This Privacy Policy explains how ShikshaSync ("we", "us", or "our") collects, uses, and protects information when you use our school management platform at shikshasync.in. By using our services, you agree to the practices described in this policy.
π’ 1. Who We Are
ShikshaSync is an AI-powered school management SaaS platform built for Indian schools and educational institutions. We provide tools for attendance management, parent-teacher communication, AI-generated academic content, and government compliance reporting.
Platform: shikshasync.in
Contact Email: someshshukla2004@gmail.com
Country of Operation: India
π 2. Information We Collect
2.1 Information You Provide
- School Administrators & Principals: Name, email address, phone number, school name, and login credentials.
- Teachers: Name, email, phone number, subjects taught, and class assignments.
- Students: Name, class, roll number, Samagra ID (if applicable), Aadhaar number (if required for government compliance), date of birth, and biometric fingerprint data (via integrated K30 devices).
- Parents / Guardians: Name, WhatsApp phone number, relationship to student, and communication preferences.
2.2 Information Collected Automatically
- Attendance records (timestamped biometric scan data from K30 fingerprint devices)
- Device status and health metrics for integrated biometric devices
- Login timestamps, IP addresses, and browser/device type for security purposes
- Usage data such as features accessed, pages visited, and interaction logs
2.3 Government & Compliance Data
For schools that use our government compliance export features, we may collect Samagra IDs, Aadhaar numbers, caste category, and other fields as required by state or central government reporting mandates. This data is collected only with explicit school administrator authorization.
π¬ 3. WhatsApp Notifications & Data Use
π WhatsApp Business API Integration
ShikshaSync uses the Meta WhatsApp Business API to send automated notifications to parents and guardians. This section explains exactly what data is used and how.
3.1 Why We Use WhatsApp
We use WhatsApp as a communication channel to deliver real-time, important school-related notifications directly to parents' phones β without requiring them to download any additional app. WhatsApp is the most widely used messaging platform in India, making it the most accessible channel for parent communication.
3.2 What Data We Send to WhatsApp / Meta
- Phone Numbers: Parent/guardian WhatsApp phone numbers are used to send messages via the WhatsApp Business API. These numbers are shared with Meta (WhatsApp's parent company) solely for message delivery.
- Message Content: Notification messages include the student's name, attendance status, timestamps, and school-relevant information. No sensitive financial or medical data is included in WhatsApp messages.
- Template IDs: We use pre-approved Meta message templates for compliance with WhatsApp Business API policies.
3.3 Types of WhatsApp Notifications We Send
- Attendance alerts (student marked present, absent, or late)
- Leave request status updates (approved or rejected)
- Replies to parent queries and complaints submitted through the portal
- School announcements, exam schedules, and event reminders
- Availability of new AI-generated study notes for the student
- Account-related notifications (registration, OTP verification)
3.4 Consent for WhatsApp Notifications
Parents and guardians provide consent for WhatsApp notifications during the school onboarding process. By providing their WhatsApp phone number to the school, and by the school registering that number in ShikshaSync, parents indicate their consent to receive automated notifications from ShikshaSync on behalf of their school.
Parents may opt out of non-critical WhatsApp notifications at any time by contacting their school administrator or by replying "STOP" to any ShikshaSync WhatsApp message.
3.5 Meta / WhatsApp Data Processing
When we send messages via the WhatsApp Business API, Meta processes the message delivery. Meta's data handling is governed by their own WhatsApp Privacy Policy and Meta Privacy Policy. ShikshaSync does not sell or share personal data with Meta for advertising purposes.
3.6 Phone Number Data Security
Parent phone numbers stored in ShikshaSync are encrypted at rest and are never sold, rented, or shared with any third party other than Meta/WhatsApp for the sole purpose of message delivery as described above.
βοΈ 4. How We Use Your Information
We use the information we collect for the following purposes:
- Providing, maintaining, and improving the ShikshaSync platform
- Processing and displaying attendance records
- Sending WhatsApp notifications to parents on behalf of schools
- Generating AI-powered academic content using Google Gemini
- Enabling parent-teacher-admin communication through the ticketing system
- Generating government compliance reports and data exports
- Authenticating users (OTP login, Google OAuth)
- Providing multi-role dashboards (Principal, Teacher, Parent, Student)
- Detecting and preventing fraud, abuse, and security incidents
- Complying with applicable Indian laws and regulations
We do not use your data for advertising, profiling, or selling to third parties.
π€ 5. Data Sharing & Third Parties
ShikshaSync shares data with third-party services only to the extent necessary to provide our platform services:
5.1 Third-Party Services We Use
- Meta / WhatsApp Business API: For sending parent notifications (see Section 3)
- Google (Gemini AI): For AI-powered content generation. Content prompts and school subject data may be processed by Google Gemini API. No student PII is sent to Gemini.
- Google OAuth: For optional Google account sign-in. Governed by Google's Privacy Policy.
- Bhashini / ULCA API (Government of India): For Indian language translation and speech services. Operated by the Ministry of Electronics & IT, Government of India.
- Google Cloud Translation: Fallback language translation service.
- Amazon Web Services (AWS S3): For secure cloud storage of generated PDF documents.
5.2 We Do Not Share Data With
- Advertisers or marketing platforms
- Data brokers
- Any party not listed in Section 5.1
5.3 Legal Disclosure
We may disclose personal data if required to do so by law, court order, or governmental authority in India.
π 6. Data Storage & Security
ShikshaSync takes the security of your data seriously. We implement the following measures:
- Authentication: HS384-signed JSON Web Tokens (JWT) with 90-day expiry for all user sessions
- Encryption: Passwords and sensitive fields encrypted at rest
- Access Control: Role-based access ensures each user can only access data they are authorized for
- Rate Limiting: API rate limiting prevents abuse and brute-force attacks
- Circuit Breakers: Resilience mechanisms prevent cascading failures
- Database: PostgreSQL with school-level data isolation
- Transport: All data transmitted over HTTPS/TLS
Data is stored on servers located in India or within compliant cloud regions.
ποΈ 7. Data Retention
We retain personal data for as long as your school account is active with ShikshaSync. Specifically:
- Student data: Retained for the duration of the student's enrollment plus 3 years, or until the school requests deletion.
- Attendance records: Retained for a minimum of 5 years in accordance with standard educational record-keeping practices.
- Parent communication data: Retained for 2 years after the last interaction.
- Account data: Retained until account deletion is requested by the school administrator.
Upon school account termination, all personal data is securely deleted within 30 days unless retention is required by law.
β 8. Your Rights
Under applicable Indian data protection laws and best practices, you have the following rights:
- Right to Access: Request a copy of the personal data we hold about you or your child
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Deletion: Request deletion of personal data (subject to legal retention requirements)
- Right to Opt-Out: Opt out of non-essential WhatsApp notifications at any time
- Right to Portability: Request your data in a structured, machine-readable format
To exercise these rights, contact your school administrator, who can process the request through ShikshaSync. Alternatively, contact us directly at someshshukla2004@gmail.com.
πΆ 9. Children's Privacy
ShikshaSync serves schools that manage student data, which includes data of minors. We collect and process student data solely on behalf of the school, which acts as the data controller. Schools are responsible for obtaining appropriate parental consent for data collection in accordance with applicable laws.
We do not knowingly collect or market to children directly. All student-facing features are provided through the school's institutional account.
πͺ 10. Cookies & Analytics
The ShikshaSync web application uses the following types of cookies and local storage:
- Authentication Tokens: JWT tokens stored in browser local storage to maintain your login session
- Preferences: UI preferences such as language selection and theme
- Session Cookies: Temporary cookies required for application functionality
We do not currently use third-party advertising or tracking cookies. We may use basic analytics to understand platform usage and improve our services.
π 11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify school administrators via email or in-app notification
Continued use of ShikshaSync after changes are posted constitutes acceptance of the updated policy. We encourage you to review this page periodically.