01 Introduction
EMBASE Pro Suit Private Limited ("EMBASE", "we", "our" or "us") respects the privacy of applicants, students, parents and guardians, faculty members, employees, alumni, institutional administrators, website visitors and other authorised users.
This Public Privacy Policy explains what personal data may be processed through EMBASE products and services, why it is processed, how responsibilities are divided between EMBASE and educational institutions, how information is protected, when it may be shared or retained, and how individuals can exercise their privacy rights.
This Policy applies to EMBASE websites, web applications, mobile applications, cloud services, support channels and related services that refer to this Policy. A specific product, module, institution or activity may provide an additional privacy notice. That additional notice will apply together with this Policy and will control for that specific processing if there is a direct conflict.
02 Legal identity
EMBASE PRO SUIT PRIVATE LIMITED is a company incorporated in India under the Companies Act, 2013.
- Corporate Identification Number (CIN): U72900KL2021PTC071582
- Registered office: Room No. 10/572, MGU Innovation Foundation, Priyadarshini Hills, Athirampuzha, Kottayam, Kerala 686562, India
- General contact: mail@embase.in
- Privacy and grievance contact: legal@embase.in
- Security incident reporting: isms@embase.in
- Website: https://egov.embase.in
When a complaint concerns an institution-controlled record or decision, EMBASE may forward it to the authorised institution contact and assist with the response. This will not prevent EMBASE from addressing any separate responsibility it has under applicable law.
03 Our role and the institution’s role
3.1 Institution-controlled educational records
EMBASE is primarily a business-to-business education technology platform. When a college, university or other educational institution uses EMBASE to manage applicants, students, guardians, faculty, staff, academic activity, examinations, finance, HR or administration, the institution normally determines the purposes for which those records are processed.
In this context, the institution generally acts as the Data Fiduciary or data controller and EMBASE generally acts as its Data Processor or service provider. EMBASE processes the data under the institution’s documented instructions, the applicable service agreement and data-processing terms, except where law requires or permits otherwise.
The institution is responsible for determining the authorised purposes, user access, required notices or consents, record accuracy, institutional retention requirements and lawful disclosure of its records. EMBASE provides technical and organisational support to help the institution fulfil these responsibilities.
3.2 Information controlled directly by EMBASE
EMBASE may act as a Data Fiduciary or independent controller for personal data that it processes for its own legitimate business and legal purposes, including:
- Website enquiries, sales enquiries and product demonstrations
- Customer account administration, contracts, billing and subscription management
- Customer support, service requests, feedback and QMS records
- Platform authentication, service monitoring, fraud prevention and cybersecurity
- Business communications, training and events
- Legal, audit, tax and regulatory compliance
The exact allocation of responsibilities may vary by service and contract. Where appropriate, the applicable institution may provide a supplementary notice explaining its own processing.
04 Who this Policy covers
This Policy may apply to personal data relating to:
- Prospective applicants and applicants
- Current and former students
- Parents, guardians and emergency contacts
- Faculty members, instructors, mentors and academic staff
- Administrative, finance, HR, library, examination and support staff
- Alumni and former employees
- Institutional administrators and authorised representatives
- Website visitors, prospective customers, vendors and professional contacts
- Other individuals whose personal data is lawfully entered into or generated through an enabled EMBASE service
05 Personal data we process
The information processed depends on the institution, user role, modules enabled, permissions granted and services used. EMBASE may process the following categories.
Identity and profile information
Name, photograph, date of birth, age, gender, username, admission number, employee or faculty identifier, university registration number and other institutional identifiers.
Contact information
Postal address, email address, mobile number, alternative contact, emergency contact and communication preferences.
Admission and enrolment information
Application details, programme preferences, eligibility, rank, quota or category information, certificates, allotment, admission status, programme, batch and enrolment history.
Academic and learning information
Programme and course registrations, timetable, attendance, leave or duty records, assignments, lesson plans, LMS activity, assessments, marks, grades, credits, OBE data, academic progress and feedback.
Examination information
Examination registration, fee status, hall ticket information, seating and room allocation, invigilation records, question or answer processing records, valuation, moderation, results, revaluation and marksheet information.
Guardian and family information
Parent or guardian name, relationship, contact details, communication preferences and information necessary for authorised institutional processes.
Financial and payment information
Fees, concessions, scholarships, payment requests, transaction references, payment status, refunds, accounting entries, bank-related details where necessary, payroll, remuneration and reimbursement information.
Employment and HR information
Employment details, qualifications, contracts, designation, department, workload, attendance, leave, salary components, deductions, performance and statutory employment records.
Communication and content
Notifications, messages, comments, support tickets, attachments, documents, photographs, audio or video submitted through an enabled service and communications with EMBASE or the institution.
