LEGAL & PRIVACY

Privacy Policy

The authoritative public privacy notice for ODA3 Institute websites, documentation, publications and services.

Effective Date: 13 July 2026 · Last Updated: 13 July 2026


PART 1 — Introduction & Governance

1.1 Who We Are

ODA3 Institute is the trading name of ODA3 Pvt Ltd, a private company incorporated in India in March 2026, with its registered office at Damyanti Sadan, Sarvodaya Nagar, Road No 4, East Gola Road, Danapur, Patna 801503, India. ODA3 Pvt Ltd is the Data Fiduciary (India DPDP Act, 2023) and Data Controller (EU/UK GDPR) for personal data processed through:

  • oda3.org and all subdomains
  • the documentation portal (GAISSF™ / UAIF™ / AI-IRF™)
  • the publication library and Download Center
  • the Training Institute site
  • any future ODA3-owned site, unless a separate policy is posted for it

This Policy does not cover data governed by a separate signed agreement. Personal data processed under a client engagement, assessment, certification, or enterprise agreement is governed by that agreement's terms, which may supplement or take precedence over this public Policy.

ODA3 Institute processes personal data under the principles in Section 1.2 and applies privacy-by-design consideration when building new site features, training programs, and future services.

1.2 Privacy Principles

  • Lawfulness, fairness, and transparency — we tell you what we collect and why.
  • Purpose limitation — data is used only for the purpose stated at collection.
  • Data minimization — we collect what's needed for that purpose, not more.
  • Accuracy — we take reasonable steps to keep data correct and current.
  • Storage limitation — data is retained only as long as necessary (Schedule B).
  • Security — reasonable technical and organizational safeguards (Section 3.3).
  • Accountability — we can demonstrate how we meet these principles on request.

1.3 Definitions

Personal Data — information relating to an identified or identifiable individual. Processing — any operation performed on personal data. User/Visitor — anyone accessing the Site. Services — publications, documentation, training, and any future certification/assessment services. Framework(s) — GAISSF™, UAIF™, AI-IRF™. Partner — an organization with a signed agreement to co-deliver research, training, or certification with ODA3. Third Party — any entity other than ODA3 and the individual concerned. Data Fiduciary/Controller — the entity determining the purpose and means of processing. Data Processor — an entity processing data on another's instructions.

1.4 Contact

  • General privacy queries: CONTACT_AT_ODA3_DOT_ORG
  • Data Protection Officer / Grievance Officer (DPDP Act, 2023): Grievance Officer — named appointment pending publication; interim operational contact: CONTACT_AT_ODA3_DOT_ORG. This individual is the primary contact for privacy inquiries globally, including DPDP, GDPR, and CCPA/CPRA matters. Current contact details will be published at /legal/grievance-redressal/index.html and updated promptly on any change.
  • Registered office: Damyanti Sadan, Sarvodaya Nagar, Road No 4, East Gola Road, Danapur, Patna 801503, India

PART 2 — Information Lifecycle

2.1 What We Collect

Provided directly by you: name, email, organization, job title, country, phone (where requested); inquiry content from any of the six contact forms; newsletter preferences; Download Center registration details; training/course registration and payment-related data (processed by a third-party payment processor — we do not store full card numbers); Faculty/practitioner application details; standards consultation feedback, framework issue reports, and errata submissions.

Collected automatically: IP address, browser/OS/device type, screen resolution, language, time zone, referral URL, session identifiers, pages visited, files downloaded, on-site search queries, click activity, time on page, server and security logs.

Cookies: the Site uses strictly necessary browser storage for basic functionality, security, theme and consent preferences. A cookie-consent banner is active. Optional analytics or embedded-service storage must not activate unless the visitor affirmatively accepts it. No advertising or cross-site behavioural tracking is currently enabled.

From third parties: none currently. We do not use Google/GitHub/LinkedIn sign-in, any identity provider, or any third-party analytics service at this time. If any of these are introduced, this section and Schedule C will be updated first.

2.2 Why We Process It, and On What Basis

Purpose GDPR Basis DPDP Basis
Responding to enquiries Consent / legitimate interest Consent
Newsletter delivery Consent Consent
Download Center access Consent / contract Consent
Training registration Contract performance Consent
Standards consultation submissions Consent Consent (certain legitimate use)
Site security (server/log data) Legitimate interest Certain legitimate use
Regulatory recordkeeping Legal obligation Legal obligation

We do not use personal data for solely automated decisions with legal or similarly significant effects.

