Official Legal Policy

NeuraMach AI Studio Private Limited - Privacy Policy

Effective Date: June 11, 2026Last Updated: June 11, 2026

ScoreVedaa CAT is a product owned and operated by NEURAMACH AI STUDIO PRIVATE LIMITED, a private limited company incorporated under the laws of India, bearing Corporate Identification Number U62099PN2025PTC245340 and operating under the brand name NeuraMach.ai.

Registered Office:

Flat No. 201, Building 1, Wing 3, The Crown Greens, Plot 17, Infotech Park, Hinjawadi, Pune, Maharashtra 411057, India.

Principal Business and Correspondence Office:

3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India.

In this Privacy Policy, references to “ScoreVedaa”, “ScoreVedaa CAT”, “NeuraMach.ai”, “Company”, “we”, “us” or “our” mean NEURAMACH AI STUDIO PRIVATE LIMITED, unless the context requires otherwise.

This Privacy Policy explains how we collect, receive, generate, use, analyse, store, disclose, transfer, retain, protect and delete Personal Data when an individual accesses or uses ScoreVedaa CAT.

Please read this Privacy Policy together with the:

  • ScoreVedaa CAT Terms and Conditions;
  • AI Usage Policy;
  • Cookie Policy;
  • Subscription, Cancellation and Refund Policy;
  • Model Improvement Notice;
  • Provider Training Notice, where applicable;
  • Institute Agreement, where applicable; and
  • Any other privacy or consent notice presented for a specific feature.

A. PRIVACY OVERVIEW AND SCOPE

1. Introduction

ScoreVedaa CAT is an AI-enabled CAT preparation and performance-intelligence platform intended for Adult Users. The Platform may provide:

  • Student registration and Account management;
  • CAT preparation tools;
  • Assessments and mock tests;
  • Exam simulation;
  • Performance analysis;
  • Topic classifications;
  • Difficulty Coverage analysis;
  • Preparation recommendations;
  • Goal and milestone planning;
  • AI-supported explanations through PRGNA;
  • Account-Level Personalisation;
  • Institute-facing tools where expressly authorised;
  • Subscription and payment facilities;
  • Support and grievance services; and
  • Optional AI model-improvement programmes.

To provide these Services, ScoreVedaa CAT may process information relating to:

  • Identity;
  • Adult eligibility;
  • Contact details;
  • Account usage;
  • Preparation activity;
  • Assessment performance;
  • Goals and preferences;
  • Device and technical activity;
  • Subscription transactions;
  • User uploads;
  • AI interactions;
  • Institute relationships;
  • Consent choices; and
  • Communications with us.

We seek to process Personal Data only for lawful, disclosed and reasonably necessary purposes.

2. Scope of this Privacy Policy

This Privacy Policy applies to Personal Data processed through:

  • The ScoreVedaa CAT website;
  • Student dashboards;
  • Institute and Faculty dashboards;
  • Web and mobile applications;
  • Registration pages;
  • Subscription and checkout flows;
  • PRGNA;
  • Assessment interfaces;
  • Support channels;
  • Institute invitation and linking processes;
  • Promotional, Trial or beta programmes;
  • Authorised integrations;
  • AI model-improvement consent interfaces;
  • Privacy and AI settings; and
  • Other ScoreVedaa CAT Services that refer to this Privacy Policy.

This Privacy Policy applies to Personal Data relating to:

  • Website Visitors;
  • Prospective Adult Users;
  • Registered Adult Students;
  • Individual subscribers;
  • Institute-sponsored Adult Students;
  • Institute Administrators;
  • Faculty Users;
  • Adult mentors and counsellors;
  • Persons contacting support;
  • Persons submitting grievances;
  • Referral or promotional participants; and
  • Persons whose Personal Data is validly supplied by an Institute or another authorised source.

This Privacy Policy does not govern:

  • Recruitment candidates covered by a separate candidate privacy notice;
  • Employees covered by internal employment policies;
  • Independent processing carried out by an Institute outside ScoreVedaa CAT;
  • Third-party websites and services governed by their own privacy policies;
  • A separately identified ScoreVedaa JEE, NEET, school-board or other product;
  • Information that has been genuinely and irreversibly anonymised so that it can no longer reasonably identify or be linked to an individual; or
  • Non-personal business or technical information that does not relate to an identifiable individual.

3. Product Separation

This Privacy Policy applies only to ScoreVedaa CAT. Access to ScoreVedaa CAT does not automatically authorise:

  • Processing for another ScoreVedaa product;
  • Cross-product use of identifiable User Content;
  • Cross-product model development;
  • Acceptance of another product’s privacy policy; or
  • Use of CAT Personal Data for JEE, NEET, school-board or other separately offered Services.

Where a User accesses another separately identified ScoreVedaa product, the privacy notice and consent framework applicable to that product will apply. Identifiable CAT Personal Data will not be used for cross-product Reusable Model development unless:

  • The proposed cross-product scope is clearly disclosed;
  • The relevant data categories and purposes are explained;
  • The User provides any separate affirmative Consent required by Applicable Law; and
  • Appropriate product-separation and security safeguards are maintained.

4. Eligibility and Age Requirement

ScoreVedaa CAT is a CAT-exam preparation platform intended for adult learners (18+) because its target examination and use case — CAT and MBA admissions — apply only to adults. This restriction is unrelated to the nature of the content, which is educational. The term 'Adult' below is used only in this defined, age-eligibility sense. ScoreVedaa CAT is intended only for individuals who have completed eighteen years of age and are legally capable of entering into a binding agreement. An individual below eighteen years of age must not knowingly:

  • Register an Account;
  • Purchase a Subscription;
  • Take an Assessment;
  • Use PRGNA;
  • Upload User Content;
  • Provide profile or preparation information;
  • Use another person’s Account; or
  • Circumvent an age-assurance or eligibility control.

A parent, guardian, Institute, teacher or other person may not create or activate a personal CAT Student Account for an individual below eighteen years of age.

We may process limited technical information when any Visitor accesses a public webpage before reaching an Adult-status declaration, including:

  • IP address;
  • Browser and device information;
  • Server and security logs;
  • Request timestamps;
  • Cookie-consent status; and
  • Network and diagnostic information.

Such processing may occur only for purposes such as delivering the public webpage, security, fraud and abuse prevention, network management, diagnostics, consent management, and legal compliance.

If we reasonably determine that an Account is being used by an individual below eighteen years of age, we may restrict access, suspend or close the Account, stop age-restricted processing, request verification, cancel attempted access where appropriate, and delete, isolate or otherwise handle associated Personal Data in accordance with Applicable Law.

Age assurance is not based on a self-declaration alone. We collect and validate date of birth at registration, apply additional verification where information is inconsistent or account sharing is suspected, and require Institutes to warrant that every student on a submitted roster is an adult.

5. Relationship With Other Documents

This Privacy Policy governs how ScoreVedaa CAT processes Personal Data. Where provisions conflict:

  • Mandatory Applicable Law prevails.
  • A valid Institute Agreement or data-processing agreement governs the relevant institutional arrangement.
  • A specific Model Improvement Notice and corresponding Training Consent govern optional internal identifiable-data model development.
  • A specific Provider Training Notice and corresponding separate Consent govern any separately approved provider-side model development.

This Privacy Policy governs general Personal Data processing. The AI Usage Policy governs permitted use and operation of AI Features and AI Outputs. The Cookie Policy governs cookies and similar technologies. The Terms and Conditions govern general access to and use of ScoreVedaa CAT.

General acceptance of the Terms or acknowledgement of this Privacy Policy does not constitute internal identifiable-data Training Consent, provider-side model-training Consent, Consent to optional cookies, Consent to unrelated marketing, or Consent to processing for another ScoreVedaa product.

