Privacy Policy
What we collect, why, who processes it, how long we keep it, and the rights you have over it under the DPDP Act.
Version 1.0 · Effective [EFFECTIVE DATE]
We verify identity against government records and record people speaking about safeguarding children. That is sensitive material, and this policy is specific about it rather than general.
For the purposes of the Digital Personal Data Protection Act, 2023, [LEGAL ENTITY NAME] is the Data Fiduciary for the personal data described here, and you are the Data Principal.
1What we collect
You give us
- Your email address, used to sign in, to send your certificate and to remind you about renewal.
- Your coaching background — sport, years coaching, city, employment type, organisation, age groups, languages you can be assessed in, and any certifications you declare.
DigiLocker gives us, with your consent
When you verify your identity we receive, from the government’s DigiLocker service via our partner Setu, only:
- Your name as recorded on Aadhaar
- Your date of birth and gender
- The last four digits of your Aadhaar number
We never receive or store your full Aadhaar number, and we never receive your Aadhaar address. Our database physically rejects any record containing twelve consecutive digits, so a full number cannot be stored even by mistake.
The assessment produces
- Voice recordings of your spoken answers, and their transcripts.
- Competency outcomes and the evaluation behind them.
We generate
- Payment records — amount, reference, transaction id and mode. Your UPI PIN and banking credentials never reach us. Your UPI address is stored only as a one-way hash, so a disputed payment can be matched without us holding the address.
- Security and audit records. IP addresses are stored only as a salted one-way hash, never in the clear. The audit log holds identifiers and state changes only — never names, numbers or transcripts.
We do not use advertising trackers, we do not sell personal data, and we do not build advertising profiles.
2Why we process it, and on what basis
Under the DPDP Act we rely on your consent, taken separately for each purpose, and on legitimate uses where the Act allows.
- Identity verification — consent. A certificate that is not tied to a verified person is worthless.
- Assessment recording and evaluation — consent. We cannot evaluate spoken judgement without recording it.
- Issuing and publishing certification status — consent. Public verifiability is the point of the product.
- Payment, tax and accounting records — legal obligation.
- Security, fraud prevention and audit — legitimate use.
You can withdraw consent at any time. Withdrawing it for identity verification or assessment recording means certification cannot continue and a live certificate lapses at renewal, because the evidence underneath it no longer stands.
4What becomes public
A certified coach has a public profile so parents and academies can check the certificate. It shows your first name and last initial, your sport, your city, your years of experience, the age groups you coach, and your certification status and dates.
It never shows your email address, your phone number, any part of your Aadhaar number, your date of birth, your address, your assessment recordings or transcripts, or which competencies took more than one attempt.
5Where it is stored, and how it is protected
All personal data is stored in India, in the Mumbai region (ap-south-1). It is not transferred outside India.
- Encrypted in transit (TLS) and at rest.
- Row-level security in the database, so one coach’s records are unreadable from another coach’s session even if the application layer is bypassed.
- Minimisation by design. Aadhaar numbers are stored masked, IP addresses and UPI addresses only as one-way hashes, and the audit log is built so that personal data cannot be written into it.
- Append-only records. Consent and audit entries cannot be edited or deleted, including by us, so what you agreed to cannot be quietly rewritten.
- Access limited to staff who need it, and logged when used.
If a personal data breach occurs we will notify the Data Protection Board of India and affected users as the DPDP Act requires.
6How long we keep it
Some records outlive your account on purpose. Rather than claim we delete everything, here is exactly what is kept and why.
| Record | Kept for | Why |
|---|---|---|
| Account and coach profile | Until you delete your account | It is the profile itself. |
| Identity verification record | Duration of certification, then seven years | Evidence that a certificate was issued to a verified person. Only your name, date of birth and the last four digits of your Aadhaar are held. |
| Assessment responses and recordings | Two years from the assessment | So a certification decision can be reviewed, appealed or audited. Deleted on request once any appeal window has closed. |
| Certificates and their status history | Permanent | A certificate that cannot be verified later is worthless. Records are retained even after an account closes, under the name shown at issue. |
| Consent records | Permanent, unlinked on erasure | Proof of what you agreed to and when. On deletion the record is detached from you and retained without identifying you. |
| Payment records | Eight years, unlinked on erasure | Required under Indian tax and companies law. |
| Audit log | Permanent, unlinked on erasure | Records that an action happened, never who you are. It holds identifiers and state changes only — no names, numbers or transcripts. |
“Unlinked on erasure” means the record survives with every identifier pointing to you removed. What remains is that a consent was given, or a payment was made, under a stated notice version at a stated time — with nobody attached to it.
7Your rights
Under the DPDP Act you have the following rights. Write to privacy@axiopro.in to exercise any of them. We respond within thirty days and we do not charge for it.
Access
Ask what personal data we hold about you and what we have done with it. We respond within thirty days.
Correction
Correct anything inaccurate or incomplete. Identity details verified through DigiLocker are corrected at source — update DigiLocker, then re-verify.
Erasure
Delete your account and personal data. Consent, payment and audit records are retained with your identity removed from them, as described in the retention table.
Portability
Receive your profile, assessment results and certificate history in a structured, machine-readable format.
Withdraw consent
Withdraw consent at any time. Withdrawing consent for identity verification or assessment recording means certification cannot continue, and any live certificate lapses at renewal.
Grievance redressal
Raise a complaint with our grievance officer at privacy@axiopro.in. If unresolved, you may escalate to the Data Protection Board of India.
Nominate
Nominate someone to exercise these rights on your behalf in the event of death or incapacity.
8Children
Axio accounts are for adults. We do not knowingly collect personal data from anyone under eighteen, and we do not create profiles for the children a coach trains. If you believe a child has created an account, tell us and we will delete it.
9Grievance officer
[GRIEVANCE OFFICER NAME]
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
privacy@axiopro.in
If we do not resolve your complaint to your satisfaction, you may escalate it to the Data Protection Board of India.
10Changes to this policy
If we change how we use personal data in a way that materially affects you, we will email you before it takes effect and, where the law requires it, ask for fresh consent. Past versions are available on request from our legal page.
Questions about this document
Write to legal@axiopro.in. For anything about your personal data, use privacy@axiopro.in, which reaches our grievance officer.