Child Data & DPDP
A large share of our learners are under 18. India's DPDP Act sets a high bar for their data, and this page states exactly how we meet it — in plain language a parent can actually check us against.
Last updated: Draft · not yet published
Why this page exists separately
Under the Digital Personal Data Protection Act, 2023, anyone under 18 is a child, and processing their personal data carries obligations that do not apply to adults. Because CEFTA Jr exists specifically to teach school-age learners, we treat these obligations as a design constraint on the whole organisation rather than a clause at the bottom of a policy.
Verifiable parental consent
We do not process a child's personal data without the verifiable consent of a parent or lawful guardian. In practice:
- A learner under 18 cannot self-enrol. Enrolment is completed by a parent or guardian.
- Consent is captured in a specific, written record naming the learner, the purposes consented to, and the date — not as a pre-ticked box or a bundled acceptance.
- We verify that the consenting adult is in fact the parent or guardian, using the enrolment interaction and, where we cannot establish it otherwise, a documentary check.
- Consent is granular. Consent to enrol is separate from consent to be photographed, and separate again from consent to be featured in our showcase. Declining the second and third has no effect on the first.
- Consent can be withdrawn at any time, as easily as it was given, by writing to our Grievance Officer.
No tracking, no profiling, no ad-targeting of minors
This is an absolute rule and we do not make exceptions for it.
- We do not run behavioural advertising to children, and we run no advertising pixels anywhere on this site.
- We do not perform tracking or behavioural monitoring of a child, and we do not build profiles of children.
- We do not share or sell a child's personal data to advertisers, data brokers or any third party for their own purposes.
- Analytics are aggregate and non-identifying, are gated behind the consent notice, and are never used to profile an identified minor.
Data minimisation for learners
We collect the minimum that lets us teach a child safely and evidence what they completed:
- Learner name and age or school grade, guardian contact details, the institution where relevant, attendance, assessment outcomes, and the work produced.
- Medical or accessibility information only where a guardian volunteers it for safety in the lab, held separately and shared only with the instructors who need it.
- We do not collect a child's own phone number or personal email where a guardian contact will do.
- We do not ask children for information about their household, income or family.
Detrimental effect
The Act prohibits processing that is likely to have a detrimental effect on the wellbeing of a child. We read that broadly: no engagement-maximising mechanics aimed at children, no manufactured urgency in anything a child sees, no dark patterns, and no marketing addressed to a child rather than to their parent.
Showcasing a learner's work
Student work is central to how we demonstrate what we do, and it is also the place where a child's privacy is easiest to get wrong. So:
- Nothing featuring a child — photograph, video, name, or their build — is published without separate, specific, written guardian consent for that use.
- A guardian may ask for first-name-only or full anonymity, and we will still feature the build.
- Consent is revocable. Ask us to take it down and we take it down, without asking why.
- We never publish a child's school, class, location beyond city, or any contact detail alongside their work.
Safety inside the lab
- A mandatory safety induction before any hardware work.
- Supervision at 15 learners per trainer or better.
- Age-appropriate limits — younger builders work low-voltage and supervised.
- Instructors who work with children are subject to our background-check policy.
Retention and deletion
A child's record is kept for the duration of the relationship plus [3 years], so a credential can be re-issued. A guardian may request erasure at any time; where we are not legally required to retain the record, we delete it and instruct our processors to do the same, and we confirm to you when it is done.
How a parent exercises these rights
Write to [Name], Grievance Officer / Data Protection Officer, at [email protected]. You can ask us for a copy of everything we hold on your child, correct it, delete it, withdraw any consent, or complain. We reply within 30 days, as required by the DPDP Act, and you may escalate to the Data Protection Board of India if we fall short.
How to reach us about your data
[Name] · Grievance Officer / Data Protection Officer
[email protected]
[Registered address], [City], [State], India
We respond within 30 days, as required by the DPDP Act.