Privacy Policy
Last updated: 2026-07-06
This Privacy Policy describes how EduGet360, a product of Artifixel Consultancy LLP, collects, uses, stores, shares, and protects Personal Data when you use our school management platform. This document is aligned with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and is subject to legal review before production use.
1. Introduction
EduGet360 ("EduGet360", "we", "us", or "our") is a cloud-based school management platform operated by Artifixel Consultancy LLP ("Artifixel"), a limited liability partnership registered in India.
This Privacy Policy explains how Personal Data is collected, used, stored, shared, and protected when educational institutions ("Institutions"), their authorized users, students, parents, guardians, employees, and other individuals use the EduGet360 platform (the "Platform" or "Services").
EduGet360 is designed for multi-tenant educational administration, including academic management, attendance, examinations, fees, payroll, communications, reporting, and related institutional workflows.
This Privacy Policy is aligned with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other Applicable Law in India. It should be read together with your Institution's privacy notices, subscription agreement, and any Data Processing Addendum.
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy to the extent it applies to you.
2. Definitions
In this Privacy Policy, the following terms have the meanings set out below:
- "Applicable Law" means applicable laws, regulations, rules, and regulatory guidance, including the DPDP Act and rules framed thereunder.
- "Biometric Data" means personal data generated from technical processing relating to physical, physiological, or behavioural characteristics of an individual, including fingerprint, facial, or other biometric identifiers used for attendance or access control.
- "Data Fiduciary" means the entity that determines the purpose and means of processing Personal Data, as defined under the DPDP Act.
- "Data Principal" means the individual to whom Personal Data relates, as defined under the DPDP Act.
- "Data Processor" means the entity that processes Personal Data on behalf of a Data Fiduciary.
- "Institution" or "Institutions" means a school, college, university, coaching centre, training institute, or other educational organization that subscribes to or uses the Platform.
- "Institution Data" means Personal Data entered, uploaded, generated, or processed through the Platform on behalf of an Institution.
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act.
- "Platform" means the EduGet360 software, applications, APIs, portals, integrations, and related services.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, retrieval, correction, or deletion.
- "Services" means the products, features, modules, and support provided through the Platform.
- "User" means any individual authorized to access the Platform, including administrators, teachers, staff, students, parents, and other roles assigned by an Institution.
3. Scope
This Privacy Policy applies to Personal Data processed through the Platform in connection with the Services.
It applies to Institutions that subscribe to or evaluate EduGet360; authorized Users of an Institution; students, parents, guardians, and employees whose data is managed through the Platform; visitors to EduGet360 websites, support channels, or demo environments where Personal Data is collected; and integrations, APIs, and connected devices that transmit data to or from the Platform.
This Privacy Policy does not apply to third-party websites, services, or devices that are not operated or controlled by EduGet360, even if linked from or integrated with the Platform. Those services are governed by their own privacy policies.
Where an Institution acts as the Data Fiduciary for Institution Data, that Institution's privacy notices and policies may also apply. EduGet360 generally processes such data as a Data Processor on the Institution's instructions.
4. Categories of Personal Data
Depending on the Institution's configuration, enabled modules, and user role, the Platform may process the following categories of Personal Data:
4.1 Account and Identity Data
- name, username, email address, phone number, photograph, role, and login credentials;
- authentication tokens, session identifiers, and multi-factor authentication records;
- user preferences, language settings, and notification preferences.
4.2 Institution and Configuration Data
- Institution name, branch details, academic structure, branding, subscription plan, and billing contact information;
- administrative settings, permissions, workflows, and module configuration.
4.3 Student and Academic Data
- admission, enrollment, attendance, timetable, examination, grading, report card, promotion, and disciplinary records;
- class, section, subject, teaching group, and academic performance information;
- parent or guardian contact details and communication history.
4.4 Staff and HR Data
- employment details, designation, department, payroll, leave, attendance, and performance records;
- bank or payment details where payroll or reimbursement features are used.
4.5 Financial Data
- fee structures, invoices, receipts, payment status, concessions, scholarships, and related billing records;
- transaction references from payment gateways where payments are processed through integrated services.
4.6 Communications and Support Data
- messages, notifications, announcements, emails, SMS, and in-app communications;
- support tickets, feedback, attachments, and call or chat records submitted to EduGet360.
4.7 Technical and Usage Data
- IP address, browser type, device identifiers, operating system, access logs, audit trails, and feature usage;
- error logs, diagnostics, and security event data.
4.8 Biometric and Device Data
- attendance punches, device identifiers, timestamps, and related metadata received from biometric or attendance devices;
- device configuration and connectivity data where ADMS or similar integrations are enabled.
4.9 AI-Related Data
prompts, inputs, and outputs where AI-powered features are used, subject to Institution configuration and applicable safeguards.
5. How Personal Data Is Collected
5.1 Institution Entry
Most Institution Data is entered directly by authorized Institution Users, imported through bulk uploads, or synchronized from approved third-party systems.
5.2 User Activity on the Platform
When Users access the Platform, certain technical and usage data is automatically generated through logs, cookies, and security monitoring.
5.3 Integrations and Devices
Personal Data may be received from integrated services such as payment gateways, messaging providers, identity providers, biometric attendance devices, and API-connected systems configured by the Institution.
5.4 Communications with EduGet360
Personal Data may be collected when you contact support, request a demo, subscribe to updates, or otherwise communicate with EduGet360.
5.5 Institution Responsibility for Collection
Where an Institution is the Data Fiduciary, the Institution is responsible for ensuring that Personal Data is collected lawfully and with all required notices and consents before it is entered into the Platform.
6. Purposes of Processing
EduGet360 processes Personal Data for the following purposes:
- providing, operating, maintaining, and improving the Platform and its modules;
- authenticating Users and managing access controls within each Institution's tenant;
- enabling academic, administrative, financial, communication, reporting, and operational workflows;
- processing attendance, examinations, fees, payroll, and other Institution-configured functions;
- sending service-related notifications, alerts, and support communications;
- monitoring, detecting, preventing, and responding to fraud, abuse, security incidents, and unauthorized access;
- complying with Applicable Law, lawful requests, and contractual obligations;
- generating analytics, audit logs, and operational reports for Institutions and internal service improvement;
- supporting integrations, APIs, biometric devices, and third-party services enabled by the Institution;
- providing AI-assisted features where enabled, subject to the safeguards described in this Privacy Policy.
Processing is carried out based on one or more lawful grounds under Applicable Law, including consent obtained by the Institution, contractual necessity, legitimate uses permitted under the DPDP Act, and legal obligations.
7. DPDP Act Compliance
EduGet360 is committed to processing Personal Data in accordance with the DPDP Act and other Applicable Law.
7.1 Role of EduGet360 and Institutions
For most Institution Data relating to students, parents, staff, and other members of an Institution community, the Institution acts as the Data Fiduciary and EduGet360 acts as a Data Processor processing such data on the Institution's documented instructions.
For certain data relating to EduGet360's own business operations, such as sales inquiries, account administration, billing, and platform security, EduGet360 may act as a Data Fiduciary.
7.2 Lawful Processing
Personal Data is processed only where permitted under Applicable Law, including where:
- the Data Principal has given valid consent;
- processing is necessary for the performance of a contract or provision of requested Services;
- processing is necessary for compliance with legal obligations;
- processing is for a legitimate use permitted under the DPDP Act; or
- processing is otherwise permitted by Applicable Law.
7.3 Consent
Where processing is based on consent, the Institution is generally responsible for obtaining, recording, and managing consent from Data Principals, including parents or guardians for children's data.
7.4 Notice
Institutions are responsible for providing appropriate privacy notices to Data Principals. EduGet360 provides this Privacy Policy to describe its own processing activities and technical role.
7.5 Data Protection by Design
EduGet360 implements technical and organizational measures designed to support privacy, tenant isolation, access control, and secure processing across the Platform.
7.6 Cross-Border Transfers
Personal Data may be processed on infrastructure located in India or, where applicable, in other jurisdictions used by subprocessors. Where Personal Data is transferred outside India, EduGet360 takes steps to ensure appropriate safeguards as required by Applicable Law.
8. Data Sharing and Disclosure
EduGet360 does not sell Personal Data. Personal Data may be shared in the following circumstances:
8.1 Within the Institution
Personal Data may be accessible to authorized Users of the subscribing Institution based on role-based permissions configured by the Institution.
8.2 Service Providers and Subprocessors
EduGet360 may engage infrastructure providers, hosting services, email and messaging providers, analytics tools, payment processors, and other subprocessors that process Personal Data on our behalf under contractual safeguards and data processing terms.
8.3 Integrations Enabled by the Institution
Where an Institution enables third-party integrations, Personal Data may be shared with those services according to the Institution's configuration and the third party's terms.
