Legal
Privacy Policy
National Nutrition and Wellness Academy, trading as NNWA Nutrition & Wellness Academy ("NNWA"), provides online nutrition and wellness education from Kolkata. This Privacy Policy is our notice of how we collect, use, share, keep and protect personal data on nnwa.in, through our enquiry channels, our programmes, our verification pages and our consultancy. By using the site, enquiring, enrolling or booking a consultation you accept this Policy.
Last updated: 12 September 2026.
Part 1: Who we are and what this Policy covers
1.1 The Data Fiduciary
National Nutrition and Wellness Academy, trading as NNWA Nutrition & Wellness Academy ("NNWA", "we", "us" or "our"), registered office 64/4A Graham Road, Third Floor, Regent Park, Kolkata 700 040, West Bengal, India, decides why and how the Personal Data described in this Policy is processed. We are its Data Fiduciary under the DPDP Act and the body corporate responsible for it under the IT Act. Our contact details and Grievance Officer are in clause 17.1.
1.2 What this Policy covers
Personal Data we process when you visit nnwa.in (the "Site"); enquire, request a brochure or free guide, or contact us by email, telephone or WhatsApp; attend a webinar or workshop; enrol in a Programme and use the Learning Platform; book a consultation with NNWA Clinic and Wellness Consultancy as it operates today; appear on a verification page; take part in Refer and Earn; give a testimonial; or work with us as staff, faculty, mentor, counsellor, intern or contractor.
1.3 What this Policy does not cover
Services operated by others, including our payment aggregator's checkout pages, finance partners, the Awarding Body, WhatsApp and social media platforms, each of which processes your data under its own policy (Part 15). Nor any separate clinical records system, application or platform we may build or operate for consultations in future: it will carry its own privacy notice, and nothing here extends to it by implication. Health information given for a consultation today is governed by Part 11.
1.4 Applicable Data Protection Law
"Applicable Data Protection Law" means section 43A of the Information Technology Act 2000 (the "IT Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (the "SPDI Rules"); the Digital Personal Data Protection Act 2023 (the "DPDP Act") and its rules, as and when each provision is in force; and any other Indian law regulating Personal Data. The DPDP Act is being brought into force in phases; at the date of this Policy its provisions on notice, consent, rights and Data Fiduciary obligations had not commenced, and until they do the IT Act and SPDI Rules are the operative law. We apply the DPDP Act's standards from the date of this Policy regardless, and this Policy is intended to be the notice the DPDP Act requires for consent given before and after commencement.
1.5 Defined terms
- "Personal Data" means any data about an individual identifiable by or in relation to it. "Sensitive Personal Data" means passwords, financial details such as bank account or payment instrument information, physical, physiological or mental health information, sexual orientation, medical records and history, biometric information, and any other category the Applicable Data Protection Law treats as sensitive.
- "Data Principal" means the individual the Personal Data relates to and, for a person under 18, includes the parent or lawful guardian. "Data Processor" means a person who processes Personal Data on our behalf.
- "Programme" means any course we offer; "Flagship Programme" and "Short Course" are defined in the Terms. "Learning Platform" means the third-party learning management, live-class and recording services through which we deliver Programmes. "Awarding Body" means Medhavi Skills University, Sikkim, through which Flagship Programmes are awarded under the partnership in force from time to time. "Content Platform" means the third-party content management service holding the Site's content and the records in clause 2.3 and clause 2.4.
- "Enquirer", "Learner" and "Client" mean a person who enquires or contacts us, a person enrolled in a Programme, and a person who books a consultation. "Service Communications", "Marketing Communications" and "Consent Record" are defined in clause 9.1, clause 9.2 and clause 3.4. "Terms" means our Terms and Conditions; "Refund Policy" means our Refund and Cancellation Policy; "Board" means the Data Protection Board of India; "Grievance Officer" means the person named in clause 17.1.
Part 2: The Personal Data we collect
2.1 Identity and contact data
Your name, email address, telephone number and city. At enrolment: your name exactly as it is to appear on a certificate; your date of birth or age where a Programme or the Awarding Body requires it; documents proving the eligibility you claim, where required; and billing details you ask us to show on an invoice. Where a parent or lawful guardian enrols a person under 18: the parent's or guardian's identity, contact details and basis of guardianship.
2.2 Enquiry and lead data
The Site has two enquiry forms, one site-wide and one on the admissions page. We receive what you type: name, email address and telephone number and, on the admissions form, city, the Programme you are interested in and a free-text message about your background and what you want from a qualification. The Site attaches, without your typing it, the address of the page you were on (including any query string), the campaign parameters you arrived with (source, medium, campaign, term and content), a label identifying the form and, for a brochure request, which brochure you asked for. We use these to attribute our marketing and give your counsellor the context of your interest. Do not put health, financial or identity-document details in the free-text field; if you do, Part 11 applies and we may delete them.
2.3 Learner records and certificates
Name, learner code, email address, Programme, batch, enrolment status, attendance, assessments and results, Programme correspondence, the certificates issued with their identifiers and status (issued or revoked) and, for Flagship Programmes, the data the Awarding Body requires. Name, learner code, email address, Programme, batch, status and certificate list are held in the Content Platform, from which the Site and the verification pages in Part 7 are built.
