1. Privacy
Legal Document / Privacy

Privacy Policy

Last Updated: April 20, 2026

Effective Date: April 20, 2026

How Classgrid collects, processes, and protects user and student data.

Introduction

01

WHAT THIS POLICY COVERS

Last Updated: April 20, 2026

This Privacy Policy covers the treatment of personally identifiable information ("Personal Information") and other data that the Company gathers when You access, use, or interact with the Platform. This Policy covers the following:

  • Classgrid Website — classgrid.in (the marketing and information website)
  • Tenant Websites — Institutional websites hosted on sub-domains (e.g., collegename.classgrid.in)
  • Classgrid ERP — The school/college management system including dashboards for Super Admins, Org Admins, Faculty, Students, and Parents
  • Classgrid Mobile Application — The Android and iOS applications available on Google Play Store and Apple App Store
  • Classgrid APIs — Backend services used to power all of the above

This Policy does not apply to the practices of third-party companies that the Company does not own or control, or to individuals that the Company does not employ or manage. The Company is not responsible for the privacy practices of third-party websites, applications, or services linked from Our Platform.

02

DEFINITIONS

Last Updated: April 20, 2026

For the purpose of this Privacy Policy:

  • "User" / "You" / "Your" — Any person who accesses or uses the Platform in any capacity, including Students, Parents/Guardians, Faculty Members, Institutional Administrators, and Visitors.
  • "Student" — An individual enrolled in an educational institution that uses the Platform.
  • "Parent/Guardian" — A parent or legal guardian of a Student, who may access the Platform on behalf of or in relation to the Student.
  • "Faculty" — A teacher, professor, lecturer, or other educational staff member employed by a Tenant Organization.
  • "Org Admin" / "Institutional Administrator" — An authorized representative of a Tenant Organization who manages the institution's account on the Platform.
  • "Super Admin" — An employee or authorized agent of the Company who manages the Platform at the highest level.
  • "Tenant Organization" — An educational institution (school, junior college, coaching institute) that has subscribed to and uses the Platform.
  • "Personal Information" — Any information that relates to an identified or identifiable natural person.
  • "Sensitive Personal Data" — Personal data including financial information, health data, biometric data, passwords, and any data relating to minors, as defined under applicable Indian law.
  • "Data Fiduciary" — The entity that determines the purpose and means of processing personal data. In the context of institutional data, the Tenant Organization is the Data Fiduciary. For Platform-level data, the Company is the Data Fiduciary.
  • "Data Processor" — The entity that processes personal data on behalf of the Data Fiduciary. The Company acts as a Data Processor for institutional data.
  • "Platform" — Collectively refers to the Website, App, ERP, Tenant Websites, and APIs operated by the Company.

03

INFORMATION WE COLLECT

Last Updated: April 20, 2026

We collect the following categories of information depending on Your role and usage of the Platform:

3.1 Information Provided by Institutional Administrators (Org Admins)

When an institution onboards onto Classgrid, the Org Admin provides:

  • Institutional Information: Institution name, type (school/junior college/coaching), address, contact details, affiliation details, trust/society details, logo, branding assets, accreditation information
  • Admin Account Information: Full name, email address, phone number, designation, profile photo
  • Faculty Data: Names, designations, departments, subjects, qualifications, profile photos, contact information of faculty members
  • Student Data: Names, enrollment numbers, class/section, date of birth, gender, parent/guardian information, address, contact details, academic records, attendance records, fee records
  • Parent/Guardian Data: Names, contact numbers, email addresses, relationship to student, occupation, address
  • Academic Content: Notices, circulars, academic calendars, syllabi, examination details, merit lists, fee structures, timetables
  • Website Content: Hero images/videos, gallery photos, blog posts, event details, testimonials, alumni data, mandatory disclosures, committee information, infrastructure details
  • Financial Data: Fee structures, payment records, scholarship information, installment plans

3.2 Information Provided by Students

When Students use the Platform:

  • Account Information: Name, email address, phone number, date of birth, gender, profile photo
  • Academic Information: Class/section/batch, enrollment number, academic performance data, assignment submissions, attendance records
  • Communication Data: Messages sent through the Platform's communication features, feedback, and queries
  • Device Information: Device type, operating system, app version (when using the mobile app)

3.3 Information Provided by Parents/Guardians

When Parents/Guardians use the Platform:

  • Account Information: Name, email address, phone number, relationship to student
  • Communication Data: Messages, feedback, queries sent through the Platform
  • Device Information: Device type, operating system, app version (when using the mobile app)

3.4 Information Provided by Faculty Members

When Faculty Members use the Platform:

  • Account Information: Name, email address, phone number, designation, department, qualifications, profile photo
  • Professional Information: Subject expertise, teaching schedule, attendance records
  • Content Created: Assignments, study materials, grades entered, attendance marked, feedback given
  • Device Information: Device type, operating system, app version (when using the mobile app)

3.5 Information Collected Automatically

When You use the Platform, We may automatically collect:

  • Log Data: IP address, browser type and version, operating system, referring/exit pages, date/time stamps, clickstream data
  • Device Information: Device model, unique device identifiers, mobile network information, operating system version, app version
  • Usage Data: Pages visited, features used, time spent on pages, navigation patterns, search queries on the Platform
  • Location Data: General geographic location based on IP address (We do not collect precise GPS location unless explicitly required and consented to)
  • Error and Crash Data: Application crash logs, error reports, performance data to improve Platform stability

3.6 Information from Third-Party Authentication

When You sign in using third-party authentication services (such as Google Sign-In):

  • Google Account Information: Name, email address, profile picture, unique Google identifier
  • We only access the minimum information necessary for authentication. We do not access Your Google contacts, Google Drive files, Gmail messages, or any other Google services data beyond what is required for sign-in.

3.7 Information We Do NOT Collect

We want to be clear about what We do not collect:

  • Biometric data (fingerprints, facial recognition data)
  • Health or medical records (unless explicitly provided by the institution as part of student records)
  • Caste, religion, or political affiliation
  • We do not store financial information such as bank account numbers or credit/debit card details. Payments are securely processed by third-party payment processors (Razorpay). Card and banking information is handled entirely by the payment processor and never touches Our servers.
  • Precise real-time GPS location data (unless explicitly consented to for specific features)
  • Contacts from Your phone's address book
  • Call logs or SMS messages
  • Photos or files from Your device storage (unless You explicitly upload them)

04

HOW WE COLLECT INFORMATION

Last Updated: April 20, 2026

We collect information through the following methods:

4.1 Direct Collection

  • When You create an account or register on the Platform
  • When an Org Admin enters institutional data, student records, or faculty information
  • When You fill out forms, upload documents, or submit content
  • When You communicate with Us or other Users through the Platform
  • When You contact Our support team

4.2 Automated Collection

  • Through server logs when You access the Platform
  • Through the mobile application's standard operating system interfaces
  • Through error and crash reporting tools integrated into the Platform

4.3 Third-Party Collection

  • From Google Sign-In when You choose to authenticate using Your Google account
  • From institutions when they onboard student and faculty data onto the Platform
  • From publicly available sources for institutional information (e.g., affiliation codes, NAAC grades)

05

PURPOSE OF DATA COLLECTION

Last Updated: April 20, 2026

We collect and use Your information for the following specific purposes:

5.1 Core Platform Services

  • To provide, operate, and maintain the Classgrid ERP Platform
  • To create and manage User accounts across all roles (Student, Parent, Faculty, Org Admin)
  • To enable institutional management features including attendance tracking, grade management, timetable scheduling, fee management, and communication
  • To generate and host institutional tenant websites on sub-domains
  • To enable academic management features including assignment distribution, submission tracking, and performance analytics
  • To facilitate communication between institutions, faculty, students, and parents

5.2 Authentication and Security

  • To verify Your identity during sign-in and account access
  • To prevent unauthorized access to accounts and institutional data
  • To detect, prevent, and respond to fraud, abuse, and security incidents
  • To maintain audit trails of data access and modifications

5.3 Communication

  • To send You important notices, updates, and announcements from Your institution
  • To send Platform-related communications including service updates, maintenance notifications, and security alerts
  • To respond to Your inquiries, feedback, and support requests
  • To send transactional notifications (e.g., fee payment confirmations, assignment deadlines)

5.4 Platform Improvement

  • To analyze usage patterns and improve Platform features, performance, and user experience
  • To diagnose technical problems, debug errors, and monitor Platform health
  • To conduct internal research and development for new features
  • To generate aggregated, anonymized analytics and insights (never identifying individual Users)

5.5 Legal Compliance

  • To comply with applicable laws, regulations, and legal processes
  • To respond to lawful requests from government authorities
  • To enforce Our Terms of Use, Disclaimer, and other policies
  • To protect the rights, property, and safety of the Company, Our Users, and the public

5.6 Institutional Compliance

  • To assist Tenant Organizations in meeting regulatory requirements (NAAC, AICTE, State Boards)
  • To generate mandatory disclosure reports as required by educational governing bodies
  • To maintain records as required by educational regulations

06

INFORMATION SHARING AND DISCLOSURE

Last Updated: April 20, 2026

We take the privacy of Your information seriously. We do not sell, rent, or trade Your personal information to any third party for their commercial purposes.

We may share Your information only in the following circumstances:

6.1 Within the Institutional Context

  • Student data is accessible to the Tenant Organization's authorized administrators and relevant faculty members
  • Parent/Guardian data is accessible to the Tenant Organization for communication purposes
  • Faculty data is accessible to the Tenant Organization's administrators
  • Data shared within an institution is governed by the institution's own data handling policies in addition to this Privacy Policy

6.2 With Service Providers (Data Processors)

We engage trusted third-party service providers who assist Us in operating the Platform. These providers are contractually bound to use Your data only for the services they provide to Us and are required to maintain appropriate security measures:

Service ProviderPurposeData Shared
MongoDB AtlasPrimary ERP Database hostingEncrypted institutional and user data
Supabase (AWS S3)File and Media storage (images, PDFs, videos)Uploaded media files and documents
Google Cloud PlatformAPI Management, OAuth, and Firebase NotificationsAuthentication tokens, API usage logs
VercelFrontend Website and ERP hostingWebsite content and visitor logs
YouTube (Google)Video embedding on tenant websitesNo user data shared — public embeds only
RazorpayPayment processingFee payment transactions (card/UPI/netbanking details handled entirely by Razorpay)

6.3 For Legal Reasons

We may disclose Your information if required to do so by law, or if We believe in good faith that such action is necessary to:

  • Comply with a legal obligation, court order, or legal process
  • Protect and defend the rights or property of the Company
  • Prevent fraud or investigate potential violations of Our terms
  • Protect the personal safety of Users or the public
  • Comply with directions issued by any government authority under applicable Indian law

6.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of Our assets, Your personal information may be transferred as part of that transaction. We will notify You via email and/or a prominent notice on the Platform of any change in ownership or uses of Your personal information.

6.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, and de-identified data that cannot reasonably be used to identify You. This data may be used for industry analysis, demographic profiling, research, and other purposes. For example: "85% of institutions using Classgrid report improved attendance tracking efficiency."

6.6 With Your Consent

We may share Your information with third parties when You have explicitly consented to such sharing.

6.7 Tenant Website Public Data

Content that a Tenant Organization publishes on their tenant website (faculty profiles marked public, gallery photos, notices, events, blog posts, testimonials) is publicly accessible by design. The Tenant Organization controls what content is made public through their CMS dashboard.

07

DATA STORAGE AND SECURITY

Last Updated: April 20, 2026

7.1 Storage Location

Your data is stored on secure servers provided by:

  • MongoDB Atlas — Primary cloud database with encryption at rest and in transit
  • AWS (via Supabase) — Media file storage with access-controlled buckets
  • Google Cloud Platform — Authentication services, API management, and Push Notifications (Firebase)

Our primary data storage servers are located in regions compliant with applicable data protection laws. We ensure that all data storage providers maintain industry-standard security certifications.

7.2 Security Measures

We implement the following technical and organizational security measures to protect Your data:

Technical Measures:

  • Encryption of data in transit using TLS 1.2+ (HTTPS)
  • Encryption of data at rest in Our databases
  • Secure password hashing using industry-standard algorithms (bcrypt)
  • JWT (JSON Web Token) based authentication with token expiration
  • Role-based access control (RBAC) ensuring Users can only access data relevant to their role
  • API rate limiting to prevent abuse
  • Regular security patches and dependency updates
  • Automated backup systems with encrypted backups
  • Firewall protection and DDoS mitigation

Organizational Measures:

  • Access to production data is limited to authorized personnel only
  • All Company employees and contractors are bound by confidentiality agreements
  • Regular security awareness training for team members
  • Incident response procedures for data breach scenarios
  • Periodic security audits and vulnerability assessments

7.3 Security Limitations

While We strive to use commercially acceptable means to protect Your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of Your data. In the event of a data breach, We will notify affected Users and relevant authorities as required by applicable law.

08

DATA RETENTION

Last Updated: April 20, 2026

8.1 Retention Periods

Data TypeRetention PeriodReason
Active User AccountsDuration of account existenceRequired for service delivery
Student Academic RecordsDuration of enrollment + 5 years after graduation/leavingEducational record-keeping requirements
Institutional DataDuration of subscription + 1 year after subscription endsTransition and data export period
Server Logs90 daysSecurity monitoring and debugging
Error/Crash Reports90 daysPlatform stability improvement
Communication RecordsDuration of account existenceService continuity
Payment Transaction Records7 years after transactionTax and financial compliance (Indian law)
Backup Data30 days (rolling backups)Disaster recovery

8.2 Data After Account Deletion

When a User account is deleted:

  • Personal information is removed from active databases within 30 days
  • Data may persist in encrypted backups for up to 30 additional days before being permanently purged
  • Aggregated and anonymized data derived from Your usage may be retained indefinitely as it cannot identify You
  • Data required to be retained for legal compliance will be retained for the mandatory period

8.3 Institutional Data After Subscription Ends

When a Tenant Organization's subscription ends:

  • Institutional data is retained for 1 year to allow for reactivation or data export
  • After 1 year, all institutional data including student records, faculty data, and website content is permanently deleted
  • The institution's tenant website is taken offline immediately upon subscription termination
  • The Org Admin will be notified at 30-day intervals during the retention period

09

CHILDREN'S PRIVACY

Last Updated: April 20, 2026

9.1 Our Commitment to Children's Privacy

The Platform is used by educational institutions that serve minors (children under the age of 18). We are committed to protecting the privacy of children and comply with all applicable laws regarding children's data.

9.2 Parental/Guardian Consent

  • Student accounts for minors (below 18 years of age) are created by the Tenant Organization (school/college) with the understanding that the institution has obtained appropriate parental/guardian consent as part of their enrollment and admission process
  • The Company relies on the Tenant Organization to obtain and maintain valid parental/guardian consent for the collection and processing of minor students' data
  • Parents/Guardians may request access to, correction of, or deletion of their child's data through the Tenant Organization or by contacting Us directly

9.3 Limited Data Collection for Minors

For minor students, We ensure that:

