Privacy Policy
Last updated: Draft — legal review pending
1. Who we are
Surge Foundry Foundation is a Section 8 (not-for-profit) company registered in India. We operate the Surge Foundry platform at surgefoundry.org, app.surgefoundry.org and api.surgefoundry.org.
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), we are a Data Fiduciary — the organisation that determines why and how your personal data is processed.
2. What data we collect
Data you give us
- Name, email address, date of birth, city, state.
- GitHub username (via OAuth — we request
read:useranduser:emailscopes only). - Profile information you choose to add: bio, skills, links.
- Application and participation data: cohort preferences, chapter selection, team membership.
- Journal entries and project submission details.
Data we generate
- Product Passport records: verification status, rubric scores, gate outcomes.
- Builder level progression.
- Audit logs of state changes (submissions, scores, role changes).
- Ambassador activation scores.
Data we read from GitHub
- Public repository metadata: existence, ownership, commit history, fork status.
- We never request write access to your repositories.
Technical data
- IP address, browser type, device type, pages visited.
- Essential cookies for session management (see Section 8).
3. Why we collect it
| Purpose | Data used | Basis |
|---|---|---|
| Verify eligibility (18+ requirement) | Date of birth | Legitimate use — program integrity |
| Run your application and cohort participation | Name, email, GitHub, application data | Consent at registration |
| Verify your project and issue Product Passport | Repository metadata, journal, submission | Consent + legitimate use |
| Operate the Commons and public verification | De-identified Passport data, project links | Legitimate use — ecosystem function |
| Communicate with you | Consent | |
| Prevent fraud and enforce Code of Conduct | Audit logs, IP address | Legitimate use |
| Improve the platform | Aggregated, anonymised usage data | Legitimate use |
A note on date of birth. We collect your date of birth solely to verify you are 18 or older at the cohort start date. We store it but do not expose the raw date outside administrative contexts — only a derived age is shown where needed.
4. How we share it
- We do not sell your personal data. Ever.
- Mentors and reviewers see your project submission, journal and GitHub metadata during verification. They do not see your date of birth, email or private profile fields.
- Peer reviewers see your project and journal during peer review.
- Service providers who help us operate the platform (hosting, email delivery) process data on our behalf under data processing agreements.
- Legal obligations. We may disclose data if required by Indian law or a court order.
5. Public profile
Your profile on the Commons is off by default. If you opt in, the following becomes publicly visible:
- Display name, city (not full address), cohort, builder level.
- Product Passport summaries and project links.
- Skills and bio you choose to share.
You can turn your public profile off at any time from your account settings.
6. How long we keep it
| Data | Retention |
|---|---|
| Applications (not accepted) | 24 months, then deleted |
| Active account data | While your account is active |
| Product Passport records | Indefinitely, in de-identified form after account deletion — so third-party verification never breaks |
| Audit logs | 7 years |
| Technical logs | 90 days |
After account deletion, personal fields are anonymised within 30 days. Product Passports remain verifiable in de-identified form.
7. Your rights under the DPDP Act
You have the right to:
- Access your personal data — see what we hold about you.
- Correct inaccurate or incomplete data.
- Withdraw consent for processing based on consent (this may affect your ability to participate).
- Delete your account and have personal data erased.
How to exercise your rights. Use the “Download my data” and “Delete my account” options in your account settings on the portal, or email us at privacy@surgefoundry.org.
If you believe we have not addressed your concern, you have the right to complain to the Data Protection Board of India (DPBI).
8. Cookies
We use essential cookies only — for session management and security (CSRF protection). These are:
Secure,HttpOnly, andSameSite=Lax.- Scoped to
app.surgefoundry.org.
We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify you.
9. Security and breach notification
We protect your data with:
- Encryption in transit (TLS) and at rest.
- Password hashing with Argon2id.
- Role-based access controls — staff see only what their role requires.
- Regular access reviews and audit logging.
In the event of a personal data breach that is likely to cause you harm, we will notify you and the Data Protection Board of India as required by the DPDP Act.
10. Children
Surge Foundry is for people aged 18 and older. We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it promptly.
11. Changes and contact
We may update this policy as the platform or the law evolves. Material changes will be communicated via email or a notice on the platform.
Contact us:
- Privacy questions: privacy@surgefoundry.org
- General enquiries: hello@surgefoundry.org
Surge Foundry Foundation, India.
