Skip to content
IdeaScore
Legal

Privacy policy

How CMS Global collects, uses and protects personal data on IdeaScore.

This document is a structured draft awaiting legal review. Wording may change before it takes effect. Last updated 20 September 2026.

This policy explains what personal data IdeaScore collects, why, and what rights you have over it. It applies to the IdeaScore website and application, whether hosted by CMS Global or run on a customer's own server. Where an institution (a university, research park, incubator or accelerator) uses IdeaScore to run a programme, that institution is ordinarily the Data Fiduciary for applicant and evaluator data under the Digital Personal Data Protection Act, 2023 (DPDP Act), and CMS Global processes that data on the institution's instructions as its Data Processor. Questions about a specific programme's data should go to that institution first, then to us.

1. Scope and roles

1.1 This policy covers personal data processed through the IdeaScore website (ideascore.online), the IdeaScore application (app.ideascore.online) and any customer-hosted instance running IdeaScore software.

1.2 CMS Global ("we", "us", "IdeaScore") is the Data Fiduciary for: website visitors, sales and support contacts, and organisation admin accounts we bill directly.

1.3 The customer institution running a programme is ordinarily the Data Fiduciary for applicant, evaluator and reviewer data entered into that programme; CMS Global is its Data Processor. Terms specific to that relationship are in the Data Processing Agreement.

2. Data we collect

2.1 From organisation admins and programme administrators: name, work email, phone number (optional), role, login history and actions taken in the audit log.

2.2 From evaluators and jury members: name, email, areas of expertise, conflict-of-interest declarations, and the scores, notes and comments they enter.

2.3 From applicants: the information requested by a programme's application form (which varies by programme and is configured by the institution), pitch decks and other uploaded files, contact details, and status and communication history within the platform.

2.4 From all users: technical data collected automatically, such as IP address, browser and device type, and session timestamps, for security and audit purposes.

2.5 From payment: billing contact details and invoice history for organisations on a paid plan. Card details are handled by our payment processor and are not stored on IdeaScore's servers.

3. Purposes and lawful basis

3.1 We process personal data to operate the platform: authenticate users, run application forms, route submissions for review, calculate scores, generate reports, and send transactional notifications (deadlines, status changes, invites).

3.2 Under the DPDP Act, processing is carried out on the basis of consent given at sign-up or application, or for a specified lawful purpose such as performing a contract with the organisation that engaged IdeaScore, or as necessary to comply with a legal obligation.

3.3 IdeaScore AI processes application text and pitch-deck extracts to produce evaluator-facing research summaries. See section 8 for what is and is not sent to IdeaScore AI.

3.4 We do not sell personal data, and we do not use applicant or evaluator data to train any AI model outside the specific programme it was submitted to.

4. Sharing and disclosure

4.1 Within a programme, data is visible to the roles the institution configures: programme administrators, assigned evaluators, and, for their own submission, the applicant.

4.2 We share data with sub-processors who help us run the service (hosting, email delivery, error monitoring). Categories of sub-processor are listed on the Trust page and in the Data Processing Agreement; we do not share data with any party for their own marketing purposes.

4.3 We disclose data where required by Indian law, a valid court order, or to protect the rights, safety or property of IdeaScore, an institution, or a data principal.

4.4 If a customer chooses to self-host IdeaScore on its own server, programme data does not pass through CMS Global's cloud infrastructure at all, other than for optional support access explicitly granted by the customer.

5. Retention

5.1 Programme data is retained for the term of the institution's subscription plus a grace period of 90 days, after which it is deleted on request or on contract end, subject to any shorter or longer period the institution instructs in writing.

5.2 Billing and audit-log records are retained for as long as needed to meet accounting and legal obligations under Indian law.

5.3 Backups follow the retention described in the Trust page and are purged on the same rolling schedule as live data, save for backups already taken before a deletion request.

6. Your rights

6.1 Subject to the DPDP Act and any applicable rules, you may request access to, correction of, or erasure of your personal data, and may withdraw consent where processing relies on consent.

6.2 Applicants and evaluators should direct these requests to the institution running the programme in the first instance, since it is ordinarily the Data Fiduciary; the institution may route the request to us as its processor.

6.3 You may nominate another individual to exercise your rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.

6.4 You may lodge a grievance with our Grievance Officer at the contact below, and, if unresolved, with the Data Protection Board of India.

7. Security

7.1 We apply reasonable security practices and procedures as required under Indian law, including the measures described on the Security page: encryption in transit, encrypted backups, role-based access, and audit logging.

7.2 No system is perfectly secure. If we become aware of a breach likely to affect you, we will notify the affected institution and, where required by law, the relevant authority, without undue delay.

8. IdeaScore AI and data

8.1 IdeaScore AI sends the application's text answers and extracted pitch-deck content to a third-party language model to produce grounded research and a summary, and fetches supporting sources from the public web.

8.2 IdeaScore AI never sends passwords, session tokens, evaluator identities, or another organisation's data. The identity of the model provider is not disclosed in product copy; the feature is presented to users only as "IdeaScore AI".

8.3 Institutions can disable IdeaScore AI for a programme entirely; where disabled, no application data leaves the platform for AI research.

9. Cookies

9.1 The website and application use only strictly necessary cookies today (session and preference). See the Cookie policy for the full list and why no consent banner is currently required.

10. Children

10.1 IdeaScore is intended for institutional use by adults (administrators, evaluators, student and faculty applicants of ordinary university age). We do not knowingly collect data from children below the age recognised under the DPDP Act without appropriate consent from a parent or lawful guardian.

11. Changes to this policy

11.1 We may update this policy as the product or the law changes. Material changes will be notified to organisation administrators by email; the "Last updated" date above always reflects the current version.

12. Contact

12.1 Questions, requests and grievances about this policy can be sent to privacy@ideascore.online.