2.4 Employee, faculty and contractor records
For employees, faculty, mentors, counsellors, interns and contractors: identity, contact, qualification, credential, bank, tax, attendance, performance, engagement and exit records. For those whose role involves it: the name, employee identifier, designation, department, status, date of joining and, where the person has agreed in writing, the telephone number, email address and LinkedIn profile shown on the employee verification page (clause 7.3), and the biography, credentials and photograph published on the Site (clause 10.5). Unsuccessful applicants' data is deleted after twelve months.
2.5 Payment metadata
Fees are paid through an RBI-authorised payment aggregator, at present Razorpay, on a checkout page it operates under its own terms and privacy policy or, if you choose financing, through a finance partner. Card numbers, security codes, UPI credentials and net-banking details are entered on their pages and never reach us. We keep only what accounts for your fee: your name, the amount, date, Programme, transaction and order references, the type of payment method, a masked reference where supplied, and the invoice and any credit note we issue. A payment method saved for instalments is held as a token by the aggregator and card network, not by us, and can be removed through their channels.
2.6 Communications
The content and metadata of your emails, calls, WhatsApp messages, Learning Platform messages and support requests, including time, channel, the number or address used and any attachment. WhatsApp conversations are held with our WhatsApp Business service provider (clause 9.3). We do not record calls unless we say so at the start.
2.7 Analytics, cookies, browser storage and device data
When you use the Site, Google Tag Manager loads Google Analytics 4, which collects the address of each page you view (including campaign parameters), the referring address, browser and device type, screen size and language, an approximate location derived from your IP address, a pseudonymous client identifier held in a cookie, and the events in clause 8.3. Our own code sets no cookie; it writes three items to session storage that clear when you close the tab (clause 8.1). Our hosting provider records access logs (IP address, browser identifier, page, referring address and time) and may set a cookie recording that your browser passed its automated bot check. Images are fetched from the Content Platform's delivery network, which sees your IP address. The chat widget in clause 8.5 loads on every page.
2.8 Assessments and submissions
Assignments, case work, projects, examination answers, posts in any community space we host, questions asked in live sessions and feedback you give, which may include your opinions and, where an exercise involves a real person, the data in clause 10.6.
2.9 Recordings of live classes and webinars
Live classes, mentoring sessions, webinars and workshops may be recorded. A recording captures the voice, likeness, display name, chat messages and on-screen contributions of every participant with a microphone or camera on or who writes in the chat. Part 10 explains how recordings are used and how to limit your appearance.
2.10 Consultation data
When you book a consultation with NNWA Clinic and Wellness Consultancy we collect, through an intake form and during the consultation, your health goals, diet and lifestyle history, measurements, medical conditions, medicines, allergies, pregnancy status and anything else you tell us. This is health information, therefore Sensitive Personal Data, governed by Part 11.
2.11 Testimonials, faculty profiles, case studies and referral data
For a testimonial or graduate story you agree to give: the name you wish to be credited with, your role, employer, photograph, rating and words. For faculty and authors: name, role, credentials, biography and photograph. Case studies on the Site are composites containing no real person's data (clause 10.4). Under Refer and Earn: the referrer's and referred person's names and contact details, the referral date and whether it leads to a confirmed enrolment, so that we can decide and pay any reward under the Terms and account for it as tax law requires.
2.12 What stays in your browser, and what we do not collect
The calculators on the Site take health-related inputs, including age, sex, height, weight, waist, hip and neck measurements, activity level, weeks of pregnancy and family history of diabetes. Every calculation runs in your browser: nothing is sent to us or anyone else, nothing is stored, and the values vanish when you leave the page. The copy guard, which adds a source line when you copy a long passage and stops images being dragged or saved, collects and transmits nothing. The Site has no newsletter sign-up form and no quiz or poll. We do not collect full card numbers, card security codes, UPI PINs, net-banking credentials, biometric data, or data about caste, religion or political opinion, and we do not collect a Learner's health information as part of a Programme except as clause 11.5 describes.
Part 3: Purposes and lawful basis
3.1 Purposes by category
We process each category only for the purposes stated against it:
- Identity and contact data: to identify and communicate with you, confirm eligibility and enrolment, invoice you, register you with the Awarding Body and issue certificates in the correct name.
- Enquiry and lead data: to respond to your enquiry, counsel you on Programmes, send the welcome email and first WhatsApp message (clause 9.1), release what you asked for, and attribute the enquiry to the page, campaign or referral that produced it.
- Learner records and certificates: to deliver the Programme, assess your work, issue and where necessary revoke certificates, operate the verification pages, answer verification requests, and keep the academic record a certificate rests on.
- Employee, faculty and contractor records: to recruit, engage, pay and manage the person and, where the role requires, publish their role, credentials and verification record.
- Payment metadata: to collect fees, administer instalments and financing you request, issue invoices and credit notes, process refunds, respond to payment disputes and chargebacks, and keep the records tax law requires.
- Communications: to answer you, record what was agreed, train and supervise staff, and evidence our dealings if a dispute arises.
- Analytics, cookies, browser storage and device data: to measure use of the Site, attribute enquiries to campaigns, make the enquiry and brochure features work, keep the Site secure and detect faults and abuse.
- Assessments and submissions: to assess and give feedback, maintain academic integrity and, anonymised, improve teaching. Recordings: to deliver a session to those who missed it, teach the batch and later batches, and review teaching quality.
- Consultation data: to provide the consultation you booked and keep the record of guidance given. Testimonials, faculty profiles and graduate stories: to publish them with consent. Referral data: to run Refer and Earn and pay rewards.
- All categories: to evidence your agreement and consents (clause 3.4); to comply with tax, accounting and other legal obligations and lawful requests (clause 6.3); to establish, exercise or defend legal claims; and to keep our systems secure.
3.2 Lawful basis
Each purpose rests on one or more of: your consent, given by a clear affirmative action, for Marketing Communications, publication of your name, likeness or words, use of recordings beyond your own batch, Sensitive Personal Data, analytics cookies where the Applicable Data Protection Law requires consent for them, and any purpose not covered by another basis; your voluntary provision of Personal Data for a specified purpose you have not objected to, which covers responding to an enquiry, sending what you asked for, replying to your message and providing the Programme or consultation you asked for; performance of the contract formed when you enrol or book, which is also the agreed basis under the SPDI Rules for disclosure to the Awarding Body, the Learning Platform providers, the payment aggregator and a finance partner you choose; compliance with a legal obligation; employment purposes, for staff data; and the operation and security of the Site and Learning Platform as part of the service you asked for.
3.3 Purpose limitation
We do not use Personal Data for a purpose outside clause 3.1 unless we first tell you and, where the Applicable Data Protection Law requires it, obtain your consent. An enquiry about one Programme is not authority for indefinite promotion of others; clause 9.2 and clause 12.2 limit what we send and how long we keep a lead.
3.4 The Consent Record
Each time you accept the Terms, the Refund Policy or this Policy, or give or withdraw a consent, we record the fact, date and time, the form or page used, the version shown to you, the choices you made and the IP address used. We keep this Consent Record because the Applicable Data Protection Law places on us the burden of proving valid notice and consent, and because it evidences our contract. It is kept for the period in clause 12.2.
Part 4: Consent
4.1 How consent is given
By a clear affirmative action: ticking a box that was not pre-ticked, clicking a button whose label states what you are agreeing to, replying to a message with the word we ask for, or submitting a form beneath a statement of what will follow. Where more than one consent is asked for, each is a separate choice, and no service is made conditional on a consent it does not need.
4.2 What an enquiry consents to
Both enquiry forms state that by submitting the form you agree to be contacted about NNWA Programmes and accept this Policy. Submitting a form, asking for a brochure or free guide, or starting a WhatsApp conversation with us is your request to be contacted about that enquiry and your consent to be contacted about NNWA Programmes by telephone call, email and WhatsApp for admissions and counselling. It authorises the welcome email, the first WhatsApp message and a counsellor's follow-up. A brochure is released after you submit the enquiry form; the free guide is sent by email or WhatsApp after an enquiry; the recipe book is a direct download that collects nothing. An enquiry does not by itself authorise Marketing Communications unrelated to it (clause 9.2), and you may stop the contact at any time under clause 4.5.
4.3 What enrolment involves
Enrolling requires the processing needed to deliver the Programme: holding your identity and contact details, operating your Learning Platform account, assessing your work, registering you with the Awarding Body for a Flagship Programme, issuing your certificate and publishing the verification record in clause 7.2. It also involves recording of the live sessions you attend (clause 10.1). Each is stated separately at enrolment and recorded in the Consent Record.
4.4 Sensitive Personal Data
We ask for your express, specific consent before collecting Sensitive Personal Data and tell you then what we will collect, why, who will see it and for how long. You may decline; if you decline to give health information needed for a consultation, we may be unable to provide it.
4.5 Withdrawing consent
You may withdraw any consent at any time, as easily as you gave it: by the unsubscribe or STOP route in a message, by a setting where one is offered, or by writing to contact@nnwa.in with the subject "Withdraw consent". Withdrawal takes effect within seven days for Marketing Communications and within a reasonable time not exceeding thirty days otherwise, and we instruct our Data Processors accordingly. It does not affect processing already done or require erasure of data clause 12.3 requires us to keep.
4.6 Effect of withdrawal on a Programme in progress
If you withdraw consent to processing that clause 4.3 describes as needed to deliver a Programme, we cannot continue it and will treat the withdrawal as your withdrawal from the Programme; the Refund Policy governs whether any fee is refundable, and the consequences are yours, as the DPDP Act provides. Withdrawing consent to Marketing Communications, to use of a recording for later batches, or to a testimonial does not affect your Programme.
4.7 Consent Managers
Once Consent Managers registered with the Board are available, you may give, review and withdraw consent through one, and we will act on a withdrawal received that way as if sent to us directly.
4.8 Your duties
The DPDP Act requires a Data Principal not to impersonate anyone, not to suppress material information when giving Personal Data for a document or identity proof, not to register a false or frivolous grievance, and to give only verifiably authentic information when asking for correction or erasure. We rely on the accuracy of the contact details (clause 9.5) and eligibility information you give.
Part 5: Children
5.1 Our services are for adults
Our Programmes, consultations and Marketing Communications are directed at adults. A person under 18 may enrol only through a parent or lawful guardian, who is the contracting party under the Terms and the person who consents under this Policy.
5.2 Verifiable parental consent
Before processing the Personal Data of a person we know to be under 18, we obtain the verifiable consent of the parent or lawful guardian, verifying that the person consenting is an identifiable adult by reference to identity details they give us or we already hold, or a government-backed identity or age token where available, and recording the verification in the Consent Record. A ticked declaration that a person is the parent is not, on its own, verifiable consent.
5.3 No tracking or targeted advertising
We do not track or monitor the behaviour of a person we know to be under 18 and do not direct targeted advertising at children. Where a parent enrols a child we process only what the Programme needs and send no Marketing Communications to the child.
