Privacy Policy
Effective 7 October 2026 · Last updated 7 October 2026
1. Identity of the Data Fiduciary
This Website (“Website”) is operated by the ISA-RAIT Student Chapter, the student chapter of the International Society of Automation at Ramrao Adik Institute of Technology, D. Y. Patil University, Navi Mumbai (“ISA-RAIT”, “we”, “us”, or “our”).
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), ISA-RAIT acts as the Data Fiduciary in respect of the personal data processed by us as described in this Privacy Policy.
ISA-RAIT determines the purposes for which such personal data is processed and the manner in which such processing is carried out, subject to applicable law.
ISA-RAIT is a student chapter and is not a company or separate corporate entity.
Organisational details:
ISA-RAIT Student Chapter
Ramrao Adik Institute of Technology
D. Y. Patil University
Sector 7, Nerul
Navi Mumbai 400706
Maharashtra, India
Email: isa.rait@rait.ac.in
Responsibility for the processing of personal data described in this Privacy Policy rests with ISA-RAIT Student Chapter as the Data Fiduciary. ISA-RAIT does not designate a separate individual or office solely for data-protection matters.
2. Scope and applicability
This Privacy Policy applies to personal data processed by ISA-RAIT in connection with:
- the Website;
- certificate access and verification;
- workshop and event participation;
- Artemis Hackathon registration;
- support and enquiry submissions;
- membership registration;
- membership and committee applications;
- payment and refund administration associated with Website-based activities;
- communications associated with the foregoing activities; and
- other services or functionalities expressly provided through the Website.
This Privacy Policy describes the categories of personal data processed by ISA-RAIT, the purposes for which such personal data is processed, the entities that may process such data, applicable retention practices, security measures, and the rights available to Data Principals under applicable law.
3. Categories of personal data processed
ISA-RAIT follows the principle of data minimisation and processes personal data only to the extent reasonably necessary for a specified purpose.
ISA-RAIT does not operate advertising systems, behavioural-profiling systems, analytics packages, or cross-site tracking systems.
The categories of personal data processed depend upon the service or functionality with which you interact.
3.1 Workshop attendance and certification records
For workshops and other activities for which attendance and certification records are maintained, ISA-RAIT may process:
- Unique Identification Number (UID);
- name;
- college or institution;
- email address; and
- details of the workshop or activity attended.
Such information is obtained through the applicable attendance records and is used for participation administration, certification, and certificate verification.
3.2 Certificate authentication and access
The Website provides certificate-access functionality through which a user may be required to provide a UID and access code.
The submitted access code is processed solely for authentication and certificate retrieval.
The access code is not stored in its original form and is discarded following the authentication process.
Certificate files may contain the certificate holder's name and other information necessary for the certificate.
3.3 Artemis Hackathon registration
The Artemis Hackathon registration form is hosted and processed through a third-party online form service.
Depending on the applicable registration form, applicants may be required to provide:
- name;
- email address;
- contact number;
- college or institution;
- team or participant information;
- hackathon registration information;
- proof of payment or transaction confirmation; and
- other information specifically requested by the registration form.
A submitted proof of payment may contain information appearing in the relevant screenshot or document, including transaction identifiers, UPI identifiers, payment-application information, or other transaction-related information.
Such information is processed for the purposes of:
- processing and verifying hackathon registrations;
- verifying applicable registration payments;
- administering participation;
- communicating registration-related information;
- processing refunds where applicable; and
- maintaining necessary event records.
Applicants should not voluntarily submit information that is not required for the relevant registration process.
3.4 Support and enquiry submissions
The Website provides a Support/Query form operated by ISA-RAIT on the Website.
Information submitted through this form includes:
- name;
- email address;
- the subject and contents of the enquiry; and
- the submitter's confirmation of consent to this Privacy Policy and that they are 18 years of age or older.
Each submission is given a reference number, which is shown to the submitter and may be quoted in correspondence about the enquiry.
Such information is processed for the purpose of responding to and managing the relevant enquiry or request.
3.5 Membership registration
The Membership Registration form is operated through a third-party online form service and is used to facilitate an applicant's membership with the International Society of Automation.
Depending on the applicable form, information collected may include:
- name;
- email address;
- contact number;
- college or institution;
- academic information;
- membership-related information;
- account information;
- payment or membership-related information; and
- an account password where such credential information is required to complete the membership process on the applicant's behalf.
3.5.1 Processing of account credentials
When an applicant requests assistance from ISA-RAIT in obtaining or activating membership and the applicable process requires an account password, the applicant may be requested to provide such password.
An account password constitutes confidential authentication information and is processed solely for the purpose of completing the specified membership process.
