Legal

    HAILM Privacy Policy

    1. Scope

    This Privacy Policy explains how HAILM collects, uses, stores, shares, protects, and deletes personal data in connection with the HAILM website, registration forms, learning platform, assessments, certificates, awards, communications, support, events, and related services.

    HAILM is operated by Eduxa Consulting. For the purposes of this Policy, "HAILM", "we", "us", and "our" refer to Eduxa Consulting and its authorised personnel. Where service providers process data for HAILM, they do so under HAILM's instructions and applicable contractual safeguards.

    2. Data Fiduciary and Contact Details

    HAILM's role as Data Fiduciary, joint Data Fiduciary, Data Processor, or service provider may vary by flow and must be confirmed by counsel, especially where schools upload or facilitate student data.

    Privacy contact: support@hailm.org

    3. Categories of Personal Data Collected

    HAILM may collect the following categories of data, depending on the user's role and the applicable flow:

    User categoryData categories
    StudentName, class/grade, school name, city, state, roll number or school identifier, email, phone number where used, login credentials, learning progress, assessment responses, completion records, certificate details, support communications.
    Parent or guardianName, relationship to student, email, phone number, consent records, support communications, payment details where applicable.
    TeacherName, school, subject, classes taught, email, phone number, login credentials, learning progress, certificate records, support communications.
    School or coordinatorSchool name, address, board, city, state, pincode, principal details, coordinator details, estimated student and teacher counts, participation preferences, support and onboarding records.
    Payment userPayment reference, invoice details, transaction status, refund status, payment gateway metadata, and limited billing details as required to process payment and comply with law.
    Website visitorDevice information, browser details, IP address, approximate location, pages visited, referral source, cookies, analytics identifiers, and consent preferences.
    Event or award participantEligibility records, attendance, submission details, scores, certificate data, award evidence, media consent records, photographs or videos where expressly consented.
    Olympiad participantLevel selected, payment status, attempt records, answer data, score, integrity logs, device/browser data, camera/microphone permission status, proctoring images/video/audio where used, room scan where required, identity verification status, phone verification or secondary-device status.

    HAILM should not collect Aadhaar number, Virtual ID, government identity documents, financial account credentials, health data, biometric data, or other sensitive identity material unless a separate counsel-approved process, notice, consent, and security design has been implemented.

    4. Sources of Data

    HAILM may receive personal data directly from students, parents or lawful guardians, teachers, principals, school coordinators, schools, payment gateways, support channels, webinar tools, learning systems, assessment systems, analytics systems, and implementation partners.

    Where a school provides or facilitates personal data, the school must ensure it has the necessary authority, internal approval, notice, and consent.

    5. Purposes of Processing

    HAILM may process personal data for the following purposes:

    • Registration, identity verification, and account creation;
    • Parent or lawful guardian consent capture and consent records;
    • School approval, coordinator activation, teacher activation, and student activation;
    • Delivery of learning modules, assessments, certificates, dashboards, support, and program updates;
    • Tracking completion, eligibility, certificate generation, rankings, awards, and event participation;
    • Sending operational communications, reminders, support responses, policy updates, payment receipts, and event notices;
    • Payment processing, invoicing, cancellation, refund, tax, and accounting records;
    • Child safety, academic integrity, fraud prevention, misuse prevention, security, and platform monitoring;
    • Olympiad proctoring, identity verification, test integrity checks, investigation of suspected malpractice, and result validation where the participant has opted into the paid Olympiad;
    • Analytics, product improvement, troubleshooting, and service reliability;
    • Compliance with law, legal requests, record-keeping, dispute resolution, and enforcement of terms.

    HAILM should not use children's personal data for targeted advertising, behavioural advertising, or behavioural monitoring for advertising purposes.

    6. Consent and Lawful Processing

    HAILM processes personal data only for lawful purposes and on a legally valid basis. Where consent is relied upon, consent must be free, specific, informed, unconditional, unambiguous, verifiable and based on a clear affirmative action. Consent must be limited to the personal data necessary for the stated purpose.

    Where the Data Principal is a child, consent must be obtained from the parent or lawful guardian before processing the child's personal data.

    HAILM must maintain records showing the notice presented, the version of the notice, the date and time of acceptance, the person accepting, the route, IP/device metadata where appropriate, and the consent purpose.

    7. Children's Data

    HAILM treats any user below 18 years as a child unless counsel approves a different legally valid operational rule. HAILM will not knowingly process a child's personal data without required parent or lawful guardian consent.

    HAILM will not knowingly process children's data in a way likely to cause detrimental effect on the well-being of a child. HAILM will not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

    Where a child participates in a paid Olympiad, HAILM should obtain separate parent or lawful guardian consent for proctoring data before the attempt. Proctoring must be limited to test integrity, identity verification, security, dispute review, and result validation, and must not be repurposed for advertising or unrelated profiling.

