Legal
Privacy Policy
Effective from 2 September 2026. Last updated 2 September 2026.
This policy tells you what personal data JEEMOCKS collects, why, who else touches it, how long we keep it, and what you can require us to do about it.
Each section begins with a short plain statement of what it means. The numbered clauses beneath it are the operative terms. If the two ever appear to differ, read them together: the plain statement is there to help you understand the clause, not to narrow it.
This policy is issued as the notice required under section 5 of the Digital Personal Data Protection Act, 2023.
1. Definitions
In plain terms. These words have specific meanings throughout this policy.
1.1 "Company", "we", "us", "our" means Edzok 226 Innovations Private Limited, described in clause 2.1.
1.2 "Service" means the JEEMOCKS website at jeemocks.com and every page, mock test, practice question, explanation, report and feature served through it.
1.3 "You", "your" means the individual using the Service. Where that individual is below eighteen years of age, it also means the Guardian who has consented on their behalf.
1.4 "Guardian" means a parent or lawful guardian of a User below eighteen years of age.
1.5 "Account" means the registered profile through which you access the Service.
1.6 "Personal Data" means any data about you by which you are identifiable, and carries the meaning given in the Digital Personal Data Protection Act, 2023.
1.7 "the Act" means the Digital Personal Data Protection Act, 2023, together with any rules made under it.
1.8 "Data Principal" means you, in your capacity as the individual to whom the Personal Data relates.
1.9 "Data Fiduciary" means the Company, in its capacity as the person determining the purpose and means of processing your Personal Data.
1.10 "Processor" means a third party that processes Personal Data on our instructions and on our behalf.
1.11 "Board" means the Data Protection Board of India.
2. Who we are, and our role
In plain terms. JEEMOCKS is run by Edzok 226 Innovations Private Limited, a company registered in Mumbai. We decide what data is collected and why, which makes us responsible for it in law.
2.1 The Service is owned and operated by:
| Registered name | Edzok 226 Innovations Private Limited |
| Corporate Identity Number | U80902MH2019PTC331876 |
| GSTIN | 27AAFCE6772K1Z5 |
| Registered office | 213, Neo Corporate Plaza, Ramchandra Lane, Malad West, Mumbai 400064, Maharashtra, India |
| Date of incorporation | 18 October 2019 |
| Website governed by this policy | jeemocks.com |
2.2 The Company acts as Data Fiduciary in respect of all Personal Data described in this policy.
2.3 Grievance Officer. Puja S, contactable at puja@phyzok.com. The Grievance Officer is appointed under clause 14 and is the person responsible for answering questions and complaints about this policy.
2.4 General contact. support@phyzok.com.
3. Scope
In plain terms. This policy covers jeemocks.com and nothing else.
3.1 This policy applies to Personal Data processed through the Service.
3.2 This policy does not apply to any website or service operated by a third party, including any site reached by following a link from the Service. The privacy policy of that site governs your use of it.
3.3 This policy does not apply to any other product or website operated by the Company.
4. The Personal Data we process
In plain terms. This is the complete list of what we hold about you. Nothing outside this list is collected.
4.1 Data you provide
4.1.1 On creating an Account: your name, email address, mobile number, a password stored only as a cryptographic hash and not in any recoverable form, the examination you are preparing for, and your class or target examination year.
4.1.2 Where the User is below eighteen: the Guardian's name, email address and mobile number, together with a record of the consent given, the date and time it was given, and the method by which it was verified.
4.1.3 When you contact us: the content of your message and the address you sent it from.
4.1.4 When you report a defect in a question: the identity of the question and the description you provide.
4.2 Data generated by your use of the Service
4.2.1 Before an Account exists. On your first visit we assign an identifier to your browser so that a test in progress survives a page reload. That identifier is not linked to your name, email address or mobile number. If you subsequently create an Account, activity recorded against the identifier is associated with that Account so that your work is preserved. If no Account is created, the identifier remains unassociated with any identified individual.
