part of the Terms & Conditions;?(iii) give your free, informed, unconditional and specific consent to the collection and processing of your data under the Digital Personal Data Protection Act, 2023 (?DPDPA?) and the Digital Personal Data Protection Rules, 2025 (?DPDP Rules, 2025?), to the extent such provisions are in force; and?(iv) provide consent under the General Data Protection Regulation (?GDPR?), where applicable.

1.4  If you do not agree with this Privacy Policy, you should stop using the Platform immediately.

1.5  If you use the Platform on behalf of another individual (such as a student, minor, employee, dependent, or end-user), you represent that you are authorised to accept this Privacy Policy on their behalf.

2.  Compliance With Applicable Laws

2.1  This Privacy Policy is published in accordance with, and to demonstrate compliance with, the following legal frameworks:

2.1.1 Indian Law

(i) Digital Personal Data Protection Act, 2023 (DPDPA), including the DPDP Rules, 2025, to the extent such provisions have been notified and brought into force in accordance with the Government?s phased implementation schedule.

(ii) Section 43A of the Information Technology Act, 2000, relating to compensation for failure to protect personal data, to the extent consistent with the DPDPA framework and any notified security standards, as applicable.

(iii) CERT-In Directions, 2022, governing cybersecurity incident reporting, log maintenance, time-bound breach notification, and security hygiene requirements.

2.1.2 European Union ? GDPR

2.2 Where applicable, the processing of personal data of individuals located in the European Union/ EEA is carried out in accordance with the General Data Protection Regulation (EU) 2016/679 (?GDPR?).

2.3 For such processing, Brainberg acts as the ?Data Controller?, responsible for ensuring compliance with GDPR?s principles, lawful bases, obligations, and data subject rights.

3.  Categories of Information We Collect

3.1  To provide our services effectively, Brainberg collects the following categories of personal information (?Information?). We collect only the information necessary for lawful and specified purposes, in accordance with the DPDPA and the DPDP Rules, 2025.

3.1  Personal Identifiable Information (PII)

3.1.1  This includes information that can identify you directly or indirectly, such as:?(i) name, gender, age, date of birth;?(ii) email address, mobile number, postal address;?(iii) parent/guardian details (for minors);?(iv) employer, school, institution, or organizational details; and?(v) user account information and login identifiers (excluding passwords).

3.2  Sensitive / Special Category Information

3.2.1 Some Brainberg services (e.g., assessments, behavioural analysis, cognitive profiling, recommendations) may involve processing information that is considered:?(i) sensitive personal data under the DPDPA framework; and?(ii) special category data under the GDPR.

3.2.2 This includes, without limitation:?(i) assessment responses;?(ii) psychological, behavioural, emotional, and cognitive indicators;?(iii) reports, scores, summaries, insights, and recommendations;?(iv) information exchanged between you and Brainberg experts/assessors; and?(v) data relating to minors (processed with parental or institutional authorisation).

3.2.3 Such information is collected only with explicit, affirmative consent, or with valid institutional authorisation for school/organizational assessments, as permitted by applicable law.

3.3 Technical and Usage Data

3.3.1 When you use the Platform, we may automatically collect:?(i) IP address, device identifiers, device type, and operating system;?(ii) browser type, version, language, and session logs;?(iii) date and time of access, clickstream data, and usage patterns;?(iv) referrer URLs and exit pages;?(v) internet service provider (ISP) information; and?(vi) diagnostic, security, and performance analytics (including crashes and load times).

3.3.2 The above collection may involve the use of cookies, tags, pixels, and similar tracking technologies, as further detailed in Section 9 (Cookies and Tracking Technologies).

3.3.3 Proctoring-Related Technical Data: For certain assessments or tests conducted on the Platform that require online proctoring, and only for the duration of such assessment, Brainberg (or its authorised proctoring service provider) may additionally collect limited technical and monitoring data, which may include:?(i) camera feed, images, or video recordings;?(ii) audio recordings (where enabled);?(iii) screen sharing, screen recordings, or screen captures; and?(iv) session-level device, browser, and integrity signals relevant to assessment conduct.

Such proctoring-related data is collected only with prior notice and explicit consent, is used strictly for assessment integrity, authentication, malpractice detection, and dispute resolution, and is governed by Clause 4.2 (Test Proctoring)of this Privacy Policy.

3.4 Information You Voluntarily Provide

3.4.1 This includes any information you choose to share, such as:?(i) emails, messages, responses, or communications with Brainberg;?(ii) documents, files, or materials voluntarily uploaded by you;?(iii) support, feedback, or survey responses; and?(iv) additional data provided during onboarding, consultations, or follow-ups.

3.5 Payment & Transaction Data

3.5.1 For paid services, we may collect:?(i) payment mode (UPI, card, net banking, wallet);?(ii) masked card details or tokenized identifiers;?(iii) billing address; and?(iv) transaction metadata (amount, date/time, status).

3.5.2 All payments are processed through secure, compliant, PCI-DSS certified payment gateways. Brainberg does not store full card or banking details.

4. Information We Do NOT Collect

4.1 Except as expressly stated under Clause 4.2 (Test Proctoring) below, Brainberg does not, and will not, collect, access, monitor, or record:?(i) keystrokes (including any keylogging outside the Platform);?(ii) form inputs entered outside the Platform;?(iii) passwords entered in third-party websites or applications;?(iv) screenshots, screen recordings, or camera feeds unrelated to the use of the Platform;?(v) files, documents, or content stored on your device without your active upload; or?(vi) any information not intentionally submitted by you or not visible to you on the screen.

