Privacy Policy
Last updated: 11 July 2026
This policy explains how CHITRAM.AI PRIVATE LIMITED (“Ojas”, “we”, “us”) handles personal data on Ojas.Plus, in line with India’s Digital Personal Data Protection Act, 2023 and other applicable law. It covers learners who use the Ojas Academy, webinars, consultations, and productized services; experts and partners who teach or advise on the platform; and visitors who register interest in a future ready-made business.
1. What Ojas.Plus is
Ojas.Plus is an education and brand-incubation platform: an educational platform, an expert consultation desk, and a productized-services builder. We help you learn to build a brand of your own.
We are not a manufacturer, a lender, or a compliance filer. Any project report, formulation card, or similar dossier we generate is a draft that requires review and sign-off by a licensed professional before you rely on it. You can browse the published ready-made businesses and register interest in one; buying one is not yet live.
2. Data we collect
- Account data — name, email, password (stored as a salted hash), timezone, locale, and organisation membership.
- Enquiry & registration data — what you tell us when you register for a webinar, ask about a course or service, or register interest in a future ready-made business: your name, contact details, and what you’re looking for.
- Learning data — the courses and sessions you view, your progress, and the briefs you share with an expert so a consultation or service can be delivered.
- Payment data — where you buy a paid course, consultation, or service: amounts, currency, payment status, and provider references. Card and UPI details go directly to the payment provider; we never see or store them.
- Technical data — IP address, browser type, and request logs used for security, rate limiting, and debugging.
3. How we use data
We use personal data to:
- run the service — register you for webinars, give you access to courses, and deliver consultations and productized services you request;
- deliver paid services you have bought, and invoice them on the terms quoted to you before work began;
- send transactional communication — registration confirmations, session reminders, and updates about a course, consultation, or service you asked for;
- keep the platform safe — fraud prevention, abuse detection, rate limiting, and audit logging of sensitive actions; and
- meet legal obligations, including tax and accounting.
We do not sell personal data, and we send no registration, learning, or order record to any advertising network. The page-view analytics the site can load is a separate matter, and the Meta pixel is an advertising product — Cookies and analytics says exactly what it sends and how to block it.
4. Legal basis
We process data with your consent (given when you register, create an account, or purchase a service) and for certain legitimate uses recognised by law, such as complying with legal obligations and responding to emergencies. You may withdraw consent at any time; services that depend on that data may stop working once you do.
5. Who we share data with
- Experts and consultants see the briefs and enquiries assigned to them so they can deliver the session or service you requested — never another learner’s data.
- Payment providers (such as Razorpay and Cashfree) process payments and refunds for paid courses and services.
- Service providers host our infrastructure and deliver email on our instructions, under contracts that restrict their use of the data.
- Other Ojas products — where you choose to move into a live sibling (such as Ojas Legal or Ojas Loans), your Ojas identity carries across so you don’t sign up again; each product handles your data under its own policy.
- Authorities, where the law requires us to disclose.
6. Cookies and analytics
Two cookies are ours, and the product needs both:
- a session cookie that keeps you signed in; and
- a preference cookie that remembers your theme so pages paint correctly on first load.
Your browser also keeps a cart token and a few interface preferences in its own local storage, on your device.
Analytics, stated plainly. This site is built to load Google Analytics 4 and the Meta (Facebook) pixel. They load only on a deployment that has been given a measurement id or a pixel id and has analytics switched on; with neither configured, no Google or Meta script is loaded and nothing is sent to either. Where they are configured they set their own cookies, and the only thing our code tells them is which page you opened — no registration, learning, or order record is passed to them, because nothing on this site calls them with one. Google and Meta then collect their own technical details, such as your IP address and browser, and may use what they collect to measure and target advertising on other sites.
There is no cookie consent banner here, and we do not detect a Do Not Track or Global Privacy Control signal. Saying otherwise would be a promise the code does not keep. To stop the analytics scripts, block or clear cookies and scripts for this site in your browser settings, or use a tracking-blocker extension or Google’s Analytics opt-out add-on — the site works normally with all of it blocked. Payment providers may set their own cookies on their checkout components, governed by their policies.
7. How long we keep data
Account data is kept while your account is active. Enquiry, order, and invoice records are kept for as long as tax and accounting law requires, typically eight years in India. Audit records of sensitive actions are kept alongside the records they concern. When data is no longer needed and no legal duty to keep it remains, we remove it or irreversibly anonymise it — and where that clean-up is not yet automatic for a given record, we do it on request rather than pretending a schedule runs.
8. Your rights
You can:
- access and correct your data from your account settings;
- ask for a copy of your data, or for erasure where we have no legal duty to keep it;
- withdraw consent for non-essential processing; and
- raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied with our response.
Requests go to privacy@ojas.plus — we respond within the timelines the law sets.
9. Security
Data is encrypted in transit, passwords are stored as salted hashes, access is scoped per tenant so one customer can never read another’s data, sensitive actions are audit-logged, and documents are served from private storage with ownership checks. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.
10. Children
Accounts and enquiries are for adults (18+). The platform is intended for learning and building a business and is not directed at children.
11. Cross-border processing
Where a service provider processes data outside India, we do so only as permitted by applicable law and under contracts that protect the data to the standards of this policy. We are not making a data-residency guarantee on this page: our hosting regions are not settled yet, and when they are we will name them here rather than leave you to assume.
12. Changes to this policy
We may update this policy as the product and the law evolve. Material changes are notified by email or in-product notice.
13. Contact and grievances
Privacy questions and grievances: privacy@ojas.plus. General support: hello@ojas.plus or the contact page. Postal correspondence reaches us at the registered office of CHITRAM.AI PRIVATE LIMITED.