Legal

Privacy Policy

How Gradify Labs collects, uses, and protects your information — in plain language.

This Privacy Policy explains how Gradify Labs LLP ("Gradify", "we", "our", or "us"), incorporated in India and headquartered in Udaipur, Rajasthan, collects, uses, shares, and protects information in relation to our blockchain-based academic credential platform and related services.

It is designed to comply with India's Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and SPDI Rules, 2011, and — where applicable — the EU/UK GDPR. By using our services you agree to the handling of information described here.

This Privacy Policy is incorporated into our Terms & Conditions. Additional rights may apply depending on your jurisdiction, as outlined below.

Legal Framework

Gradify Labs LLP ("Gradify", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and security of personal data processed through our websites, applications, credential platforms, verification services, APIs, and related products and services (collectively, the "Service").

Depending upon the nature of the relationship and the processing activity, Gradify may act as a Data Fiduciary, Data Processor, or in another capacity recognized under applicable data protection law. Where Gradify determines the purpose and means of processing personal data, it may act as a Data Fiduciary. Where Gradify processes personal data solely on behalf of an educational institution, organization, government authority, employer, or other customer pursuant to their instructions, Gradify may act as a Data Processor or equivalent service provider.

This Privacy Policy is intended to describe our general privacy practices and is governed by applicable Indian data protection and information technology laws and, where legally applicable based on your location and the nature of the processing, the data protection laws of other jurisdictions.

  • Digital Personal Data Protection Act, 2023 (DPDP Act) and rules, regulations, and subordinate legislation made thereunder, to the extent applicable.
  • Information Technology Act, 2000 and applicable rules and regulations relating to information security and protection of personal information, to the extent applicable.
  • EU/UK GDPR and other applicable European data protection requirements, where Gradify is legally subject to such requirements.
  • Other applicable privacy, cybersecurity, consumer protection, contractual, and regulatory requirements governing the processing of personal data.

We seek to process personal data in a lawful, fair, transparent, and proportionate manner and only for specified, legitimate, and reasonably necessary purposes. Where consent is required by applicable law, we will obtain consent in an appropriate manner. Where another lawful basis or permitted use applies, processing may take place without obtaining consent where legally permitted.

Where a customer institution or organization determines the purposes and means of processing, the relevant customer may remain responsible for determining the appropriate legal basis, providing required notices, obtaining necessary permissions or consents, and responding to requests relating to its processing activities, subject to the terms of the applicable agreement between the parties.

What We Collect

The categories of personal data we collect depend on how you interact with Gradify, the Service you use, whether you are a student, credential holder, verifier, institutional administrator, employee, visitor, or other user, and the requirements of the institution or organization using our platform.

  • Identity & contact information: name, email address, telephone number, postal address, date of birth where required, institutional affiliation, username, account information, and authentication credentials.
  • Academic and professional information: student identifiers, enrollment information, academic records, degrees, diplomas, certificates, transcripts, examination information, graduation information, professional qualifications, credential identifiers, issue dates, expiry dates, status, and related metadata.
  • Verification information: QR-code identifiers, credential verification requests, verification timestamps, verification results, referring information, and information reasonably required to validate the authenticity or status of a credential.
  • Government or identity documents: government-issued identification information, including identity document numbers or copies, only where such information is specifically required for a legitimate verification, onboarding, compliance, or institutional purpose and is lawfully collected.
  • Blockchain and cryptographic information: wallet addresses, transaction identifiers, cryptographic hashes, digital signatures, public keys, blockchain network information, and other technical identifiers associated with blockchain-based credential operations.
  • Technical and device information: IP address, browser type, operating system, device information, approximate location derived from technical information where applicable, access timestamps, referral information, network information, and other diagnostic or security logs.
  • Usage and interaction information: pages visited, features used, verification activity, service interactions, preferences, and other information generated through your use of the Service.
  • Communications: information contained in enquiries, support requests, complaints, correspondence, feedback, and other communications submitted to us.

We may obtain personal data directly from you, from educational institutions and other authorized customers, from employers or verification partners where legally permitted, automatically through your interaction with the Service, or from publicly available blockchain networks and other lawful sources.

We seek to limit collection to information that is reasonably necessary for the relevant purpose. You should not provide sensitive or confidential information to Gradify unless it is specifically requested or required for the applicable Service.

How We Use It

We process personal data only for specified and legitimate purposes and in accordance with applicable law. Depending on the Service and your relationship with Gradify, we may use personal data to:

  • Register, authenticate, maintain, and administer user and institutional accounts.
  • Issue, manage, store, transmit, present, and verify digital academic, professional, and institutional credentials.
  • Enable students, credential holders, institutions, employers, and other authorized parties to verify credential information.
  • Generate credential identifiers, verification records, QR codes, cryptographic hashes, and blockchain transaction records.
  • Provide customer support, respond to enquiries, process complaints, and communicate important service-related information.
  • Monitor the security, integrity, performance, availability, and reliability of the Service.
  • Detect, investigate, prevent, and respond to fraud, unauthorized access, misuse, abuse, security incidents, and other potentially unlawful activity.
  • Maintain operational records, audit trails, and technical logs necessary for security, accountability, and service administration.
  • Improve, develop, test, maintain, and optimize our products, infrastructure, features, and user experience, subject to applicable law.
  • Process payments, invoices, subscriptions, and other commercial transactions where applicable.
  • Comply with applicable laws, regulations, legal processes, governmental requests, court orders, and other lawful obligations.
  • Establish, exercise, or defend legal rights and claims and protect the rights, property, safety, and legitimate interests of Gradify and other persons.

Depending on the applicable jurisdiction and processing activity, our lawful basis may include consent, performance of a contract, compliance with a legal obligation, a permitted legitimate or lawful use, or another lawful basis recognized under applicable law.

Where processing is based on consent, you may withdraw consent subject to applicable law. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and may not require deletion where continued processing is permitted or required by law, contract, security requirements, or another lawful basis.

Blockchain note: certain credential-related information may be represented on a public blockchain through cryptographic hashes, transaction identifiers, wallet addresses, or other technical records. Blockchain records may be publicly accessible and technically immutable. We seek to minimize the amount of directly identifying personal information placed on-chain and, where technically and operationally appropriate, use cryptographic representations rather than storing unnecessary personal information directly on the blockchain.

Data Security

We take the security and confidentiality of personal data seriously and maintain reasonable technical, organizational, and administrative safeguards designed to protect personal data against unauthorized access, alteration, disclosure, destruction, accidental loss, misuse, or other unlawful processing.

Depending on the nature and sensitivity of the information and the risks associated with processing, our safeguards may include encryption in transit and, where appropriate, at rest, access controls, authentication mechanisms, role-based permissions, secure credential management, logging and monitoring, infrastructure security controls, backup procedures, vulnerability management, and periodic security assessments and testing.

Access to personal data is restricted to personnel, contractors, processors, and other authorized persons who require such access for legitimate business, operational, technical, security, or legal purposes and who are subject to appropriate confidentiality obligations.

Despite the safeguards described above, no electronic transmission, storage system, software application, network, or security mechanism can be guaranteed to be completely secure. Accordingly, Gradify cannot guarantee absolute security or eliminate every possible cybersecurity risk.

Blockchain transactions and public ledger records may be visible to participants of the relevant blockchain network. Wallet addresses and other public identifiers may potentially be associated with an individual through external information or analysis. You are responsible for maintaining the security of your own wallets, private keys, recovery phrases, passwords, and authentication credentials.

If Gradify becomes aware of a personal data breach or security incident that triggers a notification obligation under applicable law, we will take appropriate steps to investigate, contain, remediate, and report the incident to the relevant authority and affected individuals where and to the extent required by applicable law.

Sharing & Disclosure

We do not sell personal data for monetary consideration. We may disclose or make personal data available to third parties where reasonably necessary to provide the Service, fulfill contractual obligations, comply with applicable law, protect rights and security, or otherwise carry out a lawful processing purpose.

Depending on the circumstances, recipients may include:

  • Service providers and Data Processors: hosting providers, cloud infrastructure providers, database providers, analytics services, communication providers, payment processors, security providers, customer-support providers, email services, and other technology vendors that process information on our behalf and subject to appropriate contractual or legal obligations.
  • Educational institutions and organizations: institutions, universities, government authorities, employers, professional organizations, or other credential issuers or authorized entities involved in issuing, administering, or verifying credentials.
  • Credential verifiers: employers, institutions, organizations, or other persons who legitimately access a credential or verification service, subject to the applicable access controls and permissions.
  • Professional advisers: lawyers, auditors, accountants, consultants, insurers, and other professional advisers where disclosure is reasonably necessary for legitimate business, legal, compliance, or risk-management purposes.
  • Government and law-enforcement authorities: where required or permitted by applicable law, regulation, court order, legal process, or lawful governmental request, or where disclosure is reasonably necessary to investigate fraud, security incidents, unlawful conduct, or threats to safety or rights.
  • Business successors: a purchaser, successor, investor, affiliate, or other relevant party in connection with a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction, subject to applicable law and appropriate confidentiality protections.

Where Gradify acts as a Data Processor on behalf of an institutional customer, personal data may be processed and disclosed in accordance with that customer's documented instructions and the applicable service agreement.

Personal data may be processed or transferred across state or national borders where necessary to provide the Service or engage authorized service providers. Such transfers will be undertaken in accordance with applicable data protection requirements and any legally required safeguards, contractual arrangements, consent requirements, or governmental restrictions.

Your Rights

Depending on your jurisdiction, your relationship with Gradify, the nature of the processing, and applicable law, you may have certain rights regarding your personal data. These rights are subject to applicable legal limitations, exemptions, verification requirements, and the rights of other persons.

Subject to applicable law, you may have the right to:

  • Access: request information about the personal data processed by us and, where legally required, obtain access to such information.
  • Correction: request correction, completion, or updating of personal data that is inaccurate, incomplete, or outdated.
  • Erasure or deletion: request deletion of personal data where such right is available under applicable law and where we are not legally entitled or required to retain the information.
  • Withdrawal of consent: withdraw consent for processing where processing is based on consent, subject to applicable legal and contractual limitations.
  • Grievance redressal: raise a complaint or grievance concerning our processing of personal data and request appropriate resolution.
  • Nomination: exercise nomination-related rights available under applicable Indian law, including rights available to a Data Principal under the DPDP Act, where applicable.
  • Additional GDPR rights: where the GDPR applies, you may have additional rights including rights relating to restriction of processing, objection, data portability, automated decision-making, and other rights provided under applicable GDPR provisions.

To submit a request, contact us at contact@gradifytech.com. We may need to verify your identity before processing a request to prevent unauthorized access, disclosure, alteration, or deletion of personal data.

We will respond to valid requests within the period required by applicable law. Certain requests may be refused, limited, or subject to conditions where permitted or required by law, including where retention is necessary for legal compliance, security, fraud prevention, contractual obligations, establishment or defense of legal claims, or preservation of the integrity of blockchain records.

Where personal data has been supplied by or is controlled by an educational institution, employer, government authority, or other customer, Gradify may direct the request to the relevant organization where that organization is the appropriate Data Fiduciary or controller responsible for the relevant processing.

Children's Data

Gradify recognizes the importance of protecting the personal data of children and individuals who may require the involvement of a parent or lawful guardian. Where applicable law requires verifiable parental or guardian consent before processing a child's personal data, we will seek to implement appropriate measures to obtain or verify such consent.

Under applicable Indian law, the treatment of a person as a child and the obligations relating to children's personal data are determined by the applicable statutory and regulatory framework in force at the relevant time.

We do not knowingly use children's personal data for targeted advertising or behavioral profiling where such processing is prohibited by applicable law. We also seek to avoid unnecessary collection of children's personal data and process such information only for legitimate purposes such as educational credential issuance, verification, account administration, security, compliance, or other authorized services.

If you believe that a child's personal data has been provided to Gradify in circumstances where such processing was not authorized or permitted, please contact us at contact@gradifytech.com so that we can review the matter and take appropriate action.

Cookies

Gradify may use cookies, local storage, pixels, tags, and similar technologies to operate, secure, analyze, and improve the Service. These technologies may store or access information on your device and may allow us to recognize your browser or session.

  • Essential cookies: required for authentication, account access, session management, security, fraud prevention, and core platform functionality.
  • Analytics cookies: used, where applicable, to understand usage patterns, performance, traffic, and interactions with the Service so that we can identify errors and improve functionality.
  • Functionality cookies: used to remember preferences, settings, language selections, or other choices made during use of the Service.

Where consent is required for non-essential cookies or similar technologies, we will seek consent through appropriate mechanisms. You may control or delete cookies through your browser or device settings and, where available, through the cookie preferences provided by the Service.

Disabling or blocking certain cookies may affect the availability, security, performance, or functionality of portions of the Service, particularly features that require authentication or session management.

Retention

We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, provide the relevant Service, maintain appropriate business and security records, comply with contractual obligations, satisfy legal and regulatory requirements, resolve disputes, establish or defend legal claims, prevent fraud, and protect the rights and security of Gradify and others.

  • Account and transaction records: retained for the duration of the relevant relationship and, where required or reasonably necessary, for an additional period to satisfy accounting, tax, legal, audit, fraud-prevention, or dispute-resolution requirements.
  • Educational and credential records: may be retained for the period reasonably necessary to support credential lifecycle management, verification, institutional requirements, legal obligations, and the integrity and reliability of credential verification services.
  • Communications and support records: retained for a period reasonably necessary to manage support requests, complaints, contractual relationships, legal obligations, and service quality.
  • Technical and security logs: retained for a period appropriate to security monitoring, fraud detection, incident investigation, system administration, and applicable legal requirements.

Specific retention periods may vary depending on the nature of the information, the purpose of processing, contractual requirements, applicable law, and the role Gradify performs in relation to the relevant data. Where personal data is no longer required and there is no lawful basis for continued retention, we will take reasonable steps to delete, anonymize, or otherwise securely dispose of it.

Information recorded on public blockchain networks may not be capable of deletion or modification by Gradify. Where technically appropriate, we seek to minimize directly identifiable personal information placed on-chain and may use cryptographic hashes or other representations. However, blockchain immutability means that deletion of an associated off-chain record does not necessarily result in deletion of the corresponding blockchain record.

Changes

Gradify may update, amend, supplement, or otherwise modify this Privacy Policy from time to time to reflect changes in our services, technology, business practices, data processing activities, applicable laws, regulatory requirements, security standards, or other operational considerations.

When we make changes, we will update the "Last updated" date displayed on this page. Where reasonably practicable and where required by applicable law, material changes may also be communicated through email, account notifications, or a prominent notice on our website or Service.

Unless otherwise stated, the revised Privacy Policy will become effective from the date specified in the updated policy. Your continued use of the Service after the effective date constitutes acknowledgment of the updated policy to the extent permitted by applicable law.

We encourage you to periodically review this Privacy Policy to remain informed about how we collect, use, disclose, retain, and protect personal data.

Grievances & Contact

If you have questions, concerns, requests, complaints, or grievances relating to this Privacy Policy, the processing of your personal data, your privacy rights, account information, credential information, or security matters, you may contact Gradify using the details below.

  • Grievance Officer / Privacy Contact: Gradify Labs LLP
  • Email: contact@gradifytech.com (subject: "Data Protection – [request type]")
  • Registered address: Udaipur, Rajasthan 313001, India

When submitting a privacy request or grievance, please provide sufficient information to allow us to identify the relevant account, transaction, credential, or processing activity and understand the nature of your request. We may request reasonable information to verify your identity before disclosing or modifying personal data.

We will acknowledge, investigate, and respond to legitimate privacy requests and grievances within the applicable statutory or regulatory timelines. Where Gradify is processing information on behalf of an institutional customer, we may coordinate with that customer where appropriate to determine the correct response or route your request to the organization that acts as the relevant Data Fiduciary or controller.

Where applicable law provides you with a right to escalate an unresolved grievance to a competent governmental, regulatory, judicial, or supervisory authority, you may exercise that right in accordance with the procedures prescribed by the relevant authority.