1. Introduction & Scope
This Privacy Policy is published by UniSyft Technologies Pvt. Ltd. ("UniSyft", "edSyft", "we", "us", or "our"), the creator and operator of the edSyft school network ERP platform.
This Policy applies to:
- edsyft.com — our public marketing website, where prospective customers request demos
- app.edsyft.com — the edSyft platform used by school networks, their staff, students, and parents
This Policy governs how we collect, use, store, share, and protect personal data, and explains the rights available to individuals under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025.
By using our website or platform, you acknowledge that you have read and understood this Policy.
2. Data Fiduciary vs. Data Processor
Under the DPDP Act, 2023, two distinct roles govern personal data processing:
| Role | Who | Meaning |
|---|---|---|
| Data Fiduciary | Your school / school network (our Customer) | Determines the purpose and means of processing personal data (DPDP Act, s.2(i)) |
| Data Processor | edSyft / UniSyft | Processes personal data on behalf of, and only on the instructions of, the Data Fiduciary (DPDP Act, s.2(k)) |
This means your school (as Data Fiduciary) bears primary responsibility for ensuring a lawful basis exists before uploading personal data to edSyft. edSyft (as Data Processor) processes that data solely to provide the platform service, strictly under the school's instructions and our agreed terms.
Students and parents who have questions about how their school uses their data should contact their school administration first. Direct requests to edSyft are also accepted — see Section 15.
3. Data We Collect & Why
3A. Marketing Website (edsyft.com)
When you submit a demo request via our website, we collect:
| Data | Purpose | Basis |
|---|---|---|
| Full name | To address you in correspondence | Consent |
| Work email address | To send demo confirmation and follow-up | Consent |
| Phone number | To schedule your demo call | Consent |
| School / organisation name | To personalise your demo | Consent |
| Your role (dropdown) | To tailor demo to your function | Consent |
| Number of campuses | To demonstrate multi-campus features | Consent |
| Optional message | To understand your specific challenge | Consent |
We use Resend (email delivery service) to forward your request to our sales team. No data is stored in a database by the marketing website — it is transmitted by email and retained by our team in email only. We do not use cookies, analytics, tracking pixels, or any third-party scripts on edsyft.com.
3B. edSyft Platform (app.edsyft.com)
Authentication Data
Users log in using their email address or mobile phone number. A one-time password (OTP) is sent for verification. No passwords are stored. The email/phone number is your account identifier and is used solely for authentication and account management.
Staff & Administrator Data
- Full name, work email, phone number
- Assigned role (e.g., Principal, Accountant, Teacher)
- Organisation and campus assignments
- Profile picture (optional, stored in AWS S3)
Student Personal Data
- Full name, date of birth, gender
- Admission number, roll number, class, section, academic year
- Permanent and current residential address
- Blood group (Sensitive — see Section 4)
- Caste / category (Sensitive — see Section 4)
- Aadhaar number (Sensitive — see Section 4)
- Previous school records, TC number
- Academic performance records
- Nationality, religion
Parent / Guardian Data
- Father, mother, and guardian: full name, occupation, phone, email
- Relationship to student
- Residential address
Fee & Payment Data
- Fee ledger entries: amount billed, collected, outstanding
- Payment receipts with transaction reference IDs (Razorpay)
- Payment method type (cash, cheque, UPI, card, NEFT — reference numbers only)
- We do not store full card numbers or bank account numbers — Razorpay handles PCI-DSS compliance
Documents
- Scanned certificates, mark sheets, transfer certificates, photographs uploaded during onboarding
- Stored in AWS S3 (Mumbai region, ap-south-1)
- All document access is logged
System-Generated Data
- Audit logs: every action performed by every user (who, what, when)
- Sensitive field access logs: when Aadhaar, caste, or blood group fields are viewed
- Session tokens (HTTP-only, short-lived, server-side)
4. Sensitive Personal Data
The following fields carry heightened protections under the DPDP Act. Explicit, separate consent is obtained and logged before any sensitive data is processed.
Aadhaar Number
- Collected only where mandated by applicable law (e.g., government scholarship portals, statutory reporting)
- Stored in masked/tokenised form — full number never displayed after entry
- Access restricted to Principal and Admin roles only
- Every access is recorded in the
sensitive_field_access_logsaudit table
Caste / Category
- Collected only for government scheme eligibility or statutory regulatory reporting
- Not used for any profiling, discriminatory purpose, or commercial processing
- Same access controls and logging as Aadhaar
Blood Group
- Collected solely for medical emergency purposes on school premises
- Shared only with the school's medical/nursing staff
- Not used for insurance, profiling, or any other purpose
5. Minor Students & Parental Consent
The DPDP Act, 2023 requires verifiable parental or guardian consent before processing personal data of children under 18 years of age.
edSyft is a B2B platform provided to schools. The school (as Data Fiduciary) is responsible for:
- Obtaining verifiable parental/guardian consent before enrolling a student on the platform
- Providing parents with a privacy notice that discloses edSyft as a data processor
- Responding to parental requests to withdraw consent, and instructing edSyft accordingly
By agreeing to edSyft's Terms & Conditions, the school warrants that it has fulfilled these obligations for every student enrolled.
edSyft's commitments regarding student data:
- We do not engage in tracking, monitoring, behavioural profiling, or targeted advertising of students
- Student data is never used for commercial purposes beyond delivering the school's ERP service
- Student data is never sold, licensed, or shared with any third party beyond the sub-processors listed in Section 6
6. How We Share Data
We never sell personal data. We share data only in the following circumstances:
6A. Authorised Sub-Processors
| Sub-Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Msg91 | OTP delivery via SMS and email | Mobile phone number or email address only | India |
| Resend | Transactional email delivery | Email address and name | USA (SCCs apply) |
| Razorpay | Online fee payment processing | Payment amount and reference only | India |
| AWS S3 (ap-south-1) | Document and file storage | Uploaded documents and files | India (Mumbai) |
6B. Customer Schools (Data Fiduciaries)
Authorised users within a Customer school can access the personal data of their own students, parents, and staff. edSyft enforces row-level security so that no school can access another school's data — even within the same network.
