Institutional Scope, Legal Identity & Data Fiduciary
This Privacy, Data Protection, and Telemetry Security Policy (hereinafter referred to as the "Privacy Policy") governs the collection, storage, encryption, and processing of personal data collected through academy.meeways.in, associated subdomains, student portal learning applications, and our official WhatsApp communication interfaces.
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000, the primary Data Fiduciary responsible for your personal information is Meeways 360° Creative Agency / Meeways 360° Private Limited, operating Academy 2.O from our production studio hub in Delhi NCR, India.
Categories of Information We Collect
We collect only the minimum necessary information required to facilitate educational onboarding, deliver curriculum assets, provide live technical mentoring, and satisfy statutory accounting obligations:
2.1 Student Registration & Contact Records
- Full Name: Required for official cohort roster generation, batch assignment, and issuing verifiable graduation credentials.
- WhatsApp Mobile Number: Utilized for instant automated dispatch of the 12-Week Syllabus PDF, live mentorship link notifications, and cohort announcements.
- Email Address: Utilized for sending formal Razorpay payment receipts, account credentials, and academic evaluation feedback.
- Educational & Professional Background: Optional career context to assist directors in tailoring individualized mentorship feedback.
2.2 Technical & Device Identifiers
When accessing our web portals or LMS video repositories, our servers automatically log technical metadata including your browser user-agent, operating system, IP address, screen resolution, and coarse geographical city-level location to prevent unauthorized multi-device account sharing.
Razorpay Payment Gateway & Financial Telemetry
Academy 2.O upholds strict zero-storage policies regarding sensitive banking credentials:
All financial checkout transactions are processed directly through Razorpay Software Private Limited, an RBI-authorized Payment Aggregator certified under PCI-DSS Level 1 (the highest international security standard).
- Academy 2.O NEVER collects, views, or stores complete debit card numbers, credit card numbers, expiration dates, or CVV/PIN codes.
- Our database only receives non-sensitive confirmation tokens (such as Razorpay Order ID
order_xxxxxxand Payment IDpay_xxxxxx) along with payment status timestamps.
LMS Video Telemetry, Session Playback & Attendance Logs
To enforce academic integrity and substantiate eligibility under our Action-Based Guarantee, our video delivery infrastructure logs student engagement telemetry:
- Watch-Time Telemetry: Precise second-by-second playback completion counters for each module lecture.
- Playback Rate & Skipping Indicators: Automated event logging tracking if video scrub controls were utilized or if playback rate exceeded approved pedagogical speeds.
- Live Session Attendance: Attendance records logged during live Zoom/Google Meet studio sessions to record participation.
Purpose & Legal Basis of Data Processing
We process your personal information under lawful grounds recognized under Section 4 and Section 6 of the Digital Personal Data Protection Act, 2023:
- Performance of Educational Contract: Delivering the video curriculum, grading project assignments, providing mentor feedback, and issuing certificates.
- Operational Communications: Transmitting essential cohort scheduling alerts, syllabus PDFs, and billing receipts via WhatsApp and email.
- Security & Fraud Prevention: Validating single-user license compliance and preventing unauthorized credential distribution.
- Statutory Tax Compliance: Maintaining GST accounting invoices and audit ledgers mandated by Indian taxation authorities.
Our Strict Zero-Data-Selling Guarantee
Academy 2.O and Meeways 360° Creative Agency maintain an absolute, non-negotiable policy: We do NOT sell, rent, monetize, trade, or distribute student contact lists, email directories, or personal profile data to third-party telemarketers, lead brokers, external ad networks, or spam agencies.
Your phone number and email address are used exclusively for your educational lifecycle at Academy 2.O and direct communications from our admissions and mentorship desks.
Cookies, Web Beacons & Influencer Attribution Tracking
Our web applications employ minimal, secure HTTP cookies and local storage tokens designed to optimize user experience:
- Essential Session Cookies: Required to maintain student login states, preserve registration modal inputs, and prevent cross-site request forgery (CSRF).
- Creator & Affiliate Attribution Cookies: When a prospective student accesses our website via an influencer scholarship link (e.g.
?coupon=AHSAN20), a lightweight tracking token (academy_2o_affiliate_partner) is stored locally in your browser for a maximum duration of 30 days. This ensures that your ₹500 fee discount is automatically honored during checkout. - Anonymous Performance Analytics: Aggregated, non-personally identifiable pageview metrics to measure website load latency and server health.
Cloud Infrastructure, Encryption & Cybersecurity Safeguards
We implement defense-in-depth technical safeguards to protect student data against unauthorized access, loss, or alteration:
- Transport Layer Security: All client-to-server traffic is enforced via 256-bit SSL/TLS encryption with modern cipher suites and HSTS preloading.
- Encryption at Rest: Database storage volumes and learner backups are encrypted using AES-256 standard encryption keys.
- Role-Based Access Control (RBAC): Student records are accessible exclusively by authorized admissions and technical directors who have executed formal Non-Disclosure Agreements (NDAs).
- Server Architecture: Hosted on ISO 27001 and SOC 2 Type II certified cloud infrastructure equipped with real-time DDoS mitigation and web application firewalls.
Data Retention Periods & Permanent Profile Purging
We retain personal data only for the duration necessary to fulfill the educational purposes for which it was gathered:
- Active Student Profiles: Retained for the duration of the course cohort plus 12 months thereafter to facilitate verifiable certificate validation.
- Financial Tax Invoices: Retained for 7 fiscal years in accordance with Section 44AA of the Indian Income Tax Act, 1961.
- Purging Mechanism: Following the statutory retention period, digital student records are cryptographically overwritten and permanently destroyed from our production storage.
Student Statutory Rights (DPDPA 2023 & Global Rights)
As a student data principal, you hold affirmative rights under the Digital Personal Data Protection Act, 2023:
Right to Access & Summary
You may request an electronic summary of all personal information and telemetry records associated with your student ID.
Right to Rectification
You may request immediate correction of any inaccurate or outdated phone numbers, email addresses, or name spellings.
Right to Erasure & Withdrawal
You may request the deletion of your personal records, subject to our statutory duty to retain tax and financial accounting ledgers.
To exercise any of these rights, transmit a verified request to privacy@meeways.in from the registered email address used during enrollment.
Minor & Guardian Safeguards
Our curriculum is designed for vocational students, college learners, and career professionals. While learners under the age of 18 are eligible to participate in Academy 2.O cohorts, enrollment must be conducted with the explicit authorization and knowledge of a parent or legal guardian.
If we discover that personal data of a minor has been gathered without parental consent, we will promptly take steps to obtain verifiable guardian consent or delete the profile accordingly.
Designated Grievance Officer & Statutory Contact Desk
In accordance with Rule 5(9) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 19 of the DPDPA 2023, the details of our designated Grievance Officer are set forth below: