Our Approach

Privacy is an important part of how SHTC delivers workplace training and compliance technology.

Organizations trust SHTC with information relating to their employees, training assignments, course progress and compliance records. We seek to collect and process only the information reasonably required to provide the platform and related services.

SHTC applies structured information-security and quality-management practices across its operations and service delivery.

ISO 27001 ISO 9001
Important distinction: SHTC’s general website forms and routine learning platform are not channels for filing a PoSH complaint or uploading complaint evidence. Use the Internal Committee or authorised channel communicated by the relevant employer.

Introduction

Insadec Services Private Limited operates its PoSH training and compliance-support services under the brand name “SHTC”. In this Privacy Policy, “SHTC”, “we”, “us” and “our” refer to Insadec Services Private Limited in relation to the SHTC services.

This Policy explains how we collect, use, store, disclose, protect and delete personal data when you visit www.shtc.co.in, use our learning management platform, participate in training or assessments, receive certificates, attend events, communicate with us or use our PoSH compliance-support services (together, the “Services”).

We are committed to processing personal data responsibly, transparently and securely in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 according to their phased commencement and applicability

Scope

This Policy applies to website visitors, prospective and existing clients, corporate administrators, learners, employees of client organisations, trainers, speakers, consultants, external Internal Committee members, vendors, job applicants and other individuals who interact with SHTC.

Separate contractual terms or notices may apply to employees, candidates, corporate clients or particular services. Where a more specific notice applies, that notice supplements this Policy for the relevant processing activity.

Our role in processing personal data

When SHTC determines the purpose

SHTC generally acts as the Data Fiduciary when it determines why and how personal data is processed, including for website enquiries, direct purchases, events, billing, recruitment, support, vendor administration and SHTC’s own business communications.

When a corporate client determines the purpose

Where an employer or corporate client provides employee information, assigns training, selects authorised administrators and decides how learning reports will be used, the client generally acts as the Data Fiduciary and SHTC processes the information as a Data Processor on the client’s documented instructions.

Corporate learners may also contact their employer for information about the employer’s purposes for assigning training or using learning records.

Case-support engagements

For external IC-member, advisory, mock-investigation or other case-support services, the respective roles and responsibilities of SHTC and the client depend on the written engagement. Complaint or inquiry information will be accepted only through an authorised process

Personal data we collect

Category Examples
Identity and professional information Name, employee or learner identifier, organisation, designation, department, entity, work location and preferred language.
Contact information Email address, telephone number, postal address and communication preferences.
Account information Username, account status, assigned organisation, authentication information and administrator relationship.
Learning and certification information Courses assigned, attendance, progress, completion, assessment responses and scores, feedback, acknowledgements, certificate number, issue date and verification status.
Client and compliance information Organisation details, workforce information, locations, Internal Committee information, training status, policy or audit information supplied by an authorised client.
Enquiry and support information Enquiries, service requests, proposals, correspondence, feedback, complaints and support records.
Transaction information Subscription, order, invoice, GST, payment-status and refund information. Payment-card or UPI credentials are processed by the relevant payment provider and are not intended to be stored by SHTC.
Technical and usage information IP address, browser, device, operating system, login date and time, pages or features used, security events, diagnostic information and cookie identifiers.
Event and recruitment information Registration, attendance, professional profile, qualifications, CV, references, interview information and accessibility requirements voluntarily provided.
PoSH case information Only under a separate authorised engagement: allegations, submissions, correspondence, witness details, interview notes, evidence, schedules and reports.

We do not ordinarily request Aadhaar, PAN, salary, bank-account information, health information, webcam recordings or PoSH complaint evidence from routine learners or website visitors. If such information is genuinely required for a specific service, we will explain the need and apply appropriate safeguards.

How we collect personal data

We may collect personal data:

  • Directly from you when you contact us, register, participate in training, complete an assessment, request support, attend an event, make a purchase or apply for a role;
  • From your employer, corporate administrator or another authorised representative when they enrol you or administer a programme;
  • Automatically through our website, learning platform, cookies, logs and security technologies;
  • From service providers such as hosting, webinar, identity, email, support and payment providers; and
  • From lawful public or professional sources where reasonably necessary for B2B communications, trainer verification or due diligence.

Why we process personal data

We process personal data only for specified purposes and on an applicable legal basis, including valid consent, certain legitimate uses recognised by law, performance of a contract, compliance with legal obligations or documented instructions from a client Data Fiduciary. We use data to:

  • respond to enquiries and prepare proposals or demonstrations;
  • create, authenticate and secure accounts;
  • enrol learners and deliver courses, assessments and certificates;
  • send training reminders and essential service communications;
  • provide authorised administrators with participation, completion, assessment and certification reports;
  • deliver external IC-member, policy, audit, advisory or case-support services under written engagement;
  • process subscriptions, invoices, payments, refunds and accounting records;
  • provide customer support and resolve technical issues;
  • improve service quality and understand aggregate usage;
  • detect fraud, account sharing, certificate misuse and cybersecurity threats;
  • send marketing communications where permitted and honour opt-outs;
  • comply with legal, tax, audit, regulatory and recordkeeping requirements; and
  • establish, exercise or defend legal claims and protect rights, security and safety.

We will not use personal data for an incompatible new purpose without providing appropriate information and obtaining consent where required.

Consent and withdrawal

Where processing is based on consent, we will seek a free, specific, informed, unconditional and unambiguous indication through clear affirmative action. The request will describe the personal data and specified purpose.

You may withdraw consent using the method communicated when consent was obtained or by contacting support@shtc.co.in. Withdrawal will not affect processing already lawfully undertaken. We may continue processing where another lawful basis or legal obligation applies. If the withdrawn information is necessary to provide a requested Service, we will explain the resulting limitation or termination of that Service.

Corporate learning accounts and reports

If your employer or organisation assigns an SHTC programme, authorised administrators may view information needed to administer the programme, including enrolment, participation, progress, completion, assessment score, reminders and certificate status.

The employer determines its independent use of those reports for training, compliance, workforce administration or governance. SHTC restricts administrator access according to the client account and may suspend access where misuse or unauthorised disclosure is suspected.

PoSH complaint and inquiry information

General training and LMS services are not channels for filing a PoSH complaint. Complaints must be submitted to the Internal Committee or other authorised channel communicated by the relevant employer.

Where SHTC is separately authorised to handle complaint or inquiry information, we apply enhanced safeguards appropriate to its confidential nature. These may include need-to-know access, confidentiality undertakings, segregation from routine learner records, secure transmission, restricted copying or downloading, access records and case-specific return, retention or destruction.

We do not use identifiable complaint, complainant, respondent, witness, conciliation or inquiry information for marketing, testimonials, demonstrations, public training or training general-purpose artificial-intelligence systems. Any learning derived from a case must be lawfully anonymised and appropriately authorised.

Cookies and similar technologies

We may use cookies or similar technologies to operate and secure the website and learning platform, remember preferences, diagnose errors and understand usage.

Cookie Category Purpose
Strictly necessary Authentication, session management, security, load balancing and privacy preferences.
Functional Remember language, display or other choices where enabled.
Analytics and performance Understand traffic, performance and feature usage where permitted.
Marketing Measure campaigns or advertising only where actually used and valid consent or another lawful basis applies.

Where required, non-essential cookies will remain disabled until you make a choice. You may use the cookie preference tool or browser controls to reject or delete cookies. Disabling necessary cookies may affect core functionality.

Sharing personal data

We may share personal data only where necessary and proportionate with:

  • the corporate client or authorised administrator that assigned or purchased the Services;
  • hosting, LMS, email, webinar, analytics, identity, payment, support, accounting and security providers;
  • authorised trainers, consultants, legal advisers, external IC members or investigators;
  • auditors, insurers and professional advisers under confidentiality obligations;
  • government bodies, courts, regulators or law-enforcement authorities where required or permitted by law; or
  • a lawful successor in a merger, restructuring or business transfer, subject to appropriate protections.

We do not sell personal data. Service providers are not permitted to use personal data for their own advertising merely because they process it for SHTC.

Service providers and Data Processors

We assess relevant service providers and use contractual or other appropriate safeguards. Depending on the service, these may address confidentiality, security, processing instructions, sub-processors, breach reporting, rights-request assistance, data location, retention and deletion.

A list of material processors or additional information may be provided to corporate clients where required by law or contract.

International processing and transfers

Personal data may be processed in India and, where necessary and disclosed, in other countries by approved providers or authorised personnel. Before cross-border access or transfer, we consider the purpose, recipient, destination, client instructions, contractual protections, security measures and applicable restrictions.

We will comply with restrictions or requirements prescribed by the Government of India and any stricter sector-specific obligation. Where European data-protection law applies, an appropriate transfer mechanism and supplementary safeguards will be used where required.

Data retention and deletion

We retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected or processed, to provide and administer the Services, to comply with documented client instructions, or to meet applicable legal, contractual, tax, accounting, security, audit or regulatory requirements, resolve disputes, or establish, exercise or defend legal claims.

Where applicable, SHTC will comply with statutory minimum retention requirements, including those applicable under Rule 8(3) of the Digital Personal Data Protection Rules, 2025. Where continued retention beyond any statutory minimum is necessary or permitted under applicable law, contractual obligations, documented client instructions, legal hold or another lawful purpose, the relevant data may be retained for the applicable additional period.

At the end of the applicable retention period, personal data will be securely deleted, anonymised or returned, as applicable. Where deletion is temporarily prevented by a legal hold, investigation or backup cycle, access and use will be appropriately restricted until deletion is possible.

Record Type Retention Approach
Website enquiries and proposals For a reasonable business follow-up period and then deleted or anonymised unless a relationship or legal need continues.
Marketing preferences Until opt-out; a minimum suppression record may be retained to honour the choice.
Corporate learner records For the programme or subscription and the period agreed with the client or required for audit and certificate verification.
Assessment and certificate records For the approved verification period or as agreed with the client.
Contracts, billing and tax records For applicable statutory, accounting and limitation periods.
Technical and security logs For the approved security or legally required period.
Recruitment information For the recruitment process and a reasonable period thereafter unless longer retention is authorised.
PoSH case information According to the written engagement, client instructions, applicable confidentiality law and case-closure arrangements.

Information security

We maintain reasonable technical and organisational measures proportionate to the nature, volume and risk of processing. Depending on the system and information, safeguards may include:

  • role-based and least-privilege access;
  • strong authentication and multi-factor authentication for appropriate accounts;
  • encryption in transit and, where appropriate, at rest;
  • secure configuration, patching and malware protection;
  • logging and monitoring of security-relevant activity;
  • backup and restoration arrangements;
  • vulnerability assessment and remediation;
  • vendor due diligence and contractual safeguards;
  • employee confidentiality and security awareness;
  • incident response and business continuity; and
  • enhanced segregation and access restrictions for PoSH case information.

No digital system is completely secure. Users must protect their credentials and promptly report suspected unauthorised access to support@shtc.co.in.

Certification status: Insadec Services Private Limited, operating under the brand name SHTC, is certified to ISO/IEC 27001:2022 for information security management and ISO 9001:2015 for quality management, within the scope specified on the respective certificates.

Personal data breaches

We maintain procedures to identify, contain, assess, investigate, document and remedy personal data breaches. Where SHTC processes data for a corporate client, we will notify and assist the client in accordance with the applicable agreement. Where required by law, affected individuals and competent authorities will be informed in the prescribed manner and timeframe.

Your rights and choices

Subject to the commencement and applicability of relevant law, verification and lawful exceptions, you may request to:

  • obtain prescribed information about the processing of your personal data;
  • correct inaccurate or misleading personal data;
  • complete incomplete personal data;
  • update personal data;
  • erase personal data where continued retention is not required;
  • withdraw consent;
  • opt out of marketing communications;
  • submit a privacy grievance; and
  • nominate another individual to exercise applicable rights in the event of death or incapacity.

Send requests to support@shtc.co.in with the subject “Privacy Request”. State your relationship with SHTC and the request. We may verify your identity and authority before acting. If we process the data only for a corporate client, we may refer the request to that client or assist it in responding.

We will respond within the period required by applicable law. We may retain information where necessary to comply with law, resolve a dispute, protect another person’s rights or establish, exercise or defend a legal claim.

Grievance redressal

Privacy questions or grievances may be addressed to:

Contact Details
Organisation Insadec Services Private Limited, operating under the brand name SHTC
Officer Privacy and Grievance Officer
Email support@shtc.co.in
Website www.shtc.co.in

We will acknowledge and address grievances within a reasonable period and within any statutory period applicable at the time. If the DPDP Act applies and you are dissatisfied after using our grievance mechanism, you may approach the Data Protection Board of India in accordance with applicable law.

This contact is not a PoSH complaint channel. For a workplace sexual-harassment complaint, use the relevant employer’s Internal Committee or authorised statutory channel.

Children

Our Services are intended for adult workplace participants and are not directed to children under 18. We do not knowingly seek children’s personal data through routine registration. If a client proposes to enrol a person under 18, it must notify SHTC in advance so that necessity, legal requirements and verifiable parental or guardian consent can be assessed. If we learn that data was collected without appropriate authority, we will take reasonable steps to delete or otherwise lawfully address it.

Marketing communications

We may send relevant SHTC service information, compliance updates, learning resources or event invitations where permitted. Marketing messages will provide a working opt-out method. You may unsubscribe through the message or contact support@shtc.co.in. We may retain a minimum suppression record to honour the request.

Training reminders, security notices, contractual communications and essential service updates are not marketing and may continue while the relevant relationship exists.

Artificial intelligence

We do not use ordinary learning scores or website behaviour to make solely automated employment decisions about learners. Corporate clients independently determine how they use authorised reports.

Identifiable PoSH case information must not be entered into public generative-AI services or used to train general-purpose models. Any material AI-enabled processing introduced by SHTC will be assessed for purpose, necessity, transparency, security, contractual authority and human oversight.

Third-party links

Our website may link to third-party websites, payment providers, webinar platforms or social media. Their independent processing is governed by their own privacy notices. We are not responsible for an independent third party’s privacy practices, but we remain responsible for selecting and overseeing Data Processors where required by law and contract.

European and other regional requirements

The adoption of privacy principles does not mean every SHTC activity is governed by the European General Data Protection Regulation (“GDPR”). Where GDPR or another foreign privacy law applies to a particular service or processing activity, we will assess and implement the relevant additional notices, legal bases, rights, contracts, security and transfer safeguards.

SHTC does not describe itself as “GDPR certified” or make an unqualified claim of full GDPR compliance.

Changes to this Policy

We may update this Policy to reflect changes in law, technology, vendors or Services. The revised version will be posted with its updated date. If a change materially affects the purpose of processing or your rights, we will provide additional notice and obtain fresh consent where required. Continued website use will not be treated as consent where applicable law requires affirmative action.

Contact us

For questions, privacy requests or grievances, contact:

Privacy & Grievance Contact

Privacy and Grievance Officer

Insadec Services Private Limited Operating under the brand name SHTC

Email support@shtc.co.in Website www.shtc.co.in

© 2026 Insadec Services Private Limited. SHTC is a brand operated by Insadec Services Private Limited. All rights reserved

SHTC, operated by Insadec Services Private Limited, has developed its privacy and data-protection practices with reference to the principles of the European Union’s General Data Protection Regulation (GDPR).

Although Insadec Services Private Limited is established in India, GDPR may apply to certain processing activities where SHTC:

  • Offers services to individuals in the European Economic Area;
  • Monitors the online behaviour of individuals in the European Economic Area;
  • Processes personal data on behalf of an EU-based client;
  • Receives personal data transferred from an EU-based organisation; or
  • Becomes subject to GDPR through an applicable legal or contractual arrangement.

Where GDPR applies, SHTC is committed to implementing appropriate legal, technical and organisational measures proportionate to the nature, purpose and risk of processing.

Our GDPR-Aligned Principles

SHTC’s privacy framework is based on the following principles:

  • Lawfulness, fairness and transparency;
  • Purpose limitation;
  • Data minimisation;
  • Accuracy;
  • Storage limitation;
  • Confidentiality, integrity and availability;
  • Accountability;
  • Privacy by design and by default; and
  • Respect for the rights of individuals.

Lawful Processing

Where GDPR applies, SHTC will identify and document an appropriate legal basis before processing personal data.

Depending on the activity, the legal basis may include:

  • Consent;
  • Performance of a contract;
  • Compliance with a legal obligation;
  • Protection of vital interests;
  • Performance of a task in the public interest; or
  • Legitimate interests that are not overridden by the rights and interests of individuals.

Consent will not be treated as the default legal basis where another more appropriate legal basis applies.

Individual Rights

Subject to the applicability of GDPR and lawful limitations, individuals may have the right to:

  • Receive information about the processing of their personal data;
  • Access their personal data;
  • Correct inaccurate or incomplete information;
  • Request erasure of personal data;
  • Restrict processing;
  • Receive certain information in a portable format;
  • Object to processing;
  • Withdraw consent;
  • Object to direct marketing;
  • Receive protection concerning solely automated decision-making; and
  • Submit a complaint to the relevant supervisory authority.

Requests may be submitted to support@shtc.co.in with the subject line “GDPR Privacy Request”.

SHTC may verify the identity and authority of the requester before acting on a request.

SHTC as Controller and Processor

SHTC’s data-protection role depends on the nature of the service and processing arrangement.

SHTC may act as a Controller where it determines the purposes and methods of processing, including for:

  • Website enquiries;
  • Direct subscriptions;
  • Billing and payments;
  • Recruitment;
  • Events and webinars;
  • Customer support; and
  • SHTC’s own business communications.

Where a corporate client provides employee information, assigns training and determines how learning reports will be used, the client will generally act as the Controller and SHTC will act as a Processor on the client’s documented instructions.

The respective responsibilities of SHTC and the client should be recorded in a Data Processing Agreement or other appropriate contractual document.

Learning and Certification Data

For authorised corporate training programmes, SHTC may process:

  • Learner names and business contact information;
  • Organisation, legal entity, work location, department and designation;
  • Course enrolment;
  • Training participation and progress;
  • Course completion;
  • Assessment responses and scores;
  • Certificates and verification details;
  • Reminder and communication records; and
  • Account, login and security information.

Authorised client administrators may receive learning, completion, assessment and certificate information required to administer the corporate programme and maintain compliance records.

Protection of PoSH Information

Information relating to a PoSH complaint, complainant, respondent, witness, conciliation, inquiry, recommendation or action taken receives enhanced confidentiality protection.

