Privacy Policy
Version 1.0 · In force from 16 August 2026
This Privacy Policy is issued by Devoic Skilltech & Consultancy Private Limited, a company incorporated under the Companies Act, 2013, bearing Corporate Identity Number U70200MP2025PTC076786 and having its registered office at A64, Bus Stand, Semariya Chowk, Satna, Madhya Pradesh 485001, India (the "Company", "we", "us"), in respect of the website at onramp.in and the services made available through it (the "Platform").
It is issued in accordance with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Information Technology Act, 2000 and the rules made thereunder. For the purposes of the DPDP Act, the Company is the Data Fiduciary and you are the Data Principal: we determine the purpose and means of processing your personal data, and we are answerable to you for it.
This Policy is written in clear and plain language as required by section 5(3) of the DPDP Act. Please read clause 1 in particular.
1. Notice: the Platform is a public record
1.1. Material you publish on the Platform is published to the public. Your profile, your projects, your Proof Score, your leaderboard placement, the challenges you have entered and, once submissions close, the work you have submitted, are accessible to any person without an account.
1.2. Such material may be indexed by search engines, and may be cached, copied or archived by third parties over whom the Company exercises no control. Upon deletion the Company can remove material from the Platform; it cannot procure its removal from the systems of such third parties.
1.3. This is the intended operation of the Platform: a publicly verifiable record of work is what makes it of value to the organisations you wish to be discovered by. You should nevertheless proceed on the footing that anything you publish here is permanently public, and you should not publish anything confidential, anything belonging to another person, or anything you would not wish a stranger, a recruiter or your institution to read.
1.4. Browsing the Platform requires no account and no personal data whatsoever. Only participation does.
2. Consent and lawful basis
2.1. We process personal data on the basis of your consent, given at the point of account creation and at the point at which you elect to publish any material, and on the basis of such legitimate uses as are specified in section 7 of the DPDP Act, including compliance with law.
2.2. Your consent is limited to the purposes enumerated at clause 4. We do not process your personal data for any purpose not stated in this Policy.
2.3. You may withdraw your consent at any time, in the manner set out at clause 8. The consequence of withdrawal is that we can no longer maintain your account or publish your work, and the account will be deleted.
3. Categories of personal data processed
3.1. Account data. Your email address; your password, retained solely as a Scrypt hash and not recoverable by any person; whether your email address has been confirmed; one-time verification codes, retained in hashed form and valid for fifteen (15) minutes; and session and refresh tokens.
3.2. Profile data. Username, name and profile image; account type; for students, institution, branch and year of study; for organisations, organisation name, website and contact particulars; and any biographical note you provide.
3.3. Work and activity data. Projects published by you; challenges joined and the dates thereof; submissions, including descriptions, repository, demonstration and video links, and the history of earlier versions where a submission has been revised; reviews, shortlisting and outcomes recorded by organisations; upvotes, comments and endorsements given or received; and your Proof Score together with the itemised record of events affecting it.
3.4. Usage data. Where a signed-in user opens a project page, the project, the viewing account and the time are recorded, so that the author may see that their work is being viewed. Short-lived counters of actions per account or email address are maintained for the prevention of automated abuse. Notifications issued to you, your notification preferences and any muted challenges are retained.
3.5. Push notification data. Where you enable push notifications, the subscription issued by your browser — comprising an endpoint address, two encryption keys and your browser's user-agent string — is retained so that your devices may be distinguished. Such records are removed automatically upon an endpoint ceasing to function. Push notifications are optional and are disabled until enabled by you.
3.6. Academy and waitlist data. Name, email address and telephone number; cohort, price tier, amount paid and payment status; and any event or referral code applied.
3.7. Verification data. Any document furnished by you in support of a request for student or organisation verification, and the status of that request. Such documents are seen only by personnel of the Company assessing the request, are not published, and are deleted upon the request being determined.
3.8. Payment data is not processed by the Company. Card, UPI and bank particulars are collected and processed entirely by our payment gateway. We receive the outcome of a transaction and no more.
4. Purposes of processing
| Purpose | Categories relied upon |
|---|---|
| Operation of your account, including authentication, email confirmation and password reset | 3.1 |
| Publication of your work, profile and Proof Score, being the service contracted for | 3.2, 3.3 |
| Conduct of challenges, including receipt and assessment of submissions by organisations | 3.3 |
| Notification of matters concerning your submissions, challenges and deadlines, through channels enabled by you | 3.4, 3.5 |
| Maintenance of the integrity of the record, including rate limiting, prevention of abuse and verification | 3.4, 3.7 |
| Enrolment in, payment for and conduct of Academy programmes | 3.6 |
| Compliance with legal obligations, including taxation and lawful requests | as applicable |
5. Processing we do not undertake
5.1. The Company does not: (a) display advertising or deploy advertising trackers upon the Platform; (b) employ third-party analytics, session recording or heat-mapping of any kind; (c) sell personal data, or disclose it to data brokers; (d) employ cookies for tracking or advertising, the authentication token being retained in the browser's local storage and used for no purpose other than maintaining a session; or (e) send marketing communications which have not been requested.
6. Disclosure
6.1. To the public, in the manner described at clause 1.
6.2. To organisations conducting challenges. Upon entering a challenge, the organisation conducting it is given access to your profile and, upon the closure of submissions, to your submitted work. Such organisation is independently responsible for its subsequent handling of that data.