  • Only data necessary for educational purposes is collected
  • No behavioral advertising or profiling is conducted on minor students' data
  • No data of minor students is sold or shared with third parties for commercial purposes
  • AI features processing minor students' data are limited to educational analytics only
  • The mobile app does not request permissions beyond what is necessary for core educational features

9.4 Institutional Responsibility

Tenant Organizations (schools and junior colleges) that enroll minor students are responsible for:

  • Obtaining appropriate parental/guardian consent before entering minor students' data
  • Ensuring that faculty and staff handle student data in accordance with this Privacy Policy
  • Informing parents/guardians about the use of the Platform and this Privacy Policy
  • Responding to parental requests regarding their children's data in a timely manner

9.5 Verifiable Parental Consent (DPDP Act Compliance)

Under the Digital Personal Data Protection Act, 2023, processing of children's personal data requires verifiable consent from the parent or lawful guardian. We implement the following:

  • Tenant Organizations must confirm during onboarding that they have obtained parental consent
  • The Platform provides mechanisms for parents to view and manage their child's data
  • Parents can contact the Grievance Officer to exercise their rights regarding their child's data

10

INSTITUTIONAL DATA AND TENANT WEBSITES

Last Updated: April 20, 2026

10.1 Data Fiduciary Relationships

  • For Institutional/Student Data: The Tenant Organization is the "Data Fiduciary" and the Company is the "Data Processor." The institution determines what data is collected and how it is used within the Platform.
  • For Platform Usage Data: The Company is the "Data Fiduciary" and processes usage data for Platform improvement purposes.

10.2 Tenant Website Data

  • Tenant Organizations manage their own websites through the Classgrid CMS
  • Content published on tenant websites (notices, faculty profiles, gallery, events, blog posts, testimonials, mandatory disclosures, committee details, infrastructure information) is controlled entirely by the Tenant Organization
  • The Company does not edit, moderate, or take responsibility for content published by Tenant Organizations
  • Publicly accessible content on tenant websites may be indexed by search engines

10.3 Data Isolation

  • Each Tenant Organization's data is logically isolated from other Tenant Organizations
  • No institution can access another institution's data
  • Super Admins (Company employees) can access institutional data only for Platform support, maintenance, and troubleshooting purposes, subject to strict access controls and audit logging

10.4 Institutional Data Export

  • Tenant Organizations may request export of their institutional data in standard formats (CSV, PDF, JSON)
  • Data export requests can be made through the Org Admin dashboard or by contacting Our support team
  • We will fulfill data export requests within 30 days of receiving the request

11

MOBILE APPLICATION PERMISSIONS

Last Updated: April 20, 2026

The Classgrid Mobile Application requests the following permissions on Your device. Each permission is explained with its specific purpose:

11.1 Android Permissions

PermissionPurposeRequired/Optional
Internet (INTERNET)Required for all Platform functionality — data sync, authentication, content loadingRequired
Network State (ACCESS_NETWORK_STATE)To detect network availability and show offline indicatorsRequired
Camera (CAMERA)To scan QR codes for attendance, capture profile photos, and upload assignment imagesOptional — requested only when You use camera features
Read/Write Storage (READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE)To download and save documents (PDFs, circulars, assignments) and upload filesOptional — requested only when You download or upload files
Notifications (POST_NOTIFICATIONS)To receive push notifications about notices, assignments, attendance alerts, and institutional announcementsOptional — You can disable notifications in device settings
Vibrate (VIBRATE)To provide haptic feedback for notificationsRequired

11.2 iOS Permissions

PermissionPurposeRequired/Optional
CameraTo scan QR codes for attendance, capture profile photosOptional
Photo LibraryTo select and upload images for profiles, assignments, and galleryOptional
NotificationsTo receive push notificationsOptional
Face ID / Touch IDFor biometric app lock (if enabled by User)Optional

