Legal

Privacy Policy

Effective Date:27 August 2026Last Updated:27 August 2026

Epoch Olympiad Foundation Pvt. Ltd. and its associated initiatives, including Epoch Olympiad, Brainiac Global and MY CCBee ("we", "us", "our" or "Foundation") respect your privacy and are committed to protecting personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal data when you:

Our objective is to process personal data responsibly, transparently and only for legitimate educational, administrative, operational and related purposes.

This Policy applies when you

  • visit our website;
  • register a school;
  • participate in our Olympiads or Brain Booster examinations;
  • access the Genie App or other digital platforms;
  • use MY CCBee;
  • request information or support;
  • communicate with us;
  • participate in our programmes, surveys, events or initiatives; or
  • otherwise interact with our services.
1.

About Us

Data Fiduciary / Organisation
EPOCH OLYMPIAD FOUNDATION PVT. LTD.
Brand / Initiative
Epoch Olympiad Foundation and its initiatives
Registered Office
Plot No. 666 A Kalyanpur Bithoor Road, Kanpur (U.P.)

For privacy-related requests, please contact:

Privacy Contact / Grievance Contact

Name
Mrs. Deepmala Gupto
Postal Address
Plot No. 666 A Kalyanpur Bithoor Road, Kanpur (U.P.), Pincode - 208017
2.

Our Commitment to Privacy

We believe that educational technology should strengthen learning without compromising privacy.

We therefore follow the principles of:

Purpose LimitationData MinimisationTransparencySecurityAccuracyAccountabilityResponsible Retention

We collect only information reasonably required for the purposes explained in this Policy and seek appropriate consent wherever required by applicable law.

3.

Whose Personal Data May We Collect?

Depending on the service being used, we may process information relating to:

A. Parents / Guardians

For example:

  • name;
  • mobile number;
  • email address;
  • relationship with the child;
  • communication preferences;
  • consent records.

B. Students / Children

Where required for educational participation or reporting:

  • student's name;
  • class / grade;
  • age or date of birth;
  • school;
  • academic identifiers;
  • examination details;
  • responses and assessment results;
  • performance indicators;
  • Academic Health Report information;
  • participation and award information.

C. School Representatives

For example:

  • principal's name;
  • teacher's name;
  • coordinator's name;
  • designation;
  • school name;
  • official contact details;
  • school address;
  • communication records.

D. Advisors, Educators and Professionals

We may collect:

  • name;
  • designation;
  • organisation;
  • professional biography;
  • professional photograph;
  • contact information;
  • LinkedIn or other professional profile;
  • information supplied in an Expression of Interest.

E. Website Visitors

We may automatically receive limited technical information such as:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • approximate location derived from technical information;
  • pages visited;
  • referring page;
  • access times;
  • cookies and similar technologies.
4.

Children's Personal Data

We recognise that children's data requires enhanced protection.

Where applicable, we will:

  • obtain appropriate consent from a parent or lawful guardian;
  • use children's information only for specified and legitimate educational or service-related purposes;
  • avoid unnecessary collection of children's information;
  • implement appropriate security safeguards;
  • avoid using children's personal data for unrelated commercial purposes;
  • restrict access to authorised personnel and service providers;
  • maintain appropriate records of consent where required.

We will not knowingly permit children's personal data to be used for targeted advertising or behavioural profiling for advertising purposes.

Where applicable law requires additional safeguards for children's data, we will follow those requirements.

The DPDP framework contains specific protections for children, including requirements relating to parental consent and restrictions on certain processing involving children.

5.

Information We Collect

We may collect information through:

Information You Provide Directly

For example, when you:

  • submit a School Registration Form;
  • register for an examination;
  • complete a parent consent form;
  • request a demo;
  • contact us;
  • submit an Expression of Interest for the Advisory Board;
  • participate in surveys;
  • communicate through email, telephone or other channels.

Information Provided by Schools

A school may provide student, teacher or parent information to us for purposes such as:

  • examination registration;
  • assessment administration;
  • results;
  • Academic Health Reports;
  • school-level analytics;
  • awards and recognition;
  • platform services.

Where a school provides personal data on behalf of parents/guardians, the school is responsible for obtaining any consent or authorisation required from the relevant individuals, unless otherwise agreed or required by law.

6.

How We Use Personal Data

We may process personal data for the following purposes:

Educational Services

  • registering students;
  • conducting examinations;
  • evaluating responses;
  • generating results;
  • generating Academic Health Reports;
  • providing learning resources;
  • providing performance insights;
  • administering awards and recognition.

School Services

  • registering schools;
  • communicating with school representatives;
  • coordinating examinations;
  • providing school-level reports;
  • providing MY CCBee services;
  • providing technical and administrative support.

Genie App

Information may be processed to:

  • authenticate users;
  • provide access to educational resources;
  • display results;
  • provide Academic Health Reports;
  • provide sample papers and previous-year papers;
  • provide syllabus and marking information;
  • provide awards and scholarship information;
  • improve the functionality of the platform.

MY CCBee

Where applicable, data may be used to:

  • record school activities;
  • monitor learner participation;
  • provide performance insights;
  • track relevant educational KPIs;
  • generate reports;
  • support timely intervention and communication between school and parents.

Communication

We may use contact information to:

  • respond to enquiries;
  • provide service-related communications;
  • send examination updates;
  • provide important account information;
  • provide support;
  • communicate programme-related information.

Marketing communications will be sent in accordance with applicable law and applicable consent/preferences.

7.

Assessment and Academic Data

Our educational assessments may generate information about a student's:

  • reasoning;
  • problem-solving;
  • conceptual understanding;
  • analytical abilities;
  • learning patterns;
  • performance across assessment areas;
  • strengths and areas requiring development.

Such information is used primarily to provide educational assessment, benchmarking, reporting and improvement insights.

Academic Health Reports are intended to provide educational insights and should not be interpreted as medical, psychological, psychiatric or clinical diagnoses unless expressly stated otherwise.

10.

Sharing of Personal Data

We do not sell personal data.

We may share personal data only where reasonably necessary for legitimate purposes, including with:

Schools

Relevant student or assessment information may be shared with the participating school for educational administration, assessment and reporting.

Parents / Guardians

Relevant information about a child may be made available to an authorised parent or guardian through appropriate channels.

Technology and Service Providers

We may use trusted third-party service providers for:

  • hosting;
  • cloud storage;
  • database management;
  • authentication;
  • communications;
  • payment processing;
  • analytics;
  • technical support;
  • application infrastructure.

Such providers may process data only for authorised purposes and subject to appropriate contractual or security safeguards.

Legal / Regulatory Authorities

We may disclose information where required by:

  • applicable law;
  • court order;
  • governmental authority;
  • regulatory requirement;
  • lawful investigation.

Professional Advisors

Information may be disclosed where reasonably necessary to legal, accounting, auditing, insurance or professional advisors subject to appropriate confidentiality obligations.

11.

Third-Party Platforms

Our services may use third-party platforms or services, including, depending on the particular service:

  • Google Forms;
  • Google Analytics or similar analytics services;
  • payment gateways;
  • cloud hosting providers;
  • email/SMS/WhatsApp communication providers;
  • YouTube or other video-hosting platforms;
  • app stores;
  • authentication providers.

Their processing may be governed by their respective privacy policies.

We recommend that users review the privacy practices of third-party services before using them.

12.

Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • operate essential website functions;
  • remember preferences;
  • understand website usage;
  • improve performance;
  • maintain security;
  • measure website traffic.

Where required, non-essential cookies will be used only after obtaining appropriate consent.

Users may control cookies through their browser settings, although disabling certain cookies may affect website functionality.

13.

Data Security

We take reasonable technical and organisational measures designed to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • unauthorised disclosure;
  • misuse;
  • other unlawful processing.

Security measures may include, where appropriate:

  • access controls;
  • authentication;
  • encryption;
  • secure transmission;
  • backups;
  • logging and monitoring;
  • role-based access;
  • vendor security controls;
  • employee confidentiality obligations;
  • incident-response procedures.

The 2025 DPDP Rules specifically contemplate reasonable security safeguards including measures such as encryption, access controls, monitoring, backups and breach detection/response.

No electronic system can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security of information transmitted over the internet.

14.

Data Breach

If we become aware of a personal data breach, we will assess and respond to it in accordance with applicable law.

Depending on the nature and severity of the incident, this may include:

  • containing the incident;
  • investigating its cause;
  • restoring affected systems;
  • notifying relevant authorities where legally required;
  • notifying affected individuals where legally required;
  • taking measures to reduce potential harm;
  • implementing corrective measures.

The notified DPDP Rules provide for breach notifications to affected Data Principals and the Data Protection Board, including detailed reporting requirements within the prescribed timeframe.

15.

Data Retention

We retain personal data only for as long as reasonably necessary for:

  • providing the relevant service;
  • fulfilling the purpose for which it was collected;
  • maintaining educational and assessment records;
  • responding to disputes;
  • complying with legal, accounting or regulatory obligations;
  • protecting our legal rights;
  • maintaining legitimate business records.

When personal data is no longer required, we will securely delete, anonymise or otherwise dispose of it, subject to applicable legal or contractual retention requirements.

We will periodically review retention periods.

16.

Accuracy of Personal Data

We seek to maintain accurate and reasonably up-to-date information.

Users, parents/guardians and schools should notify us if information is inaccurate, incomplete or outdated.

Where appropriate, we will take reasonable steps to correct or update the information.

17.

Your Privacy Rights

Subject to applicable law, individuals may have rights relating to their personal data, including rights to:

  • access information about processing;
  • request correction of inaccurate information;
  • request deletion/erasure where applicable;
  • withdraw consent where consent is the basis for processing;
  • raise a grievance;
  • exercise other rights available under applicable law.

The DPDP framework expressly establishes rights for Data Principals, subject to its provisions and applicable commencement dates.

18.

Children's Rights and Parent/Guardian Requests

A parent or lawful guardian may contact us regarding personal data relating to their child.

To protect the child and prevent unauthorised disclosure, we may require reasonable verification of the identity and authority of the person making the request.

We may refuse or limit a request where permitted or required by applicable law.

19.

School Responsibilities

Where a school provides us with personal data relating to students, parents, teachers or other individuals, the school should ensure that:

  • the information provided is accurate;
  • the school has appropriate authority to provide the information;
  • required parent/guardian consent has been obtained where applicable;
  • individuals have been appropriately informed;
  • information is not provided beyond what is reasonably necessary.

Where our agreement with a school allocates particular privacy responsibilities, those contractual arrangements will also apply.

20.

International Data Transfers

Some of our technology providers may store or process information outside India.

Where personal data is transferred outside India, we will do so in accordance with applicable law and any restrictions or requirements prescribed by the Government of India or other applicable jurisdiction.

We will take reasonable steps to ensure that appropriate contractual, organisational and technical safeguards are in place.

21.

International Users

Our primary operations are based in India.

If you access our services from another country or jurisdiction, additional privacy laws may apply depending on the circumstances.

Where laws such as the EU/EEA GDPR, UK GDPR, or other applicable data-protection laws apply to our processing, we will comply with the obligations applicable to us.

This Policy does not by itself create rights under a law that does not otherwise apply to our activities.

22.

Educational Research and Analytics

As an education research foundation, we may conduct research and statistical analysis using assessment and educational data.

Where research requires identifiable personal data, we will process such data only where legally permitted and for an appropriate purpose.

Where reasonably possible, research and statistical outputs will use:

  • aggregated data;
  • anonymised data; or
  • de-identified data.

We will not publicly identify individual students in research publications or public performance analyses without appropriate authority or consent where required.

23.

Awards, Recognition and Publicity

We may publish information relating to award recipients, participating schools or educational achievements where appropriate and lawfully permitted.

For children, we will obtain appropriate consent/authorisation before publicly displaying identifiable information such as:

  • photograph;
  • full name;
  • school;
  • achievement;
  • video;
  • testimonial.

Parents/guardians may contact us regarding applicable publicity permissions.

24.

Testimonials and Photographs

Where a principal, teacher, parent, student or other individual voluntarily provides a testimonial, photograph or video for publication, we will use such material for the purposes for which permission was granted.

We will not imply an endorsement beyond the scope of the permission provided.

25.

Payments

Where payments are made through our website or services, payment information may be processed by authorised payment service providers.

We generally do not need to store complete debit-card, credit-card or banking credentials ourselves.

Payment service providers may process payment information according to their own privacy and security policies and applicable financial regulations.

27.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes in our services;
  • changes in technology;
  • changes in applicable law;
  • regulatory requirements;
  • changes in our data-processing practices.

The updated version will be published on this page with a revised “Last Updated” date.

Where required by law, we will provide additional notice or obtain consent for material changes.

28.

Grievance Redressal

If you have a privacy concern, complaint or request, please contact:

Privacy & Grievance Contact

Name
Mrs. Deepmala Gupto
Designation
Director
Postal Address
Plot No. 666 A Kalyanpur Bithoor Road, Kanpur (U.P.), Pincode - 208017

How to Raise a Request

Please include:

  1. 1Your full name;
  2. 2Registered email/mobile number;
  3. 3Nature of your request or complaint;
  4. 4Relevant student/school/account reference, where applicable;
  5. 5Supporting information, if necessary.

We may request reasonable information to verify your identity before processing the request.

We will address privacy requests and grievances within the time periods prescribed by applicable law.

30.

Governing Law

This Privacy Policy shall be interpreted in accordance with the laws applicable to the processing of personal data and the services provided by us.

For matters governed by Indian law, applicable laws of India shall apply, subject to mandatory rights and remedies available to individuals under applicable law.