B. DEFINITIONS AND RESPONSIBLE ENTITY

6. Definitions

For this Privacy Policy:

  • “Account” means a registered User profile through which a User accesses ScoreVedaa CAT.
  • “Account-Level Personalisation” means processing undertaken to customise or adapt the Services for a particular User or Account without training a Reusable Model for general use across other Users.
  • “Adult” means an individual who has completed eighteen years of age or such higher age as may be required to enter into a binding agreement under Applicable Law.
  • “AI Feature” means a feature using artificial intelligence, machine learning, statistical models, automated rules or related systems.
  • “AI Output” means a question, explanation, recommendation, classification, analysis, plan, summary, prediction or other output generated or assisted by an AI Feature.
  • “Applicable Law” means any law, rule, regulation, order, direction or legally binding requirement applicable to the processing of Personal Data.
  • “Assessment” means any diagnostic, topic, chapter, sectional, mock, practice, foundation, maintenance, stabilisation, challenge or other test offered through ScoreVedaa CAT.
  • “Authorised User” means an individual validly permitted to access an Account, workspace, batch or institutional feature.
  • “Consent” means consent satisfying the requirements of Applicable Law.
  • “Data Fiduciary” means a person that alone or together with another person determines the purpose and means of processing Personal Data, or as otherwise defined under Applicable Law.
  • “Data Principal” means the individual to whom Personal Data relates, or as otherwise defined under Applicable Law.
  • “Data Processor” means a person or entity that processes Personal Data on behalf of and under the documented instructions of a Data Fiduciary, or as otherwise defined under Applicable Law.
  • “Faculty User” means an Adult teacher, mentor, counsellor or similar individual authorised by an Institute.
  • “Institute” means a coaching institution, educational organisation, training provider, college, company or other organisation that purchases, sponsors, administers or facilitates Adult access to ScoreVedaa CAT.
  • “Institute-Linked Account” means an Account connected to an Institute, batch, programme or institutional Subscription through an expressly authorised process.
  • “Model Improvement Notice” means a separate notice describing optional internal Reusable Model development, including the relevant data categories, model-development purposes, whether historical information is included, whether human review may occur, whether approved Data Processors may assist, the retention approach, consequences of refusing or withdrawing Consent, and the withdrawal mechanism.
  • “Performance Data” means information concerning Assessments, answers, attempts, scores, timing, classifications, preparation patterns, goals and related activity.
  • “Personal Data” means any data about an individual who is identifiable by or in relation to that data, or as otherwise defined under Applicable Law.
  • “Personalised Recommendation” means a suggestion concerning preparation priorities, Assessments, topics, revision, milestones or next actions generated wholly or partly from available User data.
  • “Platform” means the ScoreVedaa CAT website, applications, dashboards, portals, APIs and supporting systems.
  • “PRGNA” means ScoreVedaa CAT’s learning and doubt-assistance feature, or any successor feature.
  • “Private User Content” means non-public prompts, conversations, uploads, Assessment answers, study notes, support communications and other User Content not intentionally made public by the User to the general internet. Sharing information within a closed Institute-Linked batch or with specific Authorised Users does not make it public.
  • “Processing” includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, analysis, alignment, combination, disclosure, transmission, restriction, erasure or destruction of Personal Data, or any equivalent activity under Applicable Law.
  • “Provider Training Notice” means a separate notice describing proposed use of Personal Data by a third-party provider for the provider’s independently controlled model training or product improvement.
  • “Reusable Model” means an artificial-intelligence, machine-learning, statistical or automated model, system or component trained, fine-tuned, tested, evaluated, validated, calibrated, benchmarked or improved using data so that the resulting learning may be used beyond the immediate User-requested transaction, session or Account-Level Personalisation.
  • “Service Provider” means a vendor, contractor, Data Processor, professional adviser or infrastructure provider supporting the Services.
  • “Student” means an Adult User accessing ScoreVedaa CAT for learning, CAT preparation, Assessment or performance analysis.
  • “Training Consent” means separate affirmative Consent through which a User agrees to specified optional internal Reusable Model development involving identified categories of Private User Content or identifiable Performance Data. Training Consent is not created by acceptance of the Terms, acknowledgement of this Privacy Policy, silence, inactivity, continued use, failure to opt out, a pre-selected checkbox, or a pre-enabled setting.
  • “User Content” means questions, prompts, screenshots, documents, notes, images, messages, answers, feedback or other material submitted by a User.
  • “User”, “you” or “your” means an Adult person using or interacting with ScoreVedaa CAT.
  • “Visitor” means a person accessing a publicly available part of the Platform without registering an Account.

7. Data Fiduciary and Responsible Entity

For Personal Data processed for ScoreVedaa CAT’s own purposes, the responsible entity and Data Fiduciary is: NEURAMACH AI STUDIO PRIVATE LIMITED CIN: U62099PN2025PTC245340 Registered Office: Flat No. 201, Building 1, Wing 3, The Crown Greens, Plot 17, Infotech Park, Hinjawadi, Pune, Maharashtra 411057, India. Principal Business and Correspondence Office: 3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India. Privacy Contact: privacy@neuramach.ai Grievance Contact: grievance@neuramach.ai

Depending on the relevant arrangement:

  • We are not currently a Significant Data Fiduciary. If designated as one, we will additionally appoint a Data Protection Officer based in India responsible to our Board of Directors, and carry out periodic Data Protection Impact Assessments and independent data audits.
  • ScoreVedaa may act as a Data Fiduciary for Account creation, security, billing, platform operation, AI inference, personalisation, support and internal model development;
  • An Institute may act as a separate Data Fiduciary for its own educational, administrative or commercial purposes;
  • ScoreVedaa may act as a Data Processor where it processes specified Institute Data solely on documented instructions from an Institute; or
  • ScoreVedaa and an Institute may have distinct responsibilities for different processing activities.

The applicable responsibilities may be described in an Institute Agreement, a data-processing addendum, an Institute privacy notice, the Institute-linking notice, this Privacy Policy, and Applicable Law. ScoreVedaa is not responsible for independent processing undertaken by an Institute outside the Platform or beyond ScoreVedaa’s instructions and control, without limiting ScoreVedaa’s own legal obligations.

C. SOURCES AND CATEGORIES OF PERSONAL DATA

8. Sources of Personal Data

We may receive Personal Data:

8.1 Directly from you

For example, when you register an Account, complete your profile, purchase a Subscription, set preparation goals, take Assessments, use PRGNA, upload User Content, contact support, submit feedback, report an error, accept an Institute invitation, join a programme, select privacy preferences, provide Training Consent, or submit a grievance or rights request.

8.2 Automatically through the Platform

For example, through server logs, device and browser information, authentication events, cookies and similar technologies, Assessment interaction records, error logs, security monitoring, consent-event logs, and feature-usage records.

8.3 From Institutes

An Institute may validly provide Adult Student rosters, contact details, batch or programme information, access entitlements, Faculty information, Assessment assignments, Institute identifiers, and authorisation records.

8.4 From Service Providers

We may receive information from payment providers, authentication providers, communication providers, customer-support providers, fraud-prevention providers, cloud and AI providers, analytics providers, and security vendors.

8.5 From authorised third parties

We may receive information from referral partners, promotional partners, a person authorised by the User, publicly available lawful sources, and legal or regulatory authorities. We will use information received from third parties only for lawful, disclosed and reasonably necessary purposes.

9. Account, Identity and Contact Information

We may process full name, username, email address, mobile number, Account identifier, password hash, authentication tokens, verification status, Adult-status declaration, age or date-of-birth information where required, registration date, Account status, preferred language, communication preferences, time zone, country or general region, Institute association, accepted policy versions, consent choices, and Account recovery information.

We use this information to create and maintain Accounts, confirm Adult eligibility, authenticate access, send operational communications, recover Accounts, manage privacy preferences, prevent duplicate or fraudulent Accounts, administer Subscriptions, link Accounts to authorised Institute programmes, maintain consent evidence, and provide support. We do not intend to store passwords in plain text.

10. Adult-Eligibility and Verification Information

To enforce the Adult-only requirement, we may process Adult-status declarations, date of birth or age range, verification status, inconsistency or fraud indicators, Institute-supplied eligibility information, limited identity information where reasonably required, and records of verification actions.

Additional age or identity assurance may be requested where supplied information is inconsistent, Account sharing is suspected, an Institute provides conflicting information, a restricted feature requires verification, or Applicable Law requires verification. We will seek to use proportionate verification measures and avoid collecting unnecessary identity documents.

11. Student Profile and Preparation Information

A Student may provide or generate CAT attempt year, preparation stage, sections and topics being studied, coaching or self-study status, study schedule, target score, target percentile, target institutions, academic or preparation preferences, preferred language, self-identified strengths, self-identified areas of concern, preparation history, selected goals, milestones, and other information voluntarily entered into the profile.

We use this information to configure the Student experience, personalise the Platform, select relevant Assessments, create goals and milestones, present relevant insights, generate recommendations, and improve support provided to that User. Users should avoid entering sensitive, confidential or unrelated Personal Data into optional free-text fields.

12. Goal and Action-Plan Information

We may process target score and percentile, target institutions, exam year, sectional targets, weekly study availability, milestones, selected priorities, completed tasks, skipped or delayed tasks, study plans, revision plans, recommended activities, User-selected activities, changes to goals, and progress indicators.

This information may be used to build preparation plans, prioritise topics, recommend Assessments, update milestones, recalculate action plans, track progress, and present dashboard information. Goal information is advisory and is not treated as an official admission application or institutional commitment.

