Data Protection
How Veranox Systems Private Limited aligns with the Digital Personal Data Protection Act, 2023: roles, consent, purpose limitation, minimisation, disclosure, automated processing, security, retention, residency and grievance redressal.
Veranox Systems Private Limited · Chennai, Tamil Nadu, India
In effect from 22 August 2026 · version 2.0
1Roles under the Act
Veranox Systems Private Limited is the Data Fiduciary for personal data processed through this website and, under a pilot agreement, for the learner data an institution entrusts to us. The individual whose data is processed — a learner, a staff member, an enquirer — is the Data Principal. Where this notice and our privacy notice overlap, read them together; neither contradicts the other.
2Consent, and what it gates
We process on free, specific, informed, unambiguous consent given by a clear affirmative action, tied to a stated purpose, and withdrawable as easily as it was given. Inside the product a learner sees four separate purposes, not one blanket agreement, and controls each independently:
- Assessment grading — scores answers and computes cluster scores. This is what the platform does, so it is on while a learner uses assessments; it cannot be switched off and the service used at the same time.
- Resume processing — off unless turned on. The uploaded file never leaves the learner's device; only extracted text is processed. Withdrawing deletes that text immediately.
- Employer discovery — off unless turned on. The learner appears under a pseudonym; name and contact details are revealed only when they apply to a role. Withdrawing removes them from employer searches immediately.
- AI tutor — off unless turned on. Lets the tutor use cluster gaps and lesson history. Withdrawing leaves the tutor working, just without that context.
Every optional purpose defaults to off. An undecided learner has consented to nothing beyond the assessment they came for, because the Act treats consent as an affirmative act and a pre-ticked box is not one. Each purpose states, in the learner's own settings, exactly what withdrawing it will do — so withdrawal is as easy and as informed as giving it, per section 6(4) of the Act.
On this website there is no form, no account and no cookie, so there is nothing to consent to. If you write to us by email, sending the message is the consent action, and its scope is answering you.
3Purpose limitation
Personal data is processed only for the purpose consent was given for. Enquiry data handles your enquiry. Learner data in a pilot assesses competence, computes Readiness and issues a Signal — and does nothing outside that. We do not repurpose either for unrelated analytics, for marketing, or for training models. We do not sell data, and we do not share it with data brokers or ad networks.
4Data minimisation
We collect the least that the purpose needs. This marketing site collects nothing at all — that is enforced by its content security policy, which permits no third-party host, not merely promised in this paragraph. Inside the product we hold the evidence required to grade competence and the identifiers required to attach a result to the right learner, and the public surface of a Signal is reduced to the minimum that makes it useful: bands and validity.
5Selective disclosure — bands, never PII
This is the core of the design. Competence is made verifiable without exposing identity.
- The public verifier exposes competence as bands plus validity — never raw scores, names, institutions or contact details.
- A Signal carries a pseudonym and competence bands. Raw personal data is never placed on the public surface.
- Verification needs no login. Anyone can confirm authenticity by checking the Ed25519 signature, and the check returns no personal data.
- The consequence worth stating plainly: an employer can confirm a Signal is genuine without us learning that they looked, and without the learner being identified to us in the process.
6Consent-gated discovery, and where k-anonymity applies
Two different protections operate here, and they are worth separating because they are often conflated.
Learner discovery is consent-gated. An employer searching for candidates sees a learner only if that learner has granted the employer-discovery consent, which is off by default and which they can withdraw at any time. Withdrawing removes them from every employer's search. Where no learner in a cohort has granted it, a search returns an empty result rather than a partial one. Discovery is intended to surface individual candidates — that is what an employer is doing — so the protection here is the learner's own decision, not aggregation.
Aggregate insight is k-anonymity-floored. Where we show an institution which employers are hiring against which competences, employer names are withheld unless at least five distinct employers are in the set, so a small sample cannot be resolved back to one party. The floor is a fixed server-side constant, not a display preference.
7Automated processing and AI grading
Open-ended work is marked against a rubric using third-party language models. The following sets out exactly what is and is not sent to them.
- Sent to the model: the question, the rubric, and the learner's submitted answer.
