1. Data we process
- Account data: name, email, phone (if supplied), NewNcert ID, role, class, target exam and institution/batch information.
- Learning data: questions viewed or attempted, answers, scores, time, progress, bookmarks, revision state, weak-topic indicators, practice/test history and generated analytics.
- Commercial data: selected plan, licence, subscription status, coupon/referral attribution, invoice/tax details and transaction references. Card details, CVV, OTP and UPI PIN are processed by the payment provider and are not stored by NewNcert.
- Technical and security data: device/session identifiers, IP-derived security records, browser/user-agent, audit logs, cookie preferences and error diagnostics.
- Communications: support requests, error reports, consent/acceptance records and administrative correspondence.
2. Why we process it
We process data to create and secure accounts; deliver question-bank, test, revision and analytics services; personalise learning; administer subscriptions and licences; prevent account sharing, abuse and fraud; provide support; maintain academic integrity; comply with tax, accounting, consumer and legal obligations; and improve service reliability. We do not sell personal data.
3. Sharing and processors
Data is shared only where needed with hosting, email, analytics, security, customer-support and payment service providers, or with authorised faculty/institute administrators for students legitimately mapped to them. Access is role-scoped. We may disclose information when required by law or to protect users, the Platform or the public. Service providers are expected to process data only for the contracted purpose.
4. Student, faculty and administrator visibility
A student can view their own learning and account information. Faculty may view mapped students within their assigned scope. Administrators can view operational, subscription, security and learning records needed to run the service. A closed student account cannot sign in or retrieve retained records. Other students do not receive a closed student's identity; closed students are removed from public leaderboards.
5. Account closure and erasure
Eligible students can initiate closure from Profile → Account & Privacy after confirming their password and typing the confirmation phrase. Access is disabled immediately and all sessions are revoked. Direct identifiers are scheduled for anonymisation after a 30-day safety window.
We erase personal data when it is no longer necessary for its specified purpose unless retention is necessary for that purpose or for compliance with law. Payment, tax, licence, dispute, fraud-prevention and academic-integrity records may therefore remain in restricted administrator systems for the applicable period. Learning statistics needed for product integrity may be retained in anonymised or aggregated form. Closing an account does not entitle the student to a refund for activated digital access.
6. Retention guide
| Category | Typical retention approach |
|---|---|
| Active account and learning profile | While the account is active; direct identifiers are anonymised after a valid closure request and safety window unless still required. |
| Payment, invoice and tax records | For the period required by applicable accounting, tax and dispute-resolution obligations. |
| Consent, policy acceptance, licence and fraud/security records | For the relevant service, legal, security or dispute purpose; then deleted or anonymised. |
| Learning analytics | Account duration and, after closure, only where required for academic integrity or in anonymised/aggregated form. |
| Routine security logs | Short rolling periods unless an incident, investigation or legal requirement justifies longer retention. |
7. Your choices and rights
Subject to applicable law, you may request access to a summary of your personal data, correction or completion of inaccurate data, erasure, withdrawal of consent where consent is the basis, grievance redressal and nomination. Profile information can be corrected in the Profile page. For other requests, email privacy@medlearno.in from the registered address. We may verify identity before acting and will explain if limited retention is necessary.
8. Children and students under 18
NewNcert is an educational service and some learners may be under 18. Where applicable law requires verifiable parent or lawful-guardian consent for processing a child's personal data, the parent/guardian must provide or manage that consent. We do not knowingly use children's data for targeted advertising or processing likely to cause detrimental effects. A parent/guardian may contact privacy@medlearno.in to review, correct or request closure of a child's account, subject to verification and applicable law.
9. Security and incidents
Controls include encrypted HTTPS transport, password hashing, role-based access, session/device controls, nonce-protected state changes, rate limits, security headers, payment signature verification, backups and audit logs. No internet service can promise absolute security. If a personal-data breach occurs, we will contain and investigate it and provide notices required by applicable law.
10. Cookies and communications
Essential cookies support login, security and saved preferences. Optional analytics or promotional communications should be used according to the consent and opt-out controls shown on the Platform. Transactional and security messages may still be sent when necessary to provide or protect the service.
11. Updates and grievance contact
Material updates are posted with a new effective date and, where appropriate, communicated in-product or by email. Continued processing that requires fresh consent will not rely only on silence or continued browsing.
Privacy/legal: privacy@medlearno.in / legal@medlearno.in
Support: support@medlearno.in
Website: https://newncert.in/
Jurisdiction: India