This Privacy Policy explains how Alpheric Consultants Private Limited, operating as "Kheloge" ("Kheloge", "we", "us") collects, uses, discloses and protects personal data when you use our websites, our mobile applications and the services provided through them (together, the "Platform").
We are the Data Fiduciary for the personal data described in this policy, within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act"). This policy is published in accordance with the DPDP Act, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Please read it alongside our Terms & Conditions and, if you run an academy, a coaching practice or a venue on the Platform, our Partners Policy.
1. Who this policy covers
The Platform is used by several distinct groups, and their relationship to us differs:
- Partners — academies, independent coaches and venue operators who hold an account with us and use the Platform to run their business.
- Partner personnel — owners, managers, coaches and staff who sign in under a Partner's account.
- Players and guardians — the people a Partner coaches, and the parents or guardians responsible for them. Their records are entered by the Partner.
- Enquirers and visitors — people who contact a Partner through the Platform or browse our websites.
Where a Partner enters data about an athlete or a guardian, that Partner determines why the data is collected and we process it on their instructions. We remain responsible for keeping it secure and for the purposes described in this policy.
2. Personal data we collect, and why
2.1 Account and identity
Name, email address, mobile number, password (stored only as a cryptographic hash, never in readable form), profile photograph where you upload one, and the business you belong to. Purpose: to create and secure your account, authenticate you, and attribute actions taken on the Platform.
2.2 Player and guardian records
Names, dates of birth, contact numbers, guardian relationships, photographs, enrolment in batches, attendance and progress notes entered by a Partner. Purpose: to operate the coaching relationship between a Partner and the athletes they coach.
2.3 Financial and payment data
Invoices, amounts due and paid, payment method used, transaction references, and for Partners receiving payouts, bank account details, UPI identifiers and PAN. Purpose: to raise and settle fees, calculate and make payouts, and meet our accounting and tax obligations.
We never store complete card numbers, CVVs or UPI PINs. Card and UPI details are entered on the payment gateway's own secure page and never reach our servers. Bank account details, PAN and identity numbers held for payouts are encrypted at rest.
2.4 Verification data (KYC)
Where a Partner is onboarded for payouts, identity and business documents including PAN, GSTIN, incorporation details, and where applicable a reference to an Aadhaar-based verification. Purpose: to verify who we are paying, and to satisfy the requirements our banking and payment partners place on us. We store a reference to a verification result rather than the underlying document where the verification provider allows it.
2.5 Location, when a register is marked
When a coach saves an attendance register in the Kheloge Partner app, we record the device's location at that moment and how accurate the device reported the reading to be. Purpose: so a Partner can see that a session was marked at the ground rather than elsewhere.
This is collected only at the moment a register is saved. We do not track a device continuously, and the app does not collect location in the background. Refusing the location permission does not prevent a register being marked — the record is simply saved without a location.
2.6 Technical and diagnostic data
Device model, operating system version, application version, IP address, and crash and error reports. Purpose: to keep the Platform working and to diagnose faults. Crash reports are redacted before they are stored: we remove anything that looks like a token, a key, an email address or a phone number.
2.7 Communications
Messages sent through the Platform, including WhatsApp notifications about fees, bookings and sessions, and support conversations. Purpose: to deliver the message you or a Partner asked us to send, and to answer support requests.
3. The legal basis on which we process
We process personal data on one or more of the following grounds:
- Consent — where you have given it, for example to receive notifications or to share a device's location. Consent may be withdrawn at any time, as described in section 7.
- Performance of a contract — to provide the Platform you or your Partner has subscribed to.
- Legitimate uses under the DPDP Act — including responding to an emergency involving a threat to life or health, and complying with a legal obligation.
- Compliance with law — including tax, accounting and anti-money laundering requirements.
4. Children's data
A significant proportion of the athletes on this Platform are under 18. We treat their data with the additional care the DPDP Act requires:
- An athlete under 18 is enrolled by a Partner with the consent of a parent or lawful guardian. The Partner is responsible for obtaining that consent before entering a child's details.
- We do not use a child's personal data for advertising, behavioural tracking or profiling of any kind.
- Notifications about a child — fees, cancellations, feedback requests — are sent to the guardian, not to the child.
