Privacy Policy
This explains what NeuraPath Academy collects about you, why, who else touches it, how long we keep it and what you can make us do about it — in the same plain language we use for our fees.
It is written from our actual systems, so the lists here are complete rather than defensive: every cookie we set, every provider that handles your data, and a real retention period for each kind of record.
1.Who we are
NeuraPath Academy is a live, mentor-led Data Science and AI academy operated by NovixoAI Private Limited. For everything described on this page, that company is the data fiduciary — the one accountable for your personal data under India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”).
Our registered office is in Delhi; our teaching centre is in Noida. Both are listed above because they answer different questions — the Delhi address is the company's statutory address, and Noida is where in-person labs and capstone days actually happen.
2.What this policy covers
This policy covers neurapath.in, the student and trainer portals on it, our live classes and recordings, and the email, phone and WhatsApp conversations we have with you about a programme. It applies whether you are a visitor, an enquiry, an applicant, an enrolled learner, or an alumnus.
It does not cover other companies' websites we link to, the hiring partners you choose to interview with once you share your CV with them, or the app stores and social platforms you may reach us through. Those have their own policies.
3.What we collect
We ask for a different amount depending on how far along you are. Nothing in the later groups is collected from someone who has only made an enquiry.
When you enquire, book a call, or use the free skill check
- Your name, mobile number and (optionally) email.
- The programme you are interested in, your years of experience, your timeline for starting, your current role if you tell us, and whether you have acknowledged the fee range.
- If you use the skill check: the role you chose and your score, the benchmark it was compared against, and which skills matched or were missing.
- The campaign details in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content, placement), the click identifier the advertising platform adds to the link (gclid, wbraid or gbraid from Google, fbclid from Meta, msclkid from Microsoft), the page you arrived on, the page you filled the form on, and the website that linked you to us — its domain only, never the full address. This tells us which advert or article you came from. We keep it in your browser for the current visit only, in a way that is cleared the moment you close the tab, and it reaches us only if you submit a form.
- A priority score our system calculates from the answers above, and the counsellor the enquiry was assigned to. This is an internal number used to decide who calls you first.
When you apply or enrol
The enrolment form asks for what a training provider needs in order to admit you, run your batch, invoice you and certify you:
- Identity and contact: full name, date of birth, gender, mobile, email, address, city, state and pincode.
- An emergency contact — a name and a number different from your own.
- Education and work: qualification, college, branch, year of passing, marks, current status, employer, years of experience, self-rated coding level, and your LinkedIn URL if you give it.
- Programme choices: course, duration, preferred timings, preferred start date, and whether your device and internet are ready for live sessions.
- Fees: fee plan, payment method, amount paid, the UTR / reference number of your transfer, and a GST number if you are claiming input credit.
- Documents you upload: photograph, CV, ID proof, marksheet and payment proof.
- Your declarations: which consent boxes you ticked, the name you typed as your signature, the timestamp, and the IP address the form was submitted from. We keep these because they are the record that you agreed, and to what.
- From your ID document we store only the last four digits of the number, the type of ID, and the name on it. The full number is never written to our database.
The enrolment form saves your progress as you go, so you can come back to a part-filled application instead of starting again. That draft holds your name, mobile, email and the choices you had made so far, and it exists even if you never submit. If you would rather it did not, email admissions@neurapath.in and we will delete it — see how long we keep things.
While you are learning with us
- Your login for the student portal. Your password is stored only as a one-way hash — we cannot read it, and it is stripped out of our backups entirely.
- Attendance per live session, assignment and quiz submissions, assessment scores, and progress through the curriculum.
- Recordings of live sessions, which include your voice, your video if your camera is on, your display name and anything you type in the meeting chat. This is important enough to have its own section.
- Payments and instalments: what was paid and when, the balance, your instalment schedule and your receipt numbers.
- Our correspondence with you — a log of which emails we sent you, when, and why, plus a copy of each in our sent folder.
Automatically, when you browse
- Standard server request data: IP address, browser and device type, pages requested and timestamps. This is how any website works and how we spot abuse.
- Only if you accept analytics cookies: aggregate usage data through Google Analytics 4 and Meta's advertising pixel. If you choose “Essential only”, neither loads at all. Full list in cookies and tracking.
4.Why we use it, and our legal basis
Under the DPDP Act we may only use your data for the purpose you gave it for. Here is that mapping in full.
| What we do with it | What it uses, and why we are allowed to |
|---|---|
| Call you back about a programme | Your name, number, course interest and the answers you gave. Your consent, given when you submitted the form asking to be contacted. |
| Assess and process your admission | Your education, experience and identity documents. Your consent, and necessary to enter the contract you are asking for. |
| Run your batch | Your name, contact, timings, attendance, submissions and portal login. Performance of our contract with you. |
| Invoice you and account for the money | Payment details, UTR, GST number, receipts. Legal obligation — the Companies Act, the Income-tax Act and GST law all require us to keep books. |
| Verify who you are before certifying you | ID type, name on ID, last four digits, marksheet. Necessary so a certificate in your name means something. |
| Arrange interviews and internships | Your CV, projects, attendance and capstone status, shared with a hiring partner. Only with your consent, and you can decline any individual introduction. |
| Provide recordings of sessions you missed | The session recording, which may contain you. Performance of our contract — and see the limits in section 5. |
| Improve the site and understand our advertising | Aggregate analytics and pixel data. Your consent, via the cookie banner, and revocable at any time. |
| Keep the service secure and recoverable | Request logs, audit records of staff actions, nightly backups. Our legitimate interest in not losing your records or letting someone else reach them. |
We do not sell your personal data. We do not rent or trade it, we do not hand it to a third-party marketing database, and we do not buy lists of learners from anybody else. We do not use your data to train machine-learning models, and your coursework is not used as teaching material for other cohorts without asking you first.
5.Live sessions are recorded
Every live session is recorded, and the recording is published to the cohort so learners who missed it can catch up. You should assume that a recording captures your voice, your video if your camera is on, your display name, and the meeting chat.
- Recordings go only to enrolled learners of that batch and to our teaching and admin staff. They are stored privately and played through short-lived signed links, so a URL copied out of the page stops working — they are not public, and they are not listed anywhere a search engine can reach.
- You may keep your camera off in any session. Nothing in our assessment or attendance rules requires you to be on video.
- If you ask a question you would rather not have recorded, say so and we will take it after the recording stops, or you can send it to your programme manager instead.
- If a recording captures something you want removed, tell us and we will edit or remove that portion where it is technically possible to do so without destroying the session for everyone else.
- Recordings are ours, and are licensed to you for personal study only. Downloading, re-sharing or reposting them is not allowed — that rule protects your classmates as much as our content.
8.How we protect it
- Your documents are not public. Uploads go to private storage, and staff view them through short-lived signed links rather than a permanent URL. There is no address you can guess to reach someone else's ID proof.
- Passwords are hashed, never stored or emailed in a readable form, and are removed from our backups — an exported file of password hashes is a target worth stealing, and restoring your records does not need it.
- Password reset links are stored only as a hash, expire in 45 minutes, work once, and invalidate every other outstanding link for your account when used.
- Access is by role. A trainer sees their own batches; a counsellor sees their own enquiries. Staff actions on records are written to an audit log.
- ID numbers are truncated on the way in. We keep four digits, so a breach of our database cannot expose a full identity number. We ask you to mask the first eight digits of an Aadhaar before uploading it, and never to send us an unmasked one.
- We take no card details. Fees are paid by bank transfer or UPI, so we never see or store a card number, CVV or bank password. If you are asked for those in our name, it is not us.
- Nightly encrypted backups of all records, with an automated check that every document we have a record of is still actually there.
No system is perfectly secure, and we would rather say so than imply otherwise. If we ever suffer a breach affecting your data, we will notify you and the Data Protection Board of India as the DPDP Act requires.
9.How long we keep it
We keep data only as long as the purpose it was collected for lasts, or as long as the law requires — whichever is longer. In plain terms:
| What | How long |
|---|---|
| An enquiry that never became an application | Up to 24 months after we last spoke, then deleted or reduced to anonymous statistics. Ask us sooner and we will delete it sooner. |
| A part-filled application you abandoned | Up to 90 days, then deleted. It is a draft, not a record. |
| Your ID proof | Until your admission is confirmed. Ask us and we will delete it at that point — we keep the ID type, the name on it and four digits as the verification record, which is enough. |
| Enrolment, fees, receipts and tax records | Eight financial years from the end of the relevant year, because the Companies Act, 2013 and Indian tax law require it. This one we cannot shorten on request. |
| Attendance, assessments, certificate record | Kept for as long as your certificate needs to be verifiable — a credential nobody can check is worthless. |
| Session recordings | For the duration of your access to the programme, and while the cohort is running. |
| Marketing analytics | As set by Google and Meta for their own tools; we do not hold a separate copy tied to you. |
Where we are required to keep a financial record, we keep the record and not the extras — a closed learner file does not need to retain your uploaded documents.
10.Your rights, and how to use them
The DPDP Act gives you the following rights over your data. You do not need a reason, and exercising them is free.
- Know what we hold. Ask for a summary of your personal data, what we are doing with it, and who we have shared it with.
- Correct or complete it. If your number, name, qualification or address is wrong or out of date, we will fix it.
- Have it erased. We will delete what we no longer need for the purpose you gave it for, or where you withdraw consent — except records the law requires us to keep, and we will tell you which those are.
- Withdraw consent. At any time, as easily as you gave it. Withdrawing consent to be contacted stops the calls and marketing messages; withdrawing consent we need in order to run your programme may mean we cannot continue to deliver it, and we will say so plainly before acting.
- Nominate someone. You can nominate another person to exercise these rights on your behalf if you die or become incapacitated.
- Complain. Raise a grievance with us and, if we do not resolve it, with the Data Protection Board of India.
How to ask
Email admissions@neurapath.in from the address you registered with, or write to the registered office below. Tell us what you want done. We will confirm receipt and respond within 30 days. If we need to verify it is really you before acting — which we will, for a deletion request — we will ask for the least we can manage with.
Marketing, calls and WhatsApp
When you submit an enquiry asking us to call you, you are consenting to that call, that WhatsApp message and that email, including where your number is on the National Do Not Call register — because you asked us specifically. That consent is limited to your enquiry, and you can end it at any time by replying STOP to a WhatsApp message, using the unsubscribe link in an email, or simply telling the counsellor. We will confirm and stop. Messages about a programme you are actually enrolled in are service messages and will continue while you are enrolled.
11.Children
Our programmes are for working professionals, graduates and final-year students, and are intended for people aged 18 and over. We do not knowingly collect the personal data of a child under 18, and we do not run behavioural advertising or tracking aimed at children.
If you are under 18, please do not submit a form here — have a parent or guardian contact us instead, so consent is given by someone who can legally give it, as the DPDP Act requires. If we learn we hold a child's data without verifiable parental consent, we will delete it. Tell us at admissions@neurapath.in.
12.Grievance redressal
If you are unhappy with how we have handled your data, or with any answer you have had from us, escalate it here. This is the contact required by the DPDP Act, and a real monitored mailbox rather than a form that goes nowhere.
Write “Privacy grievance” in the subject line so it is routed correctly. We will acknowledge it and respond within 30 days. Academic and fee complaints follow a different route — your programme manager first, escalating to the academy head within 7 working days, as set out in our Terms & Conditions.
If we do not resolve it to your satisfaction, you have the right to complain to the Data Protection Board of India.
13.Changes to this policy
We will update this page when what we do changes — a new provider, a new form field, a new tag. The date at the top is the date of the current version, and material changes affecting how we use data you have already given us will be notified to enrolled learners by email rather than only posted here.
Questions about anything on this page are welcome at admissions@neurapath.in. See also our Terms & Conditions, which cover fees, refunds, attendance, certification and what we do and do not promise about outcomes.
NovixoAI Private Limited, incorporated in India on 10 September 2025. CIN U62012DL2025PTC455022. This policy is governed by the laws of India, and the courts at New Delhi have exclusive jurisdiction over any dispute about it.