Skip to content
Mugdha Ventures Private Limited

Privacy Policy

Last updated July 24, 2026

This Privacy Policy explains how Mugdha Ventures Private Limited ("MVPL") collects, uses, shares, and protects personal data across its exam-security, biometrics, and software-development services. It is written to align primarily with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and to reference the concepts of the EU General Data Protection Regulation (GDPR) only where they genuinely apply (for example, where MVPL processes EU personal data). It gives special emphasis to the safeguarding of biometric and examination data, which MVPL treats as high-risk, heightened-sensitivity information as a matter of policy and best practice.

1. Introduction & Scope

Mugdha Ventures Private Limited ("MVPL", "we", "us", or "our") respects the privacy of every individual whose personal data we handle and is committed to processing that data responsibly, lawfully, and transparently. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal data in the course of operating our business and delivering our services.

This Policy applies to personal data we process in connection with:

  • Our exam-security and biometrics offerings, including biometric candidate check-in (fingerprint and facial recognition), digital smart locks, RFID question-paper and asset tracking, and exam-hall monitoring and anti-cheating systems;
  • Our custom software development work, including websites, e-commerce platforms, mobile applications for iOS and Android, and Learning Management Systems (LMS);
  • Our additional technology practices, including artificial intelligence and machine learning, AI-driven search engine optimization, cloud and infrastructure services (across AWS, Azure, and Google Cloud), DevOps and migration, data and analytics, and CRM/ERP development and integration;
  • Our website at mvpl.info, and our sales, marketing, support, and administrative activities.

The way this Policy applies depends on our role in a given engagement. Where MVPL determines the purposes and means of processing (for example, our own website, marketing, and corporate operations), we act as a data controller / Data Fiduciary and this Policy governs directly. Where we process personal data on behalf of, and under the instructions of, a client institution (for example, an examination body, university, government agency, or enterprise customer), we generally act as a data processor / processor acting on behalf of a Data Fiduciary, and the client's own privacy notice and our contract with that client govern the primary relationship. In those cases, this Policy explains our practices for transparency, but individuals should also consult the notice provided by the relevant client organization.

This Policy does not apply to third-party websites, products, or services that we do not control, even where they are linked from or integrated with our services. Please review the privacy notices of those third parties separately.

2. Who We Are

MVPL is a business-to-business information-technology and security-technology company incorporated in India. For personal data that we process as a controller / Data Fiduciary, our identity and contact details are as follows:

  • Entity: Mugdha Ventures Private Limited ("MVPL")
  • Registered address: H-352-353, EPIP, RIICO Industrial Area, Sitapura, Jaipur 302022, Rajasthan, India
  • Email: info@mvpl.info
  • Telephone: +91 98290 59862
  • Website: mvpl.info

For questions about this Policy, or to raise a request or complaint about how your personal data is handled, you may contact us using the details above or reach our Grievance Officer as described in the "Grievance Officer / Contact Us" section below. Where MVPL acts as a processor for a client institution, the client generally remains the primary point of contact for data-principal requests; we will support the client in responding and, where appropriate, direct your request to them.

3. Information We Collect

We collect personal data in several ways and in amounts proportionate to the purpose for which it is needed. The categories below describe what we may collect; the specific data collected in any engagement depends on the services in use and, where we act as a processor, on the instructions of the relevant client institution.

3.1 Information you provide to us

  • Contact and identity details such as name, job title, employer, business email address, postal address, and telephone number, provided when you enquire about services, request a proposal, enter into a contract, or communicate with us;
  • Account and credential information for portals, dashboards, or applications we operate, such as usernames and authentication data;
  • Commercial and transactional information relating to the services you or your organization procure, including correspondence, billing contacts, and payment-related details processed through our payment providers;
  • Content and support information you submit, including messages, tickets, feedback, and any information contained in documents you share with us;
  • Candidate registration details supplied in connection with examinations, such as name, roll or registration number, photograph, and identity references, where an examination client engages us to process them.

3.2 Information we collect automatically

When you use our website or the digital services we host, we and our tools may automatically collect technical information, including:

  • Device and connection data such as IP address, browser type and version, operating system, device identifiers, and language settings;
  • Usage and interaction data such as pages viewed, features used, referring and exit pages, timestamps, and diagnostic and performance logs;
  • Cookies and similar technologies as described in the "Cookies & Similar Technologies" section below.

3.3 Biometric and examination data (high-risk / heightened-sensitivity information)

In our exam-security and biometrics practice we may process biometric and examination-related information that MVPL treats as high-risk, heightened-sensitivity information warranting enhanced protection. This treatment is a matter of MVPL policy and best practice. The classification of such data as a distinct, more sensitive category derives from frameworks such as Article 9 of the GDPR — which designates biometric data used to uniquely identify a person as a special category — where those frameworks apply. India's DPDP Act does not create an equivalent "sensitive" or "special-category" tier and treats personal data uniformly (subject to specific additional rules for children and persons with disabilities); nonetheless, MVPL voluntarily applies enhanced safeguards to this data regardless of whether any special-category regime applies to a given engagement. The data we may process in this practice includes:

  • Fingerprint data captured for candidate check-in and identity verification;
  • Facial-recognition data captured for candidate check-in, identity verification, and exam-hall monitoring;
  • Examination event data generated by our anti-cheating and monitoring systems, such as check-in and check-out records, seat allocation, alerts, and audit logs;
  • Asset and material tracking data from RFID and digital smart-lock systems that may be associated with a candidate, invigilator, or custodian, including access and custody records.

Because of its heightened sensitivity, this data is subject to the additional controls described in the dedicated "Biometric & Examination Data" section below. In most examination engagements MVPL acts as a processor on behalf of the client institution that owns the examination, and we process such data strictly in accordance with that client's instructions and applicable law.

3.4 Information from third parties and clients

We may receive personal data from sources other than you directly, including:

  • Client organizations that engage us to build, host, integrate, or operate systems, and that provide data about their own candidates, learners, employees, or customers so that we can deliver the contracted services;
  • Business partners, resellers, and referral sources in the ordinary course of B2B activity;
  • Service providers and analytics, security, and fraud-prevention tools that supply technical and log information;
  • Publicly available sources and professional networks, used in a limited way for lawful business development consistent with applicable law.

4. How We Use Your Information

We use personal data only for specified, lawful purposes, including:

  • To provide, operate, maintain, and support our services, including exam-security, biometrics, software, cloud, data, and CRM/ERP solutions;
  • To verify candidate identity and safeguard the integrity of examinations, where engaged to do so by a client institution;
  • To develop, test, deploy, secure, and improve our products, platforms, and infrastructure, and to diagnose and resolve technical issues;
  • To communicate with you about enquiries, proposals, contracts, service updates, security notices, and support requests;
  • To manage our commercial relationships, including onboarding, billing, invoicing, and account administration;
  • To conduct limited business-to-business marketing about our services, subject to your consent where required and to your choices and applicable law;
  • To protect the security, availability, and integrity of our systems, prevent fraud and misuse, and investigate suspected violations;
  • To comply with legal, regulatory, tax, accounting, and contractual obligations, and to establish, exercise, or defend legal claims;
  • To carry out corporate transactions such as audits, financing, reorganizations, mergers, or acquisitions, subject to appropriate safeguards.

Where we act as a processor for a client institution, we use personal data only for the purposes defined by that client and set out in our agreement with them, and not for our own independent purposes.

6. Biometric & Examination Data

We recognize that biometric identifiers and examination records are among the most sensitive categories of personal data we handle, and we treat them as high-risk, heightened-sensitivity information regardless of whether any special-category regime formally applies. This section describes the specific safeguards we apply to them. These measures supplement, and do not replace, the general protections set out elsewhere in this Policy.