The password:
- shall not be used for any purpose unrelated to the membership process;
- shall not be used for marketing, profiling, or unrelated activities;
- shall not be intentionally retained after completion of the relevant membership process;
- shall not be disclosed to persons who do not require access for the relevant membership process; and
- shall be deleted from records under ISA-RAIT's control as soon as reasonably practicable following completion of the relevant process.
Upon completion of the membership process, the applicant shall be instructed to change the relevant account password.
Applicants are advised not to reuse passwords across different services.
3.6 IP address and technical security information
When certificate sign-in, access-code reset, or a form on the Website is used, the Website temporarily processes the user's IP address and, for form submissions, the email address submitted.
Such information is processed solely for security purposes, including rate-limiting, abuse prevention, detection of repeated or automated submissions, and detection of repeated or automated authentication attempts.
The counters used for these purposes are automatically deleted within two days at most.
4. Purposes of processing
ISA-RAIT processes personal data only for specified and legitimate purposes.
4.1 Workshop and certificate administration
Workshop attendance and certification information is processed to:
- verify participation;
- issue certificates;
- facilitate certificate access and verification; and
- maintain reasonable records of participation.
4.2 Certificate authentication
UIDs and access codes are processed to authenticate authorised users and provide access to the relevant certificate.
4.3 Electronic communications
Email addresses may be used to:
- deliver certificate access codes;
- provide access-code reset links where requested; and
- communicate information necessary for the specific service or request for which the email address was provided.
ISA-RAIT does not operate a general promotional mailing list using these addresses.
4.4 Artemis Hackathon administration
Information submitted through the Artemis Hackathon registration form is processed to:
- process registrations;
- verify applicable payments;
- administer participation;
- communicate with participants;
- process applicable refunds; and
- maintain necessary event records.
4.5 Support and enquiry management
Information submitted through the Support/Query form is processed to respond to and manage enquiries and requests.
4.6 Membership administration
Information submitted through the Membership Registration form is processed to:
- process membership requests;
- facilitate membership;
- verify applicable registration or payment information;
- complete the membership process where assistance has been requested;
- communicate with applicants; and
- maintain necessary membership records.
Where an account password is temporarily provided, it is processed solely for completion of the relevant membership process.
4.7 Payment and refund administration
Where the Website facilitates the collection of registration fees or other payments in connection with an ISA-RAIT event or activity, payment-related information may be processed for purposes including:
- registration and payment verification;
- transaction reconciliation;
- event administration;
- accounting and record-keeping;
- processing refunds where applicable; and
- communicating with participants regarding payments or refunds.
A refund shall be issued only where ISA-RAIT cancels the relevant event for which payment was collected through the Website.
No refund shall be provided solely because a participant:
- wishes to cancel their registration;
- is unable or unwilling to attend the event;
- requests cancellation of their registration; or
- otherwise requests a refund without cancellation of the event by ISA-RAIT.
Where ISA-RAIT cancels an event for which payment has been collected through the Website, the amount collected for the cancelled event shall be refunded to the respective participant through the same mode or payment method through which the original payment was made, subject to the processing requirements and limitations of the applicable payment service.
Personal data reasonably necessary to identify the relevant transaction and process the applicable refund may be used for this purpose.
ISA-RAIT shall not use payment-related personal data for advertising, profiling, or unrelated purposes.
4.8 Information security
Temporary technical information, including IP addresses, is processed to protect authentication functionality, prevent abuse, and implement reasonable security controls.
5. Lawful basis for processing
ISA-RAIT shall process personal data only for a lawful purpose permitted under applicable law.
Where consent is relied upon as the basis for processing, consent shall be obtained through a clear affirmative action after the relevant information concerning the processing has been made available.
Where applicable, consent shall be free, specific, informed, unconditional, and unambiguous.
5.1 Processing based on consent
Where a form or service relies upon consent, the relevant notice and consent mechanism shall be presented at or before the point at which personal data is submitted.
A Data Principal may withdraw consent where consent constitutes the applicable basis for processing.
The mechanism for withdrawing consent shall be reasonably comparable in ease to the mechanism through which consent was provided.
Withdrawal of consent may affect ISA-RAIT's ability to provide the service or complete the activity for which the personal data was collected.
5.2 Workshop and certification records
Workshop attendance and certification records are processed for the specified purposes communicated in connection with the relevant activity, including administration of participation, issuance of certificates, and maintenance of reasonable participation records.
A request for deletion may affect the availability, verification, or reissuance of the associated certificate.
6. Third-party data processors and service providers
ISA-RAIT does not sell personal data and does not disclose personal data to third parties for their own advertising or marketing purposes.
Certain Website functions rely upon third-party technology and service providers.
The categories of service providers currently used are:
- Website hosting. Categories of information: technical information, including IP addresses. Purpose: serving the Website and its functionality.
- Email and document services. Categories of information: workshop attendance records and relevant email information. Purpose: attendance records and certificate-related communications.
