═══════════════════════════════════════════════════

MockPe

PRIVACY POLICY

(गोपनीयता नीति)

═══════════════════════════════════════════════════

Business Name: MockPe

Business Type: Sole Proprietorship (MSME Registered)

MSME Number: AHTYU1873553756468200

State: Uttar Pradesh, India

Registered Address:
0987/98 hthara hgae, htgfytj, ythgg fd
Uttar Pradesh, India

Last Updated: [Insert Date]

Effective Date: [Insert Date]

Version: 1.0

📑 TABLE OF CONTENTS - Quick Navigation

TABLE OF CONTENTS

[Insert page numbers after finalizing document]

Section Title Page
1Introduction
2Data Controller Information
3Data We Collect
4How We Use Your Data
5Legal Basis for Processing
6Data Sharing and Disclosure
7Data Storage and Retention
8Data Security
9Your Rights as Data Principal
10Cookies and Tracking Technologies
11Children's Privacy
12Third-Party Services
13International Data Transfer
14Data Breach Notification
15Changes to Privacy Policy
16Grievance Redressal
17Contact Information
18Legal Framework
19Consent

1. INTRODUCTION

(परिचय)

1.1 Our Commitment to Privacy

MockPe ("we", "us", "our", "Company", "हम") is deeply committed to protecting the privacy and security of your personal data. This Privacy Policy explains our practices regarding the collection, use, storage, sharing, and protection of your personal information.

We believe in:

  • Transparency in data practices
  • User control over personal data
  • Strong security measures
  • Compliance with Indian data protection laws
  • Respect for privacy rights

1.2 Scope of This Policy

This Privacy Policy applies to:

✅ Covered ❌ Not Covered
MockPe website Third-party websites we link to
All registered users (Students, Teachers, Institutes) Third-party services' data practices
All features and services we provide Data practices of our business partners
All data collection methods we use Offline interactions not related to our service

1.3 Agreement to Privacy Policy

By using the MockPe platform, you:

  • Acknowledge that you have read this Privacy Policy
  • Understand how we collect, use, and protect your data
  • Consent to our data processing practices as described
  • Agree to the terms of this Privacy Policy

⚠️ Important: If you do not agree with this Privacy Policy, please do not use our platform.

1.4 Integration with Terms and Conditions

This Privacy Policy is an integral part of our Terms and Conditions. Both documents should be read together. In case of any conflict between the two, the Privacy Policy shall prevail on privacy-related matters.

1.5 Language

This Privacy Policy is provided in English and Hindi. In case of any discrepancy, the English version shall prevail.

2. DATA CONTROLLER INFORMATION

(डेटा नियंत्रक जानकारी)

2.1 Data Fiduciary Details

Under the Digital Personal Data Protection Act, 2023, MockPe acts as a Data Fiduciary (controller of personal data).

DATA FIDUCIARY / CONTROLLER
(डेटा न्यासी / नियंत्रक)

Legal Name: MockPe
Business Structure: Sole Proprietorship
Registration: MSME Registered (Micro, Small & Medium Enterprises)
MSME/Udyam Number: AHTYU1873553756468200
Proprietor: [YOUR FULL NAME] (Data Protection Officer)
State: Uttar Pradesh, India
Registered Address: 0987/98 hthara hgae, htgfytj, ythgg fd, Uttar Pradesh, India
Contact: [YOUR WHATSAPP NUMBER]
Email: [YOUR EMAIL - if available]

2.2 Responsibilities as Data Fiduciary

As a Data Fiduciary, we are responsible for:

  • Determining the purpose and means of processing personal data
  • Ensuring lawful, fair, and transparent data processing
  • Implementing appropriate security measures
  • Respecting data principal rights
  • Complying with DPDP Act, 2023 and other applicable laws
  • Notifying data breaches
  • Maintaining records of data processing activities

2.3 Data Protection Officer

Designated Officer:

Role Details
Name [YOUR FULL NAME]
Designation Proprietor & Data Protection Officer
Responsibilities Overall data protection compliance, breach management, rights requests
Contact [WHATSAPP NUMBER]

3. DATA WE COLLECT

(हम क्या डेटा एकत्र करते हैं)

3.1 Categories of Personal Data

We collect the following categories of personal data:

3.1.1 Identity Data

Data Element Mandatory/Optional Purpose
Candidate Full Name Mandatory Account identification, personalization
Father's Name Mandatory Additional identification
Mother's Name Mandatory Additional identification

Legal Basis: Contract performance, legitimate interest

3.1.2 Contact Data

Data Element Mandatory/Optional Purpose
Mobile Number 1 Mandatory Primary communication, account recovery, support
Mobile Number 2 Mandatory Alternative contact, security
Email Address Optional Additional communication (if provided)

Legal Basis: Contract performance, consent

3.1.3 Account Data

Data Element Mandatory/Optional Purpose
User ID Auto-generated Account access
Password Set by user Security, authentication
Date of Joining Auto-captured Subscription tracking, analytics
Account Type Assigned Service differentiation (Student/Teacher/Institute)
Subscription Status System-maintained Access control
Subscription Expiry Auto-calculated Renewal reminders

Legal Basis: Contract performance

Note: Passwords are stored in hashed and encrypted form, NOT in plain text. We cannot retrieve your original password.

3.1.4 Usage Data

Data Element How Collected Purpose
Exams Attempted Auto-tracked Performance analytics, service improvement
Exam Scores Auto-calculated Performance tracking
Self-Created Exams User-generated Service provision
Shared Exam Files User action Feature functionality
Time Spent Session tracking User engagement analytics
Features Used Click tracking Feature optimization
Login History Access logs Security monitoring

Legal Basis: Legitimate interest, service improvement

3.1.5 Technical Data

Data Element Auto-Collected Purpose
IP Address Yes Security, fraud prevention, location approximation
Browser Type Yes Technical compatibility
Device Type Yes Responsive design, support
Operating System Yes Compatibility testing
Screen Resolution Yes UI/UX optimization
Referrer URL Yes Marketing analytics
Session Duration Yes Engagement metrics
Error Logs Yes Technical troubleshooting

Legal Basis: Legitimate interest, technical necessity

3.2 What We DO NOT Collect

❌ WE DO NOT COLLECT THE FOLLOWING:

Sensitive Personal Data:

  • Financial information (bank account, card details, UPI ID)
  • Aadhaar number
  • PAN card number
  • Passport details
  • Driving license
  • Voter ID
  • Health or medical information
  • Biometric data (fingerprints, facial recognition, iris scans)
  • Genetic data
  • Sexual orientation
  • Religious beliefs or affiliations
  • Political opinions or affiliations
  • Caste or tribe information
  • Trade union membership
  • Criminal records or allegations

Other Data:

  • Physical home address (unless you provide voluntarily)
  • Educational certificates or mark sheets
  • Income information
  • Family member details (beyond father's/mother's names)
  • Social media credentials
  • Location tracking (GPS coordinates)
  • Call logs or SMS content
  • Photos or videos (unless you upload for profile)

हम संवेदनशील व्यक्तिगत डेटा एकत्र नहीं करते।

Legal Framework:

SPDI Rules, 2011 - Rule 3: Defines Sensitive Personal Data or Information (SPDI)

We intentionally avoid collecting SPDI to minimize privacy risks.

3.3 How We Collect Data

Collection Methods:

Method Data Collected When
Direct Input Name, parent names, mobile numbers Account creation by us or authorized user
User Actions Exam attempts, content creation During platform use
Automated Tools IP address, device info, cookies When you access platform
Communication Support queries, feedback When you contact us

3.4 Data from Minors (Below 18)

Special Protocol for Children's Data:

  • We collect data of minors ONLY with verifiable parental consent
  • Parent/Guardian provides consent during account creation
  • Same data elements as adults (no additional data)
  • Parent/Guardian can access, modify, or delete child's data anytime
  • We do NOT engage in behavioral tracking of minors
  • We do NOT serve targeted advertisements to minors

Compliance: DPDP Act, 2023 - Section 9

4. HOW WE USE YOUR DATA

(हम आपके डेटा का उपयोग कैसे करते हैं)

4.1 Primary Purposes

We use your personal data for the following purposes:

4.1.1 Service Provision

Purpose Data Used Frequency
Account Creation & Management Name, parent names, mobile, DOJ One-time + updates
Authentication & Login User ID, password Every login
Dashboard Access Account data Continuous during session
Exam Delivery Account data, preferences On-demand
Content Storage User-created exams, preferences Continuous
Feature Access Control Account type, subscription status Real-time
Subscription Management Subscription dates, payment status Daily checks

Legal Basis: Contract performance (Section 7, DPDP Act, 2023)

4.1.2 Communication

Purpose Data Used Channel Opt-Out
Service Updates Mobile number WhatsApp No (essential)
Technical Support Mobile, name, issue details WhatsApp No (on-demand)
Account Notifications Mobile number WhatsApp No (essential)
Renewal Reminders Mobile, subscription data WhatsApp No (essential)
Promotional Messages Mobile number WhatsApp YES (send "STOP")
Feature Announcements Mobile number WhatsApp YES
Educational Tips Mobile number WhatsApp YES

Legal Basis:

  • Essential communications: Contract performance
  • Promotional: Consent (Section 6, DPDP Act, 2023)

4.1.3 Service Improvement

Purpose Data Used How
Performance Analytics Usage data, exam scores Aggregate analysis
Feature Optimization Feature usage patterns Statistical analysis
User Experience Enhancement Session data, click patterns Behavior analysis
Error Detection & Fixing Error logs, technical data Troubleshooting
Platform Stability Access logs, load metrics Monitoring

Legal Basis: Legitimate interest

Privacy Protection: Data is aggregated and anonymized for analytics. Individual users are not identified.

4.1.4 Security & Fraud Prevention

Purpose Data Used Method
Unauthorized Access Prevention Login history, IP addresses Pattern detection
Account Security Login attempts, device data Anomaly detection
Fraud Detection Payment data, usage patterns Risk scoring
Abuse Prevention Account activity, content created Monitoring
System Integrity Access logs Intrusion detection

Legal Basis: Legitimate interest, legal obligation

4.1.5 Legal Compliance

Purpose Data Used When
Tax Records Payment records As per Income Tax Act
Legal Proceedings Relevant user data When required by court
Regulatory Reporting As mandated When required by law
Government Requests As specified in order When lawful order received

Legal Basis: Legal obligation (Section 7, DPDP Act, 2023)

4.2 Marketing and Promotional Use

With Your Consent:

We may send you:

  • New feature announcements
  • Special discounts or offers
  • Referral program invitations
  • Educational content and tips
  • Platform updates and improvements

Your Control:

  • You can OPT-OUT anytime by sending "STOP" to our WhatsApp number
  • Opt-out processed within 48 hours
  • You will still receive essential service communications

Compliance:

  • TRAI Regulations on Unsolicited Commercial Communication
  • DPDP Act, 2023 - Section 6 (Consent requirements)
  • Respect for DND (Do Not Disturb) registry

4.3 Purposes We DO NOT Use Data For

❌ WE DO NOT USE YOUR DATA FOR:

  • Selling or renting to third parties for their marketing
  • Sharing with data brokers or aggregators
  • Targeted advertising on external platforms
  • Creating detailed personal profiles for advertising
  • Tracking you across other websites or apps
  • Political campaigns or lobbying
  • Credit scoring or financial profiling
  • Insurance underwriting
  • Employment screening
  • Any purpose not disclosed in this policy

हम आपके डेटा को तीसरे पक्ष को बेचते या साझा नहीं करते।

5. LEGAL BASIS FOR PROCESSING

(प्रसंस्करण का कानूनी आधार)

5.1 Lawful Grounds Under DPDP Act, 2023

We process personal data only on lawful grounds as specified in the Digital Personal Data Protection Act, 2023:

5.1.1 Consent (Section 6)

When We Rely on Consent:

Processing Activity Type of Consent
Promotional WhatsApp messages Free, specific, informed, unambiguous
Optional data collection (e.g., email) Explicit consent
Cookies (non-essential) Implied consent (can be withdrawn)

Your Rights:

  • Consent can be withdrawn at any time
  • Withdrawal does not affect lawfulness of prior processing
  • Withdrawal may affect service delivery (for essential processing)

How to Withdraw:

  • Send "STOP" for promotional messages
  • Contact Grievance Officer for other consents

5.1.2 Contract Performance (Section 7)

When We Rely on Contract:

Processing Activity Necessity
Account creation Cannot provide service without this
Login authentication Essential for access
Dashboard provision Core service delivery
Exam delivery Primary service
Subscription management Contractual obligation

This processing is necessary to perform our contract with you (Terms and Conditions).

5.1.3 Legal Obligation (Section 7)

When We Rely on Legal Obligation:

Processing Activity Legal Requirement
Tax record keeping Income Tax Act, 1961 (8 years retention)
Compliance with court orders CrPC, CPC
Government information requests IT Act, 2000 (Section 69)
Data breach reporting DPDP Act (to Data Protection Board)
CERT-In reporting CERT-In Directions, 2022 (6 hours)

5.1.4 Legitimate Interest

When We Rely on Legitimate Interest:

Our Interest Processing Your Rights
Platform security IP logging, access monitoring Object to processing
Service improvement Analytics, performance metrics Object to processing
Fraud prevention Pattern analysis Object to processing
Business operations Backup, disaster recovery Object to processing

Balancing Test: We ensure our legitimate interests do not override your fundamental rights and freedoms.

5.2 Special Provisions for Children

Under DPDP Act, 2023 - Section 9:

For users below 18 years:

  • Verifiable parental consent is mandatory
  • Parent/Guardian acts as data principal
  • Parent can exercise all rights on behalf of child
  • No behavioral tracking or profiling of children
  • No targeted advertising to children

Our Implementation:

  • Account in parent's name (parent provides consent)
  • Parent's contact details registered
  • Parent can request deletion anytime

6. DATA SHARING AND DISCLOSURE

(डेटा साझाकरण एवं प्रकटीकरण)

6.1 Our General Policy

OUR DATA SHARING COMMITMENT

(हमारी डेटा साझाकरण प्रतिबद्धता)

WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL DATA

हम आपका व्यक्तिगत डेटा नहीं बेचते, किराये पर नहीं देते, या व्यापार नहीं करते

Your data is yours. We respect your privacy.

6.2 When We DO NOT Share

We do NOT share your data with:

  • Third-party advertisers
  • Data brokers or marketing companies
  • Social media platforms (for advertising)
  • Credit bureaus
  • Insurance companies
  • Recruitment agencies
  • Any entity for commercial exploitation
  • International entities (data stays in India)

6.3 When We MAY Share

We may share your data ONLY in the following limited circumstances:

6.3.1 Service Providers

Who: Technical service providers essential for platform operation

Service Provider Type Data Shared Purpose Safeguards
VPS Hosting Provider All platform data Infrastructure hosting Data Processing Agreement, India-based servers
WhatsApp (Meta) Mobile numbers, messages Communication Meta's privacy policy applies
Payment Gateway Payment transaction data Payment processing PCI-DSS compliant, minimal data

Protections:

  • Contractual obligations to protect data
  • Process data only as per our instructions
  • Cannot use data for their own purposes
  • Data Processing Agreements in place

6.3.2 Legal Obligations

Who: Law enforcement, courts, government authorities

Authority When What Data Legal Basis
Police/Law Enforcement FIR, investigation As requested in lawful order CrPC Section 91, IT Act Section 69
Courts Court order, summons As specified in order CPC, court orders
Tax Authorities Tax audit, inquiry Payment records, business data Income Tax Act
CERT-In Cybersecurity incident Incident-related data CERT-In Directions, 2022
Data Protection Board Complaint investigation Relevant data DPDP Act, 2023 Section 28

Process:

  1. Verify authenticity of request
  2. Assess legal validity
  3. Share minimum necessary data
  4. Document the disclosure
  5. Notify user (if legally permissible)

6.3.3 Business Transfers

In case of:

  • Merger with another company
  • Acquisition by another entity
  • Sale of business assets
  • Bankruptcy or insolvency

Then:

  • Your data may be transferred to successor entity
  • You will be notified of such transfer
  • Successor must honor this Privacy Policy
  • You have right to delete data before transfer

6.3.4 With Your Consent

If we need to share data for any purpose not covered above:

  • We will ask for your explicit consent
  • We will explain the purpose and recipient
  • You can refuse without consequences
  • You can withdraw consent later

6.4 Data NOT Shared

Internal Use Only:

The following data is NEVER shared externally:

  • Passwords (even hashed versions)
  • Individual performance/scores
  • Private exam content you created
  • Support conversation details
  • Payment method details

6.5 Aggregate & Anonymized Data

We may share:

  • Aggregate statistics (e.g., "10,000 exams attempted this month")
  • Anonymized data for research
  • Industry benchmarks

Protection: Data is aggregated/anonymized so individual users cannot be identified.