- Never sent: name, email address, roll number, institution, or any identifier that would let a provider connect the work to a person. The call carries the work and nothing that says whose it is.
- Not used for training. We do not train models on submitted work, and we do not engage a provider whose terms would let it train on what we send.
- No human marks anything. There is no examiner, moderator, second marker or human review step anywhere in the pipeline. Fixed-answer questions are marked deterministically on our server; open-ended answers are marked against a rubric by a model. We state this because an assessment product is commonly assumed to include human marking, and this one does not.
- Fails closed twice. Where no model is reachable, a fixed rubric fallback marks the attempt and the result is held as provisional until the live marker re-marks it. And model output passes a content-safety classifier before any learner sees it; if that gate cannot reach a verdict, the output is discarded rather than shown.
- Coding scores cannot back a Signal. Coding tasks run their tests in the candidate's own browser, so the score is the candidate's own account of their own work. It is recorded as client-reported and is barred from backing a Signal.
- No proctoring, and no surveillance to enable it. We never access a camera, a microphone, a screen recording, another browser tab or a device identifier, and we collect no biometric data and no government ID. Assessments are taken unsupervised, by design.
We will name the model providers in use to any institution that asks before a pilot begins, and we will tell you before that list changes.
8Security safeguards and breach response
Reasonable safeguards, proportionate to the data: encrypted transport, access controls, least-privilege handling and pseudonymisation. Signals carry Ed25519 digital signatures, so a credential cannot be forged or silently altered — a tampered Signal fails verification rather than passing quietly. In the event of a personal-data breach we will act on our obligations under the Act, including notifying the Data Protection Board of India and affected Data Principals, and we will tell the affected institution first rather than last.
9Retention
Personal data is kept only as long as the purpose requires or the law mandates, then deleted or anonymised. Enquiry correspondence that does not lead to a pilot is deleted within twelve months. Learner-data retention in a pilot is fixed by the pilot agreement with the institution, bounded to what the purpose needs and given an end date rather than left open.
10Residency and cross-border processing
Veranox is an Indian company operating under Indian law. Where each part of the system runs:
- The product database — Supabase, ap-south-1 (Mumbai). Learner personal data is held in India.
- Application services — Render.
- Website and portal delivery — Cloudflare, which serves from the edge location nearest the visitor and holds no personal data of ours.
- Email — Zoho Mail carries and stores correspondence sent to us.
- Model providers — may process outside India. What they receive is set out in section 7: work without identifiers.
Each provider processes under its own data-processing terms, and subject to any restriction the Central Government notifies under the Act. We reduce what any border exposes by keeping personal data out of the public Signal surface entirely and out of the grading call specifically. Anything hosted on a demonstration environment runs on synthetic records and refuses every write — there is no real learner data in a demo to move anywhere.
11Grievance Officer
We operate one reachable point of contact for every data question, request and complaint. We acknowledge within 72 hours and resolve within 30 days.
Grievance Officer
Veranox Systems Private Limited
Chennai, Tamil Nadu, India
If we do not resolve your grievance to your satisfaction, you may escalate it to the Data Protection Board of India.
12Your rights and how to exercise them
Write to the Grievance Officer in section 11. We will verify your identity and respond within the timelines the Act requires.
- Access — a summary of the personal data we process about you and what we do with it.
- Correction and completion — fix anything inaccurate or incomplete.
- Erasure — deletion where the data is no longer needed for its purpose.
- Withdraw consent — at any time, without affecting the lawfulness of what came before.
- Grievance redressal — a readily available route to complain, and to escalate.
- Nomination — name another individual to exercise your rights on death or incapacity.
13Learners under 18
Some first-year undergraduates are under 18, and the Act treats them as children. Where a learner in a pilot cohort is under 18, the institution obtains verifiable parental consent before that learner is enrolled, and the pilot agreement carries that obligation explicitly. We do not track, profile or behaviourally advertise to any learner, of any age, and we run no advertising at all.
14Updates to this notice
We will keep this current as the Act's rules are operationalised and as the product changes, and we will move the date and version at the top when we do. A material change is communicated directly to active pilot institutions rather than left to be discovered.