1. Roles - who controls your data
For data about students, parents and staff, the school is the Data Fiduciary - it decides why and how that data is processed and it owns the relationship with the data principals. Vidyom is a Data Processor, processing that data solely on the school’s documented instructions under a written data-processing agreement (DPA). We do not decide the purposes of that processing and we do not use school data for our own ends.
For data we collect directly - for example a “register your school” or demo enquiry from this website, or the billing and account details of a subscribing school - Vidyom is the Data Fiduciary and this policy governs that data in full.
2. What we process and why (purpose limitation)
- School operations - admissions and enrolment, attendance, assessments and report cards, fees and accounting, transport, library, hostel, communications and the day-to-day running of the school.
- Children’s data - student records are processed only for school purposes (curriculum, attendance, assessment, health and child-safety, and statutory reporting such as UDISE+ / APAAR where applicable).
- Staff and payroll - to run HR, attendance, payroll and statutory filings for a subscribing school.
- Account & billing - to provide the service to a subscribing school and raise GST-compliant tax invoices.
- Website enquiries - to respond to a demo or “register your school” request and to contact you about it.
Each category of data is tagged to a specific purpose. We do not repurpose data beyond what the school’s notice and lawful basis allow, and we do not sell personal data or share it for third-party advertising.
3. Children’s data safeguards (Section 9)
Student records carry a hard under-18 flag. For children we do not undertake tracking, behavioural monitoring, profiling for advertising, or targeted advertising. Where consent is required, the school obtains verifiable parental consent: the consenting adult is identified - via identity/age data or a DigiLocker-issued virtual token - and the verified parent-child linkage is retained as evidence of that consent. Self-declared age or a blanket permission slip is not used as a lawful basis.
4. Consent and its withdrawal
Where processing relies on consent, a clear, itemised notice (each data category mapped to a purpose) is presented in plain language, and - where required - in the data principal’s chosen Indian language. Consent is sought per purpose, never bundled, and withdrawing consent is as easy as giving it. Withdrawal stops the affected processing and, where no other lawful basis applies, triggers erasure. Because the school is the Fiduciary, consent notices and withdrawals for student and parent data are managed through the school; Vidyom provides the mechanism and records the consent artefact.
5. Your rights as a Data Principal
- Access - a summary of the personal data processed about you and the processing activities.
- Correction & completion - to correct inaccurate data and complete incomplete data.
- Erasure - to have data erased where retention is no longer required or the basis has lapsed.
- Nomination - to nominate another individual to exercise your rights in the event of death or incapacity.
- Grievance redressal - to raise a grievance and receive a timely response.
Access, correction, completion and erasure requests are actioned within a target of 30 days - the DPDP Rules set no fixed statutory deadline for these rights requests, so each Data Fiduciary publishes its own period, and this is ours. Grievances are resolved within a ceiling of 90 days, the maximum the DPDP Rules, 2025 permit for grievance redressal. Requests concerning student, parent or staff data are routed to the school as Data Fiduciary; Vidyom assists the school in fulfilling them, including erasure that fans out across the linked systems that hold the record.
6. How we use artificial intelligence - and the lines we will not cross
Student personal data is never sent to, or used to train, any third-party AI or large-language-model service. The analytics, forecasts and risk indicators in Vidyom (for example fee-collection forecasts, attendance or drop-out risk flags) are deterministic and reason-coded - every score comes with the specific, inspectable reasons behind it. There is no opaque, black-box model making decisions about a child.
The one optional feature that uses an external language model - an assistant that helps design document and report templates - is off by default and, when a school turns it on, it receives only the names of fields (structural dot-paths such as student.name), never the actual values in those fields. No real student, parent or staff data leaves the platform for this feature.
7. Security safeguards
Vidyom is hosted in India and each school’s data is isolated from every other school’s by fail-closed row-level security enforced in the database - a request that cannot prove which school it belongs to is denied, so one school can never see another’s data.
