Privacy Policy
Last updated: September 24, 2026
This is a structured draft reflecting what this platform actually does — every clause below describes a real, built feature, not an aspiration. It has not been reviewed by a lawyer. Please have it reviewed before relying on it as your final published policy.
This policy explains what PsiQ ("we," "us," "the platform") collects, why, who can see it, how long we keep it, and the controls you have over it. It applies to everyone who uses PsiQ: individuals, students added by an institute, psychologists, institute administrators, and researchers.
- What we collect
- How we use your data
- Legal basis for processing
- Who can see your results
- Students, minors, and institute consent
- How we secure your data
- Your rights over your data
- Data retention
- Cookies and sessions
- Third-party processors
- Where your data is stored
- Breach notification
- Changes to this policy
- Grievance officer & contact
1. What we collect
Account data: name, email address, phone number (where provided), password (stored as a salted hash — we never store or can retrieve your plaintext password), and role (individual, student, psychologist, institute administrator, researcher, or super admin). If you're a student added by an institute, your institute-provided details (enrollment number, grade/year, group assignment) are also stored, scoped to that institute only.
Assessment data: your item-by-item responses, response timestamps, computed raw scores, subscale scores, and percentile/stanine results where a normative dataset exists for that assessment. Draft/in-progress attempts are stored so a session can resume, and are locked from further editing once submitted or expired.
Payment data: we store the order amount, Razorpay order/payment IDs, and payment status. Your card, UPI, or bank details are entered directly into Razorpay's own checkout and never pass through or get stored on our servers.
Practice-management data (psychologists only): case notes, session/appointment records, and client notes you create for your own clients — scoped strictly to the psychologist-client relationship that already exists between you and that person.
Research data (researchers only): study definitions, participant group assignments, and custom demographic-form responses your participants submit for a specific study.
Technical and usage data: IP address and basic request metadata, kept in server error logs and the audit log described below, plus public-page usage information collected through Google Analytics. We use this information for security, debugging, and understanding public-site use; we do not sell it or use it for targeted advertising.
Communications: messages you send through the Support Chat or Contact form, including any information you choose to include in them.
2. How we use your data
To provide the assessment and scoring service itself; to send account-related and transactional notifications (invitations, verification codes, password resets, assignment due dates, results ready, payment/invoice confirmations, security alerts on lockout) by email and in-app notification; to let institutes, psychologists, or researchers you're connected to see the specific data their role and relationship to you actually authorizes, and nothing more; to detect and prevent abuse (rate limiting, account lockout after repeated failed logins); and to maintain the audit trail described in Section 6.
We do not use your data for advertising, do not sell it to third parties, and do not run behavioral profiling on it.
3. Legal basis for processing
Under India's Digital Personal Data Protection Act, 2023 (DPDPA), we process your personal data on the basis of your affirmative, informed consent, given when you create an account, accept an institutional invitation, or take an assessment. Where data relates to mental health screening and psychological testing, processing is further governed by the duty of confidentiality and consent principles under Section 23 of the Mental Healthcare Act, 2017 (MHCA). We also process certain administrative and audit data on the basis of legitimate uses explicitly recognized under the DPDPA, such as maintaining security audit logs, fulfilling tax/invoicing statutory obligations, and resolving legal claims. You may withdraw consent at any time by requesting deletion of your account (Section 7), subject to statutory record-retention requirements described in Section 8.
4. Who can see your results & MHCA 2017 confidentiality
In strict alignment with Section 23 of the Mental Healthcare Act, 2017 (Right to Confidentiality), your psychological assessments, item responses, and reports are treated as privileged and confidential. They are visible only to:
- You (the individual assessment-taker);
- Your authorized psychologist or clinician, but strictly within an active professional-client relationship established on the platform;
- Your educational institute administrator, if your account was provisioned by that specific school or university, strictly isolated at the database tenant query layer so that no other institute or unauthorized third party can ever query your records;
- Platform authorized technical administrators, strictly under non-disclosure obligations for infrastructure maintenance, bug remediation, or security auditing.
Your assessment scores, subscale breakdowns, and psychological responses are never sold, never disclosed to employers, insurers, or commercial data brokers, and never made publicly visible.
Our public verification endpoint (/verify.php) is intentionally zero-knowledge: when presented with a specific report verification code, it displays only that a valid certificate was issued, the participant name, and the issuance timestamp — never score metrics, mental health indices, or item responses.
5. Processing data of children & minors (Section 9, DPDPA 2023)
PsiQ is committed to the highest standards of child data protection in compliance with Section 9 of the Digital Personal Data Protection Act, 2023:
- Verifiable Parental Consent: Independent self-registration on PsiQ requires the user to be at least 18 years of age. For children and adolescents under 18 years of age (including participants taking developmental and age-calibrated IQ tests), testing must be initiated, authorized, and supervised by a parent or lawful guardian who provides verifiable consent.
- Educational Institute Enrollments: Where a school, college, or academic institute registers student accounts or assigns cognitive assessments to minors, the institute contractually certifies that it has secured prior verifiable parental or legal guardian consent in accordance with Section 9(1) of the DPDPA 2023.
- No Tracking or Profiling of Children: In strict compliance with Section 9(2) and Section 9(3) of the DPDPA 2023, PsiQ does not undertake tracking, behavioral monitoring, targeted advertising, or any processing of children's data that is likely to cause any detrimental effect on the physical, mental, or emotional well-being of a child.
6. How we secure your data
Passwords are hashed, never stored or logged in plaintext. Every state-changing action on the
platform — logins, failed login attempts, data exports, account deletions, assignment changes,
and more — is written to an append-only audit_logs table from day one of this
platform's build, not added later as an afterthought. Two-factor authentication (email OTP) is
available for super admins, institute admins, and psychologists. Sessions are invalidated and
regenerated on login to prevent session fixation, and you can view and revoke your own active
sessions from your account settings. All traffic to PsiQ is served over HTTPS.
7. Your rights over your data
You can, at any time, from your account's Privacy settings:
- Export a full copy of your own data — profile, results, sessions, orders, and notifications — as a JSON file you can keep or move elsewhere.
- Delete your account. This anonymizes your personal information (your name is replaced with "Deleted User," your email with a random placeholder, and your password is rotated) rather than erasing the underlying records outright — the same approach used by most professional testing and clinical platforms, so that an institute's audit trail or a psychologist's clinical record obligations aren't broken by a deletion request. Deletion requires re-entering your password and typing "DELETE" to confirm, specifically so it can't happen by accident.
You may also contact us (Section 14) to request correction of inaccurate data we hold about you.
8. Data retention
We retain account and assessment data for as long as your account is active. After a deletion request, anonymized result records and audit-log entries may be retained where an institute, psychologist, or PsiQ itself has a legal, contractual, or professional-standards reason to keep them (for example, a clinical record-keeping obligation, or a payment record required for tax purposes) — always without your name or contact details attached once anonymized.
9. Cookies and sessions
We use a session cookie to keep you signed in and, where you've opted in, a "remember this device" mechanism for two-factor authentication. Public pages also load Google Analytics to measure site usage. We do not use advertising cookies, Meta Pixel, or other cross-site advertising trackers.
10. Third-party processors
We share the minimum data necessary with:
- Razorpay — payment processing. Receives your payment details directly (we never see your card/bank details) and the order amount/reference we generate.
- Our email delivery provider (SMTP) — sends transactional email only (verification codes, notifications, invoices). Receives your email address and the message content of that specific email.
- Google Analytics — measures use of public pages. Google may receive technical information such as IP address, browser/device information, and page interactions in connection with this service.
- Google Fonts — provides web fonts used by the public site. Your browser connects to Google's font service when loading a page that uses those fonts.
We do not sell personal data or share it with third parties for targeted advertising.
11. Where your data is stored
The platform's primary application and database are intended to be hosted in India. Third-party services listed in Section 10 may process technical or transaction-related data through their own infrastructure, which may involve processing outside India. Their own privacy notices also apply to the data they process.
12. Breach notification
If we become aware of a personal data breach that is likely to affect you, we will notify affected users and the relevant regulatory authority as required under the DPDPA and applicable rules, without undue delay.
13. Changes to this policy
We may update this policy as the platform's features change. Material changes will be reflected by updating the "Last updated" date above; continued use of PsiQ after a change constitutes acceptance of the updated policy.
14. Statutory Grievance Officer & Redressal Mechanism (IT Rules 2021 & DPDPA 2023)
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 13 of the Digital Personal Data Protection Act, 2023, PsiQ has appointed a designated Grievance Officer and Data Protection Officer to address grievances concerning data privacy, personal data rights, and platform compliance.
Grievance Redressal & Data Protection Officer
- Designation: Grievance Redressal & Data Protection Officer
- Entity: PsiQ Psychometrics Platform
- Official Grievance Email: grievance@psiq.in
- General Data Support: privacy@psiq.in / Online Contact Desk
- Jurisdiction & Domicile: India
Statutory Resolution Timelines: We will acknowledge receipt of your formal privacy or content grievance within 24 to 48 hours and provide a reasoned resolution or response within 15 calendar days as mandated under Indian cyber laws. If a grievance pertains to unauthorized access or breach of personal data, escalated triage is initiated immediately.