WhatsApp

Privacy Policy

DATA PRIVACY POLICY, PROCEDURES &
STANDARD OPERATING PROCEDURES

1. Policy Statement

1. Policy Statement

1. Policy Statement

Powered by Dreamtime Learning (DTL) is committed to maintaining the highest standards of data privacy, technical security, and regulatory compliance across its B2B school transformation ecosystem, including prospective school founders, partner K–12 institutions, preschool franchisees, educators, and institutional technology users. DTL operates with full transparency regarding its dual role as a Data Fiduciary for B2B partner leads and as a Data Processor supplying technology and curriculum operating systems to partner schools in full alignment with the Digital Personal Data Protection Act, 2023.

Powered by Dreamtime Learning (DTL) is committed to maintaining the highest standards of data privacy, technical security, and regulatory compliance across its B2B school transformation ecosystem, including prospective school founders, partner K–12 institutions, preschool franchisees, educators, and institutional technology users. DTL operates with full transparency regarding its dual role as a Data Fiduciary for B2B partner leads and as a Data Processor supplying technology and curriculum operating systems to partner schools in full alignment with the Digital Personal Data Protection Act, 2023.

2. Objectives

2. Objectives

2. Objectives

B2B Governance: Ensure lawful, fair, and transparent processing of institutional partner data and prospective lead information.

Role Clarity: Define clear data fiduciary and data processor boundaries between DTL and partner school entities.

Platform Security: Safeguard B2B platform data, CRM records, teacher training metrics, and institutional analytics against unauthorized access.

Robust SOPs: Establish robust SOPs for data processing agreements, multi-tenant cloud isolation, and B2B vendor management.

Regulatory Alignment: Maintain full compliance with Indian data protection legislation and institutional best practices.

B2B Governance: Ensure lawful, fair, and transparent processing of institutional partner data and prospective lead information.

Role Clarity: Define clear data fiduciary and data processor boundaries between DTL and partner school entities.

Platform Security: Safeguard B2B platform data, CRM records, teacher training metrics, and institutional analytics against unauthorized access.

Robust SOPs: Establish robust SOPs for data processing agreements, multi-tenant cloud isolation, and B2B vendor management.

Regulatory Alignment: Maintain full compliance with Indian data protection legislation and institutional best practices.

3. Scope

3. Scope

3. Scope

This policy applies across all B2B operational touchpoints:
Prospective Partners & Applicants: Applies to school owners, founders, franchise applicants, and institutional leads.

Partner School Personnel: Applies to enrolled school administrators, management personnel, and teachers participating in DTL training.

DTL B2B Teams: Applies to internal operations, sales teams, AIQ platform developers, and technical support engineers.

Third-Party Processors: Applies to cloud service providers, CRM platforms (Zoho), and analytics vendors processing data for Powered by DTL.

This policy applies across all B2B operational touchpoints:
Prospective Partners & Applicants: Applies to school owners, founders, franchise applicants, and institutional leads.

Partner School Personnel: Applies to enrolled school administrators, management personnel, and teachers participating in DTL training.

DTL B2B Teams: Applies to internal operations, sales teams, AIQ platform developers, and technical support engineers.

Third-Party Processors: Applies to cloud service providers, CRM platforms (Zoho), and analytics vendors processing data for Powered by DTL.

4. Categories of Data Collected

4. Categories of Data Collected

4. Categories of Data Collected

4.1 Prospective Partner & Lead Data

4.1 Prospective Partner & Lead Data

4.1 Prospective Partner & Lead Data

Applicant Information: Founder full name, professional email address, phone number, city, proposed school location, investment capacity, enquiry type, and communication records.

Applicant Information: Founder full name, professional email address, phone number, city, proposed school location, investment capacity, enquiry type, and communication records.

4.2 Institutional & Operator Data

4.2 Institutional & Operator Data

4.2 Institutional & Operator Data

Organizational Records: Partner school name, institutional registration details, billing address, contract history, fee structures, and authorized management contacts.

Organizational Records: Partner school name, institutional registration details, billing address, contract history, fee structures, and authorized management contacts.

4.3 Platform & AIQ Intelligence Data

4.3 Platform & AIQ Intelligence Data

4.3 Platform & AIQ Intelligence Data

System Analytics: User credentials for the Dreamtime AIQ platform, teacher training module completion status, portal usage metrics, and institutional performance analytics.

System Analytics: User credentials for the Dreamtime AIQ platform, teacher training module completion status, portal usage metrics, and institutional performance analytics.

5. Consent & Rights of Data Principals

5. Consent & Rights of Data Principals

5. Consent & Rights of Data Principals

5.1 Business Consent

5.1 Business Consent

5.1 Business Consent

Explicit consent is obtained from prospective school owners prior to capturing lead information through web enquiry forms, call scheduling calendars, or chat widgets. Partners may withdraw consent or request lead deletion prior to contract execution.

Explicit consent is obtained from prospective school owners prior to capturing lead information through web enquiry forms, call scheduling calendars, or chat widgets. Partners may withdraw consent or request lead deletion prior to contract execution.

5.2 Rights of Institutional Partners

5.2 Rights of Institutional Partners

5.2 Rights of Institutional Partners

Right to Access: Partners may request summaries of institutional and lead personal data held by DTL.

Right to Correction: Partners may request updating of inaccurate contact or organizational details.

Right to Erasure: Partners may request deletion of non-essential business records upon contract expiry or lead closure.

Right to Grievance Redressal: Partners may submit privacy queries or complaints for prompt resolution.

Right to Access: Partners may request summaries of institutional and lead personal data held by DTL.

Right to Correction: Partners may request updating of inaccurate contact or organizational details.

Right to Erasure: Partners may request deletion of non-essential business records upon contract expiry or lead closure.

Right to Grievance Redressal: Partners may submit privacy queries or complaints for prompt resolution.

6. Data Protection Principles & Platform Security

6. Data Protection Principles & Platform Security

6. Data Protection Principles & Platform Security

Data Minimization: Lead and institutional data collection is restricted strictly to details required for business evaluation, school transformation services, and platform operation.
Multi-Tenant Logical Isolation: All B2B databases and AIQ cloud platforms utilize AES-256 encryption at rest, TLS 1.3 in transit, and strict multi-tenant database separation to prevent cross-institutional data access.

Role-Based Access Control: Administrative access to B2B platforms and CRM records is governed by strict Role-Based Access Control (RBAC). Access logs are maintained for one year for audit compliance.

Mandatory Data Processing Agreements: All third-party software vendors, cloud hosts, and sub-processors must execute binding Data Processing Agreements (DPAs) incorporating strict security and confidentiality terms.

Student Privacy Enforcement: When supplying software or curriculum systems to partner schools, DTL enforces technical controls prohibiting student tracking, commercial profiling, or data monetization.

Data Minimization: Lead and institutional data collection is restricted strictly to details required for business evaluation, school transformation services, and platform operation.
Multi-Tenant Logical Isolation: All B2B databases and AIQ cloud platforms utilize AES-256 encryption at rest, TLS 1.3 in transit, and strict multi-tenant database separation to prevent cross-institutional data access.

Role-Based Access Control: Administrative access to B2B platforms and CRM records is governed by strict Role-Based Access Control (RBAC). Access logs are maintained for one year for audit compliance.

Mandatory Data Processing Agreements: All third-party software vendors, cloud hosts, and sub-processors must execute binding Data Processing Agreements (DPAs) incorporating strict security and confidentiality terms.

Student Privacy Enforcement: When supplying software or curriculum systems to partner schools, DTL enforces technical controls prohibiting student tracking, commercial profiling, or data monetization.

7. Standard Operating Procedures (SOPs)

7. Standard Operating Procedures (SOPs)

7. Standard Operating Procedures (SOPs)

The DPDP SOP contains the following sections
1: Lead Collection & Consent: Present clear, itemized consent notices on all web forms, chat widgets, and meeting scheduling links. Collect only necessary business fields.

2: Platform Security & Data Isolation: Maintain strict logical database boundaries for each partner school on the Dreamtime AIQ platform. Conduct annual Data Protection Impact Assessments (DPIAs).

3: Access Control & Usage Rules: Implement role-based permissions for account managers and support engineers. Maintain audit logs of access to partner school records.

4: Contractual Retention & Erasure: Retain B2B partner records for the duration of the contract plus statutory periods. Delete or anonymize prospective lead data when enquiries are closed.

5: Incident & Breach Response: Immediately contain any suspected B2B data exposure. Notify affected partner school management and the Data Protection Board of India within statutory timelines.

6: Staff Training & Partner Onboarding: Conduct annual privacy training for B2B sales and technical staff. Provide privacy orientation for partner school administrators during onboarding.

The DPDP SOP contains the following sections
1: Lead Collection & Consent: Present clear, itemized consent notices on all web forms, chat widgets, and meeting scheduling links. Collect only necessary business fields.

2: Platform Security & Data Isolation: Maintain strict logical database boundaries for each partner school on the Dreamtime AIQ platform. Conduct annual Data Protection Impact Assessments (DPIAs).

3: Access Control & Usage Rules: Implement role-based permissions for account managers and support engineers. Maintain audit logs of access to partner school records.

4: Contractual Retention & Erasure: Retain B2B partner records for the duration of the contract plus statutory periods. Delete or anonymize prospective lead data when enquiries are closed.

5: Incident & Breach Response: Immediately contain any suspected B2B data exposure. Notify affected partner school management and the Data Protection Board of India within statutory timelines.

6: Staff Training & Partner Onboarding: Conduct annual privacy training for B2B sales and technical staff. Provide privacy orientation for partner school administrators during onboarding.

8. Accountability & B2B Governance

8. Accountability & B2B Governance

8. Accountability & B2B Governance

Powered by DTL maintains a designated B2B Compliance Officer to oversee institutional privacy, audit sub-processors, and resolve partner grievances.

Powered by DTL maintains a designated B2B Compliance Officer to oversee institutional privacy, audit sub-processors, and resolve partner grievances.

9. Policy Review & Updates

9. Policy Review & Updates

9. Policy Review & Updates

This policy is reviewed annually and published on the Powered by DTL website.

This policy is reviewed annually and published on the Powered by DTL website.

10. DESIGNATED DATA PROTECTION & GRIEVANCE DIRECTORY

10. DESIGNATED DATA PROTECTION & GRIEVANCE DIRECTORY

10. DESIGNATED DATA PROTECTION & GRIEVANCE DIRECTORY

For any privacy queries, consent withdrawal, or grievance redressal, parents and users may directly contact our designated privacy officers below:

For any privacy queries, consent withdrawal, or grievance redressal, parents and users may directly contact our designated privacy officers below:

Designated Role

Contact Channels

Official Address

B2B Compliance Officer

Bandra West, Mumbai, Maharashtra, 400050

Data Protection Officer (Group)

Bandra West, Mumbai, Maharashtra, 400050

Preschool Enquiries

High School Enquiries

Bandra West, Mumbai, Maharashtra, 400050.

connect@poweredbydtl.com

Preschool Enquiries

High School Enquiries

Bandra West, Mumbai, Maharashtra, 400050.

connect@poweredbydtl.com

Preschool Enquiries

High School Enquiries

Bandra West, Mumbai, Maharashtra, 400050.

connect@poweredbydtl.com