Privacy Notice
How MarshallRidge Consulting Private Limited collects, uses and protects your personal data under the Digital Personal Data Protection Act, 2023.
Effective 24 June 2026 · Last updated 5 July 2026
1. Who we are
MarshallRidge Consulting Private Limited (CIN U62099MR2026PTC476835), with registered office at Unit No. 52, 2nd Floor, C-39A, Gami Industrial Park, MIDC, Thane, Navi Mumbai, Maharashtra 400705, India, operates ElevateU at https://marshallridgeconsulting.in. We are the Data Fiduciary responsible for your personal data.
2. Personal data we collect
- Account data: name, email address, phone number (if provided), password (stored only in hashed form), and date of birth / age confirmation.
- Education & profile data: college/university, course, year of study, and similar details you provide.
- Career & skills data: skills, career interests, goals, and your responses to our assessments.
- Assessment / aptitude results: scores and the indicative "Student DNA" report generated from your responses. We treat these as personal data requiring care.
- Content you submit: e.g. resume text, notes, goals, and AI counselor prompts.
- Usage & device data: log data, app/device and analytics information used to operate, secure and improve the Service.
- Payment data: processed by our payment partner; we receive transaction status and invoice details but do not store full card numbers.
We do NOT collect health data, biometric data, or financial-account data.
3. Lawful basis and purposes (purpose limitation)
We process your personal data for lawful purposes, on the basis of your consent and, where applicable, for legitimate uses permitted by the DPDP Act, only for the purposes for which it was provided:
- to create and secure your account and provide the Service;
- to generate assessments, reports, recommendations and personalised guidance;
- to process payments and provide invoices;
- to communicate service, security and support messages;
- to maintain safety, prevent misuse/fraud, and comply with law; and
- to improve the Service using aggregated / de-identified data that does not identify you.
We practise data minimisation — we collect only what is necessary for these purposes.
4. Cookies, analytics and marketing pixels
We use strictly necessary cookies/local storage to keep you signed in and to operate the Service, and limited analytics to understand usage and improve reliability. You can control cookies through your browser. See our Cookie Policy for details.
With your consent (via our cookie banner), we also load the Meta (Facebook) Pixel provided by Meta Platforms, Inc. (USA) to measure and improve our marketing. This involves sharing limited usage events (such as page views and your device/identifier data) with Meta, who acts as an independent controller under its own data policy, including transfer outside India. The Pixel does not load unless you accept, and you can decline or withdraw consent at any time by clearing your site data.
5. AI processing and cross-border transfer
Some features (e.g. the AI counselor and AI insights) use the Google Gemini API. To generate a response, your prompt and relevant context may be transmitted to that provider, which may process it outside India. Cross-border transfers are made in accordance with Section 16 of the DPDP Act (which permits transfer except to countries restricted by the Central Government). Our key infrastructure providers are Cloudflare (application delivery/compute) and Amazon Web Services (AWS), Mumbai region (ap-south-1), India (database). Payments are processed by Razorpay and transactional email by our email provider.
6. Security safeguards
We implement reasonable technical and organisational security measures, including encryption in transit and at rest, hashed passwords, access controls, optional multi-factor authentication, rate-limiting and audit logging, consistent with the DPDP Act and the reasonable-security-practices standard under the Information Technology Act, 2000. No system is perfectly secure, and we cannot guarantee absolute security.
7. Your rights as a Data Principal
Subject to the DPDP Act, you have the right to:
- access a summary of your personal data and how it is processed;
- correct, complete or update inaccurate or incomplete data;
- erase your personal data where no longer necessary or where you withdraw consent (subject to legal retention);
- nominate another individual to exercise your rights in the event of death or incapacity;
- withdraw consent at any time (which does not affect prior lawful processing); and
- grievance redressal and the right to register a complaint with the Data Protection Board of India.
You can exercise these rights in-app (account settings, including data export and account deletion) or by writing to contact@marshallridgeconsulting.in. We will respond within 30 days.
8. Grievance Officer and redressal
If you have a concern about how we handle your personal data, contact our Grievance Officer / Data Protection Officer:
- Office: Grievance Officer, MarshallRidge Consulting Private Limited
- Email: contact@marshallridgeconsulting.in
- Address: Unit No. 52, 2nd Floor, C-39A, Gami Industrial Park, MIDC, Thane, Navi Mumbai, Maharashtra 400705, India
We aim to acknowledge and resolve grievances within 30 days. If you are not satisfied, you may approach the Data Protection Board of India.
9. Retention and auto-deletion
We keep personal data only as long as necessary for the purpose collected, or as required by law:
- Accounts inactive for 36 months (no login) may be deleted, with prior notice where required.
- Security/audit logs: up to 24 months.
- Analytics event logs: up to 18 months.
- Grievance / data-request records: up to 36 months (as proof of redressal).
On erasure, data is deleted or irreversibly de-identified, except backups and records we must retain by law.
10. Age (18+) — no children's data
ElevateU is intended only for individuals aged 18 and above. We require an 18+ self-attestation at sign-up and do not knowingly process the personal data of children. If we learn that a child has provided data, we will delete it.
11. Personal data breach notification
In the event of a personal data breach, we will take prompt remedial action and, as required by law, notify the Data Protection Board of India and affected Data Principals without undue delay and within the timelines prescribed under the DPDP Act and its rules. For reportable cyber security incidents, we will also notify CERT-In within six (6) hours of becoming aware, in line with the CERT-In Directions dated 28 April 2022.
12. Liability and your statutory rights
Our liability in connection with the Service is described in our Terms of Use. Nothing in this Notice or those Terms limits or excludes any liability or penalty that cannot be excluded under the DPDP Act, or any non-waivable right or remedy you have as a consumer under the Consumer Protection Act, 2019.
13. Changes to this Notice
We may update this Notice from time to time. Material changes will be notified in-app or by email and, where required, fresh consent will be sought. The "Last updated" date above shows the current version.