Where SHTC is separately authorised to process such information, appropriate controls may include:

  • Strict need-to-know access;
  • Segregation from routine LMS and training records;
  • Secure submission and transfer channels;
  • Confidentiality undertakings;
  • Restricted copying, downloading and disclosure;
  • Access and activity records;
  • Case-specific retention periods;
  • Secure return or destruction; and
  • Incident escalation procedures.

Identifiable PoSH case information will not be used for:

  • Marketing;
  • Testimonials;
  • Public training;
  • Demonstrations;
  • Unrelated research;
  • Training general-purpose artificial-intelligence systems; or
  • Any purpose unrelated to the authorised engagement.

General website forms and routine LMS functions are not intended for filing PoSH complaints or submitting complaint evidence.

Privacy by Design and Default

SHTC considers privacy and data-protection requirements when designing or materially changing its:

  • Website;
  • Learning management system;
  • Learner-registration process;
  • Assessments;
  • Certificates;
  • Client dashboards;
  • Reporting systems;
  • Compliance services; and
  • Technology and vendor arrangements.

Data collection, access, visibility, sharing and retention settings should be limited to what is reasonably necessary for the intended purpose.

Information-Security Measures

SHTC implements reasonable security measures appropriate to the nature and risk of processing.

Depending on the relevant system and processing activity, these measures may include:

  • Role-based access controls;
  • Least-privilege access;
  • Strong authentication;
  • Multi-factor authentication for sensitive or administrative accounts;
  • Encryption during transmission;
  • Encryption at rest where appropriate;
  • Secure system configuration;
  • Vulnerability and patch management;
  • Logging and monitoring;
  • Backup and recovery arrangements;
  • Employee confidentiality obligations;
  • Privacy and security awareness;
  • Vendor-security assessment;
  • Incident-response procedures; and
  • Secure data deletion and disposal.

SHTC periodically reviews its safeguards and takes corrective action where security or privacy gaps are identified.

Insadec Services Private Limited, operating under the brand name SHTC, maintains management systems certified to ISO/IEC 27001:2022 for information security management and ISO 9001:2015 for quality management, within the scope specified on the respective certificates.

These certified management systems support SHTC’s information-security, risk-management, access-control, incident-management, service-quality, internal-audit, corrective-action and continual-improvement processes. The certifications support, but do not independently establish, compliance with the GDPR or any other data-protection law.

Data Retention

SHTC retains personal data only for as long as necessary for:

  • The purpose for which it was collected;
  • Delivery and administration of Services;
  • Documented client instructions;
  • Assessment and certificate verification;
  • Legal, contractual and regulatory requirements;
  • Security and audit requirements;
  • Dispute resolution; or
  • Establishment, exercise or defence of legal claims.

At the end of the applicable retention period, personal data will be securely deleted, anonymised, returned or placed under restricted legal hold.

Data may remain temporarily in secured backups until expiry under SHTC’s backup-retention cycle.

Processors and Sub-processors

SHTC assesses technology providers and other processors that may have access to personal data.

Relevant providers are expected to comply with appropriate contractual requirements concerning:

  • Confidentiality;
  • Information security;
  • Documented processing instructions;
  • Sub-processor engagement;
  • Personal-data breaches;
  • Assistance with individual rights;
  • Retention;
  • Return or deletion of data; and
  • Audit or assurance information.

SHTC will provide information about material sub-processors to clients where required by law or contract.

International Data Transfers

Where personal data governed by GDPR is transferred from the European Economic Area to India or another country, SHTC will assess and implement an appropriate transfer mechanism.

Depending on the circumstances, this may include:

  • An adequacy decision;
  • European Commission-approved Standard Contractual Clauses;
  • Supplementary contractual and security measures;
  • An approved certification or code of conduct; or
  • A specific lawful derogation where applicable.

SHTC will not claim to use Binding Corporate Rules unless such rules have been formally approved for its corporate group.

Personal-Data Breaches

SHTC maintains procedures to identify, contain, assess, investigate, document and remedy personal-data breaches.

Where SHTC acts as a Processor, it will notify the relevant Controller without undue delay after becoming aware of a personal-data breach, according to the applicable Data Processing Agreement.

Where SHTC acts as a Controller, it will assess whether notification to a supervisory authority or affected individuals is required under applicable law.

EU Representative

Where Article 27 of GDPR requires SHTC to appoint a representative in the European Union, the representative’s identity and contact information will be published in the applicable privacy notice.

SHTC will assess this requirement before actively offering its services to individuals or organisations in the European Economic Area.

Data Protection Officer

SHTC will appoint a Data Protection Officer where legally required.

Where formal appointment is not mandatory, SHTC may designate a Privacy Officer or responsible contact to manage:

  • Privacy governance;
  • Data-protection enquiries;
  • Individual-rights requests;
  • Grievances;
  • Data breaches;
  • Privacy assessments; and
  • Processor oversight.

Relationship With Indian Law

SHTC also implements measures to comply with applicable Indian privacy and data-protection requirements, including the Digital Personal Data Protection Act, 2023 and the notified rules, according to their commencement and applicability.

Where both Indian law and GDPR apply, SHTC will assess the requirements of each framework and implement appropriate controls for the relevant processing activity.

Compliance Status

The adoption of GDPR-aligned principles does not mean that every SHTC activity is governed by GDPR.

The applicability of GDPR depends on:

  • The location of the individuals;
  • The nature of the services;
  • Whether SHTC targets individuals in the European Economic Area;
  • Whether SHTC monitors their behaviour;
  • The role of SHTC as Controller or Processor;
  • International data-transfer arrangements; and
  • Applicable contractual and legal obligations.

SHTC does not describe itself as:

  • “GDPR certified”;
  • “Fully GDPR compliant”;
  • “Government certified”

GDPR does not provide a general certification establishing that an organisation is fully compliant with all GDPR requirements. Any statement concerning GDPR compliance will therefore be limited to the particular processing activity, legal obligation, service or contractual arrangement concerned.

SHTC’s GDPR readiness is demonstrated through documented privacy controls, Data Processing Agreements, security safeguards, transfer mechanisms, individual-rights procedures, incident-response measures and periodic legal and operational review.

Insadec Services Private Limited, operating under the brand name SHTC

Commencement position: The DPDP Act and Rules commenced in phases from 13 November 2025. The principal operational provisions affecting ordinary Data Fiduciaries are scheduled to commence eighteen months after Gazette publication, on 13 May 2027. SHTC adopts this Policy during the transition period to build and evidence readiness. Provisions shall apply from their legally effective dates.

Purpose

This Policy establishes the governance, responsibilities and controls through which Insadec Services Private Limited (“Insadec”), operating the SHTC brand, protects digital personal data and prepares for and complies with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) and other applicable law.

Its objectives are to ensure lawful and transparent processing, protect the rights of Data Principals, prevent personal data breaches, demonstrate accountability and apply enhanced confidentiality to information connected with PoSH complaints or inquiries.

Scope

This Policy applies to all directors, employees, consultants, trainers, external Internal Committee members, legal associates, vendors and other authorised persons processing personal data for Insadec or SHTC.

It covers personal data processed through:

  • www.shtc.co.in and related web forms;
  • the SHTC learning management system and corporate dashboards;
  • training enrolment, attendance, assessments, reminders and certificates;
  • online and classroom programmes, events and webinars;
  • client onboarding, proposals, contracts, billing and support;
  • external IC-member, policy, audit, advisory and mock-investigation services;
  • recruitment, employment, consultant and vendor administration; and
  • email, cloud storage, devices, physical records subsequently digitised and approved third-party systems.

This Policy applies to digital personal data collected digitally and to personal data collected non-digitally and subsequently digitised. Aggregated or irreversibly anonymised information that cannot identify an individual is outside scope, provided re-identification is not reasonably possible.

Legal Framework and Precedence

This Policy shall be interpreted consistently with the DPDP Act and Rules as and when their provisions commence.

Until superseded, Insadec shall also comply with other applicable Indian privacy, cybersecurity, confidentiality, consumer, employment and contractual obligations.

Sector-specific law and the confidentiality requirements of the PoSH Act shall prevail where they impose stricter requirements.

If this Policy conflicts with applicable law, the law prevails and the Policy shall be amended. A client agreement may impose stronger protections but shall not reduce a mandatory legal obligation.

Definitions

Term Meaning for this Policy
Personal data Any data about an individual who is identifiable by or in relation to that data.
Digital personal data Personal data in digital form, including non-digital data subsequently digitised.
Processing Any wholly or partly automated operation on digital personal data, including collection, storage, use, sharing, retrieval, alteration, organisation and erasure.
Data Principal The individual to whom personal data relates; where applicable, includes a lawful guardian acting for a child or person with disability as provided by law.
Data Fiduciary A person who alone or with others determines the purpose and means of processing personal data.
Data Processor A person who processes personal data on behalf of a Data Fiduciary.
Personal data breach Unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability.
Consent A free, specific, informed, unconditional and unambiguous indication of wishes through clear affirmative action, limited to necessary personal data for the specified purpose.
Child An individual under eighteen years of age for purposes of the DPDP Act.
PoSH case data Information relating to a complaint, complainant, respondent, witness, conciliation, inquiry, evidence, recommendation or action taken.

Roles of Insadec and SHTC

Data Fiduciary

Insadec generally acts as Data Fiduciary for website enquiries, direct subscriptions, billing, recruitment, events, customer support, vendor management, its own employees and SHTC marketing because it determines why and how that data is processed.

