Last updated: February 24, 2026

Privacy Policy

Your trust matters to us. This policy explains how EdPayU collects, uses, stores, and protects your personal data in compliance with Indian law.

Section 01

Information We Collect

EdPayU is a school management platform designed for Indian educational institutions. In the course of providing our services, we collect and process the following categories of personal data:

Institution Data

School or institution name, registered address, board affiliation (CBSE, ICSE, State Board, etc.), UDISE code, contact details, and administrative information required for account setup and service delivery.

Student Data

Student name, date of birth, class and section, roll number, attendance records, examination grades and marks, parent/guardian details, and any additional academic information managed through the platform.

Teacher & Staff Data

Name, phone number, email address, academic qualifications, employment details, salary and payroll information, attendance records, and class/subject assignments.

Parent Data

Parent or guardian name, phone number, WhatsApp number, email address, and relationship to the student. This information is used for communication and fee payment purposes.

Payment Data

Fee payment records and transaction history. All payment processing is handled securely by Razorpay, our PCI-DSS compliant payment gateway. EdPayU does not store credit card numbers, debit card numbers, or bank account details on its servers.

Usage Data

Device information (type, operating system), IP address, browser type and version, pages visited, time spent on the platform, and general interaction patterns. This data is collected automatically to improve our services.

Section 02

How We Use Your Information

We process your personal data for the following legitimate purposes:

  • Provide school management services -- including attendance tracking, exam management, timetable scheduling, homework assignment, certificate generation, admissions management, HR & payroll, and transport management.
  • Send notifications -- via WhatsApp, SMS, and in-app messages to keep parents, teachers, and students informed about attendance, fees, exams, homework, events, and other academic updates.
  • Process fee payments -- securely through our integrated Razorpay payment gateway, including generating fee receipts, tracking payment history, and sending payment reminders.
  • Generate reports and analytics -- including attendance reports, exam analytics, fee collection summaries, and institutional performance dashboards to help schools make data-driven decisions.
  • Improve our platform -- by analysing usage patterns, identifying areas for enhancement, fixing bugs, and developing new features that better serve educational institutions.
Section 03

Data Sharing

We share your data only with trusted third-party service providers who are essential to delivering our platform. Each provider is bound by