HomePrivacy Policy
Statutory DPDP Act (2023) & IT Act (2000) Compliance

Privacy Policy & Data Protection Standards

Effective Date: August 26, 2026 | Document Version: 2026.2-FINAL | Operational Jurisdiction: Republic of India

1. Preamble & Statutory Alignment

This Privacy Policy governs the collection, storage, cryptographic processing, transmission, and lifecycle management of Personally Identifiable Information (PII) and institutional records managed through the SIH & Campus Hackathon Management Portal ("the Platform"), engineered and maintained by Abdul Barr.

This policy is drafted in strict adherence to:

  • The Digital Personal Data Protection Act (DPDP), 2023 (Acts of Parliament, India).
  • The Information Technology Act, 2000 (IT Act), including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
  • The Indian Computer Emergency Response Team (CERT-In) Cybersecurity Directions regarding log retention, user authentication, and incident reporting.

2. Data Fiduciary vs. Data Processor Relationships

For the purposes of data governance legislation:

Educational Institutions (Data Fiduciary)

The onboarded College / University acts as the Data Fiduciary that determines the purpose and lawful means of student roster verification and competition nomination.

The Platform (Data Processor)

The Platform operates strictly as a Data Processor providing technical infrastructure, encryption, team coordination workflows, and nomination spreadsheet generation.

3. Granular Categories of Data Collected

A. Student Participant Records

  • Full legal name, gender (required for SIH female representation quota compliance), and personal contact phone.
  • Institutional email address or personal email address (authenticated via 6-digit cryptographic OTP).
  • Academic degree program (B.Tech, BCA, MCA, Diploma), discipline, and current academic year (1st–4th year).
  • Institutional Roll Number / Enrollment ID (indexed uniquely per college).
  • Student identity card scans, college verification documents, GitHub profiles, and LinkedIn URLs.
  • Team memberships, role allocations (Leader vs. Member), and problem statement submission summaries.

B. Institutional & SPOC Administrator Data

  • Official institution name, short name, AISHE code, and university affiliation board.
  • Campus physical address, official email domain, and website endpoint.
  • Designated Single Point of Contact (SPOC) and College Admin full names, faculty designations, official emails, and mobile phone numbers.
  • Pre-approved student roll rosters uploaded by SPOCs for automated student clearance.

C. Telemetry, Security & Audit Logs

  • Client IP addresses and timestamps captured during registration, institutional agreement signing, and newsletter opt-in.
  • Canvas CAPTCHA interaction tokens to mitigate automated denial-of-service and credential stuffing attacks.
  • Immutable administrative audit records logging all SPOC verification decisions and role elevation events.

4. Purpose and Legal Basis for Processing

Under DPDP Act Section 6, the Platform processes personal data exclusively for specified, lawful purposes:

  • Institutional Enrollment Verification: Cross-referencing participant roll numbers against verified college datasets to guarantee bona fide student status.
  • Smart India Hackathon (SIH) Compliance: Validating team roster composition (6 members, minimum 1 female member) and generating compliant XLSX nomination sheets for SPOC submission to the SIH central portal.
  • Verifiable Communication: Dispatching cryptographic One-Time Passwords (OTPs) for account registration, email address updates, and newsletter double opt-in confirmations via Resend.
  • Legal Audit Trail: Maintaining verifiable records of Terms acceptance and institutional MSA signings in accordance with IT Act evidentiary requirements.

5. Multi-Tenant Scoping & Cryptographic Safeguards

To ensure zero data leakage between competing educational institutions:

  • Tenant Scoping: College Admins and SPOCs can access only student profiles, teams, and ideas belonging to their specific institution ID.
  • Student Isolation: Students can search for and invite peers strictly from their own college.
  • Password Hashing: All passwords are salted and hashed using bcrypt (10 rounds) prior to database persistence. Plaintext credentials are never retained or logged.
  • Encrypted Transport: All data in transit is protected using TLS 1.3 encryption.
  • Signed Media Vaults: Student ID cards uploaded for manual verification are stored in secure Cloudinary storage buckets with restricted access.

6. Third-Party Infrastructure Sub-Processors

Data is shared only with strictly vetted infrastructure providers under binding confidentiality agreements:

  • MongoDB Atlas: Multi-region managed database cluster with automated encryption at rest.
  • Resend Technologies: SOC-2 compliant transactional email delivery service for OTPs and notifications.
  • Cloudinary Ltd.: Encrypted asset and image storage with expiring signatures.

7. Data Principal Rights (Under DPDP Act 2023)

Every registered user and institution holds statutory rights under the law:

  • Right to Access & Summary: View all registered profile information and team associations via the Profile console.
  • Right to Rectification: Update academic details, telephone numbers, and email addresses (protected via OTP validation).
  • Right to Erasure: Request deletion of obsolete team submissions or accounts upon conclusion of the hackathon season.
  • Right of Grievance Redressal: Submit inquiries or complaints directly to the designated Data Protection Officer.

8. Data Protection Officer & Grievance Officer Contact

In accordance with Section 8 of the DPDP Act 2023 and Rule 5(9) of the IT Rules 2011, grievances regarding data processing, access requests, or regulatory disclosures should be addressed to:

Name: Abdul Barr

Designation: Chief System Architect & Data Protection Officer

Official Email: hello@abdulbarr.in

Direct Telephone: +91 7479934706

Jurisdiction: Lucknow / Ghaziabad, Uttar Pradesh, India