School Techy
School Techy
Modules
AdmissionsStudent InformationFees & FinanceAttendanceExaminationsTimetableTransportHostelLibraryHR & Payroll
Solutions
Colleges Universities Coaching institutes Mobile app Integrations
Company
Pricing All features About Case studies Security Resources Blog Partners Contact Sign in
Start free trial
Legal

Privacy Policy

A school holds more sensitive information about a child than almost any other institution they will encounter. This page states plainly what we do with it — and, just as importantly, what decisions are not ours to make.

Last updated 31 July 2026
The split

The school decides. We hold.

Under the Digital Personal Data Protection Act, 2023, the party that decides why and how personal data is processed is the Data Fiduciary. For everything inside a school's workspace — students, guardians, staff, fees, attendance, marks, medical notes — that party is the school, not us.

We are the Data Processor. We hold and process that information on the school's documented instruction, which in practice means the configuration the school sets and the actions its own staff take in the software. We do not decide what a school collects about a child, we do not decide who at the school may see it, and we do not use it for our own purposes.

This is not a disclaimer. It has three consequences that matter to you:

  • If you are a parent and want to know what is held about your child, corrected, or deleted, the school is the right first contact — they hold the record and the authority to change it. We will support them; we will not act on their data without them.
  • If you are a school, the obligations of a Data Fiduciary are yours: lawful basis, notice to parents, verifiable parental consent for children, and responding to rights requests. We give you the tools; we cannot discharge the duty for you.
  • Children's data is treated as children's data. The DPDP Act requires verifiable parental consent for anyone under 18 and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do not do any of those things, and we have declined to build the features that would require them — see Security.

Separately, for our own relationship with you — the account you create, the invoices we raise, the emails we send about the service — we are the Data Fiduciary, and this policy governs it directly.

Scope

What is actually held

Two different sets, held for two different reasons.

Inside a school's workspace (we are the processor)

  • Students: name, date of birth, gender, admission number, class and section, photograph, address, previous school, and any documents the school attaches — birth certificate, transfer certificate, Aadhaar where the school chooses to hold it.
  • Guardians: names, relationship, phone numbers, email addresses, occupation where recorded.
  • Health and welfare: allergies, medical conditions and notes, where the school records them. This is sensitive and is visible only to roles the school explicitly grants.
  • Academic: attendance, marks, assessments, report cards, remarks, certificates issued.
  • Financial: fee structures, invoices, receipts, concessions and their approvers, outstanding balances, payment references from your gateway.
  • Operational: transport route and stop allocation, hostel allocation, library issues and returns.
  • Staff: employment records, salary structure, statutory identifiers used for PF, ESI, professional tax and TDS, leave and attendance.
  • Communications: a log of the SMS, WhatsApp, email and in-app messages the school sent, with delivery status.
  • Audit: who did what, and when. Including us, when we access a workspace to support you.

About you, as our customer (we are the fiduciary)

  • The name, work email, phone number and role of the people who sign up and administer the account.
  • Your school's name, address, GSTIN where supplied, and the billing history against it.
  • Support correspondence, and notes from demos or enquiries.
  • Technical logs: IP address, browser, timestamps and error traces. These exist for security and diagnosis and are not used to build a profile of anyone.

We do not collect payment card details. Card and UPI data goes directly to the payment gateway; we receive a transaction reference and a status, never the instrument.

Purpose

Why each of those exists

Every field above is there because a specific function needs it. Where a purpose ends, so should the data — which is why the retention section below is specific rather than "as long as necessary".

  • To run the service you bought: admissions, records, attendance, fees, examinations, transport, hostel, library, payroll and communication. This is performance of our contract with the school.
  • To keep it secure: authentication, two-factor, rate limiting, audit logging and the detection of anything unusual.
  • To bill you: subscriptions, invoices and GST records, which Indian tax law requires us to retain.
  • To support you: answering a ticket, which sometimes means an authorised person here opening your workspace — time-limited, and written into your own audit log so you can see it happened.
  • To improve the product: aggregate, non-identifying usage patterns. Which screens are slow, which flows are abandoned. Not the contents of a student record.

What we do not do, stated because the absence is the point: we do not sell data, we do not share it with advertisers or data brokers, we do not use school data to train machine-learning models, and we do not profile children.

Sub-processors

Who else touches it

Running the service means a small number of specialist providers process data on our behalf. Each is bound by contract to use it only for the service they provide. The current list, by category:

  • Hosting and infrastructure — the servers and backups the application runs on.
  • Payment gateways — Razorpay, PayU, Cashfree or Stripe, depending on which the school connects. Note that schools connect their own gateway account, so the merchant relationship and the settlement are theirs.
  • SMS operators and DLT registries — Indian regulation requires the sender ID and message template to be registered before an SMS can be delivered at all.
  • WhatsApp Business providers — where a school enables WhatsApp messaging.
  • Email delivery — for transactional mail: receipts, password resets, notices.
  • Error monitoring — technical diagnostics, scrubbed of personal data.

A named, current list of sub-processors, with the data each receives, is maintained on the Data Processing Agreement page. Schools with a procurement or DPO review will want that page rather than this one.

Beyond those, we disclose data only where the law compels it — a valid order from a court or an authority with jurisdiction. Where we are legally permitted to tell the affected school first, we will.

Location. Data is stored and processed in India. If that changes, this page changes with it and affected schools are told in advance.

Retention

How long, exactly

Specific periods, because "as long as necessary" tells you nothing.

DataHeld for
A school's workspace, while subscribedFor as long as the subscription is active, plus whatever archival the school itself configures
A workspace after cancellation30 days, then permanently purged. Export before then — you can do it yourself, at any time, without asking us
Trial workspaces never converted30 days after the trial ends
Invoices, receipts and GST recordsAs required by Indian tax law, currently 8 years, regardless of cancellation
Platform audit logsPruned on a schedule; retained long enough to investigate an incident
Support correspondence3 years from the last message in the thread
BackupsRolling, and overwritten in the ordinary cycle. A record deleted from the live system persists in backups only until those backups age out

Within a live workspace, deletion is the school's decision, not ours. If a school asks us to purge earlier than the 30 days above, we will.

Protection

How it is protected

The short version; Security has the specifics and is more useful to a technical reviewer.

  • Access control is enforced in the database query, not by hiding menu items. A role that cannot see fee data does not receive fee data — the same rule covers the mobile API, which is where these gaps usually survive.
  • Each school's data is isolated at the data layer. Every query is scoped to one school before it runs.
  • Two-factor authentication is available to schools and mandatory for our own platform staff.
  • Encryption in transit, and at rest for the fields that warrant it.
  • Audit logging of consequential actions, readable by the school.
  • Support access is deliberate, time-limited and recorded in the school's own audit log. You can see when we have been in.

We are not ISO 27001 or SOC 2 certified, and we say so rather than implying otherwise. If a tender requires either, we will not qualify.

If something goes wrong. On becoming aware of a personal data breach we will notify affected schools without undue delay and in any case within 72 hours, with what we know, what we are doing, and what you may need to do. Schools, as Data Fiduciaries, have their own notification duties to the Data Protection Board and to affected people; we will give you what you need to discharge them.

Rights

Your rights, and where to exercise them

The DPDP Act 2023 gives you the right to access a summary of your personal data, to have it corrected or completed, to have it erased, to nominate someone to exercise these rights on your behalf, and to a grievance route.

Where to go depends on whose data it is.

  • Student, parent or staff data inside a school workspace — contact the school. They hold the record and the authority. We will not amend or release a school's data on a third party's request, because doing so on request would be its own security failure.
  • Your data as our direct customer — the account holder, the billing contact, an enquiry you sent us — write to us using the details below and we will respond within 30 days.

Schools: you do not need to ask us for an export. Students, guardians, the full fee ledger, attendance, marks and documents are exportable in open formats from inside the product, on every plan, at any time. We consider a vendor that charges for this, or requires a support ticket, to be setting a switching cost deliberately.

Withdrawing consent. Where processing rests on consent, it can be withdrawn as easily as it was given. Withdrawal does not undo processing already carried out lawfully, and where the data is needed to run the school's service, the school will need to decide what that means for the account.

Contact

Grievances and questions

Write to support@schooltechy.com. For a formal grievance under the DPDP Act 2023 or the Information Technology Rules, put "Grievance Officer" in the subject line — it is routed differently from ordinary support and is acknowledged within 48 hours and resolved within 30 days.

Our registered entity name and address appear on every invoice we issue and on the Contact page.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

Changes to this policy. When we change it we update the date at the top. For a change that materially affects how school data is handled, we notify subscribing schools by email at least 30 days before it takes effect, so a school that objects has time to act.

Questions

Common questions

Something not answered here?

Do you sell or share school data with anyone?
No. Not to advertisers, not to data brokers, not to anyone. The only third parties that process data are the sub-processors listed on the Data Processing Agreement page — hosting, payment gateways, SMS and WhatsApp providers, email delivery and error monitoring — each contractually limited to the service they provide.
Do you use school data to train AI models?
No. Product decisions are informed by aggregate, non-identifying usage patterns — which screens are slow, which flows get abandoned — and never by the contents of a student record.
I am a parent. How do I see what is held about my child?
Ask the school. They are the Data Fiduciary: they hold the record, decided what to collect, and have the authority to correct or delete it. We hold it on their instruction and will not release or amend it on anyone else's request, because a vendor that would do that has a security problem rather than a privacy policy.
What happens to our data if we stop using School Techy?
You export everything yourself — students, guardians, the full ledger, attendance, marks and documents, in open formats — at any time, on any plan, without asking us. Thirty days after cancellation the workspace is permanently purged. Invoices and GST records are kept longer because tax law requires it.
Can your staff read our students' records?
Only with deliberate, time-limited access granted for support, and every such session is written into your own audit log with the person and the time. You can see when we have been in. We do not browse school data and we do not use it for anything other than operating the service for you.
Is the data stored in India?
Yes. Data is stored and processed in India. If that ever changes this page changes with it, and subscribing schools are told in advance rather than after.