Privacy Policy
Last updated: 8 August 2026
This Privacy Policy explains how Scholaris Private Limited ("Scholaris", "Kairo", "we", "us", "our") collects, uses, shares, protects, and retains your personal data when you use Kairo at kairo.scholaris.co.in (the "Service").
Kairo is a paid online psychometric career-assessment for students. We take your privacy seriously and have written this policy to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under it, and the Consumer Protection Act, 2019, and to meet global best practice (including GDPR-style transparency, lawful-basis, rights, retention, transfer, and breach-notification standards).
Please read this policy together with our Terms of Service, Your Data Rights page, and Grievance Redressal page.
1. Who we are (Data Fiduciary) and how to contact us
Scholaris Private Limited (formerly Chasmis Solutions Private Limited until 15 September 2025) is the Data Fiduciary responsible for your personal data under the DPDP Act. It decides why and how your personal data is processed.
- Company: Scholaris Private Limited
- Registered office: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
- CIN: U85500MH2018PTC318097
Data Protection Officer and Grievance Officer
For any privacy question, request, or complaint, contact:
- Data Protection Officer & Grievance Officer: Bharat Bohra
- Alternate contact: Narendra Purohit
- Email: support@scholaris.co.in
- Phone: +91 9833861909
- Postal address: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
You can reach the same office to exercise any of your rights (Section 9), raise a grievance (Section 14), or ask anything about this policy.
2. Scope and who can use Kairo
Kairo is designed for students in India, typically aged about 14 to 25, and the user base includes minors (anyone under 18 years of age). Because of this, we apply heightened protections for children's data — see Section 10.
This policy applies to all personal data we process about:
- Users who register for, pay for, and take the assessment; and
- Parents or legal guardians who provide verifiable consent on behalf of a minor, and whose contact and consent details we record.
3. The personal data we collect — and why (data inventory)
We collect only the data we need to deliver the Service. The table below is the authoritative summary of what we collect, why, the legal basis under the DPDP Act, and how long we keep it.
| Category of data | What it includes | Why we process it (purpose) | Legal basis (DPDP Act) | Retention |
|---|---|---|---|---|
| Identity & contact | Name, email address, phone number, age / date of birth, city, education stage, stream of study | Create your account; deliver the assessment and report; verify eligibility; send transactional messages; provide support; account recovery | Consent; performance of contract | Up to 3 years from your most recent report, then deleted or anonymised (see Section 8) |
| Parental / guardian consent records (minors) | Guardian's name and contact, consent flag, consent timestamp, relationship to the child | Obtain and evidence verifiable parental consent before processing a minor's data, as required by the DPDP Act | Consent (parental); legal obligation | For the life of the child's account + a reasonable period to evidence consent; then deleted/anonymised with the account |
| Assessment responses | Your answers across the assessment dimensions, including any adaptive follow-up answers, and any specific career interests you mention | Generate your psychometric scores and personalised report; support retake comparison (where offered) | Consent; performance of contract | Up to 3 years, then deleted/anonymised |
| Response metadata (paradata) | Per-question response timing, answer-changes/revisions before submit, blur/focus events, basic session-activity patterns | Ensure report quality and validity (e.g., profile-clarity and bias signals); detect rushed or anomalous submissions; prevent abuse | Consent; legitimate use (quality & fraud prevention) | Up to 3 years, then deleted/anonymised |
| Derived psychometric data | Your computed archetype, career-family fit scores, and other derived indicators | The core output you pay for | Performance of contract | Up to 3 years, then deleted/anonymised |
| AI-generated report | Your personalised report; and, for eligible tiers, a parent-facing PDF (the PDF itself is generated on your device and not stored on our servers beyond a "generated-at" timestamp) | Deliver the result of the assessment to you | Performance of contract | Up to 3 years, then deleted/anonymised |
| Chatbot transcripts (where the feature is enabled for your tier) | The conversation you have with the in-product career chatbot | Provide the optional chatbot feature; safety and abuse review | Consent | 90 days after the chat window for your account closes, then deleted |
| Payment metadata | Razorpay order ID, payment ID, amount, status, and the email/phone used for the receipt. No card, UPI, or bank-credential data ever touches our servers — Razorpay handles that directly. | Take and reconcile payment; issue receipts; process refunds; meet statutory financial-record duties | Performance of contract; legal obligation | Up to 7 years for the financial record (tax/company law); identifying fields minimised/redacted where the law allows once no longer needed |
| Authentication data | Email-verification OTP codes and attempt counts (short-lived). Phone number is collected but currently not SMS-verified (see note below). | Verify your email; protect your account; rate-limit abuse | Performance of contract; legitimate use (security) | OTP codes expire within minutes (held transiently); phone retained with your identity data per the rows above |
| Technical & security data | IP address, device/browser information, rate-limit counters, and error diagnostics (with your email represented only as a one-way hash in error logs) | Render the Service, debug, secure the platform, prevent fraud and abuse | Legitimate use (security & service integrity) | Transient to short-term; error diagnostics retained only as long as needed to investigate |
| Coarse analytics | Aggregated, non-identifying usage signals (e.g., funnel/completion counts) | Understand and improve the Service in aggregate | Legitimate use | Aggregate only; no third-party advertising trackers are used |
| Safety / crisis-detection flags | Flags raised if assessment or chatbot content suggests a user may be at risk | Protect the safety and wellbeing of the user; respond appropriately | Legal obligation; legitimate use (vital interests / safety) | Retained only as long as necessary for the safety purpose |
| Anonymised aggregate data | De-identified, aggregated scores with no name, email, or phone | Improve and validate the assessment methodology | Not personal data once anonymised | May be retained indefinitely in anonymised form |
Note on your phone number. We collect your phone number for contact, account recovery, and future verification. We do not currently verify it by SMS one-time-password. SMS verification (and any SMS messaging) is planned for a later release, only after we complete the required DLT registration in India, and would then be used solely with your consent and in line with applicable telecom rules.
We do not intentionally collect special/sensitive categories of data (such as health, biometric, religious, or caste data). Please do not enter such information in free-text fields or in the chatbot.
4. How we collect your data
- Directly from you — when you register, pay, take the assessment, generate a report or PDF, or use the chatbot.
- From your parent or guardian — when, for a minor, a guardian provides verifiable consent and their contact details.
- Automatically — technical data (IP, device/browser), paradata, and rate-limit/security signals generated as you use the Service. We store assessment progress locally on your device (see Section 12) so you can resume.
- From our payment processor — payment status/metadata from Razorpay (never your card or bank details).
5. How we use your data (purposes)
Primary purposes (to deliver what you paid for):
- Create and manage your account and verify your email.
- Deliver the assessment, compute your scores, and generate your personalised report (and parent PDF, where applicable).
- Provide optional features such as retake comparison and the chatbot, where available for your tier.
- Take, reconcile, and refund payments, and issue receipts.
- Communicate with you about your report, account, payment, and support requests.
Secondary purposes (carefully limited):
- Protect the Service against fraud, abuse, and security threats.
- Maintain report quality and methodology validity, including via paradata signals and, separately, anonymised aggregated data only for methodology improvement.
- Meet our legal, regulatory, tax, and accounting obligations.
- Respond to lawful requests and protect the safety of users (including acting on crisis-detection flags).
6. What we do NOT do
- We do not sell or rent your personal data to anyone.
- We do not run third-party advertising networks, ad cookies, or cross-site tracking.
- We do not share your individual report, answers, or transcripts with advertisers, schools, employers, or your parents — except, for minors, with the consenting guardian, or where you have given permission, or where the law requires it.
- We do not allow our AI sub-processor to train its models on your personal data; we send prompts only to generate your report/answers and instruct that the data is not used for training, consistent with the provider's terms.
- We do not make automated decisions that have legal or similarly significant effects on you. Your report is exploratory guidance, not an automated decision about your future. It is intended to support reflection and conversation, and is presented with human-meaningful framing — it does not, by itself, determine any outcome for you.
