Scope and responsibility
This Policy applies to Evalat public pages, registration, role-based workspaces, mobile or progressive-web-app experiences, support, public profiles, certificate verification, subscriptions, identity verification, and other services that link to it. It does not govern an independent third-party website or service.
Urjasoft and institutions
Urjasoft determines the purposes and means of processing for direct accounts, platform security, product operations, billing, support, provider management, and public services. For institution-controlled learner, educator, assessment, or monitoring data, the institution may separately determine why the data is processed and may act as a data fiduciary or controller under applicable law, while Urjasoft processes the data to provide the contracted service. An institution must give its own notices and obtain any authorization or consent it is responsible for. This Policy does not replace an institution's privacy notice.
Applicable framework
Urjasoft processes personal data for lawful purposes under applicable Indian law, including the Information Technology Act, 2000 and rules made under it, and the Digital Personal Data Protection Act, 2023 and Rules as their relevant provisions come into force. Mandatory rights and obligations apply according to their legal commencement and scope.
Personal data we collect
| Category | Examples | When collected |
|---|---|---|
| Account and contact | Name, email, phone, password hash, role, account status, email verification, guardian contact hash | Registration, login, account recovery, support |
| Institution and education | Institution membership, invite or join records, groups, educator/student identifiers, subjects, profile details | Workspace onboarding and administration |
| Assessment content | Questions, diagrams, rubrics, exams, assignments, answers, scratchpad content, marks, feedback, results, certificates | Authoring, delivery, evaluation, and reporting |
| Integrity and security | Login events, sessions, IP address, user agent, rate-limit events, audit actions, heartbeat, focus, fullscreen, and network warnings | Security and monitored assessments |
| Billing and tax | Plan, order, invoice, amount, currency, GST or tax details, payment status, provider and transaction reference | Checkout, renewal, refund, and accounting |
| Communications | Support tickets, contact forms, announcements, notification choices, email delivery events, feedback | Support and service communication |
| Public profile choices | Username, role, biography, expertise, social links, selected achievements and visibility controls | Only when a user creates or publishes a profile |
| Technical and preference | Requested URL, timestamps, browser/device type, theme, layout choices, consent choice, optional public-page analytics | Use of the website or workspace |
Fields marked required are needed for the stated workflow. Optional fields can be omitted, but the related feature may be unavailable or less useful.
Sources, purposes, and lawful processing
We receive data directly from you; from a parent or lawful guardian; from an authorized institution, educator, or platform operator; from your device and use of Evalat; and from providers you choose to authorize, such as Google, a payment gateway, Cashfree Secure ID, or DigiLocker.
We use personal data to:
- create, authenticate, recover, and secure accounts and role-based workspaces;
- deliver assessments, save attempts, support monitoring, evaluate submissions, publish authorized results, and verify certificates;
- manage institution membership, permissions, subscriptions, invoices, usage limits, notifications, and support;
- detect fraud, cheating signals, security incidents, misuse, and service failures and maintain required audit trails;
- provide features you request, including Google sign-in, public profiles, identity verification, and AI-assisted workflows;
- meet tax, accounting, consumer-protection, legal, regulatory, dispute, and lawful-government-request obligations;
- improve reliability, accessibility, and public-page performance using aggregated operations data and optional analytics where consent is required.
Depending on the activity and applicable law, processing is based on your consent, steps taken at your request, performance of the service agreement, a permitted legitimate use, an institution's lawful instruction, or a legal obligation. Consent can be withdrawn prospectively, but withdrawal does not invalidate lawful processing already completed.
Specific and sensitive workflows
Aadhaar identity verification
Where enabled and required for a protected purpose, Evalat offers an optional Aadhaar verification route through Cashfree Secure ID and DigiLocker. Evalat does not ask you to type a full Aadhaar number or Aadhaar OTP into Evalat. Cashfree and DigiLocker process the authorization and document retrieval under their own notices and controls.
After separate, purpose-specific consent, a registered name may be used transiently to match the account. Evalat retains only the provider reference and status, consent and audit record, and, when available, a masked Aadhaar ending displayed only as "XXXX XXXX 1234". Evalat does not intentionally retain the full Aadhaar number, Aadhaar OTP, DigiLocker Aadhaar document, address, date of birth, photograph, biometrics, or full provider document response. An operator-assisted alternative can be requested. Withdrawing identity consent cancels the active verification state and removes the retained masked ending, subject to security, dispute, and legal retention.
Payments
An enabled payment gateway processes payment-instrument details on its own secured flow. Evalat does not require or intentionally store your full card number, CVV, card PIN, UPI PIN, or online-banking password. Urjasoft receives transaction references, status, amount, invoice, refund, and reconciliation records needed to provide and account for the purchase.
Google sign-in
If you choose Google sign-in, Evalat requests OpenID profile, verified email, and basic profile information needed to create or link the account. Evalat does not store your Google password. Google applies its own privacy terms to the authorization flow.
Assessment monitoring
When an authorized educator or institution enables monitoring, Evalat may record attempt heartbeat, focus changes, fullscreen events, network state, timestamps, and warnings for human review. Current Evalat monitoring does not collect camera, microphone, biometric, or precise location data. A monitoring signal is not treated as conclusive proof of misconduct.
AI-assisted processing
Content entered into an AI workflow, relevant context, generated output, model/provider reference, token usage, latency, and error information may be processed to deliver, secure, meter, and audit the request. The configured provider may process the submitted content on Urjasoft's behalf or under its applicable provider terms. Users should not enter unnecessary personal, confidential, identity, financial, or children's data. AI output remains subject to authorized human review and is not the sole basis for a consequential academic decision.
Public profiles and certificates
A public student or educator profile is indexed or displayed only according to its visibility controls. Public fields can be seen, shared, cached, or indexed by third parties. Private attempts, answers, learning notes, identity records, billing records, and security logs are not part of a public profile. Certificate verification displays only the details needed to validate an issued certificate.
Who receives personal data
Urjasoft does not sell or trade personal data. We disclose only what is reasonably necessary to:
- authorized users in the same institution or workflow, according to role permissions;
- hosting, database, storage, backup, email, notification, support, and security providers;
- configured AI providers, which may include self-hosted models or approved cloud providers selected by Urjasoft platform operations;
- Google for OAuth authorization; Cashfree Secure ID and DigiLocker for an identity flow you authorize; and an enabled payment gateway such as Cashfree, PhonePe, or Stripe for a transaction;
- optional Google Analytics, Google Tag Manager, Microsoft Clarity, or Meta measurement services only when configured and the relevant browser consent has been granted;
- professional advisers, auditors, insurers, investors, or acquirers under confidentiality and only for a legitimate corporate purpose;
- courts, regulators, law-enforcement bodies, or other authorities where disclosure is required or permitted by lawful process.
Provider availability differs by deployment and feature. Listing a supported provider does not mean it receives your data in every session. The applicable provider is used only when configured and relevant to the workflow.
Retention, deletion, and safeguards
We retain data only for as long as it is needed for the stated purpose, an active account or institution contract, assessment and certificate integrity, security and audit review, billing and tax records, dispute resolution, backup recovery, or a legal requirement. Retention is determined by the record type, user and institution instructions, statutory period, risk of fraud or dispute, and whether a record can be safely deleted or de-identified.
- Session and temporary attempt data expires or is deleted according to its operational lifecycle.
- Account, assessment, result, and certificate records remain while the relevant account, institution, or verification purpose is active, then enter the applicable deletion or de-identification process.
- Billing, tax, audit, fraud-prevention, consent, and legal records may be retained for the period required by law or needed to establish, exercise, or defend a claim.
- Backups rotate on a protected schedule. A deleted record may remain temporarily in a backup until that backup expires and will not be restored for ordinary use.
Safeguards include access policies, protected and expiring sessions, password hashing, CSRF and rate-limit controls, encryption of configured secrets, signed webhooks, audit trails, restricted operator actions, secure transport in production, and provider-access controls. No internet service can guarantee absolute security. Users must protect their credentials and report suspected compromise promptly.
Your choices and privacy rights
Subject to applicable law and any valid exception, you may:
- request a summary of personal data being processed and relevant sharing;
- correct, complete, or update inaccurate personal data;
- request erasure when the purpose has ended and retention is not otherwise required;
- withdraw consent as easily as it was given, including identity and optional cookie consent;
- object to or opt out of promotional communication;
- raise a grievance and receive a reasoned response;
- nominate another person to exercise applicable rights in the event of death or incapacity, where that statutory right applies.
Submit a request through the contact form or email contact@urjasoft.com with the subject "Evalat Privacy Request". Include the account email, institution if relevant, request type, and enough detail to locate the record. We may verify identity and authority before acting. If an institution controls the data, we may refer the request to that institution or coordinate the response with it.
Withdrawal may make an account or feature unavailable where the processing is necessary to provide it. It does not require deletion of records that Urjasoft or an institution must retain for assessment integrity, security, tax, dispute, or legal reasons.
Children and learners under 18
A parent or lawful guardian must authorize a learner under 18 to register directly and to begin an optional identity-verification flow. Institutions are responsible for age-appropriate notices and required guardian authorization when they onboard or assess children. Evalat does not knowingly use children's data for targeted advertising, behavioral profiling, or processing likely to cause detrimental effects on a child's well-being.
A guardian who believes a child registered without proper authorization should contact Urjasoft. We will verify the request and restrict or remove the data where appropriate, while preserving records that must remain for safety, legal, or assessment-integrity reasons.
International transfers, legal disclosures, and incidents
Evalat is India-centered, but a configured cloud, email, analytics, support, or AI provider may process data in another country. Urjasoft uses contractual, access, minimization, and provider-security controls appropriate to the service and follows any transfer restriction notified under Indian law. Local or self-hosted providers may be used where configured.
We may preserve or disclose information in response to a valid legal request, to protect users and the service, to investigate fraud or security incidents, or to establish or defend legal claims. Requests are reviewed for authority, scope, and necessity.
If a personal-data breach creates a notification obligation, Urjasoft will investigate, contain, document, and notify affected people and the appropriate authority in the form and timeframe required by applicable law.
Cookies, marketing, and browser choices
Essential cookies and local storage keep sessions, security, consent, theme, and requested workspace preferences working. Optional public-page analytics and marketing tags are not loaded unless configured and the relevant consent is present. Review or change choices on the Cookie Policy page. Rejecting optional cookies does not prevent account or assessment use.
Service and security messages are necessary account communications. Promotional messages are optional and can be stopped using the message controls or by contacting Urjasoft. We do not sell personal data or share it for another party's direct marketing without the required permission.
Changes to this Policy
We may update this Policy for legal, product, provider, or security changes. The effective date will change and material changes will be communicated through Evalat or registered contact details. Where a new purpose requires consent, we will request it rather than relying only on continued use.
Privacy and grievance contact
Urjasoft Enterprises Pvt. Ltd. - Evalat
CIN: U74999DL2016PTC307516
B-8, Basement Floor, Sector-2, Noida 201301, India
Email: contact@urjasoft.com
Phone: +91 767 864 9274
We aim to acknowledge a grievance within 48 hours and resolve it within one month, or sooner where applicable law requires. If the response does not resolve a statutory privacy complaint, you may use the escalation available under applicable law, including the Data Protection Board of India when the relevant provisions apply. Consumer remedies remain available through the competent consumer forum.