Privacy Policy
How we collect, use, share, and protect your personal data — compliant with the Digital Personal Data Protection Act 2023 (DPDP) and the IT Act 2000.
1. Who we are
Nexthara Overseas LLP ("Nexthara", "we", "us") is a Limited Liability Partnership incorporated in India, operating from Kozhikode, Kerala. We act as an education advisory and loan facilitation service — we help students apply to universities abroad and connect them to our network of 15+ education-loan lenders. We are the Data Fiduciary under the DPDP Act 2023 for the personal data described in this policy.
Data Fiduciary contact
Nexthara Overseas LLP
Kozhikode, Kerala, India
Email: hello@nexthara.in · Phone: +91 73561 60671
2. What personal data we collect
We collect only what is necessary to deliver our service. Categories:
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, date of birth, gender, passport number, Aadhaar (only when needed for KYC) | Direct from you |
| Contact data | Email, phone / WhatsApp number, home address | Direct from you |
| Academic data | Class 10, 12 & degree transcripts, degree certificates, English test scores (IELTS/PTE/TOEFL/OET/Duolingo), Statement of Purpose, LORs | Direct from you |
| Financial data | Bank statements, FD certificates, ITRs, Form 16, salary slips, sponsor affidavits, TT/SWIFT payment proofs | Direct from you (originals belong to you or your sponsor) |
| Immigration data | Visa history, CAS/CoE letters, prior refusals | Direct from you / from the university |
| Communication data | WhatsApp / email conversations with counsellors; counselling call recordings (per your consent) | Generated by our operations |
| Website usage data | Pages visited, referrer, approximate IP-based city, device / browser type | Automatically via Google Analytics |
3. Why we collect it (purposes)
- Admissions facilitation — shortlisting universities, submitting applications, tracking offers, CAS/CoE issuance
- Loan facilitation — matching your profile to our 15+ lender network, submitting to lenders you approve, tracking sanctions and disbursement
- Visa preparation — organising documents, mock interviews, and submission support for UKVI, DHA, Campus France, and equivalents
- Communication — updates, reminders, and support via WhatsApp / email / phone
- Legal & compliance — meeting our obligations under Indian and destination-country law; keeping records for audit
- Service improvement — anonymised analytics to improve counsellor tooling and website UX
- Marketing — only if you explicitly consent to receive our newsletters, updates, or use of your success story as a testimonial
4. Legal basis for processing
Under DPDP Sec 4, we process your personal data on the following bases:
- Consent (Sec 6) — for marketing, testimonial use, call recording, and sharing with any third party you did not specifically engage
- Legitimate use — performance of a service you asked for (Sec 7) — for admissions, loan, and visa processing you initiated
- Legal obligation (Sec 7) — where a court, regulator, or law requires disclosure
5. Who we share your data with
We share only the minimum necessary data with specific categories of recipients. We do not sell your data or make it available for third-party advertising. Categories of recipient:
| Recipient | What is shared | Why |
|---|---|---|
| Universities you apply to | Academic, English, SoP, LORs, passport copy | Application evaluation, offer letter, CAS/CoE issuance |
| Our network of partner banks and non-banking financial companies (NBFCs) — Indian and international — that you specifically apply to | KYC, financial, academic, admit letter | Loan underwriting and sanction |
| Embassies, consulates, and visa-processing centres | Full visa application pack | Visa processing |
| Our university-application partner platforms | Applicant profile, academic, English | Access to their university partnerships |
| Opt-in service providers you engage (forex, insurance, accommodation) | Name, passport, destination, course start date | Booking the service you opted into |
| Payment processors | Payment metadata (we do not store card numbers) | Fee payments where applicable |
| Our IT infrastructure providers (hosting, email delivery, workspace tools) in India and other jurisdictions | Data hosting and delivery infrastructure | Running our systems securely |
| Legal, regulatory, or governmental authorities | Only what is legally compelled | Court orders, subpoenas, statutory disclosures, law enforcement requests |
| Professional advisers (auditors, lawyers, insurers) | Only what is required for the advice or defence | Legal defence, audit, insurance |
| Any successor entity in the event of a merger, acquisition, or restructuring of Nexthara Overseas LLP | Contractual and operational records | Business continuity |
The identities of our specific partner banks, NBFCs, universities, and application platforms are confidential business relationships and are disclosed to you on a need-to-know basis at the point you engage with any specific partner. This is standard commercial confidentiality and does not diminish your DPDP rights.
6. Cross-border data transfers
Because our service is inherently international, your data will be transferred outside India, including to:
- Universities in your destination country
- Embassies and consulates in India that route to their home governments
- Cross-border lender partners for loan facilitation, where you apply to such lenders
- Our IT infrastructure providers that operate in multiple jurisdictions
All transfers are made under DPDP Sec 16 — either to jurisdictions notified as permitted by the Central Government, or with your explicit consent captured in the Student Acknowledgment. By using our service, you acknowledge that data protection standards in destination countries may differ from Indian law, and you consent to such transfers as necessary to deliver the service you have requested.
