NoventraqNoventraq

Privacy Policy

Last updated: March 1, 2026

1. Introduction

Noventraq ("we", "our", "us") is committed to protecting the privacy of universities, their staff, students, and parents who use our platform. This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian laws.

2. Data We Collect

We collect the following categories of data:

  • Institution Data: University name, address, affiliation, accreditation details.
  • User Data: Names, email addresses, phone numbers, and roles of staff using the platform.
  • Student Data: Enrollment details, academic records, attendance, fee payment records — as entered by the institution.
  • Usage Data: Log data, feature usage analytics, and platform interaction data.
  • Contact Form Data: Name, email, phone, and university name submitted via our demo request form.

3. How We Use Your Data

  • To provide and maintain the Noventraq platform and its services.
  • To generate compliance reports (NAAC, NBA, UGC) as requested by the institution.
  • To integrate with government systems (DigiLocker, ABC ID, NAD) on behalf of the institution.
  • To send service-related notifications and support communications.
  • To improve our platform through anonymised usage analytics.

4. Data Storage & Security

All data is stored exclusively in Indian data centres. We use AES-256 encryption at rest and TLS 1.3 encryption in transit. Access is controlled via role-based permissions and multi-factor authentication. We conduct quarterly security audits and penetration testing.

5. Data Sharing

We do not sell personal data to third parties. Data may be shared with government platforms (DigiLocker, NAD) only when explicitly initiated by the institution. We may use sub-processors for infrastructure (cloud hosting, email delivery) — all bound by data processing agreements.

6. Data Retention

We retain institutional data for the duration of the subscription and for 90 days after termination to allow for data export. After this period, data is permanently deleted. Institutions may request immediate deletion at any time.

7. Your Rights

Under the DPDPA 2023, data principals have the right to access, correct, and erase their personal data. Institutions may exercise these rights on behalf of their users. To make a request, contact us at privacy@noventraq.com.

8. Contact Us

For any privacy-related questions, reach out to our Data Protection Officer at privacy@noventraq.com.