Privacy Policy
Last updated 29 July 2026.
This Privacy Policy applies to the Gauhati University Services Portal at services.gauhati.ac.in (“this portal”, “we”, “us”) and to every service offered through it — currently Email Services and Document Request, and any further service the University adds over time (such as Vehicle Pass or Internal Requisition). It supplements, and should be read alongside, the University’s main Privacy Policy, which continues to govern the University’s website generally. It is intended to be read alongside the applicable laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and its rules, and the Guidelines for Indian Government Websites (GIGW) 3.0.
Information we collect
Some information is collected whichever service you use; some is collected only where a particular service needs it. This policy covers both.
Collected for every service on this portal:
- Your name and contact details, and the particulars specific to the request you are making (for example, the email account details you are requesting, or the details of the document you are requesting).
- Any document you are asked to upload to support that specific request (for example, an endorsement/proof document for an email request, or identity and supporting documents for a document request). Documents are used solely to process and verify the request they were uploaded for.
Collected only where a service requires identity verification (currently Document Request):
- Verified name, photograph and date of birth from DigiLocker e-KYC, the last four digits of your Aadhaar number for display purposes, and the e-KYC reference ID and timestamp. We do not store your full Aadhaar number under any circumstance, for any service.
Collected only where a service charges a fee (currently Document Request; Email Services is free of charge as of this writing):
- Payment information. Payments are processed by the University’s payment gateway provider through a hosted, redirect checkout page. Your card, UPI or net-banking credentials are entered directly on the payment gateway provider’s page and never reach or pass through University servers. We receive only the payment status, amount, and a transaction reference.
Collected automatically, for every visit:
- Technical information such as IP address, browser type, device information, and the pages and actions you use, for security and audit purposes.
How we use your information
We use this information only to:
- process the specific request or application you have made, through each stage of its workflow;
- where the service issues a certificate or other verifiable document (currently Document Request), generate and issue it, and push the minimal public record needed for others to verify it at verify.gauhati.ac.in;
- communicate with you about the status of your request by email;
- maintain an audit trail of who reviewed or changed your request and when, as required for institutional accountability; and
- comply with legal and regulatory obligations.
We do not sell your personal data and do not use it for commercial advertising.
Sharing and disclosure
We share your information only:
- internally, with the University staff responsible for reviewing and processing the specific service you used;
- with our payment gateway provider, solely to process payment, and only for services that charge a fee; and
- where required or permitted by law, including under the Right to Information Act, 2005, and lawful requests from authorised government agencies.
Data retention
Records, uploaded documents and audit trails for a request are retained for at least five years from the date the request is completed, and are thereafter archived rather than deleted.
Data security
The portal is served over an encrypted (HTTPS) connection. Where a service issues a certificate or other verifiable outcome, it is digitally signed so that tampering can be detected at verification. Access to requests is restricted to authorised, group-scoped staff accounts — staff for one service cannot see requests submitted to another service on this portal. While we take reasonable technical and organisational measures to protect your information, no method of transmission or storage can be guaranteed completely secure.
Your rights
Subject to the Digital Personal Data Protection Act, 2023 and other applicable law, you have the right to request access to, correction of, or (where the University is not required to retain it) erasure of your personal data, and to raise a grievance about how it has been handled.
Contact and grievance redressal
For questions about this policy, or to exercise your rights, contact [email protected]. If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or, for matters relating to your student status, to the Students’ Grievance Redressal Cell (SGRC) under the UGC (Redressal of Grievances of Students) Regulations, 2023.