EduManage

Privacy and data protection

Return to login

Privacy Notice

EduManage Privacy Notice

This notice explains how personal data is handled when an educational institution uses EduManage for administration, learning, workforce, security and financial operations.

Version 2026.3Effective 10 August 2026

This notice explains how personal data is handled when an educational institution uses EduManage for administration, learning, workforce, security and financial operations.

Education and people

Student, guardian, staff, enrollment, attendance, assessment and progression records.

Administration and finance

Institutional assignments, fees, payments, receipts, waivers and balances.

Identity and security

Accounts, scope, sessions, acknowledgements, access decisions and audit evidence.

Acknowledgement is not blanket consent. Acknowledgement records that this notice was made available and reviewed. It is not blanket consent for optional processing, and it does not replace any separate consent that applicable law requires.

Who is responsible and how roles are divided

The organization or educational institution that provides your account normally decides why and how its student, guardian, staff, academic and financial records are used. It is responsible for its instructions, lawful authority, notices, privacy contacts, retention schedule and responses to individual requests. The party operating the EduManage deployment and its authorized providers handle data to host, support and secure the configured service, subject to their agreement and any independent legal duties.

  • System administrators manage the deployment and tenant configuration. Organization administrators and delegated staff manage records only within their permitted organization, institution, campus and screen scope.
  • Selecting a different institution or campus changes the authorized operational scope; it does not merge ownership of records between organizations.
  • If another notice supplied by your institution gives more specific information, read it together with this platform-wide notice.

Personal data and where it comes from

Data is provided by students, guardians, staff and authorized institutional users; generated through education and administration workflows; received from approved imports or service providers; and created by account, security and audit activity. The exact fields depend on the modules enabled by the institution.

  • Identity and contact data: names, usernames, email addresses, telephone numbers, postal addresses, dates of birth, gender where configured, photographs and internal identifiers.
  • Relationship and scope data: organization, institution, campus, department, program, batch, semester, section, guardian relationship, staff reporting line, designation, role and assignment.
  • Education data: admission and enrollment identifiers, subjects, attendance, correction requests, assessments, marks, results, academic progression, alumni status and related history.
  • Workforce data: employee identifiers, joining details, professional or regulatory identifiers, assignments, attendance, leave and employment-related history.
  • Financial data: fee structures, scholarships or waivers, invoices, receipts, payment mode, payment status, balances and payment-provider transaction references.
  • Account and technical data: authentication and session identifiers, notice acknowledgements, access decisions, security and audit events, timestamps, correlation identifiers, and IP, browser or request metadata available to the deployment.

Government and high-risk identifiers

Aadhaar, PAN, faculty, AICTE or similar identifiers must be collected only when the institution has a documented, lawful and necessary purpose. Access should be limited to users whose duties require it, and such identifiers must not be copied into free-text notes, exports or messages without authorization.

  • Aadhaar is not generally mandatory for school admission. Where Aadhaar is not legally required, the institution should accept an authorized alternative identity document and explain whether providing Aadhaar is voluntary.
  • Do not enter Aadhaar authentication biometrics, payment card PINs, card verification codes, passwords or one-time passwords into EduManage fields.
  • Users must not place identity numbers in filenames, public reports or other locations that expose them beyond the approved purpose.

Why personal data is used

Personal data is used only for specified educational, administrative, workforce, financial, safety and security purposes authorized by the institution or applicable law. Depending on the context, processing may be necessary to provide educational services, administer an institutional or employment relationship, perform a legal or public function, protect users, comply with law, or carry out an activity covered by valid consent.

  • Manage admissions, enrollment, regulation mappings, departments, teaching assignments, attendance, assessments, results, progression, alumni records and student support.
  • Manage staff directories, reporting lines, duties, attendance, leave, delegated access and institutional compliance.
  • Create fee structures, invoices, payments, receipts, scholarships, waivers, balances and authorized financial reports.
  • Authenticate users, preserve tenant isolation, enforce role and assignment-based access, prevent misuse, investigate incidents, recover accounts and maintain reliable audit evidence.
  • Produce approved reports, templates, exports and records needed for education, accreditation, safeguarding, accounting, tax, audit, dispute resolution or lawful reporting.
  • Obtain separate consent before an optional use that relies on consent, such as unrelated promotion or optional disclosure, and allow that consent to be withdrawn through the stated channel.

Access, service providers and disclosure

Personal data is available only to authorized users with an institutional responsibility and an appropriate data scope. Access is not granted merely because a person works for the institution. The institution may appoint service providers to perform defined functions under contractual and security restrictions.

  • Providers may support hosting, backup, email, SMS, payment processing, document generation, monitoring or technical support. They receive only the data needed for the assigned service.
  • Data may be disclosed to regulators, auditors, accreditation bodies, examination bodies, receiving institutions, professional advisers, courts or public authorities when authorized, necessary or legally required.
  • Student or staff records are not sold through EduManage and are not used by the application for unrelated targeted advertising.
  • The institution should identify material categories of recipients and, where applicable, provide the names or other details required when responding to an access request.

Data location and international transfers

The storage and support locations depend on the institution's deployment and contracted providers. Data may be accessed or processed from another state or country only where the institution and deployment operator have authorized it and applicable transfer restrictions, contracts and safeguards are satisfied.

  • Ask the institution for the locations and providers applicable to its deployment.
  • A legal or government restriction on transfer takes precedence over a configured service arrangement.

Essential cookies, sessions and communications

EduManage uses essential cookies or equivalent browser storage to authenticate users, protect requests, preserve the selected organization scope and maintain account security. These mechanisms are necessary for the requested service and are not used for unrelated advertising.