13. Assessment and Attempt Data

When you take an Assessment, we may process the Assessment identifier, questions presented, answer options displayed, answers selected, correct, incorrect and unanswered responses, questions marked for review, attempt number, start and submission times, raw and calculated scores, negative marking, sectional scores, completion status, retake history, answer-key version, question feedback, Assessment-integrity indicators, and technical events affecting the attempt.

We use this information to administer Assessments, calculate scores, display solutions, generate performance analysis, classify topics, recommend next actions, maintain attempt history, investigate technical issues, detect manipulation, resolve score disputes, and personalise the Student experience. Assessment records may be corrected where an answer key changes, a question is withdrawn, a technical issue is confirmed, or a score is recalculated.

14. Timing, Navigation and Behavioural Information

We may process educational and operational activity including time spent per question, time spent per section, total Assessment time, questions visited, navigation sequence, review activity, skips, repeated visits, submission behaviour, session interruptions, pauses where permitted, frequency of Assessments, repeated topic avoidance, use of recommended activities, dashboard interactions, login patterns, and other disclosed usage signals.

We may use this information to analyse time allocation, identify preparation patterns, generate recommendations, detect technical issues, maintain Assessment integrity, improve personalisation, prevent Account misuse, and help Users understand their performance. Automated behavioural indicators are not treated as conclusive proof of a personal trait, intention or misconduct without appropriate review where the consequence is material. We do not use identifiable educational Behavioural Data for third-party targeted advertising.

15. Performance Analytics and AI-Derived Data

ScoreVedaa may calculate or generate accuracy, attempt rate, time efficiency, topic-wise performance, difficulty-wise performance, sectional performance, score trends, performance variance, question-selection patterns, improvement trends, consistency indicators, topic coverage, preparation progress, topic classifications, root-cause indicators, difficulty estimates, Personalised Recommendations, test suggestions, study plans, priority rankings, confidence indicators, readiness indicators, error-pattern summaries, and provisional findings.

These outputs may be generated using User-provided information, Assessment Data, Timing and Behavioural Data, historical performance, goals, available evidence, statistical methods, rule-based logic, AI models, human-designed educational frameworks, and hybrid processing. Performance Analytics and AI-Derived Data may be inaccurate, incomplete or provisional; may change when more evidence becomes available; are not official CAT results; are not psychological assessments; are not admission decisions; are not guarantees of future performance; and should not be used as the sole basis for punitive or exclusionary decisions.

16. User Uploads

ScoreVedaa may allow Users to upload questions, screenshots, images, PDFs, notes, documents, study material, doubts, solutions, feedback, and other authorised files. Uploads may be processed to generate requested explanations, analyse a question, provide support, maintain conversational context, investigate errors, detect malware, enforce Platform rules, comply with legal obligations, conduct limited quality assurance, and where valid Training Consent applies, support authorised internal model development.

Users should not upload government identifiers unless specifically requested, full payment-card information, bank credentials, passwords or verification codes, UPI PINs, unnecessary health information, unrelated sensitive Personal Data, Personal Data of another person without lawful authority, confidential Institute material without permission, copyrighted material without authority, leaked examination material, or unlawful Content. Private uploads will not be used for identifiable internal Reusable Model development unless the applicable Model Improvement Notice clearly includes the relevant upload category and the User has provided valid Training Consent covering that category. Users should retain independent copies of important uploads.

17. PRGNA Prompts and Conversations

When a User interacts with PRGNA, we may process prompts, questions, uploaded files, conversation history, AI responses, feedback, reported errors, conversation timestamps, technical logs, Account context, safety indicators, and abuse or security indicators. We use this information to respond to the User, maintain permitted conversational context, provide explanations, personalise the experience, troubleshoot issues, detect abuse or security threats, investigate reported errors, comply with law, and enforce the Terms and AI Usage Policy.

Private PRGNA conversations are not automatically shared with an Institute. An Institute or Faculty User may view a PRGNA interaction only where the Student expressly chooses to share it, an authorised share function is used, the interaction occurs in a clearly identified Institute-controlled workspace after advance notice, a lawful institutional arrangement specifically permits access, or disclosure is required by law. Private PRGNA conversations will not be used for identifiable internal Reusable Model development unless the applicable Model Improvement Notice expressly includes eligible AI interactions or conversations and the User has provided valid Training Consent covering that category. Users should not enter unnecessary confidential or sensitive information into PRGNA.

18. Institute and Faculty Information

For Institute Administrators and Faculty Users, we may process name, work email address, mobile number, Institute name, role and designation, batch or programme association, Account permissions, authentication records, login and access history, Assessment assignments, Student-access scope, reports accessed, administrative actions, communications, commercial contact information, and Institute-provided identity or authority information.

We use this information to create institutional Accounts, manage role-based permissions, restrict access to authorised Students, maintain audit records, prevent unauthorised access, provide Institute support, administer commercial relationships, monitor authorised use, and enforce confidentiality and data-access restrictions. Institutes must ensure that information supplied about Faculty Users is accurate and lawfully shared.

19. Institute-Linked Account Information

An Institute-Linked Account may involve Institute name, programme or batch, Student identifier, enrolment status, assigned Assessments, completion status, programme-specific goals, Institute-sponsored Subscription status, access permissions, share settings, and information expressly authorised for Institute viewing. Merely naming an Institute during registration does not automatically share Personal Data with that Institute. Before continuing Institute access is enabled, the Platform will disclose the categories of Personal Data that the Institute or authorised Faculty Users may access.

Unless separately authorised, an Institute will not automatically receive private PRGNA conversations, personal uploads, payment credentials, passwords, direct support communications, private study notes, unrelated personal goals, or activity outside the authorised programme. A Student-led display of information to a Faculty User does not automatically give the Institute permanent or ongoing access.

20. Payment and Transaction Information

For paid Services, we may process purchaser name, billing contact details, Subscription plan, price, taxes and GST information, transaction identifier, payment status, payment date, renewal date, cancellation status, refund or reversal status, payment-mandate reference, invoice details, promotional code, payment-provider response, and limited payment-method details such as provider, card type or masked account information.

Payments are generally processed by authorised payment providers. ScoreVedaa does not intend to store full card numbers, CVV numbers, full bank credentials, UPI PINs, or payment authentication secrets. We use transaction information to activate Subscriptions, process authorised recurring payments, issue invoices, confirm payments, manage cancellation, investigate failed or duplicate charges, prevent fraud, maintain accounting records, and comply with tax and legal obligations. Payment providers may independently process information under their own terms and privacy notices.

21. Device, Network and Technical Information

When you access ScoreVedaa CAT, we may automatically receive IP address, device type, operating system, browser type and version, language settings, time zone, app version, device or session identifier, login timestamp, referring page, pages or features accessed, error logs, crash information, network information, general geographic region inferred from IP address, cookie or similar identifiers, authentication events, and security events.

We use this information to deliver the Platform, maintain sessions, improve compatibility, diagnose errors, prevent fraud, protect Accounts, detect abnormal access, measure Platform performance, maintain security records, and enforce technical restrictions. We will not collect precise device location unless a feature expressly requires it, clear notice is provided, and required device permission or Consent is obtained.

22. Support, Communication and Grievance Information

When you contact us, we may process name, Account information, contact details, message content, attachments, screenshots, call notes, support history, complaint details, grievance details, rights-request details, resolution status, satisfaction feedback, relevant technical data, and relevant transaction information.

We use this information to respond to requests, verify Account ownership, investigate problems, resolve billing concerns, address privacy requests, handle grievances, maintain service-quality records, detect abuse, and establish, exercise or defend legal claims. Calls may be recorded only where recording is lawfully permitted, appropriate notice is provided, and recording is reasonably necessary.

23. Consent, Acceptance and Preference Records

We may maintain records including the User identifier, the exact notice, checkbox, button or control presented, Terms and Privacy Policy versions, Model Improvement Notice version, Provider Training Notice version, data categories covered, stated purposes, whether historical information was included, whether human review was disclosed, date and timestamp, IP address, session or device identifier, language displayed, consent status, withdrawal date, preference changes, dataset-eligibility status, suppression actions, and a copy or cryptographic hash of the notice presented.

We use these records to demonstrate electronic acceptance, prove Consent where required, honour withdrawals, prevent unauthorised training, manage privacy settings, resolve disputes, and meet legal and audit obligations.

