Privacy Policy

Last updated: [EFFECTIVE_DATE]


Who we are

[COMPANY_NAME] ("ExamPlatform", "we", "our") is an online exam and mock test platform operating in India. Registered address: [ADDRESS].

We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). This means we determine the purposes and means of processing your personal data and are responsible for protecting it.

Data we collect and why

We collect only what is necessary to provide the service. The table below explains what we collect, why, and our legal basis.

Data typeWhat it isWhy we collect itLegal basis
Account dataName, email address, profile photoTo create and manage your accountConsent
AuthenticationGoogle OAuth token, password hashTo verify your identity securelyContract
Phone numberOptional, for OTP loginLogin via phone (when available)Consent
Exam session dataQuestions answered, time spent, score, tab switchesTo conduct the exam, calculate results, detect cheatingContract + Legitimate interest
Usage dataPages visited, search queries, browser/device info, IP addressTo improve the platform and prevent abuseLegitimate interest
Push notification tokenFCM device tokenTo send exam result and new exam notificationsConsent (withdraw anytime)
Support communicationsEmails you send to usTo resolve your queriesContract

We do NOT collect: government IDs, financial card details (Razorpay handles payment data and we never see your card number), biometric data, or health data.

Third-party services we use

We share your data with the following service providers solely to deliver the platform. All are contractually bound to handle your data securely.

ServicePurposeTheir privacy policy
Google OAuthSocial loginpolicies.google.com/privacy
Amazon SESTransactional email deliveryaws.amazon.com/privacy
Cloudflare R2File storage (avatars, thumbnails, question images)cloudflare.com/privacypolicy
Firebase (Google)Push notificationsfirebase.google.com/support/privacy
PostHogUsage analytics — only if you consented to analytics cookiesposthog.com/privacy
SentryError monitoring — anonymised crash logs only, no personal datasentry.io/privacy
RazorpayPayment processing — we never see your card details (payments currently disabled)razorpay.com/privacy

How long we keep your data

DataRetention period
Account dataUntil you delete your account + 30 days for deletion processing
Exam attempt records2 years from the date of the attempt
Payment records7 years (required by Indian tax law — Companies Act)
Support communications1 year
Analytics data (PostHog)90 days (anonymised after)
Deleted accountPersonal data erased within 30 days. Anonymised exam records retained for leaderboard integrity.

Your rights under DPDP Act 2023

As a Data Principal (user), you have the following rights:

  • Access: Request a copy of all personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your account and personal data.
  • Withdrawal of consent: Withdraw consent for analytics cookies or push notifications at any time from your device settings or our cookie banner.
  • Grievance redressal: Raise a complaint with our Grievance Officer (see below).
  • Nominate: Nominate another individual to exercise rights on your behalf in case of death or incapacity.

To exercise any right: email [GRIEVANCE_EMAIL] with subject "Data Rights Request — [Your Name]". We will respond within 72 hours and resolve within 30 days.

Children and minors

ExamPlatform is open to users of all ages. If you are under 18, a parent or guardian must provide consent before you create an account. We do not knowingly collect data from users under 13 without verifiable parental consent.

If you believe a minor has registered without consent, email [GRIEVANCE_EMAIL] and we will delete the account promptly.

Data security

We use industry-standard security measures, including:

  • HTTPS/TLS for all data in transit
  • AES-256 encryption for sensitive stored data (bank account details)
  • bcrypt/argon2 password hashing
  • Short-lived JWTs with refresh rotation and Redis-based session invalidation on logout

In the event of a personal data breach that is likely to cause harm to you, we will notify affected users within 72 hours as required by the DPDP Act.

Grievance Officer (mandatory under IT Rules 2011)

Under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2011 and the DPDP Act 2023, we have appointed a Grievance Officer:

Name: [GRIEVANCE_OFFICER]

Email: [GRIEVANCE_EMAIL]

Address: [ADDRESS]

Availability: Monday–Friday, 10 AM – 6 PM IST

Response time: Within 24 hours. Resolution within 15 days.

You may also file a complaint with the Data Protection Board of India once it becomes operational.

To file a grievance, use our online Grievance Form.

Changes to this policy

We will notify registered users by email before making material changes to this policy, with at least 14 days' notice. Continued use of the platform after the effective date of the change constitutes your acceptance of the updated policy.

The "Last updated" date at the top of this page reflects when this policy was last revised.