Legal

Privacy Policy

Last updated: 14 August 2026

Your school's data is not our product. This policy explains what we collect, why we collect it, and how we protect it. It is written to be read by a principal, not by lawyers.

1. What we collect

Information you give us

When your school signs up we collect the school name, its address and affiliation or registration number where you provide them, and the name, mobile number and email of the person setting it up. We ask for what the product needs to run and nothing more.

Information we collect automatically

When you use the web app we record basic usage data: IP address, browser and device information, and which pages and actions are used. This is used to find faults and to understand which parts of the product are working. We do not build advertising profiles.

School data

This is the important category. Everything your staff enter — student and guardian records, admission documents, attendance, timetables, marks and report cards, fee structures, invoices and receipts, staff records and payroll, transport allocations, notices and messages — belongs to your school. It lives in a database schema reserved for your school alone. We do not access, analyse, mine or monetise it.

Children's data

Student records describe children. We treat them as the most sensitive data in the system. We collect them only because your school enters them to run the school, we never use them for any purpose of our own, and we never disclose them to anyone outside your school except where the law compels us.

2. How we use it

We use your information to:

  • Run the web app and the parent-facing messages your school sends
  • Authenticate staff and keep sessions secure
  • Send transactional messages you have asked for — OTPs, absentee alerts, fee reminders, receipts, notices
  • Answer support requests and contact you about your account
  • Improve the product from aggregate usage patterns, never individual tracking
  • Detect and prevent abuse, fraud and security incidents
  • Meet our legal and tax obligations

What we do not do

We do not sell your data. We do not show advertising to students, parents or staff. We do not share student information with marketing partners. We do not use your school's data to train AI models.

3. One schema per school

Edmingo uses a schema-per-tenant architecture in PostgreSQL. Every school's data lives in its own database schema, separated from every other school on the same infrastructure. Which schema a request may touch is decided by the signed session on the server, never by anything the browser sends.

What that means in practice:

  • A bug in one school's screen cannot read another school's records
  • A staff account is scoped to one school and cannot be pointed at another
  • Exports and backups are per-school, so handing you your data does not involve filtering someone else's out

4. Who else sees it

We use a small number of processors to deliver the product, and each one sees only what it needs:

  • A cloud hosting provider, for the servers and database
  • An SMS provider, to deliver the text messages your school sends
  • An email relay, to deliver transactional email
  • A payment gateway, where your school collects fees online — card and bank details are handled by the gateway and never stored by us

We do not sell or rent personal information to anyone. We disclose data outside this list only when compelled by law, and where we are permitted to tell you, we will.

5. How long we keep it

We keep your school's data for as long as your account is active. If you close your account we retain it for 90 days so it can be restored if the closure was a mistake, then delete it. Financial records may be kept longer where tax law requires it, in which case they are kept only for that purpose.

You can request deletion sooner. See the data deletion page for how.

6. How we protect it

Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form. Access to production systems is limited to the engineers who need it, and administrative access is logged.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your school's data we will tell you what happened, what was affected and what we are doing about it.

7. Your rights

You can ask us to:

  • Show you what personal data we hold about you
  • Correct it if it is wrong
  • Delete it, subject to the retention rules above
  • Export your school's data in a machine-readable format

Write to [email protected] and we will respond within 30 days. For student records, requests should come from the school, since the school is the custodian of those records.

8. Contact

Questions about this policy go to [email protected].

Nextyug Technologies Private Limited

Eden Garden By Shirke, Tathawade, Pune, Maharashtra 411033, India GSTIN: 27AAKCN2107N1Z8

This page is a plain-language summary of a binding agreement. If anything here is unclear, ask us before you rely on it — get in touch.