Legal
Privacy Policy
This page explains exactly what personal data MockTest collects, why we collect it, how long we keep it, who else sees it, and how you can get it corrected or erased.
This is a consent notice, not just a disclosure
Under the Digital Personal Data Protection Act, 2023 (the DPDP Act), we must tell you, before we process your personal data, what we will process and why. This page is that notice. It is written to be read, not skimmed past. If any part of it is unclear, write to grievance@milansalvi.com and we will explain it.
1. Who we are — the Data Fiduciary
MockTest is an online mock test and practice exam service for school students. It is owned and operated by Leena Software Solutions.
We are the Data Fiduciary in respect of your personal data under the DPDP Act, 2023. That means we decide what personal data is collected on this website and what is done with it, and we are answerable to you and to the Data Protection Board of India for it. You are the Data Principal.
- Legal entity
- Leena Software Solutions
- Entity type
- Sole Proprietorship
- Proprietor
- Milan Manohar Salvi
- Brand operated
- MockTest — https://mocktest.milansalvi.com
- Registered address
- Shree Satyam, Plot No 65, Flat No 104, Sai Section, Ambernath East, Thane, Maharashtra, 421501, India
- Phone
- +91 78875 66152 (Monday to Friday, 10:00 AM to 6:00 PM IST)
- Support email
- support@milansalvi.com
- Privacy and grievance email
- grievance@milansalvi.com
An account on MockTest is registered and operated by a parent, legal guardian, or an authorised school or teacher, who must be 18 years of age or older. A child uses the service under that adult's supervision. Where this policy says "you", it means that adult account holder. Section 10 sets out how a child's data is handled.
2. The personal data we collect
We collect only what the service actually needs to run. The table below lists every category of personal data our systems hold. There is nothing collected outside this list.
| Category | Exactly what we hold | How we get it |
|---|---|---|
| Account data | Full name; username; email address; a one-way hash of your password (we never store the password itself); the class or grade level you select; a roll number we generate for you; an optional avatar image (JPEG or PNG, up to 200 KB); and a single-use email verification token. | You type it into the registration form at /register.php or your profile page. |
| Teacher and school account data | Full name; username; mobile number; a one-way hash of the password; and an optional avatar image. Teacher accounts do not carry an email address. | Entered by the school administrator when the teacher account is created. Teacher accounts are not self-registered. |
| Payment data | Order ID; payment ID; the amount in INR; the payment method used (for example UPI, card, netbanking); the email address and mobile number you enter on the gateway's checkout; the payment and order status; and the transaction response returned to us by the gateway. | Returned to us by Razorpay Payments Private Limited after you complete a payment. |
| Usage data | The mock tests you start; the option you select for each question; the exam start time and the time you take; whether an exam was completed; your marks and pass or fail result; and your login and logout times for each session. | Generated by your use of the service. |
| Technical data | A PHP session cookie used to keep you signed in; the IP address your device connects from; the name of the page requested; the date and time of the request; and the approximate size in kilobytes of each page served, which we use to monitor server load. | Recorded automatically when a signed-in user loads a page. |
| Correspondence | The emails or messages you send us and our replies, including anything you choose to put in them. | You send it to us. |
We never see your card details
We do not store card numbers, CVV codes or expiry dates. We never receive them at all. Payments are taken on the hosted checkout of Razorpay Payments Private Limited, which loads directly from the gateway's own systems. Card, UPI and netbanking credentials are entered there and go straight to the gateway. They never touch our servers, our database or our logs. What comes back to us is only the order reference, the payment reference, the amount, the method name, and the status.
We do not collect your postal address, your date of birth, your government ID numbers, your location, or your contacts. We do not buy personal data from anyone, and we do not sell, rent or trade your personal data to anyone.
3. Why we collect it — our purposes, itemised
Each purpose below is a separate, specific reason for processing, and each one maps to a data category from section 2. We do not process your data for any purpose that is not on this list.
- To create your account and give it a unique username and roll number — account data.
- To verify that the email address is real, by sending one verification link that you must click before the account can be used — email address, verification token.
- To sign you in and keep you signed in while you move between pages and while a test is running — username, password hash, session cookie.
- To show the correct mock tests for the class or grade level selected on the account — class.
- To display the avatar on the profile page, if one has been uploaded — avatar image.
- To take payment for a mock test and to confirm with the gateway that the payment succeeded before the test is unlocked — payment data.
