Legal
Privacy Policy
This policy explains what personal data Enrolia handles on this website, why we use it, where it may be processed, and the choices available to you.
Effective 26 July 2026
1. Who we are
Enrolia Pvt Ltd (“Enrolia”, “we”, “us”, or “our”) operates enrolia.app. Depending on the law that applies to you, Enrolia is the controller, business, or other responsible organisation for the personal data described in this policy.
Enrolia helps prospective graduate students research options, understand application decisions, read educational content, and save selected website-tool results. This policy covers the public website, its account area, member articles, newsletter and dashboard waitlist, and the Application Archetype tool. A future Enrolia product may provide an additional notice if it handles different data or uses it for a different purpose.
2. Data we handle
Account and sign-in data
Enrolia uses WorkOS to provide Google sign-in and email-code authentication. When you create or use an account, we receive your WorkOS user identifier and available identity details such as your name, email address, email-verification status, and profile picture.
If you choose Google sign-in, we use those basic identity details to authenticate you and maintain your Enrolia account. We do not request access to your Gmail, Google Drive, or Google Calendar content. We never receive your Google password.
Membership and communication preferences
When an Enrolia account is first created, the current account flow records a newsletter subscription preference and places the account on the dashboard waitlist. We store the status and relevant timestamps for each. The newsletter is optional: you can unsubscribe without losing your account, member-article access, saved results, or waitlist position. Where applicable law requires separate, affirmative marketing consent, Enrolia will obtain and record that consent before sending marketing communications and will not use these terms to override that requirement.
Application Archetype data
Before you sign in, your assessment answers stay in your browser’s
sessionStorage. They are not sent to Enrolia until you
sign in and choose to save the assessment. If you save it, Enrolia
stores the answers, assessment and scoring versions, calculated
result, and record timestamps with your account. Saved information is
private unless you choose to create a public, result-only link.
A public result page can be opened by anyone who has its link. It contains the calculated result summary and creation date. It does not include your assessment answers, name, email address, or WorkOS identifier. You can revoke the link or delete the saved archetype from your account. A link is not a promise of confidentiality once you share it; people who receive it may copy or disclose the page.
Technical, security, and contact data
Our hosting, authentication, and API systems may process request timestamps, IP address, browser or device information, request path, response status, and security or diagnostic events. Enrolia’s custom authentication telemetry is deliberately limited to a random request identifier, authentication phase, success or failure outcome, safe failure category, status, and duration. It excludes names, email addresses, page URLs, OAuth codes or state, cookies, session values, access tokens, and request or response bodies.
If you contact us, we receive the information you include in your message and the details needed to respond. Please do not send passports, government identification, financial records, health records, passwords, or other sensitive documents by ordinary email.
Sources
We collect data directly from you, from the WorkOS or Google sign-in method you choose, and automatically from the browser, hosting, and security systems that deliver the service.
3. How we use personal data
We use personal data to:
- verify identity, create an account, and maintain a secure session;
- provide member articles, account controls, and saved website-tool results;
- manage newsletter preferences and the Enrolia dashboard waitlist;
- create or revoke a public result page only when you request it;
- respond to support, privacy, and account-deactivation requests;
- protect Enrolia and its users, investigate abuse, and diagnose failures;
- maintain, test, and improve the reliability of the service; and
- comply with applicable legal obligations.
Depending on your location and the particular processing, our lawful bases may include performing a contract or taking steps at your request before a contract, your consent, our legitimate interests in operating and securing the service, and compliance with a legal obligation. Where we rely on consent, you may withdraw it without affecting processing that happened before withdrawal or processing based on another lawful basis.
We do not sell your personal data. We do not use Google sign-in data, saved assessment answers, or account records for personalised advertising. We do not use this site for cross-context behavioural advertising.
5. When we share personal data
We disclose data only as needed to operate Enrolia, follow your instructions, protect the service, or meet legal requirements. The categories of recipients currently include:
- WorkOS and Google, for the sign-in method you choose and the related identity and session services;
- Cloudflare, for website delivery, security, Worker execution, and bounded operational logs;
- DigitalOcean, for Enrolia API, database, network, storage, and backup infrastructure;
- email-delivery providers when we send an authentication or newsletter message; and
- professional advisers, authorities, or another organisation when reasonably necessary to comply with law, protect rights and safety, prevent fraud or abuse, or complete a corporate transaction subject to appropriate safeguards.
We seek to use operational providers as processors or service providers where that relationship applies and to limit their use of Enrolia account data to the services they provide. Independent providers, including Google, may process data under their own terms and privacy notices. We do not permit providers to use Enrolia account data for their own advertising.
Creating a public, result-only link is a disclosure you direct us to make. Anyone who receives that link may view and copy the result summary. Enrolia does not include your name, email, WorkOS identifier, or full answers on that page, and asks search engines not to index it, but cannot control what a recipient or third party does after access.