5.4 If we learn that consent was missing
If we learn that we hold a person under 18's Personal Data without verifiable parental consent, we delete it, except what clause 12.3 requires us to keep; the Terms and Refund Policy govern an enrolment made by misstating age. A parent or guardian who believes this has happened should write to the Grievance Officer.
Part 6: Who receives your Personal Data
6.1 Data Processors
The following process Personal Data on our behalf and instructions, under contracts or accepted service terms requiring confidentiality, security safeguards and notification to us of a breach. Each holds data in the location stated in its own published terms.
- Forms and customer relationship management: Zoho Forms and Zoho CRM (Zoho, India data centre), which receive enquiry and lead data and hold our record of contact with you.
- Automation: an automation service that passes a new lead from Zoho CRM to our WhatsApp Business service provider so the first WhatsApp message can be sent; it transfers the lead and does not keep it.
- WhatsApp Business messaging: Interakt, a WhatsApp Business service provider, which sends and receives messages on our WhatsApp number and holds the conversation history.
- Analytics: Google, through Google Tag Manager and Google Analytics 4 (Part 8).
- Content management: Sanity, the Content Platform, with servers outside India (clause 6.6), holding Site content and the records in clause 2.3 and clause 2.4 from which the Site and verification pages are built.
- Build and deployment: GitHub, whose systems build the Site from the published content. Hosting: Hostinger, which serves the Site, keeps its access logs and holds the three most recent pre-deployment backups.
- Learning Platform: the learning management, live-class and recording services through which we deliver Programmes.
- Email and office tools, and professional advisers such as accountants and lawyers, all under confidentiality obligations.
6.2 Recipients who process for their own purposes
These decide for themselves how they process your data, under their own policies, and are not our Data Processors: the payment aggregator, an RBI-authorised entity operating the checkout page; a finance partner, for a loan or instalment plan you apply for, to which we give only what identifies you and the fee, at your request; the Awarding Body, for registration, assessment and certification on a Flagship Programme under the partnership in force at the time; WhatsApp and its operator, Meta, for messages you exchange with us; social media platforms, for anything you post or send there (clause 15.2); and Google, to the extent its analytics or advertising services process data for its own purposes.
6.3 Disclosures required by law
We disclose Personal Data to a court, tribunal, law enforcement agency, regulator, tax authority or the Awarding Body where a law or binding order requires it, or where necessary to establish, exercise or defend a legal claim. We verify the authority of the request, disclose only what is required, and tell you where the law permits.
6.4 Successors
If our business, or the part that serves you, is transferred to a successor, including on a change of legal form, merger, sale or reorganisation, your Personal Data may be transferred so the services continue. The successor takes it on terms no less protective than this Policy, and we notify you by email or a notice on the Site.
6.5 Changes of Data Processor
We may replace or add a Data Processor for a purpose in clause 3.1; we update this Policy when we do, and the new Data Processor is bound as clause 6.1 describes.
6.6 Transfers outside India
The Content Platform, holding the records in clause 2.3 and clause 2.4, has its servers outside India; Google may process analytics data outside India; the Site is built on GitHub's systems outside India; WhatsApp operates globally; each other Data Processor holds data where its published terms state. We transfer data outside India only where necessary to provide the Site and the services you asked for, to a provider whose terms commit it to protection to a standard not lower than that required of us, and with your consent given when you accept this Policy. The DPDP Act permits transfer to any country other than one the Central Government restricts by notification; if such a restriction affects a Data Processor holding your data, we will move the data or cease the transfer within the time the notification allows.
Part 7: Public verification pages
7.1 Certificate verification
So that employers, clients and institutions can confirm a certificate is genuine, the Site publishes a verification record for every certificate we issue. It shows the Learner's name, the certificate's title and description, the certificate identifier, and whether it was genuinely issued by NNWA or has been revoked; nothing else, and no contact details, marks, date of birth or photograph. It is found by entering the certificate identifier or an exact match on the Learner's name or email address, and a further page lists every certificate a Learner holds; that page's address is printed as a QR code on the certificate. Search terms go from your browser to the Content Platform and are not kept by us.
7.2 Consent to publication as a condition of certification
Publication of the verification record is how a certificate is authenticated, so consent to it is a condition of certification, asked for separately at enrolment and recorded in the Consent Record. You may withdraw it under clause 4.5. If you do, we remove your record from the verification pages within thirty days; your certificate remains valid and we will confirm it to an employer or client who writes to contact@nnwa.in with your written authority, but it will no longer be verifiable online and the QR code on it will not resolve.
7.3 Employee verification
To protect prospective Learners from people who falsely claim to represent us, the Site publishes a verification record for staff whose role involves public contact. It shows the person's name, employee identifier, designation, department, status (including whether they are no longer associated with NNWA), date of joining and, only where the person has agreed in writing, a telephone number, email address and LinkedIn profile. It is found by entering the employee identifier or an exact match on the name, telephone number or email address. Publication is a condition of a public-facing role, consented to in the engagement paperwork. The record confirms only that the person holds or held that role; it is not authority to collect payment or make commitments for us, which happens only through the channels in clause 13.4. A person who leaves is shown as no longer associated within thirty days and the record is removed within twelve months.
7.4 Accuracy, correction and removal
A verification record states a fact others rely on, so we keep it accurate and complete. If yours is wrong, write to contact@nnwa.in with the certificate or employee identifier; we correct an error of ours within ten working days and tell you. Revocation follows the process in the Terms, and the record then shows only that the certificate is revoked, not why.