D. PURPOSES AND GROUNDS OF PROCESSING

24. Purposes of Processing

We may process Personal Data to:

  • Create and maintain Accounts;
  • Confirm Adult eligibility;
  • Authenticate Users;
  • Provide Assessments;
  • Record and score attempts;
  • Analyse performance;
  • Generate topic classifications;
  • Calculate Difficulty Coverage;
  • Generate Personalised Recommendations;
  • Operate PRGNA;
  • Build goals and action plans;
  • Personalise the Platform;
  • Provide Institute-linked Services;
  • Process Subscriptions;
  • Manage automatic renewal;
  • Prevent fraud;
  • Secure Accounts;
  • Maintain Assessment integrity;
  • Provide support;
  • Handle complaints and grievances;
  • Send operational communications;
  • Send authorised marketing;
  • Comply with law;
  • Respond to lawful requests;
  • Protect intellectual property;
  • Detect misuse;
  • Maintain records;
  • Resolve disputes;
  • Improve Platform reliability;
  • Conduct anonymised or aggregated analytics;
  • Develop internal Reusable Models using anonymised information;
  • Conduct optional identifiable-data model development after Training Consent;
  • Enable separately consented provider-side model development where introduced; and
  • Perform other purposes disclosed at the time of collection.

We will not use Personal Data for a new incompatible purpose without appropriate notice and, where required, separate Consent or another lawful ground.

25. Grounds for Processing

Depending on the activity and Applicable Law, we may process Personal Data based on:

25.1 Consent

For example: optional internal identifiable-data model development, provider-side model training, optional cookies, non-essential marketing, optional precise-location access, and other processing for which affirmative Consent is required.

25.2 Processing requested or voluntarily initiated by the User

For example: creating an Account, taking an Assessment, asking PRGNA a question, uploading a file, purchasing a Subscription, requesting support, or accepting an Institute invitation.

25.3 Certain legitimate or permitted uses recognised by Applicable Law

For example: responding to information voluntarily provided for a specified purpose, complying with a legal obligation, responding to a medical or safety emergency where legally permitted, protecting against fraud or security threats where permitted, and other uses expressly recognised under Applicable Law.

Where we process Personal Data to secure the Services, prevent fraud or misuse, or maintain reliability, we treat such processing as necessary to provide the Services the User has requested under Sections 25.1 and 25.2, and we do not rely on any standalone "legitimate interest" balancing test, which is not a ground of processing under the Digital Personal Data Protection Act, 2023.

25.4 Legal compliance and protection of rights

For example: tax and accounting, cybersecurity, court and government requests, preservation of evidence, enforcement of agreements, establishing or defending legal claims, and protecting Users, the Platform or third-party rights.

Nothing in this Section creates an independent ground for processing. Each processing activity will be undertaken only where supported by valid Consent, an applicable certain legitimate use, a legal obligation or another ground expressly authorised under Applicable Law.

26. Consent Standards

Where processing is based on Consent, the Consent request will, where applicable: be presented in clear and plain language, identify the relevant Personal Data, explain the specified purpose, explain material uses, identify the relevant recipient or provider where required, explain how Consent may be withdrawn, provide access to the relevant notice, explain material consequences of refusal or withdrawal, and provide contact and grievance information.

Consent will not be obtained through deception, misleading language, unnecessary bundling, pre-selected checkboxes where an affirmative action is required, pre-enabled settings where an affirmative action is required, silence, inactivity, continued use alone, or failure to opt out. Withdrawal will not affect processing lawfully completed before withdrawal.

Where required by Applicable Law, the User will be given the option to access the relevant notice and Consent request in English or an available language specified in the Eighth Schedule to the Constitution. A Consent notice will be understandable independently of other information presented to the User and will contain an itemised description of the relevant Personal Data and specified purposes.

An itemised Data Collection & Consent Notice is presented to the User at the point of collection and may be read independently of this Policy.

E. PERSONALISATION, AI AND MODEL IMPROVEMENT

27. Account-Level Personalisation

ScoreVedaa CAT may use Student Profile Information, goals, Assessment history, Performance Data, topic classifications, Difficulty Coverage, PRGNA interactions, User preferences, recent activity, and feedback to customise and adapt the User’s ScoreVedaa CAT experience.

Account-Level Personalisation may include creating a User-specific preparation profile, maintaining permitted conversational context, generating Account-associated representations or embeddings, selecting relevant Assessments, adjusting question difficulty, adjusting explanation depth, ranking recommendations, recalculating action plans, identifying preparation gaps, adapting dashboards, adapting notifications, and improving the relevance of AI Outputs for that User.

Account-Level Personalisation is distinct from training a Reusable Model for use across other Users. Where reasonably necessary to provide the requested feature, Account-Level Personalisation may form part of the core Service and may not depend on optional Training Consent. Users may be able to modify goals, reset selected preferences, clear available conversation memory, reject recommendations, or disable an optional personalisation feature.

28. AI Inference and Service Delivery

To provide an AI response or other AI Feature, we may process and transmit relevant prompts, conversations, uploads, Assessment responses, Performance Data, instructions, Account context, goal information, and technical information to authorised Company systems and Service Providers.

This processing may be undertaken to generate requested AI Outputs, operate PRGNA, maintain permitted context, analyse performance, produce Personalised Recommendations, select Assessments, adjust difficulty, produce reports, moderate unsafe inputs, maintain security, detect abuse, troubleshoot errors, and comply with law. Processing information to generate an immediate response or provide a requested feature is distinct from using that information to train a Reusable Model.

29. Irreversibly Anonymised and Aggregated Model Improvement

We may transform Personal Data into information that is irreversibly anonymised or aggregated so that it no longer identifies, relates to or can reasonably be linked to an individual. We may use irreversibly anonymised or aggregated information for product analytics, research, capacity planning, reliability measurement, error-rate measurement, safety analysis, evaluation and benchmarking, improving Assessment logic, improving recommendation systems, developing educational features, training internal ScoreVedaa or NeuraMach Reusable Models, testing and validating internal models, and improving internal AI systems.

Removing direct identifiers such as a name, email address, phone number or Account identifier does not, by itself, constitute irreversible anonymisation. We may use measures including removal of direct identifiers, removal or generalisation of indirect identifiers, free-text filtering, aggregation, thresholding, tokenisation, separation of lookup keys, access controls, re-identification risk assessment, and prohibition on intentional re-identification.

Where information has been genuinely and irreversibly anonymised: it may no longer be possible to associate it with an individual User, an individual contribution may not be removable from a completed aggregate, an individual contribution may not be removable from a statistical result, and an individual contribution may not be removable from completed model parameters where no reasonable link to the User remains. Irreversibly anonymised information is distinct from identifiable-data Training Consent.

30. Optional Internal Reusable Model Development Using Identifiable Information

We may invite a User, during registration or later through the Platform, to separately consent to optional internal Reusable Model development. Where valid Training Consent is provided, we may use the specified categories of Private User Content or identifiable Performance Data to train, fine-tune, test, evaluate, validate, calibrate, benchmark and improve Company-controlled ScoreVedaa or NeuraMach Reusable Models and related AI systems.

The purposes may include improving CAT question generation, explanation quality, topic classification, difficulty estimation, error detection, recommendation quality, personalisation systems, retrieval systems, safety systems, Assessment assembly, performance analysis, and other CAT educational capabilities described in the Model Improvement Notice.

Before Training Consent is requested, the Model Improvement Notice must identify, as applicable: the data categories proposed for use, whether prompts are included, whether PRGNA conversations are included, whether uploads are included, whether Assessment responses are included, whether Performance Data is included, whether historical information is included, the model-development purposes, whether authorised human review may occur, whether approved Data Processors may assist, the retention approach, the withdrawal mechanism, and any material consequence of refusal or withdrawal.

Training Consent:

  • Is separate from the mandatory Terms checkbox;
  • Is separate from acknowledgement of this Privacy Policy;
  • Requires an initially unticked checkbox or another clear affirmative action;
  • Is optional;
  • Does not affect access to core ScoreVedaa CAT Services;
  • Is recorded for audit and compliance;
  • Does not authorise provider-side training; and
  • May be withdrawn through the Platform.

The signup prompt must clearly state that participation is optional, refusal will not affect core Services, the relevant data categories are described in the Model Improvement Notice, and Consent may be withdrawn through Settings. The consent wording may state substantially:

“Help improve ScoreVedaa’s AI. I consent to NeuraMach using the categories of my identifiable data described in the Model Improvement Notice including eligible prompts, AI interactions, Assessment responses and Performance Data—to train, test, evaluate and improve Company-controlled ScoreVedaa and NeuraMach AI models. This is optional and will not affect my access to ScoreVedaa’s core services. I can withdraw my consent at any time through Settings → Privacy & AI → AI Model Improvement.”

Where the User does not provide Training Consent, identifiable Private User Content and Performance Data will not be selected for optional internal Reusable Model development.

