Privacy Policy
Comprehensive Disclosure on Data Protection, CERT-In Directives, DPDPA & GDPR Compliance
1.0 Introduction & Data Fiduciary Scope
Reason Orbit operates as a Data Fiduciary and Controller under the Digital Personal Data Protection Act, 2023 (India) and Regulation (EU) 2016/679 (GDPR). We collect and process personal data exclusively to facilitate peer education and document research.
2.0 Categories of Personal Data Collected
We collect account identity information (name, email address, cryptographic password hash), profile preferences (skills you can teach, skills you want to learn), and system telemetry strictly required for platform security.
3.0 Lawful Grounds & Purpose of Processing
Processing is conducted under explicit contractual necessity, user consent, and legitimate compliance with statutory directives. We do not sell user data, engage in cross-site behavioral tracking, or profile users for advertising.
4.0 Cookie Inventory & Tracking Technologies
We utilize strictly necessary session cookies for authentication, CSRF defense, and interface preferences. Analytical cookies require affirmative user consent through our consent manager.
5.0 CERT-In Cybersecurity Directives & Incident Reporting
In compliance with Indian CERT-In directions under Section 70B of the IT Act, connection logs, user access timestamps, and firewall telemetry are retained securely for a mandatory 180-day period within encrypted environments.
6.0 Statutory Data Subject Rights
Users retain full rights to access, rectify, restrict, and erase their personal data under DPDPA and GDPR. To exercise any data right, submit a request to our Data Protection team at support@reasonorbit.com.
7.0 Data Protection Inquiries
Direct privacy questions and compliance correspondence to support@reasonorbit.com.