

Cozmic.in operates an artificial-intelligence-powered, cloud-based Enterprise Resource Planning (ERP) and Governance platform tailored for higher education institutions in India. In providing these services, Cozmic acts primarily as a "Data Processor" under the DPDP Act, 2023. The respective college, university, or educational group licensing the platform is the "Data Fiduciary" determining the purpose and means of data processing.
This Privacy Policy explains how we process data when you access or interact with Cozmic.in, its subdomains, desktop console nodes, and mobile applications (including those for students, parents, and faculty). By using our services, or having your data provisioned onto our platform by your licensing educational institution, you acknowledge the processing patterns defined in this document.
We process different categories of data necessary to provide a comprehensive administrative ERP and campus intelligence system. This includes:
Names, roll numbers, enrollment designations, gender, official and personal email addresses, mobile numbers, postal addresses, and official government identifiers (such as Aadhaar Card number, PAN Card number, or Voter ID where necessary for regulatory or scholarship registry integrations).
For campus security and automated roll-marking via our Stellar module, we process biometric data in the form of mathematical facial mapping vectors. Raw photos or video files captured by local hardware nodes are processed on edge devices to generate these vectors and are not stored in our central databases.
IP addresses, device logs, operating system metrics, browser parameters, access timelines, and authentication token logs collected automatically when accessing our servers.
We collect personal data through three primary mechanisms:
Data processed by Cozmic is used strictly for the following operational and legal purposes:
Under the Digital Personal Data Protection Act, 2023, and Rule 6 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, our processing operations are justified by:
| Legal Basis | Description | Applicability in Cozmic ERP |
|---|---|---|
| Consent | Processing based on clear, specific, unconditional, and informed consent (Section 6, DPDP Act). | User onboarding, personal profile updates, and opting into mobile alerts. |
| Legitimate Uses | Processing for certain legitimate purposes where consent is implied or mandated by law (Section 7, DPDP Act). | Compulsory academic enrollment updates, official examination grading, and campus safety protocols. |
| Contractual Necessity | Processing necessary for the performance of a contract between the Company and the licensing institution. | Providing core ERP services to fulfill SLA obligations. |
Cozmic does not sell, rent, trade, or monetize student or institutional databases under any circumstances. Data sharing is strictly confined to:
Cozmic maintains reasonable security practices and procedures in compliance with Section 43A of the IT Act, 2000, and Section 8 of the DPDP Act, 2023. Our security standards include:
Cozmic retains personal data only for as long as necessary to fulfill the operational requirements of the licensing institution, or as required under applicable Indian laws.
Upon expiration or termination of the institutional license agreement, all corresponding databases, user profile records, and transaction logs are deleted, purged from server nodes, or anonymized within 90 days, subject to standard statutory compliance parameters and system backup cycles.
Under Section 11, 12, and 13 of the DPDP Act, 2023, Indian citizens (students, faculty, parents) possess specific rights:
We use technical session cookies, authorization headers, and local storage tokens. These tokens do not track behavior across external websites; they are used strictly to maintain secure authentication states, compile usage load telemetry, and preserve user UI preferences.
All core databases, ledger entries, and biometric hashes are stored locally on cloud servers located within the territory of India (specifically the AWS Asia Pacific region in Mumbai).
If any minor data processing operations require cross-border transfers (e.g., utilizing global analytical utilities or email SMTP relays), such transfers are executed in strict compliance with Section 16 of the DPDP Act, 2023, ensuring that the destination countries maintain equal or greater privacy protection standards.
In compliance with Section 9 of the DPDP Act, 2023:
We reserves the right to amend this Privacy Policy to ensure alignment with technological updates or regulatory changes under the DPDP Act, 2023. Material changes will be communicated via institutional administrator circulars, portal banners, or email alerts at least 30 days prior to the implementation of the updated policy.
In accordance with Rule 3(11) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, the details of the designated Grievance Officer are provided below: