Privacy Policy
Last updated: [EFFECTIVE_DATE]
Who we are
[COMPANY_NAME] ("ExamPlatform", "we", "our") is an online exam and mock test platform operating in India. Registered address: [ADDRESS].
We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). This means we determine the purposes and means of processing your personal data and are responsible for protecting it.
Data we collect and why
We collect only what is necessary to provide the service. The table below explains what we collect, why, and our legal basis.
| Data type | What it is | Why we collect it | Legal basis |
|---|---|---|---|
| Account data | Name, email address, profile photo | To create and manage your account | Consent |
| Authentication | Google OAuth token, password hash | To verify your identity securely | Contract |
| Phone number | Optional, for OTP login | Login via phone (when available) | Consent |
| Exam session data | Questions answered, time spent, score, tab switches | To conduct the exam, calculate results, detect cheating | Contract + Legitimate interest |
| Usage data | Pages visited, search queries, browser/device info, IP address | To improve the platform and prevent abuse | Legitimate interest |
| Push notification token | FCM device token | To send exam result and new exam notifications | Consent (withdraw anytime) |
| Support communications | Emails you send to us | To resolve your queries | Contract |
We do NOT collect: government IDs, financial card details (Razorpay handles payment data and we never see your card number), biometric data, or health data.
Third-party services we use
We share your data with the following service providers solely to deliver the platform. All are contractually bound to handle your data securely.
| Service | Purpose | Their privacy policy |
|---|---|---|
| Google OAuth | Social login | policies.google.com/privacy |
| Amazon SES | Transactional email delivery | aws.amazon.com/privacy |
| Cloudflare R2 | File storage (avatars, thumbnails, question images) | cloudflare.com/privacypolicy |
| Firebase (Google) | Push notifications | firebase.google.com/support/privacy |
| PostHog | Usage analytics — only if you consented to analytics cookies | posthog.com/privacy |
| Sentry | Error monitoring — anonymised crash logs only, no personal data | sentry.io/privacy |
| Razorpay | Payment processing — we never see your card details (payments currently disabled) | razorpay.com/privacy |
How long we keep your data
| Data | Retention period |
|---|---|
| Account data | Until you delete your account + 30 days for deletion processing |
| Exam attempt records | 2 years from the date of the attempt |
| Payment records | 7 years (required by Indian tax law — Companies Act) |
| Support communications | 1 year |
| Analytics data (PostHog) | 90 days (anonymised after) |
| Deleted account | Personal data erased within 30 days. Anonymised exam records retained for leaderboard integrity. |
Your rights under DPDP Act 2023
As a Data Principal (user), you have the following rights:
- ✓Access: Request a copy of all personal data we hold about you.
- ✓Correction: Request correction of inaccurate or incomplete data.
- ✓Erasure: Request deletion of your account and personal data.
- ✓Withdrawal of consent: Withdraw consent for analytics cookies or push notifications at any time from your device settings or our cookie banner.
- ✓Grievance redressal: Raise a complaint with our Grievance Officer (see below).
- ✓Nominate: Nominate another individual to exercise rights on your behalf in case of death or incapacity.
To exercise any right: email [GRIEVANCE_EMAIL] with subject "Data Rights Request — [Your Name]". We will respond within 72 hours and resolve within 30 days.
Children and minors
ExamPlatform is open to users of all ages. If you are under 18, a parent or guardian must provide consent before you create an account. We do not knowingly collect data from users under 13 without verifiable parental consent.
If you believe a minor has registered without consent, email [GRIEVANCE_EMAIL] and we will delete the account promptly.
Data security
We use industry-standard security measures, including:
- HTTPS/TLS for all data in transit
- AES-256 encryption for sensitive stored data (bank account details)
- bcrypt/argon2 password hashing
- Short-lived JWTs with refresh rotation and Redis-based session invalidation on logout
In the event of a personal data breach that is likely to cause harm to you, we will notify affected users within 72 hours as required by the DPDP Act.
Grievance Officer (mandatory under IT Rules 2011)
Under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2011 and the DPDP Act 2023, we have appointed a Grievance Officer:
Name: [GRIEVANCE_OFFICER]
Email: [GRIEVANCE_EMAIL]
Address: [ADDRESS]
Availability: Monday–Friday, 10 AM – 6 PM IST
Response time: Within 24 hours. Resolution within 15 days.
You may also file a complaint with the Data Protection Board of India once it becomes operational.
To file a grievance, use our online Grievance Form.
Changes to this policy
We will notify registered users by email before making material changes to this policy, with at least 14 days' notice. Continued use of the platform after the effective date of the change constitutes your acceptance of the updated policy.
The "Last updated" date at the top of this page reflects when this policy was last revised.