Institutional
Privacy Policy & Data Architecture Charter
Edvanta Technologies maintains zero-compromise security protocols governed by the
Digital Personal Data Protection (DPDP) Act of India, alongside internationally
harmonized educational data protection covenants (FERPA, COPPA, and ISO/IEC 27701).
verified_userISO/IEC 27001:2022 Certified
lockSOC 2 Type II Attested
policyZero Learner Monetization
Global Trust
Ratingstarstarstarstarstar
100% In-Country
Indian institutional
telemetry and student identities are strictly preserved within Tier-IV sovereign
datacenters in Mumbai and Bengaluru.
admin_panel_settings
Dedicated Grievance Cell72-Hour Statutory
SLA for Data Correction Requests
Clause
1.0Jurisdictional
Mandate
1. Introduction and Scope of
Policy
Edvanta Technologies Private Limited ("Edvanta," "we," "us," or "our"), incorporated
under the Companies Act, 2013, with operational headquarters situated at Sigma Softtech
Park, Whitefield, Bengaluru, operates institutional educational portals, bespoke
enterprise Learning Management Systems (LMS), competency frameworks, assessment
telemetry engines, and workforce skill certification platforms globally.
This Institutional Privacy Policy strictly outlines the mechanisms through which we
capture, categorize, process, safeguard, and disclose Digital Personal Data. This
charter is structured in direct conformity with the Digital Personal Data
Protection Act, 2023 (DPDP Act) of the Republic of India, the
Information Technology (Reasonable Security Practices and Procedures and
Sensitive Personal Data or Information) Rules, 2011, and aligns with
international institutional requirements including the US Family Educational
Rights and Privacy Act (FERPA) and the Children's Online Privacy
Protection Rule (COPPA) where cross-border institutional programs are
served.
gavel
Fiduciary
Relationship
Under DPDP
nomenclature, participating Educational Institutions, Ministries, and Enterprise
Corporate Sponsors act as the Data Fiduciary, while Edvanta
Technologies operates strictly as the licensed Data Processor executing
authorized instructions.
Clause
2.0Taxonomy
2. Information We Collect
To provide robust computational infrastructure, adaptive learning paths, and verified
institutional grading, Edvanta collects disparate categories of telemetry delineated by
stakeholder classification:
Module completion rates, time-spent telemetry per learning node.
Adaptive quiz performance vectors and proctored examination logs.
Micro-credential ledger entries and mastery badges.
account_balanceB. Institutional & Entity
Records
Accreditation documentation, university portal API credentials.
Organizational hierarchy, cohort designations, and department matrices.
Faculty and administrator roster authorization directories.
Contractual billing metadata and sovereign grant references.
co_presentC. Educator & Proctor
Profiles
Instructor identity profiles, departmental designations, work emails.
Curriculum versioning records and grading rubric configurations.
Proctor review notes, digital signature tokens for certificate issuance.
terminalD. Device & System
Analytics
IP address, browser user-agent hash, screen resolution vectors.
WebRTC session metadata (only during authorized remote examination).
Network throughput diagnostics for edge video rendering optimization.
Payment Data Handling:Card numbers, CVV, and net-banking credentials are
never ingested into Edvanta servers. Transactions execute exclusively through
RBI-regulated PCI-DSS Level 1 payment aggregators.
Clause
3.0High-Protection
Threshold
3. Student Data Protection
& Digital Learning Privacy
Edvanta acknowledges that educational data represents vulnerable personal vectors
requiring distinct legal guardianship. We apply strict institutional firewalls
separating administrative processing from academic telemetry:
blockZero Data
Monetization
Under no circumstances
is student personal data, performance metrics, or behavioral profiles sold,
rented, leased, or licensed to commercial advertising networks.
child_careMinors Safeguard (Under
18)
Pursuant to Section 9
of the DPDP Act, processing data of minors requires verifiable parental consent
orchestrated through accredited institutional school boards.
fingerprintBehavioral Tracking
Ban
We strictly prohibit
automated profiling or behavioral monitoring targeting children for commercial
nudge mechanics or algorithmic advertising.
Equivalence Commitment: For international higher education
programs, Edvanta aligns its platform controls to FERPA (34 CFR Part 99) compliance
protocols, functioning as an institutional school official with recognized
legitimate educational interests.
Clause
4.0Authorized
Processing
4. Use of Information
Data acquired by Edvanta is strictly processed for legitimate, contractual educational
objectives stipulated by client institutional agreements:
cast_for_education
Pedagogical Execution
& Delivery
Provisioning
digital courseware, rendering virtual lab sessions, processing interactive
code sandboxes, and synchronizing scorm-compliant packages.
analytics
Competency Modeling
& Skill Mapping
Calibrating
adaptive learning pathways to reinforce student knowledge gaps through
non-intrusive algorithmic item response theory (IRT).
verified
Digital Credentialing
& Verification
Cryptographic
timestamping and immutable issuance of university degrees,
micro-certifications, and Skill India / NSDC badge synchronizations.
health_and_safety
System Reliability
& Threat Mitigation
Detecting
distributed denial of service (DDoS) anomalies, unauthorized proctor
evasion, session token hijacking, and identity theft.
Clause
5.0Cryptographic
Defense
5. Data Storage, Encryption
& Security Standards
Edvanta exercises multi-tier physical, logical, and cryptographic architecture to guard
institutional repositories against exfiltration, unauthorized modification, or loss.
Edvanta
Multi-Layer Shield ArchitectureData at rest is
partitioned via dynamic tenant segregation keys with hourly automated snapshots
retained across geographically isolated Indian disaster recovery centers.
check_circle
ISO/IEC 27001 &
27701Audited by
CERT-IN certified cybersecurity auditors annually.
check_circle
Data
LocalizationPrimary
processing remains within Indian sovereign boundaries
(Mumbai/Bengaluru).
Clause
6.0Auditing
Governance
6. Third-Party Disclosures
& Government Auditing
Edvanta operates on a strictly audited, need-to-know disclosure perimeter. We do NOT
share data with marketing affiliates or unauthorized vendors. Disclosures occur solely
in the following bounded contexts:
policy
Institutional Customers: Verified academic leaders and
designated university personnel receive aggregate and individual course records
for matriculated students within their exclusive administrative domain.
account_balance
Statutory & Regulatory Compulsion: Disclosure upon receiving
valid judicial warrants or notifications from authorized enforcement agencies
under the Code of Criminal Procedure, 1973, or the DPDP Data Protection Board.
verified_user
Empaneled Sub-Processors: Tier-1 computational cloud partners
(AWS India, Azure Central India) bound by Data Processing Addendums (DPAs)
matching or exceeding our internal privacy standards.
Clause
7.0Technical
Identifiers
7. Cookies and Tracking
Technologies
Our web properties employ purposeful, non-invasive cookies necessary for platform
operational health:
Cookie Category
Function
Lifespan
Consent Mandate
Strictly Essential
Maintains active authenticated JWT sessions, CSRF
token security.
Session / 24 Hours
Mandatory
Learning Progress
Caches offline module position, video playback
timestamps.
Third-party cross-site
advertising cookies are programmatically blocked across all Edvanta enterprise learning
portals.
Clause
8.0Learner
Empowerment
8. User Rights and Data
Rectification
In accordance with Chapter III of the DPDP Act, 2023, data principals (learners,
educators, and enterprise participants) hold enforceable statutory entitlements:
visibility
Right to Access Summary
Request an easily
readable summary of personal data held, processing activities completed, and
identities of institutional partners with access.
edit_note
Right to Correction & Erasure
Update inaccurate
academic identifiers or petition for data erasure where institutional program
completion criteria have lapsed.
contact_support
Right of Grievance Redressal
Expedited review by our
Data Protection Officer prior to escalation with the Data Protection Board of
India.
person_add_disabled
Right to Nominate
Designate an authorized
representative to exercise statutory data rights in case of death or medical
incapacity.
Clause
9.0Lifecycle
Management
9. Data Retention and Deletion
Protocols
Personal data is retained only for the duration required to achieve contractual
educational objectives, fulfill state accreditation directives, or address legal claims:
Standard Purging
ScheduleNIST 800-88 Compliant
Sanitization
Active Enrollment: Full records
accessible by registered institution.
180-Day Grace: Quarantined for student
transcript verification.
Irreversible Zeroing: Cryptographic
shredding of personal identifiers.
Clause
10.0Statutory
Redressal
10. Contacting Our Data
Protection Officer
In compliance with DPDP statutory provisions, Edvanta has established a permanent Data
Protection Office. All communications regarding policy interpretation, data
rectification petitions, or incident reports should be directed to:
badge
S. RamakrishnanChief Information
Security OfficerDesignated Data
Protection Officer
Statutory
Secretariat AddressEdvanta Technologies
Pvt. Ltd., Sigma Softtech Park, Beta Block, Whitefield Main Road,
Varthur Kodi, Bengaluru, Karnataka 560066, India
pin_dropBengaluru Operations & Sovereign Vault
Centre
security_update_goodFast-Track
Grievance Portal
Submit an Institutional Privacy Request
Are you an authorized Institutional Administrator, Student Principal, or Legal Guardian?
Submit your formal request through our expedited verification pipeline.
task_alt
Request Docket RegisteredDocket
#EDV-DPDP-2024-8902 has been sent to our DPO office. Verification link emailed
to your inbox.