Last updated: July 19, 2026
EduPrime AI("we," "us," or "our") provides a cloud-based school management platform for institutions, staff, students, and families, including our website (eduprimeai.com), API (api.eduprimeai.com), and native mobile applications for Android and iOS. This Privacy Policy explains what personal data we process, why we process it, where it is stored, and the choices available to you under applicable law, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
For school workspaces, your institution is typically the Data Fiduciary for student, parent, and staff records entered into the product. We act as a Data Processor(service provider) processing that data on the institution's instructions. For our marketing website, school registration requests, and platform operator accounts, we act as Data Fiduciary.
1. Who this policy applies to
- Visitors to our marketing website (including contact and school registration forms).
- Users of the EduPrime AI web application: administrators, teachers, staff, students, parents / guardians, and other roles invited by a school.
- Users of the EduPrime AI mobile apps (Android and iOS), which connect to the same school accounts and APIs as the web product.
- Platform operators who manage tenant onboarding and support for multiple schools.
2. Itemized personal data we collect
We collect only what is needed to operate the Service. Categories include:
| Category | Examples | Purpose | Typical retention |
|---|---|---|---|
| Website / sales inquiries | Name, email, organization, message, IP (abuse prevention) | Respond to inquiries; prevent spam | Up to 24 months after last contact |
| School onboarding | Admin contacts, school name, billing contact | Provision and support the tenant | Contract term + up to 7 years (tax / legal) |
| Account & profile | Name, email, phone, role, hashed password, school affiliation | Authentication and access control | While account active; then per school policy |
| Student records | Enrollment, attendance, grades / report cards, timetables, photos (optional), medical notes (optional) | School academics and administration | Per school policy / statutory education retention |
| Parent / guardian | Name, contact details, relationship, pickup / emergency flags | Family communication and safeguarding | While linked to active student; then per school policy |
| Fees & finance | Fee structures, invoices, payments, expense / payroll fields | School billing and payroll operations | Contract term + up to 7 years (financial records) |
| Communications | In-app messages, optional Gmail delivery, announcements | School operations and notifications | Messages typically up to ~2 years (configurable) |
| Parental consent records | Guardian identity, consent timestamp, method, policy version, IP / user agent (where captured) | DPDP verifiable consent for children under 18 | While processing child data + evidence period |
| Usage & security logs | Auth events, API logs, device / browser type, diagnostics | Operate, secure, and debug the Service | Typically 30–90 days unless needed for incidents |
Mobile apps. Session and refresh tokens are stored in secure on-device storage. Apps call our API over HTTPS and show only role-authorized school data. We do not require device contacts or precise location for core features. We do not sell personal information.
3. How we use information
- Provide, maintain, and improve the EduPrime AI platform and website.
- Authenticate users, enforce role-based access, and protect against fraud or abuse.
- Enable school-configured modules (admissions, attendance, grades, fees, messaging, payroll).
- Record and evidence parental / guardian consent for processing children's data.
- Send transactional messages (password reset, credentials, in-app notices).
- Respond to contact and registration requests and provide customer support.
- Comply with law, enforce our terms, and protect the rights and safety of users and the public.
We do not sell personal information. We do not use student data for targeted advertising.
4. Legal bases under the DPDP Act
Depending on the processing activity, we (or the school as Data Fiduciary) rely on:
- Consent — including verifiable parental / guardian consent before collecting personal data of children under 18.
- Legitimate use — for example performance of a contract with the school, employment-related processing directed by the school, or compliance with law.
Where consent is the basis, you (or a parent / guardian for a child) may withdraw consent through the school administrator or by contacting us. Withdrawal does not affect processing already lawfully completed.
5. Children under 18 (DPDP)
EduPrime AI is built for schools that process data of minors. Before a school collects or continues to process personal data of a student under 18 through the product, the school must capture verifiable parental or guardian consent using the in-product consent workflow (or an equivalent school-attested record). We store consent evidence (who consented, when, method, and policy version) linked to the student or admission application.
Product accounts for minors are created and managed by the school—not by children signing up on the public website. Parents and students should contact their school first for questions about records held in EduPrime AI.
6. Data storage location (India residency)
For production school workspaces serving institutions in India, we host application servers and primary databases on cloud infrastructure located within India (for example AWS Mumbai / Hyderabad, Google Cloud Mumbai / Delhi, or equivalent India regions). Backups of India-tenant data are also retained in India-region storage unless a separate written agreement states otherwise.
Optional third-party integrations (for example Google Gmail OAuth or AI providers) may process limited data outside India only when a school enables that integration and accepts the third party's terms. Schools can disable such integrations.
7. How schools and third parties connect
Your institution. Administrators control most product data: invitations, roles, modules, retention, and consent capture for families.
Google Gmail (optional).If connected, we access and send email only as authorized through Google's OAuth consent screen. Schools can disconnect at any time. See Google's Privacy Policy.
Service providers. We use infrastructure and tooling providers (hosting, database, email delivery) that process data on our behalf under contractual safeguards. A current list of categories is available on request.
8. How we protect data
We use administrative, technical, and organizational measures designed to protect information, including encryption in transit (HTTPS / TLS), access controls, password hashing, tenant isolation by school, and role-based permissions. No method of transmission or storage is completely secure; use strong passwords and report suspected incidents promptly to info.eduprimeai@gmail.com.
9. Your rights (Data Principals)
Under the DPDP Act and other applicable laws, you may have rights to access, correct, erase, or withdraw consent for your personal data, and to nominate another person in case of death or incapacity where provided by law. Product users should contact their school administrator first for data in the school workspace. You may also contact our grievance officer below. We may need to verify identity and coordinate with your institution where they are the Data Fiduciary.
You can sign out of the web or mobile application at any time. Schools can deactivate accounts and remove data subject to administrator permissions.
10. Cookies and analytics
Essential cookies are used for session management and security on the signed-in product. On the marketing website, optional analytics (for example Google Analytics) load only after you accept non-essential cookies via our cookie banner. You may change your choice by clearing site data for this domain.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated through the product or by email where appropriate.
12. Grievance officer & contact
For privacy questions, Data Principal requests, or complaints under the DPDP Act, contact our Grievance Officer at info.eduprimeai@gmail.com or use our contact form. We aim to acknowledge complaints within a reasonable period and resolve them as required by applicable law. You may also have the right to approach the Data Protection Board of India once constituted / as notified.