Privacy Policy - Learning Management System (LMS)

 

1.   Purpose and Applicability

This Privacy Policy governs the collection, processing, storage, and protection of personal data of employees and authorized internal users (“Data Principals”) who access and use the Veedol Corporation Limited (VCL) Internal Learning Management System (“LMS”).

 

This LMS is strictly for internal organizational use and is not accessible to the public.

 

This Policy is framed in accordance with the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”).

 

2.   Definitions (as per DPDP Act)

o    Personal Data: Any data about an individual who is identifiable by or in relation to such data.

o    Data Principal: An employee or authorized internal user whose personal data is processed.

o    Data Fiduciary: VCL, which determines the purpose and means of processing personal data.

o    Data Processor: Any third party processing personal data on behalf of the Data Fiduciary.

 

3.   Nature of Personal Data Collected

3.1 Employee Identity Data

o    Name

o    Employee ID

o    Official email ID

o    Department, designation, reporting structure

o    Location (office / plant / region)

 

3.2 Learning & Performance Data

o    Course enrolments and completion status

o    Assessment scores and certifications

o    Learning progress, timestamps, and participation records

 

3.3 System & Access Data

o    Login activity and access logs

o    Device, browser, and IP address (for security and audit purposes)

 

Note: The LMS does not collect sensitive personal data unrelated to learning or employment obligations.

 

4.   Purpose of Processing

Personal data is processed strictly for legitimate organizational purposes, including:

o    Delivering mandatory and optional learning programs

o    Tracking training completion and certifications

o    Assessing skill readiness and compliance requirements

o    Supporting internal audits, statutory compliance, and governance

o    Ensuring system security, access control, and misuse prevention

 

5.   Lawful Basis for Processing

Under the DPDP Act, personal data is processed based on:

o    Employment-related purposes

o    Legitimate use by the employer

o    Consent, where explicitly required (e.g., optional learning programs, profile enhancements)

 

6.   Consent Management

Where consent is required:

o    Consent is obtained digitally through the LMS

o    Consent is specific, informed, and revocable

o    Withdrawal of consent may limit access to certain non-mandatory features

 

Mandatory trainings linked to employment or statutory compliance do not require separate consent.

 

7.   Data Sharing and Disclosure

Personal data is not sold, rented, or shared externally.

Data may be shared only with:

o    Authorized HR, L&D, IT, Compliance, and Audit teams

o    Approved LMS service providers acting as Data Processors, under contractual confidentiality and DPDP compliance obligations

o    Statutory or regulatory authorities, when legally mandated

 

8.   Data Retention

Personal and learning data is retained:

o    For the duration of employment, and

o    Thereafter as required for legal, audit, or compliance purposes

 

Upon completion of the retention period:

o    Data is securely deleted or anonymized

 

9.   Data Security Safeguards

VCL & Data processor implements reasonable security safeguards including:

o    Role-based access control

o    Authentication and authorization mechanisms

o    Encryption of sensitive data

o    Secure hosting and backup controls

o    Periodic security reviews and access audits

 

10.    Rights of Data Principals

In accordance with the DPDP Act, employees have the right to:

o    Access their personal data

o    Request correction or updating of inaccurate data

o    Seek grievance redressal

o    Nominate a representative (where applicable)

 

Requests can be raised through the contact details provided below.

 

 

 

11. Grievance Redressal

Any grievance related to personal data processing may be addressed to:

 

Grievance Officer Contact:

Name:

Email:

Address:

 

Grievances will be acknowledged and resolved within timelines prescribed under the DPDP Act.

 

12. Cross-Border Data Processing

If LMS data is processed or stored outside India, appropriate safeguards are ensured in line with DPDP Act requirements and government notifications.

 

 

13. Children’s Data

This LMS is intended solely for employees and authorized internal users.

It is not designed for individuals below 18 years of age.

 

14. Policy Updates

This Privacy Policy may be updated periodically to reflect:

o    Changes in law

o    Organizational practices

o    System enhancements

 

Material changes will be communicated through internal channels or LMS notifications.

 

15. Acknowledgement

By accessing and using the LMS, employees acknowledge that:

o    They have read and understood this Privacy Policy

o    Their personal data is processed in accordance with the DPDP Act and organizational policies

 

Internal Disclaimer

This document is an internal policy and forms part of Veedol Corporation Limited information security and data protection framework.

 

 

                                                                                                                   Date: