OUTLOOPAI

Privacy, Consent & Cookie Notice

Effective date
21/09/2026
Last updated
21/09/2026
Data controller / Data Fiduciary
MSI Consulting Group (operating the OutloopAI brand)
Contact
info@outloopai.com

1. Who We Are

This Privacy, Consent & Cookie Notice explains how OutloopAI collects, uses, stores, shares and protects personal data when you visit the OutloopAI website, create an account, use the Free AI Capability Assessment, participate in the National AI Challenge, or interact with related services and communications.

The final published notice should identify the legal entity that determines the purposes and means of processing personal data, together with its registered address and contact details.

2. What This Notice Covers

This Notice covers website visitors, prospective participants, registered users, assessment participants, paid competition participants, finalists and other individuals whose personal data is processed in connection with OutloopAI services.

It covers personal data collected directly from you, data generated through use of the platform, and limited data received from service providers or other lawful sources where applicable.

3. Personal Data We May Collect

The actual fields should be limited to what is reasonably necessary for the service. Depending on the journey, OutloopAI may collect:

Basic identity and contact details such as name, email address and mobile number.

Account information, login credentials or authentication-related information, with passwords handled through appropriate security controls rather than stored in plain text.

Profile information such as experience level, role/function, education or stated career/work goal where needed for assessment interpretation or progression.

Assessment information including responses, scores, capability dimensions, readiness results, transcript data, assessment version and related participation records.

Competition information including registration details, participation status, structured responses, practical submission information, challenge results, ranking/percentile information where applicable, and finalist-verification information.

Payment and transaction information necessary to confirm a paid entry. Full card, bank or other payment credentials should normally be handled by the authorised payment provider rather than stored by OutloopAI unless there is a specific lawful and operational need.

Technical and security information such as IP address, device/browser information, timestamps, login events, session information, error logs and other platform-security records.

Cookie and analytics information in accordance with the choices and settings made available to you.

Communications you send to OutloopAI, including support requests, complaints, feedback or other correspondence.

4. Why We Use Personal Data

OutloopAI should use personal data only for specified and lawful purposes. Depending on the service, purposes may include:

Creating and managing user accounts.

Providing the Free AI Capability Assessment and generating the participant transcript.

Scoring assessment responses and maintaining the integrity and version history of assessment results.

Registering participants for the National AI Challenge and administering participation.

Processing payments, issuing receipts and resolving transaction issues.

Providing participant support, handling complaints and responding to requests.

Maintaining security, preventing fraud, investigating abuse and protecting the integrity of assessments and competitions.

Improving platform usability, service quality and assessment/competition operations using appropriate aggregated or otherwise permitted data.

Sending service communications and, where lawfully permitted and appropriately consented, marketing or promotional communications.

Meeting legal, regulatory, accounting, tax, dispute-resolution and record-keeping requirements.

5. Privacy Notice and Specific Consent

Where consent is the applicable legal basis for processing, OutloopAI should provide a clear notice identifying the personal data involved and the specific purpose for which it is requested. Consent should be a clear affirmative choice and should not be bundled with unrelated purposes.

Where processing is necessary to provide a requested service, the relevant data may be processed on another lawful basis where permitted by applicable law. The final live privacy design should identify the lawful basis actually relied upon for each material processing activity rather than treating every activity as consent-based.

6. Your Consent Choices

Where processing is based on consent, you may withdraw consent through the mechanism made available for that purpose. Withdrawal should be reasonably as easy as giving consent. Withdrawal does not invalidate processing that was lawful before withdrawal.

Withdrawing consent may affect access to a feature or service where the requested processing is necessary to provide that feature or service. Where another lawful basis permits continued processing, OutloopAI may continue the relevant processing to the extent allowed by law.

Optional marketing preferences should be managed separately from service-essential processing. Unsubscribing from marketing communications should not ordinarily disable the core account or paid service.

7. Cookies, Analytics & Similar Technologies

OutloopAI may use cookies, local storage, pixels, tags or similar technologies to operate the website or application, remember preferences, support security, measure usage and improve services.

Essential technologies

These are used for functions such as login, session management, security, fraud prevention, load balancing or other features necessary to provide the requested service. Disabling these technologies may prevent some parts of the website or application from functioning.

Optional analytics technologies

Where optional analytics are used, they should be identified and controlled according to the live consent and privacy configuration. Analytics should be configured to collect only what is reasonably necessary for the stated purpose.

Optional marketing / advertising technologies

Where used, these should be presented as optional where legally required, with an understandable explanation of the purpose and a practical way to change the choice later.

Cookie settings

The live website should provide a clear cookie-choice mechanism where required or appropriate. Your choices should be capable of being revisited through a visible settings or privacy-control link.

8. Do Not Treat Cookie Consent as General Privacy Consent

A cookie banner or cookie-choice control should not be used to obtain broad consent for unrelated personal-data processing. Service-essential processing, assessment processing, marketing consent and optional analytics choices should be distinguished where appropriate.

9. Sharing with Service Providers

OutloopAI may use third-party service providers that process personal data on its behalf, such as hosting, cloud infrastructure, authentication, email, analytics, customer support, payment processing, security, communications and other technology providers.

