Privacy Policy for TRACER
1. Introduction and Commitment
Welcome to TRACER (Teacher's Research Accreditation Criteria Explorer & Repository), an academic research management platform provided by BytesWrite Solution Private Limited (“BytesWrite”, “we”, “us”, or “our”). We are deeply committed to safeguarding the privacy and confidentiality of faculty research information, institutional credentials, and publication analytics.
Our core commitments guiding academic data handling include:
- “Research Integrity”: We protect the confidentiality of research data and academic information.
- “Faculty Privacy”: We respect the privacy rights of faculty members and researchers.
- “Institutional Trust”: We maintain the highest standards for educational data protection.
- “Regulatory Compliance”: We adhere to academic data protection regulations including GDPR, and the Digital Personal Data Protection Act (DPDP), 2023.
- “Transparent Practices”: We provide clear information about our data handling practices.
- “Innovation Focus”: We foster a culture of innovation, continuously seeking new ways to enhance user privacy and data protection.
Please read this Privacy Policy carefully to understand our practices regarding your research data, faculty records, and institutional information. By using TRACER, you acknowledge and agree to the practices described in this Privacy Policy.
2. Scope of This Policy
This Privacy Policy governs all data collection, indexing, analysis, and reporting activities across TRACER, including:
- Faculty research tracking and performance evaluation.
- Academic publication and citation management.
- NAAC accreditation support and reporting.
- Integration with academic platforms (Google Scholar, Scopus, ResearchGate, ORCID).
- Administrative dashboards and analytics.
- Institutional research repositories.
TRACER is utilized under agreements with educational institutions and research bodies. Individual user access is managed in accordance with institutional authorization and applicable research governance frameworks.
3. Definitions
In this Privacy Policy, key academic and data protection terms are defined as follows:
- Application: Refers to the TRACER Academic Research Management System.
- Personal Data or Personal Information: Refers to any information related to you or information that can identify you, collectively referred to as "Personal Data" or "Personal Information".
- Processing: Refers to the handling, sharing, processing, protecting, or storing of your Personal Data within the academic research management context.
- Data Principal: Individual whose personal data is processed by TRACER.
- Faculty Member: Academic staff using TRACER for research management.
- Administrator: Institutional personnel managing TRACER implementation.
In this Privacy Statement, the terms “Us,” “We,” and “Our” refer to BytesWrite Solution Private Limited and its authorized group entities that operate and maintain the TRACER research management platform.
4. Comprehensive Academic Data Collection Framework
TRACER gathers and structures academic information across multiple stakeholders to support research evaluation and NAAC accreditation:
| Data Category | Faculty Members | Administrators | Research Staff |
|---|---|---|---|
| Personal Data | Name, email address, phone number, institutional affiliation, academic credentials, ORCID ID | Name, email address, administrative role, system permissions, institutional settings | Name, email address, research collaboration data, research collaborator information |
| Research Data | Publication history, citation metrics, h-index, Google Scholar data, journal details, conference presentations | Faculty performance reports, institutional analytics, NAAC compliance data, system configuration logs | Research project details, collaborative networks, inter-institutional partnerships |
| Technical Data | Platform usage logs, login patterns, feature utilization, document uploads | System administration activities, data validation logs, backup management | Research data validation activities, quality assurance metrics |
5. Enhanced Data Processing And Usage
Every data processing activity in TRACER is underpinned by a lawful, recognized legal basis under the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act (DPDP), 2023.
5.1 Primary Processing Purposes
| Processing Purpose | Description |
|---|---|
| Automated Academic Data Integration | TRACER employs advanced data crawling capabilities from academic platforms, particularly Google Scholar, to automatically gather publication data, citation metrics, and research performance indicators. |
| Administrative Verification Process | Every data entry undergoes rigorous validation by administrators through reliable academic sources such as Scopus and Scimago, ensuring accuracy and authenticity of research information. |
| Direct Faculty Input | Faculty members provide personal and professional information through secure forms, including research achievements, academic credentials, and collaboration details. |
| External Academic Sources | We may obtain academic data from publicly available sources including business-oriented academic networks and research databases, subject to established internal controls. |
5.2 Accreditation & Performance Legal Basis
| Legal Basis | Purpose |
|---|---|
| Faculty Performance Evaluation | Comprehensive research scoring and academic performance metrics |
| NAAC Accreditation Support | Streamlined data management and compliance reporting for institutional accreditation |
| Research Analytics | In-depth analysis of research performance at individual and departmental levels |
| Academic Reporting | Advanced performance reports covering current and five-year academic periods |
5.3 General Legal Grounds
| Legal Basis | Application in TRACER | Examples |
|---|---|---|
| Legitimate Interests | Delivering effective academic products, maintaining data security, improving research analytics | Research performance tracking, platform optimization |
| Legal and Professional Obligations | Compliance with academic regulations, institutional policies, NAAC requirements | Accreditation reporting, regulatory compliance |
| Contractual Necessity | Fulfilling service agreements with educational institutions | Account management, service delivery |
| Consent | Processing of sensitive academic data where required | Special research categories, marketing communications |
5.4 Academic Operations
TRACER utilizes validated academic data to facilitate:
- Research Collaboration: Facilitating connections between faculty members and research collaborators
- Data Validation: Ensuring accuracy of research information through administrative oversight
- Communication: Email notifications for data verification, profile updates, and system alerts
- Access Management: Role-based system controls for administrators and faculty members
5.5 Sensitive Academic Information Exclusions
TRACER is strictly designed for academic performance and research management. It does not collect or process special categories of sensitive personal data, such as:
- Race or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Physical or mental health details
- Genetic or biometric data
- Sexual life or orientation
- Criminal records
TRACER does not require or intentionally store special category personal data. Users and institutional administrators should not upload non-academic sensitive personal information into the system.
6. Strategic Data Sharing And Platform Integrations
TRACER integrates with reputable academic indexing databases and cloud infrastructure providers to provide seamless research analytics:
| Data Sharing | Internal Academic Sharing | External Academic Platform Integration | Third-Party Service Providers |
|---|---|---|---|
| Description | Within the institutional framework, certain data may be shared internally under strict academic governance policies: | TRACER integrates with trusted academic platforms to enhance research tracking capabilities: | We may share limited data with vetted service providers for: |
| Data Sharing |
|
|
|
| Data Protection Assurance | All third-party integrations are governed by strict data processing agreements and security protocols. We do not sell or monetize academic data. Any data shared with third-party vendors is strictly purpose-bound and limited to what is essential for operational services. | ||
7. Academic Data Retention and Deletion Schedule
We retain academic and institutional data only for as long as necessary to satisfy research tracking, accreditation verification, and statutory compliance periods:
7.1 Retention Schedule by Data Category
| Data Category | Retention Period | Purpose |
|---|---|---|
| Faculty Research Data | Up to 7 years post-employment* | Academic continuity, institutional research tracking |
| Publication Records | Up to 7 years | Research impact analysis, accreditation support |
| Administrative Data | Up to 7 years* | Compliance requirements, audit trails |
| System Logs | 1-5 years | Security monitoring, technical support |
| NAAC Compliance Data | Up to 7 years* | Regulatory requirements, accreditation cycles |
7.2 Deletion & Archival Protocols
- Automated Cleanup: Systematic removal from active production systems using automated cleanup scripts
- Secure Archival: Limited metadata preservation for regulatory compliance in isolated storage
- Complete Purging: Irreversible deletion including all backups and archives
- Compliance Verification: Ensuring adherence to "right to erasure" requirements
Once active retention periods expire, data is securely archived in encrypted, read-only storage for compliance verification or irreversibly deleted in adherence with GDPR Article 17 and DPDP erasure mandates.
8. Advanced Security Measures
TRACER incorporates multi-layered technical safeguards, administrative oversight, and research ethics protections to ensure maximum data integrity:
8.1 Technical Safeguards
| Security Layer | Implementation in TRACER | Academic Context |
|---|---|---|
| Data Encryption | Industry-standard encryption for data at rest and in transit | Protection of sensitive research and faculty information |
| Access Controls | Role-based access controls ensure that only authorized personnel can access sensitive academic data. | Prevention of unauthorized access to academic records and research data. |
| Regular Audits | Periodic security audits and vulnerability assessments are conducted to identify and mitigate potential risks. | Ensures ongoing compliance with security policies and protects academic integrity. |
| Incident Response Plan | A comprehensive incident response plan is in place to address any security breaches or data leaks promptly. | Minimizes the impact of security incidents on academic operations. |
8.2 Administrative Controls
- Privacy Governance: Dedicated data protection oversight aligned with academic ethics and regulatory requirements.
