How the Jago Yuva, Jago Bharat platform protects the data it holds. Because most participants are minors, protecting their data is the platform’s first priority.
Last updated 31 August 2026
Advaita Ashrama takes practical, layered measures to protect the personal data on the Platform, in line with India’s Digital Personal Data Protection Act, 2023. This page summarises those measures. It complements the Privacy Policy and the Data Processing Agreement.
Personal data is stored in India, in our database provider’s Mumbai region. Some processing or hosting infrastructure may operate from outside India; where that happens, the data is protected by appropriate contractual and technical safeguards.
Data is encrypted in transit using TLS across the whole service, and encrypted at rest by our storage provider.
Every request is authorised on the server, and each institution can reach only its own data. Field roles are checked in the primary database on every protected request: DRPs and SPOCs are limited to their assigned State or Union Territory, a National Observer has nationwide read-only access, and authorised Platform administrators have nationwide scope. The database is not exposed directly to the browser: row-level security is enabled with no public REST policies (a PostgREST lockout), and data is served only through controlled, authenticated server paths.
Field access is granted by review or appointment, never by self-assertion. A District Resource Person’s enrolment is a request that grants no access until a Platform administrator or an active in-state SPOC approves it, and a rejected request cannot be resubmitted. A State Point of Contact is appointed by the JYJB Team and cannot self-activate. Either assignment can be revoked at any time.
Material school changes create append-only attribution history. Routine access to sensitive school data is recorded internally without copying student, guardian, submission, or payment values into the access record.
Payments are handled by a PCI-DSS-compliant payment gateway. We do not collect or store card details; we keep only the references needed to reconcile a payment (the order ID and the UPI/bank reference).
We minimise what we collect about students, gate every student record behind the institution’s consent attestation, and do not track, profile, or advertise to children. See the Privacy Policy — Children’s data for detail.
If a personal data breach occurs, we act to contain and remediate it, assess the impact, and notify the relevant authority and affected persons as required by the DPDP Act. Institutions can help by reporting anything suspicious promptly (see below).
If you believe you have found a security vulnerability, please tell us before disclosing it publicly. Email jagoyuva@advaitaashrama.org with enough detail to reproduce the issue. We will acknowledge your report and work to address valid issues promptly.
For security or data-protection questions, contact our Grievance Officer: