In plain English
- We are the Data Fiduciary; you are the Data Principal, and these are your rights, written out in full.
- We never sell your data and never use health information for advertising.
- Marketing consent is separate. Refusing it never affects your plan or price.
- You can access, correct, erase, nominate and withdraw consent — and we respond to requests within the timelines the DPDP Act prescribes.
- If something goes wrong, we notify the Board and every affected person as the law requires.
- Write to hello@chandrayog.com for any data request or grievance.
Who we are and our role
ChandraYog Online Yoga Studio (“ChandraYog”, “we”, “us”) runs live online yoga classes at chandrayog.com. For the purposes of India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it, ChandraYog is the Data Fiduciary: we decide why and how your personal data is processed. You are the Data Principal.
This policy explains what personal data we collect, the purposes we collect it for, how we protect it, how long we keep it, and the rights you can exercise over it. It applies to this website, to our live classes, to your enrolment and payments, and to any support you receive from our team.
Our promise in one line
We collect the least we can, use it only for the purposes we have told you about, never sell it, and delete it when it is no longer needed.
Definitions we use in this policy
- Personal data
- Any data about an individual who is identifiable by or in relation to that data — for example your name, email address, phone number, or a health note that identifies you.
- Data Principal
- You — the individual to whom the personal data relates.
- Data Fiduciary
- Us — the entity that determines the purpose and means of processing your personal data.
- Data Processor
- A third party that processes personal data on our behalf, under a valid written contract, and only on our instructions.
- Processing
- Anything we do with personal data — collecting it, storing it, using it, sharing it, or deleting it.
- Consent
- Your free, specific, informed, unconditional and unambiguous agreement, given by a clear affirmative action, to the processing of your personal data for a specified purpose.
- Consent Manager
- A person registered with the Data Protection Board of India who can enable you to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.
- Board
- The Data Protection Board of India, established under the DPDP Act, 2023.
What personal data we collect
We collect only what your practice actually needs. Depending on how you interact with us, that may include:
| Category | Examples | Do we collect it? |
|---|---|---|
| Identity & contact | Name, email address, phone number, city, age or date of birth | Yes — on enrolment and enquiry |
| Enrolment & plan | Plan chosen, batch, start and end dates, pause history, attendance | Yes — to deliver your plan |
| Payment records | Transaction reference, amount, status, invoice details | Yes — but never your full card number, CVV or banking password |
| Health & screening data | PAR-Q answers, conditions disclosed, injuries, pregnancy stage, medication categories, medical clearance notes | Yes — only where you provide it, and only for safe placement |
| Communications | Emails, chat messages, and notes from support conversations | Yes — when you contact us |
| Technical & usage | Device type, browser, approximate location derived from IP, pages viewed, session metadata | Yes — limited, via server logs and analytics |
| Class media | Your display name and, where your camera is on, your live image during a session | Live only; recorded excerpts only with your consent |
| Dietary preferences | Food preferences or restrictions you share for a nutrition plan | Only where your plan includes nutrition guidance |
We ask that you do not send us sensitive data we have not asked for — for example detailed medical reports, prescriptions or test results that are not part of the screening or clearance process.
Why we process your data, and our lawful basis
Under the DPDP Act we may process personal data only for a lawful purpose, either on the basis of your consent or for a permitted legitimate use. We do not process your data for any purpose you have not been told about.
| Purpose | Data used | Basis |
|---|---|---|
| Confirming your enrolment and allocating you to a batch | Identity & contact, enrolment & plan, screening outcome | Consent; performance of our agreement with you |
| Placing you safely — reviewing screening answers and adapting practice | Health & screening data | Your explicit consent (you may withdraw it, but we will not be able to continue a therapeutic or prenatal plan without it) |
| Delivering live classes and sharing batch links | Identity & contact, enrolment & plan | Consent; performance of our agreement |
| Processing payments, invoicing and tax compliance | Payment records, identity & contact | Consent; compliance with law |
| Support, complaints and grievance redressal | Communications, enrolment & plan | Consent; compliance with law |
| Service emails — batch reminders, schedule changes, policy updates | Identity & contact | Consent |
| Improving our classes, website and safety practice | Technical & usage, aggregated and de-identified insights | Legitimate use (internal, non-identifying analysis) |
| Marketing and offers about new batches or plans | Identity & contact | Separate, optional consent — you may decline and still enrol |
| Preventing fraud, abuse or chargebacks; securing our systems | Technical & usage, payment records | Legitimate use (safety and security) |
We never sell your personal data. Marketing consent is never bundled with enrolment: refusing it does not affect your plan, your batch, or the price you pay.
How we take your consent — and how you withdraw it
Before or at the time we collect your personal data, we give you a notice that states the personal data we want, the purpose we want it for, how to exercise your rights, how to complain to the Board, and how to reach the person who answers your requests. Consent is taken through a clear affirmative action — a tick, a click, or a signed declaration. We do not use pre-ticked boxes or implied consent.
| Consent | Required? | If you decline |
|---|---|---|
| Enrolment and delivery of your plan | Yes | We cannot provide the classes you are buying |
| Health screening and sharing your screening summary with your trainer | Yes, for Therapeutic and Prenatal plans | A therapeutic or prenatal place cannot be confirmed. General Yoga may still be possible with a self-declaration. |
| Marketing emails about offers and new batches | No | You simply do not receive them. Nothing else changes. |
| Use of your image in promotional material | No | Your camera image is never used in our promotions. |
Withdrawing consent
- You may withdraw any consent at any time by writing to hello@chandrayog.com or by using the unsubscribe or preference link in our emails. Withdrawing is as easy as giving consent.
- On withdrawal, we stop processing for that purpose and delete the data concerned, unless we are required by law to keep it.
- Withdrawing consent for the data we need to run your plan ends the plan; the unused portion is handled under the Refund & Cancellation Policy.
- You may also give, manage, review and withdraw consent through a Consent Manager registered with the Board, once that facility is available to us.
Health and screening data — handled with extra care
Health information is the most sensitive thing you ever share with us, and it gets the strictest handling.
- Purpose limitation. Your screening answers are used only to place you in a suitable batch, to plan modifications, and to keep the class safe for you.
- Who sees it. Your screening summary is visible only to the trainers who teach your batch and to the small number of team members who run batch allocations and safety. It is not visible to other students.
- Never for advertising. Health data is never used for marketing, profiling, targeted advertising, or sold or rented to anyone.
- Minimisation. We ask for categories of information, not documents. We do not need your full medical history, test reports or prescriptions unless a clearance note is required.
- Retention. Screening records are kept for the duration of your active enrolment plus a limited safety period, and then deleted. See clause 11.
- Not shared with processors for their own use. Where a service provider helps us host or communicate, health data is either excluded or protected by contract and used only on our instructions.
One thing to know
If you do not tell us about a condition that affects your safety, we cannot adapt your practice — and both your safety and our ability to help you are compromised. Please answer the screening honestly.
Children’s data
- We do not knowingly enrol or process the personal data of children under 13. If you believe a child under 13 has given us data, write to hello@chandrayog.com and we will delete it.
- For students aged 13 to 17, we process personal data only after obtaining verifiable consent from a parent or legal guardian, and we do not process data in a way that is likely to cause a detrimental effect on the child.
- We do not carry out tracking, behavioural monitoring, or targeted advertising directed at children, and we do not share children’s data with third parties for such purposes.
- A guardian must be present in the room during the session, as required by the Terms of Service.
Cookies, analytics and marketing
- Essential cookies and storage, where used by the main site, support its core functions. This screening form itself holds answers only in page memory; it does not use cookies or local storage to save your responses.
- Analytics helps us understand which pages are used and where people get stuck. We use aggregated and, where possible, de-identified information.
- Marketing and embedded tools. Where we embed a third-party tool (for example a chat widget or video platform), that provider may set its own cookies under its own privacy policy. We select providers carefully and disclose them here rather than silently.
- Your control. You can block or delete cookies in your browser settings. You can opt out of marketing emails at any time using the link in any email, without affecting your plan.
Who we share your data with
We share personal data only as described here, and only as much as the task requires.
| Recipient | What they receive | Why |
|---|---|---|
| Trainers for your batch | Your screening summary and name | To guide your practice safely |
| Video conferencing provider | Display name; camera and microphone streams during class | To deliver live sessions |
| Payment gateway | Name, contact details, payment amount | To process your payment securely |
| Email and messaging providers | Name, email address, message content | To send confirmations, reminders and support replies |
| Website hosting and analytics | Technical and usage data | To serve and improve the website |
| Professional advisers | Relevant records, where necessary | Legal advice, insurance, dispute resolution |
| Government or law enforcement | Only what is lawfully required | Compliance with a valid legal request |
- Every processor is engaged under a valid contract that limits them to processing on our instructions and requires appropriate security.
- We do not sell, rent, or trade personal data, and we do not share it for anyone else’s advertising.
- If ChandraYog is ever reorganised, merged or sold, personal data may transfer as part of that transaction, and this policy would continue to apply to it.
Where your data is processed
We are based in India and our default is to store and process personal data in India. Some service providers — for example a global video-conferencing or hosting platform — may process data outside India.
Under the DPDP Act, we will not transfer personal data to any country or territory restricted by the Central Government by notification. Where data is processed outside India, we require at least the same standard of protection through contract and security controls, and we remain accountable for it.
How long we keep your data
We keep personal data only for as long as it is needed for the purpose it was collected for, or as required by law, and we delete it once that purpose is no longer served — whichever is earlier.
| Data | Retention period |
|---|---|
| Enquiry details that do not become an enrolment | Deleted within 12 months of last contact |
| Enrolment and attendance records | Duration of the plan, then up to 24 months for support and dispute handling |
| Health screening records | Duration of active enrolment plus 12 months, then deleted |
| Medical clearance notes | Until the plan ends, or 12 months, whichever is later, then deleted |
| Payment, invoice and tax records | As required by applicable tax and accounting law |
| Support and complaint records | Up to 36 months from closure |
| Marketing consent and preferences | Until you withdraw consent, plus a short suppression record |
| Server and security logs | Typically up to 12 months |
Where data is no longer needed, we delete it and ensure our processors delete their copies too. Where deletion is impossible (for example, in an encrypted backup that will be cycled out), we isolate and secure the data until it can be deleted.
How we protect your data, and what happens if something goes wrong
- Reasonable security safeguards. We use measures appropriate to the sensitivity of the data — access controls and least-privilege permissions, encrypted transmission (HTTPS), protected storage, controlled sharing of batch links, and staff confidentiality obligations.
- Limited access. Only the team members and trainers who need your data for the purpose described can see it.
- Accuracy. Where your data is used to make a decision that affects you, or may be shared with another Data Fiduciary, we take reasonable steps to keep it accurate and complete. Please help us by telling us when your details change.
- If a breach happens. In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines required by law, and we will tell you plainly what happened, what it means for you, and what we are doing about it.
- No system is perfect. We cannot promise absolute security, but we commit to acting quickly, transparently and lawfully if something goes wrong.
If you suspect a security issue involving your ChandraYog data, write to hello@chandrayog.com immediately and change any reused password.
Your rights as a Data Principal
The DPDP Act gives you enforceable rights over your personal data. We honour them without charge and without requiring you to explain yourself.
- Right to access (Section 11)
- Ask for a summary of the personal data we process about you, our processing activities, and the identities of the Data Fiduciaries and Data Processors with whom we have shared it.
- Right to correction and erasure (Section 12)
- Ask us to correct inaccurate or misleading data, complete incomplete data, update it, or erase it where it is no longer needed for the purpose it was collected for.
- Right to grievance redressal (Section 13)
- Raise a grievance with us first. We must respond within the period the rules prescribe. If you are not satisfied, you may complain to the Data Protection Board of India.
- Right to nominate (Section 14)
- Nominate another individual who may exercise your rights in the event of your death or incapacity. Write to us to record a nomination.
- Right to withdraw consent
- Withdraw any consent at any time, as easily as you gave it. See clause 5.
- Right to a language of your choice
- Ask to access this notice and your consent request in English or in any language listed in the Eighth Schedule to the Constitution of India, and we will provide it.
- Right against unfair processing
- You may also escalate where processing is not in accordance with the DPDP Act.
How to exercise a right
- Write to hello@chandrayog.com with the heading “Data request”.
- Tell us which right you are exercising, and enough detail for us to verify and locate your data (for example, the email address you enrolled with).
- We will acknowledge within 48 hours and respond substantively within the period prescribed under the DPDP Act and the rules, ordinarily within 30 days.
- If we need more information to verify your identity, we will ask for it. We will not ask for anything more than we need.
Grievance redressal and the Board
- Our Data Protection contact. hello@chandrayog.com — the person responsible for answering questions about the processing of your personal data and for handling your requests. Mark privacy matters “Data request” or “Grievance”.
- Our grievance mechanism. Every grievance is logged, acknowledged within 48 hours, and addressed within 7 working days wherever possible. If it will take longer, we tell you why and when to expect an answer.
- Complaining to the Board. If we do not resolve your grievance, you have the right to complain to the Data Protection Board of India, the adjudicating body established under the DPDP Act, 2023. We will give you the information you need to do so, and we publish our contact details for exactly this purpose.
- If we are notified as a Significant Data Fiduciary, we will appoint a Data Protection Officer based in India and an independent data auditor, and carry out Data Protection Impact Assessments as required — and we will update this policy to say so.
Changes to this policy
- We may update this policy to reflect changes in law, our services, or the way we process data. The version that applies to you is the one in force when your data is processed, identified by the effective date at the top of this page.
- Where a change materially affects how we use your data, we will notify you by email or through a clear notice on this website before it takes effect, and where the law requires it, we will ask for your consent again.
- This policy is governed by the laws of India. Nothing in it limits any right you hold under the DPDP Act, 2023 or any other law.
Data requests and grievances
Use the heading “Data request” for access, correction, erasure or nomination, and “Grievance” for a complaint. Include the email address you enrolled with so we can locate your records quickly.
ChandraYog Online Yoga Studio
Within 7 working days
This policy is aligned with the Digital Personal Data Protection Act, 2023 and the rules made under it, as applicable to ChandraYog. As the rules are phased in, certain procedures — including Consent Manager interoperability and any Significant Data Fiduciary obligations — will be activated and reflected here.