Privacy Policy

Last updated: Draft — legal review pending

1. Who we are

Surge Foundry Foundation is a Section 8 (not-for-profit) company registered in India. We operate the Surge Foundry platform at surgefoundry.org, app.surgefoundry.org and api.surgefoundry.org.

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), we are a Data Fiduciary — the organisation that determines why and how your personal data is processed.

2. What data we collect

Data you give us

  • Name, email address, date of birth, city, state.
  • GitHub username (via OAuth — we request read:user and user:email scopes only).
  • Profile information you choose to add: bio, skills, links.
  • Application and participation data: cohort preferences, chapter selection, team membership.
  • Journal entries and project submission details.

Data we generate

  • Product Passport records: verification status, rubric scores, gate outcomes.
  • Builder level progression.
  • Audit logs of state changes (submissions, scores, role changes).
  • Ambassador activation scores.

Data we read from GitHub

  • Public repository metadata: existence, ownership, commit history, fork status.
  • We never request write access to your repositories.

Technical data

  • IP address, browser type, device type, pages visited.
  • Essential cookies for session management (see Section 8).

3. Why we collect it

Purpose Data used Basis
Verify eligibility (18+ requirement) Date of birth Legitimate use — program integrity
Run your application and cohort participation Name, email, GitHub, application data Consent at registration
Verify your project and issue Product Passport Repository metadata, journal, submission Consent + legitimate use
Operate the Commons and public verification De-identified Passport data, project links Legitimate use — ecosystem function
Communicate with you Email Consent
Prevent fraud and enforce Code of Conduct Audit logs, IP address Legitimate use
Improve the platform Aggregated, anonymised usage data Legitimate use

A note on date of birth. We collect your date of birth solely to verify you are 18 or older at the cohort start date. We store it but do not expose the raw date outside administrative contexts — only a derived age is shown where needed.

4. How we share it

  • We do not sell your personal data. Ever.
  • Mentors and reviewers see your project submission, journal and GitHub metadata during verification. They do not see your date of birth, email or private profile fields.
  • Peer reviewers see your project and journal during peer review.
  • Service providers who help us operate the platform (hosting, email delivery) process data on our behalf under data processing agreements.
  • Legal obligations. We may disclose data if required by Indian law or a court order.

5. Public profile

Your profile on the Commons is off by default. If you opt in, the following becomes publicly visible:

  • Display name, city (not full address), cohort, builder level.
  • Product Passport summaries and project links.
  • Skills and bio you choose to share.

You can turn your public profile off at any time from your account settings.

6. How long we keep it

Data Retention
Applications (not accepted) 24 months, then deleted
Active account data While your account is active
Product Passport records Indefinitely, in de-identified form after account deletion — so third-party verification never breaks
Audit logs 7 years
Technical logs 90 days

After account deletion, personal fields are anonymised within 30 days. Product Passports remain verifiable in de-identified form.

7. Your rights under the DPDP Act

You have the right to:

  • Access your personal data — see what we hold about you.
  • Correct inaccurate or incomplete data.
  • Withdraw consent for processing based on consent (this may affect your ability to participate).
  • Delete your account and have personal data erased.

How to exercise your rights. Use the “Download my data” and “Delete my account” options in your account settings on the portal, or email us at privacy@surgefoundry.org.

If you believe we have not addressed your concern, you have the right to complain to the Data Protection Board of India (DPBI).

8. Cookies

We use essential cookies only — for session management and security (CSRF protection). These are:

  • Secure, HttpOnly, and SameSite=Lax.
  • Scoped to app.surgefoundry.org.

We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify you.

9. Security and breach notification

We protect your data with:

  • Encryption in transit (TLS) and at rest.
  • Password hashing with Argon2id.
  • Role-based access controls — staff see only what their role requires.
  • Regular access reviews and audit logging.

In the event of a personal data breach that is likely to cause you harm, we will notify you and the Data Protection Board of India as required by the DPDP Act.

10. Children

Surge Foundry is for people aged 18 and older. We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it promptly.

11. Changes and contact

We may update this policy as the platform or the law evolves. Material changes will be communicated via email or a notice on the platform.

Contact us:

Surge Foundry Foundation, India.