Data Processor

Where a corporate client supplies employee information, assigns training, decides report recipients and determines the purposes of processing, the client generally acts as Data Fiduciary and Insadec/SHTC acts as Data Processor under documented instructions and the applicable Data Processing Agreement (“DPA”).

Case-Specific Role

For external IC-member, investigation-support or advisory engagements, roles shall be assessed and recorded before case data is accepted. SHTC shall not assume that routine LMS terms authorise processing of PoSH case data.

Data Protection Principles

Lawfulness, Fairness and Transparency

Processing shall have a lawful basis, be fair to individuals and be explained through clear notices.

Purpose Limitation

Personal data shall be collected for specified purposes and not reused incompatibly without appropriate notice and authority.

Data Minimisation

Only data reasonably necessary for the stated purpose shall be collected or retained.

Accuracy

Reasonable efforts shall ensure completeness, accuracy and consistency; correction channels shall be available.

Storage Limitation

Data shall be erased, anonymised or returned when its purpose and lawful retention requirements end.

Security

Reasonable safeguards shall protect confidentiality, integrity and availability throughout the lifecycle.

Rights and Control

Processing shall enable applicable access, correction, completion, updating, erasure, consent withdrawal, nomination and grievance rights.

Accountability

Owners, approvals, inventories, contracts, incidents, requests, risks and corrective actions shall be documented.

Data Inventory and Processing Records

The Privacy Officer shall maintain a personal data inventory or Record of Processing Activities identifying:

  • processing activity and business owner;
  • categories of Data Principals and personal data;
  • specific purpose and lawful basis or legitimate use;
  • source of data;
  • systems, storage locations and access roles;
  • recipients, processors and sub-processors;
  • international access or transfer;
  • retention and deletion rule;
  • security classification and safeguards; and
  • whether children’s data or PoSH case data is involved.

New or materially changed processing shall not proceed until the inventory, notice, contracts, retention and controls are reviewed.

Collection and Notice

At or before consent-based collection, SHTC shall provide a notice that can be understood independently, in clear and plain language, containing an itemised description of personal data, specified purposes, goods/services or uses enabled, and accessible methods to withdraw consent, exercise rights and make a complaint.

Collection forms shall not use bundled, vague or pre-ticked consent. General enquiry forms shall state that PoSH allegations and evidence must not be submitted through that channel.

Where data is received from a corporate client rather than directly from the learner, the contract shall allocate notice responsibilities and SHTC shall provide an appropriate learner notice within its service interface where required.

Grounds for Processing

Consent

Consent shall be obtained where required, limited to necessary personal data and capable of proof.

Withdrawal shall be as easy as giving consent. Following withdrawal, processing shall cease unless continued processing is authorised by law or necessary to meet another lawful obligation.

Service consequences shall be clearly explained without coercion.

Certain Legitimate Uses

SHTC may process without consent only where a legitimate use specified by the DPDP Act applies, including where an individual voluntarily provides data for a specified purpose without indicating refusal, for compliance with legal obligations, medical emergencies or employment-related purposes and safeguarding the employer from loss or liability, as applicable.

The relevant condition and necessity shall be documented; “legitimate interest” shall not be used as a generic substitute for the statutory grounds under Indian law.

Processor Instructions

Where acting as Processor, SHTC shall process only on documented instructions from the client Data Fiduciary, except where law requires otherwise.

SHTC shall notify the client if an instruction appears unlawful, insecure or outside contract scope.

Categories and Approved Purposes

Data Category Approved Purposes
Learner identity and work information Account creation, enrolment, entity allocation, support and accurate reporting.
Learning records Training delivery, progress, reminders, assessment, completion, certificates and authorised compliance reports.
Website and enquiry information Responding to enquiries, demonstrations, proposals, service improvement, security and permitted business communication.
Commercial and billing data Contracting, invoicing, tax, payment, audit and dispute management.
Technical and security data Authentication, fraud prevention, diagnostics, logging, monitoring, incident response and service availability.
Employee/recruitment/vendor data Workforce and contractor administration, recruitment, payment, due diligence, security and legal compliance.
PoSH case data Only under separate written authorisation: confidential case support, documentation, hearing support, advice or other assigned activity.

Routine learner registration shall not request Aadhaar, PAN, bank details, salary, health data, webcam recordings or complaint evidence unless necessity, notice, authority, retention and safeguards are separately approved.

Corporate Learner Accounts and Dashboards

Authorised client administrators may receive learner enrolment, participation, progress, assessment score, completion and certificate status necessary for programme administration and compliance.

Access shall be limited by client, legal entity and role; bulk downloads shall be controlled and logged where reasonably practicable.

Administrators shall not use reports for an undisclosed incompatible purpose.

SHTC may restrict access and notify the client where unauthorised viewing, excessive downloading, account sharing or disclosure is suspected.

PoSH Confidentiality and Data Segregation

Training records and case data shall be treated as separate information classes. Routine website or LMS channels are not complaint channels.

Before receiving case data, SHTC shall confirm the authorised recipient, secure channel, purpose, role, access list, retention/return instruction and incident contact.

  • Need-to-know access and confidentiality undertakings;
  • Segregation from routine LMS and marketing systems;
  • Approved encrypted transmission and storage;
  • Restricted printing, copying, downloads and forwarding;
  • Access logging where supported;
  • Redaction or anonymisation where suitable;
  • Prohibition on personal email, consumer messaging and unauthorised cloud storage;
  • Prohibition on entering identifiable cases into public generative-AI services; and
  • Secure return, archival, legal hold or destruction at case closure.

Identifiable case data shall not be used for marketing, testimonials, demonstrations, general training, product development or unrelated analytics.

Accuracy and Data Quality

Business owners and authorised client administrators shall maintain accurate data.

Before information is used to make a decision affecting a Data Principal or disclosed to another Data Fiduciary, reasonable efforts shall be taken to ensure it is complete, accurate and consistent.

Corrections shall be propagated to relevant recipients where required and reasonably practicable.

Data Retention, Erasure and Legal Hold

Retention

Insadec shall retain personal data only for so long as is necessary for the purpose for which such personal data was collected or processed, or for such longer period as may be required or permitted under applicable law, contractual obligations, client instructions, audit requirements, dispute resolution, legal claims or other lawful requirements.

Retention Schedule

The Privacy Officer, in consultation with Management and the relevant business owner, shall maintain a documented retention schedule specifying the applicable retention period, retention trigger, responsible owner and approved method of deletion, anonymisation or return for each material category of personal data.

Retention Under Rule 8(3) of the DPDP Rules, 2025

Where Rule 8(3) is applicable, Insadec shall retain the relevant personal data, associated traffic data and other logs of processing for a minimum period of one year from the date of such processing.

Where continued retention beyond one year is necessary or permitted under applicable law, contractual obligations, documented legal or regulatory requirements, a legal hold, or another lawful purpose for which retention remains necessary, such data may be retained for the applicable additional period.

Upon expiry of the applicable retention period and cessation of the purpose or other lawful basis for retention, the relevant personal data and logs shall be securely erased, anonymised or returned, as applicable.

Processor Retention Obligations

Where Insadec acts as a Data Processor, it shall comply with the retention, return and deletion instructions of the relevant Data Fiduciary, subject to any applicable legal requirement requiring continued retention.

Where Rule 8(3) applies to processing undertaken by or on behalf of a Data Fiduciary, the relevant Data Processing Agreement shall appropriately address the corresponding retention and deletion obligations of the Data Processor.

Erasure, Anonymisation or Return

Upon expiry of the applicable retention period, or when the purpose for which personal data was collected or processed is no longer being served and no lawful basis for continued retention exists, the personal data shall be securely erased, anonymised or returned to the relevant Data Fiduciary, as applicable.

Legal Hold and Restricted Retention

Where personal data is required to be retained pursuant to a legal obligation, regulatory requirement, audit requirement, dispute, investigation, litigation, legal claim or other lawful requirement, such data shall be subject to an appropriate legal hold or restricted-retention status and shall not be used for any unrelated purpose.

Backup Copies

Backup copies containing personal data shall be retained only in accordance with the documented backup and disaster-recovery retention cycle and shall be securely overwritten or deleted upon expiry of that cycle, unless continued retention is required by applicable law or a legal hold.

Retention Principles by Category

Subject to applicable law, contractual obligations and client instructions, the following retention principles shall apply:

Category Retention Reason
Website enquiries Retain only for the period necessary to respond to the enquiry, manage the commercial relationship, comply with applicable law or establish, exercise or defend legal claims.
Marketing Preferences Retain only for as long as necessary to honor the individual's preference, including minimum suppression information where necessary to ensure that an opted-out individual is not contacted again.
Learner and Accounts records Retain for the duration of the relevant subscription/service relationship and thereafter only for the period necessary for certificate verification, contractual, audit, legal or other documented lawful purposes.
Assessment and Certificate records Retain for the period necessary to administer, verify and evidence completion or certification and to meet applicable contractual, audit or legal requirements.
Contracts, billing and tax records Retain for the applicable statutory, accounting and limitation periods.
Security and processing logs Retain in accordance with applicable law and the approved security-log retention schedule, including the minimum retention period prescribed under Rule 8(3), wherever applicable.
Support tickets and recordings Retain only for the period necessary for service management, quality assurance, dispute resolution, legal compliance or another documented lawful purpose. Recordings shall be retained only where their collection and retention are lawfully authorized.
POSH case data Retain strictly in accordance with applicable law, the relevant client's documented instructions, the applicable case or engagement requirements and any legal hold. Such data shall remain segregated and shall not be retained or used for unrelated purposes.
Recruitment Data Retain only for the period necessary for recruitment administration, legal compliance, defence of claims or another documented lawful purpose, in accordance with the approved retention schedule.