Legal Basis: DPDP Act, 2023 - Section 2(j) excludes anonymized data from definition of "personal data"

7. DATA STORAGE AND RETENTION

(डेटा संग्रहण एवं प्रतिधारण)

7.1 Storage Location

All your data is stored in INDIA:

DATA STORAGE LOCATION
(डेटा संग्रहण स्थान)

Primary Server: India-based VPS Server
Backup Server: India-based (same or different provider)
Country: INDIA ONLY
International Transfer: NO
Data Sovereignty: Indian laws apply

Compliance: DPDP Act, 2023 - Section 16 (Cross-border data transfer restrictions)

7.2 Storage Infrastructure

Component Details
Primary Storage VPS (Virtual Private Server) in India
Database Encrypted database on VPS
Backup Storage Separate backup location in India
Backup Frequency Daily automated backups
Backup Retention 30 days rolling backups
Disaster Recovery Backup restoration capability

7.3 Data Retention Periods

We retain your data for the following periods:

7.3.1 Active Account Data

Data Category Retention Period Reason
Account Information While subscription active + 30 days grace Service provision
Login Credentials While account active Authentication
Usage Data While account active Service delivery, analytics
Support Communications 2 years from last communication Record keeping, quality

7.3.2 Post-Termination Data

Data Category Retention After Termination Reason
Personal Data 30 days grace period, then deleted User may reactivate
Payment Records 8 years Tax compliance (Income Tax Act)
Legal/Compliance Data As required by law Legal obligation
Aggregated Analytics Indefinitely (anonymized) Not personal data

7.3.3 Specific Data Types

Data Type Retention Deletion
Session Cookies Session-based Auto-expire on logout/browser close
Log Files 90 days Auto-deleted after 90 days
Support Tickets 2 years Deleted after 2 years
Marketing Consent Until withdrawn Immediate upon opt-out
Backup Data 30 days rolling Oldest backup auto-deleted

7.4 Retention Timeline Flowchart

┌─────────────────────────────────────────────────────────┐
│               DATA RETENTION TIMELINE                   │
├─────────────────────────────────────────────────────────┤
│                                                         │
│  ACTIVE SUBSCRIPTION                                    │
│  └─► All data retained and actively used               │
│                                                         │
│  SUBSCRIPTION EXPIRES                                   │
│  └─► Day 0: Subscription ends                          │
│      Day 1-30: Grace period (data retained)            │
│      Day 31: Deletion process initiated                │
│      Day 45: All personal data permanently deleted     │
│                                                         │
│  EXCEPTIONS (Retained Longer):                          │
│  └─► Payment records: 8 years                          │
│  └─► Legal hold: Until resolved                        │
│  └─► Fraud investigation: Until concluded              │
│                                                         │
└─────────────────────────────────────────────────────────┘

7.5 Data Deletion

Secure Deletion Process:

When data is deleted:

  • Removed from production databases
  • Removed from backup systems (within backup cycle)
  • Overwritten to prevent recovery
  • Deletion logged for audit trail

Data Residuals:

  • Some metadata may remain in logs (anonymized)
  • Aggregate statistics remain (no personal identifiers)

7.6 Legal Retention Requirements

We are legally required to retain certain data:

Law Data Period
Income Tax Act, 1961 Financial records 8 years
Companies Act, 2013 Business records 8 years (if applicable)
Limitation Act, 1963 Contract-related 3 years (for suits)
Court Orders As specified As ordered

These override our standard deletion timelines.

8. DATA SECURITY

(डेटा सुरक्षा)

8.1 Our Security Commitment

🔒 SECURITY MEASURES

(सुरक्षा उपाय)

We implement industry-standard technical and organizational measures to protect your data from:

• Unauthorized access
• Accidental loss
• Unlawful processing
• Destruction
• Disclosure
• Alteration
• Theft
• Damage

हम आपके डेटा को अनधिकृत पहुंच, हानि, और चोरी से बचाने के लिए उद्योग-मानक उपाय लागू करते हैं।

8.2 Technical Security Measures

8.2.1 Encryption

Layer Encryption Method Purpose
Data in Transit SSL/TLS (HTTPS) Protect data during transmission
Data at Rest Database encryption Protect stored data
Password Storage Bcrypt/Argon2 hashing Cannot be reversed
Backup Data Encrypted backups Protect backup data

Implementation:

  • All website communications over HTTPS
  • Minimum TLS 1.2 or higher
  • Strong encryption algorithms (AES-256)
  • Regular security certificate updates

8.2.2 Access Controls

Control Type Implementation
Authentication User ID + password (hashed)
Session Management Secure session tokens, auto-logout
Role-Based Access Different access levels (Student/Teacher/Institute)
Internal Access Limited staff access, need-to-know basis
Admin Access Multi-factor authentication, audit logs

