call+91 95916 05768
location_onBengaluru HQ, India
shield DPDP Act Compliant (2023)
Data Governance & Institutional Privacy

Institutional Privacy Policy & Data Architecture Charter

Edvanta Technologies maintains zero-compromise security protocols governed by the Digital Personal Data Protection (DPDP) Act of India, alongside internationally harmonized educational data protection covenants (FERPA, COPPA, and ISO/IEC 27701).

verified_user ISO/IEC 27001:2022 Certified
lock SOC 2 Type II Attested
policy Zero Learner Monetization
Global Trust Rating star star star star star
100% In-Country

Indian institutional telemetry and student identities are strictly preserved within Tier-IV sovereign datacenters in Mumbai and Bengaluru.

admin_panel_settings
Dedicated Grievance Cell 72-Hour Statutory SLA for Data Correction Requests
Clause 1.0 Jurisdictional Mandate

1. Introduction and Scope of Policy

Edvanta Technologies Private Limited ("Edvanta," "we," "us," or "our"), incorporated under the Companies Act, 2013, with operational headquarters situated at Sigma Softtech Park, Whitefield, Bengaluru, operates institutional educational portals, bespoke enterprise Learning Management Systems (LMS), competency frameworks, assessment telemetry engines, and workforce skill certification platforms globally.

This Institutional Privacy Policy strictly outlines the mechanisms through which we capture, categorize, process, safeguard, and disclose Digital Personal Data. This charter is structured in direct conformity with the Digital Personal Data Protection Act, 2023 (DPDP Act) of the Republic of India, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and aligns with international institutional requirements including the US Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Rule (COPPA) where cross-border institutional programs are served.

gavel
Fiduciary Relationship

Under DPDP nomenclature, participating Educational Institutions, Ministries, and Enterprise Corporate Sponsors act as the Data Fiduciary, while Edvanta Technologies operates strictly as the licensed Data Processor executing authorized instructions.

Clause 2.0 Taxonomy

2. Information We Collect

To provide robust computational infrastructure, adaptive learning paths, and verified institutional grading, Edvanta collects disparate categories of telemetry delineated by stakeholder classification:

school A. Learner & Student Telemetry
  • Legal name, institutional registration number, student UID.
  • Module completion rates, time-spent telemetry per learning node.
  • Adaptive quiz performance vectors and proctored examination logs.
  • Micro-credential ledger entries and mastery badges.
account_balance B. Institutional & Entity Records
  • Accreditation documentation, university portal API credentials.
  • Organizational hierarchy, cohort designations, and department matrices.
  • Faculty and administrator roster authorization directories.
  • Contractual billing metadata and sovereign grant references.
co_present C. Educator & Proctor Profiles
  • Instructor identity profiles, departmental designations, work emails.
  • Curriculum versioning records and grading rubric configurations.
  • Proctor review notes, digital signature tokens for certificate issuance.
terminal D. Device & System Analytics
  • IP address, browser user-agent hash, screen resolution vectors.
  • WebRTC session metadata (only during authorized remote examination).
  • Network throughput diagnostics for edge video rendering optimization.
Payment Data Handling: Card numbers, CVV, and net-banking credentials are never ingested into Edvanta servers. Transactions execute exclusively through RBI-regulated PCI-DSS Level 1 payment aggregators.
Clause 3.0 High-Protection Threshold

3. Student Data Protection & Digital Learning Privacy

Edvanta acknowledges that educational data represents vulnerable personal vectors requiring distinct legal guardianship. We apply strict institutional firewalls separating administrative processing from academic telemetry:

block Zero Data Monetization

Under no circumstances is student personal data, performance metrics, or behavioral profiles sold, rented, leased, or licensed to commercial advertising networks.

child_care Minors Safeguard (Under 18)

Pursuant to Section 9 of the DPDP Act, processing data of minors requires verifiable parental consent orchestrated through accredited institutional school boards.

fingerprint Behavioral Tracking Ban

We strictly prohibit automated profiling or behavioral monitoring targeting children for commercial nudge mechanics or algorithmic advertising.

Equivalence Commitment: For international higher education programs, Edvanta aligns its platform controls to FERPA (34 CFR Part 99) compliance protocols, functioning as an institutional school official with recognized legitimate educational interests.

Clause 4.0 Authorized Processing

4. Use of Information

Data acquired by Edvanta is strictly processed for legitimate, contractual educational objectives stipulated by client institutional agreements:

cast_for_education
Pedagogical Execution & Delivery

Provisioning digital courseware, rendering virtual lab sessions, processing interactive code sandboxes, and synchronizing scorm-compliant packages.

analytics
Competency Modeling & Skill Mapping

Calibrating adaptive learning pathways to reinforce student knowledge gaps through non-intrusive algorithmic item response theory (IRT).

verified
Digital Credentialing & Verification

Cryptographic timestamping and immutable issuance of university degrees, micro-certifications, and Skill India / NSDC badge synchronizations.

health_and_safety
System Reliability & Threat Mitigation

Detecting distributed denial of service (DDoS) anomalies, unauthorized proctor evasion, session token hijacking, and identity theft.