- A guardian may ask, through the academy or directly through the Grievance Officer, to see, correct or erase a child's record.
5. Who we share personal data with
We do not sell personal data. We do not share it for advertising. We disclose it only in the following circumstances:
- With your Partner. An academy sees the records of the athletes it coaches and the staff who work for it. It does not see any other Partner's data.
- With service providers who process on our behalf, under contract and only for the purpose we engage them for:
- payment gateways regulated by the Reserve Bank of India, to collect fees and make payouts;
- a messaging provider, to deliver WhatsApp and SMS notifications;
- cloud hosting and storage providers, to run the Platform;
- a verification provider, for KYC checks.
- Where the law requires it — in response to a lawful order from a court, a regulator or a law enforcement agency with jurisdiction over us.
- On a business transfer — if the business is merged, acquired or reorganised, subject to the acquirer being bound by this policy.
6. Where data is stored, and for how long
Personal data is stored on servers located in India. Where a service provider processes data outside India, we do so only in countries not restricted by the Central Government and under contractual safeguards.
- Account and operational records — for as long as the account is active.
- After account closure — deleted or irreversibly anonymised within 90 days, except where a longer period is required by law.
- Financial records — retained for eight years, as required by the Companies Act, 2013 and the Income-tax Act, 1961.
- Crash and diagnostic reports — 90 days.
- Notification delivery logs — 12 months.
7. Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you and how it is being processed;
- Correction and completion of data that is inaccurate or incomplete;
- Erasure of data we no longer need for the purpose it was collected for;
- Withdraw consent at any time, with the same ease as it was given — withdrawal does not affect processing already carried out;
- Nominate another person to exercise these rights on your behalf in the event of your death or incapacity;
- Grievance redressal — to complain to us first, and to the Data Protection Board of India if you are not satisfied with our response.
To exercise any of these, write to the Grievance Officer named below. Account holders may also start a deletion from inside the Kheloge Partner app, or from our account deletion page. We will verify your identity before acting, so that one person cannot alter another's record.
Where you ask us to erase data that a Partner entered about you — an attendance history, say — we will tell the Partner, because the record belongs to the coaching relationship between you and them.
8. How we protect personal data
- Traffic between your device and the Platform is encrypted in transit (TLS).
- Bank details, KYC identifiers, multi-factor secrets and payment credentials are encrypted at rest with AES-256-GCM.
- Passwords are stored only as salted cryptographic hashes and are never recoverable.
- Each Partner's data is isolated at the database level, so one business cannot read another's records even if an application fault occurred.
- Access by our personnel is restricted to what their role requires, and is logged.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and every affected person, as the DPDP Act requires, without delay.
9. Cookies
We use cookies that are strictly necessary to sign you in and keep your session secure, and a small number that remember preferences such as your chosen business. We do not use advertising or cross-site tracking cookies. Blocking necessary cookies will prevent you signing in.
10. Changes to this policy
We may update this policy as the Platform or the law changes. The date at the top shows when it was last revised. Where a change materially affects your rights we will tell you by email or through the Platform before it takes effect.
11. Contact and grievance redressal
This platform is owned and operated by Alpheric Consultants Private Limited, a company incorporated in India and operating under the brand Kheloge.
Registered office
Alpheric Consultants Private Limited
6th Floor, Magnus Tower
Sector 73
Noida Uttar Pradesh 201301
India
Statutory identifiers
- Corporate Identity Number (CIN): U85500UP2023PTC187437
- GSTIN: 09AAZCA2335G1ZD
How to reach us
- General enquiries: [email protected]
- Customer care: +91 72890 76890 — Monday to Saturday, 10:00 to 19:00 IST, excluding public holidays
Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, the following officer may be contacted about any complaint regarding this platform or the handling of your personal data:
Neeraj Dhiman
Grievance Officer
Alpheric Consultants Private Limited
[email protected]
We acknowledge every complaint within 48 hours of receiving it and aim to resolve it within 30 days. Where a complaint cannot be resolved in that time we will write to you explaining why and when we expect to conclude.
12. Escalation to the Data Protection Board
If you are not satisfied with how we have handled your complaint, you may refer it to the Data Protection Board of India established under the Digital Personal Data Protection Act, 2023.