WeAce — Coaching & Mentoring Platform
A brand of NorthCap Services Private Limited
Last updated: September 14, 2026
Effective date: September 14, 2026
1. Introduction
This Privacy Policy explains how NorthCap Services Private Limited, operating under the brand name "WeAce" ("WeAce", "we", "us", "our"), together with its group entity in United Arab Emirates (see Section 2), collects, uses, discloses, and protects personal data when you use our coaching and mentoring platform, including our website, mobile applications, AI Coach feature, and any related services (collectively, the "Platform").
This Policy applies to all users of the Platform, including:
Coachees (individuals receiving coaching or mentoring)
Coaches / Mentors (individuals delivering coaching or mentoring)
Organisation Administrators (representatives of client organisations who onboard employees onto the Platform)
Visitors to our website
We act as a data controller (or "data fiduciary" under Indian law) in respect of most personal data processed through the Platform. Where an organisation ("Client") onboards its employees onto the Platform, WeAce may act as a data processor on the Client's behalf for certain data; this is set out in Section 4 and governed by a separate Data Processing Agreement (DPA) with the Client.
This Policy is drafted with reference to the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU GDPR (where applicable), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), together with any applicable free zone data protection regimes (e.g. the DIFC Data Protection Law 2020 or ADGM Data Protection Regulations 2021) where WeAce or a Client operates from those jurisdictions, and India's Digital Personal Data Protection Act, 2023 ("DPDPA"). Jurisdiction-specific provisions are set out in Sections 16 and 17.
2. Who We Are and How to Contact Us
Data Fiduciary / Parent Entity (India, and default controller for the Platform): NorthCap Services Private Limited, operating under the brand name "WeAce," a company incorporated under the Companies Act, 2013
CIN: U74999HR2020PTC089022.
Registered address: The Palm Springs, Golf Course Road, OPP. HOTEL, IBIS,, Sector - 54, Gurugram, Gurgaon, Haryana, 122001
India Grievance Officer: Meeta Srivastava / Partner & Head of Talent Acquisition, [email protected]
Data Protection Officer / Privacy Lead: Anurag Dixit / Project Manager
3. Personal Data We Collect
3.1 Data you provide directly
Account & profile data: Name, email, professional biography.
Onboarding & assessment data: Coaching goals, development areas, skills, and preferences used for matching.
Coaching content: Goals logged in-platform and messages exchanged with coaches/coachees.
AI Coach interaction data: Prompts, conversation transcripts, and feedback provided on AI responses.
Calendar data: Availability, meeting titles, attendees, timestamps, and metadata shared through calendar integrations (e.g., Google Calendar, Outlook/Microsoft 365).
Communications: Support requests, survey responses, and feedback forms.
Payment data (where applicable): Billing name, address, and transaction history. Card details are processed by our payment processor and are not stored by us.
3.2 Data collected automatically
Device and log data (IP address, browser type, operating system, device identifiers)
Usage data (pages visited, features used, session duration, click patterns)
Cookies and similar tracking technologies (see Section 11)
3.3 Data from third parties
Single sign-on (SSO) providers (e.g. Google Workspace, Microsoft Entra ID) when you log in via your employer's identity provider
Calendar and scheduling providers, when you connect your calendar
Your employer/Client organisation, where onboarding data is provided in bulk (e.g. via HRIS integration or CSV upload)
3.4 Special category data
Coaching conversations may incidentally touch on topics that constitute special category data under UK GDPR Article 9 (e.g. references to mental health, stress, disability, or wellbeing). We do not require you to disclose such information, and we minimise its collection wherever possible. Where special category data is processed, we rely on your explicit consent (Article 9(2)(a)) or another applicable legal basis such as employment/social protection obligations (Article 9(2)(b)), and it is subject to heightened access controls described in Section 9.
We do not knowingly collect special category data through the AI Coach for profiling or automated inference purposes; such disclosures within a conversation are treated as incidental to the coaching support being provided, not as a data point used to build a behavioural profile.
