Last updated: 16 August 2026 · Compliant with India's Digital Personal Data Protection Act, 2023
Who This Applies To
This policy covers four kinds of people who use Pathsala:
- Schools — institutions that subscribe to Pathsala to run their administration.
- School staff — administrators, teachers, librarians, accountants who log in.
- Students & parents — whose information schools enter into Pathsala.
- Marketing-site visitors — anyone browsing pathsala.org or requesting a demo.
What We Collect
From schools: institution name, registered address, GSTIN, billing details, subscription tier, and the data they enter — student records, attendance, exam marks, fee transactions, library issues, and similar operational data.
From staff: name, email, phone, employee ID, role, photograph, and login activity (last seen, IP for security auditing).
From students & parents: only what their school enters — name, date of birth, parent contact, address, attendance, marks, fee status, photographs for face-recognition attendance (with explicit school consent), GPS position where the school has enabled location-based attendance, and optional blood group and medical conditions.
From visitors: form submissions (contact form, demo requests, newsletter), and standard server logs (IP, user agent, page visited) retained for 90 days.
Why We Ask for Your School's Data
We ask only for what the software cannot run without. Every field below exists because something concrete stops working without it — not because it is useful to us. Where a field is optional, this says so.
- School name, address and GSTIN — to raise a GST-compliant tax invoice your school can actually claim, and to print your school's own name on report cards, fee receipts and your public website. Without a GSTIN we can still bill you, but not as a claimable tax invoice.
- The admin's email and phone number — this is the account owner's login. It is what a password reset goes to, what payment receipts go to, and how we reach you about expiry or downtime. We do not use it for marketing.
- Your chosen subdomain — it becomes your school's own website address and determines which database your school's data is created in. It cannot be blank because it is how the system tells your school apart from every other school.
- Student records (name, date of birth, class, parent contact) — to mark attendance against the right child, generate report cards, raise the correct fee bill, and make sure a parent sees only their own child. Date of birth drives age-based promotion and the report-card format your board requires.
- Fee and payment records — to raise bills, record what was paid, produce GST receipts, and reconcile against the payment gateway. Indian tax law also requires us to keep these.
- Staff records (name, role, employee ID) — to decide who can see what. A class teacher sees only their own classes; an accountant sees fees but not exam marks. Without a role, the permission system cannot restrict anything.
- Attendance signals — only the ones your school switches on. Covered in detail in the next section.
- Blood group and medical conditions — optional. These fields exist so a school can reach the right care in an emergency. They are never required, and a school that leaves them blank loses no functionality.
We do not ask for Aadhaar numbers, caste, religion, or income. The software has no field for them and no feature that uses them.
Location and Attendance Data
Some attendance features record where a person is. These are off unless your school turns them on, and they are the only features in Pathsala that use location.
- Position when attendance is marked — if your school enables GPS attendance, the coordinates at the moment of marking are stored alongside that attendance record, so the school can confirm the person was at school rather than marking from home. It is kept for as long as the attendance record itself.
- Live location sharing — when a school enables it, the student, teacher and staff apps upload their current position roughly every three minutes while sharing is active. This is what lets a school see its staff roster on a map, and lets a parent see their own child on the Parent app. These live location points are automatically deleted after 7 days.
- Who can see it — school staff with the relevant permission, and a parent for their own child only. Students cannot see anyone else's location. It is never shared outside the school and never sold.
- Face and fingerprint attendance — where a school enables it, what is stored is an encrypted mathematical template derived from the face, not a usable photograph, and it stays in that school's own database. Fingerprint verification happens on the person's own device; the fingerprint itself never reaches our servers.
Each of these can be switched off by the school at any time from the attendance settings, and switching one off stops the collection.
How We Use It
- To deliver the service the school is paying for
- To send transactional emails (welcome, password reset, fee receipts, exam results)
- To process payments via authorised payment gateways
- To improve the platform — aggregate, anonymised usage metrics only
- To respond to support requests
- To meet legal obligations under Indian law
What We Do Not Do
- We do not sell, rent, or trade your data. Ever.
- We do not advertise inside the platform. There are no banner ads and no third-party tracking pixels on the school portal, on any school's own website at {school}.pathsala.org, or on any page where you log in, make a payment, or submit your details. Advertising on our public marketing website is covered separately below.
- We do not use student data to train AI models.
- We do not share data across tenants. Each school's data lives in its own isolated database.
Advertising on Our Public Website
Our public marketing pages — for example the FAQ, comparison and guide pages on www.pathsala.org — may show advertising supplied by Google. This is entirely separate from the Pathsala platform your school uses, and never appears on the pages listed in the section above.
- Third-party vendors, including Google, use cookies to serve ads based on your previous visits to this and other websites.
- Those cookies are set by the advertising provider in your own browser. They carry no school data, no student data and no account information from Pathsala. We do not send any of it to advertisers, and we will not.
- You can switch off personalised advertising in Google Ads Settings, or opt out of other vendors' cookies at aboutads.info/choices.
Multi-Tenant Isolation
Pathsala uses one database per school. A query that runs for School A can never reach School B's data — at the storage layer, not just the application layer. This is verified by automated tests and an annual third-party audit.
Where Data Lives
All data is stored on servers located in India (Mumbai region). We use AWS for primary hosting and have backups in a second Indian region. Data does not leave Indian jurisdiction except for transactional emails sent via SES.
How Long We Keep Data
- Active subscriptions: retained as long as the school's account is active.
- Cancelled subscriptions: data is retained for 30 days, then permanently deleted unless the school requests a data export.
- Marketing-form submissions: 24 months.
- Server logs: 90 days.
Your Rights Under the DPDP Act
If your data is on Pathsala — as a student, parent, teacher, or marketing-form submitter — you can:
- Request a copy of what we hold about you
- Correct anything that's wrong
- Ask for it to be deleted
- Withdraw consent at any time
- Complain to the Data Protection Board of India if we don't comply
To exercise these rights, email [email protected] with a copy of any ID. We respond within 14 days.
Security
We use HTTPS everywhere, bcrypt for password hashing, JWT with short-lived tokens for sessions, and CSRF protection on all forms. Servers are patched weekly. We run quarterly penetration tests. If you discover a vulnerability, please email [email protected].
Children
Pathsala is used by schools whose students are minors. Under the DPDP Act, processing children's personal data requires verifiable parental consent. We obtain this consent from the school as the data fiduciary, which is documented in our master service agreement.
Changes to This Policy
If we make material changes, we'll email every school admin 30 days before the change takes effect. The latest version always lives at pathsala.org/privacy-policy.
Contact
Pathsala Technologies
Meerut, Uttar Pradesh, India 250103
Email: [email protected]
Phone: +91 7719445176