Technical and usage information
IP address, browser, device type, operating system, app version, login and session events, timestamps, feature interactions, diagnostic information, crash records, audit trails and security logs.
Special or high-risk institutional information
Health, disability, community, religion, socioeconomic, government-identifier, bank, statutory or similar information where an institution is legally permitted and requires it for an identified educational, employment, financial, safety or compliance purpose.
06 Sources of personal data
Personal data may be obtained from:
- The individual, including through forms, uploads, account settings, support requests or communications
- The educational institution and its authorised administrators
- Parents, guardians, referees or authorised representatives
- Universities, boards, government bodies or other authorities where lawful
- Payment gateways, banks, identity providers, communication providers and authorised integration partners
- Devices, browsers, applications and security systems when the service is used
- Existing institutional records that are migrated into EMBASE under the institution’s instructions
07 Why personal data is processed
Depending on the service and applicable law, personal data may be processed to:
- Create, authenticate, manage and protect user accounts
- Manage enquiries, applications, admissions, enrolment and student records
- Deliver academic, learning, attendance, examination and outcome-based education services
- Manage institutional finance, fees, payments, scholarships, concessions, accounting and reporting
- Manage faculty, staff, HR, contracts, payroll, leave, workload and statutory obligations
- Provide communications, alerts, notices, reminders and emergency messages
- Provide library, hostel, transport, event, alumni, accreditation and other enabled institutional functions
- Generate authorised reports, analytics, dashboards and operational insights
- Provide customer support, troubleshoot problems and improve service reliability
- Detect, prevent and investigate unauthorised access, fraud, abuse, security threats and technical failures
- Maintain audit trails, backups, business continuity and disaster recovery
- Comply with applicable law, court orders, regulatory requirements, university rules and lawful government requests
- Establish, exercise or defend legal claims and enforce applicable agreements
- Improve products and services using aggregated or de-identified information wherever reasonably practicable
08 Grounds for processing
EMBASE and institutions process personal data only for lawful purposes. Depending on the circumstances and applicable law, processing may be based on:
- Consent that is free, specific, informed, unconditional and unambiguous, where consent is required
- The individual voluntarily providing personal data for a specified service or request
- The institution’s lawful educational, administrative, employment or statutory functions
- Compliance with applicable law, university regulations, court or government directions
- Employment-related purposes and safeguarding the institution or EMBASE from loss or liability
- Medical emergencies, safety, disaster response or other uses permitted by applicable law
- Other lawful or legitimate uses recognised by applicable data-protection law
Where consent is the basis of processing, it may be withdrawn using the available account, institution or privacy-request channel. Withdrawal does not affect processing lawfully completed before withdrawal. A service that necessarily depends on the withdrawn data may no longer be available.
09 Institution administrators and authorised access
Institution administrators and other authorised users may access institutional records according to roles and permissions configured by the institution. Depending on their role, they may be able to view, create, correct, export, restrict, archive or delete records; reset credentials; manage permissions; suspend access; and produce institutional reports.
Users should direct questions about institutional decisions, academic records, attendance, marks, employment, fees or institution-configured access to the relevant institution. EMBASE does not independently alter institution-controlled records except under authorised instructions, for security or support where permitted, or where required by law.
10 Payments and financial processing
When an institution enables online payments, payment credentials may be processed by an authorised payment gateway, bank or payment service provider. EMBASE may receive information such as payer identity, institution, amount, transaction reference, date, payment status, reconciliation status, refund status and masked payment information.
EMBASE does not intentionally store complete payment-card credentials. Users should not send card numbers, PINs, passwords or one-time passwords through support tickets, email or chat. Payment providers process information under their own terms and privacy notices in addition to the institution’s arrangements.
11 Location, biometrics and attendance technologies
11.1 Location
Location data is processed only when a location-dependent feature is enabled for an identified purpose such as authorised attendance, institutional transport or campus safety. The data collected may depend on device permissions and the institution’s configuration. Users may control device permissions, but disabling a permission may prevent the related feature from working.
11.2 Facial recognition and other biometrics
Where an institution enables biometric attendance or identity verification, EMBASE may process facial images and derived biometric templates under the institution’s instructions. Such processing must be limited to the disclosed purpose, protected through restricted access and retained only for the required period.
A biometric match is an automated indicator and should be subject to appropriate human review where it may materially affect attendance, access or another individual outcome. A failed or uncertain match should not by itself create an irreversible adverse decision. Alternative verification procedures are determined by the institution and applicable requirements.
12 Artificial intelligence and automated features
EMBASE may offer institution-enabled AI features for tasks such as document extraction, classification, search, summarisation, data validation, academic or institutional analytics, student-success indicators, anomaly detection, accreditation mapping and recommendations.