7. Who we share data with (sub-processors and international transfers)
To run Kairo we use a small set of carefully chosen service providers ("Data Processors" / sub-processors). They process your data only on our instructions, only to the extent necessary for their function, and under data-processing agreements that require appropriate confidentiality and security. Some of them may process or store data outside India; where that happens we rely on the transfer mechanisms permitted under the DPDP Act and apply appropriate contractual and technical safeguards.
| Sub-processor | Function | Data involved | Location / transfer note |
|---|---|---|---|
| Cloudflare | Edge hosting, request routing, security/WAF, edge Worker, transient OTP & rate-limit storage | In-flight request data; transient OTPs and counters | Global edge network; may process data outside India under safeguards |
| Supabase | Primary database and authentication backend | Structured user data per Section 3 | Hosted in EU and/or US regions; international transfer under safeguards |
| Anthropic (Claude AI) | Generates the AI report and adaptive questions, and powers the chatbot | The assessment payload needed to generate output (minimised; no card data); prompts are sent to generate your result and are not used to train models per the provider's terms | May be processed outside India under safeguards |
| Resend | Transactional email delivery (e.g., verification, receipts, notices) | Email address and message content/variables | May process data outside India under safeguards |
| Razorpay | Payment processing | Email, phone, amount, order/payment IDs (card/UPI/bank data handled by Razorpay, not us) | India |
| MSG91 (future) | SMS delivery for OTP and notifications (planned, after DLT registration) | Phone number and message content | India |
Each sub-processor has its own privacy policy. We review our sub-processors and keep this list current; material changes are reflected here and, where significant, communicated to registered users.
We may also disclose personal data where required by law, to respond to a valid legal process, to enforce our Terms, to prevent fraud or imminent harm, or in connection with a corporate transaction (in which case this policy or an equally protective one will continue to apply).
8. How long we keep your data (retention schedule)
We keep personal data only as long as necessary for the purposes above or as required by law. Our standard schedule:
- Assessment data, paradata, derived scores, and the AI report: retained for up to 3 years from your most recent report, after which it is deleted or irreversibly anonymised by an automated sweep that runs daily.
- Account / identity & contact data: retained while your account is active and up to the 3-year window above; deleted/anonymised thereafter or on a valid erasure request.
- Parental consent records (minors): kept for the life of the child's account plus a reasonable period to evidence that consent was validly obtained, then deleted/anonymised.
- Chatbot transcripts: deleted 90 days after the chat window for your account closes.
- Payment / financial records: retained for up to 7 years to meet Indian tax and company-law obligations; identifying fields are minimised or redacted where the law permits.
- Authentication OTPs and rate-limit counters: transient, expiring within minutes to the length of the relevant window.
- Anonymised aggregate data: as it is no longer personal data, it may be retained indefinitely for methodology improvement.
You can ask us to delete your data sooner (subject to the legal-retention exceptions above) — see Section 9. Our internal data inventory and erasure cascade are designed so that deleting your core record automatically removes your downstream data (report, chatbot transcripts, and related rows) in a single operation.
9. Your rights (Data Principal rights) and how to exercise them
Under the DPDP Act — and consistent with global data-protection standards — you (the Data Principal) have the following rights. For a minor, these rights are exercised by the parent or legal guardian.
- Right to access — obtain a summary of the personal data we hold about you and how we process it.
- Right to correction and updating — have inaccurate or incomplete data corrected, completed, or updated.
- Right to erasure — have your personal data deleted where it is no longer needed and no legal exception requires us to keep it.
- Right to withdraw consent — withdraw consent for any consent-based processing at any time, as easily as it was given. Withdrawal does not affect processing already carried out, and some features may no longer work without the relevant data.
- Right to grievance redressal — raise a complaint with our Grievance Officer and receive a timely response (Section 14).
- Right to nominate — nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
In addition, reflecting global best practice, you may request data portability (a machine-readable copy of data you provided) and may object to or restrict certain processing; we will honour such requests to the extent applicable law allows.
How to exercise your rights. You have two routes:
- In-product flow — use the in-product controls where available (for example, to discard an in-progress session or request deletion from your account), and the self-service options described on our Your Data Rights page.
