Skip to content
Vidyom
Security & privacy

Built for trust, and for the DPDP Act

A school’s data is a child’s data. Vidyom is engineered so money can’t drift, one school can never see another, and personal data is handled the way India’s Digital Personal Data Protection Act requires — ahead of the 2027 enforcement deadline.

How we protect your data

Security by design

Fail-closed tenant isolation

Every school’s data is isolated with row-level security that defaults to denying access. One school can never see another’s data.

Append-only money & audit

Money and sensitive actions are written to append-only, tamper-evident trails — the books and the audit log replay to any moment.

Role-based access control

Every privileged action — especially money writes — is gated by roles, enforced server-side and checked in CI.

No student PII to third-party AI

AI features are grounded and human-gated; student personal data is never sent to a third-party large-language model.

Encryption & data residency

Sensitive fields are encrypted; data is hosted in India and isolated per school.

Verifiable parental consent

For under-18 records, the consenting adult is verified (identity / age data or a DigiLocker token) and the linkage is retained as evidence.

Hardened transport

HTTP Strict Transport Security is on by default, with HMAC request signing and mutual-TLS available for the machine and mobile planes.

The law

Ready for the DPDP timeline

India’s Digital Personal Data Protection Act, 2023 and its Rules phase in through 2027. Vidyom is built for the operative obligations before they bite.

Nov 2025 — Board established

The Data Protection Board is set up; initial rules take effect.

~Nov 2026 — Consent managers

Consent-manager registration provisions come into force.

~May 2027 — Obligations bite

Notice, consent, security safeguards, breach reporting, retention and data-principal rights become operative.

Is your school ready for 2027?

Take the 8-question DPDP readiness self-assessment and get a prioritised gap report.

Check your readiness

Your rights

Data-principal rights, on a clock

Parents and staff can exercise their rights, and the school can honour them within DPDP’s time limits — access, correction and erasure within 30 days; grievances within 90.

Access. A summary of the personal data processed and how.
Correction & completion. Fix inaccurate or incomplete data.
Erasure. Have data erased when retention no longer requires it.
Grievance & nomination. Raise a grievance and nominate a representative.

If the worst happens

A dual-clock breach response

On a personal-data breach, two timers run concurrently to different recipients.

CERT-In — 6 hours

A technical / forensic report to CERT-In within six hours of becoming aware.

DPDP Board — 72 hours

Notify affected data principals without delay, then a detailed report to the Data Protection Board within seventy-two hours. As a processor, Vidyom alerts the school promptly so it can meet its own clocks.

See our privacy policy for the full detail. This page is informational, not legal advice.

Run a school your parents can trust

Register your schoolBook a demo