Kharghar, Navi Mumbai · Shilp Chowk, Sector 201:1 therapy · Occupational · Speech · Special Education · Behavioural Management & Intervention

Privacy Policy

Effective date: 30 September 2026   |   Last reviewed: 30 September 2026   |   Version 1.0

At Raah Child Development Center, we want parents and caregivers to know what happens to information they share with us. This policy explains how we handle personal information collected through raahcdc.in, our enquiry form, email, phone and links to third-party services.

A simple request: Please do not put detailed medical records, reports, therapy notes, identity documents or other highly sensitive information into the website enquiry form. The form is meant to start a conversation. We can guide you to an appropriate channel if more information is needed.

1. Who is responsible for your information?

For this website, the relevant organisation is Raah Child Development Center. Where Raah determines why and how personal information is processed, it acts as the responsible data fiduciary/controller for that processing.

Privacy contact: cdc.raah@gmail.com
Phone: +91 74004 50035
Current centre: Shop No. 12, Meera Arcade, Shilp Chowk, Sector 20, Kharghar - 410210

2. What we collect

  • Enquiry information: parent or caregiver name, phone number, selected service and the message you choose to send.
  • Information you voluntarily include: you may mention a child's needs in your message. Please share only what is necessary.
  • Communication information: information you provide when you contact us by phone, email or WhatsApp.
  • Technical information: basic information generated when a website is requested, such as IP address, browser/device information, request time and security logs, as processed by our hosting, CDN or security providers.
  • Third-party interaction: Google Maps, WhatsApp and Instagram may process information when you use those services. Their own privacy terms apply to those interactions.

3. Why we use it

  • To respond to your enquiry or request for a callback.
  • To arrange or discuss consultations, assessments and services.
  • To communicate with you about an existing or proposed service relationship.
  • To maintain appropriate business or clinical records when you become a client, subject to applicable professional and legal requirements.
  • To keep the website, communications and systems secure and to investigate misuse or security incidents.
  • To meet legal, regulatory or lawful authority requirements.
  • To handle complaints, requests, disputes and legal claims where necessary.

We do not sell personal information. We do not use information collected through this enquiry form to build advertising profiles about children.

4. Children and parent or guardian information

Raah provides services to children, so child information needs additional care. The website enquiry form is intended for a parent, caregiver or other authorised adult. Where information about a child is provided, Raah will use it only for the enquiry or service-related purpose for which it is needed and will apply any parental or guardian safeguards required by applicable law.

We do not ask children to submit personal information directly through the website, and we do not use children's information for targeted advertising or behavioural profiling.

The notified Digital Personal Data Protection Rules, 2025 contain specific safeguards for children's data, including verified parental consent requirements and defined healthcare-related exemptions in certain circumstances. Those provisions come into force in phases. This policy is written to be ready for the notified framework as it becomes applicable.

5. Consent and your choices

Where consent is the basis for processing, we aim to ask for it in clear language and only for the information necessary for the stated purpose. Where applicable law gives you the right to withdraw consent, you can contact us using the privacy contact above. Withdrawal does not undo processing that was lawful before withdrawal.

The notified DPDP framework also requires a clear notice at the point of consent and a practical way to exercise data rights. We have therefore kept the enquiry notice short, visible and separate from this longer policy.

6. Sharing and service providers

We may share information with people who need it to handle your request, such as authorised Raah staff and service providers that support website hosting, security, communications or other operations. If you choose WhatsApp, your message is sent to WhatsApp and then handled under WhatsApp's own terms and privacy practices. Google Maps and Instagram also operate under their own policies when you use them.

We may also disclose information where required by law, legal process, court order, or a lawful request from a competent authority.

7. International processing

Some third-party technology providers may process information outside India. Where this occurs, we expect the relevant processing to be subject to applicable law and appropriate contractual and security safeguards. The notified DPDP Rules address transfers of personal data outside India subject to requirements that may be specified by the Central Government.

8. How we protect information

We use practical technical and organisational measures appropriate to the information we handle. These include secure connections, controlled access, reasonable staff confidentiality practices, security monitoring and provider safeguards. We do not claim that any internet service can be completely risk-free.

The notified DPDP Rules describe safeguards including access control, encryption or similar protections, monitoring, logs and measures for continuity and breach response. We use those principles as part of our security direction and will update controls as our systems grow.

9. How long we keep information

We keep information only for as long as it is reasonably needed for the purpose for which it was collected, for an ongoing service relationship, to meet professional or legal record-keeping obligations, to resolve disputes, or to protect our systems and rights. When information is no longer needed, we delete or securely dispose of it, or anonymise it where appropriate, subject to applicable law.

10. Your rights and requests

Depending on the law that applies to your information, you may have rights to request access to personal information, correction or updating, erasure where permitted, withdrawal of consent, and information about how your data is being handled.

Send a request to cdc.raah@gmail.com with the subject line Privacy Request. We may ask for reasonable information to confirm your identity or authority before disclosing or changing personal information, particularly where a request concerns a child's information.

The notified DPDP Rules require a clear route for rights requests and a grievance redressal system. Where those rules apply, our process will operate within the applicable statutory timeline.

11. Photos, videos and testimonials

We do not publish identifiable photographs or videos of children on our website without appropriate parent or lawful guardian permission. Where we publish an identifiable testimonial, case story or family statement, we will use it only with appropriate permission and will not knowingly alter its meaning.

12. Cookies and analytics

The current site does not intentionally use advertising cookies or behavioural advertising trackers. Essential technical mechanisms may be used by the website infrastructure and security services. Third-party services such as Google Maps may process technical information when their content is loaded or used.

If we add non-essential analytics or marketing technologies later, we will update this policy and implement any consent or disclosure controls required by applicable law before using them for those purposes.

13. Security incidents

If Raah becomes aware of a personal-data breach that requires notification, we will assess it and take the steps required by applicable law, including notifying affected individuals and authorities where required. The notified DPDP Rules prescribe breach-notification obligations and specific information to be provided to affected people and the Data Protection Board.

14. International visitors and GDPR

Raah is primarily a local service in India. The General Data Protection Regulation can apply to organisations outside the EU in certain circumstances, including where they offer services to people in the EU or monitor their behaviour. If Raah deliberately begins targeting services or monitoring people in the EU/EEA, we will review whether additional GDPR-specific obligations apply.

15. Changes to this policy

We may update this policy when our website, services, technology or legal obligations change. The latest version will be posted on this page with a revised effective date.

Back to Raah