Privacy Policy
Certaze Technologies ✦ DPDP Act 2023 & DPDP Rules 2025 · India
01Who We Are
Certaze Technologies ("Certaze", "we", "us") operates the certification exam preparation platform at certaze.in. We are the Data Fiduciary responsible for your personal data under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (India).
Contact our Data Fiduciary at: admin@certaze.in
02Data We Collect
We collect the following categories of personal data, with your knowledge and consent at account creation:
| Category | Data collected | Why |
|---|---|---|
| Account data | Email address, display name, password (hashed via Firebase) | Authentication and account management. Your email address and display name are shared with our email provider (Resend, for account/service emails) so that they can reach you — see §04. |
| Usage data | Questions answered, scores, session history, domain performance, study streak | AI readiness prediction, personalised coaching |
| Device data | Browser type, device type, IP address | Security, rate limiting, abuse prevention |
| Payment data | Transaction ID, plan purchased, payment status | Subscription management. Card details processed by Razorpay — never stored by us. |
| Analytics data | IP address (used by Google to derive a coarse country/region-level location and to detect spam; discarded after use, never linked to a user identifier), the coarse location derived from it, a randomly-generated measurement identifier stored in your browser, and page/feature usage events (e.g. which screens are opened) | Aggregate product measurement — understanding how the App is used so we can improve it. See §09. |
Your study progress (scores, session history, domain performance, study streak) is synced by default to your account in our Firestore database while you are signed in, so it follows you across your devices. A local copy is also kept in your browser's localStorage for fast, offline access. You can turn cloud sync off, and clear your previously-synced progress, via Profile → Settings (see §07).
Our analytics measurement is deliberately kept separate from your account: it is not linked to your name, email, login, or user ID, and we do not use it to build a profile of you as an individual. §09 sets out exactly what it does and does not involve.
03How We Use Your Data
We use your data only to:
- Provide and operate the Certaze exam preparation service
- Authenticate you and maintain your account security
- Generate personalised AI questions, feedback, and pass predictions
- Calculate and display your study analytics and readiness score
- Process subscription payments and manage your plan status
- Send transactional emails (account, password-reset and service emails) via our email provider Resend. We do not track opens or link-clicks in transactional or password-reset emails — they contain no open-tracking pixel, and their links go directly to our own site with no tracking redirect. Separately, marketing emails — which you opt into and can unsubscribe from at any time — are sent via Brevo and do include open/click measurement
- Detect and prevent fraudulent activity and abuse
- Improve question quality using aggregated, anonymised data only
- Understand, in aggregate, how the App is used — which screens and features people open — so we can improve it (see §09)
We do not use your data to train AI models. Your questions and answers are processed in real time by the Anthropic API and not retained by Anthropic for training under our agreement.
04Third-Party Services
We use the following third-party processors to operate Certaze:
| Service | Purpose | Data shared | Policy |
|---|---|---|---|
| Google Firebase (USA) | Authentication, database, hosting | Email, usage stats, device info | firebase.google.com |
| Google Analytics 4 (USA) | Aggregate product analytics — usage measurement only | IP address (used for coarse location + spam detection, discarded after use, never linked to a user identifier), a randomly-generated measurement identifier, page/feature events. No name, email, account or user ID. | policies.google.com |
| Anthropic (USA) | AI question generation (Claude API) | Session prompts — not linked to your identity | anthropic.com |
| Razorpay (India) | Payment processing | Name, email, amount. Cards handled by Razorpay only. | razorpay.com |
| Resend (Ireland, EU) | Transactional email delivery (account, password-reset and service emails) | Your email address and display name; delivery status. No open-tracking pixel and no click-tracking on transactional or password-reset emails. | resend.com |
| Brevo (France, EU) | Marketing email only (where you have separately opted in) | Your email address and display name; delivery status; and, for marketing emails, whether you opened the email or clicked a link. Not used for transactional or password-reset email. | brevo.com |
| Vercel (USA) | Frontend hosting | IP address, request logs | vercel.com |
| Render (USA) | Backend API hosting | API request logs, IP address | render.com |
| Cloudflare (USA) | DNS and network security | IP address, request metadata — not content | cloudflare.com |
| Upstash (USA) | Rate limiting and abuse prevention | Request frequency data; no personal data stored beyond active session | upstash.com |
05Cross-Border Data Transfers
Certaze is an India-based service. However, several of our third-party processors — including Google Firebase, Google Analytics, Anthropic, Vercel, Render, Cloudflare, and Upstash — are incorporated in and operate infrastructure within the United States of America. Our email providers are incorporated in and operate infrastructure within the European Union: Resend (Ireland, transactional email) and Brevo (France, marketing email).
By creating an account and using Certaze, you acknowledge and consent to your personal data being transferred to and processed in the United States, which may have data protection laws different from India's.
DPDP Rules 2025 note: Under the DPDP Act 2023 and the DPDP Rules 2025, personal data may be transferred outside India except to any country or territory that the Central Government of India restricts by notification. We monitor these notifications and will not transfer data to a restricted destination. We will update this section as further requirements are notified.
06Data Storage and Security
- Firebase / Firestore: Account credentials and your study progress (scores, session history, domain performance, study streak) — synced by default while you are signed in, so your progress follows you across devices; encrypted at rest and in transit
- Your device (localStorage): a local copy of the same study data for fast, offline access — you can turn off cloud sync, and clear synced progress, via Profile → Settings
- Render.com: API request logs retained up to 30 days for security, then auto-deleted
Security measures include HTTPS everywhere, Firebase Authentication, Firestore security rules, server-side rate limiting via Upstash, and Cloudflare network-layer protection. No system is perfectly secure.
Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and each affected data principal without undue delay and within the timelines and manner prescribed under the DPDP Rules 2025. Our notice to you will describe, in plain language, the nature of the breach, the data affected, the measures we are taking, steps you can take to protect yourself, and our contact details for further queries.
07Your Rights
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (India), you have the following rights. In line with the Rules, we publish the periods within which we respond: we acknowledge a request or grievance within 72 hours (with a reference number and point of contact), and we fulfil verified rights requests within 7 working days. Where a request is complex, we may extend this once, and we will tell you the reason and the revised timeline before the original period expires.
Access
Request a summary of personal data we hold about you.
Correction
Ask us to correct inaccurate or incomplete data.
Deletion
Request deletion of your account and all associated data, subject to legal retention obligations. You can also erase just your study progress — both the cloud-synced copy and the local copy — while keeping your account and sign-in active, via Profile → Reset all data.
Portability
Export your study data via Reports → Export CSV at any time.
Withdraw Consent
Cloud sync is on by default while you are signed in, so your study progress follows you across your devices. You can turn it off anytime via Profile → Settings, and clear your previously-synced progress via Profile → Reset all data (this erases both your cloud and local study progress; your account and sign-in stay active). To withdraw all consent and delete your account entirely, contact admin@certaze.in — this results in account deletion. Withdrawing consent is as easy as giving it.
You can clear the analytics measurement identifier stored in your browser at any time by clearing your browser's site data, or block it with a tracker-blocking extension (see §09).
Nominate
You may nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act 2023.
Grievance Redressal
Raise concerns with our Grievance Officer at admin@certaze.in — acknowledged within 72 hours and resolved within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
To exercise any right, email admin@certaze.in with subject "Data Request". We will verify your identity and respond within the periods stated above.
08Data Retention
- Account data: Retained while active. On a verified deletion request we action erasure within 7 working days; any residual copies in encrypted backups are purged within 30 days.
- Study data (cloud-synced): Retained while active. Reset anytime via Profile → Reset all data.
- Payment records: Retained for 7 years as required by Indian tax law.
- Analytics data: Aggregate, non-identifying usage data retained only as long as needed to understand usage trends, under Google Analytics 4's standard retention settings. You can clear the measurement identifier from your browser at any time (see §09).
- Server logs: Retained up to 30 days, then auto-deleted.
- Rate limiting data (Upstash): Rolling window only — not retained beyond the active session.
09Cookies, Local Storage and Analytics
Certaze uses browser localStorage to store a local copy of your study data on your device for fast, offline access. While you are signed in, this data is also synced by default to our Firestore database, so your progress follows you across devices — see §02 and §06. You can turn cloud sync off at any time via Profile → Settings.
Firebase Authentication uses a secure session token to maintain your signed-in state. This is strictly necessary and cannot be disabled while using the Service.
Analytics
We use Google Analytics 4 to understand, in aggregate, how the App is used — which screens are opened and which features are used — so we can improve it. This is measurement, not surveillance: we are not trying to find out who you are.
What this involves, in plain terms:
- Your IP address. Google Analytics receives your IP address and uses it to work out a coarse (country/city-level) location and to detect spam and abuse. Google states that it does not associate raw IP addresses with any user identifier, and discards the raw IP address after this use. Your IP address is not shown to us in analytics reports, is not stored by us against any analytics record, and is not linked to your Certaze account.
- Google Analytics sets a randomly-generated measurement identifier in your browser so it can tell repeat visits apart from new ones in aggregate reporting — for example, so we can see "how many people came back a second day" as a number, not as a list of people. This identifier is not your name, email, or account.
- It is not linked to your account. We do not send your user ID, email, name, or any account identifier to Google Analytics, and we do not join analytics data to your Certaze account records. Your study data itself is never sent to Google Analytics — it stays on your device and (by default, while signed in) in Firestore, as described in §02 and §06.
- What we measure: page/screen views, scrolls, clicks on links that lead away from the App, in-App searches, interactions with any video or downloadable file, and a signal distinguishing a repeat visit from a new one. We do not measure your form interactions, and we do not capture what you type.
- Location. Google Analytics derives a coarse, country/region-level location from that IP address as part of standard measurement. We do not receive or store a precise location, and we have switched off Google Analytics' "granular location and device data collection" setting for this property. We do not use location to identify you.
- No advertising use. We do not use advertising cookies, tracking pixels, cross-site tracking, remarketing, or Google Signals / ads personalisation, and we do not sell or share your data with advertisers.
You can block or clear this at any time using your browser's cookie/site-data controls or a tracker-blocking extension — the App will keep working, since analytics is not required to use the Service.
10Children's Privacy
The Service is not directed to persons under 18 years of age. We do not knowingly collect personal data from minors, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a person under 18 has provided us with personal data without appropriate consent, please contact admin@certaze.in with the subject "Minor Data Concern". We will take prompt steps to delete that information.
11Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via your registered email at least 14 days in advance and posted at certaze.in/privacy with a new effective date. Continued use constitutes acceptance.
12Grievance Officer
In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025:
- Name: Shyama Ramesh Varma
- Designation: Grievance Officer & Data Fiduciary, Certaze Technologies
- Email: admin@certaze.in
- Address: Palakkad, Kerala, India
Grievances acknowledged within 72 hours (with a reference number) and resolved within 30 days; data-principal rights requests are fulfilled within 7 working days (see §07). If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India.
Privacy questions or data requests?
Contact our Grievance Officer and Data Fiduciary.
Subject: "Data Request" or "Privacy Concern" · Acknowledged within 72 hours