- Online form services. Categories of information: membership and committee-application information, Artemis registration information, and payment proof. Purpose: hosting and processing the relevant forms.
- Database services.Categories of information: UID, name, college, email, and attendance information; Support/Query submissions; and rate-limiting counters. Purpose: database infrastructure supporting the certificate portal, the Support/Query form, and the Website's security controls.
- Spreadsheet services. Categories of information: Support/Query submissions. Purpose: making submissions available to authorised committee members.
- Cloud file storage. Categories of information: certificate files. Purpose: private storage and certificate-file delivery.
A Data Principal may request the identities of the Data Processors with whom their personal data has been shared, in accordance with the DPDP Act, through the channels in Section 11.
Third-party service providers may process technical information, including IP addresses, when their services are accessed or loaded. Where a third-party form is embedded in a page of the Website, the relevant provider may process such information when that page is loaded.
Third-party providers may process information in jurisdictions outside India. Any such processing or transfer shall be subject to applicable law and any restrictions or requirements applicable to transfers of personal data outside India.
Users should review the applicable privacy policies and terms of the relevant third-party service providers.
7. QR codes and linked destinations
The Website may display QR codes that direct users to registration forms, certificate-access pages, payment facilities, membership services, event resources, external websites, or other digital destinations.
A QR code itself does not necessarily collect personal data. However, the destination to which a QR code directs the user may process personal data.
Where a QR code directs a user to a service operated by ISA-RAIT, the processing of personal data on that destination shall be governed by this Privacy Policy to the extent applicable.
Where a QR code directs a user to a third-party website, application, payment service, registration system, or other external platform, any personal data subsequently provided or automatically processed by that third party shall be governed by the relevant third party's privacy policy and terms.
ISA-RAIT does not control the privacy or security practices of third-party destinations accessed through QR codes.
Users should verify the destination of a QR code before providing personal data, payment information, credentials, or other information.
8. Disclosure pursuant to law
ISA-RAIT may disclose personal data where such disclosure is:
- required by applicable law;
- required pursuant to a lawful order, direction, or request of a competent authority;
- necessary to comply with a legal obligation; or
- otherwise permitted under applicable law.
Where legally permissible, ISA-RAIT shall make reasonable efforts to inform the affected Data Principal of such disclosure.
No such notification shall be provided where notification is prohibited by applicable law or by a lawful direction of a competent authority.
9. Retention of personal data
ISA-RAIT shall retain personal data only for as long as reasonably necessary to fulfil the specified purpose for which it was collected, maintain necessary records, address disputes or requests, protect the Website and its users, or where retention is otherwise required or permitted by applicable law.
The current retention periods are:
- Workshop roster records and certificate files: three years following the last workshop attended through ISA-RAIT.
- Support and enquiry records: one year.
- Event and membership registration records: one year following the relevant event or activity.
- Rate-limiting counters: automatically deleted within two days at most.
- Records relating to access or processing activity: one year.
- Account passwords temporarily provided for membership processing: deleted as soon as reasonably practicable following completion of the relevant membership process.
- Payment and refund records: retained for the period reasonably necessary for transaction verification, reconciliation, refund administration, accounting, and applicable legal requirements.
Where a Data Principal requests erasure, ISA-RAIT shall cease processing the relevant personal data for the applicable purpose and delete it where deletion is appropriate and legally permissible.
Certain limited information may nevertheless be retained where retention is required by law, necessary to establish compliance, or necessary for the exercise or defence of legal rights.
Such information shall not be used for unrelated purposes.
Electronic communications already delivered to a recipient may remain in the recipient's mailbox or within the applicable email service. ISA-RAIT cannot recall or delete an email from a recipient's personal mailbox after delivery.
10. Rights of Data Principals
Subject to applicable law, a Data Principal may exercise rights in relation to personal data processed by ISA-RAIT, including:
10.1 Right to access information
The right to obtain information concerning the personal data processed by ISA-RAIT and applicable processing activities.
10.2 Right to correction and updating
The right to request correction, completion, or updating of personal data that is inaccurate, incomplete, or outdated.
10.3 Right to erasure
The right to request erasure of personal data, subject to circumstances in which retention is required or permitted under applicable law.
Erasure of certificate-related records may result in the inability to access, verify, or reissue the associated certificate.
10.4 Right to grievance redressal
The right to raise a grievance concerning the processing of personal data or the exercise of applicable rights.
10.5 Right to nominate
The right, subject to applicable law and prescribed procedures, to nominate another individual to exercise applicable rights in the event of death or incapacity.
11. Exercise of rights and grievance redressal
Data Principals may submit requests concerning access, correction, updating, erasure, withdrawal of consent, or other applicable rights, and questions or grievances concerning the processing of personal data, to ISA-RAIT Student Chapter by email:
Email: isa.rait@rait.ac.in
Requests and grievances received through this channel shall be reviewed and addressed by ISA-RAIT Student Chapter in accordance with applicable law.