6. International transfers
Enrolia and its providers may process personal data in India, the United States, and other countries where our providers operate. Those countries may have data-protection rules different from the rules in your country.
Where a law restricts an international transfer, we will use a legally recognised transfer mechanism or safeguard, such as an adequacy decision, approved standard contractual clauses, the UK IDTA or Addendum where relevant, or another mechanism permitted by applicable law. You may contact us to request information about the safeguards relevant to your data, subject to lawful confidentiality limits.
7. Retention and deletion
We keep account and membership records while your account is active and as reasonably needed to provide the service. Saved archetypes remain until you delete them or the account data is otherwise removed. Revoking a public share makes its link stop resolving; deleting an archetype also removes its active public share. Callback state is short-lived, and the session cookie has a maximum lifetime of seven days at a time.
Security and operational logs are retained for a limited period appropriate to troubleshooting, abuse prevention, and audit needs. Backups may retain encrypted copies for a bounded backup cycle before they expire or are overwritten. We may retain limited records when required for security, fraud prevention, legal compliance, or the establishment or defence of legal claims. We use the purpose of the data, the need to provide the service, legal requirements, and the risk of misuse to set retention periods; we do not keep data longer than reasonably necessary for those purposes.
At launch, submitting an account-deactivation request creates a durable request for Enrolia to handle. It is not an immediate, automated deletion. Enrolia reviews the request and coordinates any required account, session, database, and provider action. We will not describe the account as deleted until that work is complete.
8. Security and incidents
We use measures designed to protect personal data, including encrypted network connections, secure and HttpOnly cookies, verified authentication callbacks, short-lived access tokens, per-user API authorization, restricted infrastructure credentials, database access controls, backups, and privacy-limited authentication telemetry. No internet service can promise absolute security, and you use Enrolia at your own risk subject to rights that cannot lawfully be excluded.
We maintain incident-handling procedures appropriate to the service. If a security incident triggers a legal notification duty, we will notify affected people, regulators, or other parties as required by applicable law and within the required time.
9. Your rights and choices
You can use the account page to:
- review your account, newsletter, and dashboard-waitlist status;
- unsubscribe from or resubscribe to newsletter email;
- delete a saved Application Archetype;
- create or revoke a public result-only link; and
- submit an account-deactivation request.
Depending on the law that applies to you, you may ask us to confirm whether we process your data, provide access or a copy, correct or complete it, delete it, restrict or object to processing, provide portable data, or stop marketing. You may withdraw consent where consent is the legal basis. You may also raise a grievance with us and complain to your local data-protection or supervisory authority.
European Economic Area, United Kingdom, and Switzerland
If the GDPR or UK GDPR applies, your rights may include access, rectification, erasure, restriction, portability, objection (including an absolute right to object to direct marketing), and the right to withdraw consent. You may complain to the supervisory authority in the country where you live, work, or believe an infringement occurred.
India
If Indian data-protection law applies, you may have rights to access information about processing, correct or update data, request erasure where permitted, withdraw consent, and raise a grievance through the applicable mechanism. We will publish or provide any designated data-protection contact required for the service as the applicable rules come into force.
California and other United States state laws
Where applicable, you may have rights to know or access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal treatment. Enrolia does not sell personal data or share it for cross-context behavioural advertising. We will honour a legally valid opt-out signal, including Global Privacy Control, where required. We will not discriminate against you for exercising a right.
Brazil, Australia, and Canada
Where applicable, Brazilian users may exercise LGPD rights such as confirmation, access, correction, anonymisation, blocking, deletion, portability, and withdrawal of consent. Australian and Canadian users may request access or correction, ask about overseas disclosures, and make a privacy complaint. All such rights are subject to the exceptions, procedures, and limits in the law that applies to the request.
To make a request, email us using the address below. We may need to verify your identity, ask for clarification, and decline or limit a request where a lawful exception applies. We will respond within the period required by applicable law. We do not charge a fee unless the law permits one for a manifestly unfounded, excessive, or repetitive request.
10. Children
Enrolia is a general-audience service for people planning higher education and is not directed to children under 13. We do not knowingly collect personal data from a child under 13 without the legally required parental consent. If you believe a child has given us data, contact us so we can investigate and take appropriate action.
In places where a child is defined as under 18, including under India’s data-protection framework where applicable, additional parental-consent and child-data rules may apply. People under 18 should use Enrolia only with a parent or lawful guardian where required. We do not use this site for child-targeted advertising or behavioural monitoring.
11. Changes to this policy
We may update this policy when the product, providers, or legal requirements change. We will post the revised policy here and change the effective date. If a change materially affects how we use existing personal data, we will provide additional notice or seek consent where required.
12. Contact us
For privacy questions, data requests, or grievances, email contact@enrolia.app. Please do not send passports, government identification, financial records, health records, passwords, or other sensitive documents by ordinary email.