Periodic Review of Retention

Retention periods shall be periodically reviewed and revised where required by changes in applicable law, regulatory requirements, contractual obligations, processing purposes, security risks or business operations.

Evidence of Deletion

Where personal data is erased, anonymised or returned, appropriate records or evidence of such action shall be maintained where reasonably necessary to demonstrate compliance with this Policy and applicable law.

Rights of Data Principals

Subject to commencement, applicability, verification and lawful exceptions, SHTC shall enable:

  • Access to prescribed information about processing and sharing;
  • Correction of inaccurate or misleading personal data;
  • Completion of incomplete data;
  • Updating of personal data;
  • Erasure where retention is no longer necessary;
  • Withdrawal of consent;
  • Grievance redressal; and
  • Nomination of another individual to exercise rights in the event of death or incapacity.

Requests shall be submitted to support@shtc.co.in with “DPDP Request” in the subject.

Identity and authority shall be proportionately verified.

If SHTC acts solely as Processor, it shall promptly refer the request to and assist the client Data Fiduciary.

Requests, decisions, response dates and reasons for refusal or partial action shall be recorded.

Grievance Redressal

Insadec shall prominently publish the business contact details of a person able to answer privacy questions.

Grievances shall be acknowledged within [3 business days] and resolved within the period published by SHTC, not exceeding any statutory maximum applicable at the time.

The individual shall be informed of the outcome and escalation route.

The privacy grievance channel is not a substitute for filing a PoSH complaint.

Allegations and evidence shall be directed to the relevant employer’s Internal Committee or authorised statutory channel.

Children and Persons Requiring Lawful Guardianship

SHTC workplace services are intended for adults.

An individual under eighteen shall not be enrolled without prior review.

Where processing of a child’s data is proposed, SHTC shall obtain verifiable parental consent unless a lawful exemption applies and shall not undertake processing likely to cause detrimental effect or prohibited tracking, behavioural monitoring or targeted advertising.

Where a lawful guardian acts for a person with disability who cannot act independently, the guardian’s status shall be verified in accordance with applicable law and Rules.

Reasonable Security Safeguards

Security safeguards shall be proportionate to the volume, sensitivity, context and risk of processing and shall include, as appropriate:

  • Data classification and asset inventory;
  • Role-based and least-privilege access;
  • Multi-factor authentication for privileged and sensitive systems;
  • Encryption, obfuscation, masking or tokenisation where appropriate;
  • Secure configuration, patching, malware protection and vulnerability management;
  • Logs, monitoring and review for unauthorised access;
  • Backups, restoration tests and continuity measures;
  • Secure development and change controls for relevant applications;
  • Endpoint, remote-working and removable-media controls;
  • Vendor security assessment and contract controls;
  • Confidentiality obligations and security awareness;
  • Incident response, forensic preservation and corrective action; and
  • Secure disposal of digital and paper-derived records.

Controls shall be tested periodically. Insadec Services Private Limited, operating under the brand name SHTC, maintains management systems certified to ISO/IEC 27001:2022 for information security management and ISO 9001:2015 for quality management, within the scope stated on the respective certificates. These certifications support, but do not replace, Insadec’s obligations under the DPDP Act, DPDP Rules and other applicable laws.

Personal Data Breach Management

Report

Immediately report suspected loss, unauthorised access, disclosure, alteration, destruction, phishing, malware or service compromise to [incident email/telephone].

Contain the Incident

Contain the incident without destroying evidence; restrict access, reset credentials and preserve relevant logs.

Assess the Incident

Assess affected data, individuals, systems, duration, cause, likely harm and cross-border/client impact.

Processor Notification

Where SHTC acts as Processor, notify the client Data Fiduciary without undue delay under the DPA and provide ongoing assistance.

Data Fiduciary Notification

Where Insadec acts as Data Fiduciary, provide legally required notice to affected Data Principals and the Data Protection Board in the prescribed form and timeframe after the relevant provisions commence.

Documentation and Corrective Action

Document decisions, communications, remediation, recovery and lessons learned; track corrective actions to closure.

Only authorised personnel may communicate externally about a breach. Notices shall be clear, accurate and include available mitigation and contact information.

Data Processors, Vendors and Contracts

No Processor shall receive personal data before due diligence and an appropriate written agreement.

Contracts shall address:

  • Documented purpose and instructions;
  • Confidentiality and access;
  • Security safeguards;
  • Sub-processor approval or notification;
  • Breach notification and cooperation;
  • Rights-request assistance;
  • Audit/assurance information;
  • Business continuity;
  • Data location and international access;
  • Retention, return and secure deletion; and
  • Termination and evidence preservation.

Insadec remains responsible for processing undertaken on its behalf to the extent provided by applicable law.

A material processor register shall be maintained.

Cross-Border Transfers

Before personal data is made accessible outside India, the business owner shall record the destination, recipient, purpose, client instruction, contract, safeguards and any sectoral or Government restriction.

Transfers shall comply with any general or special order of the Central Government and any stricter applicable law or client requirement.

GDPR-governed transfers shall also use an appropriate EU transfer mechanism where applicable.

Direct Marketing and Cookies

Marketing shall use an appropriate legal basis and clear opt-out.

Withdrawal or objection shall be honoured promptly and a minimum suppression record may be retained.

Purchased or publicly sourced contact data shall be assessed for lawful use and transparency.

Non-essential analytics, functional or advertising cookies shall not be activated where consent is required until the user has made a valid choice.

The website shall provide “accept”, “reject non-essential” and granular preference options and maintain an accurate cookie inventory.

Artificial Intelligence

Personal data shall not be entered into a public generative-AI service without approved purpose, lawful authority, vendor assessment, contractual protection, security review and documented retention controls.

Identifiable PoSH case data is prohibited from public AI tools.

AI features affecting individuals shall undergo privacy and risk assessment, transparency review, human oversight and testing before deployment.

Data Protection Impact and Risk Assessment

A documented privacy/risk assessment shall be completed before high-risk or materially changed processing, including case-management systems, large-scale monitoring, sensitive workplace analytics, children’s data, biometrics, new AI uses, cross-border hosting or extensive integration.

The assessment shall address necessity, proportionality, risks to individuals, mitigations, residual risk and approval.

If Insadec is notified as a Significant Data Fiduciary, it shall fulfil the additional obligations applicable to it, including appointment of a Data Protection Officer based in India, independent data auditor, periodic impact assessment and audit, and other prescribed measures.

Training and Confidentiality

All personnel with access to personal data shall receive role-appropriate privacy and security training at induction and periodically thereafter.

Persons handling PoSH case data, administrator accounts, rights requests or incidents shall receive enhanced training.

Confidentiality obligations survive role change and termination.

Monitoring, Audit and Corrective Action

The Privacy Officer shall monitor implementation through data-inventory reviews, access reviews, consent and notice checks, vendor assessments, deletion evidence, incident exercises, vulnerability assessments, rights-request testing and management reporting.

Nonconformities shall be risk-ranked, assigned, time-bound and verified after remediation.

Roles and Responsibilities

Role Responsibilities
Board/Management Approve policy, provide resources, set risk tolerance and oversee material breaches and compliance.
Privacy Officer Maintain framework, notices, inventory, requests, grievances, assessments, training and reporting.
Information Technology/Security Implement technical safeguards, access, logging, backup, testing, incident response and vendor controls.
Service/Programme Owners Define purpose, minimise data, maintain accuracy, control reports and apply retention.
HR Manage employee/candidate data, confidentiality, training and employment-related legitimate-use documentation.
Client Administrators Provide authorised and accurate data, manage users, restrict report access and follow client duties.
Employees/Consultants/Trainers Follow policy, use approved systems, protect credentials, minimise disclosure and report incidents.
Processors/Vendors Process only as contracted, secure data, report breaches and return/delete at end of service.

Non-Compliance

Violation may result in access restriction, corrective training, disciplinary or contractual action, vendor remediation or termination, notification to affected clients or authorities, and legal action where appropriate.

Action shall be proportionate and follow applicable employment and contract terms.

Policy Review and Change

This Policy shall be reviewed at least annually and following commencement or amendment of relevant law, material service or vendor changes, new high-risk processing, serious incidents or audit findings.

Changes require approval and communication to affected personnel. Public notices shall be updated where processing changes materially.

Appendix A — DPDP Implementation Register

Control Owner Evidence/Status
Legal entity and privacy contact published Management/Privacy [Open]
Data inventory and processing records Privacy/Business owners [Open]
Website and learner notices Privacy/Legal [Open]
Consent and withdrawal mechanism Product/Privacy [Open]
Rights and grievance workflow Privacy/Support [Open]
Client and vendor DPAs Legal/Procurement [Open]
Retention schedule and deletion jobs Privacy/IT [Open]
MFA, access reviews and logging IT/Security [Open]
Breach plan and exercise Security/Privacy [Open]
PoSH case-data segregation Service owner/Security [Open]
Children’s-data control Product/Privacy [Open]
Privacy and security training HR/Privacy [Open]

Appendix B — Contact Points

Purpose Contact
Privacy questions and DPDP requests support@shtc.co.in
Privacy/Grievance Officer Ankur Gohri
Security incident reporting support@shtc.co.in
PoSH complaint Use the Internal Committee or authorised channel communicated by the relevant employer; do not use the general privacy mailbox.
Postal communication Insadec Services Private Limited, C/O Workingdom, Block A, 2nd Floor, Plot No. 11, 12, 16, 17 Palam Extension, Sector 7 Dwarka, Delhi, 110077 India

What Are Cookies?

