> Cogitating_
> Cogitating_
ApexDevs handles the personal data of Data Principals in India. This page summarises the controls, processes, and contractual measures we have in place to meet the requirements of the Digital Personal Data Protection Act, 2023.
A DPDP §6-aligned notice listing the data we collect, the purposes we process it for, the legal basis (your consent), our processors, retention periods, and your rights.
Read the notice →You must tick a consent box at sign-up and again at internship enrolment before any personal data is processed. Consent is granular, recorded with a timestamp, and withdrawable.
We collect only what we need: name, contact details, address with pin code, and one institution / college ID. We do NOT collect Aadhaar, Passport, Driving Licence, Voter ID, or any other government-issued ID. We do not store payment card data — that lives at Razorpay.
Download a JSON copy of every piece of personal data tied to your account from the Profile page in one click.
Profile → Your Data Rights →Request deletion of your account and personal data from your Profile. We act within 30 days, retaining only what Indian law obliges us to keep (tax records, certificate metadata).
Profile → Your Data Rights →A single point of contact (grievance@apexdevs.io) for any privacy concern, with a 30-day response SLA, per DPDP §8(9). Unresolved grievances may be escalated to the Data Protection Board of India.
We have a written incident-response process. Any breach likely to cause harm is notified to both the Data Protection Board and to affected Data Principals within the timeframe prescribed by the Rules, per DPDP §8(6).
TLS in transit, Postgres Row-Level Security on every table, private access-controlled storage for the institution ID and résumé uploads, bcrypt-hashed passwords, least-privilege admin access, and processor relationships covered by published standard terms with data-protection commitments equivalent to those required by the DPDP Act.
Strictly necessary authentication cookies always run. Google Analytics (anonymised IP, measurement ID G-QF3KB9R9XH) loads only after you accept it in the consent banner shown on first visit. No advertising, social-media tracking, or cross-site cookies of any kind.
| Right | Reference | How to exercise |
|---|---|---|
| Right to access | DPDP §11 | Profile → Export my data (JSON) |
| Right to correction | DPDP §12 | Edit fields directly on Profile, or open a help ticket |
| Right to erasure | DPDP §12 | Profile → Request account deletion |
| Right to grievance | DPDP §13 | grievance@apexdevs.io (30-day SLA) |
| Right to nominate | DPDP §14 | Email Grievance Officer to record a nominee |
| Withdraw consent | DPDP §6 | Profile → Withdraw consent |
We share strictly the personal data necessary, only with the processors below. Each operates under their published standard terms of service, which include data-protection commitments equivalent to those required by the DPDP Act.
| Processor | Purpose | Notes |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | AWS-backed; institution-ID and résumé uploads in private buckets |
| Razorpay Software Pvt. Ltd. | Payment processing | Card / UPI / net-banking data never touches our servers |
| Microsoft Corporation (Outlook 365) | Transactional email | Sender mailbox controlled by HR / admin team |
| Google LLC (Google Analytics) | Anonymised usage measurement | Loaded only when the user accepts analytics in the consent banner |
Raise any privacy concern, rights request, or breach report with our Grievance Officer, Abhi Mitra (Founder, Motionwave Studios LLP). We respond within 30 days. Unresolved grievances may be escalated to the Data Protection Board of India.
grievance@apexdevs.io