Privacy Policy
Effective Date: August 17, 2026
1. Categories of Personal Data Handled
To deliver multi-tenant campus management services, Fensta processes the following categories of personal data:
- Identity & Profile Data: Full legal name, institutional email address, phone number, avatar/profile image, and biographical description.
- Academic & Institutional Credentials: Affiliated college/university name, department, academic degree/program, expected graduation year, and official student roll number or institutional identifier.
- Event & Participation Records: Event registrations, dynamically encrypted QR digital pass tokens, timestamped check-in attendance records, and hackathon round submissions.
- Volunteer & Role History: Volunteer applications, assigned coordination roles, selection statuses, and organizer reviews.
- Certificates & Badges: Issued digital certificates of merit/participation, recipient identifiers, issue dates, and public cryptographic verification hashes.
- Technical & Telemetry Data: Browser session information, IP addresses (logged only for critical security events), and device user-agents captured upon affirmative policy consent.
2. Purposes & Legal Grounds for Processing
Personal data is collected and processed strictly under specified, lawful grounds:
- Authentication & Role-Based Access Control (RBAC): Authenticating users and enforcing tenant isolation across Student, Faculty, Host, University Admin, and Super Admin roles.
- Event Operations: Processing registrations, enforcing capacity limits, delivering digital passes, and verifying on-site attendance via QR scanning.
- Credentialing: Generating tamper-resistant digital certificates with unique public verification URLs.
- Governance & Safety: Maintaining immutable audit logs of administrative actions and mitigating security risks or academic fraud.
3. Third-Party Data Processors & Cloud Infrastructure
Fensta utilizes SOC-2 / ISO-27001 compliant cloud infrastructure providers to securely host platform data:
- Database & Storage: Supabase (PostgreSQL with Row-Level Security and encrypted cloud object storage).
- Application Hosting & Edge Delivery: Vercel (Edge serverless execution with TLS 1.3 transport encryption).
- Authentication Providers: Google OAuth 2.0 (optional third-party sign-in provider).
Fensta does not sell, rent, or monetize personal data to advertising brokers or non-essential third parties.
4. Data Principal Rights under DPDPA 2023
Under the Digital Personal Data Protection Act, 2023, you hold statutory rights regarding your personal data:
- Right to Information: The right to obtain a summary of personal data being processed and the identities of data fiduciaries/processors.
- Right to Correction & Erasure: The right to rectify inaccurate data or request deletion via our Account & Data Deletion Portal.
- Right to Grievance Redressal: The right to seek resolution of grievances with our designated Grievance Officer.
- Right to Nominate: The right to nominate an individual to exercise rights on your behalf in the event of incapacity.
5. Data Retention & Cryptographic Security
Personal data is retained only for the duration necessary to satisfy event administration, institutional accreditation, dispute resolution, and statutory compliance.
We implement comprehensive security controls including Row-Level Security (RLS) database policies, encrypted HTTPS/TLS in transit, salted password hashing, and role-gated API authorization. While we employ industry-standard safeguards, no digital system can guarantee absolute security against all unforeseen vulnerabilities.
6. Grievance Officer & Contact Information
For inquiries regarding personal data protection, consent withdrawal, or to escalate a privacy concern, contact our privacy desk:
Grievance Office: Fensta Privacy & Legal Compliance
Grievance Portal: Submit a Grievance
Jurisdiction: Bengaluru, Karnataka, Republic of India