App Store & Play Store Verified

Vidyasetu Legal & Privacy Center

Publicly accessible compliance documentation ensuring transparent data governance, student privacy protection, and adherence to international mobile application store laws.

Data Deletion PolicyPrivacy PolicyTerms & Conditions
Privacy & Data Governance

Vidyasetu ERP Privacy Policy

Effective Date: January 1, 2026 | Last Updated: Current Academic Session. This document explains how educational data is gathered, protected, and processed across web and mobile platforms.

1. Information We Collect & Institutional Data Controller Role

General Clause

Vidyasetu operates strictly as an Enterprise Resource Planning (ERP) technology processor for educational institutions. All data gathered is commissioned directly by your registered school or college administration.

Specific Policy Bullet Points

Student Demographic Records: Names, enrollment numbers, grade levels, academic sections, date of birth, and official photographs provided during school admission.
Guardian Contact Information: Primary phone numbers, email addresses, and residential communications coordinates required for emergency broadcasting and SMS circulars.
Academic Activity Data: Daily classroom attendance markings, examination homework submissions, report cards, and fee structure alignments.
Staff Credentials: Faculty qualifications, class schedule assignments, and institutional payroll identifiers.

2. Financial Transactions & Cashfree Gateway Integration

Security Clause

To enable seamless digital fee collections, Vidyasetu integrates with Reserve Bank of India (RBI) compliant payment gateways, primarily Cashfree Payments.

Specific Policy Bullet Points

Zero Card Storage: Vidyasetu servers never capture, store, or log sensitive debit card numbers, credit card CVVs, or UPI PIN credentials.
Encrypted Processing: All payment sessions are initiated over TLS 1.3 encrypted webhooks directly between the parent's device and the banking gateway provider.
Transaction Audit Trails: We retain order IDs, transaction timestamps, receipt numbers, and settlement statuses solely to update academic fee ledgers and issue official student tax receipts.

3. Adherence to COPPA, FERPA & DPDP Act 2023

Legal Clause

Our compliance architecture is engineered to satisfy strict national and international data privacy statutes governing minors and educational records.

Specific Policy Bullet Points

DPDP Act India Compliance: Explicit verifiable parental consent is established via institutional onboarding before any minor's data is processed within the ERP application.
FERPA Alignment: Educational records are disclosed exclusively to authorized school personnel and guardians. Students maintain the right to inspect academic records through their portal.
COPPA Protection: We do not track children across third-party apps or websites, nor do we serve behavioral advertisements to any student account.

4. Mobile Application Device Permissions Justification

Permissions Clause

Per Google Play Store and Apple App Store transparency laws, our Android and iOS applications request specific hardware permissions strictly for essential academic features:

Specific Policy Bullet Points

Camera Access: Required solely for students to scan QR code homework assignments or upload photos of handwritten exam answer sheets.
Storage / Media Access: Required to download PDF report cards, syllabus brochures, and fee receipts to the user's local device storage.
Push Notifications (FCM/APNS): Mandated for delivering real-time emergency school closure alerts, attendance absentees SMS triggers, and exam timetable alerts.
No Location Tracking: Vidyasetu does not request continuous background GPS location tracking for standard student or parent profiles.

5. Data Sharing & Third-Party Non-Disclosure

Security Clause

We enforce strict data isolation protocols across our cloud clusters to ensure your institution's repository remains completely insulated.

Specific Policy Bullet Points

Zero Commercial Sale: Under no circumstances is institutional or student data leased, sold, or shared with marketing agencies, advertisers, or external data brokers.
Cloud Infrastructure Security: Data at rest is encrypted using AES-256 standards across enterprise cloud vaults with automated disaster recovery backups.
Government Compliance: Data disclosures occur only when formally mandated by judicial subpoenas or educational ministry statutory audits.

Have Questions About Institutional Privacy?

In accordance with the Information Technology Act 2000 and DPDP Rules, inquiries regarding student data records should first be addressed to your school principal or ERP desk. For platform-level security inquiries, reach out to our Chief Compliance Officer.