31. Withdrawal of Internal Training Consent

A User may review and withdraw Training Consent through: Settings → Privacy & AI → AI Model Improvement. The relevant setting will be labelled substantially as: “Use my identifiable data to improve ScoreVedaa’s AI models.” The setting will display ON only after valid affirmative Training Consent has been provided, display OFF where Consent has not been provided, display OFF after withdrawal, link to the applicable Model Improvement Notice, reflect the User’s current consent status, and permit withdrawal without unnecessary steps.

Training Consent may also be withdrawn through web Account settings, mobile-app settings, the consent-management interface, privacy@neuramach.ai, or another communicated method. Following withdrawal, we will within a reasonable period: stop selecting new identifiable information for the withdrawn purpose, update the User’s consent status, update dataset-eligibility status, remove or suppress identifiable information from active training or evaluation datasets where reasonably practicable and legally required, instruct relevant Data Processors to cease the withdrawn optional processing, and retain only information required for legal, audit, security, fraud or dispute purposes.

Withdrawal applies prospectively. Withdrawal does not affect processing lawfully completed before withdrawal. Individual removal may not be possible where information has already been irreversibly anonymised, included in a completed aggregate, incorporated into completed statistical results, or incorporated into model parameters in a manner that cannot reasonably identify or be linked to the User. This limitation must be disclosed before Training Consent is obtained. Withdrawal of Training Consent will not automatically disable Account access, Assessment services, AI inference, performance analysis, core Account-Level Personalisation, or other processing necessary to provide the Services.

32. Limited Quality Assurance, Safety and Incident Review

Regardless of Training Consent, we may conduct limited and purpose-specific review of a particular AI interaction, AI Output, Assessment response, Performance Data record, technical record, User upload, or related context where reasonably necessary to reproduce a reported error, respond to support, investigate a security incident, detect fraud or abuse, verify whether a feature operated as represented, investigate an incorrect question or answer key, investigate an incorrect classification or recommendation, respond to a legal complaint, test a specific correction, enforce Platform rules, or protect the reliability and safety of the Services.

Such processing may be used to correct software defects, correct questions or answer keys, correct retrieval sources, correct rules or calculations, adjust operational prompts, adjust workflows, improve rule-based, non-machine-learning safeguards, resolve the incident, or produce anonymised operational metrics. This limited processing does not independently authorise general identifiable-data Reusable Model training.

33. Third-Party AI and Cloud Providers

We may use authorised third-party providers for large language models, AI inference, cloud hosting, model hosting, retrieval infrastructure, moderation, security, logging, analytics, customer support, and related infrastructure. Such providers may process relevant prompts, User Content, Performance Data, Account context, and technical information only as reasonably necessary for the authorised Service or purpose.

We will use only Paid, Enterprise, Business, API, or other contractually controlled configurations under which binding written terms, applicable data-processing terms or enforceable service configurations prohibit the provider from using Private User Content or identifiable Performance Data for the provider’s own general-purpose model training, independent product improvement, independent model fine-tuning, general provider benchmarking, or unrelated purposes, unless separate provider-side processing has been disclosed and affirmatively consented to in accordance with Section 34.

We will strictly not route live Private User Content or identifiable Performance Data through:

  • Free consumer AI accounts;
  • Unpaid developer configurations permitting provider training;
  • Personal chatbot accounts;
  • Public playgrounds;
  • Unapproved experimental endpoints; or
  • Provider configurations whose data-use terms have not been reviewed.

Before routing live information through a provider, we will take reasonable steps to review contractual terms, data-processing terms, retention settings, training settings, human-review conditions, security controls, and service configurations. Where we become aware that required protections no longer apply, we will stop routing new live identifiable information through the affected configuration within a reasonable period and will restore a compliant configuration, move processing to another compliant provider, or suspend the affected feature where reasonably necessary. A provider may process limited information for security, abuse detection, moderation, troubleshooting, legal compliance, reliability, or service operation where such processing is contractually permitted, reasonably necessary and lawful.

34. Provider-Side Model Training

Internal Training Consent does not authorise a third-party provider to use Personal Data for the provider’s own model training, independent model fine-tuning, independent benchmarking, general product development, or improvement of services not supplied exclusively for the Company.

Where ScoreVedaa proposes provider-side model training or independent product improvement in the future, we must first provide a separate Provider Training Notice identifying, as applicable: the provider or provider category, the relevant data categories, the provider’s purpose, whether the provider acts independently, retention, potential human review, international processing, withdrawal methods, and other material information required by Applicable Law.

Separate affirmative Consent must be obtained before enabling provider-side model training or independent product improvement using Private User Content or identifiable Performance Data. Provider-side Consent must be separate from internal Training Consent, must not be inferred from acceptance of the Terms, must not be inferred from continued use, must not be represented by a pre-enabled control, must be recorded, must be withdrawable, and must identify the relevant provider use with sufficient clarity.

The relevant control may appear under Settings → Privacy & AI → AI Model Improvement and may be labelled substantially as: “Allow eligible AI providers to use my identifiable data for model improvement.” The control should appear only where such provider-side processing is actually proposed. Refusal to provide provider-side Consent will not prevent access to ordinary ScoreVedaa CAT Services where a compliant no-provider-training configuration is reasonably available.

35. Human Review

Authorised Company personnel or contractors may review limited Personal Data where reasonably necessary for support, quality assurance, safety, fraud prevention, incident investigation, legal compliance, content moderation, error correction, or optional model development covered by valid Training Consent. Human reviewers will be subject to appropriate role-based access, confidentiality obligations, data-minimisation requirements, security controls, training, monitoring, and retention restrictions. ScoreVedaa will not represent an AI Output as human-reviewed unless it has actually been reviewed by an authorised person.

F. INSTITUTE PROCESSING AND DATA SHARING

36. Data Received From Institutes

An Institute may provide Adult Student names, Student email addresses, Student mobile numbers, batch identifiers, programme details, Faculty details, enrolment information, Assessment assignments, Institute-generated identifiers, access entitlements, and authorisation or consent records where applicable.

An Institute must ensure that it has lawful authority to provide the information, appropriate notice has been given, required Consent or authorisation has been obtained, every Student submitted for CAT onboarding is an Adult, the information is accurate, only necessary information is supplied, the information is used only for authorised purposes, and under-age individuals are not onboarded. ScoreVedaa may request evidence of an Institute’s authority. Where an Institute provides Personal Data without valid authority, the Institute remains responsible for that disclosure, subject to ScoreVedaa’s own obligations after becoming aware of the issue.

37. Sharing With Institutes

ScoreVedaa does not automatically share a Student’s Personal Data with an Institute merely because the Student attends that Institute, the Student names the Institute during registration, the Institute uses ScoreVedaa CAT, or the Student uses ScoreVedaa alongside coaching.

An Institute or authorised Faculty User may view selected information only where the Adult Student expressly shares it, an authorised share feature is used, the Student accepts an Institute invitation after receiving notice, the Student joins an authorised programme after disclosure, information is displayed during an authorised review session, a separate lawful arrangement permits access, or disclosure is required by law.

Depending on authorisation, visible information may include assigned Assessment completion, scores, accuracy, attempt rate, timing, topic classifications, goal or milestone progress, recommended educational actions, and aggregate or batch-level reports. Unless separately authorised, Institutes will not automatically receive private PRGNA conversations, personal uploads, payment credentials, passwords, direct support communications, private notes, unrelated personal goals, or activity outside the authorised programme. A Student-led display of information to a Faculty User does not automatically give the Institute permanent or ongoing access. Institute access may be revoked or modified where permitted by product configuration, contract and Applicable Law. Information already lawfully received by an Institute may remain subject to that Institute’s own retention and legal obligations.

38. Training Consent and Institute Data

An Institute or Faculty User may not provide Training Consent on behalf of an Adult Student unless the Student has expressly authorised that action, the consent method is permitted by Applicable Law, the applicable notice has been provided, and ScoreVedaa maintains sufficient evidence of the Student’s affirmative Consent. Institute Data identifying an Adult Student will not be selected for optional internal Reusable Model development merely because the Institute supplied it. The relevant Student must provide any Training Consent required for use of identifiable Student data, unless another lawful basis expressly permits the processing and the public disclosures are updated accordingly.

G. DISCLOSURES AND RECIPIENTS

39. Service Providers

We may share Personal Data with Service Providers supporting cloud hosting, database services, AI inference, model hosting, payment processing, authentication, email and SMS delivery, customer support, error monitoring, security, analytics, consent management, document storage, tax and accounting, legal services, audit services, and professional advice.

Service Providers receive only information reasonably necessary for their authorised functions. Where a Service Provider processes Personal Data on our behalf as a Data Processor, we will require the Service Provider through a valid written contract to process information only for authorised purposes, follow documented instructions where acting as Data Processors, maintain confidentiality, apply reasonable security safeguards, restrict personnel access, follow retention and deletion instructions, assist with legal obligations, notify us of relevant security incidents, and restrict subcontracting where appropriate. A Service Provider’s independent activities may also be governed by its own privacy notice.

