Privacy Policy & Security Protocol
Comprehensive Corporate Documentation • Deccan India Development Corporation Private Limited (DIDC)
1. Scope, Status & Definitions
This document represents the absolute and exhaustive Privacy Policy of ScholarERP, a proprietary software platform owned, developed, and maintained by Deccan India Development Corporation Private Limited ("DIDC", "we", "our", or "us"). This policy governs all data ingestion pipelines, storage interfaces, API configurations, and mobile stakeholder portals (Parent, Teacher, and Student Mobile Apps).
1.1 Legal Definitions
- Data Processor: DIDC, which processes personal data on behalf of educational institutions in accordance with strict contractual instructions.
- Data Controller: The subscribing educational institution (school, college, university, or coaching academy) that collects student/parent/staff profiles and determines the purposes and means of processing.
- Personally Identifiable Information (PII): Any dataset that can directly or indirectly isolate and identify a physical person.
- Sensitive Personal Data or Information (SPDI): Includes financial credentials, hashed biometrics metadata, medical/health records, and minor identifiers.
2. Deep Information Schemas
ScholarERP processes the following data categories strictly as instructed by the Data Controller:
2.1 Institutional Subscriber & Billing Data
When an administrator purchases a ScholarERP yearly subscription, we collect registration details: full names, corporate domains, billing addresses, tax registration certificates (GST numbers in India), and contact numbers. Payment transactions are processed via Razorpay integrations, logging transaction reference tokens, tax metrics, and invoice IDs.
2.2 Student Information Roster System (SIS)
Administrative panels store exhaustive student records: full names, enrollment IDs, grades, section mappings, gender markers, date of birth, pick-up authority lists, academic transcripts, homework submissions, exam grades, attendance logs, and physical RFID scanner tag logs.
2.3 Staff & Faculty Roster System
Contains employee records: names, employee codes, emails, mobile lines, subject specialization mappings, class schedule allocations, basic salaries, benefits structures, payroll calculations, and attendance logs.
2.4 Parent / Guardian Profiles
Contains parent contact records: names, emergency contact numbers, email accounts, home addresses, payment receipts log, pending outstanding fee balances, and payment gateway tokens.
2.5 Biometric & Device System Logs
Biometric integrations (such as fingerprint hardware check-ins) process mathematical hashes of biometric patterns. Raw fingerprints are never stored, sent, or uploaded to our cloud servers. Only alphanumeric validation strings and check-in timestamps are processed.
3. Lawful Processing Bases
Under global data directives (including GDPR and India's DPDPA 2023), DIDC processes personal data under the following lawful bases:
- Contractual Performance: Processing is essential to set up the Subscriber's dedicated virtual server database, clear fee checkouts, and execute school operations.
- Legitimate Interests: Processes conducted to maintain campus security (RFID gate alerts) and facilitate parent communication (automated WhatsApp follow-ups).
- Legal Obligation: Retaining taxation invoices, GST summaries, and transaction records for statutory audits.
- Explicit Consent: Validated when parents opt-in to the mobile app or school administrators upload user lists.
4. Security & Storage Architecture
Our systems feature modern, enterprise-level security measures:
- Encryption Protocols: All network traffic is encrypted using HTTPS and TLS 1.3 protocol. Database files store passwords hashed with bcrypt, and sensitive parameters are protected via industry-standard AES-256 encryption.
- Virtual Container Isolation: Subscribing schools have their database instances isolated at the hypervisor or container layer. We do not host multi-tenant databases on standard tiers, preventing cross-contamination risks.
- Auditing & Monitoring: The leads console records admin log actions (including IP addresses, timestamps, and browser configurations) to prevent unauthorized entry.
5. Data Retention & Backups
Data retention timelines are strictly governed:
- Active Database Subscriptions: Data is stored for the duration of the annual contract.
- Database Backup Cycles: Automated container dumps are performed every 24 hours. Backups are stored in encrypted vaults and are retained for 30 calendar days before automated garbage recycling.
- Post-Termination Deletion: If a subscription expires, the corresponding virtual instance is suspended. We hold data in a read-only state for 30 days to facilitate admin exports, after which the database volume is securely wiped.
6. Global Regulatory Compliance
DIDC maintains international compliance frameworks across all operating regions:
6.1 India - DPDPA 2023 Compliance
In compliance with the Digital Personal Data Protection Act (DPDPA), 2023, DIDC processes personal data strictly for specified purposes with explicit, clear consent. Institutional subscribers act as Consent Managers. Users can review, correct, or erase data by contacting the institutional administrator or our Compliance Officer.
6.2 USA - FERPA & COPPA Compliance
Under the Family Educational Rights and Privacy Act (FERPA), DIDC acts as a "School Official" with legitimate educational interests. Under the Children's Online Privacy Protection Act (COPPA), ScholarERP collects student information only through prior parent consent collected by the subscribing school.
6.3 EU - GDPR & GDPR-K Compliance
Under GDPR, EU subscribers benefit from strict data minimization, localized EU container options, right to object, and data portability. Minor consents conform strictly to regional age standards (13-16 years).
7. Data Subject Rights
Individuals whose data is stored in ScholarERP retain full ownership over their profiles. Data Subjects may request:
- Right to Review: Request details on what records are held in their profile (attendance, marks, emergency contact lists).
- Right to Correct: Request correction of inaccurate exam scores or grade records.
- Right to Erase: Request permanent removal of contact accounts or child profiles.
- Right to Nominate: (Under DPDPA) Nominate an authorized individual to exercise rights on their behalf in case of incapacity.
8. Grievance Redressal Officer
For privacy audits, security concerns, or complaints under DPDPA, GDPR, and FERPA, please contact our Compliance and Grievance Officer:
Deccan India Development Corporation Private Limited (DIDC)
Attn: DPO & Compliance Director
Email: info@didc.in
Support Address: support@scholarerp.com
Questions about our policies?
Our support team can walk you through privacy, terms, or SLA commitments for your campus.