Skip to main content
Kairo
Log in

Privacy Policy

Last updated: 8 August 2026

This Privacy Policy explains how Scholaris Private Limited ("Scholaris", "Kairo", "we", "us", "our") collects, uses, shares, protects, and retains your personal data when you use Kairo at kairo.scholaris.co.in (the "Service").

Kairo is a paid online psychometric career-assessment for students. We take your privacy seriously and have written this policy to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under it, and the Consumer Protection Act, 2019, and to meet global best practice (including GDPR-style transparency, lawful-basis, rights, retention, transfer, and breach-notification standards).

Please read this policy together with our Terms of Service, Your Data Rights page, and Grievance Redressal page.


1. Who we are (Data Fiduciary) and how to contact us

Scholaris Private Limited (formerly Chasmis Solutions Private Limited until 15 September 2025) is the Data Fiduciary responsible for your personal data under the DPDP Act. It decides why and how your personal data is processed.

  • Company: Scholaris Private Limited
  • Registered office: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India
  • CIN: U85500MH2018PTC318097

Data Protection Officer and Grievance Officer

For any privacy question, request, or complaint, contact:

  • Data Protection Officer & Grievance Officer: Bharat Bohra
  • Alternate contact: Narendra Purohit
  • Email: support@scholaris.co.in
  • Phone: +91 9833861909
  • Postal address: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India

You can reach the same office to exercise any of your rights (Section 9), raise a grievance (Section 14), or ask anything about this policy.


2. Scope and who can use Kairo

Kairo is designed for students in India, typically aged about 14 to 25, and the user base includes minors (anyone under 18 years of age). Because of this, we apply heightened protections for children's data — see Section 10.

This policy applies to all personal data we process about:

  • Users who register for, pay for, and take the assessment; and
  • Parents or legal guardians who provide verifiable consent on behalf of a minor, and whose contact and consent details we record.

3. The personal data we collect — and why (data inventory)

We collect only the data we need to deliver the Service. The table below is the authoritative summary of what we collect, why, the legal basis under the DPDP Act, and how long we keep it.

Category of dataWhat it includesWhy we process it (purpose)Legal basis (DPDP Act)Retention
Identity & contactName, email address, phone number, age / date of birth, city, education stage, stream of studyCreate your account; deliver the assessment and report; verify eligibility; send transactional messages; provide support; account recoveryConsent; performance of contractUp to 3 years from your most recent report, then deleted or anonymised (see Section 8)
Parental / guardian consent records (minors)Guardian's name and contact, consent flag, consent timestamp, relationship to the childObtain and evidence verifiable parental consent before processing a minor's data, as required by the DPDP ActConsent (parental); legal obligationFor the life of the child's account + a reasonable period to evidence consent; then deleted/anonymised with the account
Assessment responsesYour answers across the assessment dimensions, including any adaptive follow-up answers, and any specific career interests you mentionGenerate your psychometric scores and personalised report; support retake comparison (where offered)Consent; performance of contractUp to 3 years, then deleted/anonymised
Response metadata (paradata)Per-question response timing, answer-changes/revisions before submit, blur/focus events, basic session-activity patternsEnsure report quality and validity (e.g., profile-clarity and bias signals); detect rushed or anomalous submissions; prevent abuseConsent; legitimate use (quality & fraud prevention)Up to 3 years, then deleted/anonymised
Derived psychometric dataYour computed archetype, career-family fit scores, and other derived indicatorsThe core output you pay forPerformance of contractUp to 3 years, then deleted/anonymised
AI-generated reportYour personalised report; and, for eligible tiers, a parent-facing PDF (the PDF itself is generated on your device and not stored on our servers beyond a "generated-at" timestamp)Deliver the result of the assessment to youPerformance of contractUp to 3 years, then deleted/anonymised
Chatbot transcripts (where the feature is enabled for your tier)The conversation you have with the in-product career chatbotProvide the optional chatbot feature; safety and abuse reviewConsent90 days after the chat window for your account closes, then deleted
Payment metadataRazorpay order ID, payment ID, amount, status, and the email/phone used for the receipt. No card, UPI, or bank-credential data ever touches our servers — Razorpay handles that directly.Take and reconcile payment; issue receipts; process refunds; meet statutory financial-record dutiesPerformance of contract; legal obligationUp to 7 years for the financial record (tax/company law); identifying fields minimised/redacted where the law allows once no longer needed
Authentication dataEmail-verification OTP codes and attempt counts (short-lived). Phone number is collected but currently not SMS-verified (see note below).Verify your email; protect your account; rate-limit abusePerformance of contract; legitimate use (security)OTP codes expire within minutes (held transiently); phone retained with your identity data per the rows above
Technical & security dataIP address, device/browser information, rate-limit counters, and error diagnostics (with your email represented only as a one-way hash in error logs)Render the Service, debug, secure the platform, prevent fraud and abuseLegitimate use (security & service integrity)Transient to short-term; error diagnostics retained only as long as needed to investigate
Coarse analyticsAggregated, non-identifying usage signals (e.g., funnel/completion counts)Understand and improve the Service in aggregateLegitimate useAggregate only; no third-party advertising trackers are used
Safety / crisis-detection flagsFlags raised if assessment or chatbot content suggests a user may be at riskProtect the safety and wellbeing of the user; respond appropriatelyLegal obligation; legitimate use (vital interests / safety)Retained only as long as necessary for the safety purpose
Anonymised aggregate dataDe-identified, aggregated scores with no name, email, or phoneImprove and validate the assessment methodologyNot personal data once anonymisedMay be retained indefinitely in anonymised form