A current list of the categories of recipients, the identity of key Service Providers, and the countries in which Personal Data may be processed is maintained in Annex A to this Policy and is updated when material changes occur. A Data Principal may also request these details in respect of their own Personal Data by writing to privacy@neuramach.ai.

We host our infrastructure and process personal data through Amazon Web Services (AWS) under a signed Data Processing Agreement that binds AWS to process data only on our instructions, apply appropriate security safeguards, and support our compliance obligations under the DPDP Act. We host core platform data — including PostgreSQL databases, Redis caches, S3 storage, and Cognito authentication — in India (ap-south-1, Mumbai). AI inference through AWS Bedrock is processed in the United States (us-east-1, N. Virginia) because Bedrock's available model regions differ from our primary hosting region. Our Qdrant vector database is hosted via AWS in the EU (eu-central-1, Frankfurt). All three regions are governed by our AWS Data Processing Agreement.

We use Sentry for error monitoring and crash reporting, under a signed Data Processing Agreement. Sentry may process technical data such as stack traces and request metadata; we configure Sentry to scrub personal data such as names, emails, and payment details before it reaches Sentry's systems. Sentry processes this data in the United States.

40. Payment and Financial-Service Providers

Payment information may be processed by banks, card networks, UPI providers, payment gateways, mandate providers, fraud-prevention providers, tax and invoicing providers, and other entities involved in a transaction. Such providers may process information for payment authorisation, recurring mandates, pre-debit notifications, fraud screening, settlement, reconciliation, chargebacks, refunds, regulatory compliance, and dispute resolution. ScoreVedaa does not control every independent processing activity undertaken by banks, card networks or payment providers.

41. Analytics and Monitoring Providers

We may use analytics or monitoring providers to understand website traffic, feature usage, conversion paths, Platform performance, errors, session quality, device compatibility, and general engagement. Analytics may involve cookie identifiers, device information, IP address, general region, pages viewed, events completed, session duration, and technical errors. Where required, non-essential analytics will be subject to Consent or preference controls. We seek to avoid sending the following to general analytics providers: full private PRGNA conversations, full User uploads, full Assessment answers, passwords, payment credentials, or unnecessary identifiable Performance Data. Further details are provided in the Cookie Policy.

42. Legal and Regulatory Disclosures

We may disclose Personal Data to courts, tribunals, law-enforcement authorities, regulators, data-protection authorities, tax authorities, cybersecurity authorities, government departments, professional advisers, and other legally authorised recipients. Disclosure may occur where reasonably necessary to comply with law, respond to valid legal process, investigate fraud, respond to a cybersecurity incident, preserve evidence, protect legal rights, enforce agreements, protect Users, protect the Platform, or prevent serious harm. We will seek to disclose only information reasonably required or permitted. Where appropriate and legally permitted, we may notify the affected User before disclosure. We may challenge a request that appears overbroad, defective, unlawful, or inconsistent with applicable procedure.

43. Business Transfers

If the Company undergoes or considers a merger, acquisition, investment, reorganisation, financing, sale of assets, insolvency process, business transfer, or change of control, Personal Data may be reviewed or transferred where reasonably necessary for that transaction. We will seek to ensure that confidentiality is maintained, access is limited, the recipient processes Personal Data consistently with Applicable Law, mandatory User rights remain protected, existing consent restrictions remain associated with the data, model-training consent status is preserved, and appropriate notice is provided where required. Personal Data will not be transferred for an unrelated purpose merely because preliminary commercial discussions occurred.

44. International Processing

Some Service Providers may process or store Personal Data outside India. International processing may occur for cloud hosting, AI inference, model hosting, security, technical support, analytics, communication delivery, and other infrastructure services. Where Personal Data is processed outside India, we will comply with Applicable Law, follow applicable government restrictions, use appropriate contractual safeguards, assess provider security, restrict processing to authorised purposes, maintain relevant records, preserve consent limitations, and take reasonable steps to protect Personal Data. We will not knowingly transfer Personal Data to a country, territory, recipient or arrangement prohibited by Applicable Law or a binding Government restriction. International processing does not remove rights otherwise available under this Privacy Policy.

The recipients that may process Personal Data outside India, and the countries involved, are identified in Annex A to this Policy. No such recipient is located in a country restricted by notification of the Central Government under Section 16 of the Digital Personal Data Protection Act, 2023.

45. No Sale or Rental of Personal Data

ScoreVedaa does not sell or rent Personal Data as a standalone commodity. ScoreVedaa does not use private PRGNA conversations, private User uploads, Assessment answers, identifiable Performance Data, or internal Training Consent data for third-party behavioural advertising. We may use limited Account and engagement information to communicate about ScoreVedaa or NeuraMach products where the communication is lawful, required Consent or preferences are respected, and an unsubscribe or preference mechanism is provided. Business transfers, Service Provider processing and legally required disclosures are not treated as a sale of Personal Data under this Policy.

H. COMMUNICATIONS AND COOKIES

46. Operational Communications

We may send operational communications including Account verification, password resets, security notices, Assessment alerts, Subscription confirmations, renewal reminders, pre-debit messages where applicable, cancellation confirmations, payment receipts, Service notices, Institute-linking notices, policy updates, consent notices, withdrawal confirmations, grievance responses, breach notices, and support messages. Operational communications may be necessary for the Services and may not be optional while the relevant Account, request or Subscription remains active.

47. Marketing Communications

Marketing communications may include product announcements, offers, events, educational content, referral campaigns, promotional messages, and information about other ScoreVedaa or NeuraMach Services. Marketing messages will be sent in accordance with Applicable Law and applicable preferences. Users may withdraw from non-essential marketing through an unsubscribe link, Account preferences, a messaging preference mechanism, or a request to support@neuramach.ai. Unsubscribing from marketing does not prevent essential operational communications.

48. Cookies and Similar Technologies

ScoreVedaa CAT may use cookies, local storage, session storage, pixels, SDKs, tags, device identifiers, and similar technologies. These technologies may support login, authentication, security, session continuity, User preferences, Platform performance, error monitoring, analytics, consent management, and marketing where lawfully enabled. Essential technologies may be necessary for the Platform to function. Optional analytics, advertising or tracking technologies will be used in accordance with Applicable Law and applicable consent controls. Incorporation or acknowledgement of the Cookie Policy does not itself constitute Consent to optional cookies. Further information is provided in the Cookie Policy.

I. RETENTION, DELETION AND ANONYMISATION

49. Retention Principles

We retain Personal Data only for as long as reasonably necessary for providing the Services, maintaining an Account, administering a Subscription, preserving requested Assessment history, supporting performance analytics, maintaining security, preventing fraud, maintaining consent records, honouring withdrawal, resolving disputes, meeting tax, accounting or legal obligations, responding to grievances, protecting intellectual property, conducting authorised model development, and establishing, exercising or defending legal claims.

Retention periods may depend on the data category, the purpose, Account status, User choices, Consent status, security requirements, Institute arrangements, legal requirements, limitation periods, and whether a dispute is pending. We will maintain, implement and periodically review a written retention schedule covering material categories of Personal Data, processing purposes, applicable retention periods, deletion or anonymisation actions, legal holds, backup cycles and Data Processor instructions.

50. Indicative Retention by Category

If a User does not log in for 24 consecutive months, we will send a reminder to the registered contact; if there is no response within 30 days, we will erase or irreversibly anonymise the account data, except data we are required to retain by law.

50.1 Account and profile information

Generally retained while the Account is active and for a reasonable period after closure where needed for security, fraud prevention, reconciliation, legal compliance, billing, or dispute resolution.

50.2 Assessment and Performance Data

Generally retained while needed to provide progress history, reports, personalisation, recommendations, Institute programme functions, or User-requested analytics. Following Account closure, such data may be deleted, anonymised or retained where a lawful reason applies.

50.3 PRGNA conversations and uploads

Retained while reasonably necessary for the requested Service, conversation history, support, User settings, safety, dispute resolution, authorised model development, legal compliance, or backup cycles.

50.4 Training Consent and model-development records

Consent evidence may be retained while the relevant processing continues, after withdrawal to demonstrate the withdrawal, for audit purposes, for legal claims, and for applicable limitation periods. Training datasets will be subject to the applicable Model Improvement Notice and internal retention controls.

50.5 Provider Training Consent records

Retained while relevant to prove the separate Consent, honour withdrawal, manage provider instructions, demonstrate compliance, and resolve disputes.

