Official Legal Policy

NeuraMach AI Studio Private Limited - Cookie Policy

Effective Date: June 11, 2026Last Updated: June 11, 2026

ScoreVedaa CAT is a product owned and operated by NEURAMACH AI STUDIO PRIVATE LIMITED, a private limited company incorporated under the laws of India, bearing Corporate Identification Number U62099PN2025PTC245340 and operating under the brand name NeuraMach.ai.

Registered Office:

Flat No. 201, Building 1, Wing 3, The Crown Greens, Plot 17, Infotech Park, Hinjawadi, Pune, Maharashtra 411057, India.

Principal Business and Correspondence Office:

3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India.

In this Cookie Policy, references to “ScoreVedaa”, “ScoreVedaa CAT”, “NeuraMach.ai”, “Company”, “we”, “us” or “our” mean NEURAMACH AI STUDIO PRIVATE LIMITED, unless the context requires otherwise.

This Cookie Policy explains how ScoreVedaa CAT uses cookies and similar technologies through its websites, web and mobile applications, dashboards, Assessments, AI Features, Subscription flows and related Services.

Please read this Cookie Policy together with the:

  • ScoreVedaa CAT Terms and Conditions;
  • ScoreVedaa CAT Privacy Policy;
  • AI Usage Policy;
  • Subscription, Cancellation and Refund Policy;
  • Model Improvement Notice, where applicable;
  • Provider Training Notice, where applicable;
  • Any Cookie notice, preference interface or feature-specific notice made available through the Platform; and
  • Any provider-specific information made available for a relevant Third-Party Technology.

This Policy describes the categories of Cookies and Similar Technologies that ScoreVedaa CAT may use. The description of a category, purpose or type of provider does not mean that every technology falling within that category is currently deployed. ScoreVedaa CAT will process information only through technologies that are actually implemented, approved and used for an authorised purpose.

Because individual technical identifiers may change as browsers, applications, security systems and Service Providers are updated, this Policy may describe technologies by category rather than list every temporary, technical or automatically generated identifier. Where reasonably appropriate or required by Applicable Law, additional information concerning a particular provider, purpose, technology or duration may be presented:

  • At the point of collection;
  • Through a Cookie notice;
  • Through a preference interface;
  • Through an embedded-feature notice;
  • In an application-permission request;
  • In the Privacy Policy;
  • On a provider-information page; or
  • Through another reasonably accessible method.

A. OVERVIEW AND SCOPE

1. Introduction

ScoreVedaa CAT may use cookies and similar technologies where reasonably necessary to:

  • Deliver Platform pages and application functions;
  • Authenticate Users;
  • Maintain secure sessions;
  • Protect Accounts;
  • Preserve authorised preferences;
  • Record consent choices;
  • Operate Assessments and the Exam Simulator;
  • Support PRGNA and other requested features;
  • Process Subscription and payment transactions;
  • Prevent fraud, scraping, abuse and unauthorised access;
  • Diagnose technical problems;
  • Monitor service availability and reliability;
  • Understand Platform usage;
  • Improve navigation and onboarding;
  • Measure campaigns where lawfully enabled;
  • Support authorised referrals;
  • Comply with legal and security obligations; and
  • Perform other disclosed functions.

Cookies and similar technologies are divided into:

1.1 Strictly Necessary Technologies

These support functions that are essential or reasonably necessary to:

  • Deliver a Service requested by the User;
  • Maintain security;
  • Authenticate an Account;
  • Preserve a transaction or Assessment session;
  • Record consent choices;
  • Prevent fraud; or
  • Meet a legal or operational obligation.

1.2 Optional Technologies

Optional Technologies may include:

  • Non-essential preference technologies;
  • Product analytics;
  • Audience measurement;
  • Optional embedded services;
  • Campaign measurement; and
  • Marketing technologies.

An Optional Technology will be used only where:

  • It is actually deployed;
  • Its purpose has been assessed;
  • Its use is consistent with this Policy and the Privacy Policy;
  • Appropriate notice has been provided;
  • Any Consent required by Applicable Law has been obtained; and
  • The User has not withdrawn that Consent.

Where ScoreVedaa CAT does not operate a technical mechanism capable of obtaining any Consent legally required before activating an Optional Technology, that Optional Technology will not be activated until an appropriate mechanism is implemented. ScoreVedaa CAT does not condition access to its core Services on acceptance of optional analytics or marketing technologies. A technology may be required for a separately requested optional feature only where the feature cannot reasonably be provided without that technology.

2. Scope of this Cookie Policy

This Cookie Policy applies to cookies and similar technologies operating through:

  • The public ScoreVedaa CAT website;
  • Registration pages;
  • Login and Account-recovery pages;
  • Student dashboards;
  • Institute and Faculty dashboards;
  • Web applications;
  • Mobile applications, where applicable;
  • Assessment interfaces;
  • The Exam Simulator;
  • PRGNA;
  • Checkout pages;
  • Subscription-management pages;
  • Automatic-renewal flows;
  • Cancellation flows;
  • Support and grievance forms;
  • Blog and educational pages;
  • Campaign and referral pages;
  • Embedded content;
  • Trial and demonstration environments;
  • Beta features;
  • Consent-management interfaces; and
  • Other ScoreVedaa CAT Services displaying or linking to this Policy.

This Cookie Policy applies to:

  • Visitors;
  • Prospective Adult Users;
  • Registered Adult Students;
  • Individual subscribers;
  • Institute-sponsored Adult Students;
  • Institute Administrators;
  • Faculty Users;
  • Adult mentors and counsellors; and
  • Other Adult persons interacting with ScoreVedaa CAT.