Consent may be withdrawn at any time by contacting CONTACT_AT_ODA3_DOT_ORG. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where a registered DPDP Consent Manager becomes available, you may also manage consent through that channel. Where processing relies on legitimate interest, we can provide the balancing rationale on request.

2.3 Notably Absent: Data We Do Not Collect

We do not sell personal data. We do not knowingly collect precise geolocation or biometric data. We do not build advertising profiles or conduct cross-site behavioral advertising. We do not currently use advertising, cross-site tracking or behavioural-profiling cookies. Optional categories remain disabled unless affirmatively accepted and actually configured.


PART 3 — Use & Protection

3.1 How We Share Data

We do not sell personal data. We share it only as necessary with: hosting, productivity, identity and email/CRM providers, including Microsoft or Google where selected for the applicable service; payment processors, including Stripe, Razorpay or PayPal where selected for a transaction, training or certification delivery partners (only where you've registered for a jointly delivered program), legal authorities where required by law, professional advisers, and a successor entity in a merger or restructuring, subject to equivalent commitments. Current provider categories and named candidate/selected providers are listed in Schedule C. Inclusion does not mean every provider is active or receives every data category.

3.2 International Transfers

ODA3 is India-based. Microsoft, Google, Stripe, Razorpay and PayPal may process data in jurisdictions outside India depending on the selected service, account configuration and transaction route. ODA3 will confirm production configurations and apply the transfer terms, contractual safeguards and data-minimisation measures required for the relevant jurisdiction. Provider inclusion does not mean the provider is active for every visitor.

3.3 Security

We apply administrative, technical, and physical safeguards appropriate to the data held — access controls, encryption in transit, monitoring, and vendor security requirements once vendors are selected. "Reasonable" safeguards means measures appropriate to the nature of the processing, applicable law, and organizational risk. No system is completely secure, and we do not claim otherwise. We maintain internal records of processing activities as required by applicable law.

3.4 Retention

Baseline retention is a minimum of one year from the date of processing, consistent with the DPDP Rules, 2025 — a floor, not a ceiling. Specific record types follow the periods in Schedule B.

3.5 Law Enforcement & Regulatory Requests

We disclose personal data in response to valid legal process — court orders, regulatory requests, or law enforcement requests — only where required by law, after legal review, and limited to the minimum necessary to comply.


PART 4 — Special Processing (ODA3-Specific)

4.1 Standards Development & Research Participation

If you submit feedback through a standards consultation, public comment period, expert panel, or framework issue report (UAIF™, AI-IRF™, GAISSF™, or future frameworks):

  • Submissions may be reviewed and, where the consultation's stated terms allow, incorporated in summarized or attributed form into framework revisions.
  • Anonymous submissions are accepted where the mechanism allows it.
  • Submission does not itself create a confidentiality obligation on ODA3 unless separately agreed in writing.

4.2 Intellectual Property in Feedback

Corrections, schemas, mappings, translations, and examples you submit are governed, for licensing and ownership purposes, by the terms stated in the relevant submission mechanism and by the GAISSF Ecosystem License (GEL) v1.0 where the contribution relates to licensed framework content. This section addresses privacy in the submission process only — it does not modify GEL terms.

4.3 Publication & Download Analytics

Downloading publications, schemas, cheat sheets, or documentation may require registration. We log download activity (which document, when) for security purposes. We do not currently run aggregate usage analytics on this activity; if introduced, it will be described here and maintained in a form that does not reasonably identify individual users.

4.4 Training & Certification Data

Covers course enrollment, attendance, assessment/exam results, and certificates issued. Where certification requires identity verification, we collect only what's needed to confirm the credential is issued to the correct individual. Certification/audit records are retained per Schedule B. Depending on the service, ODA3 may act as a Data Fiduciary/Controller (e.g., training registrations) or as a Data Processor acting on a client's instructions (e.g., contracted assessment work), with roles specified in the relevant agreement.

4.5 AI-Assisted Functionality

We do not currently operate an AI chatbot, AI-assisted search, or automated document-processing feature that processes personal data on the public Site. If this changes, this section will be updated before launch to describe what's AI-assisted, what human review applies, and that we do not use AI to make automated decisions with legal or similarly significant effects on individuals.

4.6 User Accounts / Future SaaS / Member Portal

Not currently offered. If introduced, this section will be updated with account creation, authentication, credential security, and deletion provisions before that feature launches.