- To keep an accurate record of each transaction so that we can answer refund and chargeback queries and meet Indian financial record-keeping obligations — payment data.
- To run a test and enforce its time limit, by recording when the test started and how much time remains — usage data.
- To mark the test and show you the result, including your score, pass or fail status, and the answer sheet showing what you selected — usage data.
- To keep the account secure, by recording login and logout times, the page requested and the originating IP address, so that unauthorised access or misuse can be detected and investigated — usage data, technical data.
- To monitor server capacity, using the recorded page size and request counts, so the site stays available during a live test — technical data.
- To answer your support messages and handle grievances under section 13 — correspondence, account data.
- To comply with Indian law and to respond to a lawful order from a court, regulator or authorised government agency — any category, limited to what the order requires.
We do not profile you, we do not score you for advertising, and we do not use your data to train any machine learning model.
4. Your consent and the legal basis for processing
This section is the notice required by section 5 of the DPDP Act, 2023. We process your personal data on the basis of your consent, given when you create an account and when you make a payment, and for the specific purposes itemised in section 3 above.
Your consent must meet the standard set by the Act, and we ask for it on that basis:
- Free. You are not required to accept anything beyond what the service needs to run.
- Specific. It is given for the itemised purposes in section 3, not for open-ended future uses.
- Informed. This notice tells you what we collect, why, for how long, and who else receives it, before you give it.
- Unconditional. We do not bundle it with unrelated permissions.
- Unambiguous. It is a clear affirmative act — submitting the registration form, or completing a payment.
- Limited to what is necessary. We process only the data needed for the stated purpose, and nothing more.
Withdrawing your consent
You may withdraw your consent at any time, and it must be as easy to withdraw it as it was to give it. Email grievance@milansalvi.com from the address registered on the account, with the word "Withdraw consent" in the subject line. We will act on it once we have verified that the request came from the account holder.
Plainly, here is what withdrawal means:
- We stop processing your personal data for the purposes you have withdrawn consent for.
- If you withdraw consent for the account itself, the account is closed. You lose access to MockTest, to any test you have paid for and not yet taken, and to your past results and answer sheets.
- Withdrawal works going forward. It does not undo processing that was lawfully done before you withdrew.
- Withdrawal does not by itself entitle you to a refund. Refunds are governed by our Cancellation and Refunds Policy.
- We must still keep the records listed in section 5 that Indian law requires us to retain, in particular transaction records. We keep those and nothing else.
5. How long we keep your data
We do not keep personal data indefinitely. Each category has a fixed retention period, set by one of three criteria: how long the account is in use, how long Indian law requires us to keep a record, or how long a dispute could reasonably be raised. Once the period ends, the data is erased or irreversibly anonymised so it can no longer identify anyone.
| Data | How long we keep it | Why that period |
|---|---|---|
| Account data | For as long as the account is active, and then 90 days after the account is closed, after which it is erased. | The 90 days allow the account to be restored if it was closed in error, and allow any final billing query to be settled. |
| Teacher and school account data | For as long as the teacher account is active, and then 90 days after the school asks us to close it, after which it is erased. | The same period as any other account, for the same reason: it allows an account closed in error to be restored. |
| Email verification token | Deleted from our database the moment the email address is verified. If an account is never verified, it is deleted after 90 days. | The token has no purpose once used. |
| Avatar image | Until you replace it, or until 90 days after the account is closed. Deleted immediately if you ask us to remove it. | It exists only to appear on your own profile page. |
| Exam attempts, answers, timings and results | For as long as the account is active, and then 90 days after the account is closed. | You need your history to track progress. It has no value to us once the account is gone. |
| Payment and transaction records | 8 years from the end of the financial year in which the transaction took place. | Indian statutory financial and tax record-keeping obligations, and the window for payment disputes and chargebacks. We keep these even after an account is closed, and we keep nothing beyond the transaction record itself. |
| Session and access logs (login and logout times, page requested, IP address, request size) | 180 days from the date of the entry, then deleted. | Long enough to investigate a security incident or an account dispute; short enough that we are not sitting on a needless history of your activity. |
| Support and grievance correspondence | 3 years from the date the matter is closed. | So we can show what was asked, what we answered and when, if the matter is reopened or escalated. |
The 180-day period for session and access logs is enforced by a scheduled job that runs every day and deletes entries older than that. It is not a period we apply by hand when we remember to. An account closure is actioned by us on request, and the 90-day clock for account data runs from the date we close it.
