Data Fiduciary
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), AptiEdge is the "Data Fiduciary" — the entity that determines the purpose and means of processing your personal data.
AptiEdge operates the platform available at this website and related applications. All data processing described in this policy is carried out by AptiEdge or authorised processors acting on our behalf.
Personal Data We Collect
We collect personal data that you provide directly, data generated by your use of the Platform, and technical data collected automatically.
| Category | Examples | Source |
|---|---|---|
| Account Data | Full name, email address, phone number, password (hashed) | Provided by you at registration |
| Consent Records | Timestamp and IP address when you accepted these Terms | Captured automatically at account creation |
| Exam Preferences | Primary exam selection, subject preferences | Provided by you during onboarding |
| Performance Data | Test scores, attempt history, time-per-question, accuracy trends | Generated by your use of the Platform |
| Payment Data | Transaction IDs, subscription status (card numbers are never stored by us) | Via authorised payment processor |
| Technical Data | IP address, browser type, device info, pages visited, session duration | Collected automatically via cookies/logs |
| Communications | Support emails, feedback forms, OTP verification records | Provided by you during interactions |
Legal Basis for Processing
Under the DPDP Act, 2023, we process your personal data on the following legal grounds:
- Consent (Section 6, DPDP Act): When you create an account, you expressly consent to our processing of your personal data for the purposes described in this policy. You may withdraw consent at any time, subject to our Data Retention policy.
- Contractual Necessity: Processing is necessary to perform the contract (your subscription or use of free services) with you — for example, creating your account, delivering tests, and tracking your progress.
- Legitimate Interests: We process technical data for platform security, fraud prevention, and improving our services.
- Legal Obligation: We may process data where required by applicable Indian law, including compliance with court orders, regulatory directions, or law enforcement requests under the IT Act, 2000.
How We Use Your Personal Data
We use your data only for the specific purposes for which it was collected or for compatible purposes. Our primary uses are:
- Account Management: Creating, verifying, and maintaining your account; authenticating your identity via OTP.
- Service Delivery: Providing daily targets, tests, scores, performance analytics, leaderboards, and personalised content recommendations.
- Communication: Sending transactional emails (OTPs, receipts), service announcements, and (with your consent) educational newsletters and promotional offers.
- Consent Record-Keeping: Storing your IP address and the date/time of Terms acceptance as evidence of informed consent under the DPDP Act.
- Payment Processing: Processing subscription fees and managing billing through authorised payment gateways.
- Security & Fraud Prevention: Monitoring for suspicious activity, preventing unauthorised access, and complying with the security obligations under Section 43A of the IT Act.
- Platform Improvement: Analysing anonymised usage patterns to improve features, fix bugs, and develop new content.
- Legal Compliance: Complying with applicable laws, regulations, court orders, and government directives.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
Sharing & Disclosure
We do not share your personal data with third parties except in the following circumstances:
- Data Processors: Trusted service providers who act as our "Data Processors" under the DPDP Act — including cloud hosting, email delivery, payment gateways, and analytics providers. They process data only on our instructions and under binding data processing agreements.
- Legal Requirements: When required by law, court order, or government authority under the IT Act, 2000, or any other applicable Indian statute. We will notify you before disclosing, unless prohibited by law.
- Business Transfer: In the event of a merger, acquisition, or sale of all or part of our business, your data may be transferred to the successor entity, who will be bound by this Privacy Policy.
- Safety: Where we believe disclosure is necessary to prevent imminent harm to any person's life, safety, or security.
- With Your Consent: For any other sharing, we will seek your explicit consent before doing so.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
- Active Account Data: Retained for the duration of your account and for 3 years thereafter, to comply with legal obligations and resolve any disputes.
- Consent Records (Terms acceptance timestamp & IP): Retained for 5 years or for the period prescribed under applicable law, whichever is longer — as evidence of lawful processing under the DPDP Act.
- Performance & Test Data: Retained for the life of your account and for 1 year after account deletion.
- Payment Records: Retained for 7 years as required by financial and tax regulations.
- Technical & Log Data: Retained for up to 90 days for security monitoring purposes.
When data is no longer required, it is securely deleted or anonymised so it can no longer be attributed to you.
Your Rights under DPDP Act, 2023
The Digital Personal Data Protection Act, 2023 grants you the following rights as a "Data Principal":
Right to Access
Request a summary of personal data we hold about you and a list of entities with whom it has been shared (Section 11).
Right to Correction
Request correction or updating of inaccurate, incomplete, or outdated personal data (Section 12).
Right to Erasure
Request deletion of your personal data when it is no longer necessary for the specified purpose (Section 12).
Withdraw Consent
Withdraw your consent to processing at any time. This will not affect prior processing but may limit access to Platform features (Section 6).
Right to Grievance
Lodge a complaint with our Grievance Officer. If unresolved within 30 days, escalate to the Data Protection Board of India (Section 13).
Nominee Rights
Nominate another person to exercise your data rights in the event of your death or incapacity (Section 14).
Cookies & Tracking Technologies
We use cookies and similar technologies to operate and improve the Platform. A cookie is a small text file stored on your device.
- Essential Cookies: Required for the Platform to function (e.g., session management, login state). These cannot be disabled.
- Functional Cookies: Remember your preferences (e.g., exam selection, display settings).
- Analytics Cookies: Help us understand how you use the Platform, so we can improve it. We use anonymised and aggregated data only.
You can control non-essential cookies through your browser settings. Blocking essential cookies will affect Platform functionality. We do not use third-party advertising cookies.
Data Security
We implement "reasonable security practices and procedures" as mandated by Section 43A of the IT Act, 2000 and the IT (Reasonable Security Practices) Rules, 2011. Our measures include:
- Passwords stored as one-way cryptographic hashes (bcrypt) — plaintext passwords are never stored.
- HTTPS/TLS encryption for all data in transit.
- Role-based access controls restricting data access to authorised personnel only.
- OTP-based verification for account creation and sensitive operations.
- Server-side input validation and parameterised database queries to prevent injection attacks.
- Regular security reviews and vulnerability assessments.
Children's Privacy
The Platform is intended for users who are at least 13 years of age. We do not knowingly collect personal data from children under 13 without verifiable parental consent, in accordance with Section 9 of the DPDP Act, 2023.
Users aged 13–17 must have consent from a parent or guardian before registering. By registering, you represent that you are at least 13 and, if under 18, that you have parental or guardian consent.
If we discover that we have inadvertently collected data from a child under 13 without appropriate consent, we will promptly delete that data. Parents may contact our Grievance Officer to report any such issue.
International Data Transfers
AptiEdge primarily stores and processes data in India. Where we use service providers based outside India (such as cloud infrastructure providers), we ensure:
- Data is transferred only to countries or organisations that provide adequate data protection as notified by the Indian Government under the DPDP Act, 2023.
- Appropriate contractual safeguards (Data Processing Agreements) are in place with international processors.
- Such transfers occur only for the purposes described in this policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or our services. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Notify registered users via email with a summary of the changes.
- Where required by the DPDP Act, seek fresh consent before the revised policy takes effect.
We encourage you to review this policy periodically. Continued use of the Platform after changes are posted constitutes your acceptance of the revised policy.
Contact & Grievance Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact our Grievance Officer. We are required by Rule 5(9) of the IT Rules, 2011 and the DPDP Act, 2023 to acknowledge grievances within 24 hours and resolve them within 30 days.