Your information. Our responsibility.
Indian Institute of Design (“IID”, “we”, “us”, “our”) respects the privacy of individuals who visit, access or use our website and related digital services.
Last updated: 4 October 2026 · Version 1.1Scope of this Privacy Policy
This Privacy Policy applies to personal information collected through IID digital services. It may not apply to third-party websites, applications, platforms or services that are independently operated by other organisations.
Who is Responsible for Your Data?
For purposes of this Privacy Policy, the organisation responsible for the relevant personal data processing is Indian Institute of Design (IID), Rajkot, Gujarat, India. For specific services, IID may use authorised service providers to process information on IID's behalf.
What is Personal Data?
“Personal Data” means information that relates to an identifiable individual or can reasonably be associated with or used to identify an individual. IID will seek to collect only information that is reasonably necessary for the relevant purpose.
Information You Provide Directly
You may voluntarily provide personal information when you interact with IID through authorised channels. You should provide accurate and complete information.
Information Collected Automatically
When you visit the IID website, certain technical information may be collected automatically, depending on the website configuration and tools being used. This information may be used for website functionality, security, analytics, performance monitoring and improvement.
Information Collected Through Cookies
IID may use cookies and similar technologies. Cookies are small files or identifiers that may be stored on or associated with your device when you visit a website. IID will configure consent mechanisms for cookies where required by applicable law.
Cookie Control
Depending on the website's cookie-management system, users may be able to manage cookies as listed below. Disabling certain cookies may affect some website functionality.
Why Do We Collect Personal Data?
IID may process personal information for legitimate and specified purposes.
Legal Basis / Permitted Processing
IID will process personal data only for lawful purposes and through an applicable legal basis or permitted use under the laws applicable to the relevant processing activity. Where consent is required, IID will seek consent in an appropriate manner. The Digital Personal Data Protection Act, 2023 provides for processing based on consent or specified legitimate uses, and requires notice regarding the personal data and purpose of processing.
Consent
Where processing is based on consent, IID will seek consent in a manner that is clear, specific, informed, voluntary, unambiguous and appropriate to the relevant purpose. Where applicable, the website will clearly identify mandatory and optional fields. Providing consent for one purpose does not automatically mean consent for unrelated purposes.
Withdrawal of Consent
Where processing is based on consent, you may withdraw your consent, subject to applicable law and legitimate processing requirements. Withdrawal of consent will not affect processing lawfully carried out before withdrawal. Depending on the nature of the request, withdrawal may affect IID's ability to provide certain services or respond to certain enquiries. The DPDP Rules contemplate that users should have accessible means to withdraw consent and exercise applicable rights.
Contact Form Data
When you submit an IID contact form, the information may be used to respond to your enquiry, contact you, provide requested course or admission information, schedule counselling, follow up and maintain enquiry records. The form includes an appropriate privacy consent notice.
Marketing Communications
Where applicable, IID may request separate consent for promotional or marketing communication. Marketing consent should be separate from consent required to process an enquiry or provide a requested service where appropriate. You may opt out of promotional communication.
Phone & WhatsApp Communication
If you provide a phone or WhatsApp number, IID or its authorised representatives may use it for purposes related to your enquiry, admission process, programme information or other consented communications. Where required, separate consent may be obtained for promotional communication.
Email Communication
If you provide your email address, IID may use it for the purposes below. Where required, promotional emails will include an appropriate unsubscribe mechanism.
Admission Data
Admission-related interactions may require additional information. IID will use such information for admission and related administrative purposes.
Student & Parent/Guardian Information
Where students are minors or where a parent/guardian provides information on behalf of a student, IID may process relevant information for educational, administrative and admission-related purposes. Where applicable, IID will follow requirements relating to consent and processing of children's personal data under applicable law.
Children's Data
IID recognises that children's personal data requires additional care. Where the website or admission process involves a child, IID may require appropriate parental or lawful guardian involvement or verifiable consent where required by applicable law. IID will not knowingly use children's personal data for unrelated purposes.
Sensitive Information
IID may receive information that users voluntarily submit through admission or other forms. Users should not submit sensitive or confidential information unless IID specifically requests it for a legitimate institutional purpose. Where sensitive information is required, IID will apply appropriate safeguards and process it only for the relevant purpose.
