Privacy Policy & Data Protection Charter
Document Version: 1.0 • Effective Date: August 1, 2026 • Classification: Public Legal Policy • Jurisdiction: Republic of India
1. Data Fiduciary Identity & Scope
This Privacy Policy applies to the digital platforms, learning management systems, web applications, and services operated by SiksaTech (accessible via https://siksatech.in and https://team.siksatech.in). In terms of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), SiksaTech functions as a Data Fiduciary regarding the personal data of learners (“Data Principals”), parents, teachers, and institutional representatives.
2. Special Obligations Regarding Child Data (Learners Under 18)
Pursuant to Section 9 of the DPDP Act, 2023, SiksaTech implements strict institutional and technical safeguards for processing children's personal data:
- Verifiable Parental Consent (VPC): Prior to processing any personal data of an individual under 18 years, verifiable consent must be provided by the child's parent or lawful guardian.
- Absolute Prohibition on Detrimental Processing: SiksaTech will not undertake any processing of personal data that is likely to cause any detrimental effect on the physical or psychological well-being of a child.
- Prohibition on Behavioral Monitoring & Tracking: We strictly prohibit automated behavioral profiling, tracking of minor activity for non-educational analytics, and targeted advertising directed at children.
- Parental Rights of Oversight: Parents retain the statutory right to review, rectify, or demand the immediate erasure of their child's account and educational telemetry.
3. Categories of Personal Data Collected
| Data Category | Specific Fields | Statutory Purpose |
|---|---|---|
| Account Identity | Learner Name, Parent Name, Email, Contact Phone | Account provisioning, authentication, emergency communication |
| Academic Profile | Grade Level (Class 5–College), School/College Name | Tailoring age-appropriate learning pathways (Explorer/Builder/Creator/Engineer) |
| Build Telemetry | Code snippets, project schematics, video demo URLs, submission feedback | Assessment, mentor feedback, credential issuance, student portfolio |
| Logistics & Hardware | Shipping postal address, order receipts, payment confirmation tokens | Dispatch of hardware prototyping kits, tax invoices (GST compliance) |
4. Legal Grounds for Processing (Section 4 & 6, DPDP Act)
Personal data is processed strictly on the basis of specified, informed, and unambiguous consent from the Data Principal or lawful guardian, or for legitimate educational contract fulfillment (such as issuing course certificates and dispatching kits).
5. Data Sharing & Third-Party Processors
We do not sell, rent, or trade personal data. We engage only audited, ISO/IEC 27001 certified technology infrastructure partners (e.g., Supabase PostgreSQL with Row Level Security, Vercel hosting, certified payment aggregators) under strict Data Processing Agreements.
6. Statutory Rights of the Data Principal
Under Chapter III of the DPDP Act, you have the following rights:
- Right to Access Information: Summary of personal data being processed and third-party recipients.
- Right to Correction & Erasure: Correction of inaccurate data and permanent erasure of obsolete records.
- Right of Grievance Redressal: Right to seek redressal from our Grievance Officer within statutory timeframes.
- Right to Nominate: Right to nominate an authorized representative in event of death or incapacity.
7. Grievance Redressal Mechanism & Statutory Officer
In accordance with the DPDP Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of our designated Grievance Officer are:
Designation: Data Protection & Grievance Redressal Officer
Entity: SiksaTech India Platform Operations
Official Email: grievance@siksatech.in
Portal Submission: siksatech.in/grievance
Statutory SLA: Acknowledgment within 48 hours; resolution within 30 days.