This Cookie Policy does not govern:

  • Technologies used independently by a third-party website after a User leaves ScoreVedaa CAT;
  • Independent processing undertaken by an Institute outside ScoreVedaa CAT;
  • Employee or recruitment technologies governed by separate notices;
  • A separately identified ScoreVedaa JEE, NEET, school-board or other product; or
  • Information that has been genuinely and irreversibly anonymised.

3. Eligibility and Age Requirement

ScoreVedaa CAT is a CAT-exam preparation platform intended for adult learners (18+) because its target examination and use case — CAT and MBA admissions — apply only to adults. This restriction is unrelated to the nature of the content, which is educational. The term 'Adult' below is used only in this defined, age-eligibility sense. ScoreVedaa CAT is intended only for individuals who have completed eighteen years of age. An individual below eighteen years of age must not knowingly:

  • Register an Account;
  • Use an Account-based feature;
  • Take an Assessment;
  • Use PRGNA;
  • Purchase a Subscription;
  • Activate optional cookies;
  • Participate in model-improvement programmes; or
  • Circumvent an age-assurance measure.

A public webpage may process limited technical information before a Visitor reaches an Adult-status declaration. Such processing may include IP address, browser and device information, server logs, security records, request timestamps, consent status, and network or diagnostic information. This limited processing may occur for delivering the requested page, security, fraud and abuse prevention, diagnostics, network management, consent management, and legal compliance.

Before an Adult-status declaration has been completed, only Strictly Necessary Technologies and the limited technical processing described in this Section may operate. Optional analytics, campaign, marketing and non-essential embedded technologies will remain disabled until Adult status has been established and any required Consent has been obtained.

ScoreVedaa CAT will not use optional marketing technologies to target an individual below eighteen years of age. If we reasonably determine that an Account is being used by an individual below eighteen, we may restrict the Account and stop optional cookie-based processing in accordance with the Privacy Policy and Applicable Law.

Age assurance is not based on a self-declaration alone. We collect and validate date of birth at registration, apply additional verification where information is inconsistent or account sharing is suspected, and require Institutes to warrant that every student on a submitted roster is an adult.

4. Relationship With Other Policies

This Cookie Policy governs Cookies and Similar Technologies used through ScoreVedaa CAT. Where provisions conflict:

  • Mandatory Applicable Law prevails.
  • A specific notice presented when a technology or feature is activated governs that specific processing.
  • A preference or permission selected by the User governs the relevant optional processing to the extent technically applicable.
  • The Privacy Policy governs general Personal Data processing.
  • The AI Usage Policy governs AI Features and AI Outputs.
  • The Terms and Conditions govern general use of ScoreVedaa CAT.

This Cookie Policy governs the use of Cookies and Similar Technologies. ScoreVedaa CAT is not required by this Policy to provide a particular commercial consent-management product or third-party CMP.

Consent may, where legally valid, be obtained through:

  • A Company-operated Cookie banner;
  • A simple preference control;
  • A category-level selection interface;
  • A feature-activation prompt;
  • An application or device permission;
  • An express User request;
  • Another clear affirmative mechanism; or
  • A third-party consent solution selected by the Company.

Acknowledging this Cookie Policy does not constitute Consent to Optional Technologies. Acceptance of the Terms or Privacy Policy does not constitute Consent to Optional Technologies.

Optional-cookie Consent does not constitute:

  • Internal AI Training Consent;
  • Provider-side AI training Consent;
  • Consent to unrelated marketing;
  • Cross-product Consent; or
  • Consent for another ScoreVedaa product.

B. DEFINITIONS

5. Definitions

For this Cookie Policy:

  • “Applicable Law” means any law, rule, regulation, order, direction or legally binding requirement applicable to ScoreVedaa CAT or the use of cookies, similar technologies or Personal Data.
  • “Consent” means consent satisfying the requirements of Applicable Law.
  • “Consent Mechanism” means a banner, preference control, feature-activation prompt, application permission, device permission or another mechanism through which a User may provide, refuse or withdraw Consent where required.
  • “Cookie” means a small data record stored on or accessed from a browser, application, device or similar environment.
  • “Essential” or “Strictly Necessary” means reasonably necessary to provide a requested Service, maintain security, preserve a transaction, record Consent or perform another function that cannot reasonably be provided without the relevant technology.
  • “First-Party Technology” means a cookie or similar technology controlled directly by the Company or deployed through a Company-controlled domain.
  • “Internal Technology Register” means an internal technical or compliance record maintained by the Company concerning material Cookies and Similar Technologies actually deployed through ScoreVedaa CAT. The Internal Technology Register is maintained for security, development, vendor management, privacy review, incident response, compliance, and change control. It is not required to be made public except to the extent disclosure is required by Applicable Law or expressly undertaken by the Company.
  • “Optional Technology” means a cookie or similar technology that is not Strictly Necessary and is subject to applicable Consent or preference controls.
  • “Personal Data” means data about an individual who is identifiable by or in relation to that data, or as otherwise defined under Applicable Law.
  • “Processing” includes collection, storage, access, use, analysis, transmission, disclosure, deletion and other handling of Personal Data.
  • “Service Provider” means a vendor, contractor, Data Processor, professional adviser or infrastructure provider supporting ScoreVedaa CAT.
  • “Similar Technology” means a technical mechanism other than a conventional browser cookie that stores, reads, transmits, recognises or otherwise processes information about a browser, device, application, session or interaction.
  • “Third-Party Technology” means a cookie or similar technology controlled by or operating through another organisation.
  • “User”, “you” or “your” means an Adult individual using or interacting with ScoreVedaa CAT.

