🔒 Privacy Policy

How we handle your personal data

Last updated: July 2026

1. Information We Collect

Account Information

  • Full name, mobile number (OTP-verified), email address, password (encrypted)
  • Role-specific fields: qualification, skills, state, district, college/institute
  • Instructor / Institute: uploaded documents (Govt ID, Qualification Certificate, Registration Letter)
  • PRN Number (optional, for marksheet linkage)

Usage Data

  • Login timestamps, IP address, browser type, device fingerprint
  • Course progress, exam attempts, time spent per module
  • Search queries, filter selections (aggregated for site improvements)

Payment Data

Payment card / UPI details are handled EXCLUSIVELY by Razorpay (PCI-DSS compliant). ITI Ke Gyani ne kabhi bhi aapka full card number ya CVV store nahi karta. Sirf transaction ID + status hamare paas rehta hai.

2. How We Use Your Data

  • Account operations: Login, password reset, notifications, invoicing
  • Personalization: Recommend courses / exams based on your trade + qualification
  • Analytics: Aggregate usage patterns to improve platform
  • Communication: Course updates, exam results, admin approvals, promotional (opt-out available)
  • Legal: Comply with law enforcement requests, resolve disputes

3. Data Sharing

Hum aapka personal data third parties ko sell nahi karte. Data sirf in cases me share hota hai:

  • Institute → Student query: Jab aap kisi institute ko query bhejte ho, aapka naam + phone/email us institute + admin ke saath share hota hai.
  • Instructor → Student purchase: Course purchase par instructor ko student ka basic name + email visible hota hai (commission tracking ke liye).
  • Government inspections: NCVT / SCVT / DGT audit ke case me legal cooperation.
  • Service providers: Hostinger (hosting), Razorpay (payments), Fast2SMS (OTP), Bunny CDN (media) — all with signed data-processing agreements.

4. Data Security

  • Passwords encrypted with bcrypt (never stored in plaintext).
  • Communication over HTTPS with TLS 1.2+.
  • ISO 27001 certified Information Security Management System — see Certifications.
  • Rate limiting + IP-based OTP abuse detection.
  • Data breach protocol: 72-hour notification per Indian IT Rules 2011.

5. Data Retention

  • Active accounts: data retained till account is active + 12 months after last login.
  • Deleted accounts: PII purged in 30 days; anonymized analytics may persist.
  • Payment / invoice records: retained 7 years per Indian financial laws.

6. Your Rights

  • View your data: profile page + admin request via email
  • Correct incorrect data: profile edit or email support
  • Delete your account: email support@itikegyani.com — irreversible
  • Opt-out of marketing emails via "Unsubscribe" link

7. Cookies

Platform sirf essential cookies use karta hai (session ID, dark-mode preference, language). Third-party analytics cookies (Google Analytics) load nahi karte. In-house lightweight analytics for aggregated usage only.

8. Children's Privacy

Platform 13 saal se kam umar ke bachhon ke liye designed nahi hai. Agar aap parent/guardian ho aur aapko lagta hai ki 13 saal se kam ka bachha registered hai, please contact karein — hum turant account remove kar denge.

9. Updates to Policy

Policy time-to-time revise hoti hai. Significant changes registered users ko email/in-app notification ke through inform kiye jayenge.

10. Grievance Officer

Any privacy concern: support@itikegyani.com (subject line: "Privacy Grievance")
Response within 30 days per Indian IT Rules 2011.