1. Who is responsible
The intended data controller is [insert legal entity/operator], contactable at aaravchhaw@gmail.com. Add a postal address and representative details where legally required.
2. Information that may be collected
- Contact information: name, email, organisation and message when a user contacts Indoro.
- Pathway information: career interests, motivations, language readiness, constraints, work preferences and other questionnaire responses.
- Application or profile information: CV, education, skills or employment history only if a future secure feature explicitly collects it.
- Technical information: device, browser, approximate location, referral and usage events if analytics or hosting logs are enabled.
- Programme and research information: survey responses, workshop feedback and outcome verification where separately collected with notice and consent.
3. Pathways and Policy Pulse data
Indoro Pathways asks about education, career interests, applied skills, language readiness, workplace preparation, mobility constraints and policy priorities. The prototype generates results in the browser. If deployed with Netlify Forms or another collection service, only responses covered by an explicit research-consent choice should be used for de-identified policy analysis. The final notice must identify all hosting, analytics, form, AI and storage providers.
Do not submit passports, identity numbers, financial records, medical information or other sensitive documents unless the tool explicitly requests them through a secure and documented process.
4. Why information is used
Depending on the feature and legal basis, information may be used to provide recommendations, respond to enquiries, operate programmes, improve accessibility and accuracy, prevent misuse, evaluate outcomes, and develop evidence about corridor barriers.
Indoro should not make solely automated decisions that produce legal or similarly significant effects on users.
5. Research and policy use
Individual Pathways, Policy Pulse or survey responses should not be published in identifiable form without explicit permission. Where data informs policy research, Indoro should aggregate or de-identify it, document methodology, minimise collected fields and apply disclosure controls for small groups.
Employment outcomes should be verified with participant consent and reported with clear definitions. Testimonials require permission for the name, quotation, sector and any image used.
7. Retention
Contact enquiries should be retained only as long as needed to respond and manage the relationship. Research records should follow a documented retention schedule. Unsuccessful or inactive candidate data should not be kept indefinitely. Add specific periods before launch.
8. Security
Indoro should use access controls, encryption in transit, secure authentication, minimal permissions, vendor review, backups and incident procedures appropriate to the sensitivity of the data. No internet system is completely secure, so users should avoid sending highly sensitive documents through ordinary email.
9. User rights
Depending on applicable law, users may have rights to access, correct, delete, restrict or object to processing; withdraw consent; receive a portable copy; and complain to a regulator. Requests can be sent to the contact below. Identity may need to be reasonably verified.
10. Children and students
Indoro’s education work may involve students. The final service must define age thresholds, obtain parental or school consent where required, avoid behavioural advertising, collect only necessary information and provide age-appropriate explanations.
11. International transfers
Because Indoro concerns India, Korea and users in other locations, information may cross borders if cloud or AI providers are used. The final notice must identify transfer locations and safeguards required by applicable privacy law.
12. Changes to this notice
This notice may be updated as the service, research programme or legal obligations change. The effective date will be updated and material changes should be highlighted.
13. Contact
Privacy questions or requests can be sent to aaravchhaw@gmail.com. Add a dedicated privacy address and regulator information before launch where required.

