Document Control · ISO 9001:2015 §7.5 — Documented Information
EVP-DDP-01
Data Deletion Policy
Document ID
EVP-DDP-01
Version
1.0
Status
Active
Effective Date
2026-02-09
Owner / Custodian
Chintankumar Bhatt, Platform Founder
Classification
Public
Next Review
2027-02-09
Framework
GDPR Art. 17
Jurisdiction
Mumbai, India
Revision History
| Rev | Date | Description | Author |
|---|---|---|---|
| 1.0 | 2026-02-09 | Initial release — data deletion policy | C. Bhatt |
1. Purpose
This Data Deletion Policy establishes the rights of EduVerse™ users to request erasure of their personal data, the procedures for processing such requests, retention exceptions, and the timeline for completion. This policy is compliant with GDPR Article 17 (Right to Erasure), the Indian IT Act 2000, and the Digital Personal Data Protection Act 2023 (DPDPA).
2. Scope
This policy applies to:
- All registered users (students, tutors, administrators) requesting personal data erasure
- All personal data collected and stored by EduVerse™ as detailed in EVP-DCP-01
- Data deletion requests received via self-service, email, or formal grievance channels
3. Terms & Definitions
| Term | Definition |
|---|---|
| Erasure / Deletion | Permanent, irreversible removal of personal data from all active systems and backups |
| Right to Erasure | GDPR Art. 17 right to have personal data deleted under specified conditions |
| Retention Exception | Data that must be retained for legal, financial, or security reasons despite a deletion request |
| Anonymisation | Irreversibly removing personal identifiers from data, leaving only non-identifiable statistics |
| Grace Period | A 30-day window after deactivation during which deletion can be reversed |
4. Eligible Data for Deletion
Upon a valid deletion request, the following data categories are permanently removed:
| Data Category | Deletion Action | Timeline |
|---|---|---|
| Account credentials (email, password hash) | Permanently deleted | Within 7 days |
| Personal profile (name, phone, photo, DOB) | Permanently deleted | Within 7 days |
| KYP profile (grade, board, school, address, face photo) | Permanently deleted | Within 7 days |
| OAuth tokens (Google) | Revoked and deleted | Immediate |
| Educational records (scores, progress, assignments) | Permanently deleted | Within 7 days |
| Session history and attendance | Anonymised (tutor records retained anonymously) | Within 30 days |
| Communication logs | Permanently deleted | Within 30 days |
| Geolocation and timezone data | Permanently deleted | Within 7 days |
| Platform analytics (attributed) | Anonymised and aggregated | Within 90 days |
5. Data Retention Exceptions
The following data is exempt from deletion and will be retained for the periods stated, notwithstanding a deletion request:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Consent records (user_consents) | Minimum 7 years post-termination | EVP-CLP-01 §6.2 · IT Act 2000 · Indian Contract Act 1872 |
| Payment transaction references | 7 years | Income Tax Act 1961 (India) · GST Act |
| Fraud / security incident records | Duration of risk + 3 years | Legitimate Interest · IT Act 2000 §43A |
| Data involved in active legal disputes | Until dispute resolution | Legal Obligation |
| Anonymised analytics (no identifiers) | Indefinite | No personal data — GDPR Recital 26 |
Consent records are never deleted as they form the legally binding audit trail of the User's clickwrap agreement per EVP-CLP-01. These records contain no ongoing personal risk as they are stored in an append-only, access-restricted collection.
6. Deletion Methods
Method 1 — Self-Service (Recommended)
For the fastest processing, use the in-platform account deletion flow:
- Log in to your EduVerse™ account.
- Navigate to Settings → Account → Privacy & Security.
- Scroll to "Delete My Account" and click it.
- Confirm your identity via password, passkey, or OTP.
- Select a deletion reason (optional) and confirm.
- You will receive an email acknowledgement within 24 hours.
- Your account is deactivated immediately; full data purge completes within 30 days.
Grace Period: You may cancel a pending deletion by logging back in within 30 days.
Method 2 — Email Request
If you cannot access your account, submit a written request:
To: er.chintanbhatt@gmail.com
Subject: DATA DELETION REQUEST — [Your Registered Email]
Include:
- Full name as registered on the platform
- Registered email address and phone number
- Reason for deletion (optional)
- Identity proof (government-issued ID or screenshot of logged-in account)
Email requests are processed within 14 business days of identity verification.
Method 3 — OAuth Provider Revocation
If you signed in via Google OAuth, also revoke third-party access:
- Google: myaccount.google.com → Security → Third-party apps → EduVerse → Remove access
Note: Revoking OAuth access does NOT delete your EduVerse™ data. You must also complete Method 1 or 2.
7. Deletion Timeline Summary
| Phase | Action | Timeline |
|---|---|---|
| Immediate | Account deactivated; login disabled | 0–2 hours after confirmation |
| Phase 1 | Personal profile, KYP, and credentials deleted | Within 7 days |
| Phase 2 | Session history anonymised; communications deleted | Within 30 days |
| Phase 3 | Residual backup purge; analytics anonymised | Within 90 days |
| Retained | Consent records, payment references (exceptions §5) | Per retention schedule |
8. Data Export Before Deletion
Before requesting deletion, you may request a machine-readable export of your personal data (GDPR Art. 20 — Right to Portability):
- Email er.chintanbhatt@gmail.com with subject: "DATA EXPORT REQUEST — [Your Email]"
- Data will be provided in JSON or CSV format within 30 days
- Includes: profile data, KYP data, session history, payment references, and progress records
9. Identity Verification
To protect against unauthorised deletion requests, EduVerse™ requires identity verification for all deletion requests. Accepted verification methods:
- Authentication via the in-platform deletion flow (password/passkey)
- Government-issued photo ID (for email requests)
- Account ownership verification (access to the registered email address)
We will not process deletion requests where identity cannot be verified, to prevent malicious account deletion by third parties.
10. Contact for Deletion Requests
| Channel | Contact |
|---|---|
| Primary Contact | er.chintanbhatt@gmail.com — Chintankumar Bhatt (Founder) |
| Co-Founder | er.csbhatt@gmail.com |
| Response SLO | 3 business days (acknowledgement) · 30 days (completion) |
Related Policies
Document ID: EVP-DDP-01 · Version 1.0 · EduVerse™ · © 2026 All rights reserved.
Status: Active · Next Review: 2027-02-09