Privacy Policy
This Privacy Policy outlines how personal data is collected, processed, secured, and retained on the SHAALAOS Multi-Tenant School ERP Platform, operated by ACADERS EDUVERSITY PRIVATE LIMITED for Subscribing Educational Institutions.
1 Scope & Privacy Focus
This Privacy Policy governs the processing of personal data across all SHAALAOS portals (Admin, Teacher, Student, Parent). This document is strictly dedicated to data privacy, data ownership, and security practices. Terms regarding payment processing, subscription fees, refunds, account suspensions, or intellectual property rights are governed separately under our Terms & Conditions.
2 Data Controller vs. Data Processor
- The Educational Institution (Data Controller / Data Fiduciary): The subscribing school or institution controls and owns 100% of all student, parent, and employee records submitted to the platform. The school is responsible for obtaining lawful consent from parents, guardians, and staff as required under applicable laws.
- SHAALAOS / Acaders Eduversity Pvt. Ltd. (Data Processor / Service Provider): Processes personal data solely on behalf of the institution to deliver ERP functionalities (timetables, report cards, attendance, fee registers, payroll). We act strictly under the instructions of the subscribing institution.
- Zero Data Monetization: We never sell, rent, monetize, or trade student, parent, or institutional data to third parties, advertising networks, or data brokers — under any circumstances.
Schools may have their own privacy policies governing how data is used within the platform. In case of conflict, the School's policy and instructions shall prevail for data under their control.
3 Information We Collect
To facilitate school administrative workflows, the system processes the following categories of data:
- Student Records: Full name, date of birth, gender, roll number, admission code, class/section, photo, attendance records, exam scores, and report card transcripts.
- Parent & Guardian Records: Parent/guardian names, primary contact numbers, email addresses, residential address, and transaction receipt logs.
- Staff & Faculty Records: Name, employee ID, email address, assigned classes/subjects, attendance, leave records, and salary slip details.
- School Account Information: School name, address, contact details of authorised representatives, designation, and employee IDs.
- Payment & Transaction Information: Mode of payment, masked card details as permitted by law, transaction amounts, dates, status, transaction IDs, and bank/payment gateway references (UTR numbers). Raw card data is never stored by SHAALAOS.
- System & Technical Logs: IP address, device session tokens, browser type, operating system, login timestamps, pages viewed, features used, and error logs — used strictly for authentication and security purposes.
- Support & Communication Data: Content of queries, support tickets, feedback, and communications submitted voluntarily to our desk.
We do not intentionally collect more data than is reasonably required to deliver our services.
4 Purpose of Data Processing
Personal data is processed exclusively for the following purposes:
- Managing student enrollments, class rosters, attendance logs, and academic gradebooks.
- Enabling parent portal access to view student performance, attendance, and fee invoices.
- Generating certified hall tickets, report cards, student ID cards, and transfer certificates.
- Dispatching essential operational notifications (SMS / WhatsApp / Email alerts for attendance, fee reminders, exam dates) as initiated by the School.
- Processing fee payments and generating official digital receipts on behalf of Schools.
- Staff payroll processing, leave management, and salary slip generation.
- Maintaining system access logs and security audits.
- Monitoring platform usage to improve features and user experience (using anonymised or aggregated data).
- Complying with applicable laws, regulations, and directions from government authorities or courts.
- Preventing, detecting, and investigating fraud, unauthorised access, or misuse of the platform.
Marketing Communications (Limited): With appropriate consent or as permitted by law, we may send information about product updates or new features. You may opt-out at any time using the unsubscribe link in any such communication or by contacting us at support@acaders.in.
5 Multi-Tenant Security & Data Isolation
SHAALAOS implements enterprise-grade technical and organisational data protection controls:
- Tenant Isolation: Multi-tenant logical database isolation ensures each institution's data is strictly partitioned and completely inaccessible to other schools on the platform.
- Encryption in Transit: Data in transit is protected via HTTPS / TLS 1.3 encryption across all portals.
- Encryption at Rest: Stored database records are secured with AES-256 encryption.
- Password Protection: All user passwords are encrypted using one-way BCrypt hashing algorithms and are never stored in plain text.
- Role-Based Access Control (RBAC): Strict permission scoping ensures users can only access records relevant to their authorised role.
- Automated Encrypted Backups: Daily encrypted database snapshots are maintained to ensure data recovery and business continuity.
- Security Monitoring: Regular security testing, access audits, and error monitoring are conducted to prevent unauthorised access.
No system is completely immune to security risks. While we implement robust measures, we cannot guarantee absolute security of data transmitted over public networks. Users are encouraged to keep login credentials secure and report any suspicious activity immediately.
6 Third-Party Service Integrations & Sub-Processors
Data is shared only with vetted infrastructure sub-processors strictly necessary to operate the service. These entities are bound by contractual obligations to handle data securely and use it only for specified purposes:
- Payment Processors: PCI-DSS compliant payment gateways for online fee collections. Financial credentials and card data are handled directly by these gateways — SHAALAOS does not store raw card numbers.
- Communication Providers: SMS and email gateways (e.g., AWS SES, WhatsApp Business API) for dispatching school circulars and transactional alerts. All SMS notifications are sent in compliance with TRAI DND (Do Not Disturb) regulations.
- Cloud Infrastructure: Cloud hosting providers (including AWS, Hostinger, and Cloudflare) for encrypted database storage and web application security.
- Analytics & Monitoring: Tools used to monitor platform health, security events, and error tracking. These process only anonymised or pseudonymised technical data — no student personal data is shared with analytics providers.