Note on your phone number. We collect your phone number for contact, account recovery, and future verification. We do not currently verify it by SMS one-time-password. SMS verification (and any SMS messaging) is planned for a later release, only after we complete the required DLT registration in India, and would then be used solely with your consent and in line with applicable telecom rules.

We do not intentionally collect special/sensitive categories of data (such as health, biometric, religious, or caste data). Please do not enter such information in free-text fields or in the chatbot.


4. How we collect your data

  • Directly from you — when you register, pay, take the assessment, generate a report or PDF, or use the chatbot.
  • From your parent or guardian — when, for a minor, a guardian provides verifiable consent and their contact details.
  • Automatically — technical data (IP, device/browser), paradata, and rate-limit/security signals generated as you use the Service. We store assessment progress locally on your device (see Section 12) so you can resume.
  • From our payment processor — payment status/metadata from Razorpay (never your card or bank details).

5. How we use your data (purposes)

Primary purposes (to deliver what you paid for):

  • Create and manage your account and verify your email.
  • Deliver the assessment, compute your scores, and generate your personalised report (and parent PDF, where applicable).
  • Provide optional features such as retake comparison and the chatbot, where available for your tier.
  • Take, reconcile, and refund payments, and issue receipts.
  • Communicate with you about your report, account, payment, and support requests.

Secondary purposes (carefully limited):

  • Protect the Service against fraud, abuse, and security threats.
  • Maintain report quality and methodology validity, including via paradata signals and, separately, anonymised aggregated data only for methodology improvement.
  • Meet our legal, regulatory, tax, and accounting obligations.
  • Respond to lawful requests and protect the safety of users (including acting on crisis-detection flags).

6. What we do NOT do

  • We do not sell or rent your personal data to anyone.
  • We do not run third-party advertising networks, ad cookies, or cross-site tracking.
  • We do not share your individual report, answers, or transcripts with advertisers, schools, employers, or your parents — except, for minors, with the consenting guardian, or where you have given permission, or where the law requires it.
  • We do not allow our AI sub-processor to train its models on your personal data; we send prompts only to generate your report/answers and instruct that the data is not used for training, consistent with the provider's terms.
  • We do not make automated decisions that have legal or similarly significant effects on you. Your report is exploratory guidance, not an automated decision about your future. It is intended to support reflection and conversation, and is presented with human-meaningful framing — it does not, by itself, determine any outcome for you.

7. Who we share data with (sub-processors and international transfers)

To run Kairo we use a small set of carefully chosen service providers ("Data Processors" / sub-processors). They process your data only on our instructions, only to the extent necessary for their function, and under data-processing agreements that require appropriate confidentiality and security. Some of them may process or store data outside India; where that happens we rely on the transfer mechanisms permitted under the DPDP Act and apply appropriate contractual and technical safeguards.

