Privacy Policy
Codex Monarch and ReadyToGo Platform Data Protection Notice
1. Information We Collect
Depending on how you interact with our websites, events, and platforms, we may collect several categories of information to provide seamless services.
1.1 Information You Voluntarily Provide
- Profile and Contact Information: Full name, email address, mobile number, username, college/institution, and profile links.
- Event & Hackathon Registrations: Team names, member lists, track preferences, attendance acknowledgments, and competition entries.
- Assignments & Technical Submissions: Source code repositories, project blueprints, challenge solutions, assignment uploads, and feedback submissions.
- Enquiries: Messages, technical queries, support tickets, and correspondence submitted via our contact forms or community channels.
1.2 Account & Authentication Data
When you register or log in to Codex Monarch or ReadyToGo, we process authentication data including secure hashed credentials, session tokens, login timestamps, and verification identifiers. We never store plain text passwords, nor do we ever request passwords via email, chat, or phone.
1.3 Automatically Collected Technical Data
When accessing our web servers, standard log data is automatically recorded for security, diagnostics, and performance optimization:
- IP address and approximate geographic location (country/city level).
- Browser brand, rendering engine, and operating system details.
- Referring URLs, pages visited, time spent per page, and access timestamps.
- Security audit events (failed login attempts, rate-limit triggers).
2. How We Use Your Information
We process personal information under valid lawful bases, including service fulfillment, legitimate interests, and user consent, for the following purposes:
- Delivering Platform Features: Operating dashboards, leaderboards, assignment evaluations, challenge validation, and user profile management.
- Event Administration: Organizing hackathons, issuing automated registration IDs, validating team eligibility, coordinating judging, and producing certificates.
- Security & Abuse Prevention: Detecting fraud, safeguarding accounts from unauthorized access, defending against DDoS attacks, and enforcing platform integrity.
- Service Improvements: Resolving technical glitches, refining UI performance, and optimizing challenge curriculums.
- Legal Compliance: Adhering to statutory record-keeping and applicable digital regulations in India.
3. ReadyToGo & AI-Assisted Processing
ReadyToGo (readytogo.codexmonarch.me) is an engineering platform developed by Codex Monarch. Select features within ReadyToGo utilize automated evaluation and AI-assisted models to provide rapid feedback on code syntax, project architectures, and learning modules.
- Content submitted for automated analysis is processed strictly to generate evaluations, hints, classifications, or debugging suggestions.
- Automated AI evaluations are intended as educational aids; they do not replace human mentorship, formal grading, or official hackathon judging panels.
- We do not sell user submissions or source code to third parties for commercial AI training without explicit permission.
4. Cookies and Similar Technologies
We use essential cookies, local storage, and secure session identifiers. These technologies enable:
- Session Maintenance: Keeping you securely logged in across page navigations.
- User Preferences: Storing UI choices such as dark mode and display settings.
- System Protection: Implementing CSRF tokens and rate-limiting safeguards.
You can manage or disable cookies via your browser settings. However, disabling essential session cookies may prevent account login and protected portal features from functioning.
5. Third-Party Service Providers
We work with vetted technical infrastructure providers who process data strictly under confidentiality and data protection obligations:
- Cloud Hosting & Edge Delivery: Vercel Inc. and cloud infrastructure providers.
- Database & Storage: Turso (libSQL) cloud database and Cloudinary for media assets.
- Communication & Delivery: Transactional email gateways and verification services.
- Payment Processors: RBI-compliant payment aggregators (e.g. Razorpay) when applicable for paid events.
6. Payments & Financial Information
When paid registrations, ticket purchases, or platform services are enabled, transactions are handled directly through certified third-party payment gateways. Codex Monarch does not store complete debit/credit card numbers, CVV codes, or net-banking credentials on its servers. We only retain tokenized transaction IDs, payment status flags, and timestamps for accounting and registration confirmation.
7. Communications
We send essential service notifications, including account verification codes, hackathon registration IDs, schedule announcements, and critical security notices. Users may choose to opt out of promotional emails; however, transactional and security-related communications will remain active as they are vital to service operation.
8. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. Disclosures are strictly limited to:
- Service Infrastructure: Authorized technical providers operating under strict confidentiality.
- Legal Compliance: When required by lawful court orders, statutory directives, or governmental investigations.
- Protection of Rights: To prevent fraud, counter security breaches, or protect the safety and intellectual property of Codex Monarch, our community, and participants.
- Organizational Restructuring: In the event of a merger, acquisition, or platform transition, governed by comparable privacy commitments.
9. Data Security
We implement layered technical and administrative safeguards designed to protect personal data against unauthorized access, loss, alteration, or misuse:
- Enforced HTTPS / TLS 1.3 encryption across all web traffic.
- Strong cryptographic password hashing (bcrypt) and secure session cookies (HttpOnly, SameSite).
- Strict HTTP security headers including X-Content-Type-Options, Frameguards, and Content Security Policies.
- Automated rate limiting to mitigate brute-force and credential-stuffing attacks.
10. Data Retention
We retain personal information only for as long as needed to fulfill the operational, educational, and legal purposes outlined in this policy. Account details remain active while your profile exists. Once an account is requested for deletion or data is no longer necessary, it is securely purged or anonymized, except where statutory record-keeping requires temporary preservation.
11. Your Privacy Rights & DPDP Act Compliance
In alignment with applicable data protection principles, including India's Digital Personal Data Protection Act, 2023 (DPDP Act), you are entitled to:
- Right to Access: Request a summary of personal data held about you and how it is processed.
- Right to Correction: Update or rectify incomplete or inaccurate personal information.
- Right to Erasure: Request the deletion of your account and personal records, subject to legal retention obligations.
- Right to Grievance Redressal: Submit inquiries or complaints regarding the handling of your data.
- Right to Nominate: Designate a representative to exercise rights in the event of unforeseen incapacity.
To exercise any of these rights, please submit your request to hello@codexmonarch.me.
12. Children's Privacy
Our platforms are designed for student developers, software enthusiasts, and professionals. If a user is under the age of majority in their jurisdiction, they must obtain parent or legal guardian consent prior to providing personal information or participating in events. If we become aware that personal data of a minor was collected without requisite guardian consent, we will promptly take steps to delete that information.
13. International & Cross-Border Processing
While Codex Monarch is anchored in India, our cloud infrastructure (such as edge servers, CDN networks, and databases) operates across distributed global data centers. By accessing our services, you acknowledge that your technical information may be processed across these secure cloud regions under recognized standard safeguards.
14. External Links
Our websites may contain outbound links to GitHub repositories, external hackathon portals, WhatsApp groups, or partner sites. Codex Monarch is not responsible for the privacy practices or contents of external third-party platforms. We encourage reviewing the privacy documentation of any external service you visit.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect technological advancements, statutory requirements, or platform feature expansions. When revisions occur, the updated date at the top will be adjusted. Material modifications will be highlighted through announcements on our website or community channels.
16. Contact Information & Grievance Redressal
If you have any questions, concerns, or grievances concerning this Privacy Policy or your personal data, you may reach our team directly: