Privacy Policy

Last updated: July 7, 2026

This Privacy Policy explains how Stellarnet Technologies Pvt Ltd (“Stellarnet”, “we”) collects and processes personal data through the Stellarnet platform. It is written to meet the requirements of India’s Digital Personal Data Protection Act, 2023 (DPDP) and the EU/UK General Data Protection Regulation (GDPR) where applicable.

1. Roles: Controller vs. Processor

  • Administrators (our Customers): for admin account data we act as the data fiduciary/controller.
  • Candidates:candidate data is uploaded and controlled by the Customer organization running the assessment. For that data the Customer is the controller and Stellarnet is the processor, acting on the Customer’s instructions. Candidates should direct rights requests to the organization that invited them, and we will assist that organization in fulfilling them.

2. Data We Collect

  • Admin accounts: name, work email address, profile image (from Google or Microsoft SSO), and organization domain.
  • Candidates: name (provided by the Customer), a generated username, exam responses, scores, timing data, and integrity telemetry.
  • Proctoring streams:live camera and microphone streams are relayed in real time to the Customer’s authorized proctors. We do not record, store, or retain audio or video. No recording function exists in the Service.
  • Proctoring logs:we store event metadata only — event type (e.g., tab switch, full-screen exit) and timestamp — linked to the candidate’s attempt. These logs contain no audio, video, images, or keystroke content.
  • Technical data: IP addresses (for rate limiting and security), and standard server logs retained for a limited period.

3. How We Use Data

  • To operate assessments: authentication, timing, autosave, grading, and results.
  • To provide integrity oversight the Customer has configured (live proctoring, violation logging).
  • To secure the Service: rate limiting, abuse prevention, audit trails.
  • To communicate with administrators about their account and the Service.
  • We do not sell personal data, use candidate data for advertising, or train models on Customer Data.

4. Legal Bases (GDPR) / Grounds (DPDP)

  • Performance of contract — providing the Service to Customers.
  • Legitimate interests — securing the platform and preventing fraud.
  • Consent — where required for proctoring, obtained by the Customer from candidates before the assessment; the pre-exam system check also gives candidates clear notice that camera and microphone remain active during the exam.

5. Storage, Security & Sub-processors

  • Candidate passwords are stored only as bcrypt hashes; plaintext is shown once to the issuing administrator and never stored.
  • Data is encrypted in transit (TLS). Tenants are logically isolated by organization.
  • Sub-processors: Vercel (hosting), Neon (database), LiveKit (real-time media relay — no storage), Google/Microsoft (SSO), Razorpay (payments), Resend (transactional email, if enabled). Each processes data only as needed for its function.

6. Retention

  • Proctoring A/V: not retained (never stored).
  • Proctoring event logs, responses, and scores: retained while the Customer’s Tenant is active, so results remain auditable.
  • On Tenant termination, data is deleted within [30/60/90] days except where law requires longer retention.
  • Customers may delete individual exams (and their candidate data) at any time from the dashboard.

7. Your Rights

Depending on your jurisdiction you may have rights to access, correct, delete, or port your personal data, to object to or restrict processing, and to complain to a supervisory authority (including the Data Protection Board of India under the DPDP Act). Admins may exercise rights by emailing us; candidates should contact the organization that ran their assessment, and we will support that organization’s response.

8. International Transfers

Our infrastructure providers may process data in regions outside your country. Where GDPR applies, transfers rely on appropriate safeguards such as Standard Contractual Clauses implemented by our sub-processors.

9. Children

The Service is intended for professional and higher-education assessment. If a Customer assesses candidates below the age of digital consent in their jurisdiction, the Customer is responsible for obtaining verifiable parental/guardian consent as required by law.

10. Contact & Grievance Officer

Data protection queries: hello@stellarnettech.com. Grievance Officer (DPDP/IT Act): [NAME], [ADDRESS], [PHONE]. We aim to acknowledge grievances within 72 hours and resolve them within statutory timelines.

11. Changes

We will notify Customers of material changes to this Policy at least 14 days before they take effect.

Questions? Contact hello@stellarnettech.com or visit our contact page.