T
Techvein QA
Privacy Notice

Privacy Notice

Techvein QA is an internal quality-assurance and progress-tracking system used by Techvein staff. This notice explains what personal data the system processes and your rights under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). It applies to everyone who signs in — staff, team leads, faculty and administrators.

Who is responsible

Techvein is the Data Fiduciary for the personal data in this system. Questions and requests about your data go to the Grievance Officer named at the end of this notice.

What we collect

  • Account details — your name, work email address, assigned role and the schools or projects allocated to you.
  • Authentication data — a hashed password (Argon2id, never stored in the clear), optional two-factor secret, and sign-in / lockout timestamps.
  • Work you record — items, notes, comments, @mentions, escalations, QA scores and any files you attach.
  • Activity log — an audit trail of significant actions (who changed what, and when) for accountability.
  • Technical data — your IP address, used transiently to rate-limit sign-in attempts and secure the service. We do not use advertising or tracking cookies; the only cookie is the one that keeps you signed in.

Why we use it

We process this data to operate the quality-tracking service you were given access to: to authenticate you, apply your role’s permissions, record and report on quality and progress across schools and projects, send you notifications you have not turned off, and keep the system secure. This is processing for Techvein’s legitimate employment and operational purposes; we do not sell personal data or use it for any unrelated purpose.

Who we share it with

Access inside the system is limited by your role and scope. Outside the system we rely on a small number of processors who act only on our instructions:

  • Email delivery — a transactional email provider sends notification and account emails.
  • Hosting & storage — the application, database and any uploaded files are hosted on our cloud infrastructure in India.

We do not disclose personal data to any other party except where the law requires it.

How we protect it

Passwords are hashed with Argon2id and checked against known-breach lists; sessions expire after inactivity and have an absolute cap; access is enforced by role on every request; uploads are size- and type-checked; connections are encrypted in transit (HTTPS/HSTS) and the application sends a Content-Security-Policy and related protective headers. Databases are backed up on a schedule.

How long we keep it

Account and work records are retained for as long as your account is active and for as long afterwards as needed for audit, legal and legitimate business reasons. When an account is deactivated, the work it produced may be reassigned or retained for continuity, and personal identifiers are removed or restricted when they are no longer needed.

Your rights

Under the DPDP Act you may, in respect of your own personal data:

  • ask for access to a summary of the personal data we process about you;
  • ask us to correct or complete inaccurate or incomplete data;
  • ask us to erase data that is no longer needed, subject to our legal and audit obligations;
  • nominate another person to exercise these rights on your behalf; and
  • raise a grievance and, if unsatisfied, complain to the Data Protection Board of India.

You are responsible for keeping the data you enter accurate and for only entering data you are authorised to record.

Grievance Officer

To exercise any right above or raise a concern, contact the Grievance Officer at privacy@techvein.com. We respond within the timelines set by the DPDP Act.