4.2 Test Proctoring During Assessments

4.2.1 Certain assessments/ tests on the Platform may require online proctoring to protect test integrity, prevent impersonation, and detect malpractice (?Proctoring?). Where Proctoring is enabled, Brainberg (and/or its authorised proctoring service provider) may collect and process limited information during the assessment session, which may include:?(i) live camera feed and/or periodic photographs;?(ii) audio (where enabled);?(iii) screen-sharing/ screen recording or periodic screen captures;?(iv) device/ browser signals and session logs (including IP address, timestamps, and technical diagnostics); and?(v) identity verification inputs where required for the test (for example, an ID document upload or selfie verification), if applicable.

4.2.2 Proctoring (i) is activated only for the duration of the assessment session (and related verification checks), (ii) is disclosed through pre-test notice and/or a separate proctoring consent prompt, and (iii) is used only for:?(i) identity verification and candidate authentication;?(ii) detecting prohibited behaviour or policy violations;?(iii) generating integrity flags/reports for authorised institutional users (schools/employers) or Brainberg administrators; and?(iv) investigating disputes, appeals, or integrity incidents.

4.2.3 Brainberg does not use proctoring data for advertising or unrelated profiling, and access to such data is restricted on a strict need-to-know basis. Proctoring data is retained only for the period set out in the Data Retention clause (or as required by the relevant institution/ applicable law), after which it is deleted or irreversibly anonymised, as applicable.

4.3 Brainberg does not run spyware, hidden keyloggers, or surveillance tools to monitor your device outside the Platform, and does not access device content without your active interaction and authorisation as described in this Privacy Policy.

5. Legal Basis for Processing (DPDPA & GDPR)

5.1 Under DPDPA (India)

5.1.1 Brainberg processes personal data under the following lawful bases:

(i) Consent?Free, specific, informed and unconditional consent provided by the Data Principal (or by the authorised parent, guardian or institutional authority in the case of minors).

(ii) Legitimate Uses under Section 7 of the DPDPA:?We may process personal data without consent only where such processing is expressly permitted as a ?legitimate use? under Section 7 of the DPDPA, to the extent applicable and notified.

(iii) Performance of a Service or Contract:?Processing required to deliver Brainberg?s assessments, reports, analytics, and Platform services to the data principal or to the institution/organization availing such services.

5.1.2 Certain obligations under Section 7 and other provisions of the DPDPA and DPDP Rules, 2025 may apply in phases and will be complied with by Brainberg as and when such provisions are notified and brought into legal effect.

5.2 Under GDPR (EU / EEA Users)

5.2.1 For users located in the European Union/ EEA, Brainberg processes personal data in accordance with the following lawful bases under the GDPR:

(i) Consent – Article 6(1)(a)?Explicit, informed consent for assessments, behavioural analysis and similar processing.

(ii) Contractual Necessity- Article 6(1)(b)?Processing necessary for providing Brainberg?s services and fulfilling contractual obligations.

(iii) Legitimate Interests- Article 6(1)(f)?Processing required for:?(a) Platform security and fraud detection;?(b) service improvement; and?(c) analytics (non-intrusive and privacy-preserving),?only where such interests do not override the rights and freedoms of the data subject.

(iv) Legal Obligations ? Article 6(1)(c)?Compliance with legal or regulatory requirements applicable to Brainberg.

5.2.2 Sensitive / Special Category Data (GDPR)?Sensitive or special category data (such as psychological, behavioural or cognitive information) is processed only under:?(i) explicit consent- Article 9(2)(a); and?(ii) with safeguards under Article 9, including purpose limitation, data minimisation, and appropriate security measures.

6.  How We Use the Information

6.1  Brainberg uses your personal information strictly for lawful, specific and clear purposes, as permitted under the DPDPA, the DPDP Rules, 2025, and, where applicable, the GDPR.

6.2 Your Information may be used for the following purposes:

(i) Provision of Services:?To provide, operate, deliver, personalise and maintain Brainberg?s assessments, reports, learning tools, behavioural insights, and related services.

(ii) Assessment Processing & Report Generation:?To process assessment responses, generate scores, insights and recommendations, and deliver personalised or institution-requested reports.

(iii) Communication & Notifications:?To contact you with service-related updates, alerts, administrative messages, recommendations, and necessary information relating to your use of the Platform. (You may unsubscribe from non-essential/promotional communications.)

(iv) Matching With Experts:?To assign, match or connect you with qualified Brainberg experts, assessors, counsellors, or support personnel, as required for service delivery.

(v) Billing & Transactions:?For invoicing, payment processing, confirmations, receipts, fraud prevention, and related transactional communication.

(vi) Platform Administration & Improvements:?To supervise, administer, audit, troubleshoot, analyse usage, enhance functionality, ensure service quality, and improve the overall user experience.

(vii) Analytics, Research & Product Development:?To conduct research, analytics, quality benchmarking, and product development strictly using anonymised or aggregated data that cannot identify any individual. We do not use your identifiable data for model training without explicit consent.

(viii) Safety, Security & Fraud Prevention:?To detect, prevent, or respond to security incidents, fraudulent activities, misuse of the Platform, or situations involving risk of harm, safety concerns, or unlawful activities.