Documents Uploaded by Users
Where online forms permit document uploads, documents will be used for the stated institutional purpose and may be retained according to applicable requirements. Users should not upload unnecessary documents.
Payment Information
Where IID or an authorised payment service facilitates online payments, payment information may be processed by the applicable payment service provider. IID generally does not require users to provide complete card or banking credentials directly through ordinary website contact forms.
Third-Party Service Providers
IID may use authorised third-party service providers. Such providers may process personal information only to the extent necessary for the services they provide and subject to applicable contractual or legal requirements.
Third-Party Platforms
The IID website may contain integrations or links to independently operated platforms. These platforms may have their own privacy policies and terms. IID does not control their privacy practices. Users should review the relevant third party's privacy policy before providing information directly to that platform.
Social Media
IID may maintain official pages or profiles on social media platforms. If you interact with IID through such platforms, your interaction may also be governed by the privacy policy and terms of the relevant platform. IID may receive information that you voluntarily provide through such interactions.
Analytics
IID may use analytics tools to understand website use and performance. Analytics information may be aggregated or otherwise used for website improvement and reporting. Where applicable, IID will use appropriate consent mechanisms for non-essential analytics technologies.
Advertising & Marketing Technologies
Where IID uses digital advertising or campaign measurement tools, such technologies may collect information about interactions with advertisements or website pages. Such tools may be provided by third parties. IID will use such technologies subject to applicable law and relevant consent requirements.
How We Share Personal Data
IID may disclose personal data only where reasonably necessary for a lawful and specified purpose. IID does not intend to sell personal data as a commercial product.
Data Processors
Third-party vendors may act as service providers or data processors for IID. Such providers may process data on IID's instructions for specific purposes.
International Data Transfers
Some third-party technology providers may process or store data outside India. Where personal data is transferred, accessed or processed outside India, IID will take such steps as may be required under applicable law and contractual arrangements.
Data Security
IID will take reasonable security measures appropriate to the nature of the personal data and processing activity. However, no internet transmission or electronic storage system can be guaranteed to be completely secure.
User Responsibility
Users should take reasonable care when sharing information with IID.
Data Retention
IID will retain personal data only for as long as reasonably necessary for the purposes below. Retention periods may differ depending on the nature of the information. When personal data is no longer required, IID may delete, anonymise or otherwise securely dispose of it, subject to applicable legal or institutional retention requirements.
Data Deletion
You may request deletion of personal information where applicable and subject to legal or other legitimate retention requirements. IID may need to retain certain information where required.
Access to Personal Data
Subject to applicable law, individuals may have rights regarding their personal data, including rights to obtain information about processing and other applicable rights. Requests may be submitted using the contact details provided in this Privacy Policy.
Correction / Update of Information
If information submitted to IID is inaccurate, incomplete or outdated, you may request correction or updating where applicable. IID may verify the identity of the requester before making changes.
Grievance / Complaint
If you have concerns about the processing of your personal data, you may contact IID using the designated contact details. IID will review the concern and respond in accordance with applicable requirements.
Data Protection / Privacy Contact
For privacy-related questions, requests or complaints, contact IID's privacy / grievance contact using the official details on this page.
Identity Verification
To protect personal information, IID may need to verify the identity of a person making a privacy request. IID may request reasonable additional information where necessary to prevent unauthorised disclosure.
Fraud & Security
IID may process certain information to protect users and institutional systems.
Legal Disclosures
IID may disclose information where reasonably necessary or legally required.
Business Transfer
If IID's operations, assets or relevant organisational structure are transferred, merged, reorganised or otherwise changed, personal information may be transferred as part of such transaction, subject to applicable law. Any recipient would be expected to handle personal information in accordance with applicable legal requirements.
Links to Other Websites
IID's website may contain links to third-party websites. IID is not responsible for the privacy practices, content or security of those websites. Before submitting personal information on another website, users should review that website's Privacy Policy.
Website Security
IID may use reasonable technical and organisational measures to protect the website. Despite reasonable safeguards, IID cannot guarantee that the website will always be free from security risks.
Data Breach / Security Incident
If IID becomes aware of a personal-data breach requiring notification under applicable law, IID will take appropriate steps in accordance with applicable legal and regulatory requirements.