Capitalised terms not separately defined in this Cookie Policy have the meanings assigned to them in the ScoreVedaa CAT Terms and Conditions or Privacy Policy.

C. COOKIES AND SIMILAR TECHNOLOGIES

6. What a Cookie Is

A Cookie may contain or generate a random identifier, session status, authentication status, security information, consent choices, preference information, date and time information, device or browser information, referral information, page interactions, transaction state, or other technical information. A Cookie does not necessarily contain a person’s name. However, a Cookie identifier and associated activity may constitute Personal Data where they identify or can reasonably be linked to an individual. Cookies may be first-party or third-party, session-based or persistent, Strictly Necessary or optional, controlled by ScoreVedaa or an authorised provider, and used through a website, application or embedded feature.

7. Similar Technologies

References to Cookies in this Policy also include, where applicable: 7.1 Local storage: Browser or application storage used to retain preferences, consent choices, application state, feature state, or session information. 7.2 Session storage: Temporary storage generally limited to an active browser tab, an application session, or a defined temporary interaction. 7.3 Pixels and web beacons: Small code elements used to record whether a page was viewed, an email was opened, a link was selected, a transaction occurred, or another defined event took place. 7.4 Software Development Kits: Application code used to support authentication, security, crash reporting, analytics, messaging, consent management, embedded functions, or other disclosed purposes. 7.5 Tags and scripts: Code used to load authorised functions, operate the Consent Mechanism, collect technical information, measure defined events, or load approved third-party services. 7.6 Device and application identifiers: Identifiers associated with a browser, an application installation, a device, a session, or an advertising environment where lawfully enabled. 7.7 Server and security logs: Technical records created by servers, networks, applications, authentication systems, and transaction systems. Server logs are not conventional browser Cookies but may be governed by similar privacy, security and retention principles. 7.8 Cache and service-worker storage: Storage used for application speed, offline functionality, continuity, resource management, and technical performance.

An optional purpose does not become Strictly Necessary merely because it is implemented through a Similar Technology rather than a conventional Cookie.

8. First-Party and Third-Party Technologies

A First-Party Technology is deployed through a Company-controlled domain or controlled directly by the Company. First-party technologies may support authentication, security, preferences, consent records, Assessments, Platform functions, internal measurement, and Subscription management.

A Third-Party Technology is controlled by or deployed through another organisation. Third-party technologies may support payment processing, authentication, hosting, security, analytics, error monitoring, customer support, communications, embedded content, or marketing.

A first-party technology is not automatically Strictly Necessary. A third-party technology is not automatically optional. Classification must be based on the actual function, whether the function was requested, whether the Service can reasonably operate without it, the data collected, the recipient’s role, and Applicable Law.

9. Session and Persistent Technologies

9.1 Session technologies

Session technologies generally remain active only during a browser or application session. They may support login, navigation, temporary form data, Assessment continuity, checkout continuity, cancellation continuity, security, temporary application state, and load balancing. They may expire when the User logs out, the browser closes, the application session ends, a security event terminates the session, or the configured expiry is reached. Browser-recovery functions may preserve some session information after the browser appears to close.

9.2 Persistent technologies

Persistent technologies remain after the current session until their configured expiry, manual deletion, consent withdrawal, replacement, provider deletion, or deactivation by ScoreVedaa CAT. They may support consent records, preferences, recognised-device security, returning-visitor measurement, campaign attribution, reduced repetition of notices, and other documented purposes. Persistent technologies must have a defined retention period. They will not be configured for indefinite retention without a documented legal, security or functional justification.

D. COOKIE CATEGORIES

10. Strictly Necessary Technologies

Strictly Necessary Technologies support functions required to provide, secure or preserve a Service requested by the User. They may support page delivery, load balancing, registration, login, authentication, secure sessions, role and permission controls, logout, Account recovery, cross-site-request-forgery protection, form security, rate limiting, consent-choice storage, checkout, Subscription cancellation, payment-session continuity, Assessment-session continuity, Exam Simulator continuity, essential accessibility functions, essential service monitoring, and other necessary security or operational functions.

Where permitted by Applicable Law, these technologies may be activated without optional-cookie Consent. A technology will not be classified as Strictly Necessary merely because it is commercially useful, it makes advertising easier, it improves non-essential analytics, it increases conversion, a vendor recommends that classification, or it is commonly used by other websites. Strictly Necessary Technologies will not be used solely for behavioural advertising, cross-site tracking, campaign retargeting, third-party audience profiling, or non-essential product analytics. Blocking Strictly Necessary Technologies through a browser or device may prevent core Platform functions from operating.

11. Authentication and Session Technologies

Authentication and session technologies may be used to confirm successful login, associate an authorised session with an Account, maintain access across pages, prevent repeated login prompts, enforce role-based access, manage secure logout, detect session expiry, revoke compromised sessions, detect concurrent misuse, protect Student dashboards, protect Faculty and Institute dashboards, and maintain authorised feature access.

They may process a random session identifier, a protected authentication token, session expiry, role or permission attributes, device indicators, authentication state, and security-state information. ScoreVedaa CAT will not intentionally store plain-text passwords in Cookies. Where technically appropriate, authentication technologies will use safeguards such as secure transmission, restricted script access, appropriate SameSite settings, restricted domain and path settings, defined expiry, token rotation, session revocation, logout invalidation, and revocation following material security events.

12. Security and Fraud-Prevention Technologies

Security technologies may be used to detect suspicious login attempts, prevent credential abuse, identify bots, prevent scraping, apply rate limits, detect malicious uploads, detect payment fraud, prevent promotional abuse, protect Assessments, protect consent records, identify unusual sessions, investigate cyber incidents, and protect Platform infrastructure.

Information may include IP address, device identifier, browser characteristics, session identifier, failed-login events, security-challenge results, general IP-derived region, transaction-risk signals, Assessment-session indicators, and Account-security events. Security signals may result in additional verification, temporary restriction, session termination, password reset, payment review, attempt review, or security investigation. Where the consequence is material, a permanent action will not be based solely on an unreviewed automated Cookie-derived signal where reasonable procedural or human review is practicable. Security information will be retained for a documented security, fraud-prevention, legal, regulatory, or evidentiary period.

13. Consent and Preference Technologies

13.1 Consent technologies

Consent technologies may record whether the Cookie banner was displayed, the Policy version presented, the categories accepted or rejected, individual provider choices where offered, the date and time of the decision, consent or preference identifier, general region where relevant, withdrawal events, and technical evidence reasonably necessary to demonstrate the choice. Consent technologies may remain active as Strictly Necessary where required to remember a rejection, avoid repeatedly asking for Consent, prevent optional technologies from loading, prove a recorded choice, or honour withdrawal.

13.2 Preference technologies

Preference technologies may remember language, theme, display settings, accessibility settings, dashboard layout, time zone, notification preferences, last-used features, Assessment-interface settings, previously dismissed notices, and other User-selected choices. A preference technology may be treated as Strictly Necessary where it is required to provide a feature expressly selected by the User. Non-essential preference technologies will be subject to applicable Consent controls. Deleting them may reset saved settings. Preference technologies will not be repurposed for advertising merely because they record User choices.

14. Performance and Reliability Technologies

Performance technologies may collect technical information such as page-load time, server-response time, application latency, error events, crash information, failed resources, network quality, device type, operating system, browser version, application version, service availability, and general technical interaction. They may be used to detect errors, monitor uptime, diagnose compatibility issues, improve speed, allocate infrastructure, investigate outages, assess service reliability, identify failed transactions, and support contractual availability commitments.

Where a performance technology is used only for essential security, availability, error detection, transaction integrity, or operational monitoring, it may be classified as Strictly Necessary where permitted by Applicable Law. Where it supports non-essential product analytics, it will be classified and controlled accordingly. Performance tools will be configured so that they do not intentionally collect plain-text passwords, complete payment credentials, full private PRGNA conversations, complete private User uploads, full Assessment responses, or Personal Data not reasonably necessary for reliability monitoring.

15. Analytics Technologies

Optional analytics technologies may help ScoreVedaa CAT understand pages viewed, features used, navigation paths, session duration, referral sources, general geographic region, device and browser types, registration completion, checkout completion, Assessment initiation, feature adoption, general engagement, technical friction, and aggregate conversion. They may be used to improve navigation, identify product friction, improve onboarding, measure feature usefulness, evaluate technical design, understand aggregate usage, prepare internal statistics, and make product-development decisions.

Where Consent is required, optional analytics technologies will remain inactive until Consent is obtained. General analytics providers will be configured so that they do not intentionally receive plain-text passwords, full payment credentials, complete private PRGNA conversations, complete private User uploads, full Assessment responses, unnecessary Student names, detailed identifiable Performance Data, or information not reasonably required for analytics. Optional analytics data will not be used for provider-side AI model training unless separately disclosed and affirmatively consented to under the Provider Training Notice framework. Identifiable Cookie-derived analytics data will not be used for internal Reusable Model development unless the applicable Model Improvement Notice expressly includes the relevant data category and the User has provided valid Training Consent covering that category. Irreversibly anonymised or aggregated analytics may be used in accordance with the Privacy Policy.

16. Functional and Embedded-Service Technologies

Optional functionality technologies may support video playback, document display, support chat, appointment scheduling, interactive forms, charts, file uploads, authentication integrations, surveys, embedded educational content, and other User-requested features.

Before an optional embedded service loads, ScoreVedaa CAT may request Consent, display a placeholder, require the User to activate the feature, offer a direct external link, or provide an alternative method. Once activated, an embedded provider may receive IP address, browser information, device information, page context, interaction details, and third-party Account information where the User is logged in to that provider. A provider deploying a Cookie or similar identifier through ScoreVedaa CAT must be identified in the Internal Technology Register. A request to load a particular embedded feature may authorise technologies genuinely necessary to provide that feature where permitted by Applicable Law. It does not authorise unrelated analytics, profiling or advertising.

17. Campaign Measurement and Marketing Technologies

ScoreVedaa CAT may use optional campaign or marketing technologies only where the technology is actually deployed, the purpose is clearly disclosed, the provider appears in the Internal Technology Register, required Consent has been obtained, the User has not withdrawn Consent, use is not prohibited for the relevant User, and the technology has passed privacy and security review. Such technologies may support campaign measurement, referral attribution, conversion measurement, frequency control, Adult-User retargeting where lawfully enabled, suppression of repeated advertisements, and general audience reporting.

ScoreVedaa CAT will not use marketing technologies to: target advertising to an individual below eighteen, use Assessment answers for advertising, use identifiable Performance Data for advertising, use private PRGNA conversations for advertising, use private User uploads for advertising, use payment credentials for advertising, infer sensitive personal characteristics for advertising, build advertising profiles from confidential educational activity, sell Cookie-derived Personal Data, or condition core paid Services on optional advertising Consent. Marketing technologies will remain inactive by default wherever prior Consent is required. Rejecting marketing technologies will not prevent access to core ScoreVedaa CAT Services.

18. Payment-Provider Technologies

Payment providers may use Cookies or Similar Technologies to secure checkout, authenticate payment sessions, process cards, UPI or other payment methods, create recurring mandates, issue applicable pre-debit communications, detect fraud, prevent duplicate transactions, complete settlement, process cancellation, manage chargebacks, process reversals and refunds, and meet financial or regulatory obligations. These technologies may process transaction identifier, session identifier, payment-method category, mandate reference, IP address, device information, fraud indicators, and payment status.

ScoreVedaa CAT will not store in its own Cookies: full card numbers, CVV, UPI PIN, bank password, one-time password, or other payment-authentication secrets. Payment-provider technologies required to complete a transaction requested by the User may be treated as Strictly Necessary where permitted by Applicable Law. A payment provider’s independent practices may also be governed by that provider’s privacy and cookie notices.

E. THIRD-PARTY TECHNOLOGIES

19. Third-Party Providers

Third-party technologies may be deployed by authorised providers supporting payment processing, authentication, hosting, security, error monitoring, analytics, customer support, communications, embedded content, consent management, or marketing. Each material provider deploying a Cookie or Similar Technology through ScoreVedaa CAT must be identified in the Internal Technology Register.

Before approving a third-party technology, the Company will assess, as applicable: its stated purpose, data collected, category, duration, security, data-use terms, international processing, consent requirements, withdrawal or opt-out controls, subcontracting, whether the provider acts on our instructions, whether the provider acts independently, and whether the processing is proportionate. Where a provider processes Personal Data on our behalf as a Data Processor, we will require a valid written contract requiring the provider to process Personal Data only for authorised purposes and documented instructions, subject to applicable confidentiality, security, retention, deletion and incident-notification obligations. Independent processing by a third party may also be governed by that party’s privacy notice. A third-party technology will not be approved merely because it is convenient, it is popular, it is free, a developer included it by default, or a vendor describes it as standard.

20. Embedded Content and External Platforms

ScoreVedaa CAT may provide access to videos, documents, images, support widgets, payment pages, authentication pages, survey tools, scheduling tools, social content, and other external services. Optional third-party content will not load optional tracking technologies before required Consent or express activation. When activated, the provider may learn that the User accessed a ScoreVedaa CAT page, the User’s IP address, device and browser information, page context, interaction details, and relevant provider-Account information. External websites are governed by their own policies. ScoreVedaa CAT is not responsible for technologies independently deployed after a User leaves the Platform. We will not present an external service in a manner that misleadingly suggests that the service is entirely controlled by ScoreVedaa CAT.

21. International Processing

Some Cookie and technology providers may process information outside India. International processing may occur for hosting, security, authentication, error monitoring, analytics, communication delivery, payment processing, embedded services, and campaign measurement. Where Cookie-derived Personal Data is processed outside India, we will comply with Applicable Law, follow binding Government restrictions, assess the provider, use appropriate contractual safeguards, restrict processing to authorised purposes, preserve Consent limitations, maintain relevant records, and take reasonable security measures. We will not transfer Cookie-derived Personal Data to a country, territory, recipient or arrangement prohibited by Applicable Law or a binding Government restriction.

F. CONSENT AND PREFERENCE MANAGEMENT

22. Consent Standards

Where Consent is required before an Optional Technology may be used, ScoreVedaa CAT will seek Consent through an available Consent Mechanism appropriate to the relevant technology and purpose. The mechanism may include:

  • A Cookie banner;
  • A category-selection interface;
  • A feature-activation prompt;
  • An embedded-service prompt;
  • An application permission;
  • A device permission; or
  • Another clear affirmative process.

Where no appropriate Consent Mechanism is available, an Optional Technology requiring prior Consent will remain disabled.

Where required by Applicable Law, the relevant notice and Consent request will:

  • Be understandable independently of other information presented to the User;
  • Contain an itemised description of the relevant Personal Data or information categories and the specified purposes;
  • Be available in English or an available language specified in the Eighth Schedule to the Constitution;
  • Provide the business contact details of the person authorised to answer privacy questions and assist with the exercise of applicable rights;
  • Use clear and plain language;
  • Explain material consequences of refusal;
  • Explain how Consent may be withdrawn;
  • Provide access to this Policy or an applicable notice;
  • Be separate from unrelated contractual acceptance; and
  • Require a clear affirmative action.

The following will not constitute valid Consent where affirmative Consent is required:

  • Silence;
  • Inactivity;
  • Continued browsing alone;
  • A pre-selected optional category;
  • A pre-enabled optional control;
  • Misleading wording;
  • False urgency;
  • Confirm shaming;
  • Forced action;
  • Interface interference;
  • Material obstruction of refusal; or
  • Repeated prompts intended to override a prior refusal.

Strictly Necessary Technologies may remain active where permitted by Applicable Law.

23. Consent Interface Design

Where ScoreVedaa CAT presents an interface offering a choice between accepting and rejecting Optional Technologies, the interface will be designed to provide a genuine and reasonably understandable choice. The interface will:

  • Identify Strictly Necessary Technologies separately;
  • Avoid pre-selecting Optional Technologies;
  • Avoid presenting Optional Technologies as mandatory where they are not mandatory;
  • Avoid deceptive wording or presentation;
  • Avoid materially obstructing rejection;
  • Avoid bundling Optional Technology Consent with acceptance of the Terms;
  • Provide an explanation of relevant purposes; and
  • Provide access to further information where appropriate.

Whenever a first-layer Accept Optional Cookies option is presented, an equivalent Reject Optional Cookies option will be presented with comparable accessibility.

This Section does not require ScoreVedaa CAT to operate a permanent Cookie banner or preference centre where:

  • No Optional Technologies requiring Consent are active;
  • The relevant technology is activated only through a separate feature-specific request;
  • The User’s choice is managed through an application or device permission; or
  • Another legally valid mechanism is used.

24. Consent Records

Consent records may include Consent identifier, User or device identifier where applicable, date and time, Cookie Policy version, banner or notice version, categories selected, providers selected where applicable, general region where relevant, language displayed, withdrawal event, preference changes, and technical evidence reasonably necessary to demonstrate the choice. Consent records may be retained separately from browser Cookies for compliance, audit, dispute resolution, security, proof of withdrawal, and applicable limitation periods. Consent records will not be used to infer Consent for AI model training, unrelated marketing, another ScoreVedaa product, or a purpose not presented to the User.

25. Managing Cookie Choices

Depending on the technology and Platform functionality, Users may manage Cookie-related choices through:

  • A Cookie banner, where provided;
  • A feature-specific preference;
  • Account or application settings, where available;
  • Browser controls;
  • Device permissions;
  • Provider-specific controls;
  • Disabling or declining an optional embedded feature; or
  • Another mechanism communicated by ScoreVedaa CAT.

Where processing is based on Consent, ScoreVedaa CAT will provide or identify a reasonably accessible method of withdrawal that is comparable in ease to the method through which Consent was given, taking into account whether the choice is administered through the Platform, a device or application permission, an embedded feature or an authorised provider. Where no Company-controlled preference interface is available, Users may delete or block Cookies through browser or device controls, disable the relevant application permission, avoid activating the optional feature, use an available provider opt-out mechanism, or contact privacy@neuramach.ai for information concerning available controls.

Withdrawal will apply prospectively. Previously refused Optional Technologies will not be intentionally reactivated merely because:

  • The User logs in;
  • A page is refreshed;
  • A new session begins;
  • The application is reopened;
  • The Policy is updated; or
  • The Platform design changes.

Renewed Consent may be requested where:

  • A materially new purpose is introduced;
  • A materially different provider is introduced;
  • The categories of information materially change;
  • Applicable Law requires renewed Consent;
  • The User clears the relevant device or browser preference;
  • A prior choice cannot reasonably be demonstrated; or
  • The User accesses ScoreVedaa CAT through a new browser or device.

Any renewed request will avoid unnecessary repetition and deceptive nagging.

26. Browser, Device and Application Controls

Browsers may allow Users to view Cookies, delete Cookies, block Cookies, block third-party Cookies, clear Cookies on exit, restrict site storage, use private browsing, and manage site permissions. Devices and applications may provide controls for advertising identifiers, app tracking, storage, notifications, camera, microphone, location, contacts, and other permissions. ScoreVedaa CAT will request a device permission only where reasonably related to a disclosed feature.

Blocking or deleting technologies may sign the User out, interrupt an Assessment, interrupt checkout, interrupt cancellation, prevent payment, reset preferences, disable security checks, prevent embedded content from loading, or make protected dashboards unavailable. Users should avoid deleting session technologies during an active Assessment, checkout, cancellation, Account-recovery process, or other important transaction. Browser controls do not necessarily remove server logs, transaction records, consent evidence, security records, or information already lawfully processed by a third party.

27. Consequences of Refusing Optional Technologies

Rejecting optional technologies will not prevent access to the core ScoreVedaa CAT Platform. However: optional preferences may not be remembered, embedded services may require separate activation, optional analytics may not operate, campaign attribution may be unavailable, some optional content may not load automatically, and advertising, where displayed, may be less relevant. Blocking Strictly Necessary Technologies may prevent registration, login, secure sessions, Assessment continuity, checkout, Subscription management, cancellation, consent-choice storage, payment processing, and access to protected areas.

28. Global Privacy Signals and Do Not Track

ScoreVedaa CAT will implement reasonable technical measures to honour browser-based or device-based privacy signals where Applicable Law requires recognition, the signal has a sufficiently clear legal or technical meaning, and the signal can be reliably associated with the relevant browser, device or purpose. ScoreVedaa CAT will provide the applicable Consent Mechanism where the signal cannot reliably communicate the required preference. Where a generic Do Not Track signal has no uniform legal or technical meaning, ScoreVedaa CAT will rely on the applicable Consent Mechanism, browser permissions, device controls, provider opt-out tools, and legally required Consent mechanisms. ScoreVedaa CAT will periodically review developments relating to recognised global privacy-control signals.

G. AI, INSTITUTE AND ADVERTISING LIMITS

29. Cookies and AI Model Development

Use of Cookie-derived Personal Data for AI model development is governed by the Privacy Policy, AI Usage Policy, Model Improvement Notice and Provider Training Notice. Optional Cookie Consent does not authorise internal identifiable-data AI model training, third-party provider-side model training, cross-product model development, or human review for general model-development purposes.

Identifiable Cookie-derived Personal Data will not be selected for optional internal Reusable Model development unless the applicable Model Improvement Notice expressly includes the relevant category, the specified purpose covers that processing, and the User has provided valid Training Consent. Cookie-derived Personal Data will not be used for provider-side model training unless a Provider Training Notice has been provided, separate affirmative Consent has been obtained, and the processing complies with the Privacy Policy and Applicable Law. Irreversibly anonymised or aggregated technical information may be used for product analytics, reliability measurement, security analysis, evaluation, benchmarking, and internal product or model improvement in accordance with the Privacy Policy.

30. Institute Access to Cookie-Derived Information

An Institute will not automatically receive a Student’s browser identifiers, device identifiers, cookie choices, marketing status, general browsing history, security logs, payment Cookies, or activity outside an authorised Institute programme. An Institute may receive limited Cookie-derived or technical information where reasonably necessary to operate an authorised Institute-Linked Account, necessary to protect Account security, necessary to investigate misuse, presented as aggregated programme analytics, expressly authorised by the Adult Student, or required by law. Any Institute access remains subject to the Privacy Policy, Institute Agreement, role-based access, data minimisation, and Applicable Law.

