Effective date: 16 September 2026 · Last updated: 16 September 2026
This page explains, specifically, how Student Sewa (operated by Urban Pulse Innovations Private Limited) complies with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025. It supplements, and should be read together with, our Privacy Policy and Terms and Conditions. Where this page and the Privacy Policy describe the same thing differently, this page is the more detailed, technical version.
We are publishing this separately because "DPDP by design" is a claim we make prominently on our homepage, and we think a claim like that should be backed by a page that says exactly what it means, not just a badge.
1. Our role and identity
Under the DPDP Act, Student Sewa acts as a Data Fiduciary for the personal data of students, alumni, teachers, and other users who create accounts with us, and as a Data Processor in limited cases where we process data strictly on the instructions of an institution or government partner (for example, delivering a notice to a list of enrolled students that an institution has confirmed).
- Registered entity: Urban Pulse Innovations Private Limited
- CIN: U56290DL2024PTC433574
- Grievance Officer / Data Protection contact: Tanuj Varshney, reachable at privacy@studentsewa.in and G-10, Second Floor (Rear), South Extension Part 2, New Delhi 110049, India
Significant Data Fiduciary status is notified by the Central Government based on factors including the volume and sensitivity of personal data processed, risk to electoral democracy, security of the state, and public order. We do not believe Student Sewa meets that threshold at pilot scale. This is revisited as the user base grows — see Section 9 for what changes if it does.
2. Principles we follow
- Lawfulness, fairness, and transparency — we process personal data only on a valid legal basis (your consent, or a "certain legitimate use" recognised under the Act) and tell you what we are doing with it.
- Purpose limitation — data collected for one purpose (say, matching you to a scholarship) is not repurposed for an unrelated one (say, selling it to an advertiser) without asking again.
- Data minimisation — we collect the minimum needed. We do not ask for your marks, transcripts, or full academic record to match you to a scholarship; course, year, state, and category are usually enough.
- Accuracy — you can correct inaccurate data at any time (Section 8).
- Storage limitation — we keep data only as long as needed (Section 6) and delete or anonymise it after.
- Security by design — described in Section 7.
- Accountability — this page, our Privacy Policy, and our internal records exist so we can demonstrate compliance, not just assert it.
3. How we obtain and record consent
- Consent requests are presented as a standalone, itemised notice in plain language — not bundled into a long, unrelated document — stating what data is collected, for what purpose, and for how long it will be used.
- We do not use pre-ticked boxes, bundled consent, or dark patterns. Declining a specific consent does not silently block unrelated features unless that data is genuinely required for them.
- Consent can be withdrawn as easily as it was given, from within the app or by writing to us, and withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- We keep a record of what was consented to and when, so we can demonstrate compliance if asked, and so a Consent Manager (see Section 10) can eventually interoperate with our records.
- Notices are available in English. Our on-page translation into other languages runs through Google Translate, which is a convenience translation and not the legally operative version of the notice. TO SUPPLY: which languages the consent notice itself is human-reviewed in
4. Children’s data
What the law requires (Section 9, DPDP Act)
- Verifiable consent from a parent or lawful guardian, obtained *before* any personal data of a child is collected — not a checkbox, an unverified email, or a self-declared age field. Accepted verification methods under the Rules include Aadhaar-based identity verification of the parent (via DigiLocker), a parent’s own verified digital identity, or another government-approved method.
- No processing likely to cause detriment to the child’s wellbeing — physical, mental, social, educational, or moral — even with consent.
- Absolute prohibitions, regardless of consent: no tracking of a child’s activity across the Platform to build a behavioural profile, no behavioural monitoring, and no targeted advertising based on a child’s data or inferred behaviour. Only generic, non-targeted content may be shown.
- Limited exemptions exist for specific protective purposes (for example, a school-facilitated safety or welfare process), but these do not extend to the tracking, monitoring and advertising prohibitions above, which are absolute.
What we do about it
- No account is opened for anyone under 18 today. School onboarding stays closed until a verifiable parental consent mechanism is live, rather than opening on a self-declared age field and being repaired afterwards.
- The mechanism being built is: TO SUPPLY: the parental consent mechanism, once chosen
- An account is identified as belonging to a child by: TO SUPPLY: how date of birth or school stage is captured at verification
- No account we know or believe to belong to a child is tracked, behaviourally profiled, or shown targeted content, regardless of what any consent says. Anything a child sees — offers, courses, notifications — is shown from their stated course, year and location, never from inferred behaviour.