AI-generated outputs may be incomplete or inaccurate. They are intended to assist authorised users and should not be treated as the sole basis for a final admission, academic, employment, disciplinary, financial or other consequential decision without appropriate human review.
EMBASE does not use institution-controlled personal data to train a general-purpose AI model unless the institution has expressly authorised that use through a separate written arrangement. EMBASE may use aggregated or de-identified information to improve service quality where permitted and where individuals are not reasonably identifiable.
Where an external AI service provider is used, EMBASE will apply appropriate contractual, access, security and purpose limitations and will disclose relevant provider categories through institutional documentation or an applicable feature notice.
13 Sharing and disclosure
EMBASE does not sell, rent or trade personal data. Personal data may be disclosed only as reasonably necessary to:
- The relevant institution, its authorised users and approved institutional bodies
- Service providers that support hosting, infrastructure, communications, payments, identity, security, analytics, support, backup or other authorised platform functions
- Universities, boards, accreditation bodies, banks, auditors or government authorities where instructed by the institution and lawfully permitted
- Courts, law-enforcement agencies, regulators or government bodies where disclosure is required or permitted by law
- Professional advisers such as lawyers, auditors and insurers who are subject to confidentiality obligations
- A successor, investor or relevant counterparty in a lawful merger, acquisition, restructuring, financing or transfer, subject to appropriate confidentiality and notice requirements
Service providers are permitted to process personal data only for the contracted service and are required to apply appropriate confidentiality and security safeguards. The institution may request information about relevant subprocessors through its authorised representative.
14 International processing and transfers
EMBASE's primary infrastructure for the Services is hosted within India (AWS, Mumbai region). Personal Data is not transferred outside India in the ordinary course of providing the Services.
Where a specific integration, support function, or authorised service provider necessarily involves processing outside India, such transfer will be made only (a) to a jurisdiction or entity not restricted under applicable Indian law, including any list of countries or territories notified by the Central Government under the Digital Personal Data Protection Act, 2023; and (b) subject to appropriate contractual safeguards, such as Standard Contractual Clauses, data-processing terms, or comparable measures appropriate to the nature and risk of the processing.
Institutions may request further information relevant to hosting or processing location through their authorised representative.
15 Cookies and similar technologies
EMBASE websites and applications may use cookies, local storage, session identifiers and similar technologies to:
- Authenticate users and maintain secure sessions
- Remember language and permitted preferences
- Protect against fraud and unauthorised access
- Support load balancing, reliability and troubleshooting
- Understand service performance and feature usage
Strictly necessary technologies are required for secure operation. Where non-essential analytics or preference technologies require a choice, EMBASE will provide an appropriate consent or preference mechanism. Authenticated student and staff applications are not used to deliver targeted advertising.
16 Data retention and deletion
Personal data is retained only for as long as necessary for the identified purpose, the institution’s documented instructions, the service agreement, dispute resolution, security, legal claims or applicable legal, academic, financial, employment and regulatory requirements.
Retention is determined using criteria including:
- Whether the student, employee, applicant or customer relationship remains active
- The institution’s academic, examination, employment and statutory record obligations
- Whether data is required to provide an enabled service or complete a requested transaction
- Applicable accounting, tax, audit, university, court or government requirements
- Security, fraud-prevention, incident-investigation and audit-log requirements
- The need to establish, exercise or defend legal claims
- The time required for controlled deletion from active systems and backup-expiry cycles
When an institution’s agreement ends, institution-controlled data is exported, returned, retained or deleted according to the agreement, lawful instructions and applicable retention requirements. Data scheduled for deletion may remain temporarily in protected backups until the applicable backup cycle expires, unless law requires earlier deletion or longer retention.
When data is no longer required, EMBASE will delete it, securely dispose of it or render it anonymous so that it no longer identifies an individual, as appropriate.
17 Security safeguards
EMBASE maintains technical and organisational measures appropriate to the nature, scope and risk of the processing. These measures include, as appropriate:
- Encryption and secure transmission controls
- Role-based access controls and least-privilege access
- Authentication controls for administrative and privileged access
- Tenant and environment access restrictions
- Audit logs, monitoring and review of relevant access events
- Backups, resilience and disaster-recovery measures
- Secure development, vulnerability management and patching processes
- Employee confidentiality, training and access review
- Service-provider security and contractual controls
- Incident detection, investigation, containment and remediation procedures
No system can be guaranteed completely secure. Users must protect their username, password, OTP and device access and should promptly report suspected unauthorised access. Security concerns and suspected data incidents may be reported to isms@embase.in .
18 Children and individuals under 18
Our Services are primarily intended for use by institutions and their authorized representatives. Embase does not directly provide services to children or minors, nor does it collect their personal data for its own independent purposes.
Embase may process minors’ personal data as a Data Processor, strictly on behalf of its Customers (educational organizations). In such cases:
- The Customer, acting as the Data Controller / Data Fiduciary, is responsible for obtaining verifiable parental or guardian consent where required under applicable laws.
