Privacy Policy
Effective Date: 1 May 2026 | Last Updated: 7 May 2026
1. Data Controller
Resilient Sustainance Private Limited
Registered Office: Swaran Hans Tower, Palghar, Maharashtra 401203, India
Email: privacy@rsustain.com
Phone: +91-9343432443
For users in the United Kingdom or European Economic Area, our UK representative is Resilient Sustainance Limited, registered in England & Wales (Company No. 16530947).
2. Applicable Law
This policy is designed to comply with:
- India: Digital Personal Data Protection Act, 2023 (DPDPA)
- UK: UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018
- EU: General Data Protection Regulation (EU GDPR) 2016/679
3. Data We Collect
Account Data: Name, email, organisation (when you register for any RSustain platform).
Payment Data: Processed by Razorpay (India) or Stripe (UK/International). We do not store card details.
Usage Data: Pages visited, features used, browser type, IP address. Collected via server logs.
Assessment Data: Responses submitted through tools (BRSR Compass, Career Compass, etc.).
Contact Data: Information submitted via contact forms or emails.
4. Lawful Basis for Processing
- Contract: Processing necessary to deliver services you have purchased or registered for.
- Legitimate Interest: Website analytics, security monitoring, service improvement.
- Consent: Marketing communications (newsletter, alerts) — you may withdraw at any time.
- Legal Obligation: Compliance with regulatory requirements, tax records.
5. How We Use Your Data
- Delivering platform services (assessments, reports, courses, certificates)
- Processing payments and managing subscriptions
- Sending service-related communications
- Improving our platforms and user experience
- Complying with legal and regulatory obligations
6. International Data Transfers
Our servers are hosted in the European Union (Hostinger, Lithuania) and India (VPS). Payment processing involves:
- Razorpay: India-based processor. Data processed within India.
- Stripe: US-based processor with EU-US Data Privacy Framework certification.
Where data is transferred outside the UK/EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions.
7. Data Retention
- Account data: Retained while your account is active + 12 months after deletion request.
- Assessment data: Retained for 24 months unless you request earlier deletion.
- Server logs: 90 days.
- Payment records: 7 years (Indian tax compliance requirement).
8. Your Rights
Under DPDPA, UK GDPR, and EU GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
- Restrict processing in certain circumstances
- Data portability — receive your data in a structured format
- Object to processing based on legitimate interest
- Withdraw consent at any time for consent-based processing
To exercise any right, email privacy@rsustain.com. We will respond within 30 days.
9. Data Protection Officer
For data protection enquiries:
Data Protection Lead: privacy@rsustain.com
Resilient Sustainance Private Limited, Palghar, Maharashtra 401203, India
10. Third-Party Services
Our ecosystem platforms (Academy, Career Compass, GreenCampus, ResilientPulse, etc.) may have supplementary privacy notices. This policy covers all RSustain Group entities:
- Resilient Sustainance Private Limited (rsustain.com)
- Resilient Sustainance Limited (rsustain.co.uk)
- Resilient Sustainance LLC (rsustain.net)
- RSustain Carbon Private Limited (rsustain.org)
- Global Sustainability Solutions and Services QFZ LLC (gsustain.org)
11. Cookies
See our Cookie Policy for details on cookies and similar technologies.
12. Changes to This Policy
We may update this policy periodically. Material changes will be notified via email to registered users. Continued use constitutes acceptance.
13. Complaints
If you are unsatisfied with our response, you may lodge a complaint with:
- India: Data Protection Board of India (when constituted under DPDPA)
- UK: Information Commissioner’s Office (ICO) — ico.org.uk