8.4 Legal and Security Requirements
Personal Data may be disclosed where required by Applicable Law, court order, regulatory request, or to protect the rights, safety, and security of EduGet360, Institutions, Users, or others.
8.5 Business Transfers
In connection with a merger, acquisition, restructuring, or sale of assets, Personal Data may be transferred subject to appropriate confidentiality and continuity protections.
8.6 Aggregated or De-identified Data
EduGet360 may use aggregated or de-identified information that does not identify individuals for analytics, service improvement, and reporting.
9. Data Storage and Location
Personal Data processed through the Platform is stored using secure cloud infrastructure and related systems operated by EduGet360 and its authorized service providers.
9.1 Multi-Tenant Architecture
The Platform uses a multi-tenant architecture designed to logically separate Institution Data by tenant. Institutions are assigned isolated environments within the shared Platform infrastructure.
9.2 Storage Location
Unless otherwise agreed in writing, Personal Data is primarily stored and processed in India. Backup, disaster recovery, support, or subprocessors may involve processing in other locations subject to appropriate safeguards.
9.3 Institution Control
Institutions control much of the data entered into the Platform, including what categories of Personal Data are collected, which modules are enabled, and which integrations are activated.
9.4 Availability and Backup
EduGet360 maintains backup and recovery practices intended to support data availability and resilience, subject to the Institution's subscription terms and technical configuration.
10. Security
EduGet360 implements administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include, as appropriate to the Services: encryption in transit and, where applicable, encryption at rest; tenant isolation and role-based access controls; authentication controls, session management, and audit logging; network security, monitoring, and vulnerability management; secure development practices and access restrictions for personnel; and incident detection and response procedures.
No method of transmission or storage is completely secure. While EduGet360 works to protect Personal Data, Institutions and Users also play an important role in maintaining security through strong credentials, device protection, and appropriate access management.
Institutions are responsible for implementing reasonable safeguards within their own environments, as described in Section 18 of this Privacy Policy.
11. Data Retention
EduGet360 retains Personal Data only for as long as necessary to provide the Services, fulfil contractual obligations, comply with Applicable Law, resolve disputes, and enforce agreements.
Retention periods may vary depending on the nature of the Personal Data; the Institution's subscription status and configuration; legal, regulatory, accounting, or educational record-keeping requirements; backup, disaster recovery, and audit log requirements; and documented instructions from the Institution.
Where an Institution's subscription ends, Personal Data may be retained for a limited period to allow export, transition, billing reconciliation, dispute resolution, or legal compliance, after which it may be deleted or anonymized in accordance with the subscription agreement and Applicable Law.
Institutions may request export or deletion of data subject to contractual terms, technical feasibility, and lawful retention requirements.
12. Data Deletion
Personal Data may be deleted or anonymized when it is no longer required for the purposes for which it was processed, when lawfully requested, or when an Institution's subscription is terminated in accordance with applicable contractual terms.
12.1 Institution-Initiated Deletion
Authorized Institution Users may delete or update certain records through the Platform where permissions allow. Institutions may also request bulk deletion or account closure through contractual support channels.
12.2 Processor Deletion
Where EduGet360 acts as a Data Processor, deletion of Institution Data will generally be performed upon the lawful instruction of the Institution or as required by Applicable Law and the applicable subscription agreement.
12.3 Residual Data
Deleted data may persist for a limited period in backups, logs, or disaster recovery systems before being overwritten in the ordinary course of operations.
12.4 Legal Exceptions
Deletion requests may be declined or limited where retention is required for legal compliance, fraud prevention, security investigations, dispute resolution, or protection of the rights of others.
13. Children's Privacy
The Platform is used by educational Institutions to manage information relating to students, including minors.
Student Personal Data is generally processed on behalf of Institutions that act as Data Fiduciaries. Institutions are responsible for determining the lawful basis for processing children's Personal Data; obtaining required parental or guardian consent where applicable; providing appropriate privacy notices to students, parents, and guardians; and configuring the Platform in a manner consistent with educational and child protection obligations.
EduGet360 does not knowingly collect children's Personal Data directly from children for its own independent marketing purposes through the Platform.
Parents, guardians, or eligible students should contact the relevant Institution to exercise privacy rights relating to student records, unless Applicable Law permits direct contact with EduGet360.
15. AI Services
Certain modules of the Platform may include AI-assisted features such as content generation, recommendations, analytics, or workflow assistance.
