Legal
Privacy Policy
This policy is written to reflect the consent, export, and erasure mechanisms already defined in the product — including staged consultancy sharing and Super Admin–mediated erasure.
Who this policy covers
This Privacy Policy describes how immiNow processes personal data in connection with the immiNow consultancy dashboard and related student and partner experiences.
It is intended to reflect the consent, export, and erasure mechanisms already built into the product — not generic boilerplate that promises something different.
Privacy policy acceptance
A privacy policy must be accepted at signup before an account is usable. If the policy version changes, re-acceptance is required before continued use.
Every consent event is stored with the policy version it was given against and a timestamp, so what a person agreed to — and when — remains answerable from records.
Purpose-specific sharing with consultancies
Student data shared with consultancies follows staged, purpose-specific consent:
- Stage 1 shared set visible to a consultancy a student chats with: name and study preferences (level, target countries, field, intended intake/year, exam status). Budget is opt-in and hidden by default.
- Contact details, exact address, and uploaded documents are withheld until Stage 2 commit.
- Opening a new lead chat confirms name and study preferences for that consultancy once; commit confirms full personal data sharing and that other chats will close.
Your data rights
The product includes code-level mechanisms for the following rights:
- Right to correction: profile and preference fields are user-editable.
- Right to access (data export): support-mediated. On a verified request, Support Tools can generate an export of stored personal data such as profile, preferences, consent history, documents list, and chat transcripts. Self-serve export is not part of the current release.
- Right to erasure: a dedicated Erase User Data action is available to Super Admin only, after identity verification, with a mandatory reason and audit logging.
How erasure works
When erasure is executed:
- Hard-deleted: profile personal data (such as name, email, phone, address, date of birth, and gender), uploaded documents and files, device/push tokens, and the login credential.
- Anonymized in place where business records must survive: journey and plan records, commission and invoice entries, points ledger rows, quiz leaderboard entries, and chat messages (content removed; thread structure retained so operational history remains coherent).
- Audit log personal data is crypto-shredded: payloads are encrypted with a per-user data key at write time; erasure destroys that key so historical personal data becomes unreadable while the append-only audit chain remains intact.
- Erasure completes within 30 days of the verified request, covering files, indexes, caches, and backups within their rotation window.
Scope beyond students
These rights apply to personal data of individuals on the platform, including consultancy staff and freelancers — not only students.
One operational exception applies: Consultancy Admin and Super Admin accounts cannot self-erase while they are the sole holder of that role. A replacement admin must be designated first so the organisation is not locked out.
Contact for privacy requests
To request a data export, correction assistance, or erasure, contact immiNow through the Contact page, email contact@flyoc.in, or call +91-98473 04881. Identity verification is required before support-mediated privacy actions are completed.