Cookies are small data files stored on your computer, smartphone, or other device when you access a website. They help websites operate effectively, remember user preferences, and provide website operators with information about site usage.

How We Use Cookies?

Our website may use the following types of cookies:

  • Strictly Necessary Cookies: Required for essential website features and proper operation.
  • Performance and Analytics Cookies: Help us understand how visitors use the website so we can improve its performance and content.
  • Functionality Cookies: Remember your settings and preferences to provide a more personalised experience.
  • Advertising and Marketing Cookies: Help measure marketing activities and deliver advertisements that may be relevant to your interests.

Your Cookie Choices

You can manage or remove cookies through your browser settings. Most browsers allow you to delete existing cookies, block new cookies, or receive a notification before cookies are stored.

Please note that restricting certain cookies may affect some website features, and you may need to re-enter your preferences during future visits.

Introduction

This Copyright and Intellectual Property Policy governs the access to and use of all content, materials, courses, services, platforms and intellectual property made available by Insadec Services Private Limited, operating its PoSH training and compliance services under the brand name SHTC.

In this Policy:

  • “Insadec” means Insadec Services Private Limited.
  • “SHTC” means the PoSH training and compliance-services brand operated by Insadec Services Private Limited.
  • “Services” means the SHTC website, learning management system, training programmes, assessments, certifications, workshops, webinars, advisory services, compliance documentation and related products or services.
  • “Materials” means all content and intellectual property created, owned, commissioned, developed, acquired or lawfully licensed by Insadec or SHTC.
  • “User” means any website visitor, learner, participant, client, client administrator, employee, trainer, consultant, subscriber or other person accessing or using the Services or Materials.

This Policy forms part of SHTC’s Terms of Use and the applicable proposal, subscription, licence, statement of work or client agreement.

Ownership of SHTC Materials

Unless expressly stated otherwise, all rights, title and interest in the SHTC Services and Materials are owned by, commissioned for, assigned to or lawfully licensed to Insadec Services Private Limited.

Protected Materials include, without limitation:

  • Website content and webpages;
  • Training videos, audio recordings and animations;
  • Course modules and learning journeys;
  • Presentations and facilitator materials;
  • Assessments, quizzes, questions and answer frameworks;
  • Participant handbooks and learning guides;
  • PoSH compliance toolkits and checklists;
  • Model policies, templates and procedural documents;
  • Case studies, scenarios, exercises and role plays;
  • Articles, blogs, research reports and white papers;
  • Graphics, illustrations, photographs and infographics;
  • Compliance dashboards and reporting formats;
  • Certificate designs and verification systems;
  • Software, source code, object code and LMS functionality;
  • Databases and original selection or arrangement of data;
  • Training methodologies and original explanatory frameworks;
  • Marketing and communication materials;
  • SHTC’s brand identity, trade name, logo and design elements; and
  • Any updates, modifications, translations, adaptations or derivative versions of these Materials created by or for SHTC.

The Materials are protected under the Copyright Act, 1957, applicable rules, trademark laws, contract law, information-technology laws, other applicable Indian laws and relevant international conventions.

Acceptance of Copyright Conditions

By accessing, purchasing, subscribing to, receiving or using any SHTC Service or Material, the User agrees to:

  • Respect the copyright and intellectual-property rights of Insadec, SHTC and applicable third parties;
  • Use the Materials only for the purpose, organisation, users and period authorised under the applicable licence or agreement;
  • Not reproduce, distribute, modify, commercially exploit or misuse the Materials;
  • Protect login credentials and restricted Materials from unauthorised access;
  • Ensure that employees and authorised users comply with this Policy; and
  • Comply with applicable copyright, intellectual-property and contractual laws.

Access to SHTC Materials constitutes a limited permission to use the Materials. It does not transfer ownership, authorship, copyright or any other intellectual-property right to the User or client.

Limited Licence

Subject to payment of applicable fees and compliance with this Policy and the applicable agreement, Insadec grants the authorised User a limited, non-exclusive, non-transferable, non-sublicensable and revocable licence to access and use the assigned SHTC Materials.

The licence is restricted to:

  • Personal learning by the authorised participant;
  • Internal training and compliance purposes of the named client organisation;
  • The number of users, legal entities and locations specified in the proposal or agreement;
  • The approved subscription or access period;
  • Viewing, downloading or printing expressly enabled or authorised by SHTC;
  • Sharing certificates and compliance reports internally with authorised HR, management, auditors or regulators; and
  • Using client-specific deliverables for the internal purpose for which they were supplied.

No right is granted beyond what is expressly stated in this Policy or the applicable written agreement.

Corporate and Group-Company Use

A corporate licence is restricted to the client organisation, legal entities, locations and number of users specified in the applicable proposal, purchase order or agreement.

The following persons or organisations are not automatically covered:

  • Parent companies;
  • Subsidiaries;
  • Associate or affiliate companies;
  • Sister concerns;
  • Joint ventures;
  • Franchisees;
  • Contractors;
  • Vendors;
  • Customers; or
  • Other members of a corporate group.

Use by any additional legal entity or organisation requires SHTC’s prior written approval and may be subject to additional fees.

A licence purchased for one company or entity cannot be shared with another company merely because both companies have common directors, shareholders, management, employees or premises.

Client administrators are responsible for ensuring that access is provided only to authorised users.

Prohibited Activities

Unless expressly authorised by SHTC in writing, Users must not:

  • Copy, reproduce, duplicate or republish SHTC Materials;
  • Record, photograph, download or screen-capture restricted training content;
  • Circulate course materials through email, messaging platforms, shared drives or social media;
  • Upload SHTC Materials to another LMS, website, intranet, cloud platform or digital repository;
  • Share login credentials or allow another person to access an individual account;
  • Use a single-user licence for multiple participants;
  • Sell, licence, sublicense, rent, lease or commercially exploit SHTC Materials;
  • Use SHTC Materials to provide paid or unpaid training to another organisation;
  • Modify, translate, adapt or create derivative content from SHTC Materials;
  • Convert SHTC Materials into another course, handbook, video, presentation or digital product;
  • Remove or obscure copyright notices, trademarks, logos, watermarks or attribution;
  • Claim ownership or authorship of SHTC Materials;
  • Present SHTC Materials as another person’s or organisation’s original content;
  • Extract or reproduce SHTC assessments, quizzes, question banks or answer keys;
  • Alter, duplicate, transfer or fabricate SHTC certificates;
  • Use automation, scraping, crawling or extraction tools on the SHTC website or LMS;
  • Reverse engineer, decompile or attempt to derive the source code of SHTC systems;
  • Circumvent access controls, download restrictions or digital-rights protections;
  • Use SHTC Materials for unlawful, defamatory or misleading purposes;
  • Use SHTC Materials to create or support a competing commercial service; or
  • Assist another person or organisation in undertaking any prohibited activity.

Artificial Intelligence and Machine Learning

Unless specifically authorised in writing, Users must not:

  • Upload SHTC Materials to public or third-party generative-AI platforms;
  • Use SHTC Materials as prompts, context, knowledge files or reference documents in an AI system;
  • Use SHTC Materials to train, fine-tune, test or improve an artificial-intelligence or machine-learning model;
  • Create AI-generated adaptations, summaries, videos, assessments or training products from SHTC Materials for commercial use;
  • Build a chatbot, compliance assistant or knowledge system using SHTC Materials; or
  • Enter confidential SHTC, client or PoSH case information into a public AI platform.

Any authorised AI use must be governed by a written agreement specifying purpose, confidentiality, data protection, ownership of outputs, model-training restrictions and deletion requirements.

PoSH Policies, Templates and Compliance Documents

SHTC may provide model policies, checklists, procedural documents, registers, toolkits, handbooks and compliance templates.

These Materials are licensed to the authorised client for its internal compliance use. The client may customise organisation-specific fields, including:

  • Legal entity name;
  • Workplace locations;
  • Internal Committee composition;
  • Contact details;
  • Reporting channels;
  • Service-rule references;
  • Organisational structure; and
  • Internal procedures.

Unless expressly transferred through a written agreement, copyright in SHTC’s underlying template architecture, wording, explanations, layout, methodology and standard content remains with Insadec Services Private Limited.

A client must not sell, publish, license or distribute an SHTC template to another organisation.

Use of a template does not automatically establish statutory compliance. Each organisation remains responsible for obtaining appropriate legal review and adapting the document to its circumstances and applicable law.

Assessments and Question Banks

All assessments, quizzes, case-study questions, answer choices, answer explanations, evaluation methods and question banks made available through SHTC are protected Materials.

Users must not:

  • Copy or circulate assessment questions;
  • Photograph or record assessments;
  • Share questions or answers with other participants;
  • Use unauthorised assistance;
  • Create answer repositories;
  • Publish assessment content online;
  • Submit assessment questions to an AI tool; or
  • Misrepresent another person’s assessment performance.