15.1 Institution Control
AI features may be optional or configurable at the Institution level. Institutions are responsible for determining whether and how AI features are used within their organization.
15.2 Inputs and Outputs
AI features may process prompts, institutional records, or other inputs provided by authorized Users to generate outputs. Institutions and Users should avoid submitting Personal Data into AI features unless necessary and permitted.
15.3 Human Review
AI-generated outputs are provided for assistance only. Institutions remain responsible for reviewing outputs before relying on them for academic, administrative, employment, financial, or disciplinary decisions.
15.4 Limitations
AI outputs may be incomplete, inaccurate, or inappropriate. EduGet360 does not guarantee the accuracy, legality, or suitability of AI-generated content.
15.5 Third-Party AI Providers
Where AI capabilities are delivered through third-party providers, Personal Data may be processed by those providers in accordance with applicable contractual and technical safeguards.
16. Biometric and ADMS Integrations
The Platform may support integration with biometric attendance devices and Attendance Device Management System (ADMS) or similar protocols.
16.1 Nature of Integration
EduGet360 receives attendance events, timestamps, device identifiers, and related metadata transmitted by biometric or attendance devices configured by the Institution. EduGet360 does not directly operate or control biometric hardware.
16.2 Institution Responsibility
Institutions are responsible for device procurement, installation, maintenance, enrollment, legal compliance, notices, consents, and verification of attendance records obtained through biometric systems.
16.3 Data Accuracy Disclaimer
EduGet360 depends on data transmitted by biometric devices and Institution systems. EduGet360 does not control device calibration, enrollment quality, network conditions, or capture accuracy and is not liable for inaccuracies, omissions, duplicates, or delays in biometric attendance data.
16.4 Lawful Use
Institutions must ensure that biometric processing complies with Applicable Law, including any requirements relating to notice, consent, storage limitations, and purpose limitation for biometric information.
16.5 Security
Biometric and attendance data is processed using the Platform's security controls, but Institutions must also secure devices, networks, and local environments connected to such systems.
17. Rights of Data Principals
EduGet360 respects the rights of individuals whose Personal Data is processed through the Platform.
As EduGet360 primarily acts as a Data Processor, most privacy rights are exercised through the respective Institution acting as the Data Fiduciary.
Where required by Applicable Law, EduGet360 will reasonably assist Institutions in fulfilling such requests to the extent they relate to the Services provided.
17.1 Right to Access
Data Principals may have the right to request access to Personal Data processed about them, subject to Applicable Law.
Requests should generally be submitted to the Institution responsible for the collection and management of the Personal Data.
17.2 Right to Correction
Where Personal Data is inaccurate, incomplete, or outdated, Data Principals may request correction through the Institution.
EduGet360 provides technical capabilities that enable authorized users of the Institution to update information where permitted by the Institution's configured permissions.
17.3 Right to Erasure
Where permitted by Applicable Law and subject to applicable retention requirements, Data Principals may request deletion of their Personal Data.
As the Data Processor, EduGet360 will process deletion requests only upon the lawful instruction of the Institution or where otherwise required by Applicable Law.
17.4 Right to Withdraw Consent
Where processing is based upon consent obtained by the Institution, Data Principals may withdraw such consent by contacting the Institution.
Withdrawal of consent may affect the Institution's ability to provide educational or administrative services.
EduGet360 is not responsible for determining the legal consequences of consent withdrawal within the Institution.
17.5 Right to Grievance Redressal
Data Principals may raise concerns regarding the processing of their Personal Data with the Institution.
Where concerns relate specifically to EduGet360's processing activities, users may also contact EduGet360 using the contact information provided in this Privacy Policy.
17.6 Verification of Requests
To protect Personal Data and prevent unauthorized disclosures, EduGet360 and the Institution may require reasonable verification of identity before processing privacy-related requests.
Requests submitted by unauthorized persons may be declined.
17.7 Response Time
EduGet360 will provide reasonable assistance to Institutions in responding to valid privacy requests within commercially reasonable timeframes, subject to:
- technical feasibility;
- Applicable Law;
- contractual obligations;
- identity verification; and
- operational limitations.
17.8 Limitations
Certain requests may be refused or restricted where permitted by Applicable Law, including where processing is necessary for:
- legal compliance;
- fraud prevention;
- security investigations;
- contractual obligations;
- establishment or defense of legal claims;
- protection of the rights of other individuals; or
- other lawful purposes.
17.9 Requests Submitted Directly to EduGet360
Where EduGet360 receives a privacy request directly from a student, parent, guardian, employee, or other Data Principal concerning Institution Data, EduGet360 may:
- redirect the request to the Institution;
- notify the Institution of the request where appropriate;
- request additional verification; or
- respond directly where required by Applicable Law.
As the Institution is the Data Fiduciary, EduGet360 generally cannot modify, delete, or disclose Institution Data without the Institution's authorization.
18. Institution Responsibilities
EduGet360 provides the technical infrastructure necessary to support educational administration. The Institution remains responsible for the lawful and appropriate use of the Platform.
By using EduGet360, each Institution acknowledges and agrees that it is responsible for:
18.1 Compliance
- complying with Applicable Law;
- obtaining all required consents;
- providing legally required privacy notices;
- maintaining internal privacy policies where applicable;
- complying with educational regulations and employment laws.
18.2 Data Quality
The Institution is responsible for ensuring that Personal Data entered into the Platform is:
- accurate;
- complete;
- current;
- relevant;
- lawfully obtained; and
- appropriate for the intended purpose.
18.3 User Management
The Institution is responsible for:
- creating user accounts;
- assigning permissions;
- disabling inactive accounts;
- reviewing access rights;
- protecting administrator accounts;
- preventing unauthorized account sharing.
18.4 Security
The Institution shall implement reasonable administrative and technical safeguards including:
- secure endpoint devices;
- antivirus protection;
- secure local networks;
- staff training;
- password management;
- physical security;
- internal approval processes.
18.5 Biometric Devices
Where biometric attendance systems are used, the Institution remains responsible for:
- device procurement;
- installation;
- maintenance;
- firmware updates;
- biometric enrollment;
- attendance verification;
- network connectivity;
- payroll approvals; and
- compliance with laws governing biometric information.
18.6 AI Usage
Where AI-powered functionality is enabled, the Institution remains responsible for:
- determining acceptable AI use;
- reviewing AI-generated outputs;
- preventing inappropriate disclosure of Personal Data;
- ensuring human review before significant decisions; and
- complying with Applicable Law.
18.7 Third-Party Integrations
The Institution is responsible for evaluating and approving any third-party integrations connected to the Platform, including payment gateways, messaging providers, biometric devices, identity providers, and other external services.
18.8 Responsibility for Decisions
EduGet360 does not make educational, financial, employment, disciplinary, or administrative decisions on behalf of Institutions.
All decisions relating to admissions, attendance approval, examinations, grading, payroll, fees, promotions, disciplinary proceedings, and institutional administration remain solely the responsibility of the Institution.
18.9 Biometric ADMS Data
Where the Platform integrates with biometric attendance devices through ADMS (Attendance Device Management System) or similar protocols, EduGet360 receives and processes attendance data as transmitted by such devices.
EduGet360 does not control device calibration, enrollment quality, or capture accuracy and relies upon data provided by the devices and the Institution. EduGet360 is not liable for inaccuracies, omissions, or delays in biometric attendance data.
19. Changes to this Privacy Policy
EduGet360 may update this Privacy Policy from time to time to reflect changes in:
- Applicable Law;
- Platform functionality;
- security practices;
- technology;
- operational requirements;
- business practices; or
- regulatory guidance.
Where material changes are made, EduGet360 will update the "Last Updated" date and, where required by Applicable Law or contractual obligations, provide appropriate notice to Institutions before such changes become effective.
Continued use of the Platform after the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Privacy Policy to the extent permitted by Applicable Law.
20. Contact Information
Questions regarding this Privacy Policy or EduGet360's privacy practices may be directed to:
EduGet360
- Privacy Team
- [email protected]
- Support Team
- [email protected]
- Legal Team
- [email protected]
- Website
- eduget.in
21. Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and other Applicable Laws, EduGet360 has designated a Grievance Officer to address concerns relating to the processing of Personal Data.
Sai Harshini Chintala
- [email protected]
- Postal Address
- Artifixel Consultancy LLP, 1204, 12th Floor, Geek Space Business Centre, Manjeera Trinity Corporate, JNTU-Hitech City Road, Kukatpally, Hyderabad, Telangana 500072, India
The Grievance Officer will make reasonable efforts to acknowledge and address grievances within the timelines prescribed by Applicable Law.
22. Effective Date
Effective Date: 6 July 2026
Last Updated: 6 July 2026
This Privacy Policy supersedes all previous versions and remains effective until replaced by a subsequent version published by EduGet360.