School Techy
School Techy
Modules
AdmissionsStudent InformationFees & FinanceAttendanceExaminationsTimetableTransportHostelLibraryHR & Payroll
Solutions
Colleges Universities Coaching institutes Mobile app Integrations
Company
Pricing All features About Case studies Security Resources Blog Partners Contact Sign in
Start free trial
Legal

Data Processing Agreement

For the person doing the due diligence. What we process, on whose instruction, with which sub-processors, under what security, and what happens at the end.

Last updated 31 July 2026
Roles

Who is what

Under the Digital Personal Data Protection Act, 2023:

  • The school is the Data Fiduciary. It decides what personal data to collect about its students, guardians and staff, and why. It is responsible for lawful basis, for notice, and for obtaining verifiable parental consent for children under 18.
  • School Techy is the Data Processor. We process that data solely on the school's documented instruction — which in practice means the configuration the school sets and the actions its own staff take in the software.

This agreement takes effect automatically when a school subscribes and forms part of the Terms of Use. A school that needs a countersigned copy on its own paper can request one; the substance will be what is on this page.

We do not process school data for our own purposes. Not for advertising, not for resale, not for training machine-learning models. Product decisions are informed by aggregate, non-identifying usage patterns — which screens are slow, which flows are abandoned — never by the contents of a student record.

Annex 1

Subject matter, duration and categories

Subject matter and duration. Provision of the School Techy platform, for the term of the subscription plus the 30-day retention window described below.

Nature and purpose. Storage, retrieval, organisation, transmission and erasure of school records, for the purpose of operating admissions, student information, attendance, fees and accounting, examinations, timetabling, transport, hostel, library, payroll and parent communication.

Categories of data subject: students (including minors), parents and guardians, teaching and non-teaching staff, applicants and enquirers, and the school's own administrative users.

Categories of personal data:

  • Identity and contact — names, dates of birth, gender, photographs, addresses, phone numbers, email addresses, relationships.
  • Identifiers — admission numbers, employee codes, and government identifiers such as Aadhaar, APAAR or UDISE references where the school chooses to record them.
  • Academic — attendance, marks, assessments, remarks, certificates.
  • Financial — fee structures, invoices, receipts, concessions, outstanding balances, payment references.
  • Employment — salary structure, statutory identifiers for PF, ESI, professional tax and TDS, leave.
  • Health — allergies, medical conditions and notes, where the school records them. Treated as sensitive and restricted to roles the school explicitly grants.
  • Usage and technical — audit logs, IP addresses, device and browser information, message delivery status.

Special note on children. The majority of data subjects are minors. We do not undertake behavioural monitoring, profiling or targeted advertising directed at children, and the platform contains no feature that would require it. We have declined to build facial-recognition attendance, CCTV integration and off-campus location tracking — those are decisions, not roadmap gaps.

Annex 2

Sub-processors

Each is engaged under a written contract imposing obligations no less protective than these, and each receives only the data its function requires.

CategoryPurposeData receivedLocation
Cloud hostingRuns the application and stores the database and backupsAll workspace dataIndia
Payment gateways — Razorpay, PayU, Cashfree, StripeOnline fee collection. Schools connect their own merchant account, so the relationship and the settlement are theirsPayer name, contact, amount, reference. We never receive card or UPI credentialsIndia (Stripe: as per its own terms)
SMS operators and DLT registriesTransactional SMS. Indian regulation requires sender ID and template registration before delivery is possible at allRecipient number, message contentIndia
WhatsApp Business providersWhatsApp messaging, where the school enables itRecipient number, message contentIndia / as per provider
Email deliveryTransactional email — receipts, password resets, noticesRecipient address, message contentAs per provider
Error monitoringDiagnosing faultsTechnical traces, scrubbed of personal dataAs per provider

Changes. We notify subscribing schools by email at least 30 days before adding or replacing a sub-processor that handles personal data. A school that reasonably objects on data-protection grounds may raise it with us, and if we cannot resolve it, may terminate the affected service without penalty for the unused term.

Location. Data is stored and processed in India. Where a provider operates outside India, transfers are made only to jurisdictions permitted under the DPDP Act and subject to appropriate contractual safeguards.

Annex 3

Technical and organisational measures

Specific, so they can be assessed. The Security page has the fuller version.

  • Access control enforced in the query. A role that cannot see fee data does not receive fee data — the narrowing happens in the database query, not by hiding a menu item, and the same rule covers the mobile API. This is the control most commonly implemented badly in this sector.
  • Tenant isolation at the data layer. Every query is scoped to a single school before it executes.
  • Authentication. Two-factor available to all schools, mandatory for our platform staff. Login rate limiting. Finite API token lifetimes.
  • Administrative access. Our staff hold explicit, individually granted permissions. Support access to a school workspace is deliberate, time-limited to 60 minutes, and written into the school's own audit log with the person and the time — you can see when we have been in.
  • Encryption in transit, and at rest for the fields that warrant it.
  • Audit logging of consequential actions, readable by the school.
  • Backups taken on a schedule and held separately from the live system.
  • Personnel under confidentiality obligations, with access on a need-to-know basis and revocation on departure.

Certification, honestly. We are not ISO 27001 or SOC 2 certified. We say so rather than implying otherwise with a badge. If your procurement requires either, we will not qualify, and it is better that you know it in the first meeting.

Incidents

Breach notification

On becoming aware of a personal data breach affecting your data we will notify you without undue delay and in any case within 72 hours, by email to your registered administrative contacts.

The notification will state what we know: the nature of the breach, the categories and approximate number of records affected, the likely consequences, what we are doing about it, and what you may need to do. Where the full picture is not yet available we will send what we have rather than waiting for completeness, and follow up.

As Data Fiduciary, the school has its own duty to notify the Data Protection Board of India and affected individuals. We will provide the information you reasonably need to discharge it.

Assistance

Helping you meet your obligations

  • Rights requests. Most are answerable by the school directly, because the record is in front of you and you can correct or delete it. Where a request needs something only we can produce, we will assist within a reasonable period and at no charge for ordinary volumes.
  • Requests that come to us. If a parent or staff member approaches us directly about data in your workspace, we will not act on it. We will tell them to contact you, and tell you it happened. A processor that amends a fiduciary's records on a third party's say-so has a security problem, not a service.
  • Audits. On reasonable notice, and no more than once a year unless an incident warrants it, we will answer a written security questionnaire and provide the documentation we hold. We do not permit third-party penetration testing against shared production infrastructure, because it affects every other school on it.
  • Government or law-enforcement demands. We disclose only what a valid order requires. Where we are legally permitted to tell you first, we will.
Exit

Return and deletion

Return. You do not need to ask. Students, guardians, the full fee ledger, attendance, marks and documents export in open formats from inside the product, on every plan, at any time, at no charge. This is deliberate: a vendor that gates export is setting a switching cost, and we would rather compete on the product.

Deletion. Your workspace is retained for 30 days after the subscription ends — so a late export or a change of mind is still possible — and is then permanently purged from live systems. Backups age out on their ordinary cycle. We will purge earlier on written request.

What we keep. Invoices and GST records, for the period Indian tax law requires. Nothing else.

Contact. support@schooltechy.com. For a formal matter under the DPDP Act, put "Grievance Officer" in the subject line: acknowledged within 48 hours, resolved within 30 days.