Built for trust, and for the DPDP Act
A school’s data is a child’s data. Vidyom is engineered so money can’t drift, one school can never see another, and personal data is handled the way India’s Digital Personal Data Protection Act requires — ahead of the 2027 enforcement deadline.
How we protect your data
Security by design
Fail-closed tenant isolation
Every school’s data is isolated with row-level security that defaults to denying access. One school can never see another’s data.
Append-only money & audit
Money and sensitive actions are written to append-only, tamper-evident trails — the books and the audit log replay to any moment.
Role-based access control
Every privileged action — especially money writes — is gated by roles, enforced server-side and checked in CI.
No student PII to third-party AI
AI features are grounded and human-gated; student personal data is never sent to a third-party large-language model.
Encryption & data residency
Sensitive fields are encrypted; data is hosted in India and isolated per school.
Verifiable parental consent
For under-18 records, the consenting adult is verified (identity / age data or a DigiLocker token) and the linkage is retained as evidence.
Hardened transport
HTTP Strict Transport Security is on by default, with HMAC request signing and mutual-TLS available for the machine and mobile planes.
The law
Ready for the DPDP timeline
India’s Digital Personal Data Protection Act, 2023 and its Rules phase in through 2027. Vidyom is built for the operative obligations before they bite.
Nov 2025 — Board established
The Data Protection Board is set up; initial rules take effect.
~Nov 2026 — Consent managers
Consent-manager registration provisions come into force.
~May 2027 — Obligations bite
Notice, consent, security safeguards, breach reporting, retention and data-principal rights become operative.
Is your school ready for 2027?
Take the 8-question DPDP readiness self-assessment and get a prioritised gap report.
Your rights
Data-principal rights, on a clock
Parents and staff can exercise their rights, and the school can honour them within DPDP’s time limits — access, correction and erasure within 30 days; grievances within 90.
If the worst happens
A dual-clock breach response
On a personal-data breach, two timers run concurrently to different recipients.
CERT-In — 6 hours
A technical / forensic report to CERT-In within six hours of becoming aware.
DPDP Board — 72 hours
Notify affected data principals without delay, then a detailed report to the Data Protection Board within seventy-two hours. As a processor, Vidyom alerts the school promptly so it can meet its own clocks.
See our privacy policy for the full detail. This page is informational, not legal advice.