50.6 Payment and invoice information

Retained for periods required by tax, accounting, financial regulation, chargeback handling, and legal obligations.

50.7 Security and processing logs

ICT system logs are retained for a minimum of one hundred and eighty days within Indian territory in accordance with applicable CERT-In Directions. Certain Personal Data, traffic data and processing logs may be retained for a longer period — including at least one year from the relevant processing — where required under Applicable Law, or where necessary for incident investigation, fraud prevention, security, legal process, or another lawful requirement.

50.8 Support and grievance information

Retained for resolution, audit, quality assurance, regulatory compliance, legal claims, and evidence of response.

50.9 Backups

Residual copies may remain temporarily in secure backups until overwritten, rotated, deleted under the backup schedule, or required for disaster recovery. Backup information will not be restored for active use except for authorised recovery, security or legal purposes.

51. Account Closure and Deletion

A User may request Account closure or deletion through Account settings (where available), privacy@neuramach.ai, grievance@neuramach.ai, or another communicated process. Before completing deletion, we may verify identity, confirm the request scope, process cancellation of renewal, warn about loss of access, preserve legally required information, resolve outstanding payments, preserve evidence of Consent and withdrawal, and address pending disputes.

Account deletion may result in loss of Assessment history, reports, topic classifications, recommendations, PRGNA history, uploads, goals, Subscription access, and Institute-linked features. Deletion of an Account does not necessarily delete information already lawfully shared with an Institute, independently retained by a payment provider, required for tax or accounting, required for fraud prevention, required for legal claims, temporarily retained in backups, required by law, irreversibly anonymised, or incorporated into completed model parameters in a manner that cannot reasonably identify or be linked to the User. We will not retain deleted Personal Data longer than reasonably necessary for an authorised purpose.

52. Anonymisation and De-identification

We may de-identify or anonymise information for analytics, research, product improvement, safety, model evaluation, and internal model development. De-identified information may remain Personal Data where re-identification remains reasonably possible. We will treat information as irreversibly anonymised only where it cannot reasonably identify or be linked to an individual using reasonably available means. We will not intentionally attempt to re-identify information represented as irreversibly anonymised. Where a re-identification risk is discovered, we may restrict the dataset, apply additional transformations, delete the dataset, reclassify it as Personal Data, or take other appropriate measures.

J. SECURITY AND PERSONAL DATA BREACHES

53. Security Measures

We use reasonable technical and organisational safeguards appropriate to the nature of the Personal Data and relevant risks. Measures may include encryption in transit, encryption at rest where appropriate, password hashing, obfuscation or masking, access controls, role-based permissions, multi-factor authentication for selected administrative functions, secure development practices, logging and monitoring, malware scanning, network protections, vendor security review, backup controls, incident-response procedures, staff confidentiality obligations, least-privilege access, vulnerability management, data minimisation, retention controls, consent-status controls, dataset-separation controls, provider-configuration reviews, and periodic security assessment.

No online system is completely secure. Users should use strong and unique passwords, protect verification codes, avoid Account sharing, use updated devices and browsers, sign out from shared devices, review unusual Account activity, and report suspicious activity promptly. ScoreVedaa will not ask a User to provide a full password, CVV, UPI PIN or payment PIN through an unsolicited message.

54. Personal Data Breach Response

A Personal Data breach may include unauthorised access, disclosure, acquisition, alteration, loss, destruction, transmission, or processing of Personal Data. Where a suspected breach occurs, we may contain the incident, secure affected systems, investigate the scope and cause, preserve evidence, engage security specialists, notify affected Service Providers, reset credentials, restrict affected features, assess likely consequences, notify affected Users where required, notify competent authorities where required, mitigate risk, prevent recurrence, and provide updates.

Where required by Applicable Law, an affected User notice may include a description of the breach, its nature and timing, the categories of information affected, consequences relevant to the User, measures taken or being taken, safety measures the User may take, contact information, and further updates. Where the applicable DPDP breach-notification provisions are in force, we will notify each affected Data Principal without delay, notify the Data Protection Board without delay and provide the prescribed updated and detailed information to the Board within seventy-two hours of becoming aware of the breach, unless the Board permits a longer period. Suspected security incidents should be reported to: support@neuramach.ai or privacy@neuramach.ai.

54A. CERT-In Reporting Obligations

Independent of the Personal Data Breach framework in Section 54, the Company is subject to the Cyber Security Directions issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B(6) of the Information Technology Act, 2000. Where an event falling within the categories specified in those Directions occurs — including unauthorised access, data breach, data leak, identity theft, or an attack on the Company's servers, applications or cloud infrastructure — the Company will report the incident to CERT-In within six hours of noticing it or being made aware of it, in the form and manner prescribed by CERT-In from time to time.

In accordance with the CERT-In Directions, the Company maintains relevant ICT system logs for a rolling period of one hundred and eighty days, stored within Indian territory, and synchronises relevant system clocks with the Network Time Protocol servers maintained by the National Informatics Centre or the National Physical Laboratory. These measures operate in addition to, and do not replace, the security safeguards and retention principles described elsewhere in this Privacy Policy.

Reporting to CERT-In is a distinct process from, and does not substitute, the Company's notification obligations to affected Data Principals or the Data Protection Board under Section 54.

K. USER RIGHTS AND REQUESTS

55. Rights Overview

Subject to commencement, applicability, verification and exceptions under Applicable Law, a Data Principal may have the right to obtain information about processing, access a summary of Personal Data, obtain information about recipients or Data Processors, correct inaccurate or misleading Personal Data, complete incomplete Personal Data, update outdated Personal Data, request erasure, withdraw Consent, submit a grievance, nominate another individual to exercise rights in specified circumstances, and exercise other rights provided by Applicable Law.

Rights may be subject to identity verification, legal exceptions, fraud-prevention requirements, rights of other persons, security considerations, retention obligations, legal claims, technical limitations relating to irreversible anonymisation, and commencement and applicability of the relevant legal provisions. We will not unlawfully discriminate against a User for exercising a privacy right.

If your grievance is not resolved satisfactorily through our process, or the response period lapses, you may lodge a complaint with the Data Protection Board of India in the manner it prescribes.

56. Exercising Privacy Rights

A rights request may be submitted through Account settings (where available), a designated rights-request interface, privacy@neuramach.ai, or grievance@neuramach.ai. A request should include sufficient information to identify the User, the Account, the requested right, the relevant information, the time period, supporting documents where reasonably required, and authority to act for another individual where applicable. We may request reasonable verification to protect the User, prevent unauthorised disclosure, prevent fraudulent deletion, confirm Account ownership, and identify relevant records. We will seek to collect only verification information reasonably necessary for the request. Responses concerning the exercise of Data Principal rights will include the business contact information of the person authorised to answer questions about the processing of Personal Data.

57. Access and Processing Information

Subject to Applicable Law, a User may request a summary of Personal Data being processed, a summary of processing activities, the purposes of processing, the categories or identities of recipients where required, available information about rights, and available grievance mechanisms. A response may exclude or limit information where disclosure would reveal another person’s Personal Data, compromise security, reveal protected confidential information, prejudice fraud prevention, violate law, interfere with legal proceedings, or exceed the scope of the applicable statutory right.

58. Correction, Completion and Updating

Users may request correction, completion or updating of Personal Data that is inaccurate, misleading, incomplete, or outdated. Certain Account fields may be updated directly. For other information, we may request identification of the relevant data, the proposed correction, supporting evidence, Account verification, and proof of authority where acting for another person.

We may decline or limit a correction where the requested change is unsupported, the information is an objective historical record, the change would affect another person’s rights, retention of the original record is legally required, or fraud or manipulation is reasonably suspected. Where appropriate, we may preserve an audit record of the original transaction while displaying the corrected value. A disagreement with an educational analysis does not necessarily mean the underlying Personal Data is inaccurate. A User may instead report an analytical error, request reassessment, complete further Assessments, or challenge an integrity flag.

59. Erasure

Subject to Applicable Law, a User may request erasure of Personal Data where the specified purpose has ended, Consent has been withdrawn, retention is no longer necessary, processing is unlawful, or another applicable ground exists. Erasure may be refused, delayed or limited where retention is reasonably necessary for compliance with law, tax or accounting, security, fraud prevention, legal claims, dispute resolution, enforcement, rights of other persons, consent evidence, backup cycles, or another lawful purpose. An erasure request does not require removal of information that has been genuinely and irreversibly anonymised.

60. Withdrawal of Consent

Where processing is based on Consent, a User may withdraw it with comparable ease to the method used to provide it. Withdrawal may be available through Account settings, Privacy and AI settings, Cookie preferences, communication preferences, a consent-management interface, privacy@neuramach.ai, or another communicated method. Withdrawal may affect a feature where the relevant Personal Data is necessary for that feature.