- Staff Training: Regular privacy and security training for all platform administrators.
- Incident Response: Comprehensive breach response procedures with institutional notification protocols.
- Audit Procedures: Regular security assessments and compliance reviews.
- Vendor Management: Thorough evaluation and monitoring of third-party service providers.
8.3 Academic Research Protections
- Research Confidentiality: Special protection for ongoing research and unpublished work.
- Collaboration Privacy: Secure handling of inter-institutional research partnerships.
- Publication Ethics: Respect for academic publication timelines and embargo periods.
- Academic Freedom: Ensuring data processing does not interfere with legitimate research activities.
9. Fundamental Rights Under the DPDP Act & GDPR
Faculty members, researchers, and administrators maintain essential rights regarding their research portfolio and personal data:
| Right | Description |
|---|---|
| Right to Information And Access | Faculty members have the right to comprehensive information about how their research and personal data is processed within TRACER, including details about automated data collection from academic platforms. You may request confirmation of data processing and obtain copies of your personal data. |
| Right to Correction And Rectification | Users can request corrections to ensure accuracy of research records and academic credentials. You may request updates to inaccurate, incomplete, or outdated information in your profile. |
| Right to be Forgotten |
|
| Right to Restriction of Processing | You may request temporary limitation of data processing while verifying accuracy, as an alternative to erasure, or when data is required for legal claims. |
| Right to Data Portability | Faculty members can request their research data in a structured, commonly used, machine-readable format for transfer to other academic platforms or institutions. |
| Right to Object | You have the right to object to processing based on legitimate interests or for direct marketing purposes. This includes automated decision-making related to academic performance scoring. |
| Academic Freedom Protections | We respect principles of academic freedom and ensure that data processing does not interfere with legitimate research activities and scholarly expression. |
- Retention is required by law, statutory academic compliance, or institutional accreditation cycles.
- Data is subject to an active academic dispute, investigation, or legal proceeding.
10. Enhanced Contact and Grievance Framework
We provide dedicated communication and grievance redressal channels to address all privacy-related inquiries and research data management concerns:
10.1 Contact Information
Email Support
Support Portal
Escalation Path
Response Timeline
10.2 Grievance Redressal Process
| Steps | Resolution Process | Timeline |
|---|---|---|
| Step 1: Submission & Acknowledgment | Submit privacy concerns through official channels with authentication | Within 48 hours |
| Step 2: Review & Investigation | Thorough review by our data protection team | 7-14 business days |
| Step 3: Resolution | Timely response and corrective action when appropriate | Within resolution timeline |
| Step 4: Appeals Process | Escalation procedures for unresolved issues | Additional review period |
10.3 Regulatory and Supervisory Authorities
- Educational Data Concerns: Contact your institution's data protection officer.
- GDPR Issues: Relevant European data protection authority.
- DPDP Act Complaints: Data Protection Board of India.
- FERPA Complaints: U.S. Department of Education, Family Policy Compliance Office.
We strive to acknowledge privacy and research data inquiries within 48 business hours and provide formal resolutions within stipulated statutory timelines.
11. Policy Updates and Amendments
This Privacy Policy is periodically reviewed and updated to adapt to evolving academic regulations, technological advancements, and institutional research management standards:
11.1 Policy Review and Notification Matrix
| Change Type | Communication Method | Timeline |
|---|---|---|
| Material Changes | Email notifications, platform announcements, institutional communications | 30 days advance notice |
| Minor Updates | Platform notifications, website updates | Upon implementation |
11.2 Institutional Implementation Guidelines
- Framework Integration: Integrate with existing data governance and research ethics frameworks.
- Faculty & Staff Training: Train faculty and staff on platform-specific privacy practices.
- Compliance Monitoring: Monitor compliance with institutional data protection requirements.
Continued use of TRACER following the publication of policy amendments constitutes acknowledgment and acceptance of the revised terms.