Pathway Group

Information Security Policy

Last Updated: August 2026

Version: 1.0

1. Introduction

Pathway Academic Resource Private Limited ("PARPL", "we", "our", or "us"), a Pathway Group company, is committed to protecting the confidentiality, integrity, availability, and security of the information entrusted to us.

As an education consultancy and student services organization, PARPL processes personal information, educational records, identity documents, financial information, and other confidential information while providing counselling, admission guidance, application assistance, scholarship support, visa assistance, and related services.

This Information Security Policy establishes the principles and practices adopted by PARPL to safeguard information and reduce the risk of unauthorized access, disclosure, alteration, destruction, or misuse.

This Policy should be read together with our Privacy Policy, Data Processing Policy, Data Sharing Policy, Data Retention Policy, Consent Management Policy, Terms & Conditions, Website Disclaimer, and other legal policies published on www.parpl.org.

Pathway Academic Resource Private Limited is incorporated under the Companies Act, 2013 bearing Corporate Identification Number (CIN): U80300GJ2013PTC076270, with its Registered Office at:

404, Atlantis Heights,

Opp. Vadiwadi Fire Station,

Sarabhai Main Road,

Vadodara – 390023,

Gujarat, India.

2. Purpose

The purpose of this Policy is to:

  • Protect personal and confidential information.
  • Maintain the confidentiality, integrity, and availability of information.
  • Reduce cybersecurity risks.
  • Protect student documents and academic records.
  • Promote responsible information handling practices.
  • Support compliance with applicable laws and contractual obligations.
  • Foster trust among students, parents, institutions, and business partners.

3. Scope

This Policy applies to information processed through:

  • www.parpl.org
  • Student Portal
  • MBBS Admission Predictor
  • Counselling records
  • University application systems
  • Scholarship applications
  • Visa assistance services
  • Email communications
  • WhatsApp communications
  • CRM systems
  • Internal administrative systems
  • Future Medico Campus platforms
  • Future OSMAT platforms
  • Cloud storage
  • Physical records
  • Any digital or physical systems operated by PARPL.

This Policy applies to all directors, employees, counsellors, consultants, interns, contractors, vendors, service providers, and other authorized persons who access PARPL information.

4. Information Security Principles

PARPL follows the following information security principles:

Confidentiality

Information shall be accessible only to authorized individuals with a legitimate business need.

Integrity

Information shall be protected against unauthorized modification, corruption, or destruction.

Availability

Information shall remain available to authorized users whenever required for legitimate business purposes.

Accountability

Individuals handling information are responsible for protecting it in accordance with this Policy.

Least Privilege

Access to information shall be limited to the minimum level necessary for an individual to perform assigned responsibilities.

5. Information Classification

PARPL classifies information according to its sensitivity.

Public Information

Information approved for public release, including:

  • Website content.
  • Marketing brochures.
  • Public announcements.
  • Educational articles.

Internal Information

Information intended for internal operational use, including:

  • Internal procedures.
  • Administrative documents.
  • Staff communications.

Confidential Information

Information requiring restricted access, including:

  • Student records.
  • Counselling notes.
  • Admission applications.
  • Academic documents.
  • Financial records.
  • Contracts.
  • Business information.
  • Vendor information.

Highly Confidential Information

Information requiring the highest level of protection, including:

  • Identity documents.
  • Passport copies.
  • Visa documentation.
  • Financial documents.
  • Payment records.
  • Authentication credentials.
  • Security configurations.
  • Internal security documentation.

6. Access Control

PARPL restricts access to information based on business requirements.

Access controls may include:

  • User authentication.
  • Unique user accounts.
  • Strong password requirements.
  • Role-based access permissions.
  • Multi-factor authentication where implemented.
  • Session management.
  • Account monitoring.
  • Timely removal of inactive accounts.

Access rights shall be reviewed periodically and updated where necessary.

7. Protection of Student Information

PARPL recognizes that student information requires enhanced protection.

Reasonable safeguards include:

  • Restricted document access.
  • Secure document storage.
  • Controlled sharing procedures.
  • Identity verification before disclosure.
  • Staff confidentiality obligations.
  • Secure communication channels.
  • Periodic review of access permissions.

Student information shall be accessed only by personnel directly involved in providing the requested services.

8. Password and Account Security

Authorized users of PARPL systems are expected to:

  • Maintain confidential passwords.
  • Avoid sharing login credentials.
  • Use strong and unique passwords.
  • Change passwords when compromise is suspected.
  • Secure devices used to access PARPL systems.
  • Immediately report suspected unauthorized access.

PARPL may implement password complexity requirements and authentication controls to enhance security.

9. Device Security

Devices used to access PARPL information should be protected through reasonable security measures, including:

  • Screen lock protection.
  • Operating system updates.
  • Antivirus or endpoint protection where appropriate.
  • Device encryption where supported.
  • Secure Wi-Fi connections.
  • Protection against unauthorized physical access.

Lost or stolen devices used for business purposes should be reported promptly.

10. Network and System Security

PARPL employs reasonable technical measures to protect its digital infrastructure.

Such measures may include:

  • Firewalls.
  • Secure hosting environments.
  • SSL/TLS encryption for website communications.
  • Security monitoring.
  • Malware protection.
  • System updates.
  • Vulnerability management.
  • Access logging.
  • Network segmentation where appropriate.

Security measures may evolve as technology and risks change.

11. Email and Communication Security

Employees and authorized personnel are expected to exercise caution when communicating sensitive information through email, messaging platforms, or other electronic communication channels.

Where appropriate:

  • Sensitive documents should be shared securely.
  • Suspicious emails should not be opened.
  • Unknown attachments should not be downloaded.
  • Confidential information should not be sent to unauthorized recipients.

12. Incident Reporting

Any actual or suspected information security incident should be reported immediately to the appropriate internal authority.

Examples include:

  • Unauthorized access.
  • Data leakage.
  • Lost devices.
  • Malware infection.
  • Phishing attempts.
  • Password compromise.
  • Unauthorized disclosure.
  • Website attacks.
  • Suspicious system activity.

PARPL will investigate reported incidents and take appropriate corrective actions.

13. Business Continuity

PARPL maintains reasonable measures to support business continuity and minimize disruption in the event of system failures, cybersecurity incidents, natural disasters, or other unforeseen events.

Such measures may include:

  • Data backups.
  • Recovery procedures.
  • System redundancy where appropriate.
  • Disaster recovery planning.
  • Periodic testing of recovery processes.

14. Employee Responsibilities

Every employee, consultant, contractor, and authorized user is responsible for:

  • Protecting confidential information.
  • Following security procedures.
  • Reporting security incidents promptly.
  • Using PARPL systems responsibly.
  • Preventing unauthorized disclosure.
  • Complying with this Policy and related procedures.

Failure to comply with this Policy may result in disciplinary action, termination of access, contractual consequences, or legal action where applicable.

15. Third-Party Service Providers

PARPL may engage third-party service providers for hosting, cloud services, payment processing, communications, analytics, CRM systems, or other operational services.

PARPL undertakes reasonable due diligence before engaging such providers and expects them to implement appropriate security measures to protect information processed on PARPL's behalf.

16. Policy Review

This Policy shall be reviewed periodically to ensure continued effectiveness, compliance with applicable laws, technological developments, emerging security risks, and business requirements.

PARPL may revise this Policy whenever necessary to strengthen information security practices.

17. Changes to this Policy

PARPL reserves the right to modify or update this Information Security Policy from time to time.

The latest version will always be available on www.parpl.org together with the updated "Last Updated" date.

Continued use of PARPL's Website or services after publication of an updated Policy constitutes acknowledgement of the revised Policy.

18. Contact Us

If you have any questions regarding this Information Security Policy, please contact:

Pathway Academic Resource Private Limited (PARPL)
A Pathway Group Company

Corporate Identification Number (CIN):
U80300GJ2013PTC076270

Registered Office:
404, Atlantis Heights,
Opp. Vadiwadi Fire Station,
Sarabhai Main Road,
Vadodara – 390023, Gujarat, India.

Website:
www.parpl.org

Privacy Email:
privacy@parpl.org