Privacy Policy
How Edulae Technologies handles personal data in ScholaRise — including the data of students who are children — under the DPDP Act, 2023.
Last updated · 16 June 2026
Edulae Technologies Private Limited (“Edulae”, “we”, “us” or “our”) operates ScholaRise, a school-management platform supplied to Indian K-12 schools and the trusts and societies that run them. This Privacy Policy explains what personal data we handle, why, on whose authority, and the rights you have in relation to it.
ScholaRise processes the personal data of students (many of whom are children under the age of eighteen), their parents and guardians, and school staff. Almost all of that data is entered and controlled by the school. For that data the school is the decision-maker and we act on its instructions; for a narrower set of data that we collect directly, we are the decision-maker. Understanding which is which is the most important thing in this policy, and we set it out plainly in section 3 below.
We have written this policy to align with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made thereunder, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the “SPDI Rules”). If a school asks us, we will help it meet its own obligations under those laws.
01 1. Introduction and scope
This policy applies to two things: (a) the ScholaRise platform — the web application, mobile applications and related services through which schools manage admissions, academics, attendance, examinations, finance, communications and other school operations; and (b) our public website and the marketing, sales, billing and support interactions that surround it.
It covers personal data relating to students (including children), parents and guardians, and school staff that schools enter into ScholaRise, as well as personal data of website visitors and of the individuals who administer or pay for a school's subscription.
This policy does not govern how a school itself collects, uses or shares personal data outside ScholaRise, nor the privacy practices of any third-party website or service that we link to. Each school has its own privacy notice, and where the school is the decision-maker (see section 3) that notice, not ours, governs how the data is used.
02 2. Definitions
We use a number of terms with specific meanings, drawn where possible from the DPDP Act and the SPDI Rules:
- Personal data
- Any data about an individual who is identifiable by or in relation to such data, as defined in the DPDP Act.
- Data Principal
- The individual to whom the personal data relates. Where that individual is a child, the Data Principal includes the parent or lawful guardian who acts for the child.
- Data Fiduciary
- The person who, alone or with others, determines the purpose and means of processing personal data. For data a school enters into ScholaRise, the school is the Data Fiduciary; for data we collect directly, we are.
- Data Processor
- A person who processes personal data on behalf of, and on the documented instructions of, a Data Fiduciary. For school-entered data, Edulae is the Data Processor.
- Child
- An individual who has not completed eighteen years of age. The DPDP Act gives the personal data of children special protection (see section 5).
- Sensitive personal data or information (SPDI)
- The categories treated as sensitive under the SPDI Rules — such as passwords, financial information (bank account, card or payment details), physical, physiological and mental-health condition, and biometric information. We process such data only where the school directs it for a legitimate school purpose.
- Processing
- Any operation performed on personal data, such as collection, recording, storage, use, sharing, disclosure or erasure, whether automated or not.
- School / Customer
- The school, trust, society or other educational institution that subscribes to ScholaRise and enters and controls student, parent and staff data on the platform.
- Sub-processor
- A third party we engage to help deliver ScholaRise (for example hosting, payments or messaging providers) that processes personal data on our behalf.
03 3. Our two roles — Processor and Fiduciary
This is the heart of this policy. For the student, parent and staff data that a school enters into ScholaRise, the SCHOOL is the Data Fiduciary and Edulae is only a Data Processor — we act on the school's documented instructions and do not decide, on our own, how that data is used. For the limited data we collect directly (website visitors and the school's billing and admin contacts), Edulae is the Data Fiduciary.
As a Data Processor for school-entered data, we process that data to provide the platform under our agreement with the school. We do not sell it, we do not use it for our own marketing, and we do not use it to build advertising or behavioural profiles. We use it only to operate, secure, support and improve the service the school has asked us to provide, and otherwise on the school's instructions.
As a Data Fiduciary for data we collect directly, we determine the purpose and means of processing, give notice, and stand answerable to the Data Principal and to the Data Protection Board of India for that data. The categories table in section 4 marks, for each category, which role applies.
Where the school is the Data Fiduciary, the school is responsible for having a lawful basis (such as valid consent, including verifiable parental consent for children), for giving its own privacy notice to students, parents and staff, and for handling their rights. We support the school in meeting these obligations, but we cannot and do not exercise the school's decision-making for it.
