1. Introduction
Edvansh ("we", "our", or "us") operates the Edvansh School ERP platform — a school management system available via web at edvansh.com and via mobile application ("the Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights regarding that data.
By using the Platform, you (the school institution and its authorised users) agree to the practices described in this policy.
2. Who We Are
Edvansh Technologies
Website: edvansh.com
Support: support@edvansh.com
We are a data processor acting on behalf of the school institution (the data controller) that has subscribed to our Platform.
3. Who This Policy Applies To
This policy applies to all users of the Edvansh Platform:
- School Administrators — via the web application
- Vice Principals — via the web application
- Accountants — via the web application
- Receptionists — via the web application
- Admission Officers — via the web application
- Teachers — via the mobile application
- Parents — via the mobile application
- Students — whose data is entered and managed by the school
4. Data We Collect
4.1 School Institution Data
- School name, school code, address, contact information
- School logo and branding assets
- Academic year and term configuration
- School GPS location and attendance radius (for teacher geo-verification)
- Receipt format configuration
4.2 Staff Data
Applies to: Administrators, Vice Principals, Accountants, Receptionists, Admission Officers, and Teachers.
- Full name, email address, mobile number
- User code (employee ID)
- Role and class/subject assignments
- Department and employment type (for teaching staff)
- Profile photograph (if uploaded)
- Login timestamps and session activity
- Failed login attempts (for account security)
- Device push notification tokens (platform: iOS or Android)
- HR records: employment status history (active, on leave, notice period, resigned, retired), date of joining
- Documents uploaded to the teacher document vault (e.g. experience letters, certificates)
4.3 Student Data
- Full name, date of birth, gender
- Admission number, admission date
- Current class and section
- Parent/guardian linkage
- Address and emergency contact information
- Profile photograph (if uploaded)
- Enrolment status (active, suspended, withdrawn, alumni)
- Academic history: class transfers, promotions, academic year enrolments
4.4 Parent Data
- Full name, relation to student
- Email address, mobile number
- User code
- Linked student records
4.5 Admission Data
- Inquiry records: applicant name, contact information, class applied for, source of inquiry, inquiry status, follow-up notes
- Application records: applicant academic history, documents submitted, application status, interview and review notes
4.6 Academic and Operational Data
- Daily attendance records (present, absent, late) with timestamps
- Homework assignments and file attachments (PDF, JPG, PNG up to 5 MB)
- Examination records: exam names, subjects, maximum marks, student marks, marks edit history
- Timetable schedules: period allocations and subject-teacher-class assignments
- Curriculum structure: units, chapters, and topics per subject
- Academic term configurations
- School notices and push notifications (title, message, recipients)
- Parent queries submitted through the Platform and school responses
- Fee structures, installment schedules, payment records, and receipt PDFs
- Fee waivers and waiver reasons
- Student certificates generated via the Platform (bonafide certificates, transfer certificates)
4.7 Location Data
GPS coordinates submitted by teachers when marking their own daily attendance. Coordinates are validated against the school's configured location and attendance radius; they are stored with the attendance record for audit purposes.
4.8 Device and Technical Data
- Push notification tokens (Expo/FCM) registered at login; deleted on logout
- Platform type (iOS or Android)
- IP addresses (captured in standard server logs)
5. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Providing the Platform services (attendance, marks, fees, homework, notifications, admissions, timetable) | Contract performance |
| Verifying teacher location for geo-fenced check-in | Legitimate interest (school's operational requirement) |
| Sending push notifications and email OTPs | Contract performance |
| Account security (login monitoring, lockout after failed attempts) | Legitimate interest |
| Generating fee receipts, certificates, and academic reports | Contract performance |
| Customer support and troubleshooting | Legitimate interest |
| Compliance with applicable law | Legal obligation |
We do not use student or parent data for advertising, profiling, or any purpose outside school operations.
6. Children's Data
The Platform manages data of students who may be minors. This data is entered exclusively by the school institution (the data controller) under their own legal authority and duty of care. Edvansh processes this data solely on the school's instructions. We do not independently contact students or use student data for any purpose beyond the school's operational requirements.
Schools are responsible for obtaining any consents required from parents/guardians under applicable law before entering student data into the Platform.
7. Data Storage and Security
- All data is stored in a PostgreSQL database hosted on secured cloud infrastructure (DigitalOcean).
- Data is logically isolated by school — each school's data is scoped by a unique school identifier and is never accessible to other schools.
- Access is controlled by role-based JWT authentication with short-lived access tokens (30 minutes) and rotating refresh tokens (7 days).
- Accounts are locked after 5 consecutive failed login attempts (15-minute lockout).
- File attachments (homework, receipts, logos, teacher documents) are stored in the database as binary data — not in publicly accessible file storage.
- Data is transmitted over HTTPS/TLS at all times.
- We apply reasonable technical and organisational security measures in accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
8. Data Retention
- Active school data is retained for the duration of the school's subscription.
- Student and attendance records use soft deletion — records are deactivated, not permanently deleted, to preserve historical integrity of attendance, marks, and fee history.
- On subscription termination, we will work with the school to export their data before deletion. Data is deleted within 90 days of subscription end unless a longer retention is required by law.
- Push notification tokens are deleted on user logout and are short-lived by nature.
- Server logs are retained for up to 90 days.
9. Data Sharing
We do not sell, rent, or share personal data with third parties for commercial purposes. We share data only with:
| Recipient | Purpose |
|---|---|
| ZeptoMail (Zoho) | Transactional email delivery (OTP emails only) |
| Expo (Expo Inc.) | Push notification delivery via Expo Push Service / Firebase Cloud Messaging |
| DigitalOcean | Cloud hosting and database infrastructure |
All third-party providers are bound by data processing agreements and process data only as instructed by us. We may disclose data if required by Indian law, court order, or government authority.
10. Your Rights
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian law, individuals have the right to:
- Access — request a copy of personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Erasure — request deletion of personal data (subject to legal and contractual retention obligations)
- Grievance redressal — raise a complaint about how your data is handled
For school staff and parents: Contact your school administrator, who manages data within the Platform.
For schools (institutional requests): Email support@edvansh.com with subject line "Data Privacy Request". We will respond within 30 days.
11. Cookies
The web application uses cookies for:
- Authentication session management (JWT storage)
- User preferences (theme)
We do not use tracking or advertising cookies.
12. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last Updated" date at the top and notify schools via email. Continued use of the Platform after changes constitutes acceptance.
13. Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDPA 2023, our grievance officer can be reached at:
Email: support@edvansh.com
Response time: Within 30 days of receipt
14. Governing Law
This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the jurisdiction of competent courts in India.