A verified erasure request is handled faster than these periods. See section 9 — we act on it within 7 days.
6. Who else receives your data — our Data Processors
We share personal data with two service providers, and only to the extent each one needs it to do its job. Both are named below. We do not share your personal data with anyone else, we do not sell it, and we do not disclose it for advertising.
| Who | What they receive | Why |
|---|---|---|
| Razorpay Payments Private Limited Payment gateway |
The name or description of the test being bought, the amount in INR, the order reference, and the email address and mobile number you enter on its checkout. Your card, UPI or netbanking credentials go to the gateway directly and are never routed through us. | To collect the payment, authenticate it, and tell us whether it succeeded so we can unlock the test. |
| Hostinger Web hosting provider |
All data described in section 2, in the sense that it is stored on the servers they operate for us, along with the outbound verification email we send you. | To host the website, run the database and file storage, and deliver our transactional email. |
Razorpay Payments Private Limited also processes your data as a Data Fiduciary in its own right for its regulatory obligations as a payment aggregator. Its own privacy policy governs that processing, and we recommend you read it.
We require every processor to keep personal data secure, to process it only on our instructions and only for the purpose above, and not to retain it longer than needed. Engaging a processor does not transfer our responsibility. We remain liable to you as the Data Fiduciary under the DPDP Act for how your personal data is handled.
We may also disclose personal data where we are legally obliged to — to a court, a regulator, a law enforcement agency or the Data Protection Board of India acting under a valid order. We disclose only what the order requires, and we keep a record of it.
7. Where your data is stored, and transfers outside India
Our website, database and uploaded files are stored on servers located in India. All payment transaction records are held in India.
We do not transfer your personal data outside India for storage or for processing. Both processors named in section 6 hold your data on servers in India: Razorpay Payments Private Limited is incorporated in India and is regulated here as a payment aggregator, and our hosting account with Hostinger is provisioned on an Indian data centre region. There is no analytics provider, no advertising network, no content delivery network and no other vendor in the chain: every script, stylesheet, font and image on this site is served from this domain, so browsing the site discloses nothing about you to any third party other than the payment gateway when you are actually on its checkout.
The one flow that can cross a border is vendor support access. Hostinger is a company incorporated outside India, and its support and administration staff may access the hosting account from outside India when we raise a support request. That access is limited to what the request requires, it is not routine, and no copy of the database is moved abroad for it. Any such access is made only to a country that has not been restricted by the Government of India under section 16 of the DPDP Act. We do not transfer personal data outside India for any other reason, and we do not transfer it to any party not named in section 6.
If we ever change where data is stored, this section is updated before the change takes effect.
8. Cookies
MockTest sets one cookie: the standard PHP session cookie.
- What it is. A short random session identifier issued by the server.
- What it does. It links your browser to your signed-in session, so you stay logged in between pages and so an exam in progress and its timer belong to the right account.
- What it contains. Only the session identifier. No name, no email address, no password, no payment information.
- How long it lasts. It is a session cookie. It is removed when you log out or when the browser session ends.
- Is it optional? No. It is strictly necessary. Without it you cannot log in or take a test. That is why we do not show a cookie banner offering to switch it off — there is nothing optional to switch off.
We set no advertising cookies, no analytics cookies and no third-party tracking cookies. There is no Google Analytics tag, no advertising pixel, no session-recording script and no behavioural tracking of any kind on this site. The one exception you should know about is that when you are on the payment checkout, that checkout is operated by Razorpay Payments Private Limited and may set its own cookies under its own policy, which is necessary for the payment to work.
9. Your rights as a Data Principal
The DPDP Act gives you the following rights over your personal data. All of them are free to exercise. To use any of them, email grievance@milansalvi.com from the email address registered on the account, stating the username on the account and which right you are exercising. We verify that the request is genuinely yours before we act on it, because acting on an unverified request would itself be a data breach. A teacher or school account carries no email address of its own, so a request about one is made by the school administrator who created it, or by phone on the number in section 13, and we verify it against the mobile number held on the account.