31. No Sale or Rental of Cookie-Derived Personal Data

ScoreVedaa CAT does not sell or rent Personal Data collected through Cookies or Similar Technologies. We do not use private PRGNA conversations, private User uploads, Assessment answers, identifiable Performance Data, payment credentials, or Training Consent information for third-party behavioural advertising. Service Provider processing, lawful business transfers and legally required disclosures are not treated as a sale of Personal Data under this Policy.

H. RETENTION, SECURITY AND DELETION

32. Cookie Duration and Retention

Cookies and Similar Technologies will be retained only for a documented period reasonably necessary for their stated purpose. Duration may be until logout, until the browser or application session ends, a defined number of minutes, a defined number of hours, a defined number of days, a defined number of months, until a preference changes, until Consent is withdrawn, until the relevant transaction is completed, or another period stated in the Internal Technology Register. Duration and retention will consider security, session continuity, User convenience, Consent validity, fraud prevention, Subscription administration, Assessment continuity, analytics necessity, campaign necessity, legal requirements, and provider limitations.

The following principles apply:

  • Authentication technologies will expire, rotate or be revoked appropriately.
  • Payment-session technologies will not outlive their operational purpose.
  • Assessment-session technologies will be limited to the operational and dispute period reasonably required.
  • Referral attribution will use a defined and proportionate window.
  • Optional analytics identifiers will not be retained longer than reasonably necessary.
  • Marketing identifiers will have a defined duration.

Consent records may be retained separately to demonstrate Consent or withdrawal. Security logs may be retained longer than browser Cookies where required for security, fraud prevention, legal evidence or Applicable Law. Provider-controlled durations will be reviewed periodically and recorded in the Internal Technology Register. Deleting a browser Cookie does not automatically erase lawfully retained server logs, transaction records, consent records, payment-provider records, Institute records, security evidence, or information that has been irreversibly anonymised.

33. Security Measures

We use reasonable technical and organisational safeguards appropriate to the nature of Cookie-derived information and relevant risks. Measures may include secure transmission, encryption where appropriate, tokenisation, hashing, pseudonymous identifiers, restricted script access, SameSite controls, restricted domain and path settings, defined expiry, session rotation, session revocation, role-based access, least-privilege access, consent-category blocking, tag-management controls, vendor review, logging, monitoring, incident-response procedures, data minimisation, retention limits, and periodic testing.

No online system is completely secure. Users should keep browsers and devices updated, avoid sharing Accounts, protect verification codes, sign out from shared devices, review suspicious activity, and report suspected misuse promptly.

34. Withdrawal, Deletion and Residual Records

Where a User validly withdraws Consent to an Optional Technology, ScoreVedaa CAT will take reasonable steps, proportionate to the relevant technology and its control over that technology, to:

  • Stop future Company-controlled optional processing covered by the withdrawal;
  • Update the relevant preference where a Company-controlled preference exists;
  • Prevent the affected Optional Technology from loading in future sessions where technically controlled by ScoreVedaa CAT;
  • Delete Company-controlled optional browser Cookies where reasonably practicable; and
  • Record the withdrawal where required for compliance.

Where an Optional Technology provider acts as ScoreVedaa CAT’s Data Processor, the Company will provide appropriate withdrawal, deletion, return or restriction instructions where required by Applicable Law, the relevant contract, the nature of the processing, and the User’s valid withdrawal.

Where a third party independently determines its own processing purposes, the third party’s separate privacy notice, cookie notice, retention period, opt-out process, and deletion process may apply.

Withdrawal does not automatically require deletion of information lawfully processed before withdrawal, security records, consent and withdrawal evidence, transaction records, server logs, information subject to a legal hold, information required for fraud prevention, information retained under Applicable Law, or irreversibly anonymised or aggregated information.

I. TECHNOLOGY DISCLOSURE AND GOVERNANCE

35. Public Disclosure of Technologies

ScoreVedaa CAT will provide information about Cookies and Similar Technologies in a manner proportionate to the nature of the technology, the information processed, the relevant purpose, whether the technology is Strictly Necessary or optional, the recipient’s role, the duration of processing, the risk to Users, and Applicable Law.

Information may be provided through this Cookie Policy, a Cookie notice, a feature-specific notice, an embedded-service notice, an application-permission request, the Privacy Policy, a provider-information page, or another reasonably accessible method. ScoreVedaa CAT does not represent that it maintains a continuously updated public list of every temporary identifier, cache entry, server log, security event or technical key generated by the Platform.

Where required by Applicable Law, ScoreVedaa CAT will disclose the information required by that law. Where disclosure is not legally mandatory but is reasonably appropriate because of the nature or risk of a material Optional Technology, ScoreVedaa CAT may provide additional information concerning the provider, category, purpose, information processed, approximate duration, Consent position and international processing.

36. Internal Technology Register

The Company will take reasonable steps to maintain an Internal Technology Register covering material Cookies and Similar Technologies known to be deployed through ScoreVedaa CAT. The Internal Technology Register may include, as applicable: technology or provider name, business purpose, category, first-party or third-party status, general information processed, operational duration, consent position, responsible internal owner, provider relationship, security considerations, and review status.

The Internal Technology Register is an internal governance control and is not itself the legal basis for Processing. The lawfulness of Processing will depend on the relevant purpose, Applicable Law, notice, Consent where required, security safeguards and other circumstances. Material discrepancies identified in the Register will be reviewed and corrected within a reasonable period.

37. Technical Review and Testing

ScoreVedaa CAT will take reasonable steps to review Cookies and Similar Technologies before introducing a material new Optional Technology, when a material provider is changed, when a new payment, analytics, advertising or embedded-service integration is introduced, following a material change to consent controls, following a credible privacy or security complaint, and at other intervals considered appropriate having regard to risk and operational changes.

Review may include, as appropriate, developer verification, browser inspection, network-request review, vendor documentation review, security assessment, consent-flow testing, application-permission review, or automated scanning.

Where ScoreVedaa CAT uses a Consent Mechanism for an Optional Technology, it will take reasonable steps to verify that a recorded refusal is respected, withdrawal affects future Company-controlled processing, the technology is not materially misclassified, and optional technologies do not operate before Adult status is established where the Adult-status restriction applies. ScoreVedaa CAT will take reasonable steps to configure the relevant technology so that it does not activate before any required Consent has been obtained. Login or page refresh will be configured not to override a recorded refusal. A technical failure discovered through testing or complaint will be assessed and addressed according to its severity, the nature of the information, the affected technology, security risk, User impact, technical feasibility, and Applicable Law.

38. Governance and Change Control

The Company will maintain proportionate internal controls for adding or materially changing Cookies and Similar Technologies, having regard to the nature, purpose and risk of the relevant technology. Depending on the circumstances, such controls may include a documented business purpose, developer approval, privacy review, security review, category assignment, provider or contract review, retention assessment, Consent assessment, Internal Technology Register update, technical testing and authorised release approval.

The level of review may differ between a Strictly Necessary security fix, a temporary technical identifier, a payment integration, a non-essential analytics provider, a marketing technology, and a high-risk Third-Party Technology. The Company may retain appropriate provider contracts, change records, security assessments, consent evidence, testing records, incident records, and previous Policy versions. A technology that is no longer required will be disabled, removed from production, removed from the applicable Consent Mechanism, removed from the Internal Technology Register after an appropriate historical record is preserved, and addressed in applicable provider accounts or contracts.

J. USER RIGHTS, GRIEVANCES AND CHANGES

39. Privacy Rights

Where Cookie-derived information constitutes Personal Data, applicable rights may be exercised in accordance with the Privacy Policy and Applicable Law. Depending on applicability, a User may request information about Processing, access to a summary of Personal Data, correction, completion, updating, erasure, withdrawal of Consent, grievance redressal, and other statutory rights. A request may be submitted through the applicable Consent Mechanism, Account settings, privacy@neuramach.ai, grievance@neuramach.ai, or another designated rights-request process. Browser deletion alone is not necessarily a complete Personal Data erasure request.

40. Cookie and Privacy Grievances

Cookie-related privacy grievances may be submitted to:

Grievance Officer: Mr. Saurabh Sachdeo

Designation: Grievance Officer - Legal and Compliance

Company: NEURAMACH AI STUDIO PRIVATE LIMITED

Email: grievance@neuramach.ai

Phone: +91-8223815327

Address: 3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India.

A grievance should include Name, registered contact information where applicable, Account identifier where applicable, device or browser details where relevant, description of the issue, relevant dates, screenshot or evidence where available, the relevant Cookie or provider where known, and requested resolution. For Cookie-related privacy or consumer grievances not governed by a shorter statutory requirement, we will acknowledge the grievance within forty-eight hours and resolve it within one month of receipt, subject to Applicable Law. Where Applicable Law requires a shorter period, the shorter period will apply.

Urgent matters involving unauthorised Account access, active security threats, serious Personal Data exposure, payment fraud, or misuse of identity information will be prioritised according to severity. Content-removal and intermediary complaints may be governed by the separate timelines stated in the Terms and Conditions.

If your grievance is not resolved satisfactorily through our process, or the response period lapses, you may lodge a complaint with the Data Protection Board of India in the manner it prescribes.

41. Changes to this Cookie Policy

We may update this Cookie Policy to reflect legal changes, new technologies, provider changes, new Platform functions, consent-interface changes, security improvements, retention changes, campaign changes, mobile-application changes, or clarifications. The updated Policy will display a revised version number, an effective date, and a last-updated date.

For a material new Optional Technology, purpose or provider, we will update the Internal Technology Register and provide appropriate notice. Where Consent is required by Applicable Law, we will implement or update an appropriate Consent Mechanism and will not activate the relevant processing until the required Consent has been obtained.

Previously rejected optional categories will not become active merely because this Policy changes. A Policy update, continued browsing, silence or failure to opt out will not constitute Consent where affirmative Consent is required. Non-material clarifications may take effect upon publication. Earlier versions may be retained for compliance, audit, evidence and dispute-resolution purposes.

42. Contact Information

For Cookie questions, privacy requests or concerns, contact:

Legal Entity: NEURAMACH AI STUDIO PRIVATE LIMITED

Brand: NeuraMach.ai

Product: ScoreVedaa CAT

CIN: U62099PN2025PTC245340

Website: scorevedaa.in

Registered Office: Flat No. 201, Building 1, Wing 3, The Crown Greens, Plot 17, Infotech Park, Hinjawadi, Pune, Maharashtra 411057, India.

Principal Business and Correspondence Office: 3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India.

Privacy Email: privacy@neuramach.ai

Grievance Email: grievance@neuramach.ai

Support Email: support@neuramach.ai

Legal Email: legal@neuramach.ai

Telephone: +91-8223815327

Grievance Officer

Name: Mr. Saurabh Sachdeo

Designation: Grievance Officer - Legal and Compliance

Email: grievance@neuramach.ai

Phone: +91-8223815327