Requests should contain sufficient information to enable ISA-RAIT to understand and process the request and, where reasonably necessary, verify the identity of the requesting Data Principal.
ISA-RAIT aims to respond to grievances within 30 days, or within such other period as may be prescribed under applicable law.
A Data Principal who is not satisfied with the response to a grievance may make a complaint to the Data Protection Board of India in accordance with the DPDP Act and the rules made under it.
12. Technical and organisational security measures
ISA-RAIT implements reasonable technical and organisational measures appropriate to the nature of the personal data processed and the risks associated with such processing.
Current safeguards include:
- Access codes are stored using a one-way, deliberately slow cryptographic hashing mechanism.
- Original access codes cannot be retrieved by committee members from the stored representation.
- Certificate files are stored in private storage and are not publicly listed or directly linkable.
- Certificate downloads are provided through time-limited links that expire after approximately two minutes.
- Certificate sign-in responses are designed not to disclose whether a particular UID exists.
- Certificate sign-in and access-code reset functionality is subject to rate-limiting.
- Pages displaying personal information are configured to discourage caching by browsers and intermediary systems.
- The Website is served using HTTPS.
- Access to Support/Query submissions is restricted to authorised committee members, who sign in individually, and actions taken on submissions are logged.
- Access to membership credentials is restricted to persons authorised to process the relevant membership request.
- Account passwords temporarily provided for membership processing are not intentionally retained after completion of the relevant process.
No electronic system can be guaranteed to be completely secure.
Accordingly, although ISA-RAIT implements reasonable safeguards, it cannot guarantee that unauthorised access, disclosure, alteration, loss, or destruction can never occur.
In the event of a personal-data breach, ISA-RAIT shall take appropriate containment, investigation, mitigation, and notification measures in accordance with applicable law.
13. Cookies, local storage and similar technologies
The Website does not set first-party cookies for advertising, behavioural tracking, or analytics. A strictly necessary sign-in cookie is set only for authorised committee members when they sign in to the Website's administration area.
ISA-RAIT does not operate an analytics or advertising-tracking system.
The Website stores the user's selected light or dark theme locally in the user's browser.
This browser-local information remains on the user's device and is not used by ISA-RAIT to identify or profile the user.
It may be removed by clearing the browser's stored Website data.
When a third-party form is loaded, the relevant third-party provider may use its own cookies, local storage, or similar technologies. Such technologies are controlled by the relevant provider and are subject to that provider's privacy practices.
14. Processing of personal data relating to minors
ISA-RAIT's workshops, events, and membership activities are intended primarily for college students and other eligible participants.
Forms that ask for confirmation of age require the submitter to confirm that they are 18 years of age or older before the form can be submitted.
ISA-RAIT does not knowingly seek to collect personal data from individuals below 18 years of age through the Website.
If ISA-RAIT becomes aware that personal data relating to an individual below 18 years of age has been collected without the applicable lawful basis or consent required by law, ISA-RAIT shall take appropriate steps in accordance with applicable law.
15. External websites and third-party services
The Website may contain hyperlinks, embedded services, QR codes, registration facilities, payment facilities, or other mechanisms that direct users to third-party websites, applications, platforms, or services.
Once a user accesses a third-party service, the privacy policy, terms, and data-processing practices of that third party shall apply to processing undertaken by that third party.
ISA-RAIT does not control and is not responsible for the privacy or security practices of third-party services that it does not operate.
Users are advised to review the applicable privacy policy and terms of any third-party service before providing personal data.
16. Amendments to this Privacy Policy
ISA-RAIT may amend this Privacy Policy from time to time to reflect:
- changes to the Website or its functionality;
- changes to the categories of personal data processed;
- changes to the purposes of processing;
- changes to service providers;
- changes in applicable law or regulatory requirements; or
- changes to privacy and security practices.
The Effective Date and Last Updated date displayed at the beginning of this Privacy Policy shall be updated whenever an amendment is made.
Where a material amendment affects the processing of personal data already held by ISA-RAIT and an appropriate means of contacting the affected Data Principal is available, additional notice may be provided where required or appropriate.
17. Governing law
This Privacy Policy shall be governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and applicable rules and regulations made thereunder.
Nothing contained in this Privacy Policy shall operate to exclude, restrict, or waive any right or remedy that cannot lawfully be excluded, restricted, or waived.
18. Contact information
For enquiries concerning this Privacy Policy, requests concerning personal data, withdrawal of consent, or grievances relating to the processing of personal data, communications may be submitted to:
ISA-RAIT Student Chapter
Ramrao Adik Institute of Technology
D. Y. Patil University
Sector 7, Nerul
Navi Mumbai 400706
Maharashtra, India
Email: isa.rait@rait.ac.in

