Privacy Policy
Last updated: June 2026
1. Data We Collect
Cognivia collects institution-level data (institution name, contact information, configuration) and student/staff data as directed by the institution. We act as a data processor under India's Digital Personal Data Protection Act (DPDP Act) 2023 and the EU General Data Protection Regulation (GDPR).
2. Data Storage & Residency
All data is stored on AWS Mumbai (ap-south-1) by default. No cross-border data transfers occur without explicit institution consent. Data is encrypted at rest using AES-256 and in transit using TLS 1.3.
3. Data Retention
Student and institution data is retained for the duration of the active contract, plus 90 days post-termination to allow for data export. Audit logs are retained for 36 months. You may request deletion at any time by writing to privacy@cognivia.in.
4. Data Sharing
We do not sell, rent, or share student data with third parties for advertising purposes. Sub-processors (AWS, payment gateways) are contractually bound to equivalent data protection standards. A full list of sub-processors is available on request.
5. Your Rights
Institutions and their authorised representatives have the right to access, correct, export, and delete data held by Cognivia. Students' rights are managed through the institution as the data principal. Requests can be submitted to privacy@cognivia.in.
6. Contact
For privacy-related queries, contact our Data Protection Officer at dpo@cognivia.in or write to: Cognivia Technologies Pvt. Ltd., Mumbai, Maharashtra, India.