6.3. To data processors. The Company engages the following processors, each of which acts upon the Company's instructions only:
| Processor | Function |
|---|---|
| Convex | Database and application backend |
| Vercel | Website hosting and content delivery |
| Resend, employing Amazon Simple Email Service | Transmission of verification, reset and notification email |
| The push service of your browser vendor, being Google, Apple or Mozilla as applicable | Delivery of push notifications, where enabled |
| Cashfree Payments | Processing of payments for Academy programmes |
6.4. As required by law, or for the establishment, exercise or defence of a legal claim. Where permitted to do so, we shall inform you.
7. Transfer outside India
7.1. The processors named at clause 6.3 operate infrastructure situated outside India, and electronic mail is transmitted through a region situated in Japan. Personal data is accordingly transferred outside India in the ordinary course of operating the Platform.
7.2. Section 16 of the DPDP Act permits such transfer save to territories restricted by notification of the Central Government. The Company shall cease transfers to any territory so restricted.
8. Rights of the Data Principal
8.1. Under sections 11 to 14 of the DPDP Act you have the right to: (a) obtain a summary of the personal data processed and of the processing activities undertaken; (b) obtain correction of inaccurate or misleading data, completion of incomplete data, and updating of data; (c) obtain erasure of your personal data, save where retention is required by law; (d) withdraw consent, with the consequence stated at clause 2.3; (e) nominate a person to exercise these rights in the event of your death or incapacity; and (f) have recourse to the grievance mechanism at clause 11.
8.2. Exercise of rights. A request shall be made by electronic mail to support@onramp.in from the address associated with the account, stating the right relied upon.
8.3. Manner of compliance. Much of the right at clause 8.1(b) may be exercised directly by editing your profile. The Company does not presently provide a facility for self-service deletion; requests under clause 8.1(c) and 8.1(d) are accordingly given effect manually. Requests are acknowledged within seven (7) working days and completed within thirty (30) days.
8.4. Limitations upon erasure. (a) Copies retained by search engines, archives and other third parties may persist notwithstanding erasure by the Company, for the reason stated at clause 1.2; upon request the Company shall advise you how such third parties may be approached. (b) Where an organisation has conducted a challenge and recorded an outcome, the Company retains the fact of that outcome in a form which does not identify you, so that the record of the challenge remains coherent.
9. Retention
| Category | Period of retention |
|---|---|
| Account and profile data | Until deletion of the account, and erased within thirty (30) days thereafter |
| Published work | Until deleted by you, or until deletion of the account |
| One-time verification codes | Fifteen (15) minutes |
| Rate-limiting counters | One (1) hour |
| Push subscriptions | Until disabled by you, or until the endpoint ceases to function |
| Verification documents | Until the request is determined |
| Payment and enrolment records | Such period as taxation and accounting law requires, presently eight (8) years |
10. Security safeguards
10.1. The Company adopts reasonable security safeguards within the meaning of section 8(5) of the DPDP Act, including: retention of passwords as Scrypt hashes and in no recoverable form; retention of one-time codes in hashed form, with expiry after fifteen (15) minutes and rate limiting against both guessing and repeated issuance; encryption of all traffic in transit; enforcement of access control upon the Company's servers rather than in the browser, such that it cannot be circumvented by direct calls to the Company's interfaces; and restriction of access to production data to personnel requiring it.
10.2. No system is capable of being rendered perfectly secure, and the Company makes no representation to the contrary. In the event of a personal data breach the Company shall give intimation to the Data Protection Board of India and to each affected Data Principal, as section 8(6) of the DPDP Act requires.
11. Grievance redressal
11.1. A Data Principal aggrieved by the Company's handling of their personal data may address the Grievance Officer appointed under section 13 of the DPDP Act.
| Grievance Officer | Shivam Singh |
| Company | Devoic Skilltech & Consultancy Private Limited |
| Address | A64, Bus Stand, Semariya Chowk, Satna, Madhya Pradesh 485001, India |
| support@onramp.in |
11.2. Grievances shall be acknowledged within seven (7) working days and responded to substantively within thirty (30) days of receipt.
11.3. A Data Principal not satisfied with the response may make a complaint to the Data Protection Board of India.
12. Children
12.1. Accounts upon the Platform are available only to persons aged eighteen (18) years and above.
12.2. Section 9 of the DPDP Act confers specific protections upon persons below the age of eighteen, including a requirement of verifiable consent of a parent or lawful guardian and a prohibition upon tracking, behavioural monitoring and targeted advertising directed at them. Rather than implement those protections partially, the Company has set the age for holding an account at eighteen. This is consistent with clause 2.2 of the Terms of Use, participation involving prizes, payments and undertakings requiring capacity to contract.
12.3. Persons of any age may browse the Platform freely and without an account, such browsing involving no processing of personal data.
12.4. Upon becoming aware that an account is held by a person below the age of eighteen, the Company shall delete that account and the personal data associated with it. Such accounts may be reported to support@onramp.in.
13. Amendment
13.1. The Company may amend this Policy. Where an amendment materially affects Data Principals, notice shall be given by electronic mail and by publication upon the Platform prior to the amendment taking effect. The version and date stated at the head of this Policy reflect the text presently in force.
14. Contact
| Entity | Devoic Skilltech & Consultancy Private Limited |
| CIN | U70200MP2025PTC076786 |
| Registered office | A64, Bus Stand, Semariya Chowk, Satna, Madhya Pradesh 485001, India |
| support@onramp.in |