Last updated: July 2026
1. Information We Collect
Account Information
- Full name, mobile number (OTP-verified), email address, password (encrypted)
- Role-specific fields: qualification, skills, state, district, college/institute
- Instructor / Institute: uploaded documents (Govt ID, Qualification Certificate, Registration Letter)
- PRN Number (optional, for marksheet linkage)
Usage Data
- Login timestamps, IP address, browser type, device fingerprint
- Course progress, exam attempts, time spent per module
- Search queries, filter selections (aggregated for site improvements)
Payment Data
Payment card / UPI details are handled EXCLUSIVELY by Razorpay (PCI-DSS compliant). ITI Ke Gyani ne kabhi bhi aapka full card number ya CVV store nahi karta. Sirf transaction ID + status hamare paas rehta hai.
2. How We Use Your Data
- Account operations: Login, password reset, notifications, invoicing
- Personalization: Recommend courses / exams based on your trade + qualification
- Analytics: Aggregate usage patterns to improve platform
- Communication: Course updates, exam results, admin approvals, promotional (opt-out available)
- Legal: Comply with law enforcement requests, resolve disputes
3. Data Sharing
Hum aapka personal data third parties ko sell nahi karte. Data sirf in cases me share hota hai:
- Institute → Student query: Jab aap kisi institute ko query bhejte ho, aapka naam + phone/email us institute + admin ke saath share hota hai.
- Instructor → Student purchase: Course purchase par instructor ko student ka basic name + email visible hota hai (commission tracking ke liye).
- Government inspections: NCVT / SCVT / DGT audit ke case me legal cooperation.
- Service providers: Hostinger (hosting), Razorpay (payments), Fast2SMS (OTP), Bunny CDN (media) — all with signed data-processing agreements.
4. Data Security
- Passwords encrypted with bcrypt (never stored in plaintext).
- Communication over HTTPS with TLS 1.2+.
- ISO 27001 certified Information Security Management System — see Certifications.
- Rate limiting + IP-based OTP abuse detection.
- Data breach protocol: 72-hour notification per Indian IT Rules 2011.
5. Data Retention
- Active accounts: data retained till account is active + 12 months after last login.
- Deleted accounts: PII purged in 30 days; anonymized analytics may persist.
- Payment / invoice records: retained 7 years per Indian financial laws.
6. Your Rights
- View your data: profile page + admin request via email
- Correct incorrect data: profile edit or email support
- Delete your account: email support@itikegyani.com — irreversible
- Opt-out of marketing emails via "Unsubscribe" link
7. Cookies
Platform sirf essential cookies use karta hai (session ID, dark-mode preference, language). Third-party analytics cookies (Google Analytics) load nahi karte. In-house lightweight analytics for aggregated usage only.
8. Children's Privacy
Platform 13 saal se kam umar ke bachhon ke liye designed nahi hai. Agar aap parent/guardian ho aur aapko lagta hai ki 13 saal se kam ka bachha registered hai, please contact karein — hum turant account remove kar denge.
9. Updates to Policy
Policy time-to-time revise hoti hai. Significant changes registered users ko email/in-app notification ke through inform kiye jayenge.
10. Grievance Officer
Any privacy concern: support@itikegyani.com (subject line: "Privacy Grievance")
Response within 30 days per Indian IT Rules 2011.