If you are a parent or guardian and believe your child holds an account or has provided personal data without your consent, write to privacy@studentsewa.in and we will investigate and delete the data where appropriate.
5. Category and income data
The DPDP Act does not create a separate "sensitive personal data" category the way some other privacy laws do, but social category (General/OBC/SC/ST/EWS) and family income are exactly the kind of information that can cause real harm if mishandled, and we treat them accordingly:
- Collected only where a specific scheme’s eligibility criteria requires it, never as a default profile field.
- Used only to compute scholarship and scheme matches, then discarded from active matching use once the relevant window has passed, per the retention schedule in Section 6.
- Never shared with businesses, employers, institutions, or any advertiser, in individual or identifiable form.
- Access within our own team is restricted to those who need it to build or maintain the matching feature, not available broadly.
6. Data retention and erasure
| Data type | Retained until | Then |
|---|---|---|
| Verification documents (ID upload and similar) | Verification is confirmed, or annually at renewal | Securely deleted; only the verification result (tier, expiry) is kept |
| Category and income data used for scheme matching | The relevant application or eligibility window closes, or account deletion | Deleted or anonymised |
| Account profile (name, contact, course, year) | Account is active, or TO SUPPLY: months of inactivity after last login | Deleted or anonymised after an inactivity notice |
| Teacher payment and financial records | As required under applicable tax and company law | Deleted after the statutory retention period |
| Server and access logs | TO SUPPLY: log retention period | Deleted |
| Grievance and complaint records | TO SUPPLY: grievance record retention period | Deleted or anonymised |
Before deleting data tied to an inactive account, we make reasonable efforts to notify the user first, consistent with the notice period required under the Rules.
7. Security safeguards
- Encryption of personal data in transit and at rest.
- Role-based access controls, so that category and income data used for scholarship matching is not visible to staff working on the business and discounts side of the Platform.
- Logging and monitoring to detect unauthorised access.
- Due diligence on service providers who process data on our behalf (hosting, translation, payments, analytics), including contractual commitments that they will not use the data for their own purposes.
- Additional measures in place: TO SUPPLY: penetration testing cadence, access training, incident response plan, vendor list
8. Your rights and how we handle requests
As described in our Privacy Policy, you can request access, correction, or erasure of your data, and withdraw consent, at any time by writing to privacy@studentsewa.in. We will:
- Acknowledge your request promptly.
- Verify your identity before acting on it, so that we do not disclose or delete the wrong person’s data.
- Respond within the timeline prescribed under the DPDP Rules for that type of request: TO SUPPLY: the prescribed response timeline, confirmed with counsel
- Where we cannot fulfil a request — for example, deleting a financial record we are legally required to retain — tell you why.
If you are not satisfied with our response, you may approach the Data Protection Board of India.
9. If we become a Significant Data Fiduciary
Should Student Sewa be notified as a Significant Data Fiduciary as our user base grows, we commit to:
- Appointing a Data Protection Officer based in India, whose contact details will be published here.
- Appointing an independent data auditor.
- Conducting an annual Data Protection Impact Assessment and periodic compliance review.
- Sharing significant findings with the Data Protection Board as required.
10. Consent Managers
The DPDP framework provides for registered, independent Consent Managers — platforms that let you manage your consent across multiple organisations from one place. As that ecosystem comes online, we intend to make our consent records interoperable with a registered Consent Manager, so you are not limited to managing your Student Sewa consent only through us. This section will be updated once that integration is live.
11. Cross-border data transfer
Personal data is currently stored TO SUPPLY: where data is stored, and any cross-border arrangement. Where any personal data is transferred outside India — for example, through a global cloud or analytics provider — we do so only where such transfer is permitted under the DPDP Act and any restrictions notified by the Central Government, and under contractual protections with that provider.
12. Data breach notification
In the event of a personal data breach, we will:
- Notify the Data Protection Board of India, with a detailed report provided within the timeline required under the Rules: TO SUPPLY: the prescribed breach reporting timeline, confirmed with counsel
- Notify affected users without delay, describing what happened, what data was involved, and what we are doing about it.
- Take immediate steps to contain the breach and prevent recurrence.
13. Review of this policy
We review this page at least annually, and whenever the DPDP Rules are updated or our processing activities change materially — for example, launching a feature that collects a new category of data, or being notified as a Significant Data Fiduciary.
14. Contact
- Grievance Officer / Data Protection contact: Tanuj Varshney
- Email: privacy@studentsewa.in
- Registered office: G-10, Second Floor (Rear), South Extension Part 2, New Delhi 110049, India