Privacy & Data Protection

Compliance with DPDP Act 2023 & IT Act 2000

1. Encryption & Security

CollegeVision employs enterprise-grade **AES-256-GCM encryption** for all Personally Identifiable Information (PII). Your phone number is encrypted at rest within our secure Supabase vault, ensuring that even in the event of unauthorized access, your data remains unreadable.

2. Zero-Spam Policy

We physically enforce a strict communication policy. Our system is programmatically restricted from contacting a student more than **twice per week**. We do not sell your data to third-party aggregators. All communication is mediated through our internal verified partner network.

3. Data Minimization

We only collect data that is strictly necessary for your educational journey:

  • **Identity**: Name and email for account management.
  • **Communication**: Phone number for verified university assistance.
  • **Preference**: Target degree and budget for accurate matching.

4. Right to Deletion

Under the DPDP Act 2023, you have the absolute right to be forgotten. You can trigger a full deletion of your account and all associated PII directly from your Student Dashboard settings. This action is irreversible and removes all traces of your data from our active databases and backups.

Last updated: March 2026 • Version 1.2