(ix) Legal, Regulatory & Compliance Purposes:?To comply with applicable laws, regulations, court orders, government directions, reporting obligations (including DPBI reporting where applicable), and to establish or defend legal claims.

6.3 Brainberg does not sell, lease, trade, or rent personal data to any third party for marketing, advertising, or commercial gain.

7. User Responsibilities

7.1 As a user (?Data Principal?), you agree to the following responsibilities when accessing or using the Platform:

(i) Accuracy of Information:?You will provide accurate, complete and up-to-date information and promptly update the same whenever changes occur.

(ii) Authenticity of Data Provided:?You confirm that all information submitted belongs to you or that you are duly authorised to provide such information (including in the case of minors, dependents, or institutional uploads).

(iii) Account Security:?You will maintain the confidentiality of your account credentials, including passwords, access codes, OTPs, and login details, and will ensure that they are not shared with any unauthorised person.

(iv) Secure Device and Network Use:?You will access the Platform through secure devices and networks, maintain updated operating systems and security software, and avoid using public or unsecured networks for accessing sensitive information.

(v) Prohibited Access & Misuse Prevention:?You will not attempt unauthorised access, reverse engineering, scraping, tampering, or misuse of the Platform or its content, nor permit others to do so.

(vi) Compliance With Laws & Institutional Policies:?If you access Brainberg services through an organisation (school, employer, institution), you agree to comply with applicable institutional policies, data-use authorisations, and lawful instructions.

(vii) Notification of Unauthorised Use:?You agree to immediately notify Brainberg of any unauthorised access, breach, compromise, or suspected misuse of your account or personal information.

7.2 Consequences of Providing Incorrect or Misleading Information:?If you provide incorrect, incomplete, misleading, unauthorised, or outdated information, or if Brainberg has reasonable grounds to believe so, Brainberg may:?(i) restrict, suspend, or terminate your access to the Platform;?(ii) decline to provide or continue services; or?(iii) take any other action required to maintain platform integrity or comply with the law.

8. When We May Disclose Your Information

8.1 Brainberg may disclose your personal information only in the following limited and lawful circumstances, in accordance with the DPDPA, the DPDP Rules, 2025, and the GDPR (where applicable):

(i) With Your Explicit Consent:?When you voluntarily authorise Brainberg to share your information with a specific person, organisation, expert, or third party.

(ii) For Service Delivery:?To Brainberg?s authorised experts, assessors, psychologists, or support personnel strictly for the purpose of:?(a) processing assessments;?(b) generating reports;?(c) providing guidance, feedback or support; and?(d) enabling Platform functionality.?All such personnel are bound by confidentiality and data protection obligations.

(iii) With Third-Party Service Providers:?To carefully selected third-party processors who assist us with:?(a) cloud hosting and storage;?(b) data analytics;?(c) email/SMS communication;?(d) secure payment processing;?(e) customer support systems; and?(f) identity verification or consent management (where applicable).

These service providers:?(a) may process data only on Brainberg?s instructions;?(b) cannot use your data for their own purposes; and?(c) are contractually required to maintain high security and confidentiality standards.

(iv) With Schools, Institutions, or Employers (Where Applicable):

For assessments conducted through:

(a) educational institutions;

(b) employers;

(c) corporate learning programs; or

(d) training or evaluation initiatives;

Brainberg may share relevant assessment reports or outputs as authorised by the institution, in accordance with the consent obtained from the data principal or the authorised guardian.

(v) Data Sharing With Corporate Clients or Employers (Assessments and Psychometric Tests):

Where Brainberg conducts assessments, evaluations, or psychometric tests on behalf of corporate clients or prospective employers, the resulting data, scores, and reports may be shared with such third parties only with the explicit, informed consent of the individual Data Principal (or their authorised guardian, in the case of minors).

Brainberg does not share psychological, behavioural, assessment-related, or personally identifiable data with employers or third parties for recruitment, evaluation, or HR-related purposes without such explicit consent.

(v) Legal, Regulatory and Compliance Obligations:?We may disclose information:?(a) when required by law, regulation, subpoena, court order, or government directive;?(b) in response to a valid request from the Data Protection Board of India (DPBI) or other regulators;?(c) to comply with DPDP Rules in relation to breach notifications or legal reporting; or?(d) to establish or defend against legal claims.?Such disclosures are always limited to what is legally necessary.

(vi) To Prevent Harm or Ensure Safety:?Brainberg may disclose information where necessary to prevent or respond to:?(a) risk of harm or self-harm;?(b) abuse, exploitation, or neglect of a minor or vulnerable person;?(c) credible threats to others? safety; or?(d) situations involving illegal activities or urgent security risks.?Such disclosures are made strictly on a need-to-know basis and only to competent authorities.

(vii) Corporate Transfers (If Applicable):?In the event of:?(a) a merger, acquisition, or restructuring;?(b) a sale of business assets; or?(c) any other form of corporate transfer;?your information may be shared with the acquiring or merging entity, subject to:?(a) continuity of privacy safeguards; and?(b) obligations being no less protective than those in this Privacy Policy.

(viii) Minimal Disclosure Principle:?Brainberg always discloses only the minimum amount of personal data necessary for the specific lawful purpose (?data minimisation?). Brainberg does not sell, rent, or trade your personal information to third parties.

9. Cookies and Tracking Technologies

9.1 Brainberg uses cookies and similar tracking technologies to improve the functionality and performance of the Platform. Cookies are small data files stored on your device to recognise your browser, remember your preferences, and enhance your overall experience.

9.2 We use cookies and tracking technologies for the following purposes:

9.2.1 Essential/ Strictly Necessary Cookies:?(i) maintaining login sessions;?(ii) security and fraud prevention; and?(iii) loading pages and enabling navigation.?These cookies cannot be disabled because the Platform will not operate correctly without them.

9.2.2 Functional Cookies:?(i) remembering language settings;?(ii) storing saved preferences; and?(iii) enabling smoother navigation and user experience.

9.2.3 Performance & Analytics Cookies:?(i) understanding user behaviour on the Platform;?(ii) monitoring traffic patterns;?(iii) diagnosing technical issues; and?(iv) improving product design and performance.?Analytics may be conducted internally or through third-party analytics tools. All analytics data is processed in aggregated or anonymised form wherever feasible.

9.2.4 Advertising / Marketing Cookies (If Used)?

9.3 Brainberg does not conduct targeted advertising using personal data without explicit consent. If such cookies are used, they are:?(i) optional;?(ii) activated only with your affirmative consent; and?(iii) fully disclosed in the cookie banner.

9.4 User Choices & Cookie Management?

9.4.1 You may choose to:?(i) accept all cookies;?(ii) reject non-essential cookies; or?(iii) manage cookie preferences through your browser or device settings.

9.4.2 Disabling essential cookies may affect the functionality of the Platform, including login ability, loading speed, and certain interactive features.

9.5 Special Requirements for EU Users (GDPR & ePrivacy Directive)😕

9.5.1 For users located in the European Union/ EEA:?(i) we display a GDPR-compliant cookie banner with ?Accept?, ?Reject?, and ?Manage Preferences? options;?(ii) no non-essential cookies (analytics, functional, or marketing) are activated without explicit, granular, affirmative consent; (iii) consent can be withdrawn at any time through cookie settings; and?(iv) processing is based on Article 6(1)(a) for optional cookies and Article 6(1)(f) for essential security-related cookies.

9.6 Compliance With DPDPA:?

9.6.1 Under the DPDPA and DPDP Rules, 2025, cookies-especially those used for:?(i) personalised services;?(ii) analytics linked to an individual; or?(iii) marketing segmentation-?are treated as personal data when linked or linkable to a user.

9.6.2 Such cookies require:?(i) clear notice;?(ii) consent (unless essential); and?(iii) an easy mechanism to withdraw consent.

9.6.3 Brainberg follows these requirements and will update cookie practices as additional DPDP Rule notifications come into force.

10. Communications & Promotional Messages

10.1 Brainberg may communicate with you through various channels, including:?(i) email;?(ii) SMS or text messages;?(iii) phone calls;?(iv) in-platform notifications;?(v) mobile or web push notifications;?(vi) messaging services (such as WhatsApp or similar channels); and?(vii) communication systems integrated into the Platform.

10.2 Such communications fall under the following categories:

10.2.1 Service-Related Communications 

10.2.1.1 These are essential for providing the Platform and may include:?(i) account creation and verification;?(ii) password reset or security alerts;?(iii) assessment updates;?(iv) report availability;?(v) billing confirmations, invoices, and receipts;?(vi) administrative, operational, or compliance updates; and?(vii) policy changes or legal notifications.

10.2.1.2 These communications cannot be unsubscribed from, as they are required to deliver the services or comply with law.

10.2.2 Transactional Communications?

10.2.2.1 These include messages necessary for completing or confirming:?(i) payments;?(ii) assessment submissions;?(iii) enrolment into programs;?(iv) institutional reporting; and?(v) support interactions.

10.2.2.2 You cannot opt out of purely transactional communication.

10.2.3 Promotional/ Marketing Communications

10.2.3.1 With your consent, Brainberg may send communications relating to:?(i) new services;?(ii) offers or discounts;?(iii) updates about new assessments or features;?(iv) newsletters or educational content; and?(v) event or webinar invitations.

10.2.3.2 You may unsubscribe or withdraw consent for promotional communications at any time by:?(i) clicking the ?unsubscribe? link in the email;?(ii) changing your communication preferences in your account settings; or?(iii) contacting us as specified in this Privacy Policy.

10.2.3.3 Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.

10.2.4 Institutional or Organisational Communications?

10.2.4.1 If you access Brainberg through an organisation (school, employer, institution):?(i) Brainberg may be required to send communications authorised by that institution;?(ii) some communications may be governed by institutional consent obtained for assessments; and?(iii) withdrawal of consent for promotional content remains available.

10.2.5 Safety, Security & Legal Communications?

10.2.5.1 Brainberg may contact you without consent when necessary to:?(i) notify you of a data breach;?(ii) warn of safety risks (self-harm, harm to others, abuse cases, as legally required);?(iii) respond to legal or regulatory obligations, including DPBI-related notices;?(iv) comply with court orders or law enforcement mandates; or?(v) resolve disputes or enforce the Terms & Conditions.

10.2.5.2 These communications cannot be opted out of.

10.2.6 Compliance With Applicable Laws?

10.2.6.1 DPDPA & DPDP Rules, 2025:?(i) promotional messages require freely given, informed consent;?(ii) consent withdrawal must be simple and effective; and?(iii) the DPBI may enforce penalties for unsolicited messages that violate consent norms.

10.2.6.2 Telecom/Anti-Spam Rules (India): Communications comply with TRAI/DoT guidelines on commercial messages, including DLT regulations for SMS.

10.2.6.3 GDPR (Where Applicable):?(i) promotional communications are sent only on the basis of explicit consent-Article 6(1)(a);?(ii) service/administrative messages rely on contractual necessity- Article 6(1)(b); and?(iii) users have the right to object to marketing at any time – Article 21(2).

11. Social Media Widgets

11.1 Our Platform may include social media features or widgets provided by third parties, such as:?(i) Facebook ?Like? or ?Share? buttons;?(ii) Twitter/X ?Tweet? or ?Share? buttons;?(iii) LinkedIn ?Share? or ?Recommend? widgets;?(iv) YouTube embedded videos;?(v) Instagram embeds; and?(vi) any similar plug-ins, widgets, or interactive mini-programs.

11.2 These features may automatically collect certain information about you, including:?(i) your IP address;?(ii) the specific page(s) you visit on the Platform;?(iii) device/browser information;?(iv) cookie or tracking data placed by the third-party platform; and?(v) interaction data (for example, whether you clicked, liked, shared, or played a video).

11.3 Such widgets may set their own cookies, independent of Brainberg?s systems, and may track your browsing behaviour across other websites that use similar plug-ins.

11.4 Third-Party Privacy Practices Apply?

11.4.1 Your interaction with these features is governed solely by:?(i) the respective third party?s privacy policy;?(ii) their terms of service; and?(iii) their data collection practices.

11.4.2 Brainberg does not control, monitor, or influence:?(i) what data these platforms collect;?(ii) how they use or share that data;?(iii) whether they combine it with your existing social media profile; or?(iv) whether they conduct interest-based profiling or advertising.

11.4.3 You are encouraged to review the privacy policies of the relevant social media platforms before interacting with such features.

11.5 No Responsibility for Third-Party Data Handling?

11.5.1 Brainberg is not responsible or liable for:?(i) the accuracy, practices, or policies of third-party widgets;?(ii) any cookies or tracking technologies they deploy;?(iii) any cross-site tracking or profiling performed by them; or?(iv) any harm or misuse resulting from third-party use of your data.

11.5.2 These services operate outside Brainberg?s control and may collect personal data even if you do not actively interact with the widget, depending on their own technology.

11.6 GDPR & EU User Notice?

11.6.1 For users located in the European Union/ EEA:?(i) third-party widgets may process your personal data as independent data controllers, not as processors of Brainberg;?(ii) some widgets may perform cross-border transfers outside the EU;?(iii) consent for non-essential cookies placed by such widgets is obtained through the GDPR-compliant cookie banner; and?(iv) you may withdraw consent at any time.

11.6.2 GDPR Articles 6, 7, 13, 14, and 26 may apply to such processing.

11.7 DPDP Act Compliance (India)?

11.7.1 Under the DPDPA and DPDP Rules, 2025:?(i) any data collected by a third-party widget is processed under the third party?s legal basis, not Brainberg?s; (ii) Brainberg does not share your personal data with social media platforms unless you explicitly choose to interact with the widget (for example, sharing an assessment result); and?(iii) you may withdraw your consent for cookie-based tracking using our cookie settings.

11.8 Optional Interaction?

11.8.1 Use of these widgets is completely optional. You may avoid interaction by:?(i) not clicking on the widgets;?(ii) blocking third-party cookies in your browser; and?(iii) using privacy settings or plug-ins that control social media tracking.

12. Payment Security

12.1 Brainberg takes payment security extremely seriously. When you make payments on the Platform, the following safeguards apply:

12.2 Secure Payment Processing?12.2.1 We ensure that:?(i) all card and banking details are encrypted using industry-standard encryption protocols (such as TLS/SSL) during transmission;?(ii) all transactions are processed through authorised, RBI-compliant, PCI-DSS certified payment gateways;?(iii) payment gateways may tokenise your card information in accordance with RBI Card-on-File Tokenisation Guidelines; and?(iv) Brainberg does not receive or store your full card number, CVV, PIN, or net banking credentials at any time.

12.3 Limited Use of Payment Information?12.3.1 Payment information is used strictly for:?(i) completing the transaction;?(ii) fraud prevention;?(iii) chargeback and dispute management;?(iv) invoicing and billing; and?(v) compliance with applicable laws and financial regulations.

12.3.2 Brainberg shares payment data only with:?(i) authorised payment processors;?(ii) banks, card networks, or financial institutions; and?(iii) fraud detection and risk management partners (where applicable),?and strictly on a need-to-know, transactional basis.

12.4 No Storage of Sensitive Financial Data?

12.4.1 Brainberg does not:?(i) store full card numbers;?(ii) store CVV codes;?(iii) store net banking login details;?(iv) have access to your wallet or UPI PIN; or?(v) store passwords or authentication credentials.

12.4.2 Any payment-related information stored (for example, metadata, masked details, transaction IDs) is minimal, necessary, and cannot be used to initiate a transaction.

12.5 Compliance With Applicable Laws?12.5.1 Payment processing complies with:?(i) the DPDPA and DPDP Rules, 2025 (data protection);?(ii) the IT Act, 2000 ? Section 43A (security practices);?(iii) RBI guidelines on digital payments;?(iv) PCI-DSS (Payment Card Industry Data Security Standard); (v) GDPR Articles 5, 6, and 32 (where applicable); and?(vi) CERT-In security reporting requirements.