04 4. Personal data we process
The table below sets out the main categories of personal data handled through ScholaRise, with examples and the role we play for each. “Processor” means the school is the Data Fiduciary and we act on its instructions; “Fiduciary” means we are the decision-maker.
| Category | Examples | Our role |
|---|---|---|
| Student data (including children) | Name, photograph, date of birth, gender, admission and roll numbers, class and section, contact details, attendance, marks and academic records, fee and concession records, transport assignment, health or special-needs notes the school records, documents the school uploads. | Processor (school is Fiduciary) |
| Parent / guardian data | Name, relationship to the student, mobile number, email, address, occupation, and the login used by parents to access the platform. | Processor (school is Fiduciary) |
| School staff data | Name, role and designation, employee identifiers, contact details, branch and access permissions, attendance and leave, and login credentials within ScholaRise. | Processor (school is Fiduciary) |
| Account / billing data | Names, work emails and phone numbers of the school's administrators and billing contacts, subscription, invoice and tax (GST) details, and correspondence with our sales and support teams. | Fiduciary (Edulae) |
| Technical, usage and cookie data | IP address, device and browser type, log and diagnostic data, pages and features used, and cookies or similar technologies on our website and platform (see section 10). | Website: Fiduciary; in-platform service logs: Processor |
| Payment data | Fee payments are processed through third-party payment gateways. Card, UPI and bank details are entered with and handled by the gateway; we receive transaction references, status and amounts, not full card numbers. | Processor (school is Fiduciary); gateways act on their own terms |
05 5. Children's data
ScholaRise processes the personal data of children only on behalf of, and under the authority of, the school. The school obtains the verifiable consent of the parent or lawful guardian as required by the DPDP Act. Edulae does NOT use children's personal data for advertising, profiling, targeted advertising or behavioural tracking, and we do not undertake any processing of a child's data that is likely to cause a detrimental effect on the child.
Because much of the data on ScholaRise relates to students who are children, we treat that data with particular care. We process it strictly to deliver the platform to the school and on the school's instructions.
The DPDP Act requires that, before processing a child's personal data, the Data Fiduciary obtain verifiable consent from the child's parent or lawful guardian. In the ScholaRise context the school is the Data Fiduciary and is responsible for obtaining that consent and for keeping its consent records. As a processor we provide tools that help the school manage parent and guardian relationships, but we rely on the school's assurance that the necessary consent is in place.
Parents and guardians who wish to access, correct or erase a child's data, or to raise a concern, should contact the child's school in the first instance, because the school controls that data. We will support the school promptly in giving effect to any such request. Parents may also contact our Grievance Officer (section 14), who will route the matter appropriately.
06 6. Purposes and lawful basis
Under the DPDP Act, personal data may be processed on the basis of the Data Principal's consent or for certain legitimate uses recognised by the Act. The lawful basis depends on who is the Data Fiduciary.
Where the school is the Data Fiduciary
The school is responsible for the lawful basis on which student, parent and staff data is processed — typically consent (including verifiable parental consent for children) and the legitimate uses available to it for delivering education and running the institution. We process that data only as the school's processor, to perform our contract with the school.
Where Edulae is the Data Fiduciary
For data we collect directly, our purposes and bases are:
- Providing, securing and supporting the ScholaRise service to the school (performance of our contract and the legitimate uses connected with it).
- Account administration, billing, invoicing and tax compliance, including GST (performance of contract and compliance with law).
- Responding to enquiries, sales and support requests (consent or the legitimate use of responding to a request you make).
- Operating and improving our website, maintaining security, and preventing fraud or misuse (consent for non-essential cookies; legitimate uses for security and service operation).
- Sending service and, where you have agreed, marketing communications, which you can opt out of at any time.
- Complying with our legal obligations and establishing, exercising or defending legal claims.
07 7. How we use data
We use personal data to make ScholaRise work and to support the schools that use it. In practice this means:
- Running platform features — admissions, academics, attendance, examinations, fee and finance, transport, communications and reporting — as configured by the school.
- Authenticating users and applying the role-based access controls the school sets.
- Delivering messages and notifications the school chooses to send to parents, students or staff (for example fee reminders, results, attendance and circulars).
- Processing fee payments through payment gateways and recording the resulting transactions.
- Providing customer support and resolving issues raised by the school.
- Keeping the service secure, monitoring for abuse, diagnosing faults and maintaining backups.
- Producing aggregated and de-identified statistics to understand and improve the service; such statistics do not identify any individual.
- Meeting our legal, accounting and tax obligations.
We do not use student, parent or staff data entered by a school for our own advertising or profiling, and we do not sell personal data to anyone.
09 9. Cross-border transfers
We host and process personal data on infrastructure configured for India where available. Some of our sub-processors are global providers that may process limited data outside India in the course of delivering their services.
Where personal data is transferred or processed outside India, we do so in a manner consistent with the DPDP Act and the rules thereunder, including any restrictions the Central Government may notify on transfers to particular countries, and we require recipients to maintain appropriate safeguards. Schools that have specific data-localisation requirements should raise them with us so we can configure the service accordingly.
11 11. Data retention and deletion
For school-entered data, the school decides how long the data is kept, within the limits of its subscription and applicable law; we retain it for as long as we provide the service to the school and as the school instructs.
When a school's subscription ends, we will, on the school's instruction and within a reasonable period, return or delete the school's data, except where we are required by law to retain certain records (for example tax and accounting records) or need to retain limited data to establish, exercise or defend legal claims. Backups are deleted on a rolling cycle.
For data for which we are the Data Fiduciary, we keep it only for as long as necessary for the purposes set out in this policy or as required by law, after which we delete or anonymise it.
12 12. Security
We maintain reasonable security practices and procedures designed to protect personal data against unauthorised access, disclosure, alteration and loss. These measures include encryption of data in transit and at rest, role-based access controls, network and infrastructure protections, logging and monitoring, and regular backups. Our security practices are designed to align with the reasonable security practices expected under the SPDI Rules and the DPDP Act.
We describe our security measures in more detail on our Security page at /legal/security. We describe the measures we actually operate, and we do not claim any certification we do not hold.
If a personal data breach occurs, we will act in accordance with our obligations under the DPDP Act and the rules thereunder, including notifying the Data Protection Board of India and affected Data Principals where required, and we will support each affected school in meeting its own notification obligations as Data Fiduciary.
13 13. Your rights as a Data Principal
The DPDP Act gives Data Principals a set of rights. The table below summarises those rights and how to exercise them. Which entity actions a request depends on who is the Data Fiduciary for the data in question.
| Right | What it means | How to exercise it |
|---|---|---|
| Access | To obtain a summary of the personal data being processed and the processing activities relating to it. | For school-controlled data, contact your school; for data for which Edulae is the Fiduciary, contact privacy@edulae.com. |
| Correction and completion | To have inaccurate or misleading data corrected, and incomplete data completed and updated. | Same as above — the school for school-controlled data, Edulae for its own. |
| Erasure | To have personal data erased where it is no longer needed and retention is not required by law. | Request via your school (school-controlled data) or privacy@edulae.com (Edulae data). |
| Grievance redressal | To have a readily available means of registering a grievance and to a response within the time the law allows. | Contact our Grievance Officer at grievance@edulae.com (see section 14). |
| Nomination | To nominate another individual to exercise your rights in the event of death or incapacity. | Raise a nomination request with the relevant Data Fiduciary — your school or, for Edulae-held data, privacy@edulae.com. |
For most student, parent and staff data, the SCHOOL is the Data Fiduciary, so the school is the first point of contact for exercising your rights. We will assist the school promptly in giving effect to a valid request. If you remain unsatisfied after using the relevant Data Fiduciary's grievance-redressal mechanism, you may approach the Data Protection Board of India as provided under the DPDP Act.
We may need to verify your identity before acting on a request, and we may decline or limit a request where the law permits (for example where a request is manifestly unfounded or where retention is legally required).
14 14. Grievance redressal and data-protection contact
We have designated a Grievance Officer as required under the SPDI Rules and to handle Data Principal grievances under the DPDP Act. If you have a concern or complaint about how your personal data is handled, you can reach us as follows:
- Grievance Officer: [to confirm: name of the Grievance Officer], reachable at grievance@edulae.com.
- Data-protection / privacy queries: privacy@edulae.com.
- Security matters: security@edulae.com.
We will acknowledge and respond to grievances within the timelines required by applicable law. If your concern relates to data that your school controls, please also raise it with the school, as the school is the Data Fiduciary; we will coordinate with the school to resolve it.
If you are not satisfied with our response, you have the right to approach the Data Protection Board of India in accordance with the DPDP Act and the rules thereunder.
15 15. Changes to this policy
We may update this policy from time to time to reflect changes in our service, our sub-processors, or the law. When we make material changes, we will update the date at the top of this page and, where appropriate, notify schools through the platform or by email. We encourage you to review this page periodically.
16 16. Contact and company details
This policy is issued by Edulae Technologies Private Limited, a company incorporated under the Companies Act, 2013 and the operator of ScholaRise.
- Legal entity
- Edulae Technologies Private Limited
- CIN
- [to confirm: CIN]
- GSTIN
- [to confirm: GSTIN]
- Registered office
- Paonta Sahib, Sirmaur District, Himachal Pradesh, India — [to confirm: full registered address]
- General enquiries
- hi@edulae.com
- Support
- support@edulae.com
- Privacy / data protection
- privacy@edulae.com
- Grievance Officer
- grievance@edulae.com ([to confirm: name of the Grievance Officer])
- Security
- security@edulae.com
This page is provided for transparency and general information. It is not legal advice, and it does not create any contractual or other relationship beyond what it expressly states. If anything here conflicts with a signed agreement between your institution and Edulae Technologies, that agreement governs.