7. How long we keep your data
We retain personal data only as long as necessary for the purposes described, or as required by law, whichever is longer:
| Data type | Minimum retention | Reason |
|---|---|---|
| Signed acknowledgments and contract records | Life of the LLP plus statutory limitation periods | Legal record of the contract; defence against consumer and other claims |
| Financial documents, remittance proofs | At least 8 years from case closure | FEMA, tax, and audit obligations; dispute defence |
| Academic documents, SoP, LOR | 3 years from your last application cycle with us | Reference and audit trail |
| Counselling call recordings | 12 months from the call (may be extended if a dispute is pending) | Quality assurance and dispute resolution |
| Written communications (WhatsApp, email) | Per the platform's retention and our operational records | Communication continuity and evidence |
| Website analytics | Up to 26 months (industry default) | Trend analysis |
| Marketing consent and testimonials | Until you withdraw consent in writing | Ongoing marketing under active consent |
Retention beyond stated periods: Notwithstanding the periods above, we may retain any personal data for longer where required to: (a) comply with a legal, tax, accounting, or regulatory obligation; (b) establish, exercise, or defend legal claims (including anticipated claims); (c) respond to lawful requests from public authorities; or (d) protect our legitimate business interests. Where data is retained solely for these purposes, we restrict active processing accordingly.
8. How we protect your data
We apply reasonable industry-standard technical, physical, and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction. Our controls are aligned with the standards specified under IT Rules 2011 (reasonable security practices) and DPDP Act 2023 Sec 8(5).
These include, without limitation: encryption at rest and in transit, role-based access controls, authenticated administrative access, private document storage, immutable records for signed contracts, staff training, and vendor due diligence. Specific technical details are not published as this could itself weaken our security posture.
Despite these measures, no system is 100% secure. You acknowledge that transmitting information over the internet carries inherent risk. You are responsible for maintaining the confidentiality of any access credentials we provide. In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the Data Protection Board and affected individuals as required by DPDP Sec 8(6).
9. Cookies & tracking
Our website uses the following cookie categories:
| Cookie | Purpose | Duration |
|---|---|---|
_ga, _ga_* | Google Analytics 4 — anonymised page visit counting | 2 years |
_gid | Google Analytics — visitor distinguishing | 24 hours |
| Google Tag Manager containers | Loading analytics scripts | Session |
| Contact-form session cookie | Handling of your contact form submission (spam prevention) | Session |
We do not set advertising cookies, remarketing pixels, or third-party trackers. You can block or delete cookies via your browser settings; the site remains fully functional without them.
10. Data of minors (under 18)
Under DPDP Sec 9, we require verifiable guardian consent before processing the personal data of anyone under 18. In our operating context:
- Most study-abroad applicants are 18+ by the time they engage us
- Occasional under-18 applicants (early UG entrants, foundation year students) must have their guardian countersign the acknowledgment
- We do not market to or profile minors
- We do not knowingly collect data of children under 14
11. Your rights under DPDP
You have the following statutory rights under the DPDP Act 2023:
- Right to access and a summary (Sec 11) — a summary of the personal data we hold about you and the categories of parties we shared it with
- Right to correction and erasure (Sec 12) — correction of inaccurate data; erasure of data that is no longer needed for a lawful purpose and where retention is not required by law
- Right to grievance redressal (Sec 13) — see nexthara.in/grievance
- Right to nominate (Sec 14) — nominate someone to exercise your rights in case of death or incapacity
- Right to withdraw consent (Sec 6(4)) — for any processing based purely on your consent; withdrawal does not affect the lawfulness of processing already performed or processing that continues under another lawful basis
How to make a request: Email hello@nexthara.in or contact our Grievance Officer with your full name, passport or registration reference, the right you wish to exercise, and any supporting information.
Identity verification: To protect you from fraudulent requests, we will verify your identity before acting on any request that could disclose or alter personal data. Verification may include confirming details we already hold, requesting a copy of your government ID, or a call-back on your registered phone.
Response timeline: We will respond within 30 days of a valid, verified request. Where a request is complex or involves archived records, we may extend the response period by a further 30 days and will notify you of the reason.
Requests we may refuse or charge for: Under DPDP Sec 6 and generally accepted data-protection principles, we may refuse or charge a reasonable fee for requests that are manifestly unfounded, excessive, or repetitive, or where compliance would infringe the rights of another individual or a legal obligation binding on us. We will explain our reasoning in writing if we do so.
12. Grievance Officer
As required by DPDP Sec 8(9) and the IT Rules 2011, we have designated a Grievance Officer:
Designated Grievance Officer
Head of Operations, Nexthara Overseas LLP
Email: grievance@nexthara.in
Phone: +91 73561 60671 (office reception)
Response SLA: acknowledgment within 48 hours; resolution within 30 days of a valid, verified request
Full details and the escalation ladder are on our dedicated Grievance Redressal page.
13. Changes to this policy
We may update this policy from time to time. The current version and effective date are shown at the top. Material changes will be announced via email to registered users and via a banner on our homepage for 30 days. Continued use of our service after a change means you accept the new version.
This policy is governed by Indian law with exclusive jurisdiction at the courts of Kozhikode, Kerala. For provider-specific policies (universities, lenders, embassies), please refer to the respective provider's own privacy policy. Version v1.0 dated 29 July 2026.
