Legal
Privacy Policy
Your privacy matters to us. This policy explains how Outlook Edu Services collects, uses, protects, and discloses your personal data in compliance with Indian, UK, and US privacy laws.
Multi-Jurisdiction Compliance
DPDPA 2023
India
IT Act 2000
India
UK GDPR
United Kingdom
CCPA/CPRA
California, USA
CAN-SPAM
USA
COPPA
USA
PECR
United Kingdom
Section 1
Introduction
Outlook Edu Services ("OES," "we," "us," or "our") is a visa consultancy and educational advisory firm registered and operating from Hyderabad, Telangana, India. We are committed to protecting your privacy and handling your personal data with transparency and care.
This Privacy Policy describes how we collect, use, store, protect, share, and disclose your personal data when you:
- •
Visit or interact with our website at outlookeduservices.com ("Website")
- •
Use our visa consultancy and educational advisory services ("Services")
- •
Communicate with us via email, phone, WhatsApp, or other channels
- •
Create an account on our Website
- •
Book a consultation through our Website
This Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA, India), the Information Technology Act, 2000 (India), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act (CCPA/CPRA, USA), and other applicable data protection laws.
By accessing our Website or using our Services, you acknowledge that you have read and understood this Privacy Policy. Where required by law, we will obtain your explicit consent before processing your personal data.
Section 2
Information We Collect
We collect the following categories of personal data, depending on how you interact with us:
| Category | Details |
|---|---|
| Personal Information | Full name, email address, phone number, postal address — collected via contact forms, booking forms, and direct communication. |
| Visa-Related Information | Passport details, educational qualifications, academic transcripts, financial documents, employment history, travel history — shared during consultations for visa application preparation. |
| Account Information | Email address, authentication credentials (hashed), OAuth provider data (if using social login) — collected during account registration via our authentication system (Supabase). |
| Technical Information | IP address, browser type and version, operating system, device type, screen resolution, referring URL, pages visited, time spent on pages. |
| Usage Data | Interaction patterns with our Website, click paths, form interactions, consultation booking activity, search queries on our site. |
| Communication Data | Records of emails, WhatsApp messages, phone calls, and any correspondence with OES representatives. |
Sensitive Personal Data: Visa-related documents (passport copies, financial records) are classified as Sensitive Personal Data or Information (SPDI) under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. We collect such data only with your explicit consent and process it under heightened security measures.
Section 3
How We Collect Information
We collect your personal data through three primary methods:
1. Directly From You
When you fill out our contact form, booking form, or registration form on the Website. When you communicate with us via email, phone, WhatsApp, or in-person consultations. When you submit documents for visa application preparation.
2. Automatically
Through cookies, pixels, and similar tracking technologies when you browse our Website. Through analytics tools (Google Analytics, Meta Pixel, Vercel Analytics) that automatically collect technical and usage data.
3. From Third Parties
From universities and educational institutions (application status updates). From government portals and visa processing centres (visa status updates, where authorised by you). From authentication providers (OAuth login data, if you use social login).
Section 4
Legal Basis for Processing
We process your personal data under different legal bases depending on your jurisdiction:
India — DPDPA 2023
- •
Consent: Where you have given clear, informed consent for specific processing purposes.
- •
Legitimate Uses: Processing necessary for specified purposes as permitted under the DPDPA 2023, including performance of a contract.
- •
Legal Obligation: Where we are required by Indian law to process your data.
United Kingdom — UK GDPR
- •
Consent (Article 6(1)(a)) — for marketing communications and non-essential cookies.
- •
Contract Performance (Article 6(1)(b)) — to deliver the services you have requested.
- •
Legitimate Interest (Article 6(1)(f)) — for website analytics, fraud prevention, and service improvement.
- •
Legal Obligation (Article 6(1)(c)) — where required by UK law.
United States — CCPA/CPRA
We process personal information on a consent basis. If you are a California resident, you have specific rights under the CCPA/CPRA including the right to know, delete, and opt-out of the sale or sharing of your personal information. We do not sell your personal information.