4. How We Use Your Data and Our Legal Basis
Creating and managing your account
Data used: Profile and contact data.
Legal basis: Contract (UK GDPR Art. 6(1)(b)).
Algorithmic matching of coaches and coachees
Data used: Profile, goals, preferences, and availability.
Legal basis: Contract; legitimate interests (UK GDPR Art. 6(1)(f)) — see Section 5.
Delivering the AI Coach feature
Data used: Conversation data and profile context.
Legal basis: Contract; consent where special category data arises.
Facilitating scheduling via calendar sharing
Data used: Calendar availability and meeting metadata.
Legal basis: Contract; consent, where calendar connection is optional.
Platform improvement, analytics, and AI model evaluation
Data used: Usage data and aggregated/de-identified interaction data.
Legal basis: Legitimate interests.
Client reporting
Data used: Usage statistics and participation rates, provided to employers in aggregated or de-identified form.
Legal basis: Legitimate interests; contract with the client.
Security, fraud prevention, and abuse monitoring
Data used: Log data and account activity.
Legal basis: Legitimate interests; legal obligation.
Legal and regulatory compliance
Data used: Information as required.
Legal basis: Legal obligation (UK GDPR Art. 6(1)(c)).
Marketing communications (optional)
Data used: Contact data.
Legal basis: Consent (UK GDPR Art. 6(1)(a)).
5. Automated Decision-Making and the Matching Algorithm
We use an algorithm to recommend or assign coach-coachee matches based on factors such as stated goals, expertise, availability, and preferences.
Human involvement: Matches are recommendations. [Insert accurate description — e.g. "A member of our team or the coachee reviews and confirms suggested matches before they are finalised" OR "Matches are automated but can be changed by the coachee at any time without needing to provide a reason."]
Article 22 rights: If matching (or any other feature, including AI Coach guidance) ever results in a decision that produces legal or similarly significant effects without meaningful human involvement, you have the right to request human review, express your point of view, and contest the decision. Contact us using the details in Section 2.
Logic and factors used: On request, we will provide a general explanation of the categories of data and the logic used in matching, to the extent this does not compromise trade secrets or the rights of others.
6. How We Share Your Data
We share personal data only as necessary, with the following categories of recipients:
Coaches/Coachees you are matched with — profile and relevant session information necessary to deliver coaching.
Your employer / Client organisation — typically limited to enrolment status, participation/engagement metrics, and aggregated outcomes. We do not share the content of individual coaching sessions or AI Coach conversations with employers unless you explicitly consent, or disclosure is required by law (see Section 6.1).
Sub-processors and service providers, including:
Cloud hosting and infrastructure providers
Calendar/scheduling integration providers (e.g. Google, Microsoft)
AI model providers used to power the AI Coach feature
Analytics, customer support, and email delivery tools
Payment processors
A current list of sub-processors is available at [link] or on request.
Professional advisors and regulators, where necessary for compliance, audits, or legal proceedings.
In connection with a corporate transaction (merger, acquisition, financing, or sale of assets), subject to confidentiality protections.
6.1 Confidentiality of coaching content
We treat coaching session notes and AI Coach conversations as confidential. We will only disclose this content to your employer or third parties:
(a) with your explicit consent;
(b) where required by law, regulation, or valid legal process; or
(c) where we reasonably believe disclosure is necessary to prevent serious harm to you or others.
7. Calendar Integration
If you choose to connect a third-party calendar (e.g. Google Calendar, Outlook/Microsoft 365) to enable scheduling:
We access only the data necessary to display availability and create/manage coaching session events (e.g. free/busy status, event titles, times, and participants for events created via the Platform).
We do not read the content of unrelated calendar events beyond what is needed to determine availability, unless you grant broader permissions and are separately notified of this.
You can disconnect calendar access at any time in your account settings; this will stop future syncing but does not retroactively delete data already processed.