Accuracy of Information
IID relies on information submitted by users. Users are responsible for ensuring that information supplied to IID is accurate, complete and current. IID may request clarification or supporting documentation where necessary.
Voluntary Information
Unless specifically required for a particular service, users should avoid providing unnecessary personal information through public forms, comments or communications.
Publicly Available Information
Information voluntarily posted by a user in a publicly accessible area may become visible to other users or third parties. Users should carefully consider whether to publish personal information publicly.
Photographs & Audio-Visual Content
IID may collect or use photographs, videos or audio recordings in connection with institutional activities. Where consent or another lawful basis is required, IID will take appropriate steps.
Testimonials
Where IID publishes student, parent, alumni or other testimonials, the information will be used in accordance with the applicable permission, consent or lawful basis. Users should not assume that testimonials constitute a guarantee of a particular academic or career outcome.
Email Unsubscribe
Where promotional email communication is sent, users may use the unsubscribe mechanism provided in the communication, where applicable. Unsubscribing from promotional communication does not necessarily stop essential transactional or admission-related communications.
Marketing Opt-Out
You may request that IID stop sending non-essential promotional communications. IID may require reasonable time to process such requests.
Changes to Personal Information
If your name, phone number, email address, address, communication preference or other relevant information changes, you may contact IID to request an update where applicable.
Third-Party Data
If you provide IID with personal information relating to another person, such as a parent, guardian or student, you should do so only where you are authorised or legally permitted to provide that information.
No Sale of Personal Data
IID does not intend to sell personal data of website users as a commercial product. Personal data may nevertheless be shared with authorised service providers where necessary to operate IID's website, admissions, communications, technology or other legitimate services.
Data Minimisation
IID aims to collect personal information that is reasonably necessary for the stated purpose. Users are encouraged not to provide information that is unrelated to the enquiry or service requested.
Purpose Limitation
Personal data collected for one purpose will not ordinarily be used for an unrelated purpose unless you provide appropriate consent, the processing is otherwise permitted by applicable law, or the processing is necessary for another lawful institutional purpose.
Consent Records
Where consent is required, IID may maintain records relating to consent for compliance and operational purposes.
Privacy by Design
IID aims to incorporate reasonable privacy and security considerations into relevant website forms, digital processes and technology implementations.
Changes to this Privacy Policy
IID may update this Privacy Policy from time to time. The updated policy will be published on this webpage with a revised Last Updated date. Where required, IID may provide additional notice regarding material changes.
Governing Law
This Privacy Policy shall be governed by the applicable laws of India. Subject to applicable law, matters relating to this Privacy Policy shall be subject to the jurisdiction of the appropriate courts having jurisdiction over Rajkot, Gujarat, India.
Contact Information
For questions regarding this Privacy Policy, contact Indian Institute of Design using the official details below.
Quick Privacy Summary
The table below summarises IID's approach. The full policy above is the governing explanation.
Only information reasonably required for relevant purposes
Used to respond to enquiries
Used for admission and related administration
Separate consent where applicable
Used for functionality, analytics and other permitted purposes
Authorised service providers may process information
Payment gateways may process payment information
Reasonable technical and organisational safeguards
Kept only as long as reasonably necessary or legally required
Requests may be made where applicable
Available subject to legal/legitimate retention requirements
Available where processing is based on consent
May be submitted to IID's designated privacy contact
IID does not intend to sell personal data
This page may be updated periodically
Website Consent Notice
By submitting an IID website form, you acknowledge that you have read and understood IID's Privacy Policy and consent to the processing of the information provided by you for the stated purpose of responding to your enquiry and providing relevant IID information, subject to applicable law.
Contact Form ConsentImportant Notice
This Privacy Policy is intended to provide transparency regarding IID's website and digital data practices. The actual data collected, processing purposes, third-party integrations, retention periods and communication channels should be reviewed against IID's live website, admission system, CRM, payment gateway, analytics tools and other technology systems.
Clear & Itemised Privacy Notice
IID will endeavour to ensure that privacy notices provided at the point of data collection are clear, understandable and sufficiently specific. The notice may be presented separately from other website terms where appropriate.
Mandatory vs Optional Information
Where reasonably practicable, IID will distinguish between mandatory and optional information. Failure to provide mandatory information may prevent IID from processing the relevant request.
No Pre-Ticked Consent
Where consent is required, IID will seek an affirmative action from the individual. Consent checkboxes should not be pre-selected by default for optional processing or marketing purposes. Different purposes may require separate consent options.
Separate Marketing Consent
Consent to receive promotional communication should, where appropriate, be separate from consent required to process an enquiry or admission request. The marketing checkbox should not be treated as mandatory merely because the user wishes to submit an enquiry.
Consent Withdrawal Mechanism
Where processing is based on consent, IID will provide a reasonable mechanism through which consent may be withdrawn. The withdrawal mechanism should be reasonably accessible and should not require unnecessarily complicated steps. Withdrawal may not affect processing that was lawfully completed before withdrawal.
Data Principal Rights
Subject to applicable law, individuals may have rights relating to their personal data. The availability and scope of each right will depend on the applicable legal provisions and circumstances.
Nomination
Where applicable under the prevailing data-protection framework, IID will facilitate the exercise of a nomination-related right in accordance with applicable law and prescribed procedures.
Request Handling
Privacy requests may be submitted through IID's designated privacy contact. IID may request reasonable information necessary to authenticate the requester.
Response to Privacy Requests
IID will endeavour to respond to valid privacy requests within the time period prescribed by applicable law. Where a request cannot be fulfilled, IID may provide an explanation to the extent permitted or required by law.
Grievance Escalation
If an individual is dissatisfied with IID's response to a privacy-related request, the individual may use the applicable escalation mechanism available under law. Where applicable, information regarding the relevant statutory authority or Data Protection Board mechanism may be provided.
Data Breach Response
IID will maintain reasonable procedures for identifying, assessing, containing and responding to personal-data breaches.
Security Logs & Audit Trails
IID or its authorised service providers may maintain technical logs for security, troubleshooting, compliance and audit purposes, subject to applicable retention requirements.
Backups
IID or its authorised technology providers may maintain secure backups of relevant information. Backups may remain temporarily available even after information is deleted from an active system where necessary for disaster recovery, security or legal purposes. Such backup data will be handled in accordance with applicable retention and security practices.
Access Control
Access to personal data within IID may be restricted according to role and business necessity. Not every employee, consultant or service provider will necessarily have access to all personal information.
Employee & Vendor Confidentiality
IID may require relevant employees, consultants and service providers to maintain confidentiality regarding personal information accessed in connection with their work.
Data Accuracy & Verification
IID may rely on information provided by individuals. Users remain responsible for the accuracy of information they provide. Where necessary, IID may verify information through lawful methods.
Automated Decision-Making
IID does not intend to make significant decisions about individuals solely through automated processing unless such processing is permitted under applicable law and appropriate safeguards are implemented. Where applicable, IID may use automated tools for operational purposes such as spam detection, analytics, security monitoring or form processing.
AI & Technology Tools
IID may use technology or artificial-intelligence-enabled tools for legitimate operational purposes. Where personal data is processed through such tools, IID will seek to apply appropriate privacy, security and contractual safeguards. IID will not intentionally provide unnecessary personal information to AI tools.
Chatbots & Online Assistants
If IID introduces a chatbot, virtual assistant or automated enquiry system, information entered into that system may be processed for the purposes below. Users should avoid submitting unnecessary confidential information through a chatbot.
Call Recording
If IID records telephone calls for quality, training, security, compliance or operational purposes, IID may provide an appropriate notice at the beginning of the call or through another suitable mechanism. Where applicable, call recordings may be retained for a limited period based on the purpose for which they were collected.
CCTV & Campus Security
If CCTV or other security systems are used at IID premises, visual information may be collected for campus security and related purposes. CCTV footage may be retained for an appropriate period based on operational, security and legal requirements.
Visitor Information
Visitors to IID premises may be required to provide information for campus security and visitor management.
Event Registration Data
For events, seminars, workshops and other activities, IID may collect participant information. Event-specific notices may be provided where required.
Feedback & Surveys
IID may conduct surveys and collect feedback to improve institutional services. Participation may be voluntary unless otherwise specified.
