Legal

Privacy Policy

How UniSyft Technologies Pvt. Ltd. collects, uses, and protects personal data on the edSyft platform — in compliance with India's Digital Personal Data Protection (DPDP) Act, 2023.

Effective: 20 March 2026Last updated: 20 March 2026

1. Introduction & Scope

This Privacy Policy is published by UniSyft Technologies Pvt. Ltd. ("UniSyft", "edSyft", "we", "us", or "our"), the creator and operator of the edSyft school network ERP platform.

This Policy applies to:

  • edsyft.com — our public marketing website, where prospective customers request demos
  • app.edsyft.com — the edSyft platform used by school networks, their staff, students, and parents

This Policy governs how we collect, use, store, share, and protect personal data, and explains the rights available to individuals under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025.

By using our website or platform, you acknowledge that you have read and understood this Policy.

2. Data Fiduciary vs. Data Processor

Under the DPDP Act, 2023, two distinct roles govern personal data processing:

RoleWhoMeaning
Data FiduciaryYour school / school network (our Customer)Determines the purpose and means of processing personal data (DPDP Act, s.2(i))
Data ProcessoredSyft / UniSyftProcesses personal data on behalf of, and only on the instructions of, the Data Fiduciary (DPDP Act, s.2(k))

This means your school (as Data Fiduciary) bears primary responsibility for ensuring a lawful basis exists before uploading personal data to edSyft. edSyft (as Data Processor) processes that data solely to provide the platform service, strictly under the school's instructions and our agreed terms.

Students and parents who have questions about how their school uses their data should contact their school administration first. Direct requests to edSyft are also accepted — see Section 15.

3. Data We Collect & Why

3A. Marketing Website (edsyft.com)

When you submit a demo request via our website, we collect:

DataPurposeBasis
Full nameTo address you in correspondenceConsent
Work email addressTo send demo confirmation and follow-upConsent
Phone numberTo schedule your demo callConsent
School / organisation nameTo personalise your demoConsent
Your role (dropdown)To tailor demo to your functionConsent
Number of campusesTo demonstrate multi-campus featuresConsent
Optional messageTo understand your specific challengeConsent

We use Resend (email delivery service) to forward your request to our sales team. No data is stored in a database by the marketing website — it is transmitted by email and retained by our team in email only. We do not use cookies, analytics, tracking pixels, or any third-party scripts on edsyft.com.

3B. edSyft Platform (app.edsyft.com)

Authentication Data

Users log in using their email address or mobile phone number. A one-time password (OTP) is sent for verification. No passwords are stored. The email/phone number is your account identifier and is used solely for authentication and account management.

Staff & Administrator Data

  • Full name, work email, phone number
  • Assigned role (e.g., Principal, Accountant, Teacher)
  • Organisation and campus assignments
  • Profile picture (optional, stored in AWS S3)

Student Personal Data

  • Full name, date of birth, gender
  • Admission number, roll number, class, section, academic year
  • Permanent and current residential address
  • Blood group (Sensitive — see Section 4)
  • Caste / category (Sensitive — see Section 4)
  • Aadhaar number (Sensitive — see Section 4)
  • Previous school records, TC number
  • Academic performance records
  • Nationality, religion

Parent / Guardian Data

  • Father, mother, and guardian: full name, occupation, phone, email
  • Relationship to student
  • Residential address

Fee & Payment Data

  • Fee ledger entries: amount billed, collected, outstanding
  • Payment receipts with transaction reference IDs (Razorpay)
  • Payment method type (cash, cheque, UPI, card, NEFT — reference numbers only)
  • We do not store full card numbers or bank account numbers — Razorpay handles PCI-DSS compliance

Documents

  • Scanned certificates, mark sheets, transfer certificates, photographs uploaded during onboarding
  • Stored in AWS S3 (Mumbai region, ap-south-1)
  • All document access is logged

System-Generated Data

  • Audit logs: every action performed by every user (who, what, when)
  • Sensitive field access logs: when Aadhaar, caste, or blood group fields are viewed
  • Session tokens (HTTP-only, short-lived, server-side)

4. Sensitive Personal Data

The following fields carry heightened protections under the DPDP Act. Explicit, separate consent is obtained and logged before any sensitive data is processed.

