Privacy Policy
Last updated: 24 August 2026
1. Who operates this platform and who to contact
WorkSathi ("the platform", "we", "us") is a private, independent application assistance and processing service.
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for the personal data described here, and you are the Data Principal.
We are not a government department, government portal, examination authority, scholarship department or common service centre, and we are not affiliated with, endorsed by or acting on behalf of any of them. Decisions on any application are made solely by the relevant authority.
| Grievance Officer | info.worksathi@gmail.com |
| Data deletion requests | info.worksathi@gmail.com, or ask our support team |
| Response commitment | Within 30 days of receiving your request |
You may also raise anything in this policy with our support team directly — we speak to every student personally, and you do not need to write a formal letter to be heard.
2. The promise this policy exists to make
Your information is used to fill and process the application you asked for, and for nothing else.
We do not sell it. We do not rent it. We do not share it with advertisers, lenders, coaching agencies, recruiters or data brokers. We do not use your documents to train machine learning models. We do not use your information to profile you or to advertise to you.
Anything outside the application you asked us to process is not a use we make of your data.
3. Consent — taken at every step, not once
Consent is not collected once and assumed forever. It is taken, recorded and shown to you at each stage:
- At registration — you agree to your account being created and to us contacting you about your applications.
- Before each application — you agree to a written statement naming that specific application, the documents it needs and the authority it goes to.
- Before any portal credential is stored — a separate, explicit agreement, never bundled with anything else (section 8).
- Before a correction or resubmission — where the change is material.
For each consent we record the exact wording you agreed to, its version, the date and time, and the IP address. You can ask to see this record at any time.
You fill your own form. You provide your own information and choose your own applications. We prepare and process what you give us — we do not decide on your behalf and we do not add information you did not supply.
Withdrawing consent. You may withdraw at any time, by email or through support. Withdrawal stops further processing immediately. It cannot recall a submission an authority has already received, because that record is no longer in our hands.
4. Children and guardians
Many applications we assist with are for school students, and many applicants are under 18.
Where the applicant is a child (under 18 years), we process personal data only with the verifiable consent of a parent or lawful guardian, as required by section 9 of the DPDP Act.
- Registration asks for the applicant's date of birth.
- Where that date of birth shows the applicant is under 18, the account cannot proceed until a parent or guardian is named and that adult's consent is recorded, with their name, relationship and contact details.
- The guardian's consent is stored with the same evidence as any other consent — exact wording, version, timestamp and IP address.
- A guardian may withdraw consent, request access, or request deletion on the child's behalf at any time, using the grievance address in section 1.
In line with section 9 of the DPDP Act, we do not carry out behavioural tracking, profiling or targeted advertising directed at children. We do not do it for any user, and we especially do not do it here.
5. What we collect
We collect only what a specific application requires. The exact set depends on the application type you choose, and every field is visible to you before you submit.
Account information — name, mobile number, email address, date of birth, password (stored only as a cryptographic hash), and the institution you belong to, if any.
Guardian information — where the applicant is a minor: the guardian's name, relationship and contact details, and the record of their consent.
Student profile information — gender, parent or guardian names, category, address, and academic details such as course, year, enrolment number and roll number.
Application information — the answers you provide in an application form.
Documents — the files you upload, such as marksheets, certificates, photographs and identity proofs.
Third-party portal credentials — only where an authority's portal offers no other authorised route, and only if you explicitly choose to provide them. See section 8.
Technical information — IP address, browser and device information, and timestamps of actions taken. Used for security, audit and fraud prevention.
Payment information — amounts, status and the reference issued by our payment provider. We do not receive or store your full card number, UPI PIN or net banking credentials.
We do not ask for information an application does not need.
6. Why we collect it
| Purpose | What it covers |
|---|---|
| Providing the service | Preparing, checking and submitting the applications you ask us to process |
| Document verification | Confirming a document is legible, valid and matches the application |
| Communication | Status updates, correction requests and deadline reminders |
| Payments | Collecting service fees and issuing receipts |
| Security and audit | Detecting misuse, investigating incidents, and keeping a record of who did what |
| Legal obligations | Retaining records where the law requires it |
There is no seventh row. If a purpose is not on this table, we are not processing your data for it.
7. Who can access your information
Access is restricted by role and, for institutional users, hard-limited to their own institution.
- You can see all of your own information.
