XOlympiad takes reasonable steps to prevent unauthorized access, use, disclosure, alteration, loss or theft of personal and competition information.
What counts as data theft
Data theft includes obtaining, copying, downloading, sharing, selling, disclosing or using personal data, credentials, student records, submissions, scores or confidential event information without authorization.
Attempted phishing, impersonation, credential sharing, unauthorized scraping, malware, bypassing access controls and misuse of another participant's account are also prohibited.
Who this applies to
This policy applies to participants, parents and guardians, volunteers, judges, staff, vendors, partners and visitors who access XOlympiad systems or information.
Minors must use the service with parent or lawful guardian involvement where required by applicable law and event rules.
Protection measures
- Access is limited to people who need information for competition administration, support, safety, communications or legal obligations.
- Users must keep passwords and verification codes confidential and must not share accounts or access another person's information.
- We may use reasonable technical, organizational and physical safeguards, including access controls, secure configuration, monitoring and backups appropriate to the information and risk.
- Information is retained only for as long as reasonably necessary for the stated purpose, records, dispute resolution and legal obligations.
Reporting an incident
Report suspected data theft, unauthorized access, phishing or accidental disclosure immediately to team@xolympiad.com. Include what happened, when it happened, the affected account or information, and any evidence that can be safely shared.
Do not publish personal information or attempt to investigate by accessing another person's account.
Response and consequences
We may investigate, preserve evidence, restrict access, reset credentials, notify affected people where required, cooperate with lawful authorities and take corrective steps.
Unauthorized access, theft, misuse or disclosure may result in removal from the event, cancellation of prizes, suspension of access and civil or criminal action under applicable Indian law.
India legal framework
This policy is intended to work with India's Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and applicable rules, contractual obligations and other Indian laws. Where a law requires a different process, that legal requirement will apply.
This is a general policy template, not legal advice. It should be reviewed and adapted by an India-qualified lawyer after the organization's systems, vendors, incident contacts and data flows are confirmed.