Legal

Privacy Policy

How MIT University Sikkim collects, uses, stores and protects personal data, in line with the Digital Personal Data Protection Act, 2023.

MIT University Sikkim ("the University") respects your privacy. This Policy explains how personal data is collected, used, stored and protected when you use mituniversitysikkim.com, apply for admission, or otherwise interact with the University.

This Policy is prepared with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025. The Act's provisions are coming into force in a phased manner, with most data-fiduciary obligations applying by 14 May 2027. The University is publishing this Policy as good practice ahead of full enforcement, and will update it as further provisions take effect.

1. What We Collect

  • Identity data: name, date of birth, photograph, parent/guardian details
  • Contact data: address, phone number, email
  • Academic data: prior qualifications, marks, enrolment and examination records
  • Category/eligibility data: caste, disability or income certificates, where submitted for reservation — see Reservation Policy
  • Financial data: fee payment records (processed through the official payment gateway; the University does not store card or bank details)
  • Technical data: IP address, browser type, pages visited (via cookies/analytics, if used)

2. Why We Collect It

  • To process admission, registration and examinations
  • To communicate announcements, circulars and results
  • To process fee payments and refunds — see Refund Policy
  • To verify documents and respond to verification requests
  • To comply with UGC, Government of Sikkim and other statutory requirements
  • To improve this website

We collect only what is needed for these purposes ("purpose limitation"), and process it only with your consent or another lawful basis under the DPDP Act.

3. How We Use and Share Data

  • Data is used internally by the relevant University office (Admission, Examination, Accounts, Registrar)
  • Data is shared with statutory authorities (UGC, Government of Sikkim) where required by law
  • Data may be shared with an employer or agency for document verification, but only with your consent — see Document Verification
  • We do not sell personal data, and do not share it with third parties for marketing

4. Data Retention

Academic records are retained in accordance with the University's record-retention norms — see Old Student Verification. Data no longer required for the stated purpose, or for a legal obligation, is deleted or anonymised.

5. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access the personal data the University holds about you
  • Request correction or updating of inaccurate data
  • Request erasure of data no longer needed for the purpose it was collected, subject to the University's legal retention obligations
  • Withdraw consent, where processing is based on consent, without affecting processing already carried out
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
  • Register a grievance regarding how your data is handled

To exercise these rights, write to the contact in Section 8.

6. Security

The University takes reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or loss. No online system is completely secure, and data is transmitted at your own risk.

7. Cookies

This website may use cookies to remember preferences and understand usage. You can disable cookies in your browser; some features may not function without them.

8. Grievance & Contact

For any question, request or grievance regarding your personal data:

  • Email: registrar@mituniversitysikkim.com
  • Address: Helipad Road, near Sai Mandir, Assangthang, Namchi, Sikkim – 737126
  • You may also approach the Data Protection Board of India if your grievance is not resolved, once that recourse is operational under the Act's implementation timeline.

9. Children's Data

Where a student is a minor, personal data is processed with the consent of the parent or lawful guardian, as required under the DPDP Act.

10. Changes to This Policy

This Policy may be updated periodically, particularly as further DPDP Act provisions come into force. The version on this page is the version in effect.