4.2.2 Assessment activity. The questions presented to you, the options you selected, changes you made to an answer, questions you skipped, the time spent on each question, the sequence in which you moved between questions, and the times at which you began and submitted.
4.2.3 Derived outputs. Scores, accuracy by chapter and topic, estimated percentile and rank where displayed, patterns of recurring error inferred from your responses, and study recommendations. These are produced by us from the data described in clause 4.2.2 and are not obtained from any third party.
4.3 Technical data
4.3.1 IP address, browser type and version, operating system, device type, screen dimensions, referring page, and the pages visited within the Service. This is collected automatically by our servers and by the Processors named in clause 8.
4.4 Communications data
4.4.1 A record of each email, SMS message and WhatsApp message sent to you, its content, and whether it was delivered, opened or acted on. Where you reply, the reply is retained.
4.5 Data we do not process
4.5.1 We do not collect or store payment card details, bank details or any payment instrument. The Service is provided without charge as at the date of this policy.
4.5.2 We do not collect precise geolocation data.
4.5.3 We do not access your contacts, camera, microphone, photographs or files.
4.5.4 We do not acquire Personal Data about you from data brokers, list vendors or any other external source.
4.5.5 We do not process any category of data that would constitute financial, health, biometric or genetic information.
5. Purposes of processing, and the basis for each
In plain terms. We process your data for the purposes in this table and for nothing else. Most of it rests on the consent you give at signup.
5.1 The Company processes Personal Data only for the following purposes:
| Purpose | Personal Data used | Basis under the Act |
|---|---|---|
| Creating and maintaining your Account | Clause 4.1.1 | Consent |
| Delivering tests and practice questions and recording responses | Clauses 4.1.1, 4.2.2 | Consent |
| Producing scores, reports and topic analysis | Clauses 4.2.2, 4.2.3 | Consent |
| Sending communications relating to your Account, your results, or an incomplete test | Clauses 4.1.1, 4.4.1 | Consent |
| Sending communications about new features, content or offers | Clauses 4.1.1, 4.4.1 | Consent, separately given and separately withdrawable under clause 6.4 |
| Obtaining and recording Guardian consent | Clause 4.1.2 | Compliance with section 9 of the Act |
| Measuring aggregate usage in order to identify defects and improve the Service | Clauses 4.2.2, 4.3.1 | Consent |
| Detecting, investigating and preventing misuse, automated extraction, fraud or attack | Clauses 4.2.2, 4.3.1 | Legitimate use under the Act |
| Complying with law and responding to lawful requests from a competent authority | As required | Legal obligation |
5.2 The Company does not process Personal Data for any purpose beyond those in clause 5.1 without first obtaining fresh consent for that purpose.
5.3 The Company does not sell, rent, licence or otherwise make Personal Data available to any third party for that party's own purposes.
5.4 The Company does not share Personal Data with advertising networks and does not conduct behavioural advertising on the Service.
5.5 The Company does not use Personal Data to make any wholly automated decision producing legal effects concerning you or similarly significantly affecting you.
6. Consent: how it is given, recorded and withdrawn
In plain terms. You consent when you create an Account. We keep a record of it. You can take it back at any time and it must be as easy to take back as it was to give.
6.1 Consent is obtained at the point of Account creation by an affirmative action. Continued use of the Service is not treated as consent.
6.2 Consent to communications described in the fifth row of clause 5.1 is obtained separately from consent to the operation of the Service. Declining it does not affect your access to the Service.
6.3 The Company maintains a record of each consent, comprising the identity of the person consenting, the purposes consented to, and the date and time of consent.
6.4 You may withdraw any consent at any time by written notice to support@phyzok.com. Withdrawal takes effect on receipt and is not retrospective, meaning it does not render unlawful any processing carried out before withdrawal.
6.5 Withdrawal of consent to the purposes necessary for the operation of the Service will result in closure of your Account, because the Service cannot be delivered without them. Withdrawal of consent to communications under clause 6.2 stops those communications and has no other effect.
6.6 The Company will not make continued provision of the Service conditional on consent to any purpose that is not necessary for that provision.
7. Users below eighteen years of age
In plain terms. Most people preparing for engineering entrance examinations are under eighteen. If that is you, a parent or guardian must agree before your account works, and we will not track you across the internet or advertise to you.
7.1 The Company treats every User who states an age below eighteen as a child for the purposes of section 9 of the Act.
7.2 Verifiable Guardian consent is a precondition to use. Where a User states an age below eighteen, the Company requests the email address and mobile number of a Guardian and transmits a request for confirmation. The Account is not made available for use until that confirmation is received and recorded under clause 6.3.
7.3 In respect of any Account held by a User below eighteen, the Company shall not:
7.3.1 track or monitor the behaviour of that User across any website, application or service other than the Service;
7.3.2 display targeted or behavioural advertising of any description;
7.3.3 disclose Personal Data to any advertising network or data broker; or
7.3.4 process the Personal Data for any purpose other than delivery of the Service and communication relating to it.
7.4 Analytics in respect of such Accounts is limited to what is necessary to operate and repair the Service and is used in aggregate.
7.5 Guardian rights. A Guardian may at any time require access to the Personal Data held about the child, require its correction, require deletion of the Account and its associated data, or withdraw consent. Withdrawal of consent closes the Account. A Guardian exercising these rights should write to puja@phyzok.com from the email address by which consent was given, so that identity can be verified without collecting further Personal Data.
7.6 Where the Company becomes aware that an Account for a User below eighteen was created without Guardian consent, it shall suspend the Account and contact the Guardian. If consent is not obtained within thirty days, the Account and its associated Personal Data shall be deleted.
7.7 Accounts predating this requirement. The Service was available before the Guardian consent mechanism described in clause 7.2 was introduced. Where an Account was created before that date and the User is below eighteen, the Company shall contact the User to obtain Guardian consent. Until consent is obtained, processing in respect of that Account shall be limited to what is necessary to preserve the Account and the work saved in it, and shall not extend to any other purpose in clause 5.1.
8. Processors and disclosures
In plain terms. These are the only outside companies that touch your data, and each is contractually restricted to doing what we tell them.
8.1 The Company engages the following Processors. Each is bound by written terms restricting it to processing on the Company's instructions, prohibiting use for its own purposes, and requiring security measures no less protective than those in clause 12.
8.1.1 Database and application hosting: Neon. Account data, assessment activity and derived outputs described in clause 4 are stored in infrastructure operated by Neon. See clause 10.
8.1.2 Analytics: Google Analytics and PostHog. These receive technical data under clause 4.3.1 and events describing interactions within a page. Advertising features, audience sharing and ads personalisation are not enabled in Google Analytics, and neither Processor is permitted to use the data for advertising.
8.1.3 Email delivery: Google Workspace. Receives your email address and the content of messages sent to you.
8.1.4 SMS delivery: MSG91. Receives your mobile number and the content of messages sent to you.
8.1.5 WhatsApp messages: the WhatsApp Business Platform, operated by Meta. Receives your mobile number and the content of messages sent to you.
8.2 No Processor is authorised to engage a further Processor without the Company's prior written authorisation.
8.3 Disclosure required by law. The Company shall disclose Personal Data where required by law, by order of a court, or by a competent authority acting under lawful authority. Where the Company is permitted to inform you of such a disclosure, it shall do so.
8.4 Business transfer. In the event of a merger, acquisition or transfer of the business, Personal Data may transfer as part of that transaction. You shall be given notice before any such transfer takes effect, and the transferee shall remain bound by this policy until it issues notice of a replacement policy.
8.5 Save as set out in this clause 8, the Company does not disclose Personal Data to any third party.
9. Artificial intelligence
In plain terms. We use AI on our own question bank. We do not send anything you write or answer to an outside AI company, and nothing of yours trains any model.
