GDPR Compliance & Data Protection Statement

AIMOCK.IN (BVS INFOTECH Private Limited)

Effective Date: 12 January 2026 | Last Updated: 12 January 2026

BVS INFOTECH Private Limited ("BVS INFOTECH", "we", "us", or "our") is committed to protecting personal data and ensuring compliance with the EU General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679.

This statement explains how AIMOCK.IN, our AI-based interview and assessment platform, processes personal data of users located in the European Economic Area (EEA).

1. Scope of This Statement

This GDPR Compliance Statement applies to:

  • Students, candidates, and users accessing AIMOCK.IN
  • Educational institutions, universities, and corporate clients within the EEA
  • Personal data processed during AI mock interviews, assessments, proctoring, and analytics

2. Roles & Responsibilities Under GDPR

RoleEntity
Data ControllerInstitutions / Universities / Clients using AIMOCK.IN
Data ProcessorBVS INFOTECH Private Limited (AIMOCK.IN)

As a Data Processor, BVS INFOTECH processes personal data only on documented instructions of the Data Controller and does not use data for any independent purpose.

3. Categories of Personal Data Processed

Depending on services enabled by the Controller, we may process:

  • Identity data (name, email, student ID)
  • Audio, video, and image data (mock interviews, proctoring)
  • Assessment responses and scores
  • Behavioral and communication analysis data
  • Technical data (IP address, device, browser, logs)
  • Usage and activity data

⚠️ We do not intentionally process special category data under Article 9 unless explicitly required and authorized by the Controller.

4. Lawful Basis for Processing (Article 6)

Personal data is processed under one or more of the following lawful bases:

  • Consent – explicit consent for AI monitoring, recording, and analysis
  • Contractual Necessity – to deliver assessment and interview services
  • Legitimate Interest – ensuring exam integrity, fraud prevention, analytics
  • Legal Obligation – compliance with applicable laws and regulations

5. Data Subject Rights (Articles 12–23)

EEA users have the following rights:

  • Right to access personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("Right to be Forgotten")
  • Right to restrict processing
  • Right to object to processing
  • Right to data portability (machine-readable format)
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority

📧 GDPR Requests: Email: gdpr@bvsinfotech.co

Requests will be responded to within 30 days, as required by GDPR.

6. Data Retention Policy

  • Personal data is retained only for the duration defined by the Data Controller
  • Default maximum retention: 90 days
  • Data is securely deleted or anonymized after retention expiry
  • Institutions may request shorter retention periods

7. Data Security Measures (Article 32)

We implement appropriate technical and organizational measures, including:

  • Encryption at rest and in transit
  • Role-based access control (RBAC)
  • Secure cloud infrastructure
  • Audit logs and monitoring
  • Regular vulnerability assessments
  • Confidentiality agreements with staff and vendors

8. Data Transfers Outside the EEA

Where personal data is transferred outside the EEA, we ensure:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • GDPR-compliant cloud and hosting providers
  • Adequate safeguards for data protection and confidentiality

9. Sub-Processors

BVS INFOTECH may engage trusted sub-processors (cloud hosting, AI services) who:

  • Are GDPR-compliant
  • Operate under written Data Processing Agreements (DPAs)
  • Process data only on our instructions

A list of sub-processors can be provided upon request.

10. Data Breach Notification (Articles 33 & 34)

In the event of a personal data breach:

  • We will notify the Data Controller within 72 hours
  • We will provide details of:
    • Nature of the breach
    • Affected data
    • Mitigation actions
  • Controllers remain responsible for notifying supervisory authorities and data subjects, where required

11. Data Protection Officer (DPO)

A designated Data Protection Officer (DPO) oversees GDPR compliance.

📧 DPO Contact: dpo@bvsinfotech.co

12. Accountability & Documentation

BVS INFOTECH maintains:

  • Records of Processing Activities (ROPA)
  • Data Processing Agreements (DPAs)
  • Internal GDPR compliance policies
  • Employee data protection training

13. Updates to This Statement

This statement may be updated to reflect regulatory or operational changes. The latest version will always be available on AIMOCK.IN.

14. Contact Information

Company Name: BVS INFOTECH Private Limited

Platform: AIMOCK.IN

📧 General Contact: support@aimock.in

📧 GDPR: gdpr@bvsinfotech.co