7.5 Permitted use of the pages
The pages exist to confirm one certificate or one person's role at a time. Automated, bulk or repeated querying, harvesting of names or contact details, and use for marketing, recruitment lists or any purpose other than verification are prohibited by the Terms, and we may block and pursue anyone who does so. We publish no list of Learners, employees or certificates, and the pages are excluded from search engine indexing.
Part 8: Cookies, tags and browser storage
8.1 What our own code stores
Our code sets no cookies. It writes three items to session storage, all cleared when you close the tab: the campaign parameters of the first page you landed on, so an enquiry can be attributed to the campaign that brought you; a flag that the exit prompt has been shown, so it is not shown again; and the identifier of a brochure you asked for, so it can be released after you submit the enquiry form. None identifies you or is read by anyone else.
8.2 Third-party cookies
Cookies may be set by Google through the tag container, including analytics cookies carrying a pseudonymous client identifier that by Google's default last up to two years; by the WhatsApp Business service provider whose chat widget loads on every page (clause 8.5); by our hosting provider, to record that your browser passed its bot check; and by Zoho, within the enquiry form, which is embedded from Zoho's servers. Each is set by that provider under its own policy and lifetime and can be blocked or deleted through your browser (clause 8.6).
8.3 Google Tag Manager and Google Analytics 4
The tag container loads Google Analytics 4 when a page loads. It records page views, opening of the enquiry form, taps on WhatsApp and call buttons, the thank-you page view after an enquiry, and how far down a page you read, with the page and referring addresses, device and browser data, approximate location from your IP address and the pseudonymous identifier. Google does not store your full IP address in the analytics data. We have set retention to fourteen months, after which event data tied to your identifier is deleted by Google; aggregated reports identifying no one are kept longer. We will ask for consent before loading analytics tags where the Applicable Data Protection Law requires it.
8.4 Advertising and measurement tags
The tag container may also carry conversion-measurement or advertising tags from advertising platforms we use, to measure whether an advertisement led to an enquiry and to show advertisements to people who visited the Site. Any such tag is loaded and managed through the tag container, and this Policy is our notice of it. You can opt out under clause 8.6. We do not use advertising tags to profile a person we know to be under 18, and do not target advertising on the basis of health information.
8.5 The chat widget and other third-party requests
A chat widget supplied by our WhatsApp Business service provider loads on every page shortly after it finishes loading, whether or not you open it. On loading it may collect the page and referring addresses, your IP address and browser identifier, and may set its own identifiers; if you open it, a WhatsApp conversation begins under clause 9.3. Every WhatsApp button opens WhatsApp with a message already filled in naming the page you were on; you can edit or delete it before sending. Images come from the Content Platform's delivery network; fonts are served from our own hosting, so no request goes to a font service.
8.6 How to opt out
Refuse or delete cookies in your browser settings; block analytics cookies with Google's browser add-on for opting out of Google Analytics; adjust advertising preferences through your Google account and the advertising settings of any other platform whose tag we use; or disable scripts, which stops the tag container and chat widget loading. The Site works without cookies: the enquiry form, brochure release and calculators do not depend on them, and refusing cookies does not affect any Programme you are enrolled in. If you would rather write to us, contact@nnwa.in will explain the options for your browser.
Part 9: How we contact you, and marketing
9.1 Service Communications
"Service Communications" are messages about your enquiry, enrolment, Programme, consultation, payment or account: the welcome email and first WhatsApp message sent automatically after an enquiry; a counsellor's replies about the Programme you asked about; batch dates, timetables, session reminders, recordings, results and certificate notices; invoices, receipts and payment reminders; verification and security notices; and notice of changes to the Terms or this Policy. We send them by email, WhatsApp, SMS, telephone and the Learning Platform because they are part of the service you asked for, and they continue if you opt out of Marketing Communications.
9.2 Marketing Communications and DND
"Marketing Communications" are messages about Programmes, offers, events, webinars or services other than the one you enquired about or enrolled in. We send them only with your consent, given by a separate unticked choice or by your reply to a message asking for it, and every one carries a way to stop further messages on that channel. Promotional SMS and calls follow the Telecom Commercial Communications Customer Preference Regulations 2018; we do not send promotional SMS or make promotional calls to a number on the national Do Not Disturb register unless you have given us recorded consent, and you may register or withdraw through your telecom operator. An opt-out takes effect within seven days on the channel concerned.
9.3 WhatsApp
Our WhatsApp number is +91 99039 36057, for messages only. Messages are sent and received through Interakt, our WhatsApp Business service provider, which holds the conversation history for the period in clause 12.2, and are carried by WhatsApp under WhatsApp's own privacy policy. Business-initiated messages are sent only after you opt in by enquiring or replying to us. To stop them, reply STOP, block the number, or write to contact@nnwa.in. Do not send health information, financial details, passwords or identity documents over WhatsApp; where a Programme or consultation needs a document, we tell you the channel to use.
9.4 Calls and SMS
Our telephone number for calls is +91 82409 00957. Calls from us are made by our counsellors and staff and are not recorded unless we say so at the start. If you do not wish to be called, tell the caller or write to us and we mark your record within seven days. SMS is used for Service Communications and, only with consent, for marketing.
9.5 Wrong numbers and automated messages
If you give a telephone number or email address that is not yours, our automated welcome messages reach whoever holds it. You warrant that the contact details you give are yours, and we are not responsible for messages sent to details you supplied. Anyone who receives a message not meant for them may reply STOP or write to contact@nnwa.in, and we delete the details from the lead record. An automated message is informational: if one is sent in error, duplicated or mistimed we correct it on request, and it does not vary any written confirmation we have given you.
