Privacy Policy
How personal data is handled on this platform, who decides what happens to it, and what you can require us to do.
1. Two roles, and which one applies to you
The Digital Personal Data Protection Act, 2023 (the DPDP Act) distinguishes the Data Fiduciary, who decides why and how personal data is processed, from the Data Processor, who processes it on the Fiduciary's instructions. Which one we are depends entirely on how you reached us.
- If you are a candidate, examiner or administrator using this platform through an institution — your university, employer, examination body or certification authority — then that institution is the Data Fiduciary and we are its Data Processor. It decides what examinations run, what proctoring is switched on, how long evidence is kept within the limits below, and who may see results. Exercise your rights against the institution first; §7 explains what we do when you come to us instead.
- If you are a visitor to this website — you asked for a demo, or you verified a certificate — then we are the Data Fiduciary for that interaction and this policy is the whole of it.
2. What we process, and why
2.1 Account and identity
Name, work or institutional email address, the role you hold, and the institution, campus and department you belong to. Passwords are stored only as a one-way hash and cannot be read back by anyone, including us. Where sign-in by one-time code is enabled, the code is stored until it is used or expires.
Purpose: to establish who you are and what you are permitted to reach.
2.2 Examination records
Which assessments you were scheduled for, when you started and submitted, your answers, the marks awarded, any re-evaluation you requested, and certificates issued to you.
Purpose: to deliver the examination and to produce a result the institution can stand behind.
2.3 Proctoring evidence — read this section closely
Where an institution switches proctoring on for an assessment, and after you are told on screen before the examination begins, we process:
- a photograph captured at the pre-flight identity check;
- periodic still images from your camera during the sitting;
- browser and connection events — moving away from the examination tab, leaving full screen, attempted copy, attempted paste, sustained sound in the room, loss of connection, and the absence of any response from your device;
- a risk score derived from those events.
What we do not do, and will not claim to:
- There is no video recording. Still images only.
- There is no screen recording. We do not see your desktop, your other windows or your files.
- There is no facial recognition or biometric matching. Where an institution enables it, software running in your own browser counts how many faces are visible in a frame, so that a second person in the room or an empty chair can be raised for a human to look at. Counting faces is not recognising them: no biometric template is generated, stored, compared or transmitted, and nothing anywhere identifies who a face belongs to. Identity face matching and mobile-device detection are named in our settings screens and are not implemented — we hold no enrolment photograph to match anyone against.
- Face counting happens on your device, not ours. The detection model is served from this platform and runs in your browser. What reaches us is a number and a confidence, on the photographs that were being taken anyway — it adds nothing to what is collected about you, and no image is sent anywhere it was not already going.
- No microphone audio is retained. Sustained sound is detected as a level, and the level is what is recorded — not a recording.
Purpose: examination integrity. Every signal is reviewed by a person before it affects anyone; no result is voided by an automated decision. See §6.
2.4 Technical and security records
An append-only audit log of significant actions taken in the platform, including who took them and when. Session records. For demo enquiries submitted on this website, the IP address and browser user-agent string, kept to recognise automated abuse.
2.5 Billing
Invoices, credit consumption and subscription records belonging to the institution. We do not process card or bank details. Card payments are taken on Razorpay's own hosted form, on Razorpay's systems. What returns to this platform is a payment identifier and a status — never a card number, an expiry, a CVV or a bank credential. This platform is therefore outside PCI-DSS scope, and that is a consequence of the design rather than a claim about it.
3. Cookies and similar technologies
This platform sets a session cookie and a CSRF token cookie. Both are strictly necessary: without them you cannot stay signed in or submit a form safely. There is no advertising, analytics, profiling or third-party tracking cookie anywhere on this site or in the application. Nothing here follows you to another website.
4. How long we keep it
| Category | Retention | Set by |
|---|---|---|
| Proctoring evidence — photographs, snapshots, events | 180 days by default | The institution, within a floor of 30 days and a ceiling of 730 days that it cannot exceed |
| Audit log | 730 days by default | Platform administration, minimum 30 days |
| Backup files | 30 days by default | Platform administration, maximum 365 days |
| Notification and webhook message bodies | Emptied on a schedule; the record that a message was sent is kept | Platform administration |
| Account, examination records and certificates | For as long as the institution's account is active, and then per its instructions | The institution |
| Demo enquiries submitted on this website | 24 months from receipt | Us |
Deletion of proctoring evidence runs on a schedule and removes the files, not merely the reference to them.
5. Who else sees it
Within an institution, access is decided by role: a candidate sees their own records only; a proctor sees the sitting they are invigilating; an evaluator sees the responses assigned to them; administrators see their own institution. Data belonging to one institution is not visible to another. Isolation is applied automatically to every query rather than screen by screen.
We do not sell personal data. We do not share it for advertising. We disclose it outside the institution only where compelled by Indian law, and we will tell the institution unless we are prohibited from doing so.
Sub-processors: the platform runs on hosting infrastructure and, where the institution configures one, sends email through the institution's own mail server.
Razorpay Software Private Limited processes card payments where an institution chooses to settle an invoice online. Razorpay is a payment aggregator authorised by the Reserve Bank of India and stores payment data in India.
What we send Razorpay contains no personal data at all: the amount, the currency, and our own invoice and payment reference numbers. Nothing else. Any name, email address, telephone number or card detail entered on Razorpay's payment form is given by you to Razorpay directly, on their systems, under their privacy policy — it does not pass through this platform and we do not receive it. What Razorpay returns to us is a payment identifier and a status.
No candidate data, examination data or proctoring evidence is ever sent to a payment provider.
No other third-party service receives personal data from this platform.
6. Automated decisions
Proctoring produces flags and a risk score. Neither ends an examination and neither voids a result. Only a proctor can terminate a sitting, and a result cannot be released while an integrity flag is open — it must be resolved by a person. Release itself requires two different people: the one who requests it cannot be the one who approves it. Objective question types are marked automatically; you may ask the institution for re-evaluation, and the platform carries a route for that request.
7. Your rights under the DPDP Act
As a Data Principal you may:
- Access a summary of the personal data being processed about you and of the processing activities;
- Correct data that is inaccurate, complete data that is incomplete, and update it;
- Erase data, where it is no longer needed for the purpose it was collected for and no law requires it to be kept;
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
- Have your grievance heard — see §10.
Where to send the request. If you use the platform through an institution, send it to that institution: it is the Data Fiduciary and it holds the decision. If you send it to us instead, we will forward it to the institution and tell you we have done so; we will not act on it ourselves, because doing so would mean altering an examination record on the instruction of someone other than the body accountable for it. For enquiries you made on this website, write to us directly at privacy@macliysglobal.tech.
Erasure has a limit worth stating plainly. Examination records, certificates and the audit log are the evidence an institution relies on to defend a result. A request to erase them will usually be refused for as long as the result stands, and that refusal will be explained rather than ignored.
8. Children
Where an institution enrols candidates under 18, the DPDP Act requires verifiable consent from a parent or lawful guardian, and prohibits tracking, behavioural monitoring for advertising, and targeted advertising directed at children. This platform does no advertising, no behavioural profiling and no tracking of any kind, so the prohibition is met by construction. Obtaining and recording parental consent is the institution's obligation as Data Fiduciary; we process what it instructs.
9. Security, and one honest limitation
Reasonable security safeguards under s.8(5) of the DPDP Act and the SPDI Rules, 2011 include: role-based access with capability-gated routes; automatic per-institution data isolation; passwords stored only as hashes; an append-only audit log that no account can edit or delete; proctoring evidence held on private storage that the web server does not serve, reachable only through a permission check; rate limiting on public endpoints; scoped and rotatable API keys; and scheduled backups.
The limitation: the scheduled backup covers the database. It does not currently cover files held on disk — proctoring evidence, uploaded answers and branding assets. Those are protected in place but are not in the nightly backup, so a total loss of storage would lose them. We state this because a security section that lists only what works is not a security section.
In the event of a personal data breach we will notify the Data Protection Board of India and each affected Data Principal as required by s.8(6) of the DPDP Act, and we will notify the institution without undue delay.
10. Grievances
Write to our Grievance Officer at grievances@macliysglobal.tech. We acknowledge within 24 hours and resolve within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India. Full details, including the escalation route, are on our grievance redressal page.
11. Transfers outside India
Personal data is processed on infrastructure in India. We do not transfer it outside India except where an institution configures an integration that does so, in which case the institution makes that choice as Data Fiduciary. Any transfer is subject to s.16 of the DPDP Act and to the restrictions the Central Government notifies under it.
12. Changes
We will change this policy as the platform changes and as the DPDP Rules are notified. The date at the top is the version you are reading. Material changes affecting institutions are notified to them through the platform.
The party these documents bind
- Trading name
- Macliys Global Technologies
- Registered entity
- Not yet published
- CIN
- Not yet published
- GSTIN
- Not yet published
- Registered office
- Not yet published
- Grievance Officer
- Not yet published
- Grievance contact
- grievances@macliysglobal.tech