12.5.2 Third-party payment processors serve as independent data controllers and/or processors for financial information as per their own privacy policies.

12.6 Fraud Detection & Security Monitoring?

12.6.1 To ensure transaction safety, we may use:?(i) device fingerprinting;?(ii) anomaly detection;?(iii) transaction monitoring; and?(iv) secure OTP/2FA verification (mandated by RBI).

12.6.2 These activities protect you from unauthorised transactions and fraud.

13. No Liability for Device-Level Data Theft

13.1 While Brainberg implements robust technical and organisational security measures to safeguard your information, Brainberg is not responsible or liable for any loss, compromise, or theft of data arising from issues on your personal device or network that are outside Brainberg?s control, including but not limited to:?(i) malware, spyware, viruses, ransomware, keyloggers, or malicious applications installed on your device;?(ii) unauthorised access caused by insecure Wi-Fi networks, shared devices, outdated software, or weak passwords;?(iii) compromise of your device?s operating system or browser due to lack of security patches;?(iv) theft or loss of your device;?(v) misuse of your account resulting from your failure to protect credentials, OTPs, or authentication factors; or?(vi) interception of data caused by your use of public, untrusted, or unsecured networks.

13.2 Brainberg does not and cannot control the security environment of your personal device, browser, or network.

13.3 User Responsibilities for Device Security:?

13.3.1 To protect your information and ensure a secure experience, you are strongly advised to:?(i) install and maintain reputable security and anti-malware software;?(ii) regularly update your device?s operating system, browser, and applications;?(iii) use strong, unique passwords and enable multi-factor authentication where possible;?(iv) avoid accessing the Platform through public or unsecured Wi-Fi networks;?(v) routinely review device permissions and remove suspicious apps; and?(vi) log out after each session on shared or public devices.

13.3.2 Failure to follow these precautions can significantly increase your risk of data compromise.

13.4 Legal Considerations?

13.4.1 Under the DPDPA, 2023, liability applies only where the data fiduciary fails to implement ?reasonable security safeguards?. Brainberg?s liability does not extend to vulnerabilities arising from your personal device, software, or network.?

13.4.2 Under IT Act Section 43A, Brainberg is not liable for damages resulting from breaches caused by user-side negligence.?

13.4.3 Under GDPR, Brainberg is not responsible for device-level security failures caused by the user or third-party environments not under its control.

14. Confidentiality & Security Measures

14.1 Brainberg implements appropriate technical, organisational, and administrative safeguards to protect your personal data from unauthorised access, use, alteration, disclosure, or destruction. Our security framework includes, without limitation:

14.2 Technical Safeguards:?(i) industry-standard encryption (in transit and, where applicable, at rest); (ii) secure socket layer (SSL/TLS) protocols for data transmission;?(iii) firewalls, intrusion detection and prevention systems (IDS/IPS);?(iv) role-based access control (RBAC) ensuring only authorised personnel can access specific data;?(v) multi-factor authentication (MFA) for internal systems (where applicable);?(vi) secure, encrypted backups and disaster recovery measures;?(vii) regular vulnerability scanning and patch management; and?(viii) secure development and deployment practices.

14.3 No Brainberg employee or administrator has access to your plain-text password; all passwords are stored using irreversible cryptographic hashing.

14.4 We further implement:?(i) internal confidentiality and non-disclosure agreements with employees, experts, assessors, and contractors;?(ii) strict need-to-know access limitation for sensitive and special-category data;?(iii) staff training on data protection, security, and privacy compliance;?(iv) defined incident response and breach-handling procedures;?(v) vendor due diligence for third-party processors and service providers; and?(vi) access logging and regular security reviews.

14.5 Brainberg?s security measures comply with applicable statutory and regulatory requirements, including:?(i) DPDPA and DPDP Rules, 2025 (reasonable security safeguards and breach reporting to DPBI);?(ii) Section 43A of the IT Act, 2000 (compensation for failure to protect personal data);?(iii) CERT-In Directions, 2022 (log retention, incident reporting, time synchronisation, and related requirements);?(iv) alignment with ISO/IEC 27001 information security principles, including risk assessment, access control and information security governance; and?(v) GDPR Article 32 (where applicable), relating to security of processing.

14.6 While Brainberg implements strong security measures, no method of transmission over the internet or electronic storage is completely secure. We continuously update and enhance our security posture to meet evolving threats and regulatory standards.

15. Third-Party Contractors & Independent Tool Providers

15.1 Brainberg uses carefully selected third-party service providers (?processors?) and independent tool providers to support the delivery, improvement, and security of the Platform. These may include:?(i) cloud hosting and storage providers;?(ii) email/SMS communication platforms;?(iii) analytics and performance monitoring tools;?(iv) secure payment processors;?(v) customer support tools;?(vi) identity verification or consent management platforms; and?(vii) IT infrastructure and cybersecurity providers.

15.2 These third parties may process personal data strictly for the purposes of providing services to Brainberg.

15.3 Processors Acting on Brainberg?s Instructions?15.3.1 Where third-party contractors act as ?processors?, Brainberg ensures that they:?(i) comply with minimum data protection and security standards mandated under the DPDPA and the DPDP Rules, 2025;?(ii) are contractually bound to strict confidentiality obligations;?(iii) process personal data only on Brainberg?s documented instructions;?(iv) access only the minimum data necessary for providing their service (the ?least privilege? principle);?(v) implement adequate technical and organisational safeguards (including encryption, access control, and audits);?(vi) do not use the data for their own purposes, profiling, or advertising; and?(vii) are subject to vendor due diligence and ongoing monitoring by Brainberg.

15.3.2 Under GDPR (where applicable), such processors are bound by Article 28-compliant data processing agreements (DPAs).

15.4 Independent Controllers / Tool Providers?

15.4.1 Certain third-party tools (for example, social media widgets, external analytics providers, embedded content, and payment gateways) may act as independent data controllers under their own privacy policies.

15.4.2 In such cases:?(i) these entities determine their own purposes and means of processing;?(ii) Brainberg does not control how these third parties collect, use, or share data outside the Platform; and?(iii) your interaction with such tools is governed exclusively by the third party?s terms and privacy policy.

15.4.3 Brainberg does not share personal data with such independent controllers unless you actively engage with their functionality.

15.5 Sub-Processors: Where a third-party processor engages sub-processors:?(i) they must obtain Brainberg?s authorisation;?(ii) sub-processors must implement equivalent security and privacy safeguards;?(iii) sub-processor access is limited to the minimum necessary; and?(iv) their obligations must be at least as protective as those in Brainberg?s agreements.

15.6 Cross-Border Transfers by Processors?

15.6.1 If personal data is transferred outside India or the EU by such processors or sub-processors, they must:?(i) comply with applicable DPDP cross-border processing rules (as notified and in force);?(ii) implement Standard Contractual Clauses (SCCs) or equivalent safeguards for GDPR-covered data; and?(iii) ensure that downstream transfers maintain protections no less stringent than those applied by Brainberg.

15.7 No Excessive Disclosure?

15.7.1 Brainberg shares only the minimum amount of information necessary and never sells or rents your personal data to third parties.

16. International Data Transfers

16.1 Brainberg may process or store your personal data in:?(i) India; and?(ii) other jurisdictions where our trusted service providers, cloud hosting partners, or processors operate,?subject to applicable legal requirements and adequate safeguards.

16.2 Transfers Under the DPDPA (India)?

16.2.1 Cross-border transfers of personal data are permitted subject to the provisions notified by the Government under the DPDPA and DPDP Rules, 2025, including:?(i) government-notified whitelisted countries;?(ii) restrictions (if any) imposed on specific jurisdictions;?(iii) any conditions or contractual safeguards required under the Rules; and?(iv) ensuring the receiving country maintains a comparable level of personal data protection.

16.2.2 Brainberg will comply with all cross-border transfer requirements as they come into force during the Government?s phased implementation schedule.

16.3 Transfers of Data for EU/EEA Residents (GDPR Compliance)?

16.3.1 For individuals located in the European Union/ EEA, Brainberg transfers personal data outside the EU only in accordance with Chapter V of the GDPR, which may include:?(i) Adequacy Decisions: Transfers to countries that the European Commission has determined provide an adequate level of protection.?(ii) Standard Contractual Clauses (SCCs): Where no adequacy decision exists, Brainberg uses European Commission?approved SCCs with service providers and partners to ensure protection equivalent to EU standards.?(iii) Additional Safeguards (Schrems II Compliance): Including, where required:?(a) encryption (in transit and at rest);?(b) pseudonymisation or segmentation of identifiers;?(c) access controls ensuring only authorised recipients can access data; and?(d) contractual prohibitions on unlawful government access.?(iv) Explicit Consent – Article 49: In rare cases, if no other mechanism applies, transfers may occur only with your explicit, informed consent.

16.4 Transfers by Processors & Sub-Processors?

16.4.1 Where Brainberg?s processors or sub-processors transfer data internationally, they must:?(i) comply with applicable DPDP rules;?(ii) implement SCCs or equivalent safeguards for GDPR-covered data;?(iii) not transfer data further without Brainberg?s authorisation; and?(iv) ensure all downstream transfers provide a level of protection no less stringent than that afforded under applicable law.

16.5 No Excessive or Unauthorised Transfers?

16.5.1 Brainberg does not transfer personal data internationally unless:?(i) the transfer is necessary for service delivery;?(ii) the transfer is legally permitted and adequately safeguarded; and?(iii) the receiving country/entity ensures protection equivalent to the originating jurisdiction.

16.5.2 Brainberg never sells or rents personal data to any overseas entity.

17. Your Rights

17.1 Brainberg respects your rights as a Data Principal (under the DPDPA) and as a Data Subject (under the GDPR, where applicable). You may exercise these rights by submitting a verified request using the contact details provided in this Privacy Policy.

17.2 Under the DPDPA, you have the following rights:

(i) Right to Access:?You may request details about:?(a) the personal data we have processed;?(b) the processing activities undertaken; and?(c) the identities or categories of data processors with whom your data has been shared.

(ii) Right to Correction & Updating:?You may request correction, completion, or updating of any inaccurate or incomplete personal data.

(iii) Right to Withdrawal of Consent:?You may withdraw your consent at any time. Withdrawal will not affect:?(a) processing already completed prior to withdrawal; or?(b) processing permitted under legitimate uses (Section 7 of the DPDPA).

