Privacy Charter
Academic privacy policy. Data collection minimal. Storage AES-256. GDPR compliant. COPPA.

Privacy charter
Data minimization: only operationally necessary data. Never sell. Never share with ad networks.
Storage: 256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1.
GDPR rights: access (JSON within 30 days), correct, delete (5-year KYC retention).

Course FAQ
Privacy charter overview
We collect only operationally necessary data: account, KYC, payment, gameplay. We never sell. We never share with ad networks. We never sell browsing data, location data, social graph.
Storage: 256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1. SOC 2 Type 2 audited annually by Ernst & Young.
GDPR rights: access (JSON within 30 days, avg 48 hours), correct, delete (subject to 5-year KYC retention), export, opt-out of marketing, opt-out of analytics.
Data collection minimal
Account data: mobile number, email, username, password hash. Required for account creation.
KYC data: PAN + Aadhaar (verified via CBDT + OTP). Required for withdrawal.
Payment data: UPI ID, bank account (encrypted). Required for deposit/withdrawal.
Gameplay data: picks, contest entries, ROI tracking. Used for captain pick recommendations and methodology improvement.
Storage and security
256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1 compliance. SOC 2 Type 2 audited annually by Ernst & Young. Penetration tested quarterly by third-party.
Backup: encrypted backups every 6 hours, 30-day retention. Disaster recovery tested annually.
Access control: role-based access (RBAC), MFA required for admin access, audit logs retained 12 months.
Sub-processors and partners
6 verified sub-processors with DPAs: 1. Stripe payments (PCI-DSS), 2. AWS hosting (SOC 2), 3. Twilio SMS (HIPAA), 4. Sendgrid email (GDPR compliant), 5. Cloudflare CDN (SOC 2), 6. Persona KYC (SOC 2).
All DPAs signed Q1 2026. Sub-processors vetted for security, privacy, and compliance.
Data residency: India (AWS Mumbai region). No data leaves India unless explicit user consent for international features.
Data retention and deletion
Account data: 7 years post-closure (KYC legal requirement). Analytics: 26 months. App logs: 12 months.
After retention: data anonymized for research. We don't keep raw data beyond retention period.
User deletion request: account closed within 30 days. KYC data retained 5 years (regulatory). Marketing data deleted immediately.
GDPR rights and compliance
Access (JSON within 30 days, avg 48 hours): user requests data export via /privacy/export/. Get JSON file with all account, KYC, payment, gameplay data.
Correct: user can edit account info via app settings. KYC corrections require re-verification.
Delete: user can delete account via /privacy/delete/. 30-day cooling period, then permanent deletion.
Is the comeon academy safe?
How accurate is the academic AI?
Can I trust academy reviews?
What is COMWIN100?
How do I download the app?
Is comeon legal in India?
What is the mega contest?
How to track ROI?

Frequently Asked Questions
Is the comeon academy safe and regulated?
How accurate is the academic AI captain pick methodology?
Can I trust academy reviews and editorial independence?
What is the welcome code COMWIN100 and how do I use it?
How do I download the official comeon app safely?
Is comeon legal in India and what are the eligibility requirements?
What is the mega contest prize pool and how are winners selected?
How do I track my ROI and improve my captain pick accuracy?
Verified Statistics
| Metric | Value |
|---|---|
| Encryption at Rest | 256-bit AES |
| Encryption Transit | TLS 1.3 |
| PCI-DSS | Level 1 compliant |
| SOC 2 Type 2 | Annual audit EY |
| GDPR Rights | Access/correct/delete |
| Sub-processors | 6 verified partners |
Related topics
Related: Data collection minimal
We collect only operationally necessary data: account, KYC, payment, gameplay. Never sell. Never share with ad networks. Never sell browsing data, location data, social graph.
Related: Storage and security
256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1. SOC 2 Type 2 audited annually by Ernst & Young. Penetration tested quarterly by third-party.
Related: GDPR rights
Access (JSON within 30 days, avg 48 hours), correct, delete (subject to 5-year KYC retention), export, opt-out of marketing, opt-out of analytics. 72-hour breach notification.
Related: Sub-processors
6 verified sub-processors with DPAs: Stripe, AWS, Twilio, Sendgrid, Cloudflare, Persona. All SOC 2 compliant. All DPAs signed Q1 2026.
Continue learning
Use code COMWIN100 for Rs 100 welcome bonus on comeon platform.