    Parent or guardian withdrawal may affect the child's ability to continue participating in HAILM, receive certificates, remain visible on leaderboards, participate in awards, or attend events.

    8. Olympiad Proctoring Data

    If proctoring is used for an Olympiad or paid competition, HAILM may process camera, microphone, device, browser, screen, phone, network, timestamp, identity, room environment, and activity data only to administer the Olympiad, prevent malpractice, validate results, resolve disputes, and protect the integrity of the competition.

    HAILM should disclose before payment or attempt:

    • What proctoring permissions are required;
    • Whether camera, microphone, screen, browser, or phone access is required;
    • Whether the session is recorded or only monitored;
    • Who reviews the proctoring records;
    • How long proctoring records are retained;
    • What conduct may result in warning, score hold, cancellation, disqualification, or re-test;
    • Whether any alternate arrangement is available if the participant cannot use the required permissions.

    Proctoring records should be accessed only by authorised personnel and vendors with a need to know.

    9. Cookies, Analytics, and Similar Technologies

    HAILM may use cookies and similar technologies for website functionality, security, analytics, preference storage, and service improvement. Non-essential cookies should be subject to consent where required. Details are set out in the Cookie Policy.

    HAILM should not deploy advertising pixels, retargeting tags, or child-directed behavioural tracking without counsel approval and a separate consent design.

    10. Sharing and Disclosure

    HAILM may share personal data with:

    • Schools, principals, coordinators, and teachers where necessary for school-led participation;
    • Parents or lawful guardians where required for child consent, support, safety, completion, payment, or withdrawal;
    • Learning platform, hosting, database, email, SMS, WhatsApp, payment, analytics, webinar, support, certificate, proctoring, and event service providers;
    • Authorised implementation partners where necessary for operating HAILM;
    • Legal, accounting, audit, compliance, and professional advisers;
    • Government, regulator, court, law enforcement, or statutory bodies where required by law.

    HAILM should require service providers to process personal data only for authorised purposes, maintain appropriate security, restrict onward sharing, and delete or return data when no longer required.

    11. Cross-Border Processing

    HAILM may use service providers or cloud infrastructure located in India or outside India. Cross-border processing must comply with applicable Indian law and any restrictions in force at the time of transfer. Counsel should confirm whether any specific country, category, or contractual restriction applies before publication.

    12. Retention

    HAILM retains personal data only for as long as necessary for the purpose for which it was collected, or for legal, audit, dispute, tax, accounting, security, certificate, or legitimate program records.

    Record categoryDraft retention position
    Incomplete registration180 days
    Active account and learning recordsDuration of participation plus 180 days
    Certificate and award records2 years
    Payment and invoice recordsAs required by tax, accounting, payment, and legal requirements
    Olympiad proctoring records60 days from results
    Support and grievance records1 year
    Consent recordsAs long as necessary to prove notice and consent, subject to law
    Event/media consent recordsDuration of use plus 1 year
    Analytics data1 year

    When the purpose is no longer served and no legal basis remains, HAILM will delete, de-identify, or aggregate the data as appropriate.

    13. Security

    HAILM will use reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, misuse, or destruction. Such measures may include access controls, password controls, encryption where appropriate, logging, backups, vendor controls, least-privilege access, incident response, and staff confidentiality obligations.

    No online system is fully secure. Users or their parent(s) and/or legal guardian(s), in case of a minor, must protect their login credentials and immediately report suspected unauthorised access.

    14. Data Principal Rights

    Subject to applicable law, a Data Principal may request access to information about personal data, correction, completion, updating, erasure, withdrawal of consent, grievance redressal, and nomination of another person where applicable.

    Where the Data Principal is a child, the parent or lawful guardian may exercise rights on behalf of the child, subject to identity and authority verification.

    Requests may be sent to: support@hailm.org

    15. Withdrawal of Consent

    Where processing is based on consent, consent may be withdrawn using a mechanism comparable in ease to the mechanism by which consent was given. Withdrawal will not affect processing already carried out before withdrawal. Withdrawal may limit or end access to HAILM features that require the relevant data.

    HAILM should maintain a practical withdrawal route for student, parent, teacher, and school flows before launch.

    16. Grievance Redressal

    Data principals may submit privacy grievances to: grievance@hailm.org

    HAILM will review and respond in accordance with applicable law and internal escalation procedures.

    17. Breach Notification

    If HAILM becomes aware of a personal data breach, it will assess the incident, take containment steps, investigate, preserve evidence, notify affected persons and authorities where legally required, and take remedial measures. Counsel should confirm notification timelines and content under rules in force at the time.

    18. Changes to This Policy

    HAILM may update this Privacy Policy. Material changes should be communicated through the website, account notice, email, or another reasonable channel. The effective date should be shown at the top of the policy.

    19. Contact

    For privacy questions or general support, contact: support@hailm.org