8.2.3 Network Security

Measure Details
Firewall Server-level firewall enabled
DDoS Protection Basic protection through VPS provider
IP Filtering Suspicious IP blocking
Intrusion Detection Monitoring for unauthorized access attempts

8.2.4 Application Security

Measure Implementation
Input Validation Prevent SQL injection, XSS attacks
Output Encoding Prevent cross-site scripting
CSRF Protection Anti-CSRF tokens
Security Headers HTTP security headers implemented
Regular Updates Software patches and updates

8.3 Organizational Security Measures

Measure Details
Data Access Policy Written policy on who can access what data
Employee Training (When applicable) Staff trained on data protection
Confidentiality Staff bound by confidentiality agreements
Incident Response Data breach response plan in place
Regular Audits Periodic security audits
Vendor Management Third-party vendors vetted for security

8.4 Your Security Responsibilities

You play a crucial role in security:

✅ DO's:

  • Choose a strong, unique password
  • Keep your password confidential
  • Log out from shared/public devices
  • Report suspicious activity immediately
  • Keep your registered mobile number secure
  • Enable screen lock on your device
  • Use updated browser and operating system

❌ DON'Ts:

  • Don't share your login credentials
  • Don't use the same password on multiple sites
  • Don't log in from untrusted devices
  • Don't click on suspicious links
  • Don't share OTPs or verification codes
  • Don't ignore security warnings

8.5 Security Limitations & Disclaimer

⚠️ IMPORTANT SECURITY DISCLOSURE:

NO INTERNET-BASED SERVICE CAN GUARANTEE 100% SECURITY

कोई भी इंटरनेट-आधारित सेवा 100% सुरक्षा की गारंटी नहीं दे सकती

While we implement robust security measures, we CANNOT guarantee absolute security because:

  • Cyber threats constantly evolve
  • No system is completely invulnerable
  • User actions can compromise security
  • Third-party vulnerabilities may exist
  • Sophisticated attacks may succeed

YOU USE THE PLATFORM AT YOUR OWN RISK

We are NOT liable for:

  • Unauthorized access due to compromised passwords
  • User device security failures
  • Third-party service breaches
  • Attacks beyond our reasonable control
  • User's own security negligence

Legal Basis: IT Act, 2000 - Section 43A (reasonable security practices)

9. YOUR RIGHTS AS DATA PRINCIPAL

(डेटा प्रधान के रूप में आपके अधिकार)

9.1 Overview of Rights

Under the Digital Personal Data Protection Act, 2023, you have the following rights regarding your personal data:

YOUR DATA PROTECTION RIGHTS
(आपके डेटा सुरक्षा अधिकार)

  1. Right to Access (पहुँच का अधिकार)
  2. Right to Correction (सुधार का अधिकार)
  3. Right to Erasure (मिटाने का अधिकार)
  4. Right to Data Portability (डेटा पोर्टेबिलिटी का अधिकार)
  5. Right to Grievance (शिकायत का अधिकार)
  6. Right to Nominate (नामांकन का अधिकार)

9.2 Right to Access (Section 11)

What: Know what personal data we hold about you

How to Exercise:

Contact: [WHATSAPP NUMBER]
Request: "Data Access Request"
Provide: Your registered name and mobile number

What You Will Receive:

  • Summary of personal data we process
  • Purpose of processing
  • Recipients of data (if shared)
  • Retention period
  • Copy of your data (in readable format)

Timeline: Within 30 days of request
Cost: Free (for first request); nominal fee for subsequent requests

9.3 Right to Correction (Section 12)

What: Correct inaccurate or incomplete personal data

Examples:

  • Name spelled incorrectly
  • Wrong mobile number
  • Outdated parent names

How to Exercise:

Contact: [WHATSAPP NUMBER]
Request: "Data Correction Request"
Specify: What data needs correction
Provide: Correct information

Timeline: Within 30 days
Verification: We may verify your identity before making changes

9.4 Right to Erasure (Section 12)

What: Request deletion of your personal data

When You Can Request:

  • Purpose of processing is fulfilled
  • You withdraw consent (where processing based on consent)
  • Data no longer necessary
  • You terminate subscription

How to Exercise:

Contact: [WHATSAPP NUMBER]
Request: "Data Deletion Request"
Confirm: You understand account will be deactivated

