PsiQ
Home Assessments
Solutions
About
Support
Login

Privacy Policy

Last updated: September 21, 2026

This is a structured draft reflecting what this platform actually does — every clause below describes a real, built feature, not an aspiration. It has not been reviewed by a lawyer. Please have it reviewed before relying on it as your final published policy.

This policy explains what PsiQ ("we," "us," "the platform") collects, why, who can see it, how long we keep it, and the controls you have over it. It applies to everyone who uses PsiQ: individuals, students added by an institute, psychologists, institute administrators, and researchers.

1. What we collect

Account data: name, email address, phone number (where provided), password (stored as a salted hash — we never store or can retrieve your plaintext password), and role (individual, student, psychologist, institute administrator, researcher, or super admin). If you're a student added by an institute, your institute-provided details (enrollment number, grade/year, group assignment) are also stored, scoped to that institute only.

Assessment data: your item-by-item responses, response timestamps, computed raw scores, subscale scores, and percentile/stanine results where a normative dataset exists for that assessment. Draft/in-progress attempts are stored so a session can resume, and are locked from further editing once submitted or expired.

Payment data: we store the order amount, Razorpay order/payment IDs, and payment status. Your card, UPI, or bank details are entered directly into Razorpay's own checkout and never pass through or get stored on our servers.

Practice-management data (psychologists only): case notes, session/appointment records, and client notes you create for your own clients — scoped strictly to the psychologist-client relationship that already exists between you and that person.

Research data (researchers only): study definitions, participant group assignments, and custom demographic-form responses your participants submit for a specific study.

Technical data: IP address and basic request metadata, kept in server error logs and the audit log described below — used for security and debugging, not profiling.

Communications: messages you send through the Support Chat or Contact form, including any information you choose to include in them.

2. How we use your data

To provide the assessment and scoring service itself; to send account-related and transactional notifications (invitations, verification codes, password resets, assignment due dates, results ready, payment/invoice confirmations, security alerts on lockout) by email and in-app notification; to let institutes, psychologists, or researchers you're connected to see the specific data their role and relationship to you actually authorizes, and nothing more; to detect and prevent abuse (rate limiting, account lockout after repeated failed logins); and to maintain the audit trail described in Section 6.

We do not use your data for advertising, do not sell it to third parties, and do not run behavioral profiling on it.

3. Legal basis for processing

Under India's Digital Personal Data Protection Act, 2023 (DPDPA), we process your personal data on the basis of your consent, given when you create an account or when an institute/psychologist adds you and you subsequently accept access, and on the basis of legitimate use for administrative purposes explicitly permitted under the Act, such as maintaining records for legal, audit, or dispute-resolution purposes. You may withdraw consent at any time by deleting your account (Section 7), subject to the retention exceptions described in Section 8.

4. Who can see your results

Your assessment results are visible only to: you; a super administrator (for platform operation and support); an institute administrator, but only if you are a current student at that specific institute — enforced at the database query layer, so one institute's administrator can never query another institute's data; or a psychologist, but only for a client relationship that already exists in our system (either because an institute added you under that psychologist, or you accepted that psychologist's invitation). Independent psychologists and researchers see only their own clients or study participants, never anyone else's. No one outside these relationships can see your individual results — not other students, not other institutes, not other psychologists.

Our public verification page (/verify.php) is intentionally minimal: given a report ID, it shows only that a report with that ID exists, the name on it, and the date issued — never scores, subscale breakdowns, or any other personal detail. It exists to let a third party (e.g., an employer checking a submitted PDF) confirm a report is genuine, without exposing what's in it.

5. Students, minors, and institute consent

Where an account is created for a student by an institute rather than by self-registration, the institute is responsible for obtaining any parental/guardian consent required under applicable law before adding a minor. PsiQ's role in that relationship is to store the data the institute provides and enforce that only that institute (and, where applicable, a psychologist explicitly authorized by that institute) can access it.

6. How we secure your data

Passwords are hashed, never stored or logged in plaintext. Every state-changing action on the platform — logins, failed login attempts, data exports, account deletions, assignment changes, and more — is written to an append-only audit_logs table from day one of this platform's build, not added later as an afterthought. Two-factor authentication (email OTP) is available for super admins, institute admins, and psychologists. Sessions are invalidated and regenerated on login to prevent session fixation, and you can view and revoke your own active sessions from your account settings. All traffic to PsiQ is served over HTTPS.

7. Your rights over your data

You can, at any time, from your account's Privacy settings:

You may also contact us (Section 14) to request correction of inaccurate data we hold about you.

8. Data retention

We retain account and assessment data for as long as your account is active. After a deletion request, anonymized result records and audit-log entries may be retained where an institute, psychologist, or PsiQ itself has a legal, contractual, or professional-standards reason to keep them (for example, a clinical record-keeping obligation, or a payment record required for tax purposes) — always without your name or contact details attached once anonymized.

9. Cookies and sessions

We use one session cookie to keep you signed in, and (where you've opted in) a "remember this device" mechanism for two-factor authentication. We do not use third-party advertising, analytics, or cross-site tracking cookies.

10. Third-party processors

We share the minimum data necessary with:

We do not have any other third-party integrations that receive your personal data.

11. Where your data is stored

Your data is stored on servers located in India. We do not transfer personal data outside India except where a third-party processor listed in Section 10 does so as part of its own infrastructure (Razorpay's own compliance obligations apply to payment data it holds).

12. Breach notification

If we become aware of a personal data breach that is likely to affect you, we will notify affected users and the relevant regulatory authority as required under the DPDPA and applicable rules, without undue delay.

13. Changes to this policy

We may update this policy as the platform's features change. Material changes will be reflected by updating the "Last updated" date above; continued use of PsiQ after a change constitutes acceptance of the updated policy.

14. Grievance officer & contact

For privacy questions, data requests, or complaints about how your data has been handled, contact us. In accordance with the Information Technology Act, 2000 and its associated rules, PsiQ will designate a Grievance Officer to address complaints within the statutory timeframe once operating with real user data at scale; until that designation is published here, the contact form above is monitored and routed to the team responsible for privacy requests.