Legal
Privacy Policy
In short
This Privacy Policy explains how Scholaris Private Limited ("Scholaris", "Aptitudo", "we", "us", "our") collects, uses, shares, protects, and retains your personal data when you use Aptitudo at kairo.scholaris.co.in (the "Service").
Aptitudo is a paid online psychometric career-assessment for students. We take your privacy seriously and have written this policy to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under it, and the Consumer Protection Act, 2019, and to meet global best practice (including GDPR-style transparency, lawful-basis, rights, retention, transfer, and breach-notification standards).
Please read this policy together with our Terms of Service, Your Data Rights page, and Grievance Redressal page.
1. Who we are (Data Fiduciary) and how to contact us
Scholaris Private Limited (formerly Chasmis Solutions Private Limited until 15 September 2025) is the Data Fiduciary responsible for your personal data under the DPDP Act. It decides why and how your personal data is processed.
- Company: Scholaris Private Limited
- Registered office: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
- CIN: U85500MH2018PTC318097
Data Protection Officer and Grievance Officer
For any privacy question, request, or complaint, contact:
- Data Protection Officer & Grievance Officer: Bharat Bohra
- Alternate contact: Narendra Purohit
- Email: [email protected]
- Phone: +91 9833861909
- Postal address: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
You can reach the same office to exercise any of your rights (Section 9), raise a grievance (Section 14), or ask anything about this policy.
2. Scope and who can use Aptitudo
Aptitudo is designed for students in India, typically aged about 14 to 25, and the user base includes minors (anyone under 18 years of age). Because of this, we apply heightened protections for children's data — see Section 10.
This policy applies to all personal data we process about:
- Users who register for, pay for, and take the assessment; and
- Parents or legal guardians who provide verifiable consent on behalf of a minor, and whose contact and consent details we record.
3. The personal data we collect — and why (data inventory)
We collect only the data we need to deliver the Service. The table below is the authoritative summary of what we collect, why, the legal basis under the DPDP Act, and how long we keep it.
| Category of data | What it includes | Why we process it (purpose) | Legal basis (DPDP Act) | Retention |
|---|---|---|---|---|
| Identity & contact | Name, email address, phone number, age / date of birth, city, education stage, stream of study | Create your account; deliver the assessment and report; verify eligibility; send transactional messages; provide support; account recovery | Consent; performance of contract | Removed 3 years after your most recent report, or sooner on request — the underlying record survives de-identified (see Section 8) |
| Parental / guardian consent records (minors) | Guardian's name and contact, consent flag, consent timestamp, relationship to the child | Obtain and evidence verifiable parental consent before processing a minor's data, as required by the DPDP Act | Consent (parental); legal obligation | For the life of the child's account + a reasonable period to evidence consent; then de-identified with the account |
| Assessment responses | Your answers across the assessment dimensions, including any adaptive follow-up answers, and any specific career interests you mention | Generate your psychometric scores and personalised report; support retake comparison (where offered) | Consent; performance of contract | Kept indefinitely for research and norming; your identifying fields are removed after 3 years, or sooner on request, and what remains is de-identified (see Section 8) |
| Response metadata (paradata) | Per-question response timing, answer-changes/revisions before submit, blur/focus events, basic session-activity patterns | Ensure report quality and validity (e.g., profile-clarity and bias signals); detect rushed or anomalous submissions; prevent abuse | Consent; legitimate use (quality & fraud prevention) | Kept indefinitely for research and norming; your identifying fields are removed after 3 years, or sooner on request, and what remains is de-identified (see Section 8) |
| Derived psychometric data | Your computed archetype, career-family fit scores, and other derived indicators | The core output you pay for | Performance of contract | Kept indefinitely for research and norming; your identifying fields are removed after 3 years, or sooner on request, and what remains is de-identified (see Section 8) |
| AI-generated report | Your personalised report; and, for eligible tiers, a parent-facing PDF (the PDF itself is generated on your device and not stored on our servers beyond a "generated-at" timestamp) | Deliver the result of the assessment to you | Performance of contract | Kept indefinitely for research and norming; your identifying fields are removed after 3 years, or sooner on request, and what remains is de-identified (see Section 8) |
| Chatbot transcripts (where the feature is enabled for your tier) | The conversation you have with the in-product career chatbot | Provide the optional chatbot feature; safety and abuse review | Consent | 90 days after the chat window for your account closes, then deleted |
| Payment metadata | Razorpay order ID, payment ID, amount, status, and the email/phone used for the receipt. No card, UPI, or bank-credential data ever touches our servers — Razorpay handles that directly. | Take and reconcile payment; issue receipts; process refunds; meet statutory financial-record duties | Performance of contract; legal obligation | Up to 8 years for the financial record, as the Companies Act 2013 requires; identifying fields minimised/redacted where the law allows once no longer needed |
| Authentication data | Email-verification OTP codes and attempt counts (short-lived). Phone number is collected but currently not SMS-verified (see note below). | Verify your email; protect your account; rate-limit abuse | Performance of contract; legitimate use (security) | OTP codes expire within minutes (held transiently); phone retained with your identity data per the rows above |
| Technical & security data | IP address, device/browser information, rate-limit counters, error diagnostics (with your email represented only as a one-way hash in error logs), and the bot-check risk score returned by our anti-abuse provider (see Section 7) | Render the Service, debug, secure the platform, prevent fraud and automated abuse | Legitimate use (security & service integrity) | Transient to short-term; error diagnostics retained only as long as needed to investigate |
| Coarse analytics | Aggregated, non-identifying usage signals (e.g., funnel/completion counts), derived from our own server records | Understand and improve the Service in aggregate | Legitimate use | Aggregate only; no advertising or cross-site trackers are used |
| Safety / crisis-detection flags | Flags raised if assessment or chatbot content suggests a user may be at risk | Protect the safety and wellbeing of the user; respond appropriately | Legal obligation; legitimate use (vital interests / safety) | Retained only as long as necessary for the safety purpose |
| Anonymised aggregate data | De-identified, aggregated scores with no name, email, or phone | Improve and validate the assessment methodology | Not personal data once anonymised | May be retained indefinitely in anonymised form |
Note on your phone number. We collect your phone number for contact, account recovery, and future verification. We do not currently verify it by SMS one-time-password. SMS verification (and any SMS messaging) is planned for a later release, only after we complete the required DLT registration in India, and would then be used solely with your consent and in line with applicable telecom rules.
We do not intentionally collect special/sensitive categories of data (such as health, biometric, religious, or caste data). Please do not enter such information in free-text fields or in the chatbot.
4. How we collect your data
- Directly from you — when you register, pay, take the assessment, generate a report or PDF, or use the chatbot.
- From your parent or guardian — when, for a minor, a guardian provides verifiable consent and their contact details.
- Automatically — technical data (IP, device/browser), paradata, and rate-limit/security signals generated as you use the Service. We store assessment progress locally on your device (see Section 12) so you can resume.
- From our payment processor — payment status/metadata from Razorpay (never your card or bank details).
5. How we use your data (purposes)
Primary purposes (to deliver what you paid for):
- Create and manage your account and verify your email.
- Deliver the assessment, compute your scores, and generate your personalised report (and parent PDF, where applicable).
- Provide optional features such as retake comparison and the chatbot, where available for your tier.
- Take, reconcile, and refund payments, and issue receipts.
- Communicate with you about your report, account, payment, and support requests.
Secondary purposes (carefully limited):
- Protect the Service against fraud, abuse, and security threats.
- Maintain report quality and methodology validity, including via paradata signals and, separately, anonymised aggregated data only for methodology improvement.
- Meet our legal, regulatory, tax, and accounting obligations.
- Respond to lawful requests and protect the safety of users (including acting on crisis-detection flags).
6. What we do NOT do
- We do not sell or rent your personal data to anyone.
- We do not run third-party advertising networks, ad cookies, or cross-site tracking.
- We do not share your individual report, answers, or transcripts with advertisers, schools, employers, or your parents — except, for minors, with the consenting guardian, or where you have given permission, or where the law requires it.
- We do not allow our AI sub-processor to train its models on your personal data; we send prompts only to generate your report/answers and instruct that the data is not used for training, consistent with the provider's terms.
- We do not make automated decisions that have legal or similarly significant effects on you. Your report is exploratory guidance, not an automated decision about your future. It is intended to support reflection and conversation, and is presented with human-meaningful framing — it does not, by itself, determine any outcome for you.
8. How long we keep your data (retention schedule)
We keep personal data only as long as necessary for the purposes above or as required by law. Two different things happen on two different clocks, and we would rather state both plainly than blur them into one number:
- Your answers, scores and report content are kept indefinitely — de-identified, not deleted. They are the basis of the long-term norming and validation studies that make the assessment worth taking, and an answer set that has had every identifier stripped from it is no longer personal data. We do not run a job that destroys them on a timer, and we do not want you to believe we do.