- Embase processes minors’ personal data only in accordance with the Customer’s documented instructions and its contractual obligations.
Personal data relating to a child must not be processed in a manner likely to cause a detrimental effect on the child’s wellbeing. EMBASE does not use children’s institutional data for targeted advertising.
Where tracking or behavioural monitoring is used by an educational institution, it must be restricted to authorised educational activities or the safety of children enrolled with the institution, or another purpose permitted by applicable law.
19 Individual rights and choices
Subject to applicable law, the context of processing and the phased commencement of relevant statutory provisions, an individual may have the right to:
- Request a summary of personal data being processed and relevant processing activities
- Request correction of inaccurate or misleading personal data
- Request completion of incomplete personal data
- Request updating of outdated personal data
- Request erasure where the data is no longer required and retention is not required by law
- Withdraw consent where consent is the basis of processing
- Raise a grievance concerning processing or an unresolved request
- Nominate another individual to exercise rights where applicable
- Make a complaint to the competent authority after exhausting the available grievance process, where provided by law
Institution-controlled academic, admission, attendance, examination, fee, HR or other records should normally be addressed first to the relevant institution. EMBASE will support the institution in responding where required. Requests concerning EMBASE-controlled data may be sent directly to legal@embase.in .
20 How to submit a privacy request
A request may be sent to legal@embase.in . To help us identify and route the request, please provide:
- Your full name and contact information
- The name of the relevant educational institution, if applicable
- Your user type, such as applicant, student, guardian, faculty, staff or administrator
- Your username, admission number, employee or faculty identifier, or another appropriate identifier
- A clear description of the request and the records or processing involved
Do not send passwords, OTPs, complete payment-card details or unnecessary identity documents. EMBASE or the institution may request proportionate information to verify identity, authority and the scope of the request before acting.
Privacy requests will be acknowledged promptly and will normally be addressed within 30 days where reasonably practicable. Complex requests, identity verification, institution-controlled decisions or legal retention requirements may require additional time. EMBASE will communicate material delays and will comply with any shorter or mandatory period under applicable law.
21 Duties of the Data Principal
Under the Digital Personal Data Protection Act, 2023, and rules made thereunder, an individual exercising rights as a Data Principal must:
- comply with the provisions of applicable law while exercising such rights;
- not impersonate another person when providing Personal Data for a specified purpose;
- not suppress any material information when providing Personal Data for obtaining any document, unique identifier, proof of identity, or proof of address issued by the State or any of its instrumentalities;
- not register a false or frivolous grievance or complaint with EMBASE, an Institution, or the Data Protection Board of India; and
- furnish only verifiably authentic information when exercising the right to correction or erasure under applicable law.
22 Personal-data breaches
If EMBASE becomes aware of a personal-data breach, it will take reasonable steps to contain, investigate and remediate the incident; preserve relevant evidence; assess the nature and likely impact; and notify the relevant institution, affected individuals and competent authorities as required by applicable law and contract. A breach communication may include the nature and extent of the incident, likely consequences, measures taken, recommended protective steps and an appropriate contact point, to the extent known and legally permitted.
23 Third-party services and links
EMBASE may integrate with or link to third-party services such as payment gateways, identity providers, email or messaging platforms, video services, cloud applications or institutional websites. Those third parties may process personal data under their own terms and privacy notices. EMBASE is not responsible for an independent third party’s privacy practices, but will apply appropriate diligence and contractual controls where that party acts as an EMBASE service provider.
24 Public and shared content
Some enabled modules may allow authorised users to share notices, learning content, events, comments or other material with defined audiences. Users and institutions must select the intended audience carefully. Content made public may be visible outside the institution and may be copied or indexed by third parties. EMBASE will not make institution-controlled content public except through an authorised feature, and configuration.
25 Changes to this Policy
EMBASE may update this Policy to reflect changes in law, services, technology or processing practices. The current version will display its effective date, last-updated date and version number. If a change materially affects individual rights or the way personal data is processed, EMBASE or the relevant institution will provide an appropriate notice through the website, application, email or another suitable channel. Previous versions should be retained in a policy archive so that users and institutions can understand material changes over time. The updated Policy becomes effective from its stated effective date. Continued use of the Services after that date constitutes acceptance of the revised Policy, without prejudice to any requirement to obtain fresh consent where mandated by applicable law.
26 Definitions
27 Governing privacy framework
This Policy is intended to operate consistently with applicable Indian privacy, information-technology, cybersecurity, education, employment, financial and record-retention requirements, including the Digital Personal Data Protection Act, 2023 and rules brought into force under it. Obligations and individual rights will apply according to their legal commencement and any applicable exemptions or regulatory directions.