CSR Scholarship Portal · Version 1.0 · Effective January 2024. This online policy is the version presented for portal consent.
Privacy contact1. Scope and standards
This policy governs personal data collected for scholarship eligibility, verification, beneficiary management and fund disbursement. It covers students, parents or guardians, authorized staff, verification agencies and public visitors.
It states alignment with the DPDP Act 2023, GDPR 2016/679, ISO/IEC 27001:2022 and ISO/IEC 27701:2019.
2. Data collected
Identity & contact
Name, date of birth, email, mobile number and address/domicile
Eligibility
Gender, category/caste, family income, institution, course and academic records
Optional sensitive data
Aadhaar, bank account, PAN and supporting financial documents
Security activity
Login/access logs, IP address and document-verification events
Sensitive information receives restricted access and enhanced safeguards. The policy states that Aadhaar is optional, tokenized and not stored in plaintext, while bank and financial details are encrypted and masked in portal views.
3. How data is used
Eligibility assessment
Evaluate scholarship rules and application evidence
Verification
Verify identity, education, income, domicile and category where applicable
Disbursement
Process an approved award through authorized finance controls
Communication & compliance
Provide status updates, handle grievances and meet audit obligations
Personal data is not sold and is not shared with advertisers, marketing firms, social-media platforms or unauthorized organizations.
4. Consent and your rights
Registration requires a clear, unticked consent. Separate or fresh consent may be required for sensitive data or a new processing purpose.
- ✓ Access a copy of personal data
- ✓ Correct inaccurate or incomplete information
- ✓ Request portable data
- ✓ Restrict processing while accuracy is disputed
- ✓ Request erasure where legally permitted
- ✓ Raise a grievance or appeal a verification finding
Requests are acknowledged within 24 hours and are normally fulfilled within 30 days; complex matters may take longer as permitted by law.
5. Sharing and verification
Data may be shared only where necessary with contracted verification agencies, banks or financial institutions, CSR administration teams, cloud infrastructure providers, government bodies or lawful authorities. The policy requires confidentiality, limited access, audit controls and processor agreements.
A verification agency may check education, income, domicile and category evidence and may conduct field verification. Users may ask which agency is involved, request the report, correct inaccurate findings and appeal within 30 days.
6. Security and retention
The policy describes TLS in transit, encryption at rest, role-based access, masking, audit logs, monitoring, backups, vulnerability management and secure disposal. Retention varies by record: access logs 12 months; support records 24 months after resolution; application and verification records generally 5 years; disbursement records 7 years. Approved scholarship records are listed as lifetime records in the supplied document.
7. Incident and grievance
Suspected incidents are contained, sessions or tokens revoked where required, evidence preserved and notifications handled according to applicable law. Report privacy, grievance or security concerns to privacy@shikshavritti.org.
8. User agreement
Users must keep passwords private, provide accurate information, use one account per person and report suspected unauthorized access. Fraudulent documents, impersonation, unauthorized access, disruption and illegal activity are prohibited.
A scholarship may be cancelled for fraud, loss of eligibility, insufficient academic progress, misconduct or breach of the agreement. Continued portal use constitutes acceptance of published policy amendments after applicable notice.