Back to home

Privacy Policy

Last Updated: 19 September 2026

This policy explains what data we collect, why we collect it, and how we protect it when institutions use EduSathi. EduSathi is a B2B platform for schools, colleges, and coaching centres — it is not a consumer (B2C) product. This policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (India) and the DPDP Rules, 2025.

1. Legal Basis for Processing

EduSathi processes staff personal data based on explicit, affirmative consent as required under Section 6 of the Digital Personal Data Protection Act, 2023. Consent is collected at the time of account creation or first login for accounts created by institutional administrators. You may withdraw your consent at any time through your profile settings. Student academic records are processed on the institution's instructions (see 1A).

1A. Roles under the DPDP Act (B2B)

For staff accounts (institute admins, teachers, scanners), EduSathi is the Data Fiduciary. For student answer sheets, names, roll numbers, and marks, the institution is the Data Fiduciary and EduSathi is a Data Processor acting on the institution's documented instructions, as described in our Data Processing terms.

Institutions must have a lawful basis to upload student data (including verifiable parental consent where the Data Principal is a child under 18). EduSathi does not use student data for advertising, profiling for ads, or tracking pixels.

2. Data We Collect

  • Account data: name, email, phone, organisation details.
  • Academic data: answer sheets, exam details, and AI-generated grading outputs.
  • Usage/security logs: IP address, device info, browser user-agent, requests, and authentication events.
  • Consent records: timestamps of consent acceptance, IP at time of consent, consent withdrawal records.
  • Payment records: transaction details and invoices.

We do not store full card details. Payments are handled by third-party payment providers.

3. Purpose of Data Processing

We process your data for the following specific purposes:

  • Account management: To create, maintain, and secure your account.
  • AI-powered grading: To process uploaded answer sheets using AI models for automated evaluation and report generation.
  • Operational communication: To send service-related emails, notifications, and support updates.
  • Security & abuse prevention: To log access events, detect unauthorized usage, and maintain platform integrity.
  • Service improvement: To improve service quality using anonymized, aggregated usage patterns.
  • Legal compliance: To meet obligations under applicable Indian laws and respond to lawful government requests.

4. Data Sharing

We do not sell personal data.

We may share limited data with the following categories of service providers used to operate EduSathi:

  • AI service providers (Google Gemini / Vertex AI): Answer sheet images are sent over TLS for grading. These providers process data under their enterprise terms.
  • File storage (Google Drive API over HTTPS): Encrypted upload of answer-sheet PDFs and related files. Drive is not used as the live database.
  • Cloud infrastructure (Oracle Cloud): Application and the live MongoDB instance run on a private VM. MongoDB is bound to loopback with authentication — it is not open on the internet.
  • Off-site database copy (MongoDB Atlas, optional): Encrypted TLS restore of a backup copy only. The live application does not serve from Atlas.
  • CDN / WAF (Cloudflare): TLS termination and attack filtering. Visitor IPs are visible to Cloudflare as the HTTPS edge.
  • Email (SMTP with STARTTLS): Operational and transactional mail.
  • Payment processors: Card data is not stored by EduSathi.

We may also disclose data if required by law, valid legal process, or order of the Data Protection Board of India.

5. Cross-Border Data Transfer

Some processors (Google Drive, Gemini, optional Atlas backup) may handle data on servers outside India. Transfers are limited to what is needed to run grading, file storage, and disaster recovery, and to territories not restricted by the Central Government under DPDP Act Section 16(1). We do not load Google Fonts or Google Analytics in the browser. A demo video loads YouTube only after you click play.

6. Data Security

  • Public traffic is encrypted with TLS at Cloudflare. Origin MongoDB is not exposed to the internet.
  • Outbound Drive, Gemini, and Atlas backup connections use HTTPS/TLS.
  • SMTP mail is sent with STARTTLS.
  • Authentication uses HttpOnly secure cookies to prevent token theft.
  • Passwords are hashed using bcrypt with salt rounds.
  • Access controls enforce role-based separation between institute admins, teachers, and super admins.
  • We implement rate limiting, IP-based blocking, and audit logging for security events.

7. Data Retention

  • Account data: Kept while account is active; deleted within 30 days of a verified erasure request.
  • Answer sheets: Retained for up to 180 days after grading, then permanently removed.
  • Security/access logs: Retained for up to 90 days for auditing and incident response (CERT-In directions may require longer retention during an investigation).
  • Consent records: Retained indefinitely as legal proof of consent under the DPDP Act.
  • Tax/payment records: Retained as required by Indian tax and financial regulations.

8. Your Rights Under the DPDP Act

As a Data Principal under the DPDP Act, 2023, you have the following rights:

  • Right to Access: Request a summary of your personal data and how it is being processed.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to Withdraw Consent: Withdraw your consent at any time through your profile's "Account & Data" section. Withdrawal does not affect the lawfulness of processing done before withdrawal.
  • Right to Nominate: Nominate another person to exercise your rights in the event of your death or incapacity.
  • Right to Grievance Redressal: File a complaint with our Grievance Officer (details below). If unresolved within 30 days, you may escalate to the Data Protection Board of India.

To exercise these rights, use the "Account & Data" section in your profile, or email us at [email protected].

9. Consent Withdrawal

You may withdraw your consent at any time by navigating to Profile → Account & Data → Withdraw Consent. Upon withdrawal, you will be logged out and will not be able to access the platform until you re-consent. Your data will be reviewed for deletion within 30 days. You may also email your withdrawal request to [email protected].

9A. Cookies and browser requests

We set an essential session cookie to keep you signed in. We do not use Google Analytics, advertising cookies, or Google Fonts from Google's servers (fonts are hosted on EduSathi). Cloudflare may set strictly necessary edge cookies for HTTPS and bot management.

10. Updates to This Policy

We may revise this policy from time to time and publish the updated version on this page. Material changes will be communicated via email or in-app notification.

11. Grievance Officer

In accordance with Section 8(10) of the DPDP Act, 2023:

Name: Siddhant Gujar

Email: [email protected]

Phone: 8262969088

Office Hours: 10 AM-6 PM IST, Monday-Friday

Response target: 5 business days (max 30 days as per DPDP Act)

12. Escalation to Data Protection Board

If your grievance is not resolved by our Grievance Officer within 30 days, you may file a complaint with the Data Protection Board of India through the official portal: www.dpbi.gov.in or the grievance filing portal at dpdpa-grievance.gov.in.

13. Contact

Email: [email protected]