Modern School ERP ("we", "our", "school") is committed to protecting the privacy of students, parents, teachers, and staff. This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with applicable Indian laws including the Information Technology Act, 2000 and the IT (Amendment) Act, 2008.
We collect the following categories of personal data:
| Category | Data Points | Purpose |
| Identity | Name, DOB, Gender, Photo, Aadhar No. | Student registration, ID card |
| Contact | Mobile, Email, Address | Communication, OTP, notifications |
| Academic | Class, Roll No., Marks, Attendance | Results, marksheet, reports |
| Financial | Fee amount, transaction ID, payment status | Fee management, receipts |
| Technical | IP address, browser, device type, login time | Security, fraud prevention |
Sensitive Data: Aadhar numbers are collected only for government compliance and are stored in encrypted form. We do not store full card/bank details — all payment processing is handled by PCI-DSS compliant payment gateways.
- Admission Processing: Verifying eligibility, generating enrollment numbers, and maintaining student records
- Academic Management: Attendance tracking, exam results, marksheets, admit cards, and ID cards
- Fee Collection: Processing online payments via Razorpay / PayU / Cashfree / PhonePe / Paytm and generating receipts
- Communication: Sending OTPs, fee reminders, exam schedules, and important notices via SMS and WhatsApp
- Security: Preventing unauthorized access, detecting fraud, and maintaining login history
- Legal Compliance: Fulfilling obligations under government education regulations and UDISE reporting
We do NOT use your data for advertising, profiling, or selling to third parties.
3. Third-Party Services & Data Sharing
We share minimum necessary data with the following trusted third-party services:
| Service | Provider | Data Shared | Purpose |
| Payment Gateway | Razorpay / PayU / Cashfree / Paytm / PhonePe | Name, email, phone, amount | Fee payment processing |
| WhatsApp API | Meta (Facebook) / MPWA | Phone number, message content | OTP, notifications |
| SMS Gateway | Fast2SMS / TextLocal / MSG91 / Twilio | Phone number, message | OTP, alerts |
| Maps | Google Maps | None (embed only) | Location display |
All payment gateways are PCI-DSS compliant. We never store credit/debit card numbers. WhatsApp messaging complies with Meta's Business Messaging Policy. SMS services comply with TRAI DLT regulations.
- Encryption: All passwords are hashed using BCrypt (cost factor 12). Sensitive data is encrypted at rest.
- HTTPS: All data transmission is encrypted via SSL/TLS
- Access Control: Role-based access — students, parents, teachers, and admins see only their authorized data
- Session Security: Sessions expire automatically after inactivity. Login history is maintained.
- Backups: Regular encrypted database backups are maintained
- Audit Logs: All admin actions are logged with IP address and timestamp
In case of a data breach, affected users will be notified within 72 hours as per IT Act requirements.
- Student Records: Retained for the duration of enrollment + 5 years after leaving
- Payment Records: Retained for 7 years as per financial regulations
- Login Logs: Retained for 90 days
- Admission Applications: Retained for 3 years (approved or rejected)
- OTP Records: Deleted immediately after use or expiry (5 minutes)
We use only essential cookies:
- Session Cookie (PHPSESSID): Keeps you logged in during your session. Deleted on logout/browser close.
- Theme Cookie: Remembers your light/dark mode preference
We do NOT use advertising cookies, tracking pixels, Google Analytics, or any third-party tracking scripts.
Under applicable Indian law, you have the right to:
- Access: Request a copy of your personal data we hold
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Request your data in a machine-readable format
- Opt-out: Unsubscribe from non-essential WhatsApp/SMS communications
- Grievance: Lodge a complaint with our Grievance Officer
To exercise any right, email us at = $se ?> with subject "Data Privacy Request".
Our services are primarily for school students. For students under 18:
- Parent/Guardian consent is obtained during admission
- Parents can access and request correction of their child's data
- We do not knowingly collect data from children for marketing purposes
- Student login credentials are managed by the school and parents
9. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be:
- Posted on this page with an updated effective date
- Notified via school notice board for significant changes
- Effective immediately upon posting unless stated otherwise
10. Grievance Officer & Contact
Grievance Officer: Principal / School Administrator
Organization: Modern School ERP
Email: admin@school.com
Phone: +91-9453446003
Address: Khalispur Mubarakpur Sultanpur Uttar Pradesh 228145
Grievances will be addressed within 30 days of receipt as per IT Act, 2000 Section 43A.