HomeInstitutional MSA
Institutional Master Services Agreement & DPA

Institutional Master Services Agreement (MSA)

Legal Framework governing Educational Institution Onboarding, Faculty SPOC Delegated Authority, and Student Data Processing Addendum (DPA).

1. Institutional Authority & Legal Capacity

By completing the Institutional Onboarding process on the SIH & Campus Hackathon Management Portal, the registering individual certifies that:

  • They are a full-time academic faculty member, Head of Department, Dean, or designated Single Point of Contact (SPOC) authorized by the leadership of their college or university.
  • They hold the requisite delegated power of attorney to establish an institutional node on the Platform and administer student hackathon rosters.
  • All institutional data submitted—including AISHE Code, university affiliation, accreditation details, and campus addresses—is authentic and verifiable against Ministry of Education / UGC records.

2. Student Data Processing Addendum (DPA)

In compliance with Section 8 of the Digital Personal Data Protection Act (DPDP), 2023:

  • Purpose Limitation: Uploaded pre-approved student rosters (roll numbers, names, departments) shall be used solely for authenticating participant registration and preventing unauthorized entries.
  • Tenant Isolation: All institutional records are isolated within dedicated database partitions and are never accessible to competing educational institutions.
  • Confidentiality: The Platform shall maintain strict confidentiality over all student identification datasets and shall not monetize, sell, or disclose such data to third-party marketing entities.
  • Sub-Processor Safeguards: Sub-processors utilized for transactional email relays (Resend) and encrypted media vaults (Cloudinary) operate under binding SOC-2 and data protection covenants.

3. Faculty SPOC Governance & SIH Nomination Protocols

The appointed Faculty SPOC undertakes the following operational responsibilities:

  • Roster Verification: Ensure all nominated teams fulfill national criteria (exactly 6 members with mandatory female representation).
  • Account Security: Complete initial password reset upon first administrative login and maintain credential confidentiality.
  • Staff Delegation: Appoint and manage assistant coordinators or evaluators using the OTP-verified staff provisioning workflow.
  • Nomination Export: Validate and download official nomination spreadsheets for upload to the SIH central coordination portal.

4. Domain Configuration & Generic Email Policy

Institutions with official domain infrastructure (e.g. @bbdit.edu.in) can enforce custom domain matching to ensure seamless student registration. Institutions lacking dedicated domains may permit generic email providers (e.g. Gmail), with each account subject to mandatory real-time OTP validation and roll number verification.

5. Term, Season Closure & Secure Data Expungement

This Agreement remains in effect for the active academic hackathon cycle. Upon season conclusion, institutions may request complete expungement of student rosters by submitting an authenticated request to hello@abdulbarr.in. All corresponding student roster datasets will be securely purged within thirty (30) business days.