Aadhaar Number

  • Collected only where mandated by applicable law (e.g., government scholarship portals, statutory reporting)
  • Stored in masked/tokenised form — full number never displayed after entry
  • Access restricted to Principal and Admin roles only
  • Every access is recorded in the sensitive_field_access_logs audit table

Caste / Category

  • Collected only for government scheme eligibility or statutory regulatory reporting
  • Not used for any profiling, discriminatory purpose, or commercial processing
  • Same access controls and logging as Aadhaar

Blood Group

  • Collected solely for medical emergency purposes on school premises
  • Shared only with the school's medical/nursing staff
  • Not used for insurance, profiling, or any other purpose

5. Minor Students & Parental Consent

The DPDP Act, 2023 requires verifiable parental or guardian consent before processing personal data of children under 18 years of age.

edSyft is a B2B platform provided to schools. The school (as Data Fiduciary) is responsible for:

  • Obtaining verifiable parental/guardian consent before enrolling a student on the platform
  • Providing parents with a privacy notice that discloses edSyft as a data processor
  • Responding to parental requests to withdraw consent, and instructing edSyft accordingly

By agreeing to edSyft's Terms & Conditions, the school warrants that it has fulfilled these obligations for every student enrolled.

edSyft's commitments regarding student data:

  • We do not engage in tracking, monitoring, behavioural profiling, or targeted advertising of students
  • Student data is never used for commercial purposes beyond delivering the school's ERP service
  • Student data is never sold, licensed, or shared with any third party beyond the sub-processors listed in Section 6

6. How We Share Data

We never sell personal data. We share data only in the following circumstances:

6A. Authorised Sub-Processors

Sub-ProcessorPurposeData SharedLocation
Msg91OTP delivery via SMS and emailMobile phone number or email address onlyIndia
ResendTransactional email deliveryEmail address and nameUSA (SCCs apply)
RazorpayOnline fee payment processingPayment amount and reference onlyIndia
AWS S3 (ap-south-1)Document and file storageUploaded documents and filesIndia (Mumbai)

6B. Customer Schools (Data Fiduciaries)

Authorised users within a Customer school can access the personal data of their own students, parents, and staff. edSyft enforces row-level security so that no school can access another school's data — even within the same network.

6C. Legal Obligations

We may disclose personal data if required by Indian law, a valid court order, or a direction from the Data Protection Board of India. We will, where legally permitted, notify the relevant Customer school prior to disclosure.

7. Data Retention

We retain personal data only as long as necessary for the purposes described, or as required by applicable law.

Data CategoryRetention PeriodReason
OTP / authentication logs7 daysSecurity and fraud prevention
Session data30 days after inactivityAccount continuity
Student academic records5 years post-academic year, or per Customer instructionAcademic continuity and legal obligations
Fee / payment records8 yearsIndian accounting and tax law requirement
Audit logs3 yearsCompliance and dispute resolution
Sensitive field access logs2 yearsDPDP Act accountability requirement
Demo request data (website)90 days after demo is conductedCRM follow-up
Documents (AWS S3)Per Customer data retention policy, minimum 3 yearsCustomer instruction

Upon subscription termination, all Customer data is returned or securely deleted within 30 days of the termination date (see Terms & Conditions, Section 12).

8. Your Rights (DPDP Act)

Under the Digital Personal Data Protection Act, 2023, every Data Principal (individual whose data we process) has the following rights:

Right to Access (Section 11)

Request a summary of your personal data held by us, and the processing activities carried out. Fulfilled within 30 days.

Right to Correction (Section 12)

Request correction of inaccurate, incomplete, or outdated personal data. Fulfilled within 30 days.

Right to Erasure (Section 12)

Request deletion of your personal data where the specified purpose has been fulfilled or consent has been withdrawn, and no legal obligation requires retention. Fulfilled within 30 days.

Right to Nomination (Section 14)

Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

Right to Grievance Redressal (Section 13)

Lodge a complaint with us (see Section 14) or escalate to the Data Protection Board of India if unsatisfied.

How to exercise your rights: Email privacy@edsyft.com with the subject line "DPDP Data Request — [Right Type]". We may request identity verification before processing your request.

Students and parents should contact their school administration first (as the Data Fiduciary). The school will instruct edSyft accordingly. Direct requests to edSyft are also accepted.

9. Data Security

We implement appropriate technical and organisational measures to protect personal data:

  • Data in transit: TLS 1.2 or higher for all connections to app.edsyft.com
  • Data at rest: AES-256 encryption on AWS RDS (PostgreSQL) and AWS S3 (documents)
  • Tenant isolation: PostgreSQL row-level security (RLS) policies enforce strict data separation between organisations — no cross-tenant data leakage is possible at the database layer
  • Access control: Role-based access control (RBAC) enforced at both API and database levels; users see only what their assigned role permits
  • Sensitive field logging: Every access to Aadhaar, caste/category, and blood group fields is recorded in an immutable audit log
  • Audit trails: Every action performed on the platform (create, update, delete) is logged with the user ID, timestamp, and affected record
  • Security assessments: Regular internal reviews and third-party penetration testing

In the event of a personal data breach, we will notify the Data Protection Board of India within 72 hours as required by DPDP Act Section 8(6).

10. Breach Notification

A "personal data breach" means any accidental or unauthorised disclosure, acquisition, or destruction of personal data.

In the event of a breach:

  • We will notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as required by DPDP Act Section 8(6)
  • We will notify affected Customer schools (Data Fiduciaries) promptly and without undue delay
  • Each school, as Data Fiduciary, is responsible for notifying affected students, parents, and other individuals in compliance with their own DPDP Act obligations
  • Notifications will include: the nature and extent of the breach, likely consequences, remedial steps taken, and a point of contact for further queries

11. International Data Transfers

All student, staff, parent, and payment data is stored within India on AWS ap-south-1 (Mumbai).

The only cross-border data transfer is via Resend (email delivery, USA), which processes email addresses and names to deliver transactional emails. This transfer is carried out under appropriate safeguards (Standard Contractual Clauses / equivalent mechanisms) in accordance with the DPDP Act and Rules.

We actively monitor Central Government notifications under the DPDP Act regarding permitted and restricted countries for cross-border transfers, and will update our practices accordingly.

12. Cookies & Tracking

Marketing Website (edsyft.com)

We use zero cookies, tracking pixels, analytics scripts, or third-party SDKs on our marketing website. If you submit the demo request form, your data is transmitted directly to our team by email — nothing is stored in a browser cookie or third-party analytics platform.

Platform (app.edsyft.com)

We use session cookies only:

  • HTTP-only (not accessible to JavaScript)
  • Secure flag set (HTTPS only)
  • SameSite=Strict (cross-site request forgery protection)
  • Session expires after 24 hours of inactivity

We use no advertising cookies, no analytics cookies, and no third-party tracking on the platform.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. The "Last Updated" date at the top of this page will reflect any changes.

For material changes that affect how we process student data or sensitive personal data, we will notify Customer schools by email at least 30 days before the changes take effect. Continued use of the platform after that period constitutes acceptance of the updated Policy.

14. Grievance Officer

As required by the DPDP Act, 2023, we have designated a Grievance Officer to address data protection complaints:

Designation: Grievance Officer / Data Protection Officer

Organisation: UniSyft Technologies Pvt. Ltd.

Email: dpo@edsyft.com

Address: [Registered Address, City], India

Response timeline: We will respond to all complaints within 30 days of receipt. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

15. Contact Us

For any privacy-related queries, requests, or concerns, please contact us at:

Email: privacy@edsyft.com

Postal Address: UniSyft Technologies Pvt. Ltd., [Registered Address, City], India

Students and parents are encouraged to contact their school administration (the Data Fiduciary) in the first instance. The school will co-ordinate with edSyft on your behalf.