1. Lifecycle Governance & Data Minimization Mandate
DPGNotes enforces an uncompromising data lifecycle policy grounded in the statutory principle of storage limitation. Under Section 8(7) of the Digital Personal Data Protection (DPDP) Act, 2023 and Article 5(1)(e) of the European General Data Protection Regulation (GDPR), personal data must not be stored for longer than is strictly necessary to fulfill the educational purpose for which it was collected. Once those educational and operational goals are concluded, personal information must be permanently expunged or anonymized.
This Data Retention & Disposal Policy establishes transparent lifecycle schedules, automated purging routines, self-service account termination mechanisms, and cryptographic disposal standards across all DPGNotes data repositories.
Explicit Schedules
Auditable lifespan thresholds for every category of user profile, guest token, cover page log, and security event.
Self-Service Erasure
One-click account and log deletion via the Danger Zone permanently removes database records across all nodes.
Automated Pruning
Automated database scheduled routines purge expired guest tokens and transient analytics weekly.
2. Comprehensive Data Retention Schedule
Our infrastructure enforces strict automated and policy-based retention windows across seven operational categories:
| Data Category | Retention Window | Lifecycle Trigger | Automated Disposal Standard |
|---|---|---|---|
| Anonymous Guest Identifiers | 12 Months | Date of last active HTTP request | Automated scheduled batch delete from client & server records. |
| Daily Generation Quota Tokens | 24 Hours | Rolling 24-hour cycle or midnight UTC | Client-side storage key reset; expired cache eviction. |
| Cover Page Generator Logs (Guests) | 30 Days | Generation timestamp | Hard deletion from temporary generator collection; self-delete option available. |
| Cover Page Generator Logs (Contributors) | Account Lifespan | Active contributor tenure | Retained for student portfolio management; hard deleted upon user request or account closure. |
| Contributor Profiles & Karma | Duration of Membership | Until voluntary deletion request | Cascading hard deletion across authentication and profile database documents. |
| Uploaded Academic Notes & Guides | Indefinite / Author Discretion | Active publication status | Immediate delisting and storage bucket deletion upon author removal request. |
| Cybersecurity Audit Logs | 180 Days | Event recording timestamp | Cryptographic purge and physical overwriting of rotated log archives. |
| Grievance, DMCA & Appeal Files | 24 Months | Formal ticket resolution date | Archived in encrypted cold storage for statutory audit, then irreversibly shredded. |
3. Cover Page Generator Data Lifecycle & User Control
Our document preparation utilities (the Assignment Cover Page Generator and Practical Cover Page Generator) handle student submission metadata, including Student Name, Roll Number, Subject Code, and Course/Section. We enforce strict data handling protocols for this information:
- Local-First Preview: Cover page generation logic executes entirely in the client browser's memory. Document layout rendering occurs on client canvas/HTML components without transmitting drafts to third-party ad networks.
- Logging for History & Re-Editing: Submitted generator records are logged to support quick-action user features (View, Download, Edit, and Delete).
- Immediate Self-Service Log Purge: Both guest users and registered contributors possess real-time control to remove any generated log entry directly from their history view, triggering an immediate database deletion.
4. Self-Service Account Termination: The Danger Zone Protocol
Every registered student contributor exercises uninhibited autonomy over their digital presence on DPGNotes. Through your Contributor Dashboard → Account Settings → Danger Zone, you can trigger irreversible account closure at any time. When invoked, our database executes an atomic deletion transaction:
- Your authenticated User UID, display handle, contact email, and biographical details are permanently purged from our primary database.
- Active session authorization tokens are instantly revoked across all connected devices.
- Note Retention Choice: You are provided a clear binary choice: (a) delete all your uploaded lecture notes permanently from the platform, or (b) release your study guides into the open public domain under anonymous community attribution so future students can continue benefiting from your educational contributions.
5. Statutory Right to Erasure (Right to Be Forgotten)
Under Section 12 of the DPDP Act 2023 and GDPR Article 17, students hold the statutory right to request the total erasure of any personal information held by DPGNotes. If you wish to execute a formal erasure request outside the automated self-service dashboard:
- Submit a signed erasure request to our Data Protection Officer at its.akshatnetworkhub23@gmail.com.
- Specify your registered email or contributor profile handle.
- Verification and hard deletion are finalized within thirty (30) calendar days, accompanied by an electronic certificate of disposal.
6. Cryptographic Shredding & Secure Disposal Standards
When data reaches its retention threshold or an erasure directive is executed, DPGNotes ensures that records cannot be reconstructed, recovered, or carved from residual cloud blocks:
- NIST SP 800-88 Conformance: Logical database deletions overwrite indexes and document fields in accordance with NIST Special Publication 800-88 Guidelines for Media Sanitization.
- Key Shredding: For encrypted cold storage archives, data disposal is finalized through cryptographic key shredding—destroying the decryption keys, rendering underlying ciphertext mathematically unrecoverable.
7. Legal Hold Exceptions & Statutory Preservation
The standard retention schedules articulated herein are subject to temporary suspension solely in cases of formal Legal Hold. Where DPGNotes receives a binding statutory preservation order from a court of competent jurisdiction or a registered cyber police notice under Section 91 of the Code of Criminal Procedure / Bharatiya Nagarik Suraksha Sanhita (BNSS), records directly pertinent to an active cyber fraud investigation or copyright lawsuit will be isolated and preserved until formal judicial release.
Data Governance & Erasure Desk
DPGNotes Privacy Rights & Records Lifecycle Office
Official Erasure Email: its.akshatnetworkhub23@gmail.com
Grievance & Erasure Ticket: Support & Data Erasure Portal
SLA Guarantee: Erasure and account disposal requests fulfilled within 30 days.