11.3 Permission Principles

  • We follow the principle of least privilege — We only request permissions that are necessary for the specific feature You are using
  • Permissions are requested at the time of use, not during app installation
  • You can revoke any optional permission at any time through Your device's Settings without affecting other Platform functionality
  • The App will continue to function with reduced functionality if optional permissions are denied
  • We do not access Your contacts, call logs, SMS messages, or any data beyond the stated permissions

12

THIRD-PARTY SERVICES AND INTEGRATIONS

Last Updated: April 20, 2026

The Platform integrates with the following third-party services. Each service has its own privacy policy, and We encourage You to review them:

12.1 Authentication Services

  • Google Sign-In: Used for secure authentication. When You sign in with Google, We receive Your name, email address, and profile picture. We use Google's OAuth 2.0 protocol and comply with Google's API Services User Data Policy. Google Privacy Policy

12.2 Cloud Infrastructure

  • MongoDB Atlas: Used for database hosting. All data is encrypted at rest and in transit. MongoDB Privacy Policy
  • Google Cloud Platform: Used for cloud infrastructure, computing, and authentication services. Google Cloud Privacy Notice
  • Vercel: Used for hosting the marketing website and tenant websites. Vercel Privacy Policy

12.3 File Storage

  • Supabase: Used for storing uploaded files including images, PDFs, documents, and short video clips. Files are stored in access-controlled storage buckets. Supabase Privacy Policy

12.4 Content Embedding

  • YouTube (Google): Tenant websites may embed YouTube videos for gallery and lecture content. YouTube's privacy-enhanced mode is used where possible. No user tracking data is shared with YouTube beyond standard embed functionality. YouTube Terms of Service
  • Google Maps: Tenant websites may embed Google Maps for location display. No user data is shared with Google Maps beyond standard embed functionality. Google Maps Terms

12.5 Analytics and Monitoring

  • We may use anonymized, aggregated analytics tools to monitor Platform performance and usage patterns
  • No personally identifiable information is shared with analytics providers
  • We do not use any third-party advertising networks or targeted advertising on the Platform

12.6 Push Notification Services

  • Firebase Cloud Messaging (FCM): Used for sending push notifications to Android and iOS devices. Only device tokens and notification content are shared with Firebase. Firebase Privacy

13

GOOGLE API SERVICES AND CLOUD PLATFORM

Last Updated: April 20, 2026

13.1 Google API Services User Data Policy Compliance

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only request access to the Google API scopes that are necessary for the Platform's functionality (email, profile)
  • We do not use Google User data for serving advertisements
  • We do not transfer Google User data to third parties unless necessary for Platform functionality, required by law, or with explicit User consent
  • We do not use Google User data for any purpose other than providing and improving the Platform's user-facing features
  • Our application complies with Google's OAuth 2.0 policies

13.2 Google Cloud Console

  • The Platform uses Google Cloud Console for managing cloud infrastructure, API keys, and authentication services
  • All access to Google Cloud Console is restricted to authorized Company personnel
  • API keys and service account credentials are securely stored and never exposed in client-side code
  • We comply with Google Cloud Platform Terms of Service and Acceptable Use Policy
  • Data processed through Google Cloud services is handled in accordance with Google's Data Processing Terms

13.3 Google Play Store Compliance

The Classgrid mobile application published on Google Play Store complies with:

  • Google Play Developer Distribution Agreement
  • Google Play Developer Program Policies
  • Families Policy (for apps accessed by children)
  • Data Safety section requirements (accurately declaring data collection and sharing practices)
  • User Data policy (prominently disclosing data collection and usage)
  • Permissions policy (requesting only necessary permissions)

13.4 Data Safety Declaration (Google Play)

As displayed in Our Google Play Store listing, We declare:

Data TypeCollectedSharedPurpose
NameYesNoAccount management, institutional records
EmailYesNoAuthentication, communication
Phone NumberYesNoAccount verification, institutional communication
Profile PhotoYesNoUser profile display
Academic RecordsYesNo*Core educational service
App ActivityYesNoPlatform improvement, debugging
Crash LogsYesNoPlatform stability
Device IdentifiersYesNoPush notifications

*Academic records are shared within the institutional context (between the institution, its faculty, and the respective student/parent) as part of core Platform functionality.

