Global Privacy Policy
We are committed to maintaining the highest standards of data security and privacy for our students, educators, and institutional partners worldwide.
Contents
1. Introduction
Welcome to IT Olympiads ("Company", "we", "our", "us"). Operating at the intersection of education and technology, we recognize that the protection of personal data—particularly that of minors and institutional records—is a fundamental responsibility.
This Privacy Policy delineates our rigorous enterprise-grade protocols for collecting, storing, processing, and protecting information when you access our Olympiad examination platform, administrative portals, and associated services (collectively, the "Services"). By utilizing our Services, you consent to the data practices described in this comprehensive framework.
2. Data We Collect
To provide a seamless, secure, and verifiable examination environment, we collect discrete categories of data. We adhere strictly to the principle of data minimization.
- Identity Data: Full legal name, date of birth, gender, and photograph (for AI-proctored verification).
- Academic Data: School affiliation, institutional ID, grade/class level, historical examination performance, and associated curriculum metrics.
- Technical & Telemetry Data: IP addresses, browser fingerprints, hardware configurations, and interaction logs during active examination sessions to prevent academic dishonesty.
- Financial Data: Billing addresses and payment histories. Note: We utilize PCI-DSS compliant third-party gateways (e.g., Razorpay/Stripe); we do not store full credit card numbers on our infrastructure.
3. How We Use Your Data
Your data is exclusively utilized to facilitate, secure, and improve the examination lifecycle. Our processing is grounded in legitimate operational interests and contractual necessity.
- Examination Integrity: Deploying behavioral analysis and telemetry to ensure a fair testing environment.
- Credential Issuance: Generating cryptographic certificates, hall tickets, and verified academic portfolios.
- Institutional Reporting: Providing aggregated, anonymized performance analytics to registered schools and educational bodies.
- Service Optimization: Diagnosing infrastructural anomalies and enhancing platform resilience.
4. Children's Privacy & Institutional Consent
Given the nature of our Services, the primary end-users are minors. We operate in strict alignment with international child protection frameworks, including principles akin to the Children's Online Privacy Protection Act (COPPA) and the Family Educational Rights and Privacy Act (FERPA).
Institutional Authorization Model
For students registered via bulk school enrollments, the educational institution acts as the authorized agent granting consent for data processing on behalf of the parents/guardians, limited strictly to educational purposes. We do not use student data for targeted advertising.
5. Enterprise Data Security
Our infrastructure employs defense-in-depth methodologies to safeguard your information against unauthorized access, alteration, or exfiltration.
- Encryption: All data is encrypted in transit using TLS 1.3 and at rest utilizing AES-256 block-level encryption.
- Access Controls: strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) are mandated for all internal staff accessing the administrative backend.
- Audits: Routine penetration testing and automated vulnerability scanning across our cloud infrastructure.
6. Third-Party Disclosures
We do not sell, rent, or monetize personal data. Disclosures to third parties are strictly limited to vetted enterprise sub-processors under binding Data Processing Agreements (DPAs).
These sub-processors include our cloud hosting providers (e.g., AWS/GCP), secure payment gateways, and transactional email/SMS delivery services. In rare instances, we may disclose data if compelled by a lawful subpoena or court order in our operating jurisdiction.
7. Your Legal Rights
Depending on your jurisdiction (including GDPR and regional data protection laws), you retain substantial control over your data footprint.
- Right to Access: Request a comprehensive export of personal data held within our systems.
- Right to Erasure ("Right to be Forgotten"): Request the deletion of identifiable data, provided it does not conflict with our legal requirement to maintain academic records for a statutory period.
- Right to Rectification: Demand the correction of inaccurate academic or identity profiles.
8. Contact Legal & Privacy Team
For formal inquiries regarding our data practices, Sub-Processor lists, or to exercise your privacy rights, please contact our Data Protection Officer (DPO).
