Privacy Policy
Effective · Scripteco Technologies Private Limited
On this page
In short: we collect only what a campaign needs, we never sell your data, there is no advertising tracking, research uses anonymised answers only, and you can ask to see, correct or delete your data at any time.
This policy explains how Scripteco Technologies Private Limited ("Askofy", "we") handles personal data. It is written to meet the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 ("DPDP law"), and the Information Technology Act, 2000 and its Rules.
1. Who is responsible for your data
It depends on why the data is used.
When you take a campaign
The organisation that invited you (your employer, hospital, school or another body), and any campaign partner named in the campaign's Terms & Conditions, decide why and how your data is used. Under DPDP law, they are the Data Fiduciary. Askofy runs the platform on their behalf as a Data Processor, following their instructions and our Data Processing Addendum.
When we decide the purpose
We are the Data Fiduciary when:
- you visit askofy.com, contact us or request a demo or partnership
- you are an organisation admin with an Askofy account
- you opted in to updates from Askofy or a campaign partner
- we keep the platform secure and prevent fraud
- we create anonymised research data (see Research Data Policy)
2. What we collect
Participants (people who take a campaign)
- Identity: your name, as it should appear on your certificate.
- Contact (if asked or given): email and phone, to send your certificate and campaign updates.
- Profile (only what the campaign asks for): how you are taking part (employee, patient, visitor, guest, student, caregiver), department, occupation or stream of study, employee code, city, age group and gender.
- Learning record: your answers (stored as option numbers), score, pass or fail, time taken, certificate code, and the dates you opened, started and finished.
- Consent record: what you agreed to, the version of the Terms & Conditions and when.
We do not ask for Aadhaar, PAN, bank or card details, passwords, or medical records. Campaigns are designed not to ask about your own health conditions. If a campaign ever does, it will say so clearly, the question will be optional, and answers are used only anonymously.
Employees invited by their organisation
Your organisation may upload a list containing your name, employee code, email, phone, department, designation and location. This is used to send you your personal link and reminders, and to show your organisation who has completed. Your organisation is responsible for telling you about this.
Organisation admins and enquiries
Name, work email, phone, organisation, role, the products you are interested in and messages you send. If you sign in with a password, our login provider stores it only as a secure one-way hash. We never see it.
Automatically
- Device storage: your progress in a campaign is saved in your browser so you can resume. See the Cookie & Storage Policy.
- Technical logs: our hosting and security providers process IP address, browser type and request times to deliver the site and block attacks. We do not use these for profiling or advertising.
- Counts: we count link opens, starts and completions per campaign, without identifying you.
3. Why we use it
- Run the campaign: show the course, score answers, issue, email and verify your certificate.
- Organisation reporting: show your organisation your participation, score and department-level progress, and send reminders on its behalf.
- Updates you agreed to: campaign reminders, and optional updates only if you ticked the separate box.
- Research and impact: anonymised, aggregated answers to understand awareness and improve campaigns.
- Safety and law: keeping the service secure, preventing fraud and fake certificates, and meeting legal obligations.
- Our customers: accounts, billing, support and service messages for organisations.
Legal basis
We rely on your consent (given at the start of a campaign or in a form), or on a legitimate use allowed by DPDP law, such as an employer's legitimate employment purposes or meeting a legal obligation. You can withdraw consent at any time (see section 7). Withdrawing does not affect what was done before.
4. Who can see it
- The organisation that invited you sees your name, the details you entered, participation, score and certificate. Organisation admins cannot see contact details of other organisations' participants.
- Campaign partners named in a campaign (for example, a medical trust) receive only anonymised, aggregated results, unless the campaign's Terms & Conditions say otherwise and you agreed.
- Askofy staff with a need to know, for support, certificate delivery and security. Access to contact details is limited, masked by default, and every reveal or export is logged with a reason.
- Anyone with your certificate code can verify it, and sees your name, the campaign, the organisation and the date. See the Certificate Policy.
- Service providers who help us run Askofy, bound by contract to protect your data:
- Supabase Inc.: database, login and file storage
- Cloudflare Inc.: hosting, content delivery and security
- Hostinger International Ltd.: sending emails
- Google Fonts: fonts, which shares your IP address with Google when a page loads
- Authorities, when Indian law requires it, for example a lawful request from a court or CERT-In.
We never sell personal data, and we do not use it for third-party advertising.
5. Where it is stored
Data is stored with our providers in secure data centres, which may be in or outside India. Any transfer outside India follows DPDP law and any restrictions notified by the Government of India.
6. How long we keep it
- Participant records: while the organisation's campaign is active, then up to 12 months for reports and certificate emails. After that we delete them or make them anonymous.
- Certificate verification: the certificate code, name, campaign and date stay verifiable for 3 years from issue, unless you ask us to remove them earlier.
- Employee lists: until the organisation deletes them, or within 90 days after its account ends.
- Admin accounts and enquiries: for the life of the account, or 24 months after the last contact for enquiries.
- Invoices and payment records: for as long as tax and company law requires (currently up to 8 years).
- Security logs: 180 days, as required by CERT-In directions.
- Anonymised research data: may be kept indefinitely, as it no longer identifies anyone.
- Backups: overwritten on a rolling basis within 30 days.
7. Your rights
Under DPDP law you can:
- access a summary of your data and how it is used
- correct, complete or update it
- erase it, where it is no longer needed or you withdraw consent (certificates already shared outside Askofy cannot be recalled)
- withdraw consent, as easily as you gave it
- nominate someone to exercise your rights if you die or become unable to
- complain to us, and then to the Data Protection Board of India
How to ask: contact the organisation that invited you, or email privacy@askofy.com with your name, the campaign and the email or phone you used. We will verify your identity and reply within 30 days. When we act as a Data Processor, we pass your request to the organisation and help it respond.
To stop optional updates, use the unsubscribe link in any email or write to us.
8. Children
Askofy is not directed at children on its own. A person under 18 may take part only:
- through an organisation (such as a school) that has obtained verifiable consent from a parent or lawful guardian, or
- with a parent or guardian who agrees on their behalf.
For anyone under 18 we do not offer optional updates, do not track behaviour across sites, and do not show advertising. A parent or guardian can ask us to delete a child's data at privacy@askofy.com.
9. Security
- Data is encrypted in transit (HTTPS) and at rest.
- Database rules mean each organisation can see only its own data.
- Staff access to contact details is masked by default, logged and reviewed.
- Logins use one-time email links, or passwords stored only as one-way hashes.
- Answers are scored without exposing the correct options.
No system is perfectly secure. If a breach affects your personal data, we will inform you and the Data Protection Board of India, and report to CERT-In, within the time limits the law sets. See Security.
10. Changes
We will post updates here and change the date at the top. For significant changes affecting how participant data is used, we will ask for fresh consent where the law requires it.
11. Contact
- Privacy requests: privacy@askofy.com
- Grievance Officer: grievance@askofy.com. See Grievance Redressal.
- Post: Scripteco Technologies Private Limited, Mumbai, Maharashtra
Scripteco Technologies Private Limited · Mumbai, Maharashtra, India