14

AI-POWERED FEATURES AND DATA PROCESSING

Last Updated: April 20, 2026

14.1 AI Features Overview

The Platform may include AI-powered features such as:

  • Past paper analysis and question pattern recognition
  • Academic performance analytics and trend insights
  • Automated report generation
  • Smart suggestions for academic improvement

14.2 Data Used for AI Processing

  • AI features process academic data (questions, marks, attendance patterns, performance records) within the institutional context
  • AI processing is performed for the benefit of the Tenant Organization and its Users
  • No personal identification data (names, photos, contact details) is used for AI model training
  • AI features use anonymized and aggregated data patterns only

14.3 AI Limitations and Transparency

  • All AI-generated outputs are advisory in nature and should not replace professional academic judgment
  • AI features do not make automated decisions that produce legal or similarly significant effects on Users
  • The Company does not use User data to train general-purpose AI models
  • AI processing is conducted on secure infrastructure with the same security measures applied to all Platform data

14.4 Children's Data and AI

  • AI features do not profile minor students for behavioral or advertising purposes
  • AI processing of minor students' data is limited to educational analytics within the institutional context
  • Parents/Guardians may opt out of AI-powered features for their child by contacting the Tenant Organization or Our Grievance Officer

15

ACCESSING, UPDATING, AND DELETING YOUR INFORMATION

Last Updated: April 20, 2026

15.1 Access and Update

  • Students, Parents, Faculty: You can access and update Your profile information through the Platform's profile settings in the Web dashboard or Mobile App
  • Org Admins: You can access, update, and manage institutional data, student records, faculty records, and website content through the Org Admin dashboard
  • All Users: You may request a copy of Your personal data by contacting Us at the email address provided in this Policy

15.2 Deletion

  • Account Deletion: You may request deletion of Your account by contacting Your Tenant Organization's Org Admin or by emailing Us directly. Account deletion requests will be fulfilled within 30 days.
  • Data Deletion Within the Institution: Students and Parents must route data deletion requests through their Tenant Organization, as the institution is the Data Fiduciary for institutional data.
  • Right to Be Forgotten: You may request erasure of Your personal data, subject to legal retention requirements. We will delete Your data unless We are required by law to retain it.

15.3 Data Portability

  • You may request export of Your personal data in a structured, commonly used, machine-readable format (CSV, PDF, JSON)
  • Data portability requests will be fulfilled within 30 days

15.4 Correction of Inaccurate Data

  • You have the right to request correction of inaccurate or incomplete personal data
  • Correction requests can be made through the Platform's settings or by contacting Us directly

16

DATA SUBJECT RIGHTS UNDER DPDP ACT 2023

Last Updated: April 20, 2026

Under the Digital Personal Data Protection Act, 2023, You have the following rights as a Data Principal:

16.1 Right to Access

You have the right to obtain a summary of Your personal data being processed and the processing activities undertaken with respect to such data.

16.2 Right to Correction and Erasure

You have the right to:

  • Correct inaccurate or misleading personal data
  • Complete incomplete personal data
  • Update Your personal data
  • Erase Your personal data (subject to certain conditions and legal retention requirements)

16.3 Right to Grievance Redressal

You have the right to register grievances with the Company's Grievance Officer regarding the processing of Your personal data. The Grievance Officer's details are provided in Section 21 of this Policy.

16.4 Right to Nominate

You have the right to nominate another individual who can exercise Your rights under the DPDP Act in the event of Your death or incapacity.

