Effective: June 2026 · EduuMatch Operations & Trust & Safety
Tutors upload sensitive documents to EduuMatch for identity verification, qualification verification, and platform operations. Mishandling of these documents creates legal, privacy, and trust risks. This standard defines how documents must be stored, accessed, retained, and destroyed.
| Type | Classification | Examples |
|---|---|---|
| Class A | Highly Sensitive | Aadhaar card, PAN card, Passport, Driver's License |
| Class B | Sensitive | Degree certificates, mark sheets, professional certifications |
| Class C | Financial | Bank account details, UPI IDs, payment records |
| Class D | Public | Profile photo, name, bio, teaching subjects |
All documents are encrypted at rest using AES-256 and in transit using TLS 1.3. Keys are managed via AWS KMS or equivalent HSM with rotation every 90 days. All documents must be stored in India-region data centres. Document URLs are time-limited pre-signed URLs expiring after 5 minutes.
| Class | Active Account | After Closure |
|---|---|---|
| Class A (Identity) | Account + 90 days | 90 days, then permanently deleted |
| Class B (Qualifications) | Account + 90 days | 90 days, then permanently deleted |
| Class C (Financial) | Account + 7 years | 7 years from last transaction |
| Class D (Public) | Account + 90 days | 90 days, then permanently deleted |
| Document Type | Allowed Formats | Max Size |
|---|---|---|
| Identity documents | JPG, PNG, PDF | 10 MB |
| Certificates | JPG, PNG, PDF | 10 MB |
| Profile photo | JPG, PNG | 5 MB |
| Other documents | PDF, DOCX | 15 MB |
If document data is suspected compromised: (1) Immediately revoke all document access and rotate storage keys, (2) Identify affected documents and users, (3) Notify affected users within 72 hours, (4) Patch vulnerability and strengthen controls, (5) Report to relevant authorities as required by law, (6) Post-incident review within 7 days.