Privacy policy
How we handle student, staff and guardian data — written to be read, not just filed.
Scope of this policy
This policy explains how SchoolApp Technologies Pvt Ltd ("SchoolApp", "we") collects, uses and protects personal data when a school uses our platform. It covers our websites, mobile applications and administrative console.
Where a school subscribes to SchoolApp, the school is the data controller and SchoolApp acts as a data processor on its instructions. Parents and students should direct requests about their records to their school in the first instance.
What we collect
We collect only what is needed to run the service a school has asked for.
- Student records — name, admission number, class and section, date of birth, guardian contacts, attendance, marks, fee status and transport allocation.
- Staff records — name, work email, role, subjects taught and timetable allocation.
- Guardian details — name, relationship, phone number, email and address.
- Usage data — device type, browser, IP address, pages viewed and timestamps, used for security and diagnostics.
- Support correspondence — messages you send us and our replies.
We do not collect biometric data, and we do not use student data to train machine learning models.
How we use it
Personal data is used to deliver the platform: authenticating users, recording attendance, generating invoices and report cards, sending notifications a school has configured, and providing support when something breaks.
Aggregate, de-identified statistics may be used to improve the product and to publish research such as our annual administration report. These aggregates can never be traced back to an individual student, guardian or school.
Who we share with
We do not sell personal data. We share it only with sub-processors who help operate the service, each bound by contract:
- Cloud hosting providers, for infrastructure within the region a school selects.
- Payment gateways, for fee collection — card details are handled by the gateway and never stored by us.
- Communication providers, for email, SMS and push delivery.
We may disclose data where required by law, but will notify the school unless legally prevented from doing so.
Retention
Records are retained for as long as a school's subscription is active. On termination, a school may export its full dataset for 90 days, after which all production data is deleted and backups age out within a further 35 days.
Support correspondence is kept for three years. Server logs are retained for 90 days.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Because schools control their own records, requests should go to your school's administrator, who can action most of them directly in the platform.
If a school is unable to help, write to privacy@schoolapp.example and we will respond within 30 days.
Children's data
SchoolApp is designed for use by schools and processes data about children by necessity. Accounts for students under 13 are created and controlled by the school, not by the child. Students under 13 cannot make their data public through the platform, and there are no social or messaging features between students.
Security
Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Access by our staff is role-based, logged, and granted only where needed to support a school. We run third-party penetration tests annually and maintain a responsible disclosure programme.
Report a security issue to security@schoolapp.example. We acknowledge reports within two working days.
Changes and contact
Material changes to this policy will be notified to school administrators by email at least 30 days before taking effect. Questions can be sent to our Data Protection Officer at privacy@schoolapp.example or by post to 4th Floor, Carnival Infopark, Phase 1, Kakkanad, Kochi, Kerala 682042, India.