Privacy & Data Governance Policy
This Privacy Policy outlines how the YES INDIA FOUNDATION Institutional Feasibility & Takeover Assessment Portal collects, safeguards, and processes institutional, financial, and operational information.
1 Statutory Framework & Purpose Specification
YES INDIA FOUNDATION ("the Foundation", "Data Fiduciary") operates this Institutional Feasibility & Takeover Assessment Portal in adherence to the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000 (and applicable intermediary guidelines), and CERT-In cyber incident directives.
This portal is dedicated strictly to evaluating prospective schools, conducting infrastructural risk reviews, assessing academic readiness, and calculating economic viability for institutional transition, takeover, or management support. Personal data processed through this platform is collected solely for specified institutional verification purposes.
2 Data Minimisation & Categories of Information
Under our strict Data Minimisation policy, we collect only the minimal information strictly necessary to execute feasibility audits. We do not gather extraneous consumer metadata, student biometric records, or third-party marketing telemetry.
Institutional Data
School registration deeds, board affiliations (CBSE/ICSE/State), land ownership documents, fire safety NOCs, classroom and playground acreage dimensions.
Aggregated Academic Demographics
Aggregated grade-wise enrolment rosters, staff-to-student ratios, dropout rates, and fee tier distributions (no individual student personal profiles).
Aggregated Financial & Staff Headcount
Audited 3-year balance sheets, statutory PF/ESI compliance indicators, operational expenditure budgets, and aggregated faculty salary outlays.
Evaluator & User Account Data
Name, institutional email, phone number, designated role, and IP address collected for multi-factor authentication and security auditing.
3 Role-Based Access Control (RBAC) & School Isolation
Institutional confidentiality is preserved through a defense-in-depth architecture:
- Cryptographic School/Organization Isolation: Institutional school records, financial models, and feasibility scores are segregated at the database query layer. Users cannot view, query, or edit institutions outside their verified institutional domain.
- Granular Role Gating: Permissions are strictly enforced across Super Administrators, Lead Field Inspectors, and School Applicants. Action capabilities (such as report approvals or application status promotion) require explicit privileges.
- Child Record Scoping: Associated financial ledger entries, capital expenditure proposals, and competitor benchmarking schools are locked to their parent application ID, preventing parameter tampering.
4 Secure Document Storage & HTTPS Transport
- Mandatory HTTPS/TLS 1.3: All communications between portal users and server endpoints are encrypted in transit with strict HSTS policies. Plaintext HTTP traffic is rejected or automatically upgraded.
- Non-Public Private Storage Disk: Statutory certificates, land deeds, and audit attachments are deposited on isolated, non-web-accessible storage disks outside the public root. Direct file URL enumeration is blocked.
- Cryptographic Randomization & Integrity: File uploads receive unguessable UUID identifiers, MIME-type binary validation, and SHA-256 integrity checksums to protect against tampering.
- Gated Stream Streaming: Uploaded documents can only be retrieved through authenticated controller endpoints enforcing school ownership and inspector authorization.
5 Immutable Audit Logs
In compliance with ISO 27001 and DPDP guidelines, the portal maintains append-only, tamper-evident audit logs capturing:
- Authentication events (successful logins, logouts, failed password attempts, IP addresses, and user agents).
- Data lifecycle events (application creation, step progress saves, evaluation score updates, and board decisions).
- Document operations (file uploads, verified removals, and inspector downloads).
- Data Subject requests (DSAR personal data dossier exports and account erasure requests).
6 Data Retention Schedules & Automated Purging
Personal and institutional data is retained only for periods justified by statutory obligations, educational governance standards, and audit requirements:
| Data Category | Retention Period | Purge / Archival Action |
|---|---|---|
| Completed & Approved Feasibility Studies | 7 Years (2,555 Days) | Archived for statutory board governance; documents sanitized upon expiry |
| Incomplete / Abandoned Draft Applications | 180 Days | Automated deletion of drafts and associated temporary documents via daily cron |
| Security & Audit Trails | 365 Days | Retained for incident analysis and CERT-In compliance; aggregated thereafter |
| Temporary Session & Upload Tokens | 24 Hours | Immediate system purge upon session expiration |
7 Data Rights Workflow (Access, Portability & Deletion)
Under the DPDP Act 2023, registered institutional users and data principals hold verifiable rights regarding their personal data:
- Right to Access & Portability: Users can download an authenticated, machine-readable JSON dossier containing all personal profiles, school links, and audit histories directly from their Account Profile → Data Rights & Privacy Controls.
- Right to Correction: Users can rectify inaccurate profile attributes or update institutional credentials through their account dashboard.
- Right to Erasure: Users can trigger password-verified account deletion. Upon confirmation, personal identifiers and session tokens are permanently scrubbed. Anonymised audit records are retained solely where required by legal and financial statute.
- Right to Grievance Redressal: Grievance requests are processed by our Data Protection Officer within 30 days of receipt.
8 Sub-Processor & Third-Party Vendor Register
The Foundation contracts with selected third-party data processors bound by stringent Data Processing Addendums (DPAs) guaranteeing equivalent data protection benchmarks:
| Vendor / Processor | Processing Function | Data Transferred | Location / Standard |
|---|---|---|---|
| Google Maps Platform | Satellite imagery & geospatial coordinates | Latitude/Longitude for campus perimeter review | India / Global (Encrypted API) |
| Cloud Infrastructure Provider | Hardened VPS hosting & database operations | Encrypted portal records & application databases | India Region (ISO 27001 / SOC 2) |
| Transactional Mail Provider | Account verification & security alerts | User email address and login confirmation links | TLS 1.3 / DPA Encrypted |
| Local Encrypted Document Store | Private document repository | Institutional deeds, safety certificates, balance sheets | On-premise / Restricted Non-public Disk |
9 Security Incident Response & Breach Notification Protocol
The Foundation enforces a structured Security Incident and Breach Response Protocol in compliance with CERT-In directions and the DPDP Act 2023:
- Incident Detection & Containment: Anomalous access patterns, rate-limit triggers, and document access failures are logged automatically. Administrators can formally initiate an incident lockdown from the Portal Security Console.
- Statutory Notification Timelines:
- CERT-In Mandatory Reporting: Cybersecurity incidents are reported to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of noticing the incident.
- Data Protection Board & Data Principals: Any confirmed breach compromising personal data is notified to the Data Protection Board of India and affected data principals without unreasonable delay (targeted within 72 hours), detailing the nature of the breach, affected categories, and mitigating steps taken.
- Remediation & Forensic Archival: All actions taken during an incident are sealed into the immutable audit register for regulatory evaluation.
10 Data Protection Officer & Grievance Redressal
To exercise statutory data rights, report privacy concerns, or submit a data subject inquiry, contact our designated Data Protection & Grievance Redressal Officer:
Grievance Redressal & Data Protection Officer
Institutional Feasibility Directorate • YES INDIA FOUNDATION
Physical Address: RKP.V/720-A 12, Hanna Tower, Opp. BUS Stand Ramanatukara, Kozhikode - 673633, Kerala, India
Official Email: info@yesindiafoundation.com / dpo@yesindiafoundation.com
Direct Desk Helpline: +91 989 566 2111
Statutory Response Turnaround: Initial acknowledgment within 48 hours; substantive resolution within 30 days.