- Your identifying fields age out on a 3-year clock. An automated sweep runs daily and, 3 years after your most recent report, removes your name, email, phone, date of birth, city and your guardian's contact from the assessment records, the account record and the related rows — in place, so the de-identified answer set survives without you attached to it.
- Parental consent records (minors): kept for the life of the child's account plus a reasonable period to evidence that consent was validly obtained, then de-identified with the account.
- A minor's answers while guardian consent is still pending: stored, on the same footing as everyone else's, with no automatic expiry. If a guardian never responds we stop emailing them after 30 days (Section 10), but nothing is deleted at that point. The data is kept until the student or the guardian asks us to erase it — see the self-serve route in Section 9.
- Chatbot transcripts: deleted 90 days after the chat window for your account closes.
- Payment / financial records: retained for up to 8 years, the period the Companies Act 2013 requires us to preserve books of account; identifying fields are minimised or redacted where the law permits.
- Authentication OTPs and rate-limit counters: transient, expiring within minutes to the length of the relevant window.
- Anonymised aggregate data: as it is no longer personal data, it may be retained indefinitely for methodology improvement.
You can ask us to erase your data sooner, and you do not have to wait for any clock — see Section 9. Erasure is the route that reaches your data at any time: it strips every identifier we hold, cascades to your downstream rows (report, chatbot transcripts, and related records) in a single operation, and leaves behind only the de-identified answer set and the financial record the Companies Act obliges us to keep.
8a. Chatbot safety monitoring
If the optional chatbot feature is enabled for your tier, your conversations with it are monitored for safety purposes. This includes automated detection of language suggesting crisis, self-harm, or risk to yourself or others. If our system detects such language, it may:
- display crisis-support resources to you directly in the chat, and
- trigger an internal alert for human review, so we can respond appropriately.
This monitoring exists solely for user safety and is not used for advertising, profiling, or any commercial purpose. It applies even where the chatbot user is a minor — see Section 10 for how we handle minors' data generally.
9. Your rights (Data Principal rights) and how to exercise them
Under the DPDP Act — and consistent with global data-protection standards — you (the Data Principal) have the following rights. For a minor, these rights are exercised by the parent or legal guardian.
- Right to access — obtain a summary of the personal data we hold about you and how we process it.
- Right to correction and updating — have inaccurate or incomplete data corrected, completed, or updated.
- Right to erasure — have your personal data deleted where it is no longer needed and no legal exception requires us to keep it. In practice erasure at Aptitudo removes every identifier and deletes your login, while the de-identified answer set is kept — see Section 8.
- Right to withdraw consent — withdraw consent for any consent-based processing at any time, as easily as it was given. Withdrawal does not affect processing already carried out, and some features may no longer work without the relevant data.
- Right to grievance redressal — raise a complaint with our Grievance Officer and receive a timely response (Section 14).
- Right to nominate — nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
In addition, reflecting global best practice, you may request data portability (a machine-readable copy of data you provided) and may object to or restrict certain processing; we will honour such requests to the extent applicable law allows.
How to exercise your rights. You have two routes:
- In-product flow (self-serve erasure) — sign in and open Settings, where "Delete my account and data" runs the erasure described in Section 8 as soon as you confirm, without waiting for us to act on an email. This control is an operator setting we can switch off; if it is off for your account, the screen tells you so and route 2 applies — the right itself is never gated. A guardian acting for a minor can use the same control from the student's account, or write to us at the address below. The same screen also lets you download a copy of your data or pause your account. Our Your Data Rights page sets out how to exercise every right: a self-serve Settings route exists for access and erasure only — correction, nomination, grievance and escalation are exercised by writing to us, at the address below.
- Contact our DPO / Grievance Officer — email [email protected] from your registered email, stating the right you wish to exercise and enough detail for us to locate your record. We may need to verify your identity before acting.
Our response times: we acknowledge requests promptly (within 24 hours for grievances) and respond to access/erasure requests within 30 days, and to correction requests within about 14 days. If a request needs more time or cannot be fully met (e.g., a legal-retention exception applies), we will explain why. See the Your Data Rights and Grievance Redressal pages for full details.
10. Children's data (users under 18)
Because Aptitudo is used by minors, we apply the DPDP Act's heightened protections for children:
- Verifiable parental/guardian consent first. Before we process the personal data of a user we identify as a minor (under 18), we require verifiable consent from a parent or legal guardian, and we record the consent flag and timestamp.
- No detrimental processing. We do not undertake any processing that is likely to cause a detrimental effect on the wellbeing of a child.
- No advertising, ad profiling, or commercial behavioural monitoring of children. We do not use children's data for advertising, ad targeting, or cross-site tracking, we do not build marketing or behavioural profiles of children, and we do not sell or rent children's data. The one thing that does observe interaction behaviour is our security bot-check, described immediately below — we would rather state that plainly than make an absolute claim we cannot stand behind.
- Exploratory framing. A minor's report is framed as exploration and guidance to support reflection and conversations with parents, teachers, or mentors — never as a fixed verdict about the child.
- Parental access and erasure. A parent or guardian may access the child's data, request correction, withdraw consent, and request erasure at any time using the contacts in Section 1, or with the self-serve control in Settings (Section 9).
- What happens while consent is pending. If a student completes the assessment before a guardian has consented, the answers are stored in the meantime and nothing expires them automatically. While we wait, we send the guardian at most one reminder a week, and at most four reminders in total — each one says which reminder it is and when the outreach stops. If the guardian never responds we stop writing to them after 30 days and archive the request, but the data itself is kept until the student or the guardian asks us to erase it — see Sections 8 and 9.
The one exception, stated plainly: bot protection. Sensitive actions — creating an account, sending an email verification code, generating the adaptive follow-up questions while the assessment is in progress, generating and saving the report, starting a payment, the payment-failure help email, and sending the guardian-consent email — are protected by Google reCAPTCHA v3, an invisible anti-abuse check. Where it is active it reads interaction signals in the browser (timing, pointer and keyboard activity) together with the IP address, and returns a score indicating how likely the request is to come from an automated script rather than a person. Because some of those actions occur while an assessment is in progress, the check can be active during part of a minor's assessment session. We use the score for one purpose: to allow or block that request. It is not stored against the student's record, does not influence the report or any score in it, and is never used for advertising, marketing, or commercial profiling. Google acts as our sub-processor for this check (Section 7) and processes the data under its own terms; where the Google check cannot be reached from a school or network that blocks it, an equivalent Cloudflare bot check may run in its place, on the same terms and for the same single purpose. We keep the check enabled for every user, including minors, because it protects the email and report endpoints that would otherwise be abused; disabling it for self-declared minors would simply hand an abuser a switch.
If you believe a minor has registered without proper guardian consent, or you are a guardian who wishes to review or remove a child's data, contact [email protected] and we will act promptly.
11. Data security
We use reasonable technical and organisational measures to protect your data, including:
- Encryption in transit (TLS) and at rest for personal data.
- Row-Level Security (RLS) and least-privilege access controls so that only authorised systems and personnel can access data, and only what they need.
- Hardening against abuse — rate limiting, bot protection on sensitive actions, and stripping of sensitive headers from error logs (with email represented only as a one-way hash in diagnostics).
- A defined incident-response process and regular review of our security posture and sub-processors.
No method of transmission or storage is perfectly secure, but we work continuously to protect your data and to limit what we collect in the first place.
13. Breach notification
If we become aware of a personal-data breach that affects you, we will act quickly to contain and assess it. In line with our commitment and applicable law, we will notify the Data Protection Board of India and affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach, describing (to the extent known) the nature of the breach, the likely consequences, and the measures taken or recommended to mitigate harm.
14. Grievance redressal
If you have any concern about how we handle your data, you can raise it with our Grievance Officer:
- Grievance Officer & Data Protection Officer: Bharat Bohra (alternate: Narendra Purohit)
- Email: [email protected]
- Phone: +91 9833861909
- Address: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
Our service levels: we acknowledge within 24 hours and aim to resolve within 15 days (and in any event within the timelines required by the IT Rules and the DPDP Act). Full details, including what to include in a grievance, are on our Grievance Redressal page. Grievances may be filed in English or Hindi.
Escalation. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India (for data-protection matters) or to the appropriate consumer forum under the Consumer Protection Act, 2019, or to the appropriate courts as set out in our Terms of Service.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. If we make material changes, we will notify registered users by email and/or by a prominent notice in the Service before the change takes effect, where required. Your continued use of Aptitudo after an update means you have read the revised policy.
16. Contact
For any privacy matter, request, or grievance:
Scholaris Private Limited F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India CIN: U85500MH2018PTC318097 Data Protection Officer & Grievance Officer: Bharat Bohra (alternate: Narendra Purohit) Email: [email protected] · Phone: +91 9833861909