Section 5
How We Use Your Information
We use the personal data we collect for the following purposes:
| Category | Details |
|---|---|
| Service Delivery | To provide visa consultancy, document preparation, university counseling, and related advisory services as requested by you. |
| Communication | To respond to your enquiries, provide consultation updates, send booking confirmations, and communicate service-related information. |
| Account Management | To create and manage your user account, authenticate your identity, and provide personalised features on the Website. |
| Website Improvement | To analyse usage patterns, optimise Website performance, and improve user experience through analytics data. |
| Marketing | To send promotional communications about our services (only with your explicit opt-in consent; you may opt-out at any time). |
| Legal Compliance | To comply with applicable laws, regulations, legal processes, or enforceable governmental requests. |
| Security & Fraud Prevention | To protect our Website, Services, and users from fraudulent, abusive, or unlawful activity. |
Section 7
Third-Party Service Providers
We engage trusted third-party service providers to help operate our Website and deliver our Services. Each provider has access only to the data necessary for their specific function:
| Category | Details |
|---|---|
| Supabase | Backend infrastructure, authentication, and database services. Processes account data, contact form submissions, and booking data. Data may be processed outside India on Supabase's cloud infrastructure. |
| Vercel | Website hosting, CDN delivery, and performance monitoring. Processes technical data via its global edge network. Vercel Analytics collects anonymised performance metrics. |
| Google Analytics | Website analytics service by Google LLC (USA). Collects anonymised usage data with IP anonymisation enabled. Data is transferred to the United States and governed by Google's Data Processing Terms and Standard Contractual Clauses. |
| Meta / Facebook | Meta Pixel for conversion tracking and remarketing. Operated by Meta Platforms Inc. (USA). Data is transferred to the United States and processed under Meta's Data Processing Terms. |
| WhatsApp (Meta) | Customer support communication channel. Messages are end-to-end encrypted by WhatsApp. Operated by WhatsApp LLC, a Meta company. |
Each third-party provider is contractually bound to handle your data in accordance with applicable data protection laws and our instructions. We do not sell your personal data to any third party.
Section 8
International Data Transfers
As we use global service providers (Google, Meta, Vercel, Supabase), your personal data may be transferred to and processed in countries outside India, including the United States and other countries where these providers maintain servers.
Safeguards for International Transfers:
- •
Under DPDPA 2023 (India): Cross-border transfers are permitted unless the Indian government specifically restricts transfer to certain countries. We ensure that our service providers maintain adequate data protection measures.
- •
Under UK GDPR: We rely on Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO) and adequacy decisions where applicable.
- •
Under CCPA (USA): We ensure that any sharing of data with service providers is governed by contractual obligations prohibiting the sale of personal information.
By using our Services, you acknowledge that your data may be transferred internationally as described in this section.
Section 9
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law.
| Category | Details |
|---|---|
| Active Client Data | Retained for the duration of our engagement plus 7 years thereafter, in compliance with Indian regulatory and tax requirements. |
| Contact Form Submissions | Retained for 2 years from the date of submission, after which they are securely deleted. |
| Account Data | Retained until you request account deletion, subject to our legal and regulatory obligations. |
| Analytics Data | Retained as per Google Analytics (default 26 months) and Meta retention policies. Vercel Analytics data is aggregated and anonymised. |
| Communication Records | Retained for the duration of our relationship plus 3 years, in accordance with record-keeping best practices. |
| Visa-Related Documents | Retained for the duration of the engagement plus 7 years. Securely destroyed thereafter unless you request earlier deletion. |
Upon expiry of the retention period, personal data is securely deleted or anonymised using industry-standard methods, in compliance with the DPDPA 2023 requirements for data erasure.
Section 10
Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
Under DPDPA 2023 (India)
- •
Right to Access: Obtain a summary of your personal data and processing activities.
- •
Right to Correction: Request correction of inaccurate or incomplete personal data.
- •
Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
- •
Right to Grievance Redressal: File a complaint with our Grievance Officer or the Data Protection Board of India.
- •
Right to Nominate: Nominate another person to exercise your rights in case of your death or incapacity.
Under UK GDPR
- •
Right of Access (Subject Access Request)
- •
Right to Rectification
- •
Right to Erasure ('Right to be Forgotten')
- •
Right to Restriction of Processing
- •
Right to Data Portability
- •
Right to Object to Processing
- •
Rights related to Automated Decision-Making and Profiling
UK residents may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Under CCPA/CPRA (California, USA)
- •
Right to Know: What personal information we collect, use, disclose, and sell.
- •
Right to Delete: Request deletion of your personal information.
- •
Right to Opt-Out: Opt out of the sale or sharing of personal information. (Note: We do not sell your personal information.)
- •
Right to Non-Discrimination: You will not be discriminated against for exercising your CCPA rights.
