Legal
Privacy Policy
Effective Date: 14 June 2026
1. Identity of the Data Fiduciary
This website, aakankshagupte.com (referred to as "Spoken From Soul," "we," "us," or "our"), is operated by Aakanksha Chitnis-Gupte, a sole proprietor based in Pune, Maharashtra, India. For the purposes of applicable data protection law, Aakanksha Chitnis-Gupte is the Data Fiduciary responsible for your personal data.
2. Legal Framework
This Privacy Policy is drafted in compliance with:
- The Information Technology Act, 2000 ("IT Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- The Digital Personal Data Protection Act, 2023 ("DPDP Act"), to the extent its provisions are in force.
Where a conflict exists between the IT Act rules and the DPDP Act, the DPDP Act shall prevail to the extent it is operative.
3. Categories of Personal Data We Collect
3.1 Data You Provide Voluntarily
- Identity Data: Full name, email address, phone number, and city of residence, provided when you create an account or submit an enquiry.
- Session Preference Data: Your selected modality, preferred session format (in-person or online), scheduling preferences, and any notes you share before or during a session.
- Referral Data: If you indicate how you heard about Spoken From Soul, we store that response.
- Payment Data: Transaction identifiers and payment confirmation data processed by our third-party payment gateway. We do not store full card numbers or bank account details on our servers.
3.2 Data Collected Automatically
- Analytics Data: We use Google Analytics 4 (GA4) to collect anonymised usage data, including pages visited, session duration, referral source, device type, and approximate geographic region. GA4 does not collect personally identifiable information by default, and we have not enabled any features that would do so.
3.3 Cookies
This website uses only essential, first-party cookies required for authentication and session management. We do not use advertising cookies or third-party tracking cookies. GA4 operates via a first-party measurement cookie (_ga) that contains no personally identifiable information.
4. Purposes and Legal Bases for Processing
We process your personal data for the following purposes:
- Account creation and authentication: To allow you to create an account, sign in, and manage your bookings.
- Session booking and delivery: To schedule, confirm, and deliver the session you have requested.
- Communication: To respond to your enquiries, send booking confirmations, and provide session-related follow-ups.
- Payment processing: To process and record payments for sessions booked through the platform.
- Website improvement: To understand how the website is used and to improve its design, content, and functionality via anonymised analytics.
Under the DPDP Act, the legal basis for processing data under purposes 1 through 4 is your consent, provided at the time of account creation or enquiry submission. The legal basis for purpose 5 is legitimate use for anonymised, non-identifiable analytics data.
5. Disclosure of Personal Data
We do not sell, rent, or trade your personal data. We may share your data only in the following limited circumstances:
- Legal obligation: Where disclosure is required by a court order, regulatory directive, or lawful government request under Indian law.
- Protection of rights: Where necessary to protect the rights, safety, or property of Spoken From Soul, its users, or the public.
- Service providers: With the third-party processors identified below (Section 5.1), solely for the purposes described.
5.1 Third-Party Data Processors
- Supabase, Inc. (San Francisco, USA): Provides authentication, database hosting, and backend infrastructure. Data is stored in Supabase's cloud infrastructure. Supabase acts as a data processor under our instructions.
- Google LLC (Mountain View, USA): Provides analytics services via Google Analytics 4. Data collected is anonymised and aggregated.
- Cloudflare, Inc. (San Francisco, USA): Provides DNS, CDN, and web application firewall services. Cloudflare may process request metadata (IP addresses, headers) transiently for security and performance purposes.
Where data is transferred to processors located outside India, such transfers are conducted in compliance with applicable cross-border data transfer provisions under the DPDP Act and any rules notified thereunder.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Enquiry data: Retained for 6 months from the date of submission, unless a session is subsequently booked.
- Account and session data: Retained for 3 years from the date of your last session or account activity, whichever is later.
- Payment records: Retained for 8 years in compliance with applicable Indian tax and financial record-keeping requirements.
Upon expiry of the applicable retention period, your data will be securely deleted or anonymised.
7. Your Rights
Under the DPDP Act, you have the following rights as a Data Principal:
- Right to Access: You may request a summary of the personal data we hold about you and the processing activities performed on it.
- Right to Correction: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure: You may request deletion of your personal data, subject to our legal obligations to retain certain records.
- Right to Withdraw Consent: You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to Grievance Redressal: You may raise a complaint with us regarding the processing of your data (see Section 11).
- Right to Nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act.
To exercise any of these rights, please contact us using the details provided in Section 11.
8. Security Measures
We implement reasonable security practices and procedures, as required under the IT Act and the DPDP Act, to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Authentication via Supabase with row-level security policies.
- Access to personal data restricted to the Data Fiduciary only.
- Regular review of security configurations.
9. Breach Notification
In the event of a personal data breach that is likely to cause harm to you, we will notify the Data Protection Board of India and affected Data Principals without unreasonable delay, in accordance with the DPDP Act and any rules prescribed thereunder.
10. Amendments
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. The updated policy will be posted on this page with a revised effective date. Where changes are material, we will notify registered users via email. Continued use of the website after the effective date constitutes acceptance of the revised policy.
11. Grievance Officer
In accordance with the IT Act and the DPDP Act, the Grievance Officer for this website is:
Aakanksha Chitnis-Gupte
Email: aakanksha@thevisionbeyondautism.com
The Grievance Officer will acknowledge your complaint within 48 hours and endeavour to resolve it within 30 days of receipt.