
Emmple ECO Privacy Policy
Last updated: November 11, 2025 (IST)
This Privacy Policy explains how Wisflux Private Limited (operating as Emmple) collects, uses, discloses, and protects personal information when individuals and schools use ECO — Extra‑curricular Olympiads by Emmple. By using ECO, you agree to this Policy.
1) Roles: Schools vs. Wisflux
Schools act as controller; Wisflux as processor
When a School runs an Olympiad with ECO, the School typically acts as the data controller for student data related to the event. Wisflux acts as the School’s data processor and processes data under the School’s instructions and our data processing terms.
Wisflux as independent controller (limited data)
Wisflux may act as an independent controller for limited data such as ECO account/billing contacts, product analytics, security logs, and compliance records needed to operate and protect the Service.
Exercising rights for School‑managed data
Parents/guardians and students seeking to exercise rights for School‑managed data should contact the School; we will support the School in fulfilling requests.
2) Information We Collect
2.1 Information you or your School provide
Account & profile: name, display name, email, phone number, password (hashed), role (student/parent/teacher/organizer), school/class/section, avatar (optional), preferences (language, notifications). Olympiad participation: events joined, attempts/submissions, scores, ranks, time spent, badges/certificates generated by ECO, proctoring status, disqualifications/appeals (if any), and timestamps. Parent/guardian info: name and contact (email/phone) and links to the child’s account, where enabled. Organizer/School data: organizer admin names, contact emails/phones, institution details, event settings and rules configured for Olympiads. Support & feedback: messages to support, survey responses, issue descriptions.
2.2 Information collected automatically (Usage Data)
Device & log data: IP address, device identifiers, OS, browser/app version, pages/screens viewed, timestamps, referrer, session duration, crash logs, diagnostics. Cookies & similar tech: session/auth cookies, preference cookies, and analytics tags to keep you signed in, remember settings, and measure usage. Integrity/anti‑cheat and proctoring signals: technical signals (e.g., attempt timing, window focus changes, device/app metadata). For proctored events, we may process webcam and/or microphone captures, screen‑focus telemetry, and related device metadata to uphold fairness and integrity.
2.3 Integrations and other sources
Single Sign‑On (optional): if you choose Google SSO, we receive basic profile info (e.g., name, email) from Google per your settings. Schools/organizers: rosters or participant information supplied by the School to run Olympiads. We do not intentionally collect special categories of personal data (e.g., health, biometrics) beyond optional proctoring captures. Schools should avoid collecting sensitive data unless necessary and lawful. SSO scope minimization: When you use Google SSO, we request only basic profile and email to create or sign you in. We do not maintain ongoing access to your Google account or request additional scopes without your explicit action and consent.
3) How We Use Information (Purposes)
- Provide the Service: create/manage accounts, authenticate users, host Olympiads, administer rules, score attempts, generate certificates, operate leaderboards, and provide school/parent updates where enabled; uphold fair play (including proctoring and anti‑cheat processing).
- Improve and secure ECO: analytics, diagnostics, testing, bug‑fixes, fraud/abuse prevention, performance and reliability.
- Communications: service messages, event updates, policy changes, and support replies to participants, parents, and organizers.
- Compliance & enforcement: comply with law, respond to lawful requests, enforce terms, and protect users and our platform.
- Marketing communications (adults only): We may send optional product updates, tips, and offers to adults such as parents/guardians and organizers. Children do not receive marketing messages. You can opt out at any time via the unsubscribe link or by emailing [email protected].
- We do not use children’s data for behavioral advertising and do not use third‑party advertising cookies.
4) Cookies & Similar Technologies
- Essential cookies (e.g., session, CSRF, auth) to run ECO.
- Preference cookies to remember settings (language, view).
- Analytics tags/SDKs to understand usage and improve features.
- We do not use third‑party advertising cookies. A cookie/preferences control will be available in Settings > Privacy. Until then, you can manage cookies in your browser/app settings. If you prefer to opt out of non‑essential analytics before the in‑app control is available, email [email protected] with the subject “Analytics Opt‑out” and your account email; we will apply the preference where technically feasible. Blocking essential cookies may affect core functions.
5) When We Share Information
- Service providers (processors): hosting, delivery, analytics, email/SMS, logging/security — under contract and only as necessary.
- Parents/guardians (with authorization): limited participation results and stats for linked child accounts.
- Schools/organizers: if you participate in a School‑run Olympiad, your display name, participation, scores, rank, certificate status, and proctoring status (pass/fail/flags) are visible to the School/organizer and other participants as appropriate. Public visibility (e.g., on the web) occurs only where an event is explicitly marked public and is indicated before you join.
- Legal & safety: regulators, courts, or law enforcement when required by law or necessary to protect rights, safety, or integrity.
- Business transfers: if we restructure, merge, or sell assets, information may be transferred with continued protections and advance notice.
- We do not sell personal information.
- Subprocessors: We use vetted subprocessors to help deliver ECO. We limit access to the minimum necessary and require confidentiality and security commitments. Categories include hosting/infrastructure, email and in‑app notifications, SMS/telephony delivery (where enabled), payments (where enabled), analytics/diagnostics, logging/security monitoring.
- We will provide notice of material changes to subprocessors where required by law or contract. Institutions can request subprocessor update notifications by emailing [email protected] with the subject “Subprocessor Updates”.
6) Leaderboards, Certificates, Proctoring, and Public Results
Leaderboards
Display names appear as entered by users/parents and may be pseudonymous (e.g., initials). By default, leaderboards are restricted to event participants and the School/organizer. Public visibility occurs only for events explicitly marked public and is indicated before you join.
Certificates
ECO may issue certificates indicating your full name by default, event name, date, and performance (e.g., score, rank). Schools/organizers may require full names for identity and verification. Where allowed by event rules, you may choose a display name/initials for the certificate.
Proctoring and recordings (if enabled)
Some Olympiads may require access to camera and/or microphone or other device sensors or proctoring checks. By using such events, you consent to their operation, which may include recording during attempts for integrity and forensics. Recordings (if captured) may be retained for up to 180 days and longer if subject to investigation or legal holds.
Public winners lists
For events explicitly marked public, winners lists may be announced. For minors, publication requires parent/guardian consent via event rules or School authorization.
Automated scoring
Automated scoring and placements do not produce legal or similarly significant effects.
7) Children, Parents & Guardians
Overview
ECO is designed for students. Parents/guardians are responsible for guiding and monitoring usage, managing consents, and helping children make safe choices online. Parents/guardians can request access to and deletion of their child’s personal information, subject to legal or safety exceptions. If we learn child data was provided without appropriate authorization, we will delete it.
How parental consent works
1) Direct sign‑up with parent contact: We collect a parent/guardian email or phone number and send a consent notice with a verification link/OTP; the child account becomes active only after verification. 2) Parent‑initiated account/linking: A parent can create or link a child account from a parent dashboard with an explicit consent step. 3) School‑provisioned accounts: The School is responsible for obtaining required consents under applicable law; ECO acts as the processor. 4) Withdraw/update consent: Parents/guardians can withdraw or modify consent via in‑product settings (where available) or by contacting [email protected] or [email protected]; we may request verification.
No targeted ads to children
We do not track, behaviorally monitor, or show targeted advertising to children.
8) International Processing & Cloud Providers
- We use servers and services of popular global cloud providers such as AWS, Cloudflare, and DigitalOcean, with datacenters in the US, Europe, or India.
- When data moves across borders, we apply contractual and technical safeguards (e.g., encryption, access controls) to maintain protection comparable to applicable requirements (including India’s Digital Personal Data Protection Act, 2023).
- Regional addenda will be added as we expand to additional regions.
9) Retention
- We retain personal information only as long as necessary for the purposes in this Policy or as required by law.
- Account/profile data: life of the account + up to 12 months.
- Analytics/diagnostic logs: up to 90 days.
- Proctoring recordings (if captured): up to 180 days, or longer where required for an ongoing investigation or legal obligation.
- Backups: 30–90 days with secure rotation.
- Support records: up to 24 months.
- Deletion requests: For School‑managed accounts, contact the School. For Wisflux‑managed records (e.g., admin/billing contacts), after verification, we aim to complete deletion within up to 45 days, except where we must retain certain data for legal, security, or dispute reasons. Data in backups is not actively used and will expire on the backup schedule.
10) Your Rights
- Subject to law and the School’s role as controller, you may access your data and receive a copy, correct inaccurate or incomplete data, delete data in certain circumstances, withdraw consent where processing relies on consent, and complain to our Grievance contact and, if unresolved, to the appropriate authority.
- Under India’s Digital Personal Data Protection Act, 2023, you may nominate an individual to exercise your rights in the event of your incapacity or death.
- How to exercise: For School‑managed data, contact your School. For Wisflux‑managed records (e.g., admin/billing contacts), use in‑product settings (where available) or email [email protected]. We may request information to verify identity/authority.
11) Security and AI/ML Use
Security
We implement safeguards including encryption in transit/at rest (where applicable), role‑based access, logging/audit, backups, and vulnerability management. If a data incident occurs, we will investigate and mitigate, notify affected institutions/users and authorities without undue delay after reasonable investigation where required by law, and take remedial steps.
AI/ML use
We do not use your personal data to train external AI models. If we introduce AI features that process personal data, we will disclose the purposes, data involved, and providers, and offer appropriate choices.
12) Third‑Party Links
- ECO may link to or embed third‑party services (e.g., videos/resources). Their privacy practices are governed by their own policies. Review them before use.
13) Changes to this Policy
- We may update this Policy to reflect changes in ECO, laws, or practices. We will post updates here and revise the “Last updated” date. For material changes, we will provide prominent notice and request renewed consent where required.
14) Contact & Grievance
- Company: Wisflux Private Limited
- Address: A-107, Shiksha Vihar, Jagatpura, Jaipur, Rajasthan 302017, India
- Privacy/Support: [email protected]
- Grievance contact: [email protected]
- We acknowledge grievances within 15 days and aim to resolve them within 45 days. If your grievance remains unresolved, you may escalate to the Data Protection Board of India.
15) Regional Addenda
EEA/UK
We are preparing dedicated EEA/UK notices. When we begin offering services in these regions, we will implement appropriate data transfer mechanisms (e.g., EU Standard Contractual Clauses and the UK IDTA/Addendum) and a regional cookie consent banner.
California (CPRA/CCPA)
We do not “sell” or “share” personal information for cross‑context behavioral advertising. California residents may have rights to know/access, correct, and delete certain personal information, and to limit use of sensitive personal information, subject to exceptions. To exercise these rights, contact [email protected] or [email protected]. We do not discriminate against you for exercising your rights.
Contact Us
For privacy or support queries, email [email protected].
For grievances, email [email protected].
Address: A-107, Shiksha Vihar, Jagatpura, Jaipur, Rajasthan 302017, India
Contact Info
107 - Shiksha Vihar Colony, Jagatpura, Jaipur, Rajasthan, 302017
© 2025 EmmpleECO. All rights reserved.