How to Exercise Your Rights
To exercise any of the above rights, please contact us at contact@outlookeduservices.com or write to our Grievance Officer (see Section 15). We will respond to your request within 30 days as required under the DPDPA 2023, or within the timeframe required by your applicable jurisdiction.
Section 11
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- •
SSL/TLS Encryption: All data transmitted between your browser and our Website is encrypted using industry-standard TLS (Transport Layer Security) protocols.
- •
Supabase Row Level Security (RLS): Our database enforces granular access controls ensuring users can only access their own data.
- •
Authentication Security: Passwords are hashed using industry-standard algorithms. OAuth-based authentication is available for enhanced security.
- •
Access Controls: Access to personal data is restricted to authorised personnel on a need-to-know basis.
- •
Regular Security Assessments: We periodically review our security practices and update them in accordance with evolving threats.
Our security practices comply with the Reasonable Security Practices and Procedures required under Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India).
Incident Response
In the event of a personal data breach, we will notify the Data Protection Board of India (as required under DPDPA 2023), the ICO (for UK residents, where applicable under UK GDPR), and affected individuals without undue delay, in accordance with applicable breach notification requirements.
Section 12
Children's Privacy
Our Website and Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children under 18 years of age.
- •
Under the DPDPA 2023 (India): Processing of personal data of a child (under 18) requires verifiable consent from a parent or lawful guardian. We do not knowingly process children's data without such consent.
- •
Under COPPA (USA): We do not knowingly collect information from children under 13. If we discover that we have inadvertently collected data from a child under 13, we will delete it promptly.
- •
Under UK GDPR: Where processing relies on consent, we require consent from a parent or guardian for children under 13 (or applicable age of digital consent in the UK).
If you believe that a child has provided us with personal data without appropriate parental consent, please contact us immediately at contact@outlookeduservices.com.
Section 13
Marketing Communications
We may send you marketing communications about our Services, offers, and educational opportunities. We adhere to the following principles:
- •
Opt-In Consent: We will only send marketing communications where you have provided your explicit opt-in consent.
- •
Unsubscribe Mechanism: Every marketing communication will include a clear and easy-to-use unsubscribe option. You may opt out at any time.
- •
CAN-SPAM Compliance (USA): All email communications include our physical business address, a clear "From" identifier, accurate subject lines, and a functioning unsubscribe link. Opt-out requests are honoured within 10 business days.
- •
PECR Compliance (UK): Electronic marketing is sent only with prior consent, in accordance with the Privacy and Electronic Communications Regulations 2003.
To opt out of marketing communications, email us at contact@outlookeduservices.com with the subject line "Unsubscribe."
Section 14
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make changes:
- •
The revised Privacy Policy will be posted on this page with an updated "Last Updated" date.
- •
For material changes, we may provide additional notice through a prominent banner on our Website.
- •
Your continued use of our Website or Services after the posting of the revised Privacy Policy constitutes your acceptance of such changes.
- •
If we make changes that materially reduce the protection of your personal data, we will seek your consent where required by applicable law.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
Section 15
Grievance Officer (India)
In compliance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, we have appointed a Grievance Officer to address your concerns regarding personal data processing:
Grievance Officer
Khaja Nadeemuddin
Country Head — India, Outlook Edu Services
Address
Unit A Floor, Ahmed Mansion, 2, Santosh Nagar Main Rd,
opposite Pillar Number 60, Central Excise Colony,
New Santoshnagar, Santosh Nagar, Hyderabad,
Telangana 500059, India
The Grievance Officer will acknowledge your complaint within 48 hours and resolve it within 30 days from the date of receipt, as mandated by the DPDPA 2023. If you are not satisfied with the resolution, you may escalate your complaint to the Data Protection Board of India.
Section 16
Data Protection Officer (UK GDPR)
For users in the United Kingdom, our Data Protection Officer (DPO) can be contacted for any queries related to data processing under the UK GDPR:
Data Protection Officer
Outlook Edu Services
Email: contact@outlookeduservices.com
Phone: +91 7702180404
If you are in the UK and believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/.
Section 17
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
Company
Outlook Edu Services
Address
Unit A Floor, Ahmed Mansion, 2, Santosh Nagar Main Rd,
opposite Pillar Number 60, Central Excise Colony,
New Santoshnagar, Santosh Nagar, Hyderabad,
Telangana 500059, India
