Privacy Policy & Data Protection
Your trust, assessment integrity, and candidate privacy are our highest commitments. Learn how Medha Scholar collects, safeguards, and purges examination data.
1. Information We Collect
Medha operates as a digital examination conduit for students, academic institutions, and competitive testing bodies. To facilitate authorized examinations and certify merit rankings, we collect:
- Candidate Identity Data: Full name, verified mobile number, email address, educational institution or school name, class/grade (Grades 1 to 12), and assigned Roll Number.
- Assessment Responses: Cryptographically timestamped question choices, sectional time utilization, numerical entries, and submission signatures.
- Technical Environment Data: Browser version, operating system, IP address, screen dimensions, and connection stability metrics to ensure fair testing conditions.
- Payment Records: Transaction IDs and payment statuses processed via authorized Reserve Bank of India (RBI) regulated payment aggregators (e.g., Razorpay). Medha never stores candidate credit card numbers, debit PINs, or net banking passwords.
2. AI Webcam Proctoring & Biometric Privacy Safeguards
For proctored examinations, Medha deploys an edge-first computer vision system that runs locally within the candidate's browser:
đ Edge AI Processing & Zero Persistent Biometric Harvesting
Webcam streams are analyzed locally on your device in real-time to compute face presence and detect anomalies (such as absence of the candidate or presence of multiple individuals). Raw high-frame-rate video feeds are never streamed or permanently cataloged to central servers. Only lightweight security event logs (e.g., timestamped anomaly flags) are transmitted to the invigilation audit log.
- Anti-Cheat Telemetry: Tab switching, multi-window events, and fullscreen exits are logged with grace periods configured by examination authorities.
- Parental Consent: For candidates under the age of 18, registration by educational institutions or guardians constitutes verifiable assent for automated invigilation during scheduled tests.
3. Cryptographic Storage & System Security
Medha enforces military-grade information protection standards across all infrastructure layers:
- Data in Transit: 100% of data transmissions are encrypted using TLS 1.3 with AES-256-GCM cipher suites.
- Data at Rest: Database volumes are encrypted with AES-256 keys, and sensitive tokens utilize SHA-256 salted hashing.
- Access Segregation: Role-based access control (RBAC) isolates student records, teacher evaluation workspaces, and administrative oversight modules.
4. Data Retention & Automatic Purging Policy
In accordance with academic accountability standards and the Digital Personal Data Protection (DPDP) Act:
- Proctoring Audit Artifacts: Any temporary verification snapshots or anomaly records are automatically purged 90 days following the official certification of results.
- Merit Ranks & Certificates: Digital transcripts and certificates remain accessible for institutional verification until the candidate requests profile deletion.
5. Candidate & Institutional Rights
Every candidate or sponsoring educational institution retains the following rights:
- Right to Access & Rectify: Request an export of your examination attempts and correct any academic profile discrepancies prior to test execution.
- Right to Grievance Redressal: Contest any automated proctoring disqualification through our 24Ã12 examination support desk within 48 hours of test completion.
- Right to Erasure: Delete personal account credentials post completion of enrolled academic terms, subject to statutory exam audit requirements.
6. Data Protection Officer & Grievance Redressal
If you have inquiries regarding privacy practices, proctoring data handling, or wish to exercise statutory rights, please contact our designated Grievance Officer: