PRIVACY POLICY & DATA PROTECTION NOTICE
Effective starting: Jan 1, 2026
Platform: www.edusec.com (“EduSec” / “Website” / “SaaS Platform”)
Entity: Rudram Softech Pvt. Ltd. (“Company”, “We”, “Us”, “Our”)
Governing Laws: Digital Personal Data Protection Act, 2023 (DPDPA), Information Technology Act, 2000, and IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
Jurisdiction: Ahmedabad, Gujarat, India
LEGAL PREAMBLE & STATUTORY BASIS
This legal document is an electronic record in terms of the Information Technology Act, 2000, the rules thereunder as applicable, and the amended provisions pertaining to electronic records in various statutes as amended by the Information Technology Act, 2000. This electronic record is generated by a computer system and does not require any physical or digital signatures.
This policy is published in accordance with:
- The Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) and related statutory rules, functioning as a comprehensive, itemised statutory Notice under Section 5 of the Act.
- Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the Information Technology Act, 2000 (amended through ITAA 2008).
This privacy policy applies to all users, subscribers, educational institutions, corporate/government sponsors, vendors, employees, students, parents/guardians, and visitors of the website and SaaS platform. By using this website, logging into the software, or completing any registration or onboarding workflow, you agree and acknowledge that you have carefully read this privacy policy and accepted this agreement.
INSTITUTIONAL RESPONSIBILITY, ALLOCATION OF ROLES & DATA ENTRY
EduSec is a multi-tenant enterprise software-as-a-service (SaaS) platform licensed to schools, colleges, universities, and vocational or professional training institutes (each, a "Client Institution") to facilitate academic, vocational, operational, accounting, and institutional management. Under the DPDP Act, 2023, data governance responsibilities are partitioned as follows:
- Client Institution as the Data Fiduciary: When an educational or training institution deploys EduSec, the Client Institution determines the purpose, means, categories, and extent of personal data collected from its students, sponsored candidates, parents, guardians, teachers, administrative staff, corporate sponsors, and vendors. The Client Institution serves as the primary Data Fiduciary under Section 2(i) of the DPDP Act.
- Sole Responsibility for Data Entry & Ingestion: The Client Institution is solely and exclusively responsible for the accuracy, legality, authenticity, relevance, and updating of all information entered, imported, uploaded, or generated within the platform. Rudram Softech does not curate, verify, audit, or independently validate student records, employee salary structures, attendance cards, guardian income details, vendor bank credentials, or uploaded corporate sponsorship agreements.
- Mandatory Institutional Warranty on Consents: The Client Institution warrants and represents that it has procured all legally binding, verifiable consents required by law-specifically including verifiable parental or lawful guardian consent for minors under 18 years of age in accordance with Section 9 of the DPDP Act, 2023- prior to entering any individual's personal data into EduSec.
- Rudram Softech as the Data Processor: Rudram Softech acts solely as a Data Processor under Section 2(k) of the DPDP Act, operating purely on behalf of, and per the documented instructions of, the respective Client Institution. Rudram Softech disclaims any direct liability resulting from an institution's failure to obtain statutory consents, entry of inaccurate or defamatory records, or unlawful collection of personal data by institutional administrators, staff, or agents.
- Direct Inquiries and Data Principals: Students, staff, corporate liaison officers, vendors, and parents (Data Principals) who seek to inspect, modify, or delete their profile information must direct their requests primarily to the designated administrative authority of their respective Client Institution.
PRIVACY COMMITMENT & THIRD-PARTY PLATFORMS
While providing information for various web development and SaaS ERP services, online privacy is crucial for Rudram Softech, which is committed to safeguarding the information provided by its users. We are dedicated to creating a reasonably secured environment for our users.Respecting the privacy of online users while providing top-of-the-line services remains the core strategy of Rudram Softech. Our Privacy Policy gives users a transparent view of our privacy practices and assures them of safe passage through the website.
Our website provides links and integrations to other websites and third-party services governed by their own privacy policies (including third-party payment gateways, Amazon Web Services cloud infrastructure, Meta / WhatsApp Business API, Zoom Video Communications, Microsoft Teams, telecom SMS gateways, and Google/Facebook Single Sign-On). We do not assume responsibility for the independent privacy, operational, or security practices of these external sites and services. Users are urged to familiarize themselves with third-party privacy policies.
CORE POLICY COVERAGE
- Online processes & types of information collected through our website
- Use and disclosure of personal information
- WhatsApp, virtual classrooms & communications integrations
- Sponsored students & corporate training management
- Accounting, purchase, vendor & expense management
- Special provisions for children’s data & parental consent
- Choice, opt-out, and withdrawal of consent
- Data Principal rights under DPDP Act, 2023
- Data retention, purpose limitation & statutory exceptions
- Reasonable security practices, breach reporting & legal compliance
- Grievance redressal & regulatory escalation
- Applicable laws & jurisdiction
- Annexure-A: Itemised list of personal data collected
1. ONLINE PROCESSES & TYPE OF INFORMATION COLLECTED
Online Processes
Users visiting or utilizing our website and services participate in the following:
- User access to SaaS-based software modules (student/staff management, academic ERP, attendance tracking, report cards, fee management, and institutional administration)
- User access to online educational, instructional, virtual classrooms, and corporate training materials
- Sponsored student onboarding, client contract administration, and external performance tracking
- Institutional accounting, vendor record management, purchase orders, and expense tracking
- Get-in-touch, registration, demo scheduling, or contact-us workflows
- Payment processing executed through certified payment gateway aggregators
- Direct communication dispatch workflows via SMS, Email, and WhatsApp
Personal Data Collected
You or your Client Institution provide personally identifiable, business, and financial data (itemized comprehensively in Annexure-A, which may be updated from time to time based on operational modules) during execution of the above processes. This information becomes part of the platform database and will only be shared, stored, or processed in strict accordance with this Policy and Indian data protection laws.
2. USE AND DISCLOSURE OF PERSONAL INFORMATION
We will not sell, rent, or publish personally identifiable information collected from you. All personal data is supplied voluntarily by users or entered by Client Institutions pursuant to lawful service agreements for the following purposes:
- Service Delivery & Platform Operations: To run academic and vocational operations, process admissions, administer student profiles, manage employee human resources, calculate payroll, record attendance, track student progress, and compute academic evaluations.
- Email and Communication Records: When we receive emails or chat messages from you, we retain the content of the message, your email address, and communication metadata. We use registered email addresses and mobile numbers for system-critical alerts, password resets, verification OTPs, and operational notifications. Promotional messages are sent only with your consent, and you retain the right to opt out at any time.
- System Settings & Infrastructure Integrations: Secure storage of API configurations, mail server credentials, WhatsApp Business configurations, and single sign-on parameters to enable automated institutional communications and federated identity verification.
- Analytics & Performance Telemetry: We collect device and navigation data (IP address, ISP details, browser fingerprint, operating system) to optimize SaaS uptime, maintain security defenses, and trace unauthorized system intrusions. We also utilize Google Analytics to analyze platform stability, improve user experience, and configure responsive layouts.
- Third-Party Processing Disclosures: Personal data is shared strictly on a need-to-know basis with vetted technical sub-processors (e.g., cloud infrastructure hosts such as AWS, verified SMS gateway operators, Meta/WhatsApp API, Zoom, Microsoft, and banking/payment aggregators) solely to execute platform services.
3. WHATSAPP, VIRTUAL MEETINGS & THIRD-PARTY COMMUNICATIONS
- WhatsApp Business API Integration: The platform integrates with Meta / WhatsApp Business API to allow Client Institutions to dispatch transactional alerts (fee receipts, exam dates, attendance alerts), utility notifications, and institutional marketing/promotional messages. Because the Client Institution controls its messaging campaigns, the Client Institution is solely responsible for obtaining prior opt-in consent for promotional broadcasts and for providing instant opt-out/STOP options under TRAI regulations and the DPDP Act.
- Virtual Classrooms & Video Conferencing (Zoom & Microsoft Teams): EduSec provides API bridges and timetable integrations for live lectures, meetings, and training sessions via Zoom Video Communications and Microsoft Teams. Audio, video, and text chat generated during live sessions are governed by the hosting Client Institution's administrative controls and the respective privacy policies of Zoom and Microsoft. Rudram Softech does not record, access, or listen to live video or audio streams unless automated cloud-recording storage integrations are explicitly enabled and contracted by the Client Institution.