  • Security and operational messages may be sent to a registered email address, including activation, verification, password recovery and incident communications.
  • Do not share activation links, password-reset links, verification codes or active browser sessions.

Children and guardian authority

Student data may relate to children. The institution must verify parent or lawful-guardian authority and obtain verifiable consent where applicable law requires it, unless an authorized exception applies. Processing must not be detrimental to a child's well-being.

  • Guardian access is limited to the related student and should be reviewed, expired or revoked when authority changes or the student becomes entitled to act independently.
  • EduManage does not use children's data for targeted advertising. Any monitoring used for education, attendance, safety or safeguarding must remain within the institution's lawful purpose and applicable exemption or consent requirements.
  • A parent, guardian or adult student may be asked to provide evidence of identity and authority before records are disclosed or changed.

Imports, exports, reports and printed records

Authorized users may enter records, upload approved XLSX templates, download templates and reports, or create PDF and print outputs. Validation reduces accidental import errors but does not transfer responsibility for the source file or an exported copy.

  • Bulk workbooks are checked for file type, template structure, required values, academic references and duplicates before an accepted preview is saved in one transaction.
  • Rejected workbooks are not imported. Validation messages identify affected rows so the authorized uploader can correct the source.
  • Profile photographs are restricted to configured image types and size limits.
  • After a file, report, receipt or printout leaves EduManage, its recipient must store, share and dispose of it according to institutional access and retention rules.

Retention, account closure and deletion

The institution sets documented retention periods according to the purpose of each record and applicable education, accreditation, employment, accounting, tax, safeguarding, dispute and legal obligations. Data should be erased, anonymized or securely disposed of when its purpose is no longer served and retention is not legally required.

  • Final qualifications, transcripts or alumni records may need extended or permanent retention. Other categories should not automatically inherit that period.
  • Audit, approval and correction histories may remain after a current value changes so the institution can establish who acted, when and why.
  • Closing an account stops future access but may not erase institutional records that must be retained. Backup copies age out under the deployment's backup and recovery schedule.
  • A legal hold, investigation or active dispute may temporarily prevent deletion. Downloaded copies remain under the recipient's control.

Your choices and privacy rights

Subject to the law that applies and any permitted exception, an individual may ask for information about processing, access to personal data, correction, completion or updating of inaccurate data, erasure when retention is no longer required, and grievance redressal. Under India's DPDP framework, an individual may also nominate another person to exercise applicable rights in the event of death or incapacity.

  • Where processing relies on consent, you may withdraw it through the channel identified by the institution. Withdrawal does not invalidate earlier lawful processing; an optional service may stop if its required data can no longer be processed.
  • Submit requests first through the institution's published privacy, grievance or administration channel. The institution may verify identity, authority and the scope of the request before acting.
  • If a grievance is not resolved through the institution's process, you may approach the competent authority or Data Protection Board when the applicable law permits and its required process has been followed.
  • Portability, restriction or objection rights apply only where the governing law provides them; they are not represented as universal rights by this notice.
  • Academic judgment, marks review, employment decisions and fee disputes may follow separate institutional appeal procedures even when the underlying personal data is accurate.

Security and personal data breaches

EduManage supports tenant and scope isolation, role and screen permissions, password and session controls, encryption in transit, security logging, technical-failure auditing and controlled administrative access. Institutions and deployment operators must apply reasonable technical and organizational safeguards appropriate to their environment. No system can eliminate all risk.

  • Report suspected unauthorized access, an incorrectly scoped record, a lost export, a compromised account or an unexpected disclosure immediately through the institution's incident or support channel.
  • When applicable law requires it, the responsible institution or deployment operator will notify affected individuals and the competent authority, describing the incident, likely consequences, mitigation steps, safety recommendations and a contact point.
  • Submitted registers and approved workflow decisions use controlled correction or review paths rather than silent replacement, and accepted bulk imports are committed atomically to reduce partial-record failures.

Demonstration and non-production environments

When a Demo Mode or Sample environment banner is displayed, the environment is intended only for demonstrations, training or testing. Do not enter real personal, financial, authentication, health, biometric or confidential institutional information.

Changes to this notice

The version and effective date identify the notice presented to you. A material change creates a new canonical content hash and requires organization users to acknowledge the new version at sign-in. Acknowledgement remains evidence of notice, not consent to an optional purpose.

  • Earlier acknowledgement evidence is retained so the institution can establish which version was presented and when.
  • Where a change affects consent-based processing, the institution must address that consent separately rather than treating notice acknowledgement as approval.

Contact and complaints

For the identity and contact details of the responsible institution, its privacy or grievance contact, exact retention periods, or an institution-specific request, use the contact channel published by your institution. Platform-support requests should normally be raised through the institution so identity and authority can be verified.

  • Include enough information to identify the account and record concerned, but do not send passwords, one-time codes, card-security values or unnecessary identity-document copies.
  • For a security incident, use the institution's urgent incident channel rather than waiting for an ordinary records request.

Regulatory framework

Applicable requirements depend on the institution, deployment, data location and individuals concerned. They may include India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 as their provisions commence, the Information Technology Act and applicable rules, Aadhaar requirements, and education, employment, accounting, tax and records laws. Other deployments may also be subject to laws such as the GDPR, FERPA, COPPA or local equivalents. Institution-specific legal advice and notices take precedence where required.

For the identity and contact details of the responsible institution, its privacy or grievance contact, exact retention periods, or an institution-specific request, use the contact channel published by your institution. Platform-support requests should normally be raised through the institution so identity and authority can be verified.