INTERNAL

Document Handling Standard

Effective: June 2026 · EduuMatch Operations & Trust & Safety

1. Purpose

Tutors upload sensitive documents to EduuMatch for identity verification, qualification verification, and platform operations. Mishandling of these documents creates legal, privacy, and trust risks. This standard defines how documents must be stored, accessed, retained, and destroyed.

2. Document Classification

TypeClassificationExamples
Class AHighly SensitiveAadhaar card, PAN card, Passport, Driver's License
Class BSensitiveDegree certificates, mark sheets, professional certifications
Class CFinancialBank account details, UPI IDs, payment records
Class DPublicProfile photo, name, bio, teaching subjects

3. Storage Requirements

All documents are encrypted at rest using AES-256 and in transit using TLS 1.3. Keys are managed via AWS KMS or equivalent HSM with rotation every 90 days. All documents must be stored in India-region data centres. Document URLs are time-limited pre-signed URLs expiring after 5 minutes.

4. Retention Schedule

ClassActive AccountAfter Closure
Class A (Identity)Account + 90 days90 days, then permanently deleted
Class B (Qualifications)Account + 90 days90 days, then permanently deleted
Class C (Financial)Account + 7 years7 years from last transaction
Class D (Public)Account + 90 days90 days, then permanently deleted

5. Allowed File Formats

Document TypeAllowed FormatsMax Size
Identity documentsJPG, PNG, PDF10 MB
CertificatesJPG, PNG, PDF10 MB
Profile photoJPG, PNG5 MB
Other documentsPDF, DOCX15 MB

6. Breach Response

If document data is suspected compromised: (1) Immediately revoke all document access and rotate storage keys, (2) Identify affected documents and users, (3) Notify affected users within 72 hours, (4) Patch vulnerability and strengthen controls, (5) Report to relevant authorities as required by law, (6) Post-incident review within 7 days.

Violation of this standard by any EduuMatch team member is grounds for disciplinary action, up to and including termination.