Sub-processorFunctionData involvedLocation / transfer note
CloudflareEdge hosting, request routing, security/WAF, edge Worker, transient OTP & rate-limit storageIn-flight request data; transient OTPs and countersGlobal edge network; may process data outside India under safeguards
SupabasePrimary database and authentication backendStructured user data per Section 3Hosted in EU and/or US regions; international transfer under safeguards
Anthropic (Claude AI)Generates the AI report and adaptive questions, and powers the chatbotThe assessment payload needed to generate output (minimised; no card data); prompts are sent to generate your result and are not used to train models per the provider's termsMay be processed outside India under safeguards
ResendTransactional email delivery (e.g., verification, receipts, notices)Email address and message content/variablesMay process data outside India under safeguards
RazorpayPayment processingEmail, phone, amount, order/payment IDs (card/UPI/bank data handled by Razorpay, not us)India
MSG91 (future)SMS delivery for OTP and notifications (planned, after DLT registration)Phone number and message contentIndia

Each sub-processor has its own privacy policy. We review our sub-processors and keep this list current; material changes are reflected here and, where significant, communicated to registered users.

We may also disclose personal data where required by law, to respond to a valid legal process, to enforce our Terms, to prevent fraud or imminent harm, or in connection with a corporate transaction (in which case this policy or an equally protective one will continue to apply).


8. How long we keep your data (retention schedule)

We keep personal data only as long as necessary for the purposes above or as required by law. Our standard schedule:

  • Assessment data, paradata, derived scores, and the AI report: retained for up to 3 years from your most recent report, after which it is deleted or irreversibly anonymised by an automated sweep that runs daily.
  • Account / identity & contact data: retained while your account is active and up to the 3-year window above; deleted/anonymised thereafter or on a valid erasure request.
  • Parental consent records (minors): kept for the life of the child's account plus a reasonable period to evidence that consent was validly obtained, then deleted/anonymised.
  • Chatbot transcripts: deleted 90 days after the chat window for your account closes.
  • Payment / financial records: retained for up to 7 years to meet Indian tax and company-law obligations; identifying fields are minimised or redacted where the law permits.
  • Authentication OTPs and rate-limit counters: transient, expiring within minutes to the length of the relevant window.
  • Anonymised aggregate data: as it is no longer personal data, it may be retained indefinitely for methodology improvement.

You can ask us to delete your data sooner (subject to the legal-retention exceptions above) — see Section 9. Our internal data inventory and erasure cascade are designed so that deleting your core record automatically removes your downstream data (report, chatbot transcripts, and related rows) in a single operation.


9. Your rights (Data Principal rights) and how to exercise them

Under the DPDP Act — and consistent with global data-protection standards — you (the Data Principal) have the following rights. For a minor, these rights are exercised by the parent or legal guardian.

  • Right to access — obtain a summary of the personal data we hold about you and how we process it.
  • Right to correction and updating — have inaccurate or incomplete data corrected, completed, or updated.
  • Right to erasure — have your personal data deleted where it is no longer needed and no legal exception requires us to keep it.
  • Right to withdraw consent — withdraw consent for any consent-based processing at any time, as easily as it was given. Withdrawal does not affect processing already carried out, and some features may no longer work without the relevant data.
  • Right to grievance redressal — raise a complaint with our Grievance Officer and receive a timely response (Section 14).
  • Right to nominate — nominate another individual to exercise your rights on your behalf in the event of death or incapacity.

In addition, reflecting global best practice, you may request data portability (a machine-readable copy of data you provided) and may object to or restrict certain processing; we will honour such requests to the extent applicable law allows.

How to exercise your rights. You have two routes:

  1. In-product flow — use the in-product controls where available (for example, to discard an in-progress session or request deletion from your account), and the self-service options described on our Your Data Rights page.
  2. Contact our DPO / Grievance Officer — email support@scholaris.co.in from your registered email, stating the right you wish to exercise and enough detail for us to locate your record. We may need to verify your identity before acting.

Our response times: we acknowledge requests promptly (within 1 business day for grievances) and respond to access/erasure requests within 30 days, and to correction requests within about 14 days. If a request needs more time or cannot be fully met (e.g., a legal-retention exception applies), we will explain why. See the Your Data Rights and Grievance Redressal pages for full details.


10. Children's data (users under 18)

Because Kairo is used by minors, we apply the DPDP Act's heightened protections for children:

  • Verifiable parental/guardian consent first. Before we process the personal data of a user we identify as a minor (under 18), we require verifiable consent from a parent or legal guardian, and we record the consent flag and timestamp.
  • No detrimental processing. We do not undertake any processing that is likely to cause a detrimental effect on the wellbeing of a child.
  • No tracking, profiling, or behavioural monitoring of children, and no targeted advertising directed at children. We never use children's data for ad targeting or behavioural monitoring.
  • Exploratory framing. A minor's report is framed as exploration and guidance to support reflection and conversations with parents, teachers, or mentors — never as a fixed verdict about the child.
  • Parental access and erasure. A parent or guardian may access the child's data, request correction, withdraw consent, and request erasure at any time using the contacts in Section 1.

If you believe a minor has registered without proper guardian consent, or you are a guardian who wishes to review or remove a child's data, contact support@scholaris.co.in and we will act promptly.


11. Data security

We use reasonable technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS) and at rest for personal data.
  • Row-Level Security (RLS) and least-privilege access controls so that only authorised systems and personnel can access data, and only what they need.
  • Hardening against abuse — rate limiting, bot protection on sensitive actions, and stripping of sensitive headers from error logs (with email represented only as a one-way hash in diagnostics).
  • A defined incident-response process and regular review of our security posture and sub-processors.

No method of transmission or storage is perfectly secure, but we work continuously to protect your data and to limit what we collect in the first place.


12. Cookies, local storage, and tracking

Kairo uses only essential and functional browser storage. Specifically:

  • Session continuity — keeping you signed in.
  • Saving your progress — we use your browser's IndexedDB and localStorage (for example, under a key such as kairo:progress) so you can resume an in-progress assessment. You can discard this at any time using the in-product "abandon/discard" control, which clears that local data from your device.
  • Preferences — such as your chosen language.
  • Feature configuration cache — to load the correct experience.

We do not use third-party advertising cookies, and we do not track you across other websites. We do not embed Google Analytics, advertising pixels, or similar third-party trackers.


13. Breach notification

If we become aware of a personal-data breach that affects you, we will act quickly to contain and assess it. In line with our commitment and applicable law, we will notify the Data Protection Board of India and affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach, describing (to the extent known) the nature of the breach, the likely consequences, and the measures taken or recommended to mitigate harm.


14. Grievance redressal

If you have any concern about how we handle your data, you can raise it with our Grievance Officer:

  • Grievance Officer & Data Protection Officer: Bharat Bohra (alternate: Narendra Purohit)
  • Email: support@scholaris.co.in
  • Phone: +91 9833861909
  • Address: F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India

Our service levels: we acknowledge within 1 business day and aim to resolve within 15 days (and in any event within the timelines required by the IT Rules and the DPDP Act). Full details, including what to include in a grievance, are on our Grievance Redressal page. Grievances may be filed in English or Hindi.

Escalation. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India (for data-protection matters) or to the appropriate consumer forum under the Consumer Protection Act, 2019, or to the appropriate courts as set out in our Terms of Service.


15. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. If we make material changes, we will notify registered users by email and/or by a prominent notice in the Service before the change takes effect, where required. Your continued use of Kairo after an update means you have read the revised policy.


16. Contact

For any privacy matter, request, or grievance:

Scholaris Private Limited F-204 Meenakshi Chambers, Bhayander East, Thane 401105, Maharashtra, India CIN: U85500MH2018PTC318097 Data Protection Officer & Grievance Officer: Bharat Bohra (alternate: Narendra Purohit) Email: support@scholaris.co.in · Phone: +91 9833861909

About

Scholaris Private Limited

(formerly Chasmis Solutions Private Limited)

CIN: U85500MH2018PTC318097

F-204 Meenakshi Chambers, Bhayander East, Thane 401105

support@scholaris.co.in

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Your Data Rights
  • Grievance Officer

Transparency

  • Methodology
  • Mental Health Resources
  • IP Disclosures
  • Sitemap
Kairo

© 2026 Scholaris Private Limitedbd3337f · 2026-08-25 02:43 UTC

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.