Timeline: Within 30 days
Exceptions: We may retain data if legally required (e.g., tax records)

Post-Deletion:

  • Account deactivated
  • Personal data deleted
  • Some anonymized data may remain

9.5 Right to Data Portability

What: Receive your data in a structured, commonly used format

How to Exercise:

Contact: [WHATSAPP NUMBER]
Request: "Data Portability Request"

What You Will Receive:

  • PDF/Excel file with your data
  • Includes: Account info, exam history, scores

Timeline: Within 30 days
Format: PDF or Excel (machine-readable)

9.6 Right to Grievance Redressal (Section 13)

What: File complaints about data protection violations

When to Use:

  • We violated your data rights
  • Data processed unlawfully
  • Security breach affecting you
  • Unauthorized data sharing
  • Any privacy concern

How to Exercise:

Contact: Grievance Officer
WhatsApp: [WHATSAPP NUMBER]
Detail: Describe the violation
Evidence: Screenshots, documentation (if any)

Timeline:

  • Acknowledgment: 24 hours
  • Resolution: 15 days

Escalation: If not satisfied → Data Protection Board (when operational)

9.7 Right to Nominate (Death/Incapacity)

What: Designate someone to exercise your rights if you become deceased or incapacitated

How to Exercise:

Send written request with:

  • Your details
  • Nominee's name and contact
  • Relationship with nominee
  • Signature

Nominee Can:

  • Request data deletion
  • Access your data
  • Exercise your rights

9.8 Right to Withdraw Consent

What: Withdraw previously given consent

When Applicable:

  • Promotional messages
  • Optional data collection
  • Non-essential processing

How to Exercise:

For Marketing: Send "STOP" to WhatsApp
For Other: Contact Grievance Officer

Effect:

  • Processing stops immediately
  • Does not affect past processing
  • May affect service (if consent was for essential processing)

9.9 How to Exercise Rights

General Process:

Step 1: IDENTIFY THE RIGHT you want to exercise

Step 2: CONTACT US
        WhatsApp: [NUMBER]
        Email: [EMAIL if any]

Step 3: PROVIDE DETAILS
        - Your registered name
        - Mobile number
        - Specific request
        - Reason (optional but helpful)

Step 4: VERIFICATION
        We verify your identity using registered mobile

Step 5: PROCESSING
        We process your request within timelines

Step 6: RESPONSE
        You receive confirmation and action taken

9.10 Limitations on Rights

Your rights may be restricted if:

  • Legal obligation requires us to retain data
  • Ongoing legal proceedings involving your data
  • Fraud investigation in progress
  • Request is manifestly unfounded or excessive
  • Exercise of right would harm rights of others

We will inform you if any limitation applies.

9.11 No Fee for Reasonable Requests

Free of Charge:

  • First data access request
  • Correction requests
  • Erasure requests
  • Reasonable number of requests

Nominal Fee May Apply:

  • Excessive requests
  • Repeated requests for same information
  • Manifestly unfounded requests

Compliance: DPDP Act, 2023 - Sections 11-13

10. COOKIES AND TRACKING TECHNOLOGIES

(कुकीज़ और ट्रैकिंग प्रौद्योगिकियां)

10.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience.

Types We Use:

Cookie Type Purpose Duration Essential
Session Cookies Maintain login session Until logout/browser close ✅ Yes
Preference Cookies Remember your settings 1 year ❌ No
Security Cookies Prevent unauthorized access Session ✅ Yes

10.2 Cookies We Use

10.2.1 Essential Cookies

These are necessary for the platform to function:

Cookie Name Purpose Expiry
session_id Maintain login session Session
auth_token Authentication Session
csrf_token Security (prevent CSRF attacks) Session

You cannot disable these without affecting functionality.

10.2.2 Preference Cookies

Cookie Name Purpose Expiry
user_pref Remember your dashboard preferences 1 year
lang_pref Language preference (Hindi/English) 1 year

You can disable these; some features may not work optimally.

