Skip to main content

Privacy Policy

Last updated: 19 August 2026

Introduction

Brenman Consulting Private Limited (“BRENMAN”, “we”, “us”, and/or “our”) values the privacy of the individuals who use our website, applications, and related online services, including our learning Programs, the Bridging Room editorial and podcast, and our Consulting offerings (collectively, the “Services”). This Privacy Policy explains how we collect, use, share, and protect information from users of our Services (“you”, “your”), including learners, readers, prospective clients, and job applicants. By using our Services, you agree to the collection, use, disclosure, and procedures this Privacy Policy describes. Your use of our Services is also subject to our Terms of Service.

Information We Collect

We collect information from and about you and your devices from the sources described below.

Information you provide to us

  • Registration & profile. When you create an account we collect your name and email address, and you may add profile details such as a job title, organisation, profile photo, and professional background. If you sign in through a third-party account (Google or LinkedIn), we receive basic profile information from that provider.
  • Enrollment & learning activity. When you enroll in or work through a program, we collect your progress, quiz responses, capstone submissions, and completion records used to issue certificates.
  • Payment information. When you make a purchase, your payment details are collected and processed by our payment processor, Razorpay. We do not store your card or bank details on our servers.
  • Communications. If you contact us for support, subscribe to the Bridging Room newsletter, join a waitlist, or enquire about consulting, we collect the information you choose to provide, such as your email address and the contents of your message.
  • Careers. If you apply for a role with us, we collect the contact and background information you submit (for example, your resume or the information you make available through LinkedIn).
  • Ratings, feedback & user content. If you submit ratings, feedback, comments, or other content through the Services, we receive the information you choose to provide.

Information we collect automatically

  • Usage information. Pages and content you view, searches you run, programs you access, purchases you make, and the dates and times of your visits.
  • Device information. Your IP address, browser type, operating system, device identifiers, and similar technical details.
  • Approximate location. We may infer your general location (for example, from your IP address).
  • Cookies and similar technologies. See the Cookies section below.

Information we receive from third parties

  • If you link a third-party account (such as Google or LinkedIn), we may receive your profile information and photo from that provider. You can limit what is shared through that provider’s privacy settings.
  • We may receive additional information, such as analytics or marketing data, from service providers and combine it with information we already hold about you.

How We Use the Information We Collect

  • To provide, maintain, personalise, and improve our Services;
  • To process enrollments and payments and to issue certificates;
  • To send transactional messages (enrollment and payment confirmations, receipts, account and security notices);
  • To respond to your enquiries and provide customer and consulting support;
  • To send you the Bridging Room newsletter and other communications where you have opted in, and to tailor content and recommendations;
  • To understand how our Services are used and to develop new features and content;
  • To generate de-identified, aggregated statistics and reports;
  • To detect, prevent, and address fraud, abuse, and security issues; and
  • To comply with legal obligations and enforce our Terms of Service or other rights.

Legal Basis for Processing

We process your personal data in accordance with India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”), principally on the basis of your consent and for certain legitimate uses permitted by law (such as providing a service you have requested and complying with legal obligations). If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on an appropriate legal basis under the GDPR: consent, contractual necessity, compliance with a legal obligation, or our legitimate interests (for example, to keep our Services secure and to improve them), balanced against your rights.

How We Share the Information We Collect

We do not sell your personal data. We share information only as described below:

Service providers (data processors)

  • Supabase: authentication, database, and storage, hosted in India (AWS Mumbai / ap-south-1) for data residency.
  • Razorpay: payment processing (PCI-DSS compliant).
  • Bunny Stream: video hosting and delivery.
  • Resend: transactional and newsletter email delivery.
  • Google & LinkedIn: optional sign-in and related profile information.
  • YouTube: embedded free program content.
  • Vercel: platform hosting and privacy-aware analytics.
  • Upstash: rate limiting and caching.
  • Sentry: error monitoring.

Each provider operates under its own privacy policy; we encourage you to review them.

Other disclosures

  • Legal and safety. We may disclose information where we believe it is required or appropriate to comply with the law or lawful requests, to enforce our terms, or to protect the rights, property, or safety of you, us, or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this Privacy Policy.
  • With your consent. We may share information for other purposes with your permission.

Cookies

We and our providers use cookies and similar technologies to operate and improve the Services:

  • Strictly necessary cookies: required for login, authentication, and security (for example, your Supabase session). The Services cannot function without these.
  • Functional cookies: remember your preferences and account settings.
  • Analytics cookies: used, with your consent where required, to understand usage and improve the Services.

You can manage non-essential cookies through our cookie-consent banner and your browser settings. If you block certain cookies, some features may not work as intended.

Your Rights and Choices

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you and request a summary of its processing;
  • Correct or update inaccurate or incomplete information;
  • Request erasure of your personal data;
  • Withdraw consent for non-essential processing at any time;
  • Receive a copy of your data in a portable format (where applicable);
  • Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act; and
  • Raise a grievance with our Grievance Officer (below) and, where applicable, lodge a complaint with the Data Protection Board of India or your local supervisory authority.

Marketing. You can unsubscribe from newsletters and promotional emails via the link in those emails; you will still receive essential account and transactional messages. Do Not Track. There is no common standard for responding to browser “Do Not Track” signals, and we do not currently respond to them.

To exercise any of these rights, contact us at info@brenmanconsulting.com. We may ask you to verify your identity before acting on a request. Some exceptions and legal retention obligations may apply.

Data Retention

We retain your account data for as long as your account is active. Learning progress and certificates may be retained to support your professional records. If you request deletion, we will remove your personal data within a reasonable period (typically 30 days), except where we are required or permitted by law to retain it, or need it for backups, fraud prevention, or to resolve disputes.

Security

We use reasonable technical and organisational safeguards to protect your information, including encrypted connections (TLS), row-level security, and role-based access controls. Payment data is handled entirely by Razorpay and never touches our servers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

International Data Transfers

Our primary data storage is located in India (AWS Mumbai). Some of our service providers may process limited data outside India. Where we transfer personal data internationally, we take steps to ensure it is protected consistently with this Privacy Policy and applicable law, and we do not transfer data to territories restricted by the Government of India under the DPDP Act.

Children’s Privacy

Our Services are intended for professionals and are not directed to children under 18. We do not knowingly collect personal data from a child without verifiable parental or guardian consent as required by the DPDP Act. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.

Grievance Officer & Contact

For any questions, requests, or grievances regarding your personal data or this Privacy Policy, you may contact our Grievance Officer, Aditya Mulukuri, at adityamulukuri@brenmanconsulting.com (or info@brenmanconsulting.com). We will acknowledge and address grievances within the timelines required by applicable law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated “Last updated” date, and it becomes effective when posted. If we make material changes to how we use or share personal data previously collected from you, we will notify you through the Services, by email, or by other appropriate means.