6C. Legal Obligations
We may disclose personal data if required by Indian law, a valid court order, or a direction from the Data Protection Board of India. We will, where legally permitted, notify the relevant Customer school prior to disclosure.
7. Data Retention
We retain personal data only as long as necessary for the purposes described, or as required by applicable law.
| Data Category | Retention Period | Reason |
|---|---|---|
| OTP / authentication logs | 7 days | Security and fraud prevention |
| Session data | 30 days after inactivity | Account continuity |
| Student academic records | 5 years post-academic year, or per Customer instruction | Academic continuity and legal obligations |
| Fee / payment records | 8 years | Indian accounting and tax law requirement |
| Audit logs | 3 years | Compliance and dispute resolution |
| Sensitive field access logs | 2 years | DPDP Act accountability requirement |
| Demo request data (website) | 90 days after demo is conducted | CRM follow-up |
| Documents (AWS S3) | Per Customer data retention policy, minimum 3 years | Customer instruction |
Upon subscription termination, all Customer data is returned or securely deleted within 30 days of the termination date (see Terms & Conditions, Section 12).
8. Your Rights (DPDP Act)
Under the Digital Personal Data Protection Act, 2023, every Data Principal (individual whose data we process) has the following rights:
Right to Access (Section 11)
Request a summary of your personal data held by us, and the processing activities carried out. Fulfilled within 30 days.
Right to Correction (Section 12)
Request correction of inaccurate, incomplete, or outdated personal data. Fulfilled within 30 days.
Right to Erasure (Section 12)
Request deletion of your personal data where the specified purpose has been fulfilled or consent has been withdrawn, and no legal obligation requires retention. Fulfilled within 30 days.
Right to Nomination (Section 14)
Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
Right to Grievance Redressal (Section 13)
Lodge a complaint with us (see Section 14) or escalate to the Data Protection Board of India if unsatisfied.
How to exercise your rights: Email privacy@edsyft.com with the subject line "DPDP Data Request — [Right Type]". We may request identity verification before processing your request.
Students and parents should contact their school administration first (as the Data Fiduciary). The school will instruct edSyft accordingly. Direct requests to edSyft are also accepted.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data:
- Data in transit: TLS 1.2 or higher for all connections to app.edsyft.com
- Data at rest: AES-256 encryption on AWS RDS (PostgreSQL) and AWS S3 (documents)
- Tenant isolation: PostgreSQL row-level security (RLS) policies enforce strict data separation between organisations — no cross-tenant data leakage is possible at the database layer
- Access control: Role-based access control (RBAC) enforced at both API and database levels; users see only what their assigned role permits
- Sensitive field logging: Every access to Aadhaar, caste/category, and blood group fields is recorded in an immutable audit log
- Audit trails: Every action performed on the platform (create, update, delete) is logged with the user ID, timestamp, and affected record
- Security assessments: Regular internal reviews and third-party penetration testing
In the event of a personal data breach, we will notify the Data Protection Board of India within 72 hours as required by DPDP Act Section 8(6).
10. Breach Notification
A "personal data breach" means any accidental or unauthorised disclosure, acquisition, or destruction of personal data.
In the event of a breach:
- We will notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as required by DPDP Act Section 8(6)
- We will notify affected Customer schools (Data Fiduciaries) promptly and without undue delay
- Each school, as Data Fiduciary, is responsible for notifying affected students, parents, and other individuals in compliance with their own DPDP Act obligations
- Notifications will include: the nature and extent of the breach, likely consequences, remedial steps taken, and a point of contact for further queries
11. International Data Transfers
All student, staff, parent, and payment data is stored within India on AWS ap-south-1 (Mumbai).
The only cross-border data transfer is via Resend (email delivery, USA), which processes email addresses and names to deliver transactional emails. This transfer is carried out under appropriate safeguards (Standard Contractual Clauses / equivalent mechanisms) in accordance with the DPDP Act and Rules.
We actively monitor Central Government notifications under the DPDP Act regarding permitted and restricted countries for cross-border transfers, and will update our practices accordingly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. The "Last Updated" date at the top of this page will reflect any changes.
For material changes that affect how we process student data or sensitive personal data, we will notify Customer schools by email at least 30 days before the changes take effect. Continued use of the platform after that period constitutes acceptance of the updated Policy.
14. Grievance Officer
As required by the DPDP Act, 2023, we have designated a Grievance Officer to address data protection complaints:
Designation: Grievance Officer / Data Protection Officer
Organisation: UniSyft Technologies Pvt. Ltd.
Email: dpo@edsyft.com
Address: [Registered Address, City], India
Response timeline: We will respond to all complaints within 30 days of receipt. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
15. Contact Us
For any privacy-related queries, requests, or concerns, please contact us at:
Email: privacy@edsyft.com
Postal Address: UniSyft Technologies Pvt. Ltd., [Registered Address, City], India
Students and parents are encouraged to contact their school administration (the Data Fiduciary) in the first instance. The school will co-ordinate with edSyft on your behalf.