9.6 Our notice channel
Our primary channel for notices to a Learner is the email address on the Learner's record; WhatsApp, SMS and the Learning Platform are supplementary. Keep your email address current. A notice sent there is treated as received on the next working day.
Part 10: Recordings, testimonials and published content
10.1 Recordings of live classes
Live classes and mentoring sessions are recorded so that Learners who miss a session can watch it and so the recording can teach the same batch and later batches. By attending you consent to appear in the recording and to that use, recorded in the Consent Record at enrolment. You may keep your camera and microphone off, take part in writing, and use a display name that is not your full name. You may withdraw consent to use for later batches at any time; the withdrawal applies to recordings made after we receive it and does not require us to edit or delete recordings already made, which we keep under clause 12.2. We do not use a class recording in marketing without your separate written consent. Learners may not make their own recordings; the Terms treat doing so as misconduct. The live-class tool is a third-party service and your participation is also subject to its own terms.
10.2 Webinars and workshops
Free webinars and workshops are recorded and may be published or used in marketing. Registration collects your name, email address and telephone number and, if you choose it, the consent in clause 9.2. Attendees appear only through the display name they choose and anything they say aloud or write in a public chat; we do not show attendee video. Questions asked live are answered as general information and are not a consultation.
10.3 Testimonials and graduate stories
We publish a testimonial, graduate profile or alumni entry only with the written consent of the person, obtained after the result it describes, and only in the form (name as credited, role, employer, photograph, words, rating and channels) the consent covers. You may withdraw by writing to contact@nnwa.in; we remove the item from the Site and our own channels within thirty days, though copies already printed or distributed by others cannot be recalled.
10.4 Case studies are composites
The case studies on the Site are illustrative composites drawn from several Learners' experience. Names, cities and details are invented and each page says so; they contain no real person's Personal Data, and any resemblance to a real person is coincidental. A real graduate's story would be published only with written consent under clause 10.3 and labelled as real.
10.5 Faculty, mentors and authors
The names, roles, credentials, biographies and photographs of faculty, mentors, reviewers and authors are published on the Site and in the structured data search engines read, on the basis of their engagement with us and agreement to be published. When a person leaves we remove their profile within thirty days; content they wrote or reviewed keeps their name as author, as copyright law contemplates.
10.6 Your submissions and other people's data
You own the work you submit. We hold a licence, described in the Terms, to store it, assess it, show it to faculty and, anonymised, use it for teaching and quality review. If an exercise involves a real person, such as a family member's or client's diet history, you must anonymise their data or obtain their consent before submitting, and never submit another person's health information without consent. We may reject, redact or delete a submission that breaks this rule.
10.7 Community spaces
Where we host a community space for a batch, what you post is visible to other members and our staff. Do not post another person's Personal Data or health information; we remove it, may suspend the poster, and may report it where the law requires. Where we host user content we retain a user's registration data, and content we remove, for one hundred and eighty days after removal or account closure, as the intermediary rules under the IT Act require.
Part 11: Consultations and health information
11.1 Health information is Sensitive Personal Data
Health information given for a consultation is Sensitive Personal Data. We collect it only with your express consent on the intake form, only for the consultation you booked, and only to the extent needed for everyday diet and lifestyle guidance. Medical treatment and medical nutrition therapy for a diagnosed condition remain with your treating doctor, and we will ask you to consult one where your situation calls for it.
11.2 Why we need it
We ask you to disclose conditions, medicines, allergies and pregnancy so that the guidance is safe for you and the consultant knows when to refer you to a doctor. Withholding it makes the guidance less safe, and the Terms make disclosure your responsibility.
11.3 How we hold and limit it
Consultation records are held in one identified record for the consultancy, not in chat threads or the lead record, and are seen only by the consultant and the staff who administer bookings. We do not use health information for marketing, do not disclose it except with your consent or under clause 6.3, and never publish it, as the SPDI Rules require.
11.4 Learner observers
An advanced Learner may observe or take part in a consultation under the consultant's supervision. We tell you beforehand and ask for your consent, and you may decline without affecting your booking. An observer sees only what the supervised session requires, is bound by confidentiality under the Terms, and may keep no copy of your information.
11.5 Learners' disclosures, and a separate clinical system
We do not collect a Learner's health information as part of a Programme. If you disclose a condition to request an adjustment, deferral or support, we hold it only in the record of that request, use it only to decide it, and delete it when the request closes unless you ask us to keep it. If we introduce a dedicated clinical records system or application for the consultancy, clause 1.3 applies: it will carry its own privacy notice and consent process, and health information moves into it only under that notice.
Part 12: Retention
12.1 Principle
We keep Personal Data for as long as the purpose it was collected for continues, and then for as long as the law or the defence of a legal claim requires. The periods below are the ones we apply; when one ends we delete the data or anonymise it so it no longer identifies you.
12.2 Retention periods
- Enquiry and lead data, including page and campaign data and any free-text message: twenty-four months from our last contact with you, unless you enrol, when it joins your Learner record.
- WhatsApp conversation history: twenty-four months from the last message; exported and deleted earlier on request. Email and other correspondence: twenty-four months, or with the enrolment, consultation or dispute record it concerns.
- Learner academic records (enrolment, attendance, assessments and results) and the certificate register (name, learner code, certificate identifiers and status): permanently. A certificate may be relied on decades after issue, the Awarding Body's records depend on ours, and a record that could not be verified would harm the Learner more than keeping it could.
- Learner contact details and other enrolment data: the duration of study and eight years after your last transaction, to match the fee records. Payment, invoice and tax records: the period the Central Goods and Services Tax Act 2017 and the Income-tax Act 1961 require, which we treat as eight years from the end of the financial year concerned.
- The Consent Record: as long as the record it evidences is kept and in any case three years after our relationship ends, the period within which a claim may be brought.
- Recordings of live classes: as long as the recording is used to deliver the Programme; a recording withdrawn from teaching is deleted within twelve months.
- Consultation records: three years after your last consultation, the period within which a claim may be brought, or longer where a law requires.
- Analytics data: fourteen months, as set in Google Analytics. Server access logs: for the period our hosting provider keeps them under its own settings, and we do not export or keep them longer except to investigate a security incident or abuse. Pre-deployment backups: the three most recent, each replaced by the next.
- Employee, faculty and contractor records: the engagement and thereafter as long as employment, tax and social security law require; verification records as in clause 7.3; published profiles as in clause 10.5; unsuccessful applicants twelve months.
- Testimonials and graduate stories: until consent is withdrawn. Referral data: until any reward is settled, then with the tax records. Browser session storage: until you close the tab.
12.3 Retention required by law or for a claim
We keep data beyond these periods, and do not erase it on request, where a law requires it, where it is needed for a legal claim made or threatened, or where it is part of the academic record and certificate register in clause 12.2. In those cases we restrict the data to that purpose.
12.4 Deletion
When a period ends we delete the data from our systems and instruct the Data Processor holding it to do the same within its own deletion cycle. Data in a backup is overwritten when the backup is replaced. Anonymised statistics are not Personal Data and may be kept.
Part 13: Security and breaches
13.1 Reasonable security measures
We implement and maintain reasonable technical and organisational security measures appropriate to the nature of the data and the risk of its processing, as the IT Act and the DPDP Act require. They include serving the Site over encrypted connections; using established providers for forms, messaging, payment, content, hosting and learning delivery, each responsible under its terms for the security of its own service; keeping card and banking details out of our systems altogether; confining the records we publish to the fields in Part 7; and periodically reviewing what we hold, where and why. We review these measures at least yearly and whenever we change a system or Data Processor, and will strengthen them as our processing and the rules under the DPDP Act require. No method of transmission or storage is completely secure, and we do not warrant that Personal Data can never be accessed without authority.
13.2 Staff
Our staff, faculty, mentors, counsellors and contractors may use Personal Data only for their work and are bound by confidentiality. They are issued credentials for the systems holding Personal Data only as their role requires, and those credentials are withdrawn when they leave. Disclosing Personal Data without authority is an offence under section 72A of the IT Act, and we end the engagement of anyone who does it.
13.3 Data Processors
We engage Data Processors only under a contract or service terms requiring them to protect Personal Data, process it only on our instructions and notify us of a breach. We remain responsible to you for them as the Applicable Data Protection Law provides and cannot shift that responsibility to them.
13.4 Your part, and our official channels
Keep your Learning Platform password confidential, use it nowhere else, and tell us at once at contact@nnwa.in if you think your account has been used by someone else. We never ask for a password or one-time passcode by any channel. Our only official channels are nnwa.in and pages on that domain, email from an address ending in @nnwa.in, calls from +91 82409 00957, and our named social media accounts. Messages come only from the WhatsApp number in clause 9.3. Anything else claiming to be from us is not, and payment is made only through the payment aggregator's checkout reached from nnwa.in or a payment link sent from contact@nnwa.in.
13.5 Personal Data breaches
If we become aware of a breach of Personal Data, in our own systems or at a Data Processor, we tell each affected person without delay, in plain language: what happened, what data was affected, the likely consequences, what we have done to contain it, what you can do to protect yourself, and a contact for questions. We also report it to the Board in the form and time the rules under the DPDP Act prescribe once those provisions are in force, and to any other authority the law requires. During an incident we may suspend access, reset passwords or move a service to another provider, which the Terms provide is not a breach of them.
Part 14: Your rights
14.1 What you can ask
You may ask for a summary of the Personal Data we hold about you and the Data Fiduciaries and Data Processors we have shared it with; to correct, complete or update it; to erase it, subject to clause 14.5; to stop or limit a particular processing; to withdraw a consent (clause 4.5); to nominate a person (clause 14.6); and to have a grievance heard (clause 14.7). The SPDI Rules separately let you review and correct information you gave us; the same process applies.
14.2 How to make a request
Write to contact@nnwa.in with the subject "Data request", saying what you want and the identifier we can find you by: the email address or telephone number you gave us, your learner code or certificate identifier, or your employee identifier. You may also write to the Grievance Officer at the registered office in clause 17.1. Requests are free, and may be made in English or, on request, in a language listed in the Eighth Schedule to the Constitution.
14.3 Verifying your identity
Before disclosing or changing anything we confirm the request comes from you or someone you authorised: by replying to the email address on your record, by asking for the learner code or certificate identifier, or, where the request concerns Sensitive Personal Data or would send data to a new address, by asking for a copy of a government identity document, which we delete once the request closes. A request we cannot verify is declined, with reasons.
14.4 Timelines
We acknowledge a request within forty-eight hours and complete it within thirty days of verifying your identity. Where a request is complex or many arrive together we may take up to a further thirty days and tell you so within the first thirty. Corrections to a verification record follow the ten working days in clause 7.4.