We do not share personal data with advertising networks, data brokers, or social media platforms.
Third-Party Links: The Platform may contain links to third-party websites (e.g., payment portals, government resources). SHAALAOS is not responsible for the privacy practices or content of such external websites. We encourage users to review the privacy policies of any third-party sites they visit.
7 Data Localisation & International Transfers
SHAALAOS stores and processes all student, parent, staff, and financial data primarily on servers located within India, in compliance with applicable data localisation requirements including RBI guidelines for payment transaction data.
Where data is transferred to or processed by service providers outside India (e.g., global cloud infrastructure components), we ensure such transfers are made in compliance with the Digital Personal Data Protection (DPDP) Act 2023 and applicable data protection laws, with appropriate contractual safeguards and secure transfer mechanisms in place.
8 Children's Privacy & DPDP Act 2023 Compliance
SHAALAOS is used by educational institutions that serve children and minors. Our handling of children's data is primarily on behalf of Schools as the data fiduciary.
- We do not directly offer the Platform to children without School or parent/guardian involvement.
- Parental consent for processing student data is managed by the educational institution during student onboarding, as required under the DPDP Act 2023.
- Student records are never used for behavioural profiling, targeted advertising, or any purpose beyond school administration.
- No automated decision-making or profiling that produces significant legal or similar effects on a student or parent is carried out by SHAALAOS without School authorisation.
- Schools are responsible for ensuring information relating to minors is shared in accordance with applicable laws and School policies.
If you believe we have collected personal data from a child in a way not authorised by the School or applicable law, please contact us immediately at privacy@shaalaos.com.
9 Data Retention & Deletion Policy
- Active Service Duration: Data is retained for as long as the subscribing institution maintains an active SHAALAOS workspace.
- Typical Retention Periods: Student academic records are retained for the duration of enrolment and up to 7 years after graduation or withdrawal, unless the School instructs otherwise. Staff records are retained for the duration of employment and up to 5 years thereafter, as per standard HR and legal requirements.
- Post-Termination Grace Period: Upon subscription cancellation or non-renewal, institutions are provided a 30-day window to export complete academic and financial data in standard formats.
- Permanent Purging: Following the 30-day grace period, all tenant database records and uploaded files are permanently deleted from platform production servers and backup snapshots.
- Aggregated & Anonymised Data: Aggregated, anonymised data that no longer identifies individuals may be retained for product analytics and service improvement.
10 Data Breach Notification
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of individuals, SHAALAOS will:
- Notify the Data Protection Board of India as required under the DPDP Act 2023, within the timeframe prescribed by applicable law.
- Notify the affected School (as data fiduciary) without undue delay, and in any case within 72 hours of becoming aware of the breach, where feasible.
- Provide affected users or Schools with details of the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed.
- Maintain an internal breach register and take immediate corrective action to contain and remediate the breach.
To report a suspected security incident or data breach, please email us immediately at privacy@shaalaos.com or support@acaders.in.
11 Your Rights as a Data Principal
Subject to applicable law, including the Digital Personal Data Protection (DPDP) Act 2023, and your relationship with the School, you may have the following rights:
- Right to Access: Request access to the personal data we hold about you.
- Right to Correction: Request correction or updating of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data (subject to legal and contractual limitations).
- Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time by contacting your School's administration or writing to us at privacy@shaalaos.com. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right to Nominate: Under the DPDP Act 2023, you may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
- Right to Object / Restrict Processing: Object to or restrict certain types of data processing in specific circumstances.
- Right to Grievance Redressal: File a grievance with our Grievance Officer. All grievances will be acknowledged within 24 hours and resolved within 30 days.
- Right to Approach the Data Protection Board: If your grievance is not resolved satisfactorily, you may approach the Data Protection Board of India established under the DPDP Act 2023.
For data processed on behalf of a School (student/parent/staff records), many of these rights must be exercised by contacting your School's administration directly, as they are the data controller/fiduciary.
12 Cookies & Similar Technologies
SHAALAOS uses cookies and similar technologies strictly for:
- Session Management: Maintaining your login session and keeping you securely authenticated.
- Security Tokens: CSRF tokens and similar mechanisms to protect against cross-site attacks.
- Preference Storage: Remembering your display preferences (e.g., theme settings).
- Platform Analytics: Understanding how the platform is used to improve features (using anonymised data only).
We do not use cookies for advertising or cross-site tracking. You may manage cookies through your browser settings. Disabling certain cookies may affect platform functionality, including login sessions.
13 Legal Basis for Processing
Depending on applicable laws and the nature of data, we process personal data on the following bases:
- Performance of Contract: Processing necessary to deliver services under the School Agreement or user terms.
- Compliance with Legal Obligations: Processing required to comply with applicable laws (e.g., tax records, statutory reporting).
- Legitimate Interests: Processing for service improvement, security monitoring, and fraud prevention, where not overridden by your rights.
- Consent: Where required by law, processing is based on consent obtained by the School or directly by SHAALAOS. Schools are responsible for obtaining and managing consent for student and parent data.
14 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or data practices. When we do:
- The "Last Updated" date at the top of this document will be revised.
- Where changes are material, we will notify subscribing Schools via the platform dashboard or registered email address.
- Continued use of the Platform after changes take effect constitutes acceptance of the updated Privacy Policy.
15 Grievance Officer & Contact Details
In accordance with India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, the following Grievance Officer has been designated:
For data under the control of your School (student/parent/staff records), please contact your School's administration directly in the first instance.
If your grievance is not resolved to your satisfaction within 30 days, you may escalate to the Data Protection Board of India established under the DPDP Act 2023.