Privacy Policy
Effective Date: 26 May 2026
Last Updated: 17 June 2026
Policy Version: 1.7
1. Introduction and Scope
KarmaPSC Coaching ("KarmaPSC", "Platform", "Academy", "we", "our", or "us") operates educational coaching services, online mock test systems, assessment paper systems, learning portals, communication channels, and associated digital infrastructure accessible through karmapsc.com, including the learning portal at karmapsc.com/learn and the link infrastructure at qr.karmapsc.com.
This Privacy Policy governs the collection, processing, storage, usage, disclosure, transfer, retention, and protection of personal data in compliance with:
- Digital Personal Data Protection Act, 2023
- DPDP Rules, 2025
- Information Technology Act, 2000
- Consumer Protection Act, 2019
- Applicable Indian cyber-security and contractual regulations
By accessing or using the Platform, the User acknowledges having reviewed, understood, and consented to the practices described in this Policy.
2. Data Fiduciary, Grievance Officer and Data Protection Contact
- Entity: KarmaPSC Coaching
- Official Office Address: KarmaPSC Coaching, Varkala, Thiruvananthapuram, Kerala, India, 695145
- Grievance Officer & Data Protection Contact: Sidharth D. The Grievance Officer is also the designated person to answer questions on behalf of KarmaPSC Coaching about the processing of your personal data.
- Email: care@karmapsc.com
- Response Timeline: Acknowledgment within 72 hours; full resolution or final response within 30 calendar days.
3. Consent and Legal Basis
Personal data is processed solely on the basis of explicit, affirmative, informed, and freely provided consent, or where processing is otherwise legally permitted under Indian law.
Where students register or are enrolled through the Platform, a mandatory acknowledgment checkbox is presented to confirm agreement with these Terms, the Privacy Policy, and the Cookie Policy before registration is completed.
Public users aged 13 or older may create a public account using Supabase Auth with email/password, phone/password, phone-triggered OTP, or Google login. Public onboarding requires a phone number and affirmative acceptance of the Terms of Service and Privacy Policy before dashboard, analytics, rankings, and saved mock test features are unlocked. We store only the acceptance timestamp and policy version for this consent record. Email confirmation, confirmation resend, and password reset flows are handled through Supabase Auth and our transactional email delivery provider.
Registered students may securely link their official student profile to the same Supabase Auth login used for public access. Linking is restricted to a single student profile to prevent duplicates. Once linked, new quiz, learning progress, and analytics writes are saved to the student profile by default, while the previous public profile is kept as a read-only archived profile.
Dual-Profile Association and Public Archiving: A user may have one Supabase Auth identity with both a public profile and an official student profile. These profiles remain separate for reporting and retention. When the student profile is linked, old public attempt history is not bulk-imported or deleted by default; it remains read-only. If the student link is removed, the public profile can be restored for future public writes.
Public users may separately opt in to receive course updates, offers, and counselling messages by WhatsApp, phone call, SMS, or email. This marketing consent is optional, is not required to create or use a public account, and can be withdrawn from the public dashboard account settings or by contacting care@karmapsc.com.
Consent requests are presented separately from these Terms and are capable of being withdrawn at any time, with the ease of doing so being comparable to that with which such consent was given (e.g., via the dashboard settings or by contacting care@karmapsc.com). Withdrawal of consent shall not affect the legality of processing undertaken prior to such withdrawal.
Non-essential analytics, tracking technologies, and optional cookies remain disabled until explicit consent is provided by the User through the cookie consent interface.
Strictly necessary processing — including session management, authentication, security operations, and infrastructure delivery through Cloudflare and Vercel — does not require separate opt-in consent as it is essential for Platform operation.
4. Categories of Personal Data
- Identity information including name, student profile details, date of birth (which is securely stored in our Supabase database to verify identity and confirm user age), and linked Google account credentials (including Google email and unique Google ID if a student profile is connected).
- Contact information including mobile number and email address. Connecting a Google account syncs the primary contact email by default, though students can separately update their communication email in Settings. For public accounts, the phone number is stored as profile metadata. For users who log in via phone OTP, the phone number is used to securely look up and route the one-time password to the underlying linked email address without exposing the email in the login interface.
- Authentication credentials and session identifiers, primarily Supabase Auth session identifiers used for email/password, phone/password, OTP, and Google login.
- Public profile information including full name, email, phone, avatar URL where provided by Google, authentication provider, public user type, account creation timestamp, and Terms/Privacy acceptance timestamps and versions. Public signup and login may also involve email confirmation, confirmation resend, password reset, and OAuth callback metadata required to complete account security flows.
- Optional marketing consent records for public users, including consent status, consent timestamp, consent version, consent source, selected communication channels, and withdrawal timestamp where applicable.
- Special Protection for Minors verification: We collect and process
date_of_birthto identify if a student is under 18 years of age (a minor) and strictly enforce the special protections required under Section 9 of the DPDPA, 2023. - Mock test responses, assessment paper responses, performance metrics, score records, ranking data, and academic progress records. Public mock test attempts and public analytics are stored separately from institute student records. To protect user privacy, all student rankings and leaderboards (both batch-level and public pools) are fully anonymized (e.g. displaying "Student (ID ending 1234)" or "Public user" instead of full names).
- Device information, browser metadata, IP address, operating system, and technical diagnostics processed by the Platform and its infrastructure providers
- Communication records involving WhatsApp Business (manual, without API), email, or support requests submitted through the contact form
- Cookie identifiers and analytics metadata
- Short-lived technical cache records used to improve dashboard and analytics speed, including request-level server memoization, short Next.js route revalidation windows, and in-process analytics refresh debounce markers. These caches are used to reduce repeated database calls and are not used for advertising profiling.
- Payment confirmation records for offline payments made through cash or UPI-based methods (receipt and transaction reference data only; KarmaPSC Coaching does not process card data or operate an online payment gateway at this time)
5. Data Retention and Deletion
Personal data is retained only for the duration necessary to fulfil operational, legal, academic, contractual, security, and compliance purposes.
- Active student records: duration of enrollment + 3 years
- Mock test and assessment paper history: enrollment duration + 180 days
- Public account profile records and saved public mock test analytics: while the account remains active, unless deletion or legal retention requirements apply
- Analytics metadata: up to 26 months
- Security and audit logs: up to 24 months
- Payment acknowledgment and receipt records: as required by applicable financial and tax regulations
Upon receiving a valid erasure request, production database records are deleted or anonymised within a reasonable operational period. Backup archives may retain encrypted copies for up to 30 days before automatic overwrite cycles permanently destroy residual data.
Where the specified purpose for processing is deemed no longer served and the data is no longer necessary for legal or compliance purposes, KarmaPSC Coaching shall erase the personal data. In such instances, we will inform the User at least 48 hours prior to the erasure, unless the User logs into their account or otherwise initiates contact before the completion of the period.
Public users may delete their public accounts at any time from the account settings area, which deletes their public profile, saved mock test attempts, and related data. Deleting a public account triggers a full sign-out (clearing both the student session and Supabase session cookies) but does not delete official institute student coaching records, mock test histories, or enrollment details, which are retained separately for contractual, academic, and legal compliance purposes.
6. Security Safeguards
- TLS-encrypted communications
- Secure session cookies
- Access-controlled administrative dashboards
- Credential isolation and secure session management
- Rate limiting and abuse detection systems
- Suspicious-login monitoring
- Cloudflare Web Application Firewall and DDoS protection at the network layer
- Cloudflare Turnstile bot detection on the contact form to prevent automated abuse
- Infrastructure-level cloud security protections
No internet-based system can be guaranteed completely secure, and the Platform disclaims absolute security guarantees.
6.1 Personal Data Breach Notification
In the event of a personal data breach, KarmaPSC Coaching will, without delay and within 72 hours of becoming aware, notify the Data Protection Board of India (DPBI) and intimate affected Data Principals. The notification to Data Principals will be made in a concise and clear manner through the user account or registered communication mode, and will include a description of the breach, likely consequences, mitigation measures taken, safety steps the user can take, and business contact information for queries.
7. Third-Party Processors and Infrastructure
The Platform utilizes carefully selected third-party infrastructure providers operating under contractual processing restrictions. All processors are prohibited from independently exploiting student data for unrelated commercial purposes.
7.1 Core Infrastructure
- Cloudflare, Inc.: All traffic to karmapsc.com and its subdomains, including qr.karmapsc.com, is routed through Cloudflare's global network. Cloudflare provides content delivery, DDoS protection, web application firewall services, and domain security. Cloudflare processes IP addresses, request headers, and behavioral data as part of its security operations. Cloudflare also provides the email routing infrastructure used for care@karmapsc.com. Cloudflare automatically sets certain strictly necessary cookies as part of its CDN and bot-management services. Cloudflare's privacy policy governs its own processing practices.
- Cloudflare Turnstile: The contact form uses Cloudflare Turnstile to distinguish human users from automated bots. Turnstile processes device signals, browser metadata, and IP-level information for this purpose. It is activated only when the User opens the contact form. Turnstile does not set a persistent tracking cookie. This processing is strictly necessary for contact form security.
- Vercel, Inc.: The main karmapsc.com website is hosted on Vercel's edge hosting infrastructure. Vercel processes request data including IP addresses and request headers for operational and security purposes.
- Supabase: Institute student database operations, public email/password authentication, Google OAuth session handling, public profile storage, and structured analytics data operations are handled through Supabase infrastructure. Supabase Auth also manages email confirmation, resend confirmation, and password reset token flows.
- Resend: Transactional email delivery for public account confirmation and password reset messages may be sent through Resend SMTP. Resend processes email addresses, delivery metadata, and the content of transactional emails solely for email delivery, reliability, abuse prevention, and related operational purposes.
- Amazon Web Services (Mumbai Region): Cloud hosting infrastructure is operated through AWS in the Mumbai region, keeping data within India.
- Google Firebase: Used specifically for our internal, administrative offline receipt and bill generator app. When an offline student makes a payment, the administrator inputs receipt data locally on their device, and this data is uploaded to Firebase Firestore and Firebase Storage. This data includes student details and receipt/bill numbers and is accessible only to authorized administrators for accounting and record-keeping purposes.
7.2 Analytics
- Google Analytics: Analytics and traffic insights are processed through Google Analytics, and only where the User has explicitly opted in through the cookie consent interface. Analytics data is not collected from users who have not granted analytics consent.
7.3 Future Processors
The Platform may introduce additional third-party services in the future, such as video hosting providers or online payment processors. This Policy will be updated before any such processor is introduced, and consent will be obtained as required.
8. Communication Channels
The Platform may utilize WhatsApp Business, Telegram Channels, email systems, or other communication infrastructure for academic coordination and announcements. WhatsApp Business is used manually without API-based automation; no automated data processing or profiling is conducted through WhatsApp by KarmaPSC Coaching.
Transactional emails, including public account confirmation, confirmation resend, password reset, and security messages, may be delivered through Supabase Auth and Resend SMTP. These messages are necessary for account security and are not marketing messages.
Promotional course updates, offers, and counselling outreach to public users by WhatsApp, phone call, SMS, or email are sent only where optional marketing consent has been provided. Users may withdraw this consent from public account settings or by contacting care@karmapsc.com.
Users acknowledge that third-party messaging platforms maintain independent privacy practices outside the control of KarmaPSC Academy. Users should review the privacy policies of those platforms separately.
Public disclosure of another student's phone number, profile data, or personal information without authorization is strictly prohibited.
Email received at care@karmapsc.com is routed through Cloudflare's email routing service and forwarded to the designated recipient.
9. Subdomains and QR Infrastructure
qr.karmapsc.com is operated by KarmaPSC Coaching as a link and QR code infrastructure subdomain used to distribute resource links and academic references. All traffic through this subdomain is routed through Cloudflare's infrastructure and is subject to the same data handling practices as the main Platform.
Visit data through qr.karmapsc.com may be recorded through the Platform's standard analytics systems where analytics consent has been granted by the User.
The Platform may introduce additional subdomains in the future for user account management or other features. This Policy will be updated to reflect those additions before they are launched.
10. Offline Payment Data
KarmaPSC Coaching currently accepts course fees offline through cash or UPI-based payment methods. KarmaPSC Coaching retains payment acknowledgment and receipt records, including transaction reference numbers where applicable, for accounting and compliance purposes.
For offline students, we utilize an internal administrative offline receipt and bill generator application. When a payment is processed, the administrator enters the receipt data, which is saved locally on the administrator's device and then securely uploaded to Firebase Firestore. Associated details about the student and the receipt/bill number are stored in Firebase Storage. This data is strictly accessible only to authorized administrators.
KarmaPSC Coaching does not operate an online payment gateway and does not process card numbers, bank credentials, or online payment data through the Platform at this time. If online payment capabilities are introduced in the future, this Policy will be updated accordingly and the relevant payment processor will be disclosed.
11. Data Principal Rights
Under the Digital Personal Data Protection Act, 2023, Users have the following rights with respect to their personal data:
- Right to access personal data held by the Platform.
- Right to correction of inaccurate or outdated data.
- Right to erasure of data where processing is no longer necessary or consent is withdrawn.
- Public users may delete their public account from the dashboard settings area. Data export is not offered as a self-serve button in the dashboard, but legally required access or portability requests may be submitted to care@karmapsc.com.
- Right to grievance redressal through the Grievance Officer, with the right to complain to the **Data Protection Board of India (DPBI)** if dissatisfied.
- Right to withdraw consent at any time, with a comparable ease of withdrawal as the ease of providing it.
- Public users may unsubscribe from optional course updates and promotional contact from the dashboard account settings area.
- Right to nominate another individual to act on their behalf to exercise these rights in the event of death or physical/mental incapacity. Such nomination can be made by submitting a written request to care@karmapsc.com.
To exercise any of these rights, contact care@karmapsc.com. Requests will be acknowledged within 72 hours and addressed within 30 calendar days.
12. AI Training and Automated Extraction Restrictions
Users, bots, crawlers, automated systems, scraping tools, AI training systems, and machine-learning pipelines are prohibited from extracting, reproducing, indexing, or processing Platform content for model training or dataset generation without prior written authorization from KarmaPSC Coaching.
13. Minors and Special Protections
Where a student is below 18 years of age, enrollment requires co-authorization by a parent or guardian, who must sign the offline Admission Terms and Conditions. KarmaPSC Coaching observes due diligence to verify that the individual identifying as the parent is an identifiable adult (e.g., via offline identity verification). This constitutes the verifiable parental consent required under Section 9 of the DPDPA, 2023.
Public accounts are intended for users aged 13 or older. Public users under 18 should use the Platform with parent or guardian involvement. Public onboarding is designed to collect minimal personal data and keeps public account records separate from institute student records.
In strict compliance with Section 9 of the DPDPA, 2023, KarmaPSC Academy does not engage in any tracking, behavioral monitoring, profiling, or targeted advertising of children or minors (users under 18 years of age) on the Platform. All optional analytics tracking remains completely disabled for minor accounts, and no personal data is processed in a manner that is likely to cause any detrimental effect on the well-being of the child.
14. Material Changes and Re-Consent
Material modifications involving processing purposes, retention periods, communication practices, infrastructure providers, or student rights may require renewed consent before continued processing.
The Platform may notify Users through dashboard notices, email, WhatsApp, Telegram, or other communication channels regarding updates. The most current version of this Policy will always be posted at karmapsc.com/privacy with an updated date and version number.
15. Contact, Grievances, and Data Protection Inquiries
Privacy-related concerns, access requests, correction requests, deletion requests, consent withdrawals, queries about the processing of personal data, or grievances may be directed to our Grievance Officer:
KarmaPSC Coaching — Grievance Officer (Sidharth D)
Official Office Address: KarmaPSC Coaching, Varkala, Thiruvananthapuram, Kerala, India, 695145
Email: care@karmapsc.com
We will acknowledge your grievance or request within 72 hours and resolve it expeditiously, and in any event within 30 calendar days.
If you do not receive a response within the designated time frame, or if you are dissatisfied with the resolution provided by our Grievance Officer, you have the statutory right under the DPDPA, 2023 to file a complaint with the Data Protection Board of India (DPBI) in the manner prescribed by the Board.
View our Terms of Service and Cookie Policy.