1. Overview
Smart Pathshaala is a school management platform used by schools and educational institutions to run their day-to-day operations. This policy explains what information we handle, why we handle it, who we share it with, and the choices and rights available to you.
It covers our website, our web application, and any mobile experience we offer. If a school has signed its own agreement with us, that agreement governs where it differs from this policy.
2. Our role, and the school’s role
This distinction matters, because it determines who you should approach about a particular record.
- For student, parent, and staff records inside the platform, the school is the data fiduciary. The school decides what is collected, who may see it, and how long it is kept. We act as its data processor and handle that data only on the school’s instructions.
- For our own website visitors, demo requests, and the accounts of the people who administer a subscription, we are the data fiduciary and this policy applies directly.
If you are a parent, student, or member of staff and want a record corrected or removed, please contact your school first. We will support the school in acting on your request, but we do not change a school’s records on our own initiative.
3. Information we collect
Information a school provides
- Institution details — name, address, contact details, branches, academic sessions, classes, sections, and subjects.
- Student records — name, admission and roll numbers, date of birth, gender, class and section, guardian names and contact details, address, attendance, marks and report cards, fee structures and payment history, transport allocation, and uploaded documents.
- Staff records — name, contact details, role and permissions, employment details, attendance, and teaching assignments.
- Content the school creates — announcements, notices, remarks, timetables, and reports.
Information we collect automatically
- Authentication and session data, including the sign-in token stored in your browser.
- Security and audit data — sign-in attempts, account lockouts, and the actions taken by an account within a school’s workspace.
- Technical data such as IP address, browser and device type, timestamps, and error diagnostics.
Information you give us directly
- Demo requests and enquiries — your name, school, role, email address, phone number, city, approximate student count, and anything you write in the message field.
- Support conversations and any correspondence you send us.
We do not ask for, and the platform is not designed to store, payment card numbers. Fee collection records the amount, the mode, and a reference — not card or bank credentials.
4. How we use information
- To provide the platform — running attendance, fees, examinations, timetables, communication, transport, and reporting for the school that owns the data.
- To authenticate users and enforce the access each role is entitled to.
- To secure the service — detecting and limiting abusive sign-in attempts, investigating incidents, and keeping audit trails.
- To send transactional messages a school has configured, such as fee reminders, announcements, and account emails.
- To respond to demo requests, enquiries, and support questions.
- To maintain, troubleshoot, and improve the platform, using aggregated or de-identified information wherever it is sufficient.
- To meet our legal, tax, and regulatory obligations.
We do not sell personal data. We do not use student data to serve advertising, and we do not share it with advertising networks.
5. Consent and legal basis
We process school data to perform our contract with the school, and on the school’s documented instructions. Where consent is required — including a parent’s consent for a child’s data under India’s Digital Personal Data Protection Act, 2023 — the school is responsible for obtaining and recording it, since the school holds the relationship with the family.
For our own website and demo enquiries, we rely on your consent, given when you submit the form, and on our legitimate interest in responding to you.
6. Children’s data
Most students on the platform are children. Their records are entered and controlled by their school, not by the child. We do not knowingly collect data directly from a child outside the school’s workspace, we do not profile children for advertising, and we do not use children’s data to train AI models.
Where a student account exists, it is scoped to that student’s own academic information — their timetable, results, and school notices. A parent account is scoped to that parent’s own child.
8. AI-assisted features
Some features can draft text for a member of staff — an announcement, a fee reminder, a term remark on a report card. These call a third-party AI provider, and we designed them to send as little as possible:
- We send the minimum needed to produce a useful draft. For a term remark that is a subject-by-subject percentage, an attendance percentage, and grade bands — not the student’s name, roll number, or gender. Personal details are added back locally, after the draft returns.
- Nothing an AI feature produces is saved to a school’s records on its own. A member of staff reviews and edits every draft, then saves or sends it themselves.
- AI features are available only to staff who already hold the permission for that task. AI never widens what an account can reach.
- We record each request — which feature, which model, when, by whom, and whether it succeeded — so a school can audit AI use in its workspace.
- We do not permit our AI provider to use school data to train its models.
AI output is a suggestion and can be wrong. It is the reviewing member of staff who is responsible for what is finally saved or sent.
9. How we protect information
- Every school’s data is isolated from every other school’s. Each record carries its school’s identity, and every query is scoped to it.
- Access is controlled by role. Staff reach only the records their role permits, and a school administrator can review and change those permissions at any time.
- Traffic between your browser and the platform is encrypted in transit.
- Passwords are stored hashed, never in readable form.
- Repeated failed sign-ins lock an account for a period, and request rates are limited, to blunt password-guessing attempts.
- Access to production systems is restricted to the people who need it to operate the service.
No system is perfectly secure. If a breach affects a school’s data, we will notify the school without undue delay, along with any regulator the law requires us to inform, and tell them what happened and what we are doing about it.
10. How long we keep information
A school’s data is kept for as long as its subscription is active, because school records are meant to span years — a student’s history follows them across academic sessions by design.
- After a subscription ends, the school has 30 days to export its data. We then delete or irreversibly anonymise it within 90 days, unless the law requires us to keep it longer.
- Demo requests and enquiries are kept for up to 24 months from our last contact with you.
- Security and audit logs are kept for up to 12 months.
- Backups roll off on their own schedule; data deleted from the live system leaves backups within 90 days.
11. Your rights
Subject to applicable law, you may ask to access the personal data we hold about you, to have it corrected or completed, to have it erased, to withdraw a consent you gave us, and to nominate someone to exercise these rights on your behalf.
Where the school is the data fiduciary — which is the case for student, parent, and staff records — please raise the request with your school. We will help the school fulfil it. For data we hold as fiduciary, such as a demo enquiry, write to us directly and we will respond within the period the law allows.
13. Where data is stored
We aim to store and process school data on infrastructure located in India. Some service providers — email delivery and our AI provider among them — may process limited data outside India. Where that happens, we use providers that offer appropriate safeguards, and we send them only what the feature needs.
14. Changes to this policy
We may update this policy as the product and the law change. The “Last updated” date at the top of this page always reflects the current version. If a change materially affects how we handle school data, we will notify school administrators before it takes effect.
15. Contact and grievance redressal
Questions about this policy, or a request about your data, can be sent to our privacy contact. If you are not satisfied with how we handled it, our Grievance Officer will review the matter and respond within the period prescribed by law.