- Money and audit integrity - fees are recorded as an append-only ledger in integer paise (no floating-point rounding), and sensitive actions are written to append-only, tamper-evident audit trails.
- Encryption & access control - sensitive fields are encrypted, and role-based access control is enforced server-side - especially for money-writing actions, which cannot be authorised from the client alone.
- Transport & integrity - HTTPS with HSTS, HMAC request signing on API traffic, and optional mutual-TLS on machine and mobile planes, so requests cannot be forged or replayed.
- Anomaly detection - unusual or sensitive activity is flagged for review.
8. Personal data breach notification
On becoming aware of a suspected personal-data breach, we open a statutory incident with a dual clock that runs concurrently under two different laws: a technical/forensic report to CERT-In within 6 hours (under the CERT-In Directions, 2022), and - under the DPDP Rules, 2025 - an initial intimation to the Data Protection Board without delay, followed by a detailed report within 72 hours of becoming aware (or a longer period the Board allows), together with intimation to each affected data principal without delay, in plain language. As a Processor, Vidyom notifies the affected school promptly so the school - as Fiduciary - can meet its own reporting obligations. We do not wait for certainty to start the clock; a credible suspicion is enough to trigger the process.
9. Retention and erasure
Personal data is retained only as long as its purpose requires or the law mandates. Where a statute sets a retention floor, we keep the record until the longest applicable period lapses - for example, financial and accounting records for at least eight financial years (Companies Act, 2013), and tax records for six years under income-tax law and seventy-two months from the annual-return due date under GST. (The DPDP Rules, 2025 Third Schedule - a fixed three-year erasure rule - is specific to very large e-commerce, online-gaming and social-media data fiduciaries and does not apply to a school or a school-ERP.) When the retention basis ends, we erase the data, including across the linked systems that hold copies of it. On termination of a school’s subscription, the school can export its data, and we delete it after any applicable retention period.
10. Processors and sub-processors
To deliver the service we rely on a small set of sub-processors, each restricted by contract to documented instructions and the same protections described here. The current categories are:
- Payments - a UPI / payment gateway to collect fees and issue receipts (for example Razorpay).
- Messaging - DLT-registered SMS, voice and WhatsApp providers for school communications (for example MSG91, Exotel, WhatsApp Cloud API).
- Push notifications - mobile push delivery via Firebase Cloud Messaging (FCM) and Apple Push Notification service (APNs).
- Identity & documents - DigiLocker for verifiable identity and document issuance.
- Bank data - a consent-based Account Aggregator for bank-statement reconciliation, pulled only with the account holder’s explicit consent.
- Cloud hosting - infrastructure hosted in India.
A current list of named sub-processors is available on request, and the school is notified in advance of any material change to that list. Data is hosted in India.
11. The school’s responsibilities as Data Fiduciary
Because the school controls its data, it is responsible for obtaining lawful consent or notice from parents, students and staff, and for the accuracy and lawfulness of the data it uploads to the platform. Vidyomprocesses that data only on the school’s documented instructions; we are not the Fiduciary for it, and we are not responsible or liable for a school’s unlawful processing, unlawful collection, or failure to obtain a valid lawful basis. If a school instructs us to do something that appears unlawful, we may decline and will inform the school. This division of responsibility is set out in the DPA between Vidyom and each school.
12. Changes to this policy
We may update this policy as the product and the law evolve. We will post any change on this page with a revised “last updated” date and, where the change is material, give reasonable advance notice through the product or by email before it takes effect.
13. Grievances and contact
For data about your school (student, parent or staff records), contact your school’s grievance officer first, since the school is the Data Fiduciary. For questions about this policy, or about data we hold as Fiduciary (website enquiries and subscribing-school billing), contact our Grievance Officer at info.vidyom@gmail.com.
14. Governing law
This policy, and any dispute about personal data Vidyom holds as a Data Fiduciary, are governed by the laws of India, with the courts at Bengaluru, Karnataka having jurisdiction - consistent with our terms of service.