CampusPlugin Technologies Private Limited (“CampusPlugin”, “we”, “us”, “our”) operates CampusPlugin 360, India’s campus-to-career operating system. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you access our services as a Data Principal under the Digital Personal Data Protection Act 2023 (DPDPA).
1. Who we are
CampusPlugin acts as a Data Fiduciary for personal data that students, institution staff, employer staff, and government/CSR users provide when using our platform. For data we process on behalf of an institution (e.g., a student record an institution uploads), CampusPlugin acts as a Data Processor under instruction from that institution.
2. Data we collect
2.1 From students
- Identity: name, date of birth, gender (optional), APAAR ID (optional)
- Contact: email, phone, address (for offer logistics)
- Academic: institution, course, semester, marks, ABC credits, certifications
- Career: resume, skills, assessments, application history, offers
- Consent: per-scope consent records with timestamps
- Optional sensitive data: disability status, financial-aid status (only with explicit consent under DPDPA section 9)
2.2 From institution staff
- Identity: name, employee ID, role (TPO / coordinator / faculty / admin)
- Contact: institutional email, phone
- Activity: drives created, students managed, audit-log entries
2.3 From employer staff
- Identity: name, role at employer, employer GST + CIN
- Contact: work email, phone
- Activity: drives posted, shortlists, offers, hires
2.4 Automatically collected
- Device: browser, OS, screen resolution, anonymised IP (truncated)
- Usage: pages visited, features used, error reports
- Consent: which cookies you accepted (see Cookie Policy)
3. How we use your data
We process personal data for specific, declared purposes only:
- To deliver the service you signed up for (students: career wallet + applications; employers: hiring; institutions: placement management)
- To verify identity and institution affiliation
- To generate accreditation and compliance reports (NAAC, AICTE, UGC, NIRF, MCA-21) that your institution or employer requires
- To detect and prevent fraud (ghost employers, sybil accounts, account takeover)
- To send transactional notifications (application updates, offer alerts) and, with consent, the monthly digest
- To respond to your queries and provide support
4. Legal basis for processing (DPDPA section 6 + 7)
- Consent (section 6)— default basis. Specific, informed, unambiguous, freely given. Revocable at any time via your profile settings.
- Legitimate use (section 7)— carve-outs for: providing the service the Data Principal signed up for; legal-compliance obligations; transparent service-metrics analytics that do not identify individuals.
- Employment context— for institution-staff and employer-staff users acting within their professional role.
5. Multi-tenant data isolation
CampusPlugin 360 is multi-tenant. Every institution and employer is a separate tenant. Personal data tagged to one tenant is invisible to any other tenant. This isolation is enforced at three layers:
- Application layer— every API endpoint enforces tenant context from your authentication token.
- Service layer — every database query is scoped by
tenant_id. - Database layer— PostgreSQL Row-Level Security (RLS) policies deny-by-default on every table that contains personal data.
6. Data sharing
We share personal data only in these circumstances:
- With your institution— if you are a student, your institution sees your academic + placement records by default. You can revoke consent for marketing-style data sharing under Settings → Privacy.
- With employers you apply to— your profile becomes employer-visible only after you apply or your institution shortlists you. You see and can revoke who sees what.
- With regulators— accreditation bodies (NAAC, AICTE, UGC) receive aggregated and de-identified reports. Per-student data is shared only under your institution’s direction.
- With service providers— Razorpay (payments), Supabase (hosting), Bhashini (translation), etc. All providers are India-resident or have a Data Processing Agreement signed.
- For legal compliance— in response to a valid legal order from an Indian court or regulator.
We do not sell personal data, use it for third-party advertising, or share it with social-media platforms.
7. Data residency
All personal data is stored on infrastructure located in India (AWS ap-south-1, Mumbai). Backups, disaster-recovery replicas, and read replicas all remain within India.
8. Security measures
- TLS 1.3 in transit for all connections
- AES-256-GCM at rest for personal data
- RLS at the database layer (multi-tenant isolation)
- Role-based access control with least-privilege defaults
- MFA mandatory for admin and TPO accounts
- Quarterly penetration tests; bug-bounty programme open to external researchers
- SIEM-fed audit logs (immutable, append-only)
9. Data retention
- Active student record: retained while you maintain an account + 3 years after the institution closes the placement cycle (for NAAC audit windows)
- Application + offer history: retained for 7 years (regulatory requirement)
- Audit logs: retained for 7 years (incident-response + DPDPA section 8 evidence)
- Marketing consent + digest subscribers: retained until you unsubscribe
- Backups: rolling 30-day window; older backups are cryptographically destroyed
After retention windows expire, personal data is anonymised or deleted.
10. Your rights as a Data Principal (DPDPA section 12–14)
- Right to access— you can request a copy of all personal data we hold about you. We respond within 30 calendar days.
- Right to correction + completion— you can update or correct any personal data via your profile, or by writing to us.
- Right to erasure— you can request deletion. We delete (or anonymise) within 30 calendar days, subject to retention windows above.
- Right to nominate— you can nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to grievance redressal— if we don’t respond satisfactorily, you can escalate to the Data Protection Board of India under DPDPA section 13.
11. Children’s data (DPDPA section 9)
We do not knowingly process personal data of users under 18 without verifiable parental consent. For students under 18 onboarded by their institution, the institution captures parental consent at the onboarding step.
12. Personal data breach (DPDPA section 8)
In the event of a personal-data breach, we will notify the Data Protection Board of India within 72 hours of becoming aware. Affected Data Principals will be notified via the email on file with details of: what happened, what data was affected, what we did about it, and what you can do.
13. Data Protection Officer (DPDPA section 10)
CampusPlugin has a designated India-based Data Protection Officer (DPO). Contact:
14. Changes to this policy
Material changes are notified via email to active accounts and via the commit history of this document. The effective date at the top is updated on every revision.
15. Contact