4.7 Security Logging

Server and security logs are collected for abuse detection, DDoS protection, fraud prevention, rate limiting, and incident investigation, without disclosing specific operational configurations.


PART 5 — Individual Rights

5.1 India (DPDP Act, 2023)

Access, correction, erasure, grievance redressal (resolution no later than 90 days, per the DPDP Rules, 2025), right to nominate a representative, right to withdraw consent as easily as it was given.

5.2 EEA/UK (GDPR)

Access, rectification, erasure, restriction, portability, objection (including to direct marketing), withdraw consent, complain to your supervisory authority.

5.3 California (CCPA/CPRA)

Know, delete, correct, opt out of sale/sharing (we do not sell or share personal data as defined under CCPA/CPRA), non-discrimination, use of an authorized agent. We honor recognized Global Privacy Control signals as a sale/share opt-out.

5.4 How to Exercise Your Rights

Contact CONTACT_AT_ODA3_DOT_ORG. We may verify your identity before acting. Full procedure, including appeal paths (Data Protection Board of India for DPDP matters; your local supervisory authority for GDPR matters), in Schedule E.

5.5 Children's Privacy

Not directed at children. We do not knowingly collect data from individuals under 18 (DPDP Act threshold). If we learn otherwise, we delete it on request.

The Site may link to standards bodies, government resources, or partner sites. We're not responsible for their privacy practices.


PART 6 — Administration

6.1 Data Breach Handling

We follow an incident-response process (containment, assessment, remediation) and notify affected individuals and/or the Data Protection Board of India, or other regulators, where legally required.

6.2 Changes to This Policy

Material changes are reflected in an updated "Last Updated" date and a Policy Update History entry. We do not silently expand data use without updating this Policy first. This Policy is reviewed at least annually, or sooner following a material change in our data practices or in applicable law.

6.3 Governing Law

Governed by the laws of India. Courts at New Delhi have exclusive jurisdiction, subject to rights available to you under your own jurisdiction's law.

6.4 Policy Update History

Effective Date Summary
13 July 2026 Initial publication; cookie consent, grievance channel and provider disclosures reconciled.

Schedules

A — Cookie Notice: Strictly necessary storage supports security, navigation, theme and recording the consent choice. The active banner offers “Essential only” and “Accept optional cookies.” Optional services must remain disabled until affirmative consent and must be documented here before activation. No advertising or cross-site behavioural tracking is currently enabled.

B — Data Retention Schedule (defaults):

Record Type Retention
Contact/inquiry data 3 years after last interaction
Newsletter subscription Until unsubscribe + 30 days
Download Center registration 3 years after last download
Training/course records 5 years after course completion
Certification/audit records 10 years after issuance
Security/server logs 1 year minimum (DPDP baseline); 2 years preferred
Financial/tax records Per applicable Indian statutory retention period

C — Third-Party Service Providers: Microsoft and Google may support hosting, productivity, identity or communications; Stripe, Razorpay and PayPal may process payments. Actual use depends on production configuration and transaction route. These providers do not necessarily receive every category of data. Their independent notices and contracted processor terms apply to their processing roles.

D — International Data Transfers: Processing locations depend on the configured Microsoft, Google, Stripe, Razorpay or PayPal service. ODA3 will document the active route and applicable contractual or statutory safeguard before enabling a service that transfers personal data internationally.

E — Data Subject Rights Procedure: Submit requests to CONTACT_AT_ODA3_DOT_ORG; identity verification may be required; acknowledgment and 90-day resolution per DPDP Rules, 2025; appeal to the Data Protection Board of India (DPDP matters) or your local supervisory authority (GDPR matters).

F — AI & Automated Processing Notice: Reserved — not applicable; no AI feature is currently live.

G — Security & Incident Disclosure Principles: High-level only — access controls, encryption in transit, monitoring — no operational specifics disclosed.


Publication Readiness and Notably Absent

  • The named Grievance Officer appointment has not yet been published; CONTACT_AT_ODA3_DOT_ORG is the interim operational contact.
  • Final production configurations for Microsoft, Google, Stripe, Razorpay and PayPal have not been represented as universally active.
  • No claim is made that the Site is risk-free, that every international transfer mechanism is identical, or that the policy replaces jurisdiction-specific legal advice.
  • Final external legal-counsel sign-off is not represented as completed.