SHTC may invalidate an assessment or revoke a certificate where it reasonably identifies cheating, account sharing, unauthorised copying or manipulation.

Certificates

SHTC certificates may be used only by the individual or organisation to whom they are validly issued.

A certificate must not be:

  • Altered or edited;
  • Duplicated for another person;
  • Transferred to another participant;
  • Used with a false name or designation;
  • Used to misrepresent the training completed;
  • Used to misrepresent the training duration;
  • Used to misrepresent the assessment score;
  • Presented as a statutory licence or professional qualification;
  • Used to imply SHTC’s endorsement beyond the course completed; or
  • Fabricated or issued through an unauthorised system.

SHTC reserves the right to verify, suspend or revoke a certificate obtained or used through misrepresentation, account sharing, unauthorised assistance or other violation of this Policy.

Client-Owned Materials

A client retains ownership of documents, logos, policies, employee information and other materials lawfully supplied by the client to SHTC.

The client grants Insadec and SHTC a limited right to use those materials solely to provide the contracted Services.

SHTC will not use identifiable client-confidential materials for:

  • Public marketing;
  • Testimonials;
  • Demonstrations;
  • Training another client;
  • Publications;
  • Case studies;
  • Artificial-intelligence training; or
  • Any unrelated commercial purpose.

Unless the client provides appropriate written authorisation.

The client represents that it has the necessary rights and authority to provide the materials to SHTC.

PoSH Complaint and Inquiry Materials

Complaint documents, inquiry records, statements, evidence, interview notes, reports and other case-related information are confidential and may also contain copyright belonging to the client, individuals or third parties.

Nothing in this Policy permits SHTC or any User to publish, reproduce or commercially use identifiable PoSH case information.

Where SHTC is authorised to assist with an inquiry or complaint, case materials must be used only:

  • For the authorised engagement;
  • By persons with a legitimate need to know;
  • Through approved secure channels;
  • In accordance with confidentiality obligations;
  • For the period required for the engagement and applicable law; and
  • Subject to the client’s authorised retention, return or destruction instructions.

Case materials must not be used for general training unless they have been lawfully anonymised and their use has been appropriately authorised.

Trainers, Consultants and Content Contributors

Training materials, presentations, videos, scripts, graphics or other works created by employees, trainers, consultants, designers or content contributors for SHTC are governed by their employment, commissioning, assignment or licence agreements.

Trainers and consultants must not independently reuse, sell, distribute or provide SHTC-branded or SHTC-owned Materials unless their written agreement expressly permits such use.

Where a contributor retains ownership of specified material, SHTC’s rights and the permitted use of that material will be governed by the applicable licence or written agreement.

Third-Party Intellectual Property

Certain SHTC Materials may contain third-party trademarks, legal extracts, photographs, videos, illustrations, research, publications or other content.

Such material remains the property of the relevant rights holder and is used under licence, permission or another legally permissible basis.

Users must comply with any additional restrictions applying to third-party content. The inclusion of third-party material does not transfer ownership to SHTC or the User.

References to client names, legal authorities, statutes, regulatory bodies or third-party brands do not imply endorsement unless expressly stated.

Application to Materials Created or Used Before 2026

This Policy applies to all copyright-protected Materials owned by or licensed to Insadec Services Private Limited and SHTC, irrespective of whether those Materials were created, published, supplied, accessed, downloaded or used before, on or after 1 January 2026.

Copyright and other intellectual-property rights existing in SHTC Materials before 2026 continue to remain valid and enforceable in accordance with:

  • The Copyright Act, 1957;
  • Other applicable intellectual-property laws;
  • The licence or subscription conditions originally communicated;
  • The agreement governing the original access or use; and
  • Any confidentiality or contractual obligations applicable at that time.

The publication or revision of this Policy in or after 2026 does not retrospectively create copyright. It records, clarifies and reaffirms ownership and copyright rights that arose when the relevant Materials were created, acquired, commissioned, assigned or lawfully licensed.

Unauthorised copying, reproduction, distribution, modification, publication, commercial exploitation or continuing use of SHTC Materials may constitute copyright infringement or breach of contract, even where the Materials were originally obtained before 2026.

Nothing in this Policy retrospectively removes any permission expressly granted under a valid written agreement. However, after such permission or agreement expires or terminates, continued or future use remains subject to SHTC’s copyright and any continuing contractual obligations.

Statutory Exceptions and Permitted Legal Use

Nothing in this Policy is intended to prohibit an act expressly permitted under applicable law, including a legally recognised exception under Section 52 of the Copyright Act, 1957.

Any person relying on a statutory exception remains responsible for ensuring that the proposed use falls within the exception.

Where legally appropriate, limited use should:

  • Be fair and proportionate;
  • Be restricted to the lawful purpose;
  • Include appropriate attribution;
  • Not substitute for purchasing or licensing the original Material;
  • Not disclose confidential information;
  • Not misrepresent SHTC’s views or endorsement; and
  • Not cause unreasonable commercial harm to Insadec or SHTC.

A statutory exception concerning copyright does not automatically permit the disclosure of confidential information, personal data or PoSH complaint information.

No Transfer of Ownership

Payment of a training fee, subscription fee, consulting fee or licence fee does not transfer copyright or ownership of SHTC Materials.

Any transfer or assignment of copyright must be specifically documented in a written agreement signed by an authorised representative of Insadec Services Private Limited.

No ownership transfer will be inferred merely because:

  • A client paid for development or customisation;
  • A client requested changes;
  • Materials contain the client’s name or logo;
  • Materials were delivered electronically;
  • A User downloaded or printed the Materials; or
  • A training programme was customised for a client.

Client-specific ownership provisions contained in a signed agreement will prevail over this general clause.

Copyright Notices and Watermarks

Users must retain all copyright notices, logos, watermarks, digital identifiers, certificate numbers and proprietary statements appearing on SHTC Materials.

Removing, concealing or altering these identifiers is prohibited.

The absence of a copyright notice, watermark or logo does not mean that the Material is free from copyright or available for unrestricted use.

Monitoring and Evidence Preservation

Subject to applicable privacy and data-protection laws, SHTC may maintain appropriate records to protect its intellectual property and investigate suspected misuse, including:

  • Account-access logs;
  • User and administrator activity;
  • Download history;
  • Certificate-verification records;
  • Assessment activity;
  • IP address and device information;
  • Content-distribution records; and
  • Reported infringement evidence.

These records may be preserved where reasonably necessary for security investigation, contract enforcement, dispute resolution or legal proceedings.

Suspension and Termination

SHTC may restrict, suspend or terminate access where it reasonably believes that a User has:

  • Shared credentials;
  • Copied or distributed restricted Materials;
  • Misused assessments or certificates;
  • Infringed copyright;
  • Circumvented technical restrictions;
  • Used Materials for unauthorised commercial purposes;
  • Used Materials to create a competing service; or
  • Otherwise materially violated this Policy or the applicable agreement.

Where appropriate, SHTC may notify the client or User and provide an opportunity to explain or remedy the violation.

Termination of access does not extinguish copyright, confidentiality, payment or other obligations intended to continue after termination.

Remedies for Infringement

Unauthorised use of SHTC Materials may result in:

  • Suspension or termination of access;
  • Certificate cancellation;
  • Removal of infringing material;
  • A demand to cease use and return or destroy copies;
  • Recovery of unpaid licence or usage fees;
  • Contractual claims;
  • Claims for losses or damages;
  • Injunctive or other equitable relief; and
  • Any other remedy available under applicable law.

SHTC’s decision not to act immediately against a violation does not constitute a waiver of its rights.

Reporting Copyright Infringement

A person who believes that material available through SHTC infringes their copyright may submit a written notice containing:

  • Full name and contact information;
  • Identification of the copyrighted work;
  • Identification and location of the allegedly infringing material;
  • Evidence of ownership or authority to represent the owner;
  • A good-faith explanation of the alleged infringement;
  • A declaration that the information provided is accurate; and
  • A physical or electronic signature.

Copyright and Intellectual Property Contact

Insadec Services Private Limited
Operating under the brand name SHTC
Email: support@shtc.co.in
Telephone: +91 7042500326
Registered Address: C/O Workingdom, Block A, 2nd Floor, Plot No. 11, 12, 16, 17 Palam Extension, Sector 7 Dwarka, Delhi, 110077 India

SHTC will review properly supported notices and may remove, restrict, restore or otherwise address the relevant content as appropriate.

Permission Requests

Requests to reproduce, translate, distribute, licence or otherwise use SHTC Materials must be submitted in writing to support@shtc.co.in.

The request should identify:

  • The Material requested;
  • The proposed purpose;
  • The intended audience;
  • The number of users or copies;
  • The method of distribution;
  • The duration of use;
  • Whether the use is commercial; and
  • The countries or territories in which it will be used.

No permission is granted unless SHTC issues express written approval through an authorised representative of Insadec Services Private Limited.

Silence, non-response or previous informal access does not constitute permission.

Governing Law and Jurisdiction

This Policy is governed by the laws of India.

Subject to any mandatory legal forum, arbitration provision or dispute-resolution mechanism contained in the applicable agreement, courts at [Insert City and State] shall have jurisdiction over disputes arising from this Policy.

Changes to this Policy

Insadec may update this Policy to reflect changes in:

  • Applicable laws;
  • SHTC Services;
  • Licensing arrangements;
  • Technology;
  • Intellectual-property ownership; or
  • Operational requirements.