16.5 Duties of Data Principal

As a Data Principal under the DPDP Act, You are expected to:

  • Provide accurate and complete personal data
  • Not impersonate another person while providing data
  • Not suppress any material information while providing data
  • Not register a false or frivolous grievance or complaint
  • Comply with applicable laws while exercising Your rights

17

CROSS-BORDER DATA TRANSFERS

Last Updated: April 20, 2026

17.1 Primary Storage

Your personal data is primarily stored and processed in data centers located in regions with adequate data protection standards, as determined by Our cloud infrastructure providers (MongoDB Atlas, Google Cloud Platform, Supabase).

17.2 Transfer Safeguards

In the event that Your data is transferred to servers outside India:

  • We ensure that such transfers are made to jurisdictions that provide an adequate level of data protection
  • We implement appropriate contractual safeguards (Standard Contractual Clauses) with Our service providers
  • We comply with the DPDP Act's provisions regarding cross-border data transfers
  • Your data will not be transferred to jurisdictions restricted by the Central Government under the DPDP Act

18

CONFIDENTIALITY AND SECURITY MEASURES

Last Updated: April 20, 2026

18.1 Organizational Security

  • All Company personnel with access to User data are bound by strict confidentiality agreements
  • Access to production databases and systems is restricted based on the principle of least privilege
  • All access to sensitive data is logged and auditable
  • Regular security training is conducted for all team members

18.2 Technical Security

  • All data transmission is encrypted using TLS 1.2 or higher
  • Passwords are hashed using bcrypt with appropriate salt rounds
  • Authentication tokens (JWT) have expiration times and are refreshed securely
  • Role-based access control (RBAC) is enforced at the API level
  • Input validation and sanitization to prevent injection attacks
  • Regular dependency audits to patch known vulnerabilities
  • Automated and manual security testing

18.3 Incident Response

In the event of a data breach or security incident:

  • We will investigate the incident immediately and take steps to contain and remediate it
  • We will notify affected Users within 72 hours of becoming aware of the breach
  • We will notify the Data Protection Board of India as required under the DPDP Act
  • We will provide guidance to affected Users on steps they can take to protect themselves
  • We will document the incident and implement measures to prevent future occurrences

19

USER DISCRETION AND CONSENT

Last Updated: April 20, 2026

19.1 Consent

By using the Platform, You consent to the collection, use, storage, and disclosure of Your personal information as described in this Privacy Policy. If You are using the Platform on behalf of a Tenant Organization, You represent and warrant that You have the authority to consent to this Privacy Policy on behalf of the organization and its Users.

19.2 Withdrawal of Consent

You may withdraw Your consent at any time by:

  • Deleting Your account through the Platform settings
  • Contacting Us at the email address provided in this Policy
  • Contacting the Grievance Officer

Please note that withdrawal of consent may result in the inability to use certain or all features of the Platform. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

19.3 Your Discretion

You acknowledge that all personal information provided by You is of Your own free will. You understand that the Company may be required to collect certain information by law or for the provision of Platform services. Any information that You provide to Us that is inaccurate or incomplete may affect the quality of services We can provide.

20

CHANGES TO THIS PRIVACY POLICY

Last Updated: April 20, 2026

20.1 Modifications

We reserve the right to update or modify this Privacy Policy at any time. When We make material changes, We will:

  • Update the "Last Updated" date at the top of this Policy
  • Notify Users via email and/or in-app notification about significant changes
  • Provide a summary of key changes
  • Post the revised Policy on the Platform

20.2 Continued Use

Your continued use of the Platform after any changes to this Privacy Policy constitutes Your acceptance of the updated Policy. If You do not agree with the changes, You should discontinue use of the Platform and request deletion of Your data.

20.3 Version History

We maintain a version history of this Privacy Policy. Previous versions may be requested by contacting Us at the email address provided below.

Need legal help?

Contact our team for policy, security, or compliance clarifications.

Contact Support

Ask AI

Ask about Classgrid, Classgrid features, pricing, demos, or support.