6.1 Our role as processor

In the large majority of examination engagements, MVPL acts as a processor on behalf of the client institution — such as an examination board, university, certification body, or government agency — that determines why and how biometric and examination data is collected. In that role we process the data only under the client's documented instructions and applicable law, we do not use it for our own independent purposes, and we do not sell it. The client institution remains the primary controller / Data Fiduciary responsible for providing notice and obtaining any required consent from candidates.

6.2 How biometric data is captured and stored

  • At check-in, our systems capture a fingerprint scan and/or facial image to verify that the candidate present is the person registered for the examination.
  • Wherever technically feasible, biometric samples are converted into a mathematical representation (a biometric template) that cannot practicably be reverse-engineered into the original image, and it is this template — not a raw fingerprint or facial photograph — that is retained for matching.
  • Biometric templates and any associated records are stored in encrypted form, using encryption in transit and at rest, and are logically separated from other data wherever practicable.
  • Access to biometric and examination data is restricted through role-based access controls on a need-to-know basis, and access events are logged and auditable.

6.3 Examination and asset-tracking data

Our exam-hall monitoring, anti-cheating, RFID tracking, and digital smart-lock systems generate records such as attendance, seat allocation, custody and access logs for question papers and assets, and security alerts. These records are used to verify identity, maintain examination integrity, and provide an auditable chain of custody, and they are protected with the same encryption, access-control, and logging safeguards described above.

6.4 Retention and deletion

Biometric and examination data is retained only for as long as needed to fulfil the purpose of the engagement and to meet the client's and our legal, audit, and dispute-resolution requirements. Retention periods for a given examination are set by the client institution in our agreement; on expiry, or on the client's instruction, the data is securely deleted or de-identified in accordance with that agreement and applicable law. We do not retain biometric templates for longer than the retention period agreed with the client and permitted by law.

7. Cookies & Similar Technologies

Our website and certain hosted services use cookies and similar technologies — such as pixels, tags, local storage, and software development kits — to operate the service and understand how it is used. These technologies generally fall into the following categories:

  • Strictly necessary: required for core functionality such as security, load balancing, session management, and remembering your preferences;
  • Performance and analytics: help us understand usage patterns so we can measure and improve our website and services;
  • Functional: enable enhanced features and personalization;
  • Marketing (where used): help us present relevant B2B information about our services and measure the effectiveness of campaigns.

Where required by law, we request your consent before setting non-essential cookies, and you can manage your preferences through our cookie controls where available or through your browser settings. Disabling certain cookies may affect the functionality of parts of our website. For further detail, please refer to any cookie notice or preference tool made available on mvpl.info.

8. How We Share Information

We do not sell personal data. We share personal data only where necessary and with appropriate safeguards, in the following circumstances:

  • Service providers and sub-processors: trusted vendors who process personal data on our behalf — such as cloud hosting (including AWS, Azure, and Google Cloud), infrastructure, analytics, communications, payment processing, and security providers — under contractual obligations of confidentiality and data protection, and only for the purposes we specify;
  • Client organizations: where we act as a processor, we make personal data available to the client institution that owns the relevant engagement, and to parties the client directs us to share with;
  • Legal and compliance recipients: courts, regulators, law-enforcement, and other authorities where disclosure is required by law or legal process, or is necessary to protect our rights, safety, property, or the integrity of our services, or to prevent fraud or security threats;
  • Professional advisers: auditors, lawyers, insurers, and consultants, bound by duties of confidentiality;
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, personal data may be transferred to the relevant party, subject to appropriate confidentiality and data-protection safeguards and to this Policy.

We require our sub-processors and recipients to maintain protections consistent with this Policy and applicable law, and we do not authorize them to use personal data for their own unrelated purposes.

9. Data Retention

We retain personal data only for as long as it is necessary for the purposes for which it was collected, including to provide our services, maintain business records, and comply with legal, tax, accounting, audit, and contractual obligations, and to resolve disputes and enforce our agreements.

The retention period for any given category of data depends on its nature, sensitivity, and purpose. Where we act as a processor, retention periods for client data — including biometric and examination data — are defined by the client institution in our agreement, and we delete or de-identify that data on expiry of the agreed period or on the client's instruction. When personal data is no longer required, we securely delete, anonymize, or de-identify it in accordance with applicable law and our data-retention practices.

10. Data Security

We implement reasonable and appropriate technical and organizational safeguards designed to protect personal data against unauthorized access, use, alteration, disclosure, loss, or destruction. Depending on the service, these measures may include:

  • Encryption of high-sensitivity data, including biometric templates, in transit and at rest;
  • Role-based access controls, least-privilege principles, and authentication measures;
  • Network security, monitoring, logging, and audit trails;
  • Secure software-development practices, testing, and vulnerability management;
  • Physical and environmental safeguards for facilities and equipment;
  • Staff confidentiality obligations, training, and vendor due diligence.

While we take security seriously and apply measures aligned with recognized standards, no method of transmission or storage can be guaranteed to be completely secure, and we cannot provide an absolute guarantee of security. In the event of a personal-data breach, we will act in accordance with our obligations under applicable law. Where MVPL is the controller / Data Fiduciary for the affected data, we will notify the Data Protection Board of India and each affected Data Principal of the breach in the manner and within the timeframes required by the DPDP Act, without applying any harm or materiality threshold. Where the GDPR applies to the affected data, we will follow its risk-based rules — notifying the competent supervisory authority without undue delay and, where the breach is likely to result in a high risk to individuals, notifying the affected individuals. Where we act as a data processor / processor acting on behalf of a Data Fiduciary, we will assist the relevant client institution and notify it of the breach without undue delay so that it can meet its own notification obligations.

11. International Data Transfers

MVPL is based in India, and personal data we process may be stored and handled in India. In delivering our services — for example, when using global cloud and infrastructure providers — personal data may also be processed in, or accessed from, countries other than the one in which it was collected. Data-protection laws in those countries may differ from those in your home jurisdiction.

Where personal data is transferred across borders, we take steps to ensure it continues to receive an appropriate level of protection, and the applicable mechanism depends on the governing regime. Under the DPDP Act, transfers of personal data outside India are permitted except to those countries or territories that the Central Government notifies as restricted (a negative-list, or "notified-restricted-country", approach rather than an adequacy or standard-contractual-clause model); we do not transfer personal data to any such notified-restricted country in contravention of the Act, and we monitor the Government's notifications for changes. The GDPR uses a different model: where we transfer EU personal data outside the EEA, we rely on an adequacy decision or on appropriate safeguards such as the European Commission's standard contractual clauses (SCCs). Across all transfers we also impose contractual confidentiality and data-protection obligations on our service providers. Where we act as a processor, transfers are made in accordance with the client institution's instructions and its own transfer arrangements.

12. Your Rights & Choices

Subject to applicable law and to our role in a particular engagement, you may have the following rights in relation to your personal data:

  • Access: to obtain confirmation of whether we process your personal data and a summary of that data and how it is processed;
  • Correction: to request the correction or updating of inaccurate, incomplete, or outdated personal data;
  • Erasure: to request deletion of personal data where it is no longer necessary or where required by law;
  • Objection and restriction: where the GDPR applies, to object to, or request restriction of, certain processing, including direct marketing;
  • Withdrawal of consent: to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
  • Data portability: where applicable under the GDPR, to receive certain personal data in a structured, commonly used, machine-readable format;
  • Nomination: under the DPDP Act, to nominate another individual to exercise your rights in the event of death or incapacity;
  • Grievance redressal and complaints: to raise a grievance with us and, if unsatisfied, to complain to the competent data-protection or supervisory authority, including the Data Protection Board of India.

To exercise any of these rights, please contact us using the details in the "Grievance Officer / Contact Us" section. We may need to verify your identity before acting on a request, and we will respond within the timeframes required by applicable law. Where we process your personal data as a processor on behalf of a client institution, we will ordinarily direct your request to that client, who is responsible for responding, and we will support them in doing so.

13. Children's / Minors' Privacy

Our services are directed to businesses and institutions rather than to children, and we do not knowingly collect personal data from children through our website for our own purposes. We recognize, however, that some examination candidates whose data we process on behalf of client institutions may be minors (in India, individuals under the age of 18).

Where we process the personal data of minors in the context of an examination or educational engagement, we do so strictly under the instructions of the responsible client institution and in accordance with applicable law. Under Section 9 of the DPDP Act, processing a child's personal data requires the verifiable consent of a parent or lawful guardian, and the Act prohibits processing that is likely to cause any detrimental effect on the well-being of a child, as well as the tracking or behavioural monitoring of children and targeted advertising directed at children.

MVPL's exam-security systems — including biometric candidate check-in, exam-hall monitoring, and anti-cheating tools — necessarily verify and monitor candidates, some of whom may be children, in a manner that would otherwise sit in tension with Section 9's restrictions on tracking and behavioural monitoring. The DPDP Act empowers the Central Government to exempt specified classes of Data Fiduciaries, or specified purposes (including educational and examination purposes), from certain of these restrictions. Accordingly, for any engagement that involves minors, MVPL relies on the responsible examination or educational body to confirm in the Engagement the lawful basis for the processing — either a Government-notified exemption applicable to that class of fiduciary or purpose under Section 9, or verifiable parental/guardian consent — before such processing begins. We do not use children's data for targeted advertising, and we do not undertake behavioural monitoring of children beyond what is strictly necessary for the contracted examination-integrity purpose and permitted under the applicable exemption or consent.

A minor's biometric templates and examination records are subject to the same high-risk, heightened-sensitivity safeguards — encryption, role-based access controls, logging, and retention limits — described in the "Biometric & Examination Data" section, and are retained only for the period agreed with the client and permitted by law. The client institution remains responsible for obtaining any necessary consents and providing notice to parents or guardians. Where the GDPR applies, we observe its rules on children's data, including the age of consent for information-society services (16, or as lowered by a Member State to no less than 13) and the requirement for parental authorisation below that age. If you believe we have processed a minor's data outside these arrangements, please contact us so we can take appropriate action.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal or regulatory requirements, or business practices. When we make material changes, we will update the effective date at the top of this Policy and, where appropriate, provide additional notice through our website or other reasonable means.

We encourage you to review this Policy periodically. Your continued use of our website or services after an updated Policy takes effect indicates your awareness of the current version, subject to any consent that applicable law may require us to obtain separately.

16. Grievance Officer / Contact Us

If you have questions, requests, or complaints about this Policy or our handling of your personal data, or if you wish to exercise your rights, please contact us. We are committed to addressing grievances in a timely manner and in accordance with the DPDP Act and other applicable law.

  • Data Fiduciary / Company: Mugdha Ventures Private Limited (MVPL)
  • Attention: Grievance Officer / Data Protection Contact
  • Address: H-352-353, EPIP, RIICO Industrial Area, Sitapura, Jaipur 302022, Rajasthan, India
  • Email: info@mvpl.info
  • Telephone: +91 98290 59862
  • Website: mvpl.info

If you are not satisfied with our response, you may have the right to escalate your complaint to the competent supervisory or data-protection authority, including the Data Protection Board of India. Where your personal data is processed by us on behalf of a client institution, we may direct your grievance to that institution, which is primarily responsible for responding, and we will cooperate to help resolve the matter.

Governing law and jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of India. Subject to any mandatory rights you may have under applicable law, the courts at Jaipur, Rajasthan, India shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

Effective date: July 24, 2026.

Questions about this privacy policy? Reach our team at info@mvpl.info or through our contact page.