9.1 The Company uses artificial intelligence models in the preparation of its own content, including reading past examination papers it has obtained, classifying questions by chapter and topic, drafting explanatory material, and identifying common errors a question invites.
9.2 All such processing operates exclusively on the Company's own question bank.
9.3 No Personal Data, and no material submitted by you, is transmitted to any third party artificial intelligence provider. This includes your responses, your results, your reports, your messages to the Company and any other content you submit.
9.4 No Personal Data is used to train, fine tune or evaluate any artificial intelligence model, whether operated by the Company or by any third party.
9.5 Should the Company propose to change the position in clauses 9.3 or 9.4, it shall amend this policy and obtain your consent before any such processing occurs.
10. Processing outside India
In plain terms. Our database provider is an American company, so some of your data is handled outside India. The law permits this, and we will move the data if that ever changes.
10.1 Neon, the Processor named in clause 8.1.1, is incorporated in the United States of America. Personal Data stored in infrastructure operated by Neon is accessible to Neon's systems and authorised personnel for the purposes of operating and supporting that infrastructure. Personal Data is accordingly processed outside India.
10.2 Section 16 of the Act permits transfer of Personal Data outside India except to a country restricted by notification of the Central Government. The Company does not transfer Personal Data to any country so restricted.
10.3 Should a country on which the Company relies become restricted by such notification, the Company shall migrate the affected Personal Data rather than continue the transfer.
10.4 The specific hosting region in which the Company's database project operates at any time will be disclosed on written request to support@phyzok.com.
11. Retention
In plain terms. We keep each kind of data for a stated period and then delete it.
11.1 Personal Data is retained for no longer than the periods below, after which it is deleted.
| Category | Retention period |
|---|---|
| Account data under clause 4.1.1 | For the life of the Account, and ninety days after deletion of the Account, so that inadvertent deletion may be reversed |
| Assessment activity and derived outputs under clauses 4.2.2 and 4.2.3 | For the life of the Account, and ninety days after deletion of the Account |
| Browser identifiers and associated activity under clause 4.2.1, where no Account was created | Twelve months from the date of last activity |
| Guardian consent records under clause 4.1.2 | For the life of the Account, and three years after closure, in order to evidence that consent was validly obtained |
| Technical data under clause 4.3.1 | Ninety days |
| Communications data under clause 4.4.1 | Three years from the date of the communication |
| Correspondence under clause 4.1.3 | Three years from the date of the correspondence |
| Aggregated data containing no information by which an individual is identifiable | Retained without limit |
11.2 Where any law requires retention for a longer period, the Company shall retain the affected data for the period so required and for no longer.
11.3 On expiry of the applicable period, Personal Data is deleted from live systems and from backups in the ordinary backup rotation.
12. Security and breach notification
In plain terms. We protect the data with real measures, we do not claim they are perfect, and if something goes wrong we will tell you.
12.1 The Company implements reasonable security safeguards, including:
12.1.1 storage of passwords solely as cryptographic hashes, in a form from which the password cannot be recovered by the Company;
12.1.2 encryption of all traffic between your device and the Company's servers;
12.1.3 restriction of access to production data to those personnel whose functions require it, with such access logged; and
12.1.4 database level access controls preventing the data of one User from being returned in response to a request by another.
12.2 The Company does not represent that its systems are immune from compromise.
12.3 In the event of a personal data breach, the Company shall notify the Board and each affected Data Principal in the form and manner required by the Act, and shall inform each affected Data Principal of the nature of the breach, the categories of Personal Data involved, and the measures being taken in response.
13. Your rights
In plain terms. You can see what we hold, correct it, delete it, take back consent, appoint someone to act for you, and complain. None of it costs anything.
13.1 Right to access. You may require a summary of the Personal Data processed about you, the processing activities undertaken, and the identities of all Processors and third parties with whom it has been shared.
13.2 Right to correction and completion. You may require correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, and updating of Personal Data that is out of date.
