These terms apply when an institution uses EduSathi to grade answer sheets. They sit with the Terms and Privacy Policy. EduSathi is not a B2C consumer app. This is not a substitute for legal advice; a signed order form or contract can add further instructions.
1. Roles
- Institution (Data Fiduciary) for student names, roll numbers, answer sheets, and marks. The institution decides why that data is uploaded.
- EduSathi (Data Processor) for that student data. We process it only to provide grading, storage, and reports the institution requested.
- For teacher, scanner, and institute-admin login accounts, EduSathi is the Data Fiduciary (see the Privacy Policy).
2. Instructions and purpose
We process student data to run exams the institution creates: store uploaded sheets, send pages to the AI grader over TLS, return marks and reports, and keep backups. We do not sell student data, use it for advertising, or train public models from it as a separate product.
3. Children (DPDP Act Section 9)
School and coaching answer sheets often belong to Data Principals under 18. The institution warrants it has a lawful basis before upload, including verifiable parental or guardian consent where the DPDP Act requires it. EduSathi does not track children for ads and does not serve behavioural advertising.
4. Security
- Public access is HTTPS via Cloudflare. The live MongoDB listens only on loopback, with authentication.
- Google Drive and Gemini traffic uses TLS. SMTP uses STARTTLS.
- Staff access is role-based (institute isolation).
5. Sub-processors
We use these processors to run the service:
- Oracle Cloud — application host
- Cloudflare — TLS, CDN, WAF
- Google Drive — encrypted file storage
- Google Gemini / Vertex AI — grading
- Email SMTP — transactional mail
- MongoDB Atlas — optional off-site backup copy (not the live database)
6. Deletion and access
The institution may ask us to export or erase student data it controls. We also honour DPDP rights through the Grievance Officer listed in the Privacy Policy. Answer sheets are retained as described in that policy unless the institution instructs earlier deletion.
7. Contact
Grievance Officer: Siddhant Gujar — [email protected]