4. SPONSORED STUDENTS & CORPORATE TRAINING MANAGEMENT
Where Client Institutions deliver training under commercial contracts with corporate employers, government departments, trusts, or third-party sponsoring organizations:
- Contract and Authorized Person Data: The platform stores client agreements, Memorandums of Understanding (MoUs), and identifying credentials of corporate liaison officers or authorized signatories (names, designations, official email IDs, corporate phone numbers, and physical/digital signatures).
- Cross-Entity Academic Reporting: The platform enables Client Institutions to assign enrolled students to corporate batches, map them against specific sponsorship agreements, and generate attendance, certification, and progress reports that are shared with the sponsoring client.
- Authorization Responsibility: The Client Institution is solely responsible for establishing the legal basis under the DPDP Act for enrolling sponsored candidates, sharing candidate performance metrics with the sponsoring client, and validating commercial contract execution.
5. ACCOUNTING, PURCHASE, VENDOR & EXPENSE MANAGEMENT
EduSec includes financial ledger, purchase order, and expense auditing modules for institutional business operations:
- Vendor & Contractor Data: The platform processes identity and financial records of institutional suppliers, contractors, and vendors (business name, primary contact person, PAN card, GSTIN, billing address, phone number, and bank account/IFSC details).
- Expense Disbursements & Receipts: The platform records operational expenditures, employee reimbursement claims, purchase vouchers, invoices, and payment clearance records.
- Integrity of Books: Financial data entered into these modules is processed exclusively to maintain institutional accounts, prepare trial balances, and support internal and statutory fiscal audits.
6. SPECIAL PROVISIONS FOR CHILDREN’S DATA & GUARDIANS
Given that EduSec processes educational, academic, and identification records of minor students:
- Mandatory Verifiable Parental Consent: In accordance with Section 9 of the DPDP Act, 2023, the collection and processing of personal data belonging to any child (under 18 years of age) is undertaken only after obtaining verifiable consent from the parent or lawful guardian. The Client Institution that admits the child is contractually and statutorily mandated to procure and record this verifiable consent prior to enrolling the student onto the platform.
- No Behavioral Tracking or Profiling: We strictly refrain from conducting behavioral tracking, targeted psychological profiling, or automated tracking of child users across our SaaS platform.
- Zero Targeted Advertisements: We never serve commercial advertisements or targeted advertising directed at children.
- Protection from Detrimental Processing: No data processing activity is conducted that could cause any physical, emotional, or developmental harm to a child.
7. CHOICE, OPT-OUT, AND WITHDRAWAL OF CONSENT
Given that EduSec processes educational, academic, and identification records of minor students:
- Marketing Opt-Out: You have the option at any stage to inform us that you no longer wish to receive non-essential informational or promotional communications. You may select the "unsubscribe" link within communications, reply STOP to promotional WhatsApp messages, or submit an opt-out request to info@rudramsoftech.com.
- Withdrawal of Consent: Under Rule 5(7) of the IT SPDI Rules, 2011 and Section 6 of the DPDP Act, 2023, you have the statutory right to withdraw previously granted consent for the processing of your personal data at any time.
- Procedure for Withdrawal: Initiating withdrawal shall be as straightforward as granting consent. If you are an independent user, you may email our Grievance Officer at info@rudramsoftech.com or send a written notice to our registered office. If your data was entered by an educational or training institution, your request must be routed through the administrative office of the Client Institution acting as the Data Fiduciary.
- Consequences of Withdrawal: If consent is withdrawn for data essential to operating core educational, corporate training, or SaaS services (such as enrolment ID, fee validation, or account authentication), access to the associated software modules may be suspended or terminated.
8. DATA PRINCIPAL RIGHTS UNDER THE DPDP ACT, 2023
Every Data Principal (student, parent, employee, corporate signatory, vendor, or independent user) holds the following statutory rights, exercisable through the Client Institution or our Grievance Officer:
- Right to Access Information: The right to obtain a summary of your personal data being processed, details of processing operations, and the identities of third parties with whom data has been shared.
- Right to Correction & Erasure: The right to correct inaccurate, obsolete, or misleading information, complete partial profiles, and request the erasure of personal data that is no longer required for the purpose for which it was originally collected.
- Right of Grievance Redressal: The right to register grievances concerning the handling of your personal data and obtain a formal resolution within statutory timelines.
- Right to Nominate: The right to designate a nominee who shall, in the event of your death or legal incapacity, exercise your data protection rights on your behalf.
9. DATA RETENTION, PURPOSE LIMITATION & STATUTORY EXCEPTIONS
Given that EduSec processes educational, academic, and identification records of minor students:
- Operational Purpose Limitation: Personal data collected will only be retained for as long as necessary to satisfy the specific educational, administrative, or contractual purpose for which it was provided.
- Educational Records: Student and employee records are retained during active institutional enrollment or employment, and thereafter for mandatory academic archival periods prescribed by applicable boards, universities, or accreditation bodies.
- Statutory Financial Retention Exception: Notwithstanding any request for erasure or profile deletion submitted by a Data Principal, financial ledgers, tax invoices, purchase vouchers, payment receipts, fee records, and vendor banking data entered into the Accounting & Expense modules shall be retained for the mandatory statutory periods prescribed under the Income Tax Act, 1961, the Central Goods and Services Tax (CGST) Act, 2017, and the Companies Act, 2013 (generally up to 8 financial years).
- Purging of Data: Upon the expiration of legal retention mandates, termination of the institutional SaaS agreement, or receipt of a valid erasure directive, data is irreversibly anonymized or securely purged from active production servers in accordance with the DPDP Rules.
10. REASONABLE SECURITY PRACTICES & LEGAL COMPLIANCE
We have implemented comprehensive managerial, technical, and operational safeguards pursuant to Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and Section 8(5) of the DPDP Act, 2023 to prevent unauthorized access, loss, misuse, alteration, or disclosure.
Implemented Security Controls:
- Role-Based Access Control (RBAC): Strict separation of privileges ensuring accounting ledgers, employee payroll, student profiles, and client contracts are accessible only to verified, authorized roles.
- Cryptographic Protections: User passwords are encrypted using salted hash functions (bcrypt) and are never stored in plain text, defending against dictionary and brute-force attacks.
- Application Safeguards: Native protections against SQL injection attacks, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and unauthorized directory or file traversal.
- Secure Transit: End-to-end data encryption using Transport Layer Security (TLS) and SSL.
- Hosting Architecture: High-availability cloud deployments hosted on Amazon Web Services (AWS) compliant with enterprise physical, perimeter, and operational security standards (detailed at AWS Security).
- Organizational Controls: Internal staff training on cyber laws, credential management, and privacy compliance.
Breach Notification Obligations
In the event of a confirmed personal data breach affecting our infrastructure, Rudram Softech will notify the Data Protection Board of India (DPBI) and affected users/Client Institutions in the form and manner stipulated under Section 8(6) of the DPDP Act, 2023.
Statutory Disclosures to Law Enforcement
The management cooperates with lawful government directives. We may disclose personal data to authorized cyber investigation authorities without prior notice as mandated under Sections 67C, 69, 69A, 69B, 70B, 79, and 80 of the IT Act, 2000 and Section 36 of the DPDP Act.
Limitation of Liability
While we maintain reasonable security practices under Sections 43, 43A, 45, 66, 72A, and 85 of the IT Act, 2000, you acknowledge that no digital platform or internet transmission is completely impervious to cyber incidents. By using this website, you acknowledge that our implemented controls satisfy statutory due diligence standards, and the company shall not be held liable for damages, operational downtime, or financial loss resulting from third-party cyberattacks, zero-day vulnerabilities, or events beyond our reasonable control.
11. GRIEVANCE REDRESSAL & REGULATORY ESCALATION
In compliance with Rule 5(9) of the IT SPDI Rules, 2011 and Section 13 of the DPDP Act, 2023, Rudram Softech has appointed a designated Grievance Officer:
- Grievance Officer: Mr. GirishKumar Prajapati
- Entity: Rudram Softech (EduSec)
- Email: info@rudramsoftech.com
- Resolution Window: All grievances received will be acknowledged and resolved within 30 days of receipt (or the specific timeline enacted under subsequent DPDP operational rules).
Escalation to the Data Protection Board of India
If a Data Principal does not receive an adequate or timely resolution from our Grievance Officer (or from the respective Client Institution acting as Data Fiduciary), they possess the statutory right to file a formal complaint before the Data Protection Board of India (DPBI).
12. APPLICABLE LAWS & JURISDICTION
This Privacy Policy agreement shall be governed by and construed in accordance with the Laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, without regard to conflict of laws principles. The courts located in the city of Ahmedabad, State of Gujarat, India, shall retain exclusive territorial jurisdiction over any disputes, claims, or legal actions arising under or relating to this privacy policy or use of the SaaS platform.
ANNEXURE-A: ITEMIZED LIST OF INFORMATION PROCESSED
1. Student User Data- Personal Information: Name, email ID / login ID, phone numbers, gender, date of birth, nationality, religion, blood group, known languages, birthplace, profile image, user password, mobile device type (iOS, Android, etc., for mobile app), admission category.
- Address (Current & Permanent): Address line, city, state, country, house no., pincode, phone no.
- Academic Details: General Registration No. (GR No.), course, admission year, graduate year, graduate month, academic year, batch & section, admission date, academic remarks.
- Guardian / Parent Information: Name, email/login ID, phone number, mobile number, relation, income, qualification, occupation, home address, and office address.
- Documents: Uploaded files/documents based on institutional categories (birth certificates, transfer certificates, identity proofs).
- Personal Information: Name, email/login ID, mobile/phone number, gender, date of birth, profile image, password, mobile device type (iOS, Android, etc., for mobile app), name alias, joining date, birthplace, department, designation, category, total experience, blood group, marital status, nationality, religion.
- Address (Current & Permanent): Address line, city, state, country, house no., pincode, phone no.
- Guardian / Next-of-Kin Information: Name, email/login ID, phone number, mobile number, relation, income, qualification, occupation, home address, and office address.
- Operational & Career Details: Attendance card ID, mother’s name, specialization, reference names, languages, hobbies, qualification certificates.
- Documents: Uploaded identity and verification documents based on institutional categories.
- Leave & HR Information: Number of leave days, leave start date, leave end date, leave type.
- Financial & Payroll Data: Salary amount, working days, bank account numbers.
- Corporate Client / Sponsoring Entity Details: Sponsoring company/department name, registered address, corporate identification number (CIN/LLPIN), GSTIN, industry type, billing address.
- Authorized Signatory / Liaison Officer Information: Name, official designation, official email address, direct telephone/mobile number, signature record, authorization letters, and corporate power of attorney documents.
- Contractual & Training Records: Scanned client contracts, MoUs, service level parameters, batch allocations, course completion status, sponsor invoicing records, and progress report dispatch audit logs.
- Vendor & Supplier Profiles: Vendor entity name, trade name, contact person name, official email, phone number, registered business address, PAN (Permanent Account Number), GSTIN, MSME registration status.
- Banking & Settlement Data: Vendor bank account numbers, bank name, branch address, IFSC code, cancelled cheque images, payment clearance dates.
- Purchasing & Ledger Transactions: Purchase orders (POs), goods receipt notes, supplier bills, debit/credit notes, expense vouchers, expense category breakdowns, petty cash logs, employee travel/reimbursement claim receipts, and institutional financial ledgers.
- IP Address (Internet Protocol address), browser type, browser language, referring URL, files accessed, error reports, time zone, operating system, and audit logs.
- Amount of fees, cheque number, cheque date, bank name, bank branch, payment card details (processed via secure gateway standards), institutional bank account master list with names and aliases, fee categories.
- Google & Facebook single sign-on (SSO) profile details (name, email address, external profile ID).
- Mail Server Settings: Username/email address, mail server hostname, mail server password, encryption type (TLS/SSL), port number, sender email, sender display name.
- Google SSO Configuration: Google client ID, Google client secret.
- Facebook SSO Configuration: Facebook client ID, Facebook client secret.
- SMS API Configuration: SMS gateway usernames, passwords, authorization/access keys.
- WhatsApp Business API Configuration: WhatsApp Business Account ID (WABA ID), API access tokens, phone number IDs, and webhook verification tokens.
- Zoom Integration Credentials: Zoom OAuth client ID, client secret, SDK keys, and webhook secrets.
- Microsoft Teams Integration Credentials: Azure AD App (client) ID, tenant ID, client secret, and Graph API credentials.
- Communication & Teleconference Logs: Message delivery receipts, template approval tokens, outbound dispatch logs (SMS, Email, WhatsApp utility/marketing), and video conference meeting IDs with join/leave audit trails.
- General System Settings: Institutional time zone, date format, time format, datetime format.
- Notification Templates: Category-wise notification templates for SMS, Email, WhatsApp, and web/mobile alert configurations.
Click here to see the Previous Privacy Policy.