Legal
Privacy Policy
1. Who is responsible for your data
For the exams an organization runs, the organization (your school, institute or educator) decides why and how your data is used; Fynamics Technologies processes it on that organization's behalf to provide the service. For account, security and billing data about organizations and their administrators, Fynamics Technologies is responsible directly.
2. What we collect
Account data: name, email address, and a password (stored only in hashed form by our authentication provider).
Candidate profile: date of birth, gender, an optional mobile number and profile photo, and language preference, where the organization's exams need them.
Exam data: registrations, attempts, answers, scores, results and certificates.
Exam-integrity data: events recorded during an exam such as leaving fullscreen, switching tabs, or losing connectivity, with timestamps, so the organization can review an attempt fairly.
Organization and billing data: the organization's legal name, GST number, address, plan, invoices and payment records (amount, date, reference — never card or bank credentials).
Technical data: IP address and similar signals used to protect sign-in and sign-up from abuse, and the cookies described below.
3. Why we use it
To run exams and release results; to issue and verify certificates; to secure accounts and prevent abuse; to send service emails (registration, results, plan reminders); to bill for paid plans and meet tax obligations; and to support and improve the service. We do not sell personal data.
4. Who we share it with
The organization whose exam you took sees your candidate data for that organization. Data of one organization is kept separate from every other organization's.
Service providers that help us run the service: Supabase (database, sign-in and file storage), Vercel (hosting) and Resend (email delivery), and a payment gateway if you pay online. They may only use the data to provide their service to us.
Certificates can be checked on a public verification page by anyone who has the certificate's link; it shows what is needed to verify that certificate.
We may also disclose data where the law requires it.
5. Cookies
We use only the cookies the service needs: one to keep you signed in and one to remember your language. We do not use advertising cookies.
6. Keeping data safe
Data is encrypted in transit, access is restricted by role and by organization, and important administrative actions are recorded in a tamper-evident audit log. No system is perfectly secure; if a breach affecting you occurs we will notify the affected organization and act as the law requires.
7. How long we keep it
We keep data for as long as the organization's account is in use and as needed to meet legal, tax and audit obligations. Some records — such as issued tax invoices and audit-log entries — must be kept for integrity or by law even if other data is deleted.
8. Your choices
You can ask to see, correct or delete your personal data. For exam data, please contact the organization that ran the exam; we will support them in responding. For anything we hold directly, or if you are unsure who to ask, write to us below.
9. Children
Many candidates are students. Organizations that register candidates under 18 are responsible for obtaining verifiable parental or guardian consent where the law requires it. We do not knowingly collect data from a child except through an organization that has authorised it.
10. Contact and changes
Questions or requests: fynamicstechnologies@gmail.com or our Contact page, which also names our grievance officer. We may update this policy; the date above shows the latest version.