- Contact our DPO / Grievance Officer — email support@scholaris.co.in from your registered email, stating the right you wish to exercise and enough detail for us to locate your record. We may need to verify your identity before acting.
Our response times: we acknowledge requests promptly (within 1 business day for grievances) and respond to access/erasure requests within 30 days, and to correction requests within about 14 days. If a request needs more time or cannot be fully met (e.g., a legal-retention exception applies), we will explain why. See the Your Data Rights and Grievance Redressal pages for full details.
10. Children's data (users under 18)
Because Kairo is used by minors, we apply the DPDP Act's heightened protections for children:
- Verifiable parental/guardian consent first. Before we process the personal data of a user we identify as a minor (under 18), we require verifiable consent from a parent or legal guardian, and we record the consent flag and timestamp.
- No detrimental processing. We do not undertake any processing that is likely to cause a detrimental effect on the wellbeing of a child.
- No tracking, profiling, or behavioural monitoring of children, and no targeted advertising directed at children. We never use children's data for ad targeting or behavioural monitoring.
- Exploratory framing. A minor's report is framed as exploration and guidance to support reflection and conversations with parents, teachers, or mentors — never as a fixed verdict about the child.
- Parental access and erasure. A parent or guardian may access the child's data, request correction, withdraw consent, and request erasure at any time using the contacts in Section 1.
If you believe a minor has registered without proper guardian consent, or you are a guardian who wishes to review or remove a child's data, contact support@scholaris.co.in and we will act promptly.
11. Data security
We use reasonable technical and organisational measures to protect your data, including:
- Encryption in transit (TLS) and at rest for personal data.
- Row-Level Security (RLS) and least-privilege access controls so that only authorised systems and personnel can access data, and only what they need.
- Hardening against abuse — rate limiting, bot protection on sensitive actions, and stripping of sensitive headers from error logs (with email represented only as a one-way hash in diagnostics).
- A defined incident-response process and regular review of our security posture and sub-processors.
No method of transmission or storage is perfectly secure, but we work continuously to protect your data and to limit what we collect in the first place.
12. Cookies, local storage, and tracking
Kairo uses only essential and functional browser storage. Specifically:
- Session continuity — keeping you signed in.
- Saving your progress — we use your browser's IndexedDB and localStorage (for example, under a key such as
kairo:progress) so you can resume an in-progress assessment. You can discard this at any time using the in-product "abandon/discard" control, which clears that local data from your device. - Preferences — such as your chosen language.
- Feature configuration cache — to load the correct experience.
We do not use third-party advertising cookies, and we do not track you across other websites. We do not embed Google Analytics, advertising pixels, or similar third-party trackers.
13. Breach notification
If we become aware of a personal-data breach that affects you, we will act quickly to contain and assess it. In line with our commitment and applicable law, we will notify the Data Protection Board of India and affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach, describing (to the extent known) the nature of the breach, the likely consequences, and the measures taken or recommended to mitigate harm.
14. Grievance redressal
If you have any concern about how we handle your data, you can raise it with our Grievance Officer:
- Grievance Officer & Data Protection Officer: Bharat Bohra (alternate: Narendra Purohit)
- Email: support@scholaris.co.in
- Phone: +91 9833861909
- Address: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
Our service levels: we acknowledge within 1 business day and aim to resolve within 15 days (and in any event within the timelines required by the IT Rules and the DPDP Act). Full details, including what to include in a grievance, are on our Grievance Redressal page. Grievances may be filed in English or Hindi.
Escalation. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India (for data-protection matters) or to the appropriate consumer forum under the Consumer Protection Act, 2019, or to the appropriate courts as set out in our Terms of Service.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. If we make material changes, we will notify registered users by email and/or by a prominent notice in the Service before the change takes effect, where required. Your continued use of Kairo after an update means you have read the revised policy.
16. Contact
For any privacy matter, request, or grievance:
Scholaris Private Limited F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India CIN: U85500MH2018PTC318097 Data Protection Officer & Grievance Officer: Bharat Bohra (alternate: Narendra Purohit) Email: support@scholaris.co.in · Phone: +91 9833861909