Privacy Policy
This Privacy Policy explains how the Centre for Social Responsibility and Leadership (CSRL) collects, uses, stores, protects and processes personal data across its website, applications, portals, online forms and other CSRL-operated digital platforms.
1. Introduction
The Centre for Social Responsibility and Leadership ("CSRL", "we", "us", or "our") respects the privacy of students, parents/guardians, applicants, employees, volunteers, donors, sponsors, partners, visitors, users and other individuals who interact with CSRL.
This Privacy Policy explains how CSRL collects, receives, uses, stores, processes, shares, protects and otherwise handles personal data through its digital platforms.
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- CSRL website, including www.csrl.in;
- CSRL-owned or operated subdomains and portals;
- CSRL mobile applications;
- Online registration and admission/selection platforms;
- Online examination and assessment platforms;
- Student, parent, employee, volunteer and partner portals;
- Online forms and surveys;
- Donation and payment-related digital interfaces;
- Project-specific websites operated by or for CSRL;
- Digital communication platforms operated by CSRL; and
- Other online services displaying the CSRL name, logo or branding where CSRL is the operator.
Where a particular CSRL service has an additional service-specific privacy notice, that notice should be read together with this Privacy Policy.
3. About CSRL
The Centre for Social Responsibility and Leadership (CSRL) is a registered society working primarily in the areas of education, skill development and social development.
CSRL's initiatives include educational programmes, residential learning centres, student selection and entrance examinations, scholarship/support programmes, school projects, CSR-supported projects, publications, events, volunteering and other activities intended to create educational opportunities and social impact.
4. Personal Data We May Collect
4.1 Identification Information
- Full name
- Date of birth and age
- Gender, where relevant
- Photograph
- Identification information
- Student/application ID
- Registration number
4.2 Contact Information
- Mobile number
- Email address
- Residential or correspondence address
- City, district and state
- Parent/guardian contact information
- Emergency contact information where required
4.3 Academic and Application Information
- School/college details
- Class or course
- Academic records
- Examination marks and results
- Entrance examination information
- Test and assessment responses
- Rank or score
- Programme preferences
- Scholarship-related information
- Selection/interview information
4.4 Employment and Volunteer Information
- Resume/CV
- Educational qualifications
- Professional experience
- Skills
- Contact information
- References
- Interview information
4.5 Technical Information
- IP address
- Browser type
- Device type
- Operating system
- Device identifiers
- Application version
- Login information
- Date and time of access
- Pages/features accessed
- Error and diagnostic information
- Security and authentication logs
4.6 Location Information
CSRL may process approximate or precise location information only where it is necessary for a specific service and where permitted by applicable law and appropriate permission or consent has been obtained.
5. How We Collect Personal Data
- Website forms
- Mobile applications
- Registration forms
- Admission and selection forms
- Online examinations
- Student portals
- Employee portals
- Surveys
- Email and messaging platforms
- Events
- Payment platforms
- Recruitment platforms
- Other authorised CSRL channels
6. Purposes for Which We Use Personal Data
CSRL may process personal data for:
- Student registration and selection;
- Entrance examinations and assessments;
- Admission and programme administration;
- Scholarship and educational support;
- Academic support and mentoring;
- Attendance and participation management;
- Student and parent communication;
- Project monitoring and evaluation;
- Recruitment and employment;
- Volunteer management;
- Donation administration;
- Internal reporting and audit;
- Technical support;
- Security and fraud prevention;
- Legal and regulatory compliance; and
- Improving CSRL digital services.
7. Legal Basis for Processing
CSRL will process personal data only for lawful and specified purposes and in accordance with applicable Indian law.
Depending on the circumstances, processing may be based on:
- Consent;
- Consent provided by a parent or lawful guardian where required;
- Information voluntarily provided for a specified purpose;
- Compliance with applicable legal requirements;
- Providing a requested service or programme;
- Legitimate organisational requirements recognised under applicable law; and
- Other lawful grounds permitted under Indian law.
8. Consent
Where processing is based on consent, CSRL will provide an appropriate notice explaining the purpose for which personal data is collected.
Where applicable, users may withdraw consent. Withdrawal of consent will not affect processing that was lawfully completed before withdrawal.
Certain services may no longer be available if the requested information is essential to provide those services.
9. Children and Minors
CSRL conducts educational programmes involving students who may be below 18 years of age.
Where personal data relating to a child is collected, CSRL will implement appropriate safeguards and obtain verifiable parental or lawful guardian consent where required by applicable law.
Parents or lawful guardians may contact CSRL regarding the personal data of a child for whom they have lawful authority.
11. Third-Party Links and Platforms
CSRL platforms may contain links to third-party websites, applications or services. These may include payment providers, government websites, social media platforms, educational institutions, sponsors and partner organisations.
Once you leave a CSRL-controlled platform, the third party's privacy policy and terms may apply. CSRL is not responsible for the privacy practices or security of independent third-party services.
13. Analytics and Performance Monitoring
CSRL may use analytics and performance-monitoring technologies to understand website traffic, application performance, user interactions, technical errors, service usage and general trends.
14. Artificial Intelligence and Automated Technologies
Certain CSRL digital platforms may use artificial intelligence, automation or machine-assisted technologies for generating summaries, administrative assistance, reporting, support, analytics, search and service improvement.
Where AI or automated technologies process personal data, CSRL will implement appropriate safeguards and use such information only for lawful and specified purposes.
15. Data Accuracy
CSRL aims to maintain accurate and relevant personal data. Users should provide accurate information and inform CSRL when their information changes.
16. Data Retention
CSRL will retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law.
When personal data is no longer required, CSRL will take reasonable steps to delete, anonymise or securely dispose of it, subject to applicable legal and operational requirements.
17. Data Security
CSRL takes reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, loss, misuse, alteration, destruction and other security threats.
Security measures may include:
- Access controls;
- Authentication;
- Password protection;
- Role-based permissions;
- Encryption where appropriate;
- Secure hosting;
- Backup procedures;
- Security monitoring;
- Audit logs; and
- Vulnerability management.
18. Personal Account Security
Where a CSRL platform provides an account, users should:
- Keep login credentials confidential;
- Not share passwords;
- Use strong passwords;
- Log out of shared devices;
- Report suspected unauthorised access; and
- Provide accurate information.
19. Data Breach and Security Incidents
If CSRL becomes aware of a personal-data breach or security incident requiring action under applicable law, CSRL will take reasonable steps to assess, contain, investigate and address the incident.
Where required by applicable law, CSRL will provide notifications to affected individuals or authorities and take appropriate corrective measures.
20. Your Privacy Rights
Subject to applicable law, individuals may have rights relating to their personal data, including:
- Access to information about personal data being processed;
- Correction of inaccurate or incomplete information;
- Deletion/erasure where legally applicable;
- Withdrawal of consent where processing is based on consent;
- Nomination of another individual where permitted by law; and
- Raising a grievance regarding personal-data processing.
21. How to Exercise Your Rights
To submit a privacy request, correction request, deletion request, consent-related request or grievance, please contact CSRL using the privacy contact information provided below.
Privacy / Data Protection Contact:
To be officially designated by CSRL
Email:
[email protected]
(To be activated/confirmed by CSRL)
CSRL may require reasonable information to verify the identity and authority of the requester before processing certain requests.
22. Grievance Redressal
If you have a concern about how CSRL has collected, used or handled your personal data, you may contact CSRL through the designated privacy/data-protection contact.
CSRL will review and respond to privacy-related grievances within the time period prescribed by applicable law.
Where applicable, individuals may have additional rights to approach the appropriate regulatory authority or other legally available mechanism.
23. International Data Processing
Some CSRL technology providers, cloud services or authorised service providers may process or store information outside India.
Where personal data is transferred outside India, CSRL will take measures required under applicable Indian law concerning cross-border transfers.
24. Data of Students, Parents and Guardians
Because CSRL's activities involve education and social development programmes, student information may be used for programme administration, academic support, selection, attendance, reporting, evaluation and communication.
Where appropriate and legally permitted, information may be shared with parents/guardians, authorised project partners, sponsors or educational institutions for legitimate programme purposes.
25. Photographs, Testimonials and Success Stories
CSRL may publish photographs, videos, testimonials, achievements and success stories relating to its programmes on websites, applications, social media, annual reports, publications, presentations, newsletters and campaign materials.
Where consent or authorisation is legally required, CSRL will obtain appropriate permission. For minors, appropriate parent/guardian consent or another lawful basis will be used where required.
26. Communications
Users may receive communications necessary to provide a requested service, including:
- OTP messages;
- Application confirmations;
- Examination information;
- Admit-card information;
- Result notifications;
- Interview notifications;
- Selection information;
- Programme updates;
- Important administrative notices; and
- Security alerts.
Marketing or promotional communications will be handled in accordance with applicable law and relevant consent or opt-out requirements.
28. Third-Party Technology Providers
CSRL may engage technology providers for hosting, cloud infrastructure, communication, payment processing, analytics, cybersecurity, application development, online examinations and other services.
CSRL expects authorised service providers handling personal data on its behalf to implement appropriate safeguards and process information only for authorised purposes.
29. No Sale of Personal Data
CSRL does not sell or rent personal data to third parties as a commercial data-brokerage activity.
CSRL may share limited information with authorised service providers, programme partners, sponsors, institutions or authorities where necessary for legitimate programme, operational, legal or regulatory purposes.
30. Changes to This Privacy Policy
CSRL may update this Privacy Policy from time to time to reflect changes in law, regulatory requirements, technology, services, applications, security practices or organisational processes.
The updated Privacy Policy will be published on the relevant CSRL digital platform with a revised "Last Updated" date.
Where required by law, CSRL may provide additional notice or obtain fresh consent.
31. Governing Law
This Privacy Policy shall be governed by and interpreted in accordance with the applicable laws of India.
Any dispute concerning privacy or personal-data processing shall be subject to the applicable legal and regulatory framework in India.
32. Acceptance
By using a CSRL digital platform, you acknowledge that you have had an opportunity to read this Privacy Policy.
Where applicable law requires consent, continued use of a service alone will not be treated as consent where a separate affirmative consent mechanism is legally required.
33. Contact CSRL
Centre for Social Responsibility and Leadership (CSRL)
Office:
2nd & 3rd Floor, A-33 Swasthya Vihar,
New Delhi - 110092, India
Registered Office:
B-95 Manavsthali Apartments,
Vasundhara Enclave,
New Delhi - 110096, India
Telephone:
+91 9711909428 / +91 11 500877
General Email:
[email protected]
Privacy / Data Protection Email:
[email protected]
27. Social Media and Messaging Platforms
CSRL may maintain official accounts or communication channels on platforms such as WhatsApp and other social media or messaging services.
Interactions through these platforms may be subject to the privacy policies and terms of the respective platforms.