(iv) Right to Erasure:?You may request erasure of your personal data, subject to:?(a) legal or regulatory retention requirements;?(b) institutional retention requirements for assessments; and (c) audit, fraud prevention, or dispute-resolution needs.

(v) Right to Grievance Redressal:?You may raise a grievance with Brainberg?s Grievance Officer. If unsatisfied, you may escalate to the Data Protection Board of India (DPBI) once constituted and operational.

(vi) Right to Nominate:?You may nominate another individual to exercise your rights in the event of your:?(a) death; or?(b) incapacity.

(vii) Authentication Requirement:?Brainberg may require reasonable verification before processing any rights requests to protect your data from unauthorised access.

17.3 Rights Under the GDPR

  For individuals located in the European Union/ EEA, GDPR grants the following rights:

(i) Right of Access – Article 15:?To know what data is processed and obtain a copy.

(ii) Right to Rectification – Article 16:?To correct inaccurate or incomplete data.

(iii) Right to Erasure (?Right to be Forgotten?) – Article 17?Subject to legal or contractual retention obligations.

(iv) Right to Restrict Processing – Article 18?When accuracy is contested, processing is unlawful, or data is no longer needed.

(v) Right to Data Portability – Article 20?To receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.

(vi) Right to Object – Article 21?You may object to processing based on legitimate interests, including profiling, and object unconditionally to direct marketing.

(vii) Rights Related to Automated Decision-Making – Article 22?Including the right not to be subject to decisions based solely on automated processing that significantly affects you.

(viii) Right to Withdraw Consent – Article 7(3)?You may withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal.

(ix) Right to Lodge a Complaint – Article 77?You may lodge a complaint with your national or regional supervisory authority (Data Protection Authority) in the EU/EEA.

17.4 Timelines & Conditions for Processing Requests

  All rights requests will be processed:?(i) within the statutory timelines prescribed under the DPDP Rules, 2025; and?(ii) within the timelines prescribed under the GDPR (generally within one month, extendable as permitted by law).

17.5 Requests may be declined or delayed where permitted by law, including where:?(i) legal retention requirements apply;?(ii) there are active disputes, fraud investigations, or regulatory obligations; or?(iii) disclosure would infringe another person?s rights.

17.6 Brainberg may request additional information to verify your identity before acting on any rights request.

18. Data Retention

18.1 Brainberg retains personal data only for as long as necessary to fulfil the purposes for which it was collected, including:?(i) providing services, assessments, reports, analytics, support, and related operational functions;?(ii) compliance with legal, regulatory, and statutory obligations, including DPDPA, DPDP Rules 2025, IT Act requirements, and CERT-In Directions (for example, mandatory log retention);?(iii) audit, accounting, fraud detection, or dispute resolution, including defending against legal claims; and?(iv) institutional requirements (schools, employers, training partners), where retention is part of the engagement or compliance obligations.

18.2 Erasure:?Personal data will be erased or anonymised when:?(i) the purpose of processing is fulfilled;?(ii) you withdraw consent (unless retention is legally permitted or required); or?(iii) no legal or legitimate basis remains for retention.

18.3 Anonymised or Aggregated Data:?Brainberg may retain anonymised, aggregated, or de-identified data for:?(i) research;?(ii) statistical analysis;?(iii) product improvement; and?(iv) long-term trends or insights.?Such data cannot identify any individual and may be retained indefinitely.

19. Grievance Officer / Data Protection Officer (DPO)

19.1 In compliance with the DPDPA, DPDP Rules 2025, GDPR, and other applicable laws, Brainberg designates the following Data Protection Officer / Grievance Officer:

Brainberg Knowledge Solutions Private Limited?

Data Protection Officer / Grievance Officer?

Address: ___________________________________

Email: ____________________________________?

Phone: ____________________________________

19.2 Responsibilities:?The DPO/ Grievance Officer is responsible for:?(i) receiving and responding to user grievances;?(ii) addressing rights requests (access, correction, erasure, consent withdrawal, nomination); (iii) coordinating breach notifications;?(iv) ensuring DPDPA and GDPR compliance; and?(v) acting as the point of contact for regulatory authorities (including DPBI and supervisory authorities).

19.3 Timelines:?All grievances and rights requests will be addressed within statutory timelines, including: (i) DPDP Rules 2025: typically within such periods as may be prescribed for grievance response and rights processing; and?(ii) GDPR: generally within one month (extendable where legally permitted).

19.4 If you are not satisfied with the resolution under the DPDPA, you may escalate to the Data Protection Board of India (DPBI) once operational.

20. Changes to This Privacy Policy

20.1 Brainberg may update or modify this Privacy Policy from time to time to reflect:?(i) changes in legal or regulatory requirements;?(ii) updates to the Platform or services;?(iii) changes to data processing practices;?(iv) security enhancements; or?(v) operational needs.

20.2 Notification of Changes:?If material changes are made:?(i) a notice will be displayed on the Platform; and/or?(ii) you will be notified by email or other appropriate means (where legally required); and/or?(iii) the updated policy will be made accessible at all times on our website and Platform.

20.3 Consent for Material Changes:?Brainberg will:?(i) not process your existing personal data for any new or incompatible purpose without providing notice; and?(ii) obtain fresh consent where required by law, including under the DPDPA and GDPR.

20.4 Continued Use:?Your continued use of the Platform after such changes constitutes your acknowledgment and acceptance of the updated Privacy Policy.