The updated Policy will display its effective date.

Material changes affecting existing paid licences will be handled in accordance with the applicable agreement. Continued use will not retrospectively remove a permission expressly granted under a valid written agreement.

Severability

If any provision of this Policy is held invalid or unenforceable, the remaining provisions will continue to apply to the fullest extent permitted by law.

Order of Precedence

In the event of any inconsistency between this Policy and a specific written agreement executed between Insadec and the Client, the specific written agreement shall prevail to the extent of such inconsistency.

Contact Information

Questions concerning copyright, licensing or permitted use may be addressed to:

Insadec Services Private Limited
Operating under the brand name SHTC
Copyright Contact: Ankur Gohri
Email: support@shtc.co.in
Telephone: +91 7042500326
Registered Address: C/O Workingdom, Block A, 2nd Floor, Plot No. 11, 12, 16, 17 Palam Extension, Sector 7 Dwarka, Delhi, 110077 India

Copyright Notice

© 2021–2026 Insadec Services Private Limited. All rights reserved. SHTC is a brand operated by Insadec Services Private Limited.

All SHTC website content, training programmes, course modules, videos, presentations, assessments, question banks, certificates, handbooks, policies, templates, toolkits, graphics, reports, software and other Materials—including Materials created, supplied or accessed before 2026—are protected under applicable copyright and intellectual-property laws.

No Material may be copied, reproduced, recorded, modified, translated, republished, distributed, uploaded, transmitted, commercially exploited, used to provide competing services or used to train an artificial- intelligence system without the prior written permission of Insadec Services Private Limited, except as expressly permitted by applicable law or a valid written agreement.

Policy Faq's

Common Questions About Our Privacy Practices

SHTC retains personal data only for as long as reasonably necessary for the purpose for which it was collected.

The retention period depends on the nature of the information and may be determined by:

  • The duration of the training programme or subscription;
  • Instructions received from the corporate client;
  • Assessment and certificate-verification requirements;
  • Contractual commitments;
  • Legal, tax, accounting and regulatory obligations;
  • Security and audit requirements;
  • Dispute resolution; or
  • The establishment, exercise or defence of legal claims.

When personal data is no longer required, it is securely deleted, anonymised or returned to the relevant client. Information may remain temporarily in secured backups until it expires under the applicable backup-retention cycle.

Yes. You may request deletion of your personal data by emailing support@shtc.co.in with the subject line “Privacy Deletion Request.”

Please include your name, organisation, registered email address and sufficient information to identify the relevant account or record. SHTC may verify your identity before processing the request.

Deletion may not be possible where the information must be retained for:

  • A legal, contractual or regulatory obligation;
  • Certificate verification;
  • Compliance reporting;
  • An ongoing dispute or investigation;
  • Security or fraud prevention;
  • A legal claim; or
  • Another purpose permitted by applicable law.

Where SHTC processes your information on behalf of your employer or another corporate client, we may refer the request to that organisation or assist it in responding because the client may be the Data Fiduciary responsible for deciding whether the data should be deleted.

SHTC may share personal data only where it is necessary to provide, secure or administer its Services.

Recipients may include:

  • The employer or organisation that assigned or purchased the training;
  • Authorised corporate administrators;
  • Learning-platform and hosting providers;
  • Email, webinar and customer-support providers;
  • Payment and accounting service providers;
  • Authorised trainers, consultants and external IC members;
  • Security and technology providers;
  • Professional advisers, auditors and insurers; and
  • Government bodies, regulators, courts or law-enforcement authorities where required or permitted by law.

Service providers are expected to process information only for authorised purposes and under appropriate confidentiality, security and contractual obligations.

SHTC does not sell personal data to third parties.

If your employer or organisation enrols you in an SHTC programme, its authorised administrators may receive information required to manage and document the training, including:

  • Enrolment status;
  • Course participation;
  • Training progress;
  • Completion status;
  • Assessment score;
  • Certificate status; and
  • Pending-training reminders.

Your employer determines how it uses these reports for training, workplace compliance or administration. SHTC restricts access to authorised administrators associated with the relevant corporate account.

SHTC applies reasonable technical and organisational measures proportionate to the nature and sensitivity of the information being processed.

Depending on the relevant system and information, these measures may include:

  • Role-based access;
  • Least-privilege controls;
  • Strong authentication;
  • Multi-factor authentication for appropriate accounts;
  • Secure transmission of information;
  • Encryption where appropriate;
  • Logging and monitoring;
  • Backup and restoration arrangements;
  • Vulnerability identification and remediation;
  • Vendor-security assessment;
  • Confidentiality obligations;
  • Employee privacy and security awareness;
  • Incident-response procedures; and
  • Secure deletion and disposal.

No digital system is completely secure. Users must protect their login credentials and immediately report suspected unauthorised access to support@shtc.co.in.

Insadec Services Private Limited, operating under the brand name SHTC, is certified to ISO/IEC 27001:2022 for information security management and ISO 9001:2015 for quality management, within the scope specified on the respective certificates.

These certified management systems support SHTC’s approach to information security, risk management, access control, incident management, service quality, internal audits, corrective action and continual improvement. Certification does not guarantee absolute security, and SHTC continues to assess and improve its safeguards according to the nature and risk of the personal data processed.

General website forms and routine LMS functions are not channels for filing a PoSH complaint or submitting complaint evidence.

Where SHTC is separately authorised to handle PoSH complaint or inquiry information, enhanced safeguards may include:

  • Strict need-to-know access;
  • Segregation from ordinary training records;
  • Confidentiality undertakings;
  • Secure submission and transfer;
  • Restricted copying and downloading;
  • Access records;
  • Case-specific retention; and
  • Secure return or destruction.

SHTC does not use identifiable complaint, complainant, respondent, witness or inquiry information for marketing, testimonials, public training, demonstrations or general-purpose artificial-intelligence systems.

SHTC maintains procedures to identify, contain, assess, investigate, document and remedy suspected personal data breaches.

Where SHTC processes information for a corporate client, it will notify and assist that client in accordance with the applicable agreement.

Where required by law, SHTC or the responsible Data Fiduciary will notify affected individuals and the competent authority in the prescribed manner and timeframe. The notification may explain:

  • What happened;
  • What information may be affected;
  • The likely consequences;
  • Measures taken to address the incident;
  • Actions the affected person may take; and
  • Where to obtain assistance.

Yes. You may ask SHTC to correct, complete or update inaccurate or incomplete personal data by contacting support@shtc.co.in with the subject line “Privacy Correction Request.”

SHTC may verify your identity before making a change.

If your employer provided the information, SHTC may ask the authorised corporate administrator to confirm the requested update.

Yes. You may update your privacy or communication preferences by:

  • Using the unsubscribe link in a marketing email;
  • Changing available settings in your account;
  • Using the website’s cookie preference tool; or
  • Contacting support@shtc.co.in.

Withdrawing marketing consent will stop future promotional communications after a reasonable processing period. SHTC may retain a minimum suppression record so that your preference continues to be honoured.

Training reminders, security alerts, contractual notices and essential service communications may continue while the relevant service relationship exists.

Where SHTC relies on consent, you may withdraw it by using the method communicated when consent was obtained or by contacting support@shtc.co.in.

Withdrawal will not affect processing already lawfully undertaken before the withdrawal.

If the relevant personal data is necessary to provide a requested Service, withdrawing consent may limit or end that Service. SHTC will explain the consequence before completing the request.

SHTC may use necessary cookies to operate and secure its website and learning platform. Subject to your choices and applicable law, it may also use functional, analytics or marketing cookies.

Where consent is required, non-essential cookies should remain disabled until you accept them. You may reject or manage non-essential cookies through the cookie preference tool or your browser settings.

Please read the SHTC Cookie Policy for further information.

SHTC does not sell personal data.

SHTC may use limited contact information to send relevant service updates, compliance information, learning resources or event invitations where permitted. You may opt out of marketing at any time.

SHTC does not use identifiable PoSH complaint or inquiry information for advertising or marketing.

SHTC does not use routine learning scores or website behaviour to make solely automated employment decisions about learners.

Corporate clients independently determine how authorised training reports are used.

Identifiable PoSH complaint or inquiry information must not be entered into public generative-AI systems or used to train general-purpose AI models.

No. GDPR is a European data-protection law, not a general certification held by SHTC.

SHTC applies GDPR-aligned privacy principles where appropriate. Where GDPR applies to a specific service or client arrangement, SHTC assesses the relevant requirements and implements appropriate contractual, security, rights-management and international-transfer safeguards.

SHTC does not describe itself as “GDPR certified” or make an unqualified claim of full GDPR compliance.

SHTC is implementing privacy and security controls aligned with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 according to their phased commencement and applicability.

The principal operational provisions affecting ordinary Data Fiduciaries are scheduled to take effect on 13 May 2027. SHTC is using the transition period to strengthen privacy notices, consent management, individual rights, security safeguards, breach response, grievance redressal, retention and Processor oversight.

You may submit a privacy request or grievance to:

Privacy and Grievance Officer
Insadec Services Private Limited
Operating under the brand name SHTC
Email: support@shtc.co.in
Website: www.shtc.co.in

Please include your name, organisation, registered email address, relationship with SHTC and the nature of your request.

This privacy contact is not a channel for submitting a workplace sexual-harassment complaint. For a PoSH complaint, contact the Internal Committee or authorised reporting channel communicated by the relevant employer.