| Your right | What it means | How to use it, and by when we act |
|---|---|---|
| Access | To get a summary of the personal data we hold about you, what we are doing with it, and the identities of everyone we have shared it with. | Email the grievance address with the subject "Access request". We respond within 30 days, usually much sooner. |
| Correction | To have inaccurate or misleading personal data corrected. | You can change your own name, class, avatar and password from your profile page after signing in. For anything else, email the grievance address. We correct verified errors within 48 hours of verifying them. |
| Completion and updating | To have incomplete or out-of-date personal data completed or brought up to date. | Same route as correction, above. |
| Erasure | To have your personal data erased when it is no longer needed for the purpose it was collected for, or when you withdraw consent. | Email the grievance address with the subject "Erasure request". We erase within 7 days of verifying the request. We must keep transaction records for the statutory period in section 5; we tell you exactly what was kept and why. |
| Grievance redressal | To complain about how we have handled your data, and to have that complaint dealt with properly. | Section 13 sets out the full process, our named Grievance Officer, and our timelines. See also Grievance Redressal. |
| Nomination | To nominate another individual who may exercise all of these rights on your behalf if you die or become incapable of exercising them yourself. | Email the grievance address with the subject "Nomination", giving the nominee's full name, their email address and their relationship to you. We record the nomination against the account and confirm it in writing. You can change or cancel a nomination the same way, at any time. |
| Withdraw consent | To stop us processing your data for a purpose you previously consented to. | See section 4. Email the grievance address with the subject "Withdraw consent". |
The DPDP Act also places duties on you as a Data Principal. Please give us accurate information, do not register using someone else's identity or email address, and do not file a false or frivolous grievance. If the data on the account is wrong because it was entered wrongly, tell us and we will fix it.
10. Children's data and parental consent
MockTest exists for school students, so this section matters more here than almost anywhere else. Our position is simple and it is the same on every page of this site:
- An account is registered and operated by a parent, legal guardian, or an authorised school or teacher, who must be 18 years of age or older.
- The registration form at
/register.phpcarries a required confirmation that the person registering is 18 or older and is the parent, the legal guardian, or a teacher authorised by the school of the student named on the form, and that they accept this policy and the Terms. Ticking it is how that adult gives verifiable consent for the child's personal data to be processed for the purposes in section 3. The confirmation is checked on the server, so an account cannot be created without it, and the date and time it was given are recorded against the account. - A child does not enter into a contract with us. The adult account holder is the person who contracts with us and who makes payment.
- A child uses the service only under that adult's supervision.
We verify parental or guardian status by requiring the adult to hold and confirm the registered email address for the account, and by requiring that same address to be used for any request that affects the child's data. Where we have reason to doubt that consent is genuine, we may ask for further confirmation before we continue processing, and we may suspend the account until we get it.
We do not undertake tracking or behavioural monitoring of children, and we do not serve targeted advertising to children. The DPDP Act expressly prohibits these, and we comply. We show no advertising on this site at all. We do not build profiles of children, we do not share children's data with advertisers, and there is no analytics or tracking script on any page (see section 8). The only data we hold about a child is the account data and the exam data listed in section 2, and it is used only to run the tests and show the results.
We do not process a child's personal data in any way that is likely to cause a detrimental effect on the child's wellbeing.
How a parent, guardian or school can access or delete a child's data
Email grievance@milansalvi.com from the email address registered on the account, stating the username. You may ask us to:
- send you everything we hold about the child, in a readable form;
- correct anything that is wrong;
- delete the account and the child's data, which we do within 7 days of verifying the request, keeping only the transaction records that section 5 requires; or
- withdraw consent, which closes the account as described in section 4.
11. How we protect your data
We take reasonable security safeguards to prevent a personal data breach. These are the measures actually in place. We do not claim any security certification we do not hold, and we hold none.
- Encryption in transit. The whole site is served over HTTPS with TLS. Data moving between your browser and our server is encrypted.
- Passwords are hashed, never stored. Passwords are put through PHP's
password_hash()function using the platform's current default algorithm, with a per-password salt. We cannot read your password, and neither can anyone who obtained a copy of the database. If you forget it, we reset it — we cannot tell you what it was. - No card data on our servers. Card numbers, CVV codes and expiry dates are entered on the gateway's hosted checkout and never reach us. There is nothing of that kind in our database to steal.
- Access control. Signing in is required for every page that touches personal data, and student, teacher and administrator roles are separated so each role sees only what it needs.
- Parameterised database queries. Data submitted through the site is passed to the database using prepared statements with bound parameters, which is the standard defence against SQL injection.
- Cross-site request forgery protection. Account forms, including registration, carry a per-session CSRF token that is checked on submission.
- Recorded consent. The adult account holder's confirmation described in section 10 is a required field on the registration form, is checked on the server before any account is created, and is stamped against the account with the date and time it was given.
- Email verification. An account registered through
/register.phpcannot be used until the registered email address has been confirmed through a single-use link, which prevents accounts being opened on someone else's address. Teacher and school accounts are not self-registered — they are created by an administrator — so this step does not apply to them. - Upload restrictions. Avatar uploads are limited to JPEG and PNG files under 200 KB and are stored under a generated filename.
- Session logging. Login and logout times and the originating IP address are recorded so unauthorised access can be spotted and investigated.
No system connected to the internet can be guaranteed completely secure. Please help us by choosing a password you do not use anywhere else, not sharing your login, and logging out on a shared or school computer. If you think an account has been accessed without permission, tell us at once at grievance@milansalvi.com.
12. Personal data breaches
If a personal data breach occurs, we act on it rather than sit on it. Our commitments:
- We will notify the Data Protection Board of India within 72 hours of becoming aware of the breach, in the manner the Board requires.
- We will notify every affected user without undue delay, by email to the address registered on the account.
- That notice will describe, in plain words: the nature and extent of the breach; when it happened and when we found out; the categories of personal data involved; the likely consequences for you; the steps we have taken to contain it and stop it recurring; what you should do to protect yourself; and who to contact for more.
- We will keep you updated as the investigation progresses, and we will publish a summary here where the breach affected a large number of users.
13. Grievance Officer
We have appointed a Grievance Officer as required by the DPDP Act, 2023 and by the Information Technology (Intermediary Guidelines) Rules. Any question, complaint or request about your personal data goes to this person.
- Grievance Officer
- Milan Manohar Salvi
- Designation
- Proprietor, Leena Software Solutions
- grievance@milansalvi.com
- Phone
- +91 78875 66152
- Address
- Leena Software Solutions, Shree Satyam, Plot No 65, Flat No 104, Sai Section, Ambernath East, Thane, Maharashtra, 421501, India
- Hours
- Monday to Friday, 10:00 AM to 6:00 PM IST
- We acknowledge
- Within 48 hours of receiving your complaint.
- We resolve
- Within 30 days of receiving your complaint.
The full process, including what to put in a complaint and how escalation works, is on our Grievance Redressal page.
Escalation. If we have not resolved your grievance within 30 days, or if you are not satisfied with how we resolved it, you have the right to complain to the Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023, using the process the Board publishes. You do not need our permission to do this, and we will not treat you any differently for doing it.
14. Changes to this policy
We update this policy when the service changes, when we add or remove a service provider, or when the law changes. When we do:
- the "Last updated" date at the top of this page changes;
- the updated policy is published here, at https://mocktest.milansalvi.com/policy/privacy-policy.php, and takes effect on the date shown;
- if the change is significant — a new purpose, a new category of data, a new processor, a longer retention period, or a change in where data is stored — we email every account holder at the registered address before the change takes effect, and where the DPDP Act requires fresh consent, we ask for it rather than assume it.
We do not apply a new purpose retrospectively to data already collected without telling you first.
15. Governing law
This Privacy Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and the rules made under it. Any dispute arising out of or relating to this policy or to our processing of your personal data is subject to the exclusive jurisdiction of the courts in Maharashtra, India. This does not affect your right to approach the Data Protection Board of India.
16. Contact us
For anything about your personal data, this policy, or a grievance, use the grievance address. For everything else — billing, access to a test, technical trouble — use the support address. We answer both.
- Legal entity
- Leena Software Solutions (Sole Proprietorship), operating MockTest
- Proprietor
- Milan Manohar Salvi
- Registered address
- Shree Satyam, Plot No 65, Flat No 104, Sai Section, Ambernath East, Thane, Maharashtra, 421501, India
- Phone
- +91 78875 66152
- Support email
- support@milansalvi.com
- Privacy, data protection and grievance email
- grievance@milansalvi.com
- Business hours
- Monday to Friday, 10:00 AM to 6:00 PM IST
- Website
- https://mocktest.milansalvi.com
Read alongside our Terms and Conditions, Cancellation and Refunds Policy, Shipping and Service Delivery Policy and Grievance Redressal page.