Referral Information
If a person provides IID with another individual's contact details for a referral or enquiry, the person providing the information should ensure that they are authorised to do so or have an appropriate basis for providing it. IID may contact the referred person for the stated purpose.
Corporate / Institutional Enquiries
Where schools, colleges, organisations or businesses contact IID, IID may process the professional contact information of representatives for legitimate institutional purposes.
Career / Employment Enquiries
Where IID collects information from applicants, interns, consultants or other professionals, such information may be used for recruitment and related administration. A separate recruitment privacy notice may be used where appropriate.
Alumni Information
IID may process alumni information for legitimate institutional purposes. Where promotional communication is involved, applicable consent or communication preferences will be respected.
Refunds, Transactions & Financial Records
Where applicable, IID may retain transaction-related information. Financial records may be retained for periods required by applicable law.
Tax & Statutory Records
Where legally required, IID may retain personal or transaction-related information for tax, accounting, statutory, regulatory or audit purposes. Such retention may continue even after a user requests deletion where the information must legally be retained.
Data Retention Schedule
IID may maintain internal retention schedules identifying appropriate retention periods for different categories of data. Retention may vary according to the purpose and applicable law.
Data Destruction
When personal data is no longer required and there is no legal or legitimate reason to retain it, IID may delete, anonymise, securely destroy or permanently remove access to it. The method may depend on whether the information is stored electronically or physically.
Anonymised & Aggregated Data
IID may use anonymised or aggregated information for institutional purposes. Where information has been properly anonymised, it may no longer constitute personal data under applicable law.
Research & Academic Purposes
Where applicable, IID may use information for legitimate academic, educational or institutional research purposes, subject to applicable privacy requirements. Where practical, information may be aggregated or anonymised.
Website Forms & Spam Protection
IID may use CAPTCHA, anti-spam systems or similar security technologies. Such systems may process limited technical information as necessary for security.
Geolocation
IID may use approximate location information derived from technical information or location-enabled services where necessary and permitted. IID will not request precise device location unless the relevant feature requires it and appropriate permission is obtained.
Device Permissions
If a future IID application or digital service requests access to device features, the relevant permission will be requested through the applicable device or platform mechanism where required. Users may manage permissions through their device settings, subject to the functionality of the service.
Browser Do-Not-Track Signals
Some browsers may provide “Do Not Track” or similar signals. Because standards and technical implementations may vary, IID may not respond to every browser-level signal unless required by applicable law or supported by the relevant technology.
Domain & Hosting Information
Technical information associated with website access may be recorded by hosting, security or infrastructure providers. This information may be used for security, reliability and website administration.
Cross-Device / Cross-Service Information
Where IID or its authorised service providers use analytics or marketing technologies that associate interactions across devices or services, such processing will be subject to applicable law and relevant consent requirements.
Third-Party Embedded Content
Some IID webpages may display content from third parties. Such third parties may process technical or usage information when their content is loaded or used. Users should review the relevant third party's privacy practices.
Privacy Policy & Other Policies
This Privacy Policy should be read together with other applicable IID policies. If a specific policy contains more detailed rules for a particular service, that policy may apply to that service in addition to this Privacy Policy.
Conflict with Law
Nothing in this Privacy Policy is intended to restrict any mandatory right, protection or requirement available under applicable law. Where applicable law requires a different standard, the applicable legal requirement will prevail.
Policy Version Control
IID may maintain internal records of Privacy Policy versions. Material updates may be highlighted where appropriate.
Privacy Policy Acceptance
Where the website requires consent or acknowledgement, users may be asked to confirm that they have read and understood the applicable Privacy Policy. A Privacy Policy acknowledgement does not automatically constitute consent for every possible processing activity. Where separate consent is required, IID may provide a separate consent mechanism.
Official Privacy Contact
For all privacy-related matters, contact Indian Institute of Design. For privacy requests, users may use the subject line “Privacy Request – IID” or “Personal Data Request – IID”.
Recommended subject: Privacy Request – IID or Personal Data Request – IID
This Privacy Policy explains how IID may collect, use, store, disclose, protect and otherwise process personal information.
Indian Institute of Design — Design Education | Creativity | Innovation | Entrepreneurship
