Your Privacy Is Our Commitment
EduCore India handles some of India's most sensitive data — student academic records, personal details, and financial transactions. We are committed to protecting every byte with transparency and care.
This Privacy Policy applies to EduCore India's web platform, mobile applications (Parent App, Student App, Staff App), and all associated services operated by IvanDigitalSolutions. It covers data collected from institutions, administrators, teachers, staff, parents, and students.
1. Who We Are
EduCore India is a School & College Management Software product developed and maintained by IvanDigitalSolutions, headquartered in Pune, Maharashtra, India.
For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDP Act), EduCore India acts as a Data Processor for student and staff personal data (on behalf of institutions) and as a Data Fiduciary for data collected directly from website visitors and demo requesters.
Data Protection Officer / Grievance Contact: contact@ivandigitalsolutions.com
2. What Data We Collect
A. Institutional & Administrator Data
- Institution name, address, registration number, affiliation details
- Administrator name, designation, email, mobile number
- GST number and billing information
- Login credentials (passwords stored as irreversible bcrypt hashes)
B. Student & Academic Data
- Student full name, date of birth, gender, photograph
- Parent/guardian names, contact numbers, email addresses
- Aadhar number (if provided by institution for government reporting — stored encrypted)
- Class, section, roll number, admission number
- Academic records: marks, grades, report cards, attendance history
- Medical/health information if entered by institution
- Previous school records, transfer certificates
C. Fee & Payment Data
- Fee structures, outstanding dues, payment history, and receipts
- For online payments: transaction ID, payment status, payment gateway reference (we do not store card numbers, CVV, or net-banking credentials)
- UPI IDs used in transactions are handled directly by the payment gateway
D. Staff & HR Data
- Staff name, designation, department, joining date
- Salary, attendance, leave records
- Bank account details (if configured for payroll) — stored encrypted
E. App Usage & Technical Data
- Device type, operating system version, app version
- IP address and approximate location (for security and session management)
- Login timestamps, session duration, feature usage logs
- Push notification tokens (to deliver alerts and circulars)
- Crash reports and performance diagnostics
F. Website Visitor Data
- Name, email, phone number submitted via demo request or contact forms
- Browser type, referring URL, pages visited (via first-party analytics)
3. Legal Basis for Processing
We process personal data on the following legal grounds under the DPDP Act 2023 and IT Act 2000:
- Consent: Website forms, demo requests, and parent app onboarding
- Contract Performance: Data necessary to deliver the subscribed ERP services
- Legitimate Interests: Security monitoring, fraud prevention, and service improvement
- Legal Obligation: Compliance with government directives, court orders, or regulatory requirements
4. How We Use Your Data
Data is used solely for the following purposes:
- Providing, operating, and improving EduCore India platform and mobile apps
- Processing fee transactions and generating financial reports for institutions
- Sending academic notifications, attendance alerts, exam results to parents/students
- Generating government-mandated academic reports (e.g., board submission formats)
- Customer support, training, and onboarding assistance
- Security monitoring, fraud detection, and access control
- Responding to demo requests and sales enquiries (for website visitors)
- Compliance with legal obligations, court orders, or government directives
We do not use student data for advertising, profiling, or any commercial purpose unrelated to educational service delivery.
5. Data Sharing & Third Parties
EduCore India does not sell, trade, or rent personal data to any third party. Data is shared only in these limited circumstances:
Service Providers (Processors)
- Payment Gateways (Razorpay / equivalent): For processing online fee payments; governed by their own PCI DSS-compliant privacy policies
- SMS/Email Providers: For delivering attendance alerts, circulars, and OTPs; only the recipient's mobile/email is shared
- Cloud Hosting Provider: Data is hosted on Indian servers with ISO 27001 certified infrastructure
- Customer Support Tools: Limited data to resolve specific support tickets, subject to NDA
Legal Disclosures
We may disclose data if required by law, court order, or government authority. We will attempt to notify the affected institution unless prohibited by law.
Business Transfer
In the event of a merger or acquisition, data may be transferred to the new entity under equivalent privacy obligations. Institutions will be notified in advance.
6. Data Storage, Retention & Security
Storage Location
All personal data is stored on servers physically located within India, in compliance with DPDP Act 2023 data localisation requirements.
Retention Period
- Active subscription: Data retained for the full subscription period
- Post-termination: Data retained in read-only archive for 90 days, then permanently deleted
- Payment records: Retained for 7 years as required under GST and accounting regulations
- Website enquiries: Retained for up to 2 years for CRM and sales follow-up
Security Measures
- AES-256 encryption for sensitive fields (Aadhar, bank accounts) at rest
- TLS 1.3 encryption for all data in transit
- Role-based access control (RBAC) — each user sees only what their role permits
- Multi-factor authentication (MFA) available for admin accounts
- Regular automated backups with point-in-time recovery
- Annual third-party security audits and vulnerability assessments
- Intrusion detection and DDoS protection
7. Children's Privacy
EduCore India processes student data, which may include minors under 18 years of age. This data is entered and controlled by the educational institution, which acts as the primary data fiduciary for student data. The institution is responsible for obtaining valid parental/guardian consent before entering student data.
EduCore India does not knowingly collect data directly from minors via public-facing forms. The Student App requires institutional credentials to access, ensuring no direct registration by minors.
8. Your Rights (DPDP Act 2023)
As a data principal (individual whose data is processed), you have the following rights:
- Right to Access: Know what personal data we hold about you
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (see our Data Deletion Policy)
- Right to Grievance Redressal: File a complaint with our Data Protection Officer
- Right to Nominate: Nominate another person to exercise rights on your behalf in case of death or incapacity
To exercise these rights, email contact@ivandigitalsolutions.com with your identity verification details. We will respond within 30 days.
Note for institutions: Most data correction and access requests should be directed to your institution's administrator first, as they manage your records within the ERP.
9. Cookies & Tracking
The EduCore India website uses minimal cookies:
- Essential Cookies: Session management and CSRF protection (cannot be disabled)
- Analytics Cookies: First-party analytics to understand page popularity (no cross-site tracking)
We do not use third-party advertising cookies or tracking pixels. The ERP application uses session tokens stored in encrypted browser storage for authentication.
10. Data Breach Notification
In the event of a personal data breach that is likely to result in harm, EduCore India will:
- Notify affected institutions within 72 hours of becoming aware of the breach
- Report to the Data Protection Board of India as required by the DPDP Act
- Provide details of the nature of breach, data affected, and remediation steps
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email and in-app notice at least 14 days before the effective date. Continued use of our services after the effective date signifies acceptance.