Privacy Policy · v2.0

Privacy Policy

Effective Date: August 17, 2026

Data Principal Notice: This privacy policy outlines how Fensta collects, processes, stores, and protects personal data in compliance with the Digital Personal Data Protection Act (DPDPA), 2023 and the Information Technology Act, 2000. Fensta acts as a data fiduciary/processor for campus events and institutional workflows.

1. Categories of Personal Data Handled

To deliver multi-tenant campus management services, Fensta processes the following categories of personal data:

  • Identity & Profile Data: Full legal name, institutional email address, phone number, avatar/profile image, and biographical description.
  • Academic & Institutional Credentials: Affiliated college/university name, department, academic degree/program, expected graduation year, and official student roll number or institutional identifier.
  • Event & Participation Records: Event registrations, dynamically encrypted QR digital pass tokens, timestamped check-in attendance records, and hackathon round submissions.
  • Volunteer & Role History: Volunteer applications, assigned coordination roles, selection statuses, and organizer reviews.
  • Certificates & Badges: Issued digital certificates of merit/participation, recipient identifiers, issue dates, and public cryptographic verification hashes.
  • Technical & Telemetry Data: Browser session information, IP addresses (logged only for critical security events), and device user-agents captured upon affirmative policy consent.

2. Purposes & Legal Grounds for Processing

Personal data is collected and processed strictly under specified, lawful grounds:

  • Authentication & Role-Based Access Control (RBAC): Authenticating users and enforcing tenant isolation across Student, Faculty, Host, University Admin, and Super Admin roles.
  • Event Operations: Processing registrations, enforcing capacity limits, delivering digital passes, and verifying on-site attendance via QR scanning.
  • Credentialing: Generating tamper-resistant digital certificates with unique public verification URLs.
  • Governance & Safety: Maintaining immutable audit logs of administrative actions and mitigating security risks or academic fraud.

3. Third-Party Data Processors & Cloud Infrastructure

Fensta utilizes SOC-2 / ISO-27001 compliant cloud infrastructure providers to securely host platform data:

  • Database & Storage: Supabase (PostgreSQL with Row-Level Security and encrypted cloud object storage).
  • Application Hosting & Edge Delivery: Vercel (Edge serverless execution with TLS 1.3 transport encryption).
  • Authentication Providers: Google OAuth 2.0 (optional third-party sign-in provider).

Fensta does not sell, rent, or monetize personal data to advertising brokers or non-essential third parties.

4. Data Principal Rights under DPDPA 2023

Under the Digital Personal Data Protection Act, 2023, you hold statutory rights regarding your personal data:

  • Right to Information: The right to obtain a summary of personal data being processed and the identities of data fiduciaries/processors.
  • Right to Correction & Erasure: The right to rectify inaccurate data or request deletion via our Account & Data Deletion Portal.
  • Right to Grievance Redressal: The right to seek resolution of grievances with our designated Grievance Officer.
  • Right to Nominate: The right to nominate an individual to exercise rights on your behalf in the event of incapacity.

5. Data Retention & Cryptographic Security

Personal data is retained only for the duration necessary to satisfy event administration, institutional accreditation, dispute resolution, and statutory compliance.

We implement comprehensive security controls including Row-Level Security (RLS) database policies, encrypted HTTPS/TLS in transit, salted password hashing, and role-gated API authorization. While we employ industry-standard safeguards, no digital system can guarantee absolute security against all unforeseen vulnerabilities.

6. Grievance Officer & Contact Information

For inquiries regarding personal data protection, consent withdrawal, or to escalate a privacy concern, contact our privacy desk:

Grievance Office: Fensta Privacy & Legal Compliance

Grievance Portal: Submit a Grievance

Jurisdiction: Bengaluru, Karnataka, Republic of India