Clause 5.0 Cryptographic Defense

5. Data Storage, Encryption & Security Standards

Edvanta exercises multi-tier physical, logical, and cryptographic architecture to guard institutional repositories against exfiltration, unauthorized modification, or loss.

Edvanta Multi-Layer Shield Architecture Client Edge TLS 1.3 / mTLS Encrypted Ingestion AES-256 GCM Core Zero Knowledge Key Vault Sovereign Vault MeitY Empaneled Cloud Data at rest is partitioned via dynamic tenant segregation keys with hourly automated snapshots retained across geographically isolated Indian disaster recovery centers.
check_circle
ISO/IEC 27001 & 27701 Audited by CERT-IN certified cybersecurity auditors annually.
check_circle
Data Localization Primary processing remains within Indian sovereign boundaries (Mumbai/Bengaluru).
Clause 6.0 Auditing Governance

6. Third-Party Disclosures & Government Auditing

Edvanta operates on a strictly audited, need-to-know disclosure perimeter. We do NOT share data with marketing affiliates or unauthorized vendors. Disclosures occur solely in the following bounded contexts:

policy

Institutional Customers: Verified academic leaders and designated university personnel receive aggregate and individual course records for matriculated students within their exclusive administrative domain.

account_balance

Statutory & Regulatory Compulsion: Disclosure upon receiving valid judicial warrants or notifications from authorized enforcement agencies under the Code of Criminal Procedure, 1973, or the DPDP Data Protection Board.

verified_user

Empaneled Sub-Processors: Tier-1 computational cloud partners (AWS India, Azure Central India) bound by Data Processing Addendums (DPAs) matching or exceeding our internal privacy standards.

Clause 7.0 Technical Identifiers

7. Cookies and Tracking Technologies

Our web properties employ purposeful, non-invasive cookies necessary for platform operational health:

Cookie Category Function Lifespan Consent Mandate
Strictly Essential Maintains active authenticated JWT sessions, CSRF token security. Session / 24 Hours Mandatory
Learning Progress Caches offline module position, video playback timestamps. 30 Days Opt-out via Portal
System Telemetry De-identified platform performance metrics, memory leak analytics. 90 Days Opt-in Consent

Third-party cross-site advertising cookies are programmatically blocked across all Edvanta enterprise learning portals.

Clause 8.0 Learner Empowerment

8. User Rights and Data Rectification

In accordance with Chapter III of the DPDP Act, 2023, data principals (learners, educators, and enterprise participants) hold enforceable statutory entitlements:

visibility Right to Access Summary

Request an easily readable summary of personal data held, processing activities completed, and identities of institutional partners with access.

edit_note Right to Correction & Erasure

Update inaccurate academic identifiers or petition for data erasure where institutional program completion criteria have lapsed.

contact_support Right of Grievance Redressal

Expedited review by our Data Protection Officer prior to escalation with the Data Protection Board of India.

person_add_disabled Right to Nominate

Designate an authorized representative to exercise statutory data rights in case of death or medical incapacity.

Clause 9.0 Lifecycle Management

9. Data Retention and Deletion Protocols

Personal data is retained only for the duration required to achieve contractual educational objectives, fulfill state accreditation directives, or address legal claims:

Standard Purging Schedule NIST 800-88 Compliant Sanitization
Active Enrollment: Full records accessible by registered institution.
180-Day Grace: Quarantined for student transcript verification.
Irreversible Zeroing: Cryptographic shredding of personal identifiers.
Clause 10.0 Statutory Redressal

10. Contacting Our Data Protection Officer

In compliance with DPDP statutory provisions, Edvanta has established a permanent Data Protection Office. All communications regarding policy interpretation, data rectification petitions, or incident reports should be directed to:

badge
S. Ramakrishnan Chief Information Security Officer Designated Data Protection Officer
mail
Direct Official Email info@edvantatechnologies.com
call
Regulatory Telephone Inquiry +91 95916 05768 (Mon-Fri, 09:30 - 18:00 IST)
location_on
Statutory Secretariat Address Edvanta Technologies Pvt. Ltd., Sigma Softtech Park, Beta Block, Whitefield Main Road, Varthur Kodi, Bengaluru, Karnataka 560066, India
pin_drop Bengaluru Operations & Sovereign Vault Centre
security_update_good Fast-Track Grievance Portal

Submit an Institutional Privacy Request

Are you an authorized Institutional Administrator, Student Principal, or Legal Guardian? Submit your formal request through our expedited verification pipeline.

schedule Statutory 72-Hour Response Window