Privacy Policy

Effective Date: July 1, 2025

We believe privacy is a right, not a privilege. This policy explains exactly what data we collect, why we collect it, and how we protect it — in plain language.

Summary

  • ✓Your data is stored in India (AWS Mumbai).
  • ✓We never sell your personal data to third parties.
  • ✓We comply with India's DPDP Act, 2023 and IT Act, 2000.
  • ✓Students under 18 are protected with enhanced safeguards.
  • ✓You can request access, correction, or deletion of your data at any time.

1. Introduction

Aykan AI Private Limited ("MyLaksh", "we", "our", or "us") is committed to protecting the privacy and personal data of our users — students, parents, and coaching institute partners — in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the MyLaksh platform, including our mobile application, web application (mylaksh.com), and related services (collectively, the "Platform").

By registering on or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Platform immediately.

2. Personal Data We Collect

We collect the following categories of personal data:

a) Identity & Contact Data - Full name, date of birth, gender - Mobile number and email address - Profile photograph (optional) - City, state, and PIN code

b) Academic Data - Current class / standard (e.g., Class 11, Class 12, Dropper) - Target competitive examination (JEE Main, JEE Advanced, NEET UG, etc.) - Target year of examination - Coaching institute name and city (if applicable) - Performance data: test scores, chapter-wise accuracy, time-on-task, rankings

c) Device & Technical Data - Device model, operating system version, unique device identifiers - IP address, browser type, and language - App usage logs, crash reports, and diagnostic data - Firebase Cloud Messaging (FCM) token for push notifications

d) Payment Data - Transaction ID and payment status - UPI VPA or masked card details (processed securely via PCI-DSS compliant payment gateways; full card numbers are never stored by us)

e) User-Generated Content - Doubts, questions, and messages submitted on the Platform - Responses to quizzes, mock tests, and practice sessions

f) Sensitive Personal Data or Information (SPDI) To the extent applicable under the SPDI Rules, we treat academic performance data and financial payment data with enhanced protection. We do not collect passwords in plaintext, biometric data, or health records.

3. How We Collect Data

We collect personal data through:

  • —Direct submission — when you register, complete your profile, attempt a test, or contact support
  • —Automated collection — through cookies, SDKs (Firebase Analytics, Crashlytics), and server logs as you interact with the Platform
  • —Third-party sign-in — if you choose to log in via Google or other OAuth providers, we receive your name, email, and profile picture from that provider in accordance with your permissions
  • —Coaching institute partners — if your institute has enrolled you on the Platform, your basic academic details may be shared with us by the institute administrator

4. Purpose of Processing

We process your personal data for the following purposes:

PurposeLawful Basis
Creating and managing your accountPerformance of contract
Providing personalised AI-driven test recommendationsLegitimate interest / contract
Generating chapter-wise analytics and rank cardsContract / legitimate interest
Sending exam reminders and result notificationsConsent (push/SMS/email opt-in)
Processing subscription paymentsContract / legal obligation
Improving Platform features and fixing bugsLegitimate interest
Fraud detection and platform securityLegal obligation / legitimate interest
Responding to grievances and support requestsLegal obligation
Compliance with court orders or regulatory requirementsLegal obligation

We will not use your data for purposes incompatible with those listed above without obtaining fresh consent.

5. Data of Minors

The Platform is primarily used by students who may be below 18 years of age. In compliance with the DPDP Act, 2023:

  • —We obtain verifiable parental or guardian consent before processing personal data of children under 18 years.
  • —We do not process data of children under 13 years without explicit, verifiable parental consent.
  • —We do not serve behavioural advertising to minors.
  • —We do not track minors' location or create profiles that can harm their wellbeing.

If we become aware that we have inadvertently collected data from a child under 13 without consent, we will delete such data promptly. Parents may contact us at coreteam@mylaksh.com to review or request deletion of their child's data.

6. Data Sharing & Disclosure

We do not sell your personal data. We may share data in the following circumstances:

a) Coaching Institute Partners If you are enrolled through a coaching institute, the institute administrator may view your performance reports (test scores, attendance, rankings) solely to support your preparation. The institute is contractually bound to use this data only for educational purposes.

b) Service Providers (Data Processors) We engage trusted third-party vendors who process data strictly on our instructions: - Cloud infrastructure: Amazon Web Services (Mumbai region) - Push notifications: Firebase / Google Cloud Messaging - Payment processing: Razorpay / PayU (PCI-DSS compliant) - Analytics: Firebase Analytics, Mixpanel - Communication: Twilio (OTP / SMS)

c) Legal Disclosure We may disclose data when required by law, court order, or governmental authority, including under the IT Act, Income Tax Act, or DPDP Act. We will notify you unless prohibited by law.

d) Business Transfers In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity, subject to the same privacy protections.

e) Consent-Based Sharing We will share data with any other third party only with your explicit consent.

7. Data Storage & Localisation

All personal data of Indian users is stored on servers located within India (AWS ap-south-1, Mumbai). We do not transfer personal data outside India except to the extent permitted under the DPDP Act and applicable regulations, and only after ensuring adequate safeguards (such as standard contractual clauses) are in place.

Backups and disaster-recovery replicas are maintained within India.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Specific retention periods:

  • —Account data — Retained while your account is active, and for 3 years after account deletion (for audit and legal compliance purposes)
  • —Test & performance data — Retained for the duration of account activity plus 2 years
  • —Payment records — Retained for 8 years as required under applicable financial regulations
  • —Support and grievance records — Retained for 3 years after resolution

After the retention period expires, data is securely deleted or anonymised.

9. Cookies & Tracking Technologies

We use the following types of cookies and similar technologies on our web platform:

  • —Strictly necessary cookies — Required for authentication, session management, and security. Cannot be disabled.
  • —Analytics cookies — Help us understand usage patterns (e.g., Google Analytics, Mixpanel). You may opt out via your browser settings.
  • —Preference cookies — Remember your language or display preferences.

We do not use third-party advertising or retargeting cookies. You can manage cookie preferences through your browser settings; however, disabling strictly necessary cookies may affect Platform functionality.

10. Data Security

We implement reasonable security practices as mandated by the SPDI Rules and DPDP Act, including:

  • —TLS 1.2+ encryption for all data in transit
  • —AES-256 encryption for sensitive data at rest
  • —Role-based access controls (RBAC) for internal systems
  • —Regular security audits and vulnerability assessments
  • —Two-factor authentication (2FA) for admin accounts
  • —Incident response procedures aligned with CERT-In guidelines

In the event of a personal data breach that is likely to result in a risk to your rights or freedoms, we will notify you and the relevant authority in accordance with the DPDP Act.

11. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023, you have the following rights:

a) Right to Access — You may request a summary of the personal data we hold about you and the purposes for which it is processed.

b) Right to Correction & Erasure — You may request correction of inaccurate data or erasure of data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.

c) Right to Grievance Redressal — You have the right to have grievances addressed in a timely manner (see Section 13).

d) Right to Nominate — You may nominate another individual to exercise your rights on your behalf in the event of death or incapacity.

e) Right to Withdraw Consent — Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

To exercise any of the above rights, please write to us at coreteam@mylaksh.com with your registered mobile number or email address. We will respond within 30 days of receiving your request.

13. Grievance Redressal

In accordance with the IT Act, 2000 and DPDP Act, 2023, we have appointed a Grievance Officer to address any complaints or concerns regarding your personal data:

Grievance Officer, Aykan AI Private Limited Email: grievance@mylaksh.com Address: [Registered office address, India] Response time: Within 30 days of receipt of grievance

If you are not satisfied with our response, you may approach the Data Protection Board of India (once constituted under the DPDP Act) or a competent court having jurisdiction.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our services. Material changes will be notified via: - In-app notification - Email to your registered address - Prominent notice on our website

The updated policy will be effective from the date indicated at the top. Continued use of the Platform after the effective date constitutes acceptance of the revised policy.

15. Governing Law & Jurisdiction

This Privacy Policy is governed by the laws of the Republic of India, including the DPDP Act, 2023, the IT Act, 2000, and the SPDI Rules, 2011. Any disputes arising out of this Policy shall be subject to the exclusive jurisdiction of the courts located in [City where registered office is located], India.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Aykan AI Private Limited Email: coreteam@mylaksh.com Website: https://mylaksh.com

This Privacy Policy was last updated on July 1, 2025. Previous versions are available upon request.