14.5 Limits
We do not erase the academic record and certificate register in clause 12.2, because a certificate must remain verifiable and its basis provable; data a law requires us to keep; data needed for a claim under clause 12.3; or the Consent Record, which is the evidence of what you agreed. Erasing your contact details ends our ability to deliver a Programme (clause 4.6). We may decline a request that is manifestly unfounded, repetitive or unverifiable, and need not act on one that would disclose another person's data. Where we decline, we say so in writing with the reason.
14.6 Nomination
You may nominate a person to exercise these rights if you die or become unable to, by writing to contact@nnwa.in with their name and contact details; we confirm the nomination to you. On proof of your death or incapacity and of the nominee's identity or, where there is no nominee, of the requester's identity and status as your legal heir, we act on a request as we would for you. Certificates remain verifiable after a Learner's death.
14.7 Grievances, and the Board
If you are unhappy with how we handled your Personal Data or a request, write to the Grievance Officer at contact@nnwa.in with the subject "Grievance", or by post to the registered office. We acknowledge a grievance within forty-eight hours and resolve it within thirty days of receipt, within the one month the SPDI Rules allow; a complaint about content another user posted in a community space we host is acknowledged within twenty-four hours and resolved within fifteen days. If you are not satisfied, you may complain to the Data Protection Board of India once the provisions of the DPDP Act under which it hears complaints against a Data Fiduciary are in force; the Act requires you to exhaust our grievance process first. Nothing in this Policy limits any right you have under the Consumer Protection Act 2019 or any other law.
Part 15: Third-party sites, social media and use from outside India
15.1 Links
The Site links to sites we do not control, including those of the Awarding Body, finance partners, the payment aggregator and social media platforms. Each has its own terms and privacy policy; we do not control or endorse what it does with your data, and a link is not a recommendation. Read a linked site's policy before giving it any data.
15.2 Social media
We maintain accounts on Instagram, Facebook, YouTube and LinkedIn. Anything you post, comment or send there is processed by the platform under its own policy, and we read and may respond to public comments and direct messages. We embed no social media plug-in in the Site's code; advertising tags, if any, are described in clause 8.4. Do not send enrolment, payment or health information through social media.
15.3 Use from outside India
This Policy is written to Indian law. If you use the Site or enrol from outside India, your Personal Data is processed in India and in the locations in clause 6.6, and by using the Site or enrolling you agree to that. Your rights are those in Part 14, wherever you are.
Part 16: Changes, governing law and acceptance
16.1 Changes to this Policy and changes in law
We may change this Policy. A change that adds a purpose or category of data, adds a Data Processor holding your data in a new country, or reduces a right or retention safeguard is material: we give at least fifteen days' notice by email to every Enquirer, Learner and Client with a current record and by a notice on the Site, and where the Applicable Data Protection Law requires fresh consent for a new purpose we ask for it rather than assume it. Other changes take effect when posted with a new "Last updated" date. As the DPDP Act and its rules commence, or any other applicable law changes, we amend this Policy and our practices to comply, with the same notice. Earlier versions are available on request, and the Consent Record shows which version you accepted. If any part of this Policy is held invalid, the rest continues to apply.
16.2 Relationship with the Terms and the Refund Policy
This Policy, the Terms and the Refund Policy are separate documents that refer to one another by name. On Personal Data this Policy prevails; on fees and refunds the Refund Policy prevails; on everything else the Terms prevail.
16.3 Governing law and jurisdiction
This Policy is governed by the laws of India. Subject to the Consumer Protection Act 2019 and to the jurisdiction of the Board and any other statutory authority, the courts at Kolkata, West Bengal have exclusive jurisdiction over any dispute arising out of or in connection with this Policy, without prejudice to your right to approach a consumer commission having jurisdiction where you live or work.
16.4 Acceptance
Using the Site, submitting an enquiry, enrolling, booking a consultation or otherwise giving us Personal Data constitutes acceptance of this Policy as the notice of how we process it. Acceptance is not, by itself, consent to Marketing Communications or to any processing that Part 4 says needs a separate consent; those consents are given only as Part 4 describes.
Part 17: Grievance Officer and contact
17.1 The Grievance Officer and how to reach us
Our Grievance Officer, appointed under the IT Act framework, the Consumer Protection (E-Commerce) Rules 2020 and the DPDP Act, and the person able to answer questions about our processing of Personal Data, is Jyoti Padia.
- Email: contact@nnwa.in.
- Post: Grievance Officer, National Nutrition and Wellness Academy, 64/4A Graham Road, Third Floor, Regent Park, Kolkata 700 040, West Bengal, India.
- Telephone (calls only): +91 82409 00957.
- WhatsApp (messages only): +91 99039 36057.
The two numbers are separate channels: the first does not receive messages and the second does not take calls. Our registered office is at the address above, and our website is https://nnwa.in.
17.2 The role continues
A grievance or request addressed to the Grievance Officer is valid whoever holds the role. If the Grievance Officer, the registered office or a contact detail changes, we update this page; the details on this page when you write are the ones to use, and the change does not require this Policy to be re-issued.
17.3 Language
This Policy is written in English. We may publish a translation, and we will provide this notice in a language listed in the Eighth Schedule to the Constitution on request, as the DPDP Act contemplates. A translation is provided to help you understand the same commitments; if a translation and the English text differ, the English text prevails.
Still deciding which course fits?
A counsellor will look at your background and tell you honestly which programme fits, including telling you when a shorter, cheaper course is the better answer.