eLearningCurve

Empowering Minds, Anywhere, Anytime

WhatsApp

+91 77750 32347

Call Us

+91 90750 24452

Data Protection Commitment
eLearningCurve implements enterprise-grade security measures compliant with:
  • GDPR (Indian General Data Protection Regulation)
  • FERPA (Family Educational Rights and Privacy Act)
  • COPPA (Children’s Online Privacy Protection Act)
  • ISO 27001 information security standards
Data Collection & Processing
Types of Data Collected:
  • Personal Data: Name, email, payment info, academic records
  • Learning Data: Course progress, assessment scores, engagement metrics
  • Technical Data: IP addresses, device info, browser fingerprints
Lawful Bases for Processing:
  • Contractual necessity (course delivery)
  • Legitimate interest (service improvement)
  • Explicit consent (marketing communications)
Security Safeguards
Technical Measures:
  • Encryption: AES-256 for data at rest, TLS 1.3+ for data in transit
  • Access Controls: Role-based permissions with MFA enforcement
  • Network Security: Next-gen firewalls, IDS/IPS, DDoS protection
  • Vulnerability Management: Quarterly penetration testing
Operational Measures:
  • Employee Training: Annual security awareness programs
  • Data Minimization: Collect only essential information
  • Breach Protocol: 72-hour notification policy for incidents
Third-Party Data Sharing
We share data only with:
  • Payment Processors (PCI-DSS compliant providers)
  • Analytics Providers (Pseudonymized data only)
  • Cloud Hosting Partners (AWS/GCP with BAA agreements)
Data Retention & Disposal
  • Active Users: Data retained for 5 years post last activity
  • Inactive Accounts: Anonymized after 2 years
  • Secure Deletion: NIST SP 800-88 compliant wiping
User Rights & Controls
Users may:
  • Access/export their data via self-service portal
  • Request correction/deletion of inaccurate information
  • Opt-out of data processing (excluding essential services)
  • Withdraw consent for marketing communications
Incident Response
Our security team:
  • Maintains 24/7 SOC monitoring
  • Follows NIST CSF framework for incident handling
  • Provides breach notifications via multiple channels
Compliance & Audits
  • Annual third-party security audits
  • Continuous compliance monitoring
  • Public-facing transparency reports
Policy Updates
  • Reviewed quarterly
  • Major changes communicated 30 days in advance
  • Version-controlled documentation