Data Processing Agreement
The terms on which we process personal data on an institution's instructions, as required by section 8(2) of the Digital Personal Data Protection Act, 2023.
1. Parties and standing
This Agreement is between the Institution licensing the Platform, acting as Data Fiduciary, and Macliys Global Technologies, acting as Data Processor. It is incorporated into the Terms of Use and takes effect when the Institution accepts them. Section 8(2) of the Digital Personal Data Protection Act, 2023 (the DPDP Act) permits a Data Fiduciary to engage a Processor only under a valid contract; this is that contract.
Where this Agreement and the Terms of Use conflict on the treatment of personal data, this Agreement prevails.
2. Scope and instructions
We process personal data only on the Institution's documented instructions. The Institution's instructions are: these documents, the configuration it sets in the Platform, and any further written instruction it gives us.
We do not process personal data for our own purposes. We do not use Institution Data to train models, to build profiles, or to develop or market other products.
If we believe an instruction breaches the DPDP Act or other Indian law, we will tell the Institution and may pause that processing until it is resolved.
3. Subject matter, duration, nature and purpose
| Subject matter | Delivery of online assessment, examination, invigilation, evaluation and certification |
|---|---|
| Duration | The subscription term, plus the 30-day export window in §9 |
| Nature and purpose | Hosting, storage, structured retrieval, scheduled deletion, and transmission of notifications on the Institution's behalf |
| Categories of Data Principal | Candidates; faculty and authors; evaluators; proctors; administrators; finance and support staff |
| Categories of personal data | Identity and contact details; organisational affiliation; authentication credentials as hashes; examination responses and marks; certificates; proctoring evidence (photographs, still images, browser and connection events, risk scores); audit records; billing records |
| Not processed | Card or bank details; biometric templates; video or screen recordings; location data; advertising or behavioural profiles |
4. Confidentiality
Personnel with access to personal data are bound by written confidentiality obligations that survive their engagement. Access is granted on a need-to-know basis and removed on role change or departure.
5. Security measures
We implement reasonable security safeguards under s.8(5) of the DPDP Act and Rule 8 of the SPDI Rules, 2011:
- Tenant isolation applied automatically to every database query and every insert, rather than screen by screen — so a missed filter in one place cannot expose another institution's data.
- Capability-gated routing. Ten roles resolve to scope tiers; a route refuses independently of whether the navigation offered it.
- Credentials. Passwords stored only as one-way hashes. Optional sign-in by one-time code. Configurable password policy per institution.
- An append-only audit log. No account, including the most privileged, can edit or delete an entry.
- Proctoring evidence on private storage. Not served by the web server; reachable only through a controller that repeats the same permission check as the console.
- Two-person controls on result release, refunds and question approval: the requester cannot be the approver.
- Rate limiting on public endpoints; scoped, rotatable API keys.
- Scheduled encrypted-at-rest backups with checksum verification before any restore, and a refusal to restore while any examination is in progress.
6. Sub-processors
The Institution gives general authorisation for the sub-processors below. We remain liable for their performance.
| Sub-processor | Function | Location |
|---|---|---|
| Hosting provider | Application and database hosting, storage of evidence files | India |
| The Institution's own mail server | Delivery of notifications, where the Institution configures SMTP | Determined by the Institution |
| Razorpay Software Private Limited | Card, UPI and netbanking settlement of invoices, where the Institution chooses to pay online. Receives the amount, the currency and our invoice and payment reference numbers, and no personal data. Payment details are entered by the payer on Razorpay's own systems and do not pass through the Platform. | India (RBI-authorised payment aggregator) |
No analytics, advertising, customer-messaging or AI service receives personal data from this Platform. We will give the Institution 30 days' written notice before adding or replacing a sub-processor, and the Institution may object on reasonable data-protection grounds; if we cannot resolve the objection, the Institution may terminate the affected service without penalty.
7. Assisting the Institution
We assist the Institution, at its cost where the effort is material, with:
- Data Principal requests — access, correction, completion, updating, erasure and nomination under ss.11–14 of the DPDP Act. Where a request reaches us directly we forward it to the Institution and inform the requester; we do not act on it ourselves.
- Breach notification — see §8.
- Impact assessments and audits the Institution is required to carry out, including where it is notified as a Significant Data Fiduciary under s.10.
8. Personal data breach
We will notify the Institution without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting its data, with what is known at the time: the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, and the measures taken. We will cooperate with the Institution's notification to the Data Protection Board of India and to affected Data Principals under s.8(6).
One limitation is disclosed here rather than discovered later. The scheduled backup covers the database. It does not currently cover files held on disk — proctoring evidence, uploaded answers and branding assets. Those files are protected in place and access-controlled, but they are not in the nightly backup, so a total loss of the storage volume would lose them. Institutions with a recovery-point obligation covering evidence files should raise it with us before relying on the Platform for that obligation.
9. Retention, return and deletion
Retention within the Platform:
| Data | Default | Range the Institution may set |
|---|---|---|
| Proctoring evidence | 180 days | 30 to 730 days — enforced, and not exceedable |
| Audit events | 730 days | 30 days minimum |
| Backup files | 30 days | 7 to 365 days |
| Notification and webhook bodies | Emptied on a schedule; the delivery record is retained | — |
On termination the Institution has 30 days to export its data through the Platform. After that window we delete Institution Data, including from backups as those backups age out of their retention window, save where Indian law requires longer retention — in which case we will say what is retained and why.
10. Transfers outside India
Processing takes place on infrastructure in India. We do not transfer personal data outside India except where the Institution configures an integration that does so, which is the Institution's decision as Data Fiduciary. Any transfer is subject to s.16 of the DPDP Act and to any restriction the Central Government notifies under it.
11. Liability and term
Liability under this Agreement is subject to the limits in §11 of the Terms of Use. This Agreement continues for as long as we process personal data on the Institution's behalf, and the confidentiality, deletion and assistance obligations survive its termination.
12. Governing law
This Agreement is governed by the laws of India and is subject to the dispute resolution clause at §14 of the Terms of Use.
13. A signed counterpart
Where an institution's procurement process requires a signed and stamped copy on our letterhead, write to privacy@macliysglobal.tech with the entity name and the signatory's details.
The party these documents bind
- Trading name
- Macliys Global Technologies
- Registered entity
- Not yet published
- CIN
- Not yet published
- GSTIN
- Not yet published
- Registered office
- Not yet published
- Grievance Officer
- Not yet published
- Grievance contact
- grievances@macliysglobal.tech