Skip to content
PortKeysAI

Legal

Privacy Policy

How Quadora AI Technologies, Inc. collects, uses, and protects your information.

Effective date: July 2026. This policy is written in plain language and reflects our actual practices as an early-stage company. It will be reviewed by counsel and may be updated; the current version is always published at this address.

Who we are

Quadora AI Technologies, Inc. is a Delaware C-Corporation with delivery operations in India. We operate this website, an advisory practice for universities and students, and an online assessment platform. Because we serve students in India, we act as a “Data Fiduciary” under India's Digital Personal Data Protection Act, 2023 (DPDP Act) for the personal data we process. For privacy questions, use the contact form on this site or contact our Grievance Officer via the Grievance Redressal page.

What we collect

Inquiries and registrations. When you submit a contact form, newsletter subscription, or event registration, we collect what you enter: name, email address, organization, role, country, and your message.

Accounts. If you create a student portal account, we collect your email address and the profile information you choose to provide.

Assessment attempts. When you take a PortKeysAI assessment, we store your answers, scores, and completion times so we can show you results and benchmark performance.

We do not collect payment card details on this site, and we do not run advertising trackers.

Why we use it

We use this information to respond to inquiries, deliver advisory and assessment services, confirm event places, send newsletter content you subscribed to, and improve our assessments. We do not use your data for purposes unrelated to the service you asked for.

Where it is stored

Data submitted through this site is stored in Supabase, our hosted database provider, with access restricted by row-level security and limited to PortKeysAI personnel who need it to serve you.

No sale of data

We do not sell, rent, or trade your personal information. We do not share student data with universities or third parties except where you explicitly ask us to — for example, submitting an application on your behalf.

Cookies

We keep cookies to a minimum. The only cookies this site sets are those required for authentication when you sign in to the student portal. There are no advertising or cross-site tracking cookies.

Retention and deletion

We retain data only for as long as needed to provide the service or as required by law, in keeping with the storage-limitation principle of India's Digital Personal Data Protection Act, 2023 (DPDP Act). We do not keep personal data indefinitely. The schedule below sets out the maximum retention period for each category of data. Deletion is not manual: it is enforced automatically by a scheduled job that runs regularly (currently daily) and permanently removes records — and, for webcam frames, the underlying stored files — once they pass their retention window.

Data category Retention period Enforcement
Webcam proctoring frames (images captured during proctored assessments) 90 days Auto-deleted on schedule, including the stored image files
Behavioural proctoring events (tab switches, focus changes, and similar signals) 180 days Auto-deleted on schedule
Inquiry / lead records that did not convert to an account or engagement 24 months Auto-deleted on schedule
Abandoned assessment attempts (started but never completed or scored) 12 months Auto-deleted on schedule
Unverified consent records (for example, a guardian-consent request that was never granted) 12 months Auto-deleted on schedule

Completed account and assessment data is retained while your account is active so we can show you your results, and is deleted on request as described below or when no longer required. You may request a copy of your data or its deletion at any time; we will confirm completion by email. Deletion requests are honoured except where a legal obligation requires us to retain specific records.

Your rights as a Data Principal (DPDP Act)

If your personal data is processed by us, the DPDP Act gives you the following rights as a “Data Principal.” We honour these rights regardless of where you are located:

  • Right to access. You can ask for a summary of the personal data we hold about you and how we are processing it, and with whom it has been shared.
  • Right to correction and completion. You can ask us to correct inaccurate or misleading data, complete incomplete data, and update out-of-date data.
  • Right to erasure. You can ask us to delete your personal data, and we will do so unless retention is required to comply with a law or for the purpose you provided it.
  • Right to grievance redressal. You can raise any concern about how we handle your data through our Grievance Officer, who is required to respond within the timeline set out on our Grievance Redressal page.
  • Right to nominate. You can nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Contact us to record a nomination.
  • Right to withdraw consent. Where we rely on your consent, you can withdraw it at any time; withdrawal is as easy as giving consent and does not affect processing already carried out.

How to exercise your rights

To exercise any of the rights above, use the contact form or write to our Grievance Officer via the Grievance Redressal page. Tell us which right you want to exercise and enough detail for us to locate your data. We may ask you to verify your identity before we act, to protect your data from unauthorised requests. If you are not satisfied with our response, you may escalate to the Data Protection Board of India, as explained on the Grievance Redressal page.

Children's data

We treat anyone under the age of 18 as a child under the DPDP Act. Before we process a child's personal data, we obtain verifiable consent from a parent or lawful guardian through our guardian consent flow. In line with the DPDP Act, we do not carry out behavioural monitoring of children for advertising purposes, we do not serve targeted advertising to children, and we do not undertake processing that is likely to cause a detrimental effect on a child's well-being. A parent or guardian can withdraw consent or request deletion of a child's data at any time through the Grievance Officer.

Data-breach commitment

We maintain an internal breach-response procedure. In the event of a personal data breach, we are committed to notifying the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP Act and its rules, and — for incidents within its scope — to reporting to CERT-In within the applicable timeline (currently six hours for specified cyber-security incidents). Notifications will describe the nature of the breach, its likely consequences, and the steps we are taking and that you can take to reduce risk.

Governing law

This policy is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles.

Changes

We will post any changes on this page with a revised effective date. Material changes affecting account holders will be notified by email.

Questions or requests: contact us.