10.3 What We DO NOT Use

❌ WE DO NOT USE:

  • Third-party advertising cookies
  • Social media tracking pixels (Facebook, Google, etc.)
  • Cross-site tracking cookies
  • Analytics cookies from external providers (Google Analytics, etc.)
  • Behavioral profiling cookies
  • Retargeting/remarketing cookies

हम तृतीय-पक्ष विज्ञापन कुकीज़ का उपयोग नहीं करते।

10.4 Managing Cookies

How to Control Cookies:

Browser Settings:

Google Chrome:

  1. Settings → Privacy and Security → Cookies and other site data
  2. Choose: Block third-party cookies OR Block all cookies

Mozilla Firefox:

  1. Settings → Privacy & Security → Cookies and Site Data
  2. Choose blocking options

Safari:

  1. Preferences → Privacy
  2. Block cookies options

Microsoft Edge:

  1. Settings → Privacy, search, and services
  2. Manage cookies

Effect of Disabling:

Action Effect
Block All Cookies ❌ Cannot log in, platform won't work
Block Third-Party Cookies ✅ No impact (we don't use them)
Delete Cookies ⚠️ Will need to log in again

10.5 Other Tracking Technologies

Local Storage:

We use browser local storage to:

  • Store non-sensitive preferences
  • Improve loading performance
  • Cache non-personal data

Server Logs:

Our servers automatically log:

  • IP address
  • Browser type
  • Access time
  • Pages visited

Purpose: Security, troubleshooting, analytics

10.6 Do Not Track (DNT)

Current Position: We respect "Do Not Track" browser settings for non-essential tracking. However, essential cookies are still necessary for functionality.

11. CHILDREN'S PRIVACY

(बच्चों की गोपनीयता)

11.1 Age Policy

CHILDREN'S DATA PROTECTION
(बच्चों की डेटा सुरक्षा)

Platform Use: No age restriction (educational)
Account Creation: 18+ OR through Parent/Guardian
Data Collection: With verifiable parental consent
Advertising: NO targeting of children
Profiling: NO behavioral tracking of minors

Compliance: DPDP Act, 2023 - Section 9

11.2 Verifiable Parental Consent

For users below 18 years:

How We Obtain Consent:

  1. Account created in parent/guardian's name
  2. Parent/guardian provides their own contact details
  3. Parent accepts Terms and Privacy Policy on behalf of child
  4. Parent is the "data principal" for child's data

Verification Method:

  • Account uses parent's registered mobile number
  • Any communication goes to parent
  • Consent requests sent to parent

11.3 Parental Rights

Parents/Guardians have the right to:

  • Access child's personal data
  • Correct inaccurate data
  • Delete child's data at any time
  • Withdraw consent for data processing
  • Request what data is collected
  • Control promotional communications

How to Exercise:

Contact: [WHATSAPP NUMBER] (from registered parent mobile)
Request: Specify the right you want to exercise
Verification: Confirm you are the registered parent/guardian

11.4 Data Collected from Children

Same as adults:

  • Name, parent names, mobile numbers, date of joining
  • Usage data (exams attempted, scores)
  • Technical data (IP address, device info)

No additional sensitive data from children

11.5 How We Protect Children

Special Protections:

  • No targeted advertising to children
  • No behavioral profiling of minors
  • No selling of children's data
  • No sharing with third parties (except as per policy)
  • Parental control at all times
  • Age-appropriate content and features
  • No public forums where children can interact with strangers

11.6 Third-Party Services and Children

We do NOT integrate:

  • Social media login for children
  • Third-party advertising networks
  • Behavioral analytics specifically for children
  • Any service that tracks children across websites

11.7 Educational Purpose

Platform is designed for:

  • Educational and exam preparation purposes
  • Safe learning environment
  • No commercial exploitation of children
  • Focus on academic improvement

11.8 Parent's Responsibilities

Parents/Guardians should:

  • Supervise child's use of platform
  • Monitor child's online activities
  • Ensure child uses platform appropriately
  • Review child's exam content and scores
  • Contact us with any concerns

11.9 Reporting Concerns

If you believe:

  • We have collected child's data without parental consent
  • Child's data is being misused
  • Any child safety concern

Please contact us immediately:

Grievance Officer: [WHATSAPP NUMBER]
Subject: Child Safety Concern
Provide: Details of the concern

We will investigate promptly and take corrective action.

Legal Framework:

DPDP Act, 2023 - Section 9:

"Processing of personal data of children.

(1) The Data Fiduciary shall, before processing any personal data of a child, obtain verifiable consent of the parent of such child.

(2) The Data Fiduciary shall not undertake any processing of personal data that is likely to cause any detrimental effect on the well-being of a child.

(3) The Data Fiduciary shall not undertake tracking or behavioral monitoring of children or targeted advertising directed at children."