Withdrawal does not affect prior lawful processing, automatically require deletion of legally retained records, cancel payments already due, remove information independently held by an Institute or payment provider, reverse completed lawful processing, or require removal from genuinely anonymised information. Internal Training Consent withdrawal is governed by Section 31. Provider-side Consent withdrawal will be governed by the applicable Provider Training Notice.

61. Nomination

Subject to Applicable Law and available Platform functionality, a User may nominate one or more individuals to exercise applicable rights in the event of death, incapacity, or another legally recognised circumstance. We may require the nominee’s identity, the User’s identifier, evidence of nomination, evidence that the relevant circumstance has occurred, and other information reasonably required under Applicable Law. A nomination does not automatically give the nominee access during the User’s lifetime or while the User remains capable of exercising rights.

62. Duties of Users

Users should provide accurate and authentic information, avoid impersonation, avoid suppressing material information, avoid filing knowingly false or frivolous complaints, avoid requesting correction of information they know is false, protect Account credentials, and comply with Applicable Law. Nothing in this Section limits a good-faith privacy complaint or rights request.

L. GRIEVANCE REDRESSAL

63. Privacy Grievances

Privacy grievances may be submitted to:

Grievance Officer: Mr. Saurabh Sachdeo

Designation: Grievance Officer - Legal and Compliance

Company: NEURAMACH AI STUDIO PRIVATE LIMITED

Email: grievance@neuramach.ai

Phone: +91-8223815327

Address: 3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India.

A grievance should include Name, registered contact information, Account identifier, description of the issue, relevant dates, supporting evidence, and requested resolution.

For privacy and consumer grievances not governed by a shorter statutory requirement, we will acknowledge the grievance within forty-eight hours and resolve it within one month of receipt, subject to Applicable Law. Where Applicable Law requires a shorter period, the shorter period will apply.

Where additional information is reasonably required, we may request it from the complainant. Where a matter cannot be resolved within the stated period because of exceptional complexity or a legal dependency, we may provide the current status, the reason for delay, any additional information required, and an expected completion date, without limiting any mandatory deadline. Urgent matters involving unauthorised Account access, serious Personal Data exposure, payment fraud, active security threats, or misuse of identity information will be prioritised according to severity. A Data Principal should use ScoreVedaa’s grievance mechanism before approaching the Data Protection Board where Applicable Law requires prior exhaustion of the internal grievance process. Content-removal and intermediary complaints may be governed by separate timelines stated in the Terms and Conditions.

If your grievance is not resolved satisfactorily through our process, or the response period lapses, you may lodge a complaint with the Data Protection Board of India in the manner it prescribes.

M. AUTOMATED ANALYSIS AND HIGH-IMPACT USES

64. Automated Analysis and Profiling

ScoreVedaa may use automated processing to analyse Assessment performance, identify patterns, classify topics, estimate Difficulty Coverage, suggest root causes, recommend next actions, prioritise preparation, generate explanations, detect anomalies, produce readiness indicators, and support Account security. Such processing may constitute profiling where Applicable Law applies that term.

Automated processing is intended primarily for educational support, service delivery or security; may produce provisional or inaccurate results; may be influenced by incomplete information; does not determine admission; does not determine employment; does not create an official CAT result; does not determine lending, insurance or Government benefits; and should not be used as the sole basis for punitive or exclusionary action.

Users may report inaccuracies, complete further Assessments, change goals, reject recommendations, challenge an integrity flag, or request review through support. Where a material Account restriction is based substantially on an automated security or integrity signal, we may conduct reasonable review before permanent action, except where immediate restriction is necessary to protect Users or the Platform.

N. THIRD-PARTY SERVICES AND UNDERAGE DATA

65. Third-Party Links and Independent Services

The Platform may include links to or integrations with Third-Party Services. A third party may independently collect or process Personal Data when a User visits its website, uses its service, completes a payment, signs in through its authentication service, uses an external integration, or voluntarily provides information to that third party. ScoreVedaa is not responsible for independent processing by a third party outside ScoreVedaa’s instructions and control. Users should review the third party’s applicable terms and privacy notice.

66. Information Relating to Individuals Below Eighteen

ScoreVedaa CAT does not accept individuals below eighteen years of age as registered or interactive Users. We do not knowingly invite an individual below eighteen to create an Account, use PRGNA, take an Assessment, purchase a Subscription, or participate in model-improvement programmes.

If we reasonably determine that Personal Data relating to an individual below eighteen has been submitted contrary to the Terms, we will promptly restrict the relevant Account or processing and will delete, securely isolate or otherwise handle the information in accordance with Applicable Law, subject to reasonable verification and any lawful security, fraud-prevention, evidence-preservation or retention requirement.

An Institute must not provide a minor Student roster for ScoreVedaa CAT. An Adult should not upload a minor’s Personal Data into PRGNA, User uploads, support channels, Institute tools, or model-improvement programmes without lawful authority and a valid purpose. This Section does not prevent limited processing of technical information arising from a public webpage request as described in Section 4.

O. CHANGES AND CONTACT DETAILS

67. Changes to this Privacy Policy

We may update this Privacy Policy to reflect legal changes, new Services, new processing activities, vendor changes, security improvements, Institute-feature changes, AI-feature changes, model-development changes, organisational changes, or clarifications. The updated Privacy Policy will display a revised version number, an effective date, and a last-updated date.

For material changes involving new categories of identifiable Personal Data, new processing purposes, material Institute access, internal identifiable-data model development, provider-side model training, historical-data use, cross-product model development, human review, international processing, material changes to rights, material changes to withdrawal, or new types of disclosure, we will provide prominent advance notice and obtain renewed Consent where required by Applicable Law. A policy update, continued use, silence or failure to opt out will not constitute new Training Consent where separate affirmative Consent is required. Non-material clarifications may take effect upon publication. Earlier versions may be retained for compliance, evidence and dispute-resolution purposes.

68. Contact Information

For privacy questions, rights requests or concerns, contact:

Legal Entity: NEURAMACH AI STUDIO PRIVATE LIMITED

Brand: NeuraMach.ai

Product: ScoreVedaa CAT

CIN: U62099PN2025PTC245340

Website: scorevedaa.in

Registered Office: Flat No. 201, Building 1, Wing 3, The Crown Greens, Plot 17, Infotech Park, Hinjawadi, Pune, Maharashtra 411057, India.

Principal Business and Correspondence Office: 3rd Floor, Cabin No. 7, Quick Office, 301, 45 Baner Road, above Atithi Restaurant, Veerbhadra Nagar, Baner, Pune, Maharashtra 411045, India.

Privacy Email: privacy@neuramach.ai

Grievance Email: grievance@neuramach.ai

Support Email: support@neuramach.ai

Legal Email: legal@neuramach.ai

Telephone: +91-8223815327

Grievance Officer

Name: Mr. Saurabh Sachdeo

Designation: Grievance Officer - Legal and Compliance

Email: grievance@neuramach.ai

Phone: +91-8223815327

Annex A — Recipients and Cross-Border Processing

Last updated: July 24, 2026

We share Personal Data only with the recipients listed below. Each recipient acts under a written contract requiring it to process Personal Data solely on our documented instructions, to implement reasonable security safeguards, and not to use Private User Content or identifiable Performance Data for its own model training or unrelated purposes. This Annex is reviewed and updated whenever recipients materially change.

RecipientFunction / CategoryData categories sharedProcessing location
Amazon Web Services (AWS)Cloud hosting; AI inference (Amazon Bedrock)Account data, prompts and conversations, assessment and performance dataIndia (ap-south-1) / United States (us-east-1) / EU (eu-central-1)
CohereAI reranking / retrieval relevanceQuery text derived from user inputUnited States (Global API)
TavilySearch / retrieval infrastructureQuery text derived from user inputUnited States
SentryError monitoring and diagnosticsTechnical / diagnostic dataUnited States
RazorpayPayment processingTransaction details (no full card numbers)India
AWS SES (Simple Email Service)Operational communicationsName, email address, mobile numberIndia (ap-south-1)
Qdrant Cloud (via AWS)Vector database for retrieval and analyticsEmbeddings and vectorised user contentEU (eu-central-1, Frankfurt)
Zhipu AI (GLM)OCR (Optical Character Recognition)Uploaded images and documents for text extractionChina (Global API)
HuggingFace (OpenAI CLIP)Vision-text embeddingImage and text data for embedding generationUnited States (Global API)

Where a recipient is located outside India, the transfer is permitted under the framework of Section 16 of the DPDP Act (which permits transfer to all destinations not specifically restricted by Central Government notification) and is subject to the contractual and security safeguards described in this Policy.