Calendar providers process this data under their own privacy policies as independent controllers for their platforms, and as our sub-processors for data passed through the integration.
8. AI Coach — Specific Disclosures
Conversations with the AI Coach are processed to generate responses and may be logged for quality, safety, security, and service-improvement purposes. Where necessary, conversation data may be reviewed by authorised WeAce personnel or trusted contractors who are subject to appropriate confidentiality obligations.
AI model training: WeAce does not use AI Coach conversations or interaction data to train or fine-tune AI models.
The AI Coach is a supportive development tool and does not provide medical, psychological, financial, or legal advice. It is not a substitute for qualified professional advice or emergency services.
Data retention: AI Coach conversation data is retained in accordance with WeAce's applicable data retention policy and the terms of the contract signed with the customer organisation, where applicable. Where data is used for analytics or service improvement, WeAce may use aggregated or de-identified information where appropriate.
9. Data Security
We implement technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, access controls and role-based permissions (with enhanced restrictions on coaching content and special category data), regular security testing, and employee confidentiality obligations. No system is completely secure, and we cannot guarantee absolute security.
10. International Data Transfers
Where personal data is transferred outside the UK or EEA (for example, to hosting or AI service providers located elsewhere), we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses (as adapted for UK transfers), or transfers to jurisdictions covered by an applicable adequacy decision. For transfers of personal data out of the UAE, see Section 16.4; for transfers of personal data out of India, see Section 17.7.
11. Cookies and Tracking Technologies
We use cookies and similar technologies for authentication, essential platform functionality, analytics, and (where consented) marketing. You can manage preferences via our cookie banner or browser settings. See our [Cookie Policy] for full details.
12. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, including:
Account data: for the duration of your account plus [•] following closure, or as required by the Client contract.
Coaching session notes and AI Coach transcripts: [•] months/years, or as specified in the applicable Client DPA.
Calendar/scheduling metadata: deleted or anonymised [•] after the relevant session, or upon disconnection.
We may retain data longer where required for legal, tax, accounting, or dispute-resolution purposes.
13. Your Rights
Subject to applicable law, you have the right to:
Access the personal data we hold about you
Rectify inaccurate or incomplete data
Erase your data ("right to be forgotten"), subject to legal retention requirements
Restrict or object to certain processing, including processing based on legitimate interests
Data portability for data you provided to us
Withdraw consent at any time where processing is based on consent (e.g. calendar connection, marketing)
Rights related to automated decision-making, as described in Section 5
To exercise these rights, contact us at [[email protected]]. We will respond within statutory timeframes (generally one month under UK GDPR).
14. Children's Privacy
The Platform is intended for use by working professionals and is not directed at individuals under 18. We do not knowingly collect personal data from children.
15. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via the Platform or email prior to taking effect. The "Last updated" date at the top reflects the most recent revision.
16. Jurisdiction-Specific Provisions — UAE
This section applies to personal data processed in connection with users, Clients, coaches, or coachees based in, or where processing occurs in, the United Arab Emirates, and supplements the rest of this Policy.
16.1 Applicable law. Processing is governed by the UAE PDPL (Federal Decree-Law No. 45 of 2021) and its executive regulations. If WeAce operates through a free zone entity (e.g. in the DIFC or ADGM), the DIFC Data Protection Law 2020 or ADGM Data Protection Regulations 2021 apply instead of the federal PDPL for data processed by that entity, and are broadly aligned with GDPR-style obligations.
16.2 Legal bases. Where the PDPL applies, we rely on grounds equivalent to those in Section 4, including your consent, necessity for performing a contract with you, compliance with a legal obligation, and our legitimate interests, balanced against your rights and expectations.
16.3 Special category ("sensitive") data. As under UK/EU law, coaching conversations may incidentally touch on health, psychological, or similarly sensitive information. Under the PDPL, processing such data generally requires your explicit consent unless another statutory exception applies. We apply the same minimisation and access-control safeguards described in Sections 3.4 and 9.
16.4 Cross-border transfers. Where personal data is transferred out of the UAE (including to WeAce's UK entity, sub-processors, or AI service providers located elsewhere), we ensure the destination provides an adequate level of protection, or we rely on appropriate safeguards such as standard contractual clauses recognised under the PDPL, your explicit consent, or another permitted derogation.
16.5 Your rights. UAE-based users have rights broadly equivalent to those in Section 13, including the right to access, correct, and request erasure of personal data, to object to or restrict certain processing, to withdraw consent, and to be informed of automated decision-making that produces significant effects (see Section 5). Requests can be made using the UAE contact details in Section 2.
16.6 Data Office notification. Where required by the PDPL (e.g. for high-risk processing or certain data breaches), we will notify the UAE Data Office and/or affected individuals in accordance with statutory timeframes.
16.7 Employer/Client relationships in the UAE. Where a UAE-based Client onboards employees onto the Platform, the confidentiality protections around coaching content in Section 6.1 apply equally, and any data-sharing arrangement with the Client is governed by a DPA reflecting PDPL requirements.
17. Jurisdiction-Specific Provisions — India
This section applies where WeAce processes personal data as a company incorporated in India, or in connection with users, Clients, coaches, or coachees based in India, and supplements the rest of this Policy. Under India's Digital Personal Data Protection Act, 2023 ("DPDPA"), WeAce acts as a "Data Fiduciary" and you, as a user, are a "Data Principal."
17.1 Applicable law. Processing of personal data of individuals in India is governed by the DPDPA and its rules. Where the DPDPA and another regime (e.g. UK GDPR) could both apply to the same processing, we apply whichever standard is more protective for the relevant individual.
17.2 Legal basis / consent. We process personal data on the basis of your consent, given via clear affirmative action, or where processing falls under a "certain legitimate use" recognised by the DPDPA (e.g. you have voluntarily provided data for a specified purpose and not indicated you do not consent, compliance with law, or medical emergencies). Consent requests are presented separately from other terms, in clear language, and you may withdraw consent at any time as easily as you gave it, without affecting the lawfulness of processing before withdrawal.
17.3 Notice. Before or at the time of collecting personal data, we provide an itemised notice describing the personal data collected and the purpose of processing, in accordance with DPDPA requirements. This Policy, together with in-product consent notices, is intended to satisfy that obligation.
17.4 Children's and persons-with-disability data. The DPDPA imposes heightened obligations (including verifiable parental/guardian consent and a prohibition on tracking or targeted advertising to children) for processing the personal data of individuals under 18, or of persons with disabilities who have a lawful guardian. As noted in Section 14, the Platform is intended for working professionals and is not directed at children; if we become aware such data has been collected without appropriate consent, we will delete it.
17.5 Significant Data Fiduciary obligations. If WeAce is notified by the Central Government as a "Significant Data Fiduciary," we will comply with additional obligations, which may include appointing a Data Protection Officer based in India, appointing an independent data auditor, and conducting periodic Data Protection Impact Assessments.
17.6 Data Principal rights. Subject to the DPDPA, you have the right to: obtain a summary of personal data being processed and the processing activities undertaken; request correction, completion, updating, or erasure of your personal data; nominate another individual to exercise your rights on your behalf in the event of death or incapacity; and access a readily available means of grievance redressal via our India Grievance Officer (Section 2). We will respond to grievances within the timeframe prescribed by law.
17.7 Cross-border transfers. The DPDPA permits transfer of personal data outside India except to countries specifically restricted by the Central Government. We will observe any such restrictions and any sector-specific data localisation requirements that may apply.
17.8 Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with the DPDPA and its rules.
17.9 Employer/Client relationships in India. Where an India-based Client onboards employees onto the Platform, the confidentiality protections around coaching content in Section 6.1 apply equally, and any data-sharing arrangement with the Client is governed by a DPA reflecting DPDPA requirements.
