1. Who we are and what this covers
ClearLevel (“we”, “us”, “our”) operates the website clearlevel.in and the ClearLevel mobile app, together referred to here as the Platform. We provide online classes, mock tests, test series, printed books, mentorship and a student community for CA, CS and CMA aspirants.
This policy applies to everyone who uses the Platform, whether or not you create an account. It explains our practices as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules notified in November 2025, read with the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
It does not cover the practices of the examination bodies (ICAI, ICSI, ICMAI) or of any third-party website you reach through a link on our Platform. ClearLevel is an independent education platform and is not affiliated with, endorsed by, or acting on behalf of any of those institutes.
2. Key terms
The DPDP Act uses specific terms, and this policy uses them too:
- Personal data means any data about you by which you can be identified.
- Data Principal means you, the individual the data is about. Where the Data Principal is a child, it also means the parent or lawful guardian.
- Data Fiduciary means the party that decides why and how your data is processed. For the Platform, that is ClearLevel.
- Data Processor means a third party that processes data on our instructions, such as a payment gateway or hosting provider.
- Processing means any operation performed on personal data, including collecting, storing, using, sharing and deleting it.
3. Information we collect
We collect only what the Platform needs in order to work. In practice that falls into six groups.
a. Account and profile data
- Your name, email address and mobile number when you register.
- A securely hashed password. We never store your password in readable form.
- Optional profile details you choose to add: city, state, date of birth, and the exam and level you are preparing for.
- Your GSTIN, only if you supply one so that a business invoice can be raised.
b. Transaction data
- Records of the courses, books, test series, mock-test packs and mentorship sessions you buy, along with order numbers, amounts, coupons applied and invoices.
- A shipping address, where you order printed books.
- Payment confirmations returned by our payment gateway. We do not receive or store your full card number, UPI PIN, CVV or net-banking credentials - those go directly to the gateway.
c. Learning activity
- Mock tests and test series you attempt, your answers, scores, time taken per question, and the analysis generated from them.
- Your rank or percentile where you appear on a leaderboard.
- Which lectures or materials you have accessed, and your progress through a course.
d. Community and support content
- Posts, comments, votes and profile information you publish in the ClearLevel community. Anything you post publicly is visible to other users - please do not include personal details there that you would not want seen.
- Messages you send us through the contact form, email or WhatsApp, and our replies.
- Applications you submit to teach, mentor or partner with us, including any documents you attach.
e. Technical data
- IP address, browser and device type, operating system and approximate region.
- Pages viewed, referring page and time spent, collected through cookies and analytics.
- Log records of sign-in activity, kept for security and fraud prevention.
- A device push token, if you allow notifications in the mobile app.
f. Cart activity
If you are signed in and add items to your cart without completing checkout, we record that cart against your account so our team can follow up with help or an offer. This is described plainly in section 11, and you can opt out of those follow-ups at any time.
4. How and why we use it
We use personal data for the following purposes, and no others without telling you first.
- To provide the service - creating your account, giving access to what you have bought, running mock tests and producing your result analysis.
- To take payment - processing orders, issuing invoices and handling refunds.
- To deliver goods - shipping printed books to the address you give us.
- To support you - answering questions, resolving payment or access problems, and handling complaints.
- To keep you informed - sending transactional messages such as order confirmations, invoices, access details and exam-schedule updates.
- To improve the Platform - understanding which pages and features are used, diagnosing faults and improving performance.
- To keep the Platform safe - detecting fraud, abuse of free content, payment disputes and unauthorised account access.
- To meet legal obligations - retaining tax and accounting records, and responding to lawful requests.
Our legal basis. Under the DPDP Act we rely on your consent, which you give when you create an account or submit a form, and on certain legitimate usespermitted by the Act, such as fulfilling an order you placed and complying with a legal duty. You can withdraw consent at any time, as described in section 9. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide part of the service.
5. Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember preferences such as your cart and selected exam, and measure how the Platform is used.
- Essential cookies keep your session active and secure the checkout. The Platform cannot function without these.
- Preference cookies remember choices such as your cart contents and recently viewed items.
- Analytics cookies are set by Google Analytics 4 so we can see aggregate traffic patterns. Analytics is not loaded in the admin panel and is disabled outside our production site.
You can block or delete cookies in your browser settings. If you block essential cookies, sign-in and checkout will stop working.
6. Who we share it with
We do not sell, rent or trade your personal data. We share it only in the situations below, and only to the extent needed.
Service providers we use
Each of these processes data on our instructions under contract, and is not permitted to use it for its own purposes.
Other disclosures
- Faculty and partners - where you buy a course or book supplied by a faculty member or partner, we share only what is needed to fulfil and support that order. They are contractually barred from using your details to market to you off-platform.
- Legal authorities - where disclosure is required by law, a court order, or a lawful request from a government agency.
- Enforcement - where we need to establish, exercise or defend a legal claim, or to investigate fraud or abuse of the Platform.
- Business transfer - if ClearLevel is involved in a merger, acquisition or sale of assets, your data may transfer to the successor, which will remain bound by this policy or give you notice of any change.
7. How long we keep it
We keep personal data only as long as there is a reason to.
- Account data - for as long as your account is active, and for 24 months after it becomes inactive, after which it is deleted or anonymised.
- Order, invoice and tax records - for the period required by Indian tax and company law, which is generally eight years, even if you close your account.
- Mock-test attempts and results - for as long as your account is active, so that your progress history stays meaningful. You can ask us to delete them sooner.
- Community posts - these remain visible until you delete them or ask us to. Deleting your account removes the link between you and your posts.
- Support correspondence - up to three years from the last message, for quality and dispute-handling purposes.
- Server and security logs - typically up to 12 months.
When you ask us to delete your account, we remove or anonymise your identifiable data within 30 days, other than records we are legally obliged to keep.
8. How we protect it
We apply reasonable technical and organisational safeguards appropriate to the data we hold:
- Traffic to and from the Platform is encrypted in transit using HTTPS.
- Passwords are stored only as a salted one-way hash, never in readable form.
- Administrative access is restricted, individually accounted for, and limited to the sections each staff member needs.
- Payment credentials are handled entirely by the payment gateway and never reach our servers.
No system can be guaranteed completely secure. If you believe your account has been accessed without your permission, contact us immediately at support@clearlevel.in.
9. Your rights
As a Data Principal under the DPDP Act, you have the following rights:
- Right to access - to obtain a summary of the personal data we hold about you and how it is being processed.
- Right to correction and updating - to have inaccurate or incomplete data corrected or completed. Most profile details can be edited directly in your dashboard.
- Right to erasure - to ask us to delete your personal data where we are no longer required to keep it.
- Right to withdraw consent - to withdraw consent you previously gave, at any time and as easily as you gave it.
- Right to nominate - to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
- Right to grievance redressal - to complain to us first, using the details in section 15, and to escalate to the Data Protection Board of India if you are not satisfied with our response.
Deleting your account. You can request deletion of your account and its associated data at any time, without signing in, using our account deletion page. You can also start it from Dashboard → Profile in the app or on the web. What is deleted, what we are legally required to retain, and how long it takes are all set out on that page.
To exercise any of these, email support@clearlevel.in from the address registered on your account. We respond to requests within 30 days. We may ask you to verify your identity before acting on a request, so that we do not disclose your data to someone else.
10. Students under 18
Under the DPDP Act, anyone under the age of 18 is a child. This matters on ClearLevel because many CA Foundation and CSEET aspirants join straight after Class 12 and are still 17.
- Where a user is a child, we process their personal data only with the verifiable consent of a parent or lawful guardian.
- We do not carry out behavioural tracking or targeted advertising directed at children.
- We do not knowingly process a child's data in a way that is likely to cause them harm.
- If you are under 18, please use the Platform with your parent or guardian's involvement, and ask them to complete any purchase.
If you believe a child's data has been provided to us without proper consent, write to support@clearlevel.in and we will verify and delete it promptly.
11. Marketing and reminders
Transactional messages - order confirmations, invoices, access details, class or exam reminders and account or security notices - are part of the service and are sent to all users. These are not marketing and cannot be switched off while your account is open.
Marketing messages - offers, new-launch announcements and newsletters - are sent only where you have opted in. Every marketing email carries an unsubscribe link, and you can also reply STOP to a WhatsApp message or email us to opt out.
Cart and enquiry follow-ups - if you are signed in and leave items in your cart, or submit an enquiry, our team may contact you once or twice by email, phone or WhatsApp to help you complete it or answer a question. Tell us to stop and we will, and we will record that preference against your account.
12. Where your data is stored
Our servers and primary database are located in India, and files uploaded to the Platform are stored in the AWS Asia Pacific (Mumbai) region.
Some of the service providers named in section 6 are global companies that may process limited data - such as analytics events or push-notification tokens - on infrastructure outside India. Where that happens we rely on the provider's contractual commitments and transfer only what the service requires. We do not transfer personal data to any territory restricted by the Central Government under the DPDP Act.
13. Data breaches
We maintain procedures to detect and respond to personal data breaches. If a breach affecting your personal data occurs, we will notify you and the Data Protection Board of India in the form and within the timelines required by the DPDP Rules, and will tell you what happened, what data was involved, what we have done about it, and what you can do to protect yourself.
14. Changes to this policy
We may update this policy as our services, or the law, change. The effective date at the top of this page always shows the current version. If a change materially affects how we use your personal data, we will give you notice by email or through a prominent notice on the Platform before it takes effect. Continuing to use the Platform after a change takes effect means you accept the updated policy.
15. Contact and grievance redressal
If you have a question about this policy, want to exercise a right in section 9, or wish to complain about how we have handled your personal data, contact our Grievance Officer. We acknowledge every complaint and respond within 30 days.
Grievance Officer
Not satisfied with our response? You may escalate your complaint to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.