Privacy Policy
Effective Date: March 12, 2026
MRM Foundation (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you visit our website mrmfoundation.in, internship.mrmfoundation.in, register for programs, make donations, or interact with us in any way.
We comply with the **Digital Personal Data Protection Act, 2023 (DPDP Act)** and other applicable Indian laws. This policy applies to all personal data processed by us as a Data Fiduciary.
1. Personal Data We Collect
We collect only the data necessary for our charitable and educational objectives. This may include:
- Identity & Contact: Name, email address, phone number, address, date of birth / age
- Educational / Program: Educational qualifications, current institution, resume/CV, marksheets, ID proof, photographs (for verification / certificates)
- Donation / Payment: Transaction ID, amount, payment method type (we do **not** collect or store card numbers, CVV, UPI PIN, netbanking credentials, etc.)
- Technical: IP address, browser type, device information, pages visited, timestamps (for security and basic analytics)
- Voluntarily Provided: Any information you submit via forms, emails, WhatsApp, or messages (e.g., feedback, queries, stories)
2. How We Collect Your Data
- Directly from you: Through registration forms, donation pages, contact forms, emails, WhatsApp, or in-person interactions
- Automatically: Via cookies and server logs (see our Cookie Policy)
- From third parties: Razorpay (for payment processing), email service providers, or government portals (when verifying eligibility)
3. Purposes of Processing
We process your personal data only for legitimate purposes connected to our charitable objects:
- Processing internship, scholarship, and program registrations & verifications
- Issuing certificates, communicating updates, sending program materials
- Processing voluntary donations and issuing tax-exemption receipts (if 80G registered)
- Maintaining basic analytics to improve website/services (aggregated/anonymized)
- Preventing fraud, abuse, or misuse of our services
- Complying with legal obligations (KYC, tax reporting, regulatory requests)
- Responding to your inquiries, grievances, or support requests
4. Sharing & Disclosure
We share personal data only when necessary and under strict confidentiality:
- With Razorpay for secure payment processing (they process transaction data per their Privacy Policy)
- With service providers (email/SMS tools, cloud hosting, CA for compliance) under data processing agreements
- With government authorities, courts, or regulators when legally required
- We do **not** sell your data or share it for marketing purposes without explicit consent
We do **not** store sensitive financial data (full card details, UPI PINs, etc.). All payment-related processing is handled exclusively by Razorpay in compliance with RBI and PCI-DSS standards.
5. Data Security
We implement reasonable security safeguards (technical, organizational, physical) to protect your data from unauthorized access, loss, alteration, or breach. In the unlikely event of a data breach, we will notify affected individuals and the Data Protection Board of India as required under the DPDP Act.
6. Data Retention
We retain personal data only as long as necessary for the purpose collected or as required by law (e.g., financial/transaction records for 5–10 years per tax/RBI rules). After that, data is securely deleted or anonymized.
7. Your Rights under DPDP Act
You have the right to:
- Access, correct, or erase your personal data
- Withdraw consent (where processing is consent-based) – withdrawal does not affect prior lawful processing
- Grieve to us or escalate to the Data Protection Board of India
To exercise your rights, contact our Grievance Officer (details below). We will respond within the timelines prescribed under DPDP Rules.
8. Children's Data
If we process data of children (under 18 years), we obtain verifiable parental or guardian consent and avoid any processing that could cause harm (tracking, behavioral advertising, etc.).
9. International Transfers
If any data is processed outside India (e.g., cloud services), we ensure appropriate safeguards as required under the DPDP Act.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The revised version will be posted here with the updated effective date. Continued use of our website/services after changes constitutes acceptance.
Thank you for trusting MRM Foundation with your information.
We remain committed to using it solely to advance education and social welfare.
© MRM Foundation, Patna, Bihar | All rights reserved