13.3 Right to erasure. You may require erasure of your Personal Data. The Company shall comply unless retention is required for compliance with any law then in force, in which case it shall inform you of the requirement relied on.
13.4 Right to withdraw consent. You may withdraw consent in accordance with clause 6.4.
13.5 Right to nominate. You may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
13.6 Right of grievance redressal. You may raise a grievance in accordance with clause 14.
13.7 Exercise. To exercise any right under this clause, write to the Grievance Officer, Puja S, at puja@phyzok.com from the email address associated with your Account. The Company shall respond within thirty days of receipt. Where the Company requires longer, it shall inform you of the reason before the expiry of that period.
13.8 No fee is charged for the exercise of any right under this clause.
13.9 Your duties. The Act requires you not to impersonate another person when providing Personal Data, not to suppress material information where you are required to disclose it, and not to raise a grievance that is false or frivolous.
14. Grievance redressal
In plain terms. Complain to Puja S first. If you are not satisfied, you can escalate to the Data Protection Board of India.
14.1 The Grievance Officer appointed by the Company is Puja S, contactable at puja@phyzok.com. Correspondence by post may be addressed to the Grievance Officer at the registered office stated in clause 2.1.
14.2 A grievance should state your name, the email address associated with your Account, and the relief sought.
14.3 The Company shall acknowledge a grievance within seventy two hours of receipt and shall dispose of it within thirty days of receipt.
14.4 Where you are dissatisfied with the Company's disposal of a grievance, or where no response is received within the period in clause 14.3, you may make a complaint to the Data Protection Board of India.
14.5 A Guardian raising a grievance in relation to a child's Account should write from the email address by which consent was given, so that identity may be verified without collection of further Personal Data.
15. Cookies and browser storage
In plain terms. Three kinds, all necessary or analytical. None for advertising.
15.1 The Company uses the following:
15.1.1 Session cookies, which identify your browser to the Company's servers so that you remain signed in between pages. The Service cannot function without these.
15.1.2 Local storage, which retains your responses during a test so that a lost connection or page reload does not destroy your work. The Service cannot function without this.
15.1.3 Analytics cookies, operated by the Processors named in clause 8.1.2.
15.2 The Company does not use advertising cookies and does not permit any third party to place advertising cookies through the Service.
15.3 Browsers permit cookies to be blocked or deleted. Blocking the categories in clauses 15.1.1 and 15.1.2 will prevent the Service from functioning.
16. Status under the Act
In plain terms. We are not classified as a large scale data handler, and if that changes we will say so.
16.1 The Company has not been notified by the Central Government as a Significant Data Fiduciary under section 10 of the Act, and the additional obligations applicable to such an entity, including appointment of a Data Protection Officer resident in India and periodic Data Protection Impact Assessment, do not presently apply.
16.2 Should the Company be so notified, this policy shall be amended and the additional obligations discharged.
17. Amendment
In plain terms. If we change this, we tell you, and where the law requires we ask you again.
17.1 The Company may amend this policy. The date at the head of this policy shall be updated on each amendment.
17.2 Where an amendment is material, the Company shall give notice by email to the address associated with your Account and by prominent notice within the Service, in each case before the amendment takes effect.
17.3 Where an amendment introduces a purpose for which consent is required under the Act, the Company shall obtain fresh consent for that purpose rather than rely on consent previously given.
17.4 An earlier version of this policy will be provided on written request to support@phyzok.com.
18. Contact
18.1 For privacy matters and grievances: Puja S, Grievance Officer, puja@phyzok.com.
18.2 For all other matters: support@phyzok.com.
18.3 By post: Edzok 226 Innovations Private Limited, 213, Neo Corporate Plaza, Ramchandra Lane, Malad West, Mumbai 400064, Maharashtra, India.
19. Language
19.1 This policy is published in English. In accordance with section 5 of the Act, the Company shall provide this policy in any language specified in the Eighth Schedule to the Constitution of India on written request to support@phyzok.com.