The final privacy register should identify the relevant categories of providers and the purposes for which they are engaged. Providers should be subject to appropriate contractual and security controls, and access should be limited to what is reasonably necessary.

10. Payment Data

For the paid National AI Challenge, payment details may be collected through an authorised payment provider. OutloopAI should not collect or store full payment credentials unless specifically required for the chosen payment architecture and appropriate controls are in place.

Transaction references, payment status, amount, date, invoice/receipt details and limited payment-related information may be retained for accounting, support, fraud prevention, refunds and legal record-keeping.

11. Assessment, Competition & Integrity Data

For the Free AI Capability Assessment and National AI Challenge, OutloopAI may process information needed to score, administer and protect the integrity of the service.

This may include attempt records, assessment or challenge responses, timing and session information, technical event logs, version information and selected integrity signals.

Integrity signals are indicators for review and should not automatically be treated as proof of cheating or misconduct. Competition disqualification is governed by the applicable Challenge Rules & Scoring.

12. Data Accuracy and Minimisation

OutloopAI should collect only data reasonably necessary for the stated purpose and should take reasonable steps to keep material personal data accurate and up to date. Participants should provide truthful and current information and should notify OutloopAI where important account information needs correction.

13. Data Retention

Personal data should be retained only for as long as necessary for the purpose for which it was collected, to provide the relevant service, maintain records, resolve disputes, protect security, or comply with legal obligations.

The final published notice should be supported by an internal retention schedule defining periods for account data, assessment records, competition records, payment records, support records, security logs and marketing preferences. Different categories may have different retention periods.

14. Security

OutloopAI should maintain reasonable technical and organisational safeguards appropriate to the nature of the personal data and the risks involved. Measures may include access control, authentication, encryption where appropriate, logging, backups, monitoring, vulnerability management and controlled administrator access.

No online service can guarantee absolute security. OutloopAI should maintain incident-response procedures and take appropriate action if a personal-data breach is identified.

15. Personal Data Breach

Where a qualifying personal-data breach occurs, OutloopAI will follow the notification and regulatory requirements applicable to the incident, including any required notifications to affected individuals and competent authorities within the legally prescribed framework and timelines.

16. Your Rights and Requests

Subject to applicable law and the relevant implementation stage of the data-protection framework, you may have rights relating to access or information about your personal data, correction, erasure, withdrawal of consent where consent is the basis, grievance redressal and nomination or other rights provided by law.

The published notice should provide the practical channel through which a user can exercise applicable rights or contact the person authorised to respond to privacy requests.

17. Children

OutloopAI should define and publish its eligibility rules for minors before launch. Where the service is not intended for children, the application and competition flow should state the minimum age and apply appropriate controls. Where applicable law requires parental or guardian consent or other safeguards for children, those controls should be implemented before collecting or processing the relevant personal data.

18. Cross-Border Processing

Some service providers or infrastructure used by OutloopAI may process personal data outside India. Where this occurs, OutloopAI should apply the data-transfer and contractual safeguards required by applicable law and its internal vendor-risk controls.

19. Marketing Communications

OutloopAI may send transactional or service messages needed to administer the account, assessment or competition. Promotional communications should be sent only where permitted and, where required, based on the appropriate user choice or consent. Each marketing communication should provide a practical opt-out mechanism.

20. Changes to This Notice

OutloopAI may update this Notice when services, technologies or legal requirements change. The latest version should be published with an effective date. Where a material change requires renewed consent or notice, the applicable process should be followed before continuing the affected processing.

21. Contact & Grievance

For privacy questions, consent requests, cookie choices, data-rights requests or complaints, use the contact and grievance channel published on the OutloopAI website.

Before publication, insert the final legal entity name, registered office address, privacy contact, grievance contact and any designated officer details required for the live business.

22. Publication & Implementation Checklist

Confirm the legal entity acting as the relevant Data Fiduciary and insert its final contact details.

Create a current data inventory covering landing-page, assessment and paid-competition journeys.

Confirm every actual cookie, analytics tag, pixel, SDK and third-party processor used in production.

Separate essential service processing from optional analytics/marketing choices.

Ensure consent records and withdrawal mechanisms work in practice where consent is relied upon.

Publish retention periods internally and ensure the public notice is consistent with them.

Confirm payment-provider data flows and the exact information OutloopAI retains.

Confirm child/minor eligibility and controls before launch.

Implement privacy request and grievance workflows.

Run final legal review against the actual production system before publication.

23. Legal Status

This document is a comprehensive website-content draft and should not be treated as legal clearance. It is designed to provide a practical privacy, consent and cookie framework for the OutloopAI landing page, Free AI Capability Assessment and paid National AI Challenge. The final published version must be checked against the actual data flows, technologies, processors, contractual arrangements and applicable Indian law at launch.

The structure follows the current DPDP framework's emphasis on clear, plain-language notice, specified purposes, itemised personal-data descriptions and practical consent-withdrawal and rights mechanisms. The final legal basis, notice wording and operational controls must be confirmed for the date and scope of the live processing.