Overview and Legal Context
Entri Software Private Limited (hereinafter referred to as “Entri”, “We”, “Us”, or “Our”) is committed to securing the digital and physical privacy of all individuals applying for or participating in The Generalist Program (the “Program”). This Privacy Policy operates as a standalone statutory document detailing our protocols for the collection, processing, usage, transmission, storage, and eventual erasure of personal data.
This policy is formulated in direct alignment with the provisions of the Digital Personal Data Protection Act, 2023 (DPDP Act) and any regulatory framework prescribed under associated Indian information technology and data protection laws. Entri acts as the designated “Data Fiduciary” under the DPDP Act for all personal data processing actions executed in relation to this Program.
The Scope of the Policy
Unlike general online edtech platforms, this Program operates via an intensive, immersive offline framework inside our corporate facilities. Consequently, this Privacy Policy governs:
- Data collected through the application domain (https://thegeneralist.club/).
- Physical, behavioral, and video telemetry data captured while operating on-site within our physical corporate infrastructure.
Categories of Personal Data Collected
To facilitate admissions, administrative scaling, security protocols, and corporate networking, we collect the following metrics:
Applicant Demographics and Professional Data: Full legal name, structural contact info (email, telephone number), permanent/temporary residential address, career profiles, GitHub/LinkedIn portfolios, and structural text-based application query responses.
Media & Audio-Visual Applications: The mandatory 90-120 second video introduction file submitted by the applicant via camera or mobile link during the selection cycle.
Physical Premises Logs and Security Telemetry: Physical entrance time logs, RFID badge scans, network traffic data generated via corporate Wi-Fi connections, and continuous CCTV surveillance video footage captured across all shared environments, entrances, and workspaces within the Thrikkakara corporate headquarters.
Transactional Data: Payment identifiers, structural transactional statuses, and invoicing data processed via external, RBI-regulated gateway partners. Entri does not store card CVVs or bank accounts directly on its localized databases.
Statutory Ground for Processing (Lawful Basis)
We process personal data strictly under valid lawful grounds recognized by Section 4 of the DPDP Act 2023:
Explicit Consent: Obtained via affirmative click-wrap confirmation mechanisms during application submission or financial booking checkout.
Specified Legitimate Uses: Processing physical logs, surveillance footage, and operational network monitoring data to secure corporate assets, protect corporate trade secrets, ensure workplace safety, and maintain strict physical compliance within the corporate offices.
Purpose of Processing and Use of Information
Your personal data is leveraged exclusively to satisfy the following corporate mandates:
- Executing comprehensive admissions evaluations, filtering potential candidates, and coordinating live admissions interviews.
- Administering daily logistical operations, scheduling mentorship tables, tracking cohort attendance, and executing spatial security monitoring inside the corporate offices.
- Curating “Demo Day” profile lists to present candidate capstone projects to prospective investors, founders, and venture entities.
- Defending the legal interests of Entri, investigating code of conduct violations, complying with statutory judicial directives, or mitigating security risks.
Data Retention, Minimization, and Compulsory Erasure Mandate
Entri operates a strict data minimization schedule to guarantee that personal information is not retained longer than legally required for the fulfillment of its designated purposes:
Rejected Applicants: To prevent unauthorized data hoarding and satisfy the spirit of the DPDP Act, all video files (90-120 second application clips) and descriptive written samples submitted by unsuccessful applicants shall be securely and completely purged from all active Entri servers and cloud instances within sixty (60) calendar days following the official public announcement of the final cohort configuration.
Enrolled Participants: Personal profiles, educational milestones, and transaction accounts of active participants will be preserved for the dynamic duration of the Program and for up to one (1) fiscal year post-graduation to support continuous career placement assistance, alumni networking, and financial audit verification.
Surveillance Footage Retention: On-site CCTV surveillance records are automatically overwritten, purged, or structurally zeroed out on a standard rolling thirty (30) day loop, unless a specific segment is legally preserved under judicial hold, POSH complaint review, or law enforcement investigation requirements.
Contractual Transmission and Third-Party Disclosures
We protect your data privacy. Your personal information will never be commoditized, bartered, or leased. Information sharing is strictly confined to the following professional contexts:
Strategic Data Processors: Cloud hosting infrastructure systems, secure email servers, and automated communication tools (e.g., WhatsApp Business APIs) contractually bound to process data solely under Entri's strict operational mandates.
Demo Day Stakeholders: Profiles, CV summaries, and video demonstrations of the Capstone projects of active participants will be explicitly shared with verified angel investors, venture capital syndicates, and recruiting corporate partners during final graduation modules.
Legal Mandates: We reserve the right to share information with law enforcement agencies, judicial tribunals, or regulatory state organs if compelled by valid judicial order or clear statutory directive.
Secure Storage and Cross-Border Data Translation
Data captured under this Program is primarily localized and securely managed on high-tier encryption servers based within India. If structural operations necessitate the deployment of global cloud architectures (such as Amazon Web Services or Google Cloud platforms), any cross-border transfer of personal data will be undertaken only to countries or territories other than those restricted or notified by the Central Government under Section 16 of the DPDP Act, 2023, and subject to any conditions prescribed thereunder.
Statutory Rights of the Data Principal
Subject to verified confirmation of identity, every individual processed under this Program holds structural legal rights under the DPDP Act 2023, including:
- The Right to Summary Access: To demand a structured summary of what personal data is actively held by Entri and verification of processing activities.
- The Right to Correction and Erasure: To correct typo errors or seek deletion of outdated profiling metrics.
- The Right to Consent Withdrawal: The legal privilege to revoke processing consent at any stage; noting that withdrawal directly invalidates ongoing participation or admission evaluation.
- The Right to Nomination: To name a specific legal proxy to manage or exercise data rights in the catastrophic event of death or total incapacity.
Grievance Redressal Mechanism
For any functional queries, complaints, perceived breaches, or requests to exercise Data Principal rights under this specialized policy, please direct formal communications to our designated Grievance Redressal Officer:
Retention for Legal Defence and Investigations
Notwithstanding the retention and erasure periods specified in Section 6, and notwithstanding any request for erasure or withdrawal of consent under Section 9, Entri reserves the right to retain personal data, transactional records, communications, and CCTV footage for such longer period as is reasonably necessary to: (a) establish, exercise, or defend a legal claim or anticipated claim; (b) comply with a statutory, regulatory, judicial, or law-enforcement obligation; or (c) conduct or conclude an internal investigation, including any inquiry under the POSH Act or the Code of Conduct. Data so retained will be processed solely for those purposes and securely erased once they are fulfilled.
Monitoring and Surveillance Consent
By applying for and participating in the Program, the Data Principal expressly acknowledges and consents to the monitoring activities reasonably necessary to secure the Company's premises, assets, and systems. This includes continuous CCTV surveillance across shared areas and entrances, RFID and entry/exit logging, and the logging and monitoring of traffic on the Company's corporate network and devices. Such monitoring is undertaken on the lawful basis of the Company's specified legitimate uses described in Section 4 and is limited to what is reasonably necessary for security, safety, and compliance purposes.
Limitation of Liability (Data and Security)
Entri implements reasonable technical and organisational security safeguards to protect personal data. However, to the maximum extent permitted by applicable law, Entri shall not be liable for any unauthorised access, loss, or disclosure of personal data that does not result from Entri's failure to maintain such reasonable safeguards, nor for the independent acts or omissions of third-party data processors engaged under appropriate contractual obligations. Any liability of Entri in connection with the processing of personal data shall be subject to the limitations and cap set out in the Unified Learner Agreement.
Updates to This Privacy Policy
Entri may amend, update, or revise this Privacy Policy from time to time to reflect changes in law, regulation, technology, or operational practice. Any material change will be notified through the application domain or by direct communication, and the “last updated” date will be revised accordingly. Continued participation in, or application to, the Program following such notification constitutes acceptance of the amended Privacy Policy.