Privacy Policy - Learning Management
System (LMS)
1.
Purpose and
Applicability
This Privacy Policy governs the collection, processing, storage, and protection of personal data of employees and authorized internal users (“Data Principals”) who access and use the Veedol Corporation Limited (VCL) Internal Learning Management System (“LMS”).
This LMS is strictly for internal organizational use and is not accessible to the public.
This Policy is framed in accordance with the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”).
2. Definitions (as per DPDP Act)
o Personal Data: Any data about an individual who is identifiable by or in relation to such data.
o Data Principal: An employee or authorized internal user whose personal data is processed.
o Data Fiduciary: VCL, which determines the purpose and means of processing personal data.
o Data Processor: Any third party processing personal data on behalf of the Data Fiduciary.
3.
Nature of Personal Data
Collected
3.1 Employee Identity Data
o Name
o Employee ID
o Official email ID
o Department, designation, reporting structure
o Location (office / plant / region)
3.2 Learning & Performance Data
o Course enrolments and completion status
o Assessment scores and certifications
o Learning progress, timestamps, and participation records
3.3 System & Access Data
o Login activity and access logs
o Device, browser, and IP address (for security and audit purposes)
Note: The LMS does not collect sensitive personal
data unrelated to learning or employment obligations.
4.
Purpose of Processing
Personal data is processed strictly for legitimate organizational purposes, including:
o Delivering mandatory and optional learning programs
o Tracking training completion and certifications
o Assessing skill readiness and compliance requirements
o Supporting internal audits, statutory compliance, and governance
o Ensuring system security, access control, and misuse prevention
5.
Lawful Basis for
Processing
Under the DPDP Act, personal data is processed based on:
o Employment-related purposes
o Legitimate use by the employer
o Consent, where explicitly required (e.g., optional learning programs, profile enhancements)
6.
Consent Management
Where consent is required:
o Consent is obtained digitally through the LMS
o Consent is specific, informed, and revocable
o Withdrawal of consent may limit access to certain non-mandatory features
Mandatory trainings linked to employment or statutory compliance do not require separate consent.
7. Data Sharing and Disclosure
Personal data is not sold, rented, or shared externally.
Data may be shared only with:
o Authorized HR, L&D, IT, Compliance, and Audit teams
o Approved LMS service providers acting as Data Processors, under contractual confidentiality and DPDP compliance obligations
o Statutory or regulatory authorities, when legally mandated
8.
Data Retention
Personal and learning data is retained:
o For the duration of employment, and
o Thereafter as required for legal, audit, or compliance purposes
Upon completion of the retention period:
o Data is securely deleted or anonymized
9.
Data Security Safeguards
VCL & Data processor implements reasonable security safeguards including:
o Role-based access control
o Authentication and authorization mechanisms
o Encryption of sensitive data
o Secure hosting and backup controls
o Periodic security reviews and access audits
10.
Rights of Data
Principals
In accordance with the DPDP Act, employees have the right to:
o Access their personal data
o Request correction or updating of inaccurate data
o Seek grievance redressal
o Nominate a representative (where applicable)
Requests can be raised through the contact details provided below.
11. Grievance
Redressal
Any grievance related to personal data processing may
be addressed to:
Grievance Officer Contact:
Name:
Email:
Address:
Grievances will be acknowledged and resolved within timelines prescribed under the DPDP Act.
12. Cross-Border
Data Processing
If LMS data is processed or stored outside India, appropriate safeguards are ensured in line with DPDP Act requirements and government notifications.
13. Children’s
Data
This LMS is intended solely for employees and authorized internal users.
It is not designed for individuals below 18 years of age.
14. Policy
Updates
This Privacy Policy may be updated periodically to reflect:
o Changes in law
o Organizational practices
o System enhancements
Material changes will be communicated through internal channels or LMS notifications.
15. Acknowledgement
By accessing and using the LMS, employees acknowledge that:
o They have read and understood this Privacy Policy
o Their personal data is processed in accordance with the DPDP Act and organizational policies
Internal Disclaimer
This document is an internal policy and forms part
of Veedol Corporation Limited information security
and data protection framework.
Date: