Draft policy · Professional review required
Privacy notice
Draft privacy notice for founder and professional review. Public data collection needs approved operator contact details, retention decisions and configured storage before launch.
Draft status and operator details
Draft prepared on 8 October 2026 for founder and professional review. It is not a statement that the initiative is legally compliant, and it is not an approved paid-service agreement.
Swapnil Sahoo Learning Lab is a founder-led professional education initiative hosted on swapnilsahoo.com, proposed to be operated by Dr. Swapnil Sahoo. It is presently unincorporated. An independent business contact, operator address and any applicable tax details must be confirmed before collecting enquiries or opening paid enrolment. Academic employers and institutions do not sponsor or operate the Lab by virtue of the founder's biography.
Interest and institutional enquiries
The enquiry form asks for your name, email address and programme of interest. Institutional enquiries also ask for the institution or organisation name. Your message is optional. The form requires confirmation that you are aged 18 or over and acknowledgement of enquiry processing. Please do not include sensitive personal, student or employer information.
These details are used to record and handle the enquiry, avoid duplicate records and discuss a proposed programme or institutional pilot. Optional permission to receive programme updates is separate, unticked by default and not required to enquire. Registering interest does not enrol you.
The current source field records the Lab page path and, if present, limited campaign parameters such as utm_source, utm_medium and utm_campaign. It is not cross-site tracking. Anti-spam controls use limited technical request information and keyed identifiers for rate limiting. Database and hosting providers may also maintain their own operational logs; the final notice must identify the chosen processors and their practices.
Invited learners and administration
The pilot learner workflow uses your name, email, authentication records, assigned programme or cohort, lesson progress, attendance entered by the instructor, submitted assignment text, assessment scores and feedback. These are used to provide access, teach, assess and determine completion. Account credentials and sessions are handled by the configured authentication service. Never submit passwords through an enquiry.
Learners may access their own assigned records. Authorised administrators and instructors access only what is needed to operate the pilot. Privileged changes can create audit records. Exports must remain restricted to authorised operators and be stored securely; they are not permission to reuse data for unrelated marketing or research.
Cookies, demonstrations and external services
Authentication requires essential session cookies. Demonstration notes may be kept in your browser for your convenience; they become an assessed submission only when you explicitly submit them through the learner workflow. Browser-stored notes can be removed using your browser's site-data controls.
The first release does not configure external marketing email, analytics, AI processing or payment collection. Your exercise is not sent to an AI provider by the Lab. External resource links have the destination provider's own privacy terms. Any later integration needs a revised notice, suitable processor arrangements and any required consent before use.
Certificates and public identity
A certificate verification link is shared using a non-guessable identifier. Verification is limited to certificate status, programme, issue date and whether it is demonstration data. A learner's display name is hidden unless that learner separately chooses to publish it. Email, assessment scores, feedback and submitted work are not public verification information.
Do not share your certificate link if you do not want another person to see even these minimal details. Public name consent can be changed through the learner workflow. A testimonial, photograph, recording or public learner story requires separate permission and is not a condition of completion.
Retention, withdrawal and requests
Proposed retention decisions for approval are a review of unconverted enquiries after six months and programme records after 24 months. Security, audit, accounting and certificate records need separate justified periods, processor settings and a deletion or anonymisation procedure. These are recommendations, not a claim that automatic deletion is already configured.
Before launch, the operator must publish an independently controlled business contact for withdrawal of optional marketing permission, access, correction, deletion and complaints, and approve a workable response process. No academic email or invented contact is substituted here. Some records may need to be retained for a documented legal or dispute purpose; this must be explained rather than used as an unlimited retention rule.
The initial offer is for adults only. Do not submit a child's information. If the operator learns that an enquiry or account belongs to someone under 18, it should restrict the record and arrange appropriate deletion or other legally reviewed handling.
Review before public collection
The final notice must name the actual operator and processors, explain hosting and any cross-border processing, state the approved retention schedule and give an accessible rights and grievance contact. Indian privacy rules have phased commencement; this draft does not assert that every provision is already effective or that the Lab is compliant. The launch checklist records dated primary sources for professional review.
Contact and enquiries →