- Your guardian, where you are a minor, can see and act on your information.
- Your institution's staff can see the students and applications belonging to that institution only. One institution can never see another institution's students, applications, documents or reports.
- Our authorised processing staff can see the applications assigned to them, for the purpose of processing those applications.
- Our administrators can see operational data for support, quality and audit.
Every access to a document or a stored credential is logged with the identity of the person, the time and the reason.
8. Documents and portal credentials
Documents are stored in private storage that is not reachable from the public internet. No permanent link to a document exists. When an authorised person opens a document, the platform issues a link that is signed, tied to that person and expires within minutes.
Some authorities operate portals with no application programming interface and no delegated-access mechanism. Completing an application on such a portal requires signing in as you. If you choose to let us do that:
- You must give separate, explicit consent before any credential is stored.
- The credential is encrypted with AES-256-GCM. It is never stored in plain text and never written to any log.
- One-time passcodes are never stored. If a portal sends an OTP, you supply it at the moment it is needed.
- Every access is recorded, and you are notified by email each time your credentials are used.
- You can revoke access or delete the credential at any time from your account.
- Credentials are automatically deleted once the application reaches a final state, or after the retention period set by the platform administrator, whichever comes first.
You are never required to share a portal password to use WorkSathi. We will never ask you for your banking password, UPI PIN, card CVV or a payment OTP.
9. How long we keep information
| Category | Retention |
|---|---|
| Account and student profile | While the account is active, then up to 24 months |
| Guardian consent records | For as long as the related application record is kept |
| Application records and timeline | 7 years, as evidence of what was submitted and when |
| Documents | Until the application concludes, then up to 24 months unless you delete them sooner |
| Portal credentials | Until the application concludes or the administrator's retention window expires, whichever is sooner |
| Audit logs | 7 years, unaltered |
| Payment records | As required by applicable tax and accounting rules |
10. Your rights, and how to use them
Under the DPDP Act you may:
- Access the information we hold about you, and the consents you have given.
- Correct anything inaccurate, incomplete or out of date.
- Erase your personal data where it is no longer needed for the purpose it was collected for.
- Withdraw consent for further processing.
- Nominate another person to exercise these rights if you are unable to.
- Complain to us, and then to the Data Protection Board of India if we do not resolve it.
To have your data deleted, write to info.worksathi@gmail.com from the email address on your account, or ask our support team. Tell us your name and registered mobile number. We will confirm your identity, act within 30 days, and write back to tell you exactly what was deleted and what had to be kept.
Some records — audit logs, submitted application history and tax records — cannot be deleted on request, because their whole purpose is to be an unalterable record, and because the law requires us to retain them. We will always tell you when this applies and why.
11. Security
The controls we have implemented include: role-based access control; strict tenant isolation enforced at the query layer; encryption in transit; application-level encryption of stored credentials with AES-256-GCM; password hashing with bcrypt; mandatory two-step verification for administrator accounts; private document storage with short-lived signed access; IP-based lockout after repeated failed sign-ins; rate limiting; and an append-only audit log.
No system is immune to compromise. If a breach affects your information, we will notify affected users and the Data Protection Board of India without undue delay, and publish what we know and what we are doing about it.
12. Third parties who process data for us
They receive only what is necessary for their function, are bound to use it for nothing else, and never receive your documents unless the function requires it:
| Provider | What they handle |
|---|---|
| Fast2SMS | Your mobile number and the text of the SMS sent to you |
| SMTP email provider | Your email address and the content of the email sent to you |
| Cashfree Payments | Payment amount, reference and the details you enter on their own secure page |
| Hosting provider | The servers and database on which the platform runs, located in India |
We do not transfer your personal data outside India for any purpose other than the operation of these services.
13. Grievance redressal
If you are unhappy with how your personal data has been handled, or with any response you have received:
- Write to our Grievance Officer at info.worksathi@gmail.com. Please describe the issue and include your registered mobile number.
- We will acknowledge your complaint and respond within 30 days, as required under the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- If you remain dissatisfied, you may escalate to the Data Protection Board of India.
14. Changes
We will post any change to this policy on this page with a new effective date. Where a change is significant, we will notify account holders directly.
15. Contact
info.worksathi@gmail.com, the support address on our contact page, or our support team — whichever is easiest for you.
This policy is strictly enforced. If anything here is unclear, please contact our support team.
