Trust & Compliance Policy

Privacy Policy

Effective Date: August 30, 2026 • Attestly Technologies Inc. (attestly.in)

1. Our Core Commitment to Educational & Enterprise Privacy

Attestly Technologies ("Attestly", "we", "our", or "us") operates the cloud learning, examination proctoring, and skill attestation platform hosted at attestly.in. We serve forward-thinking universities, higher education institutions, enterprise partners, and individual learners.

We treat learner data with extreme confidentiality. We strictly comply with applicable data protection laws, including India's Digital Personal Data Protection Act (DPDPA 2023), the European Union General Data Protection Regulation (GDPR), and institutional FERPA standards.

2. Information We Collect

We collect information strictly necessary to provide authentic learning, automated code grading, proctored examinations, and cryptographic credential attestation:

  • Account Information: Full name, institutional email address, student roll number, organization identity, and authentication credentials (hashed and salted).
  • Academic & Code Telemetry: Code solutions submitted to the cloud sandbox, compiler runtime outputs, unit test execution traces, execution time, and algorithmic complexity metrics.
  • Proctored Examination Telemetry: During authorized, scheduled examination sessions utilizing the Safe Exam Browser (SEB) or proctoring engine, we record window focus events, keyboard shortcut violations, and optional consent-based webcam sampling. Proctoring is never active outside of scheduled exam sessions.
  • Public Attestation Records: Cryptographic SHA-256 digital hashes, certificate serial numbers, and issuance timestamps published to public verification endpoints (e.g., attestly.in/verify) for employer verification.

3. Zero Selling of Personal Data

We never sell, rent, or trade student, faculty, or institutional data to advertising networks or third-party data brokers.

Your data is exclusively utilized to deliver the LMS service, compute course progression, calculate accreditation outcomes (such as NBA and NAAC metrics for your university), and generate tamper-evident credentials.

4. Data Security & Storage Architecture

All customer data is encrypted in transit using Transport Layer Security (TLS 1.3) and encrypted at rest using AES-256 cryptographic standards. Database tenancies are isolated using strict row-level security and organization identifier partitioning. Cloud compilation workers execute inside isolated, ephemeral container sandboxes with strictly partitioned networking.

5. Your Data Protection Rights

Depending on your jurisdiction and organization policy, you have the right to:

  • Access and receive an export of your personal and academic learning history.
  • Request correction of inaccurate personal profile data.
  • Request erasure of your account, subject to institutional record retention obligations mandated by governing accreditation bodies.
  • Revoke optional consent for biometric or webcam sampling proctoring features.

6. Contact Our Data Protection Officer (DPO)

If you have any questions, inquiries, or grievance redressal requests regarding our privacy practices, please contact our Data Protection Team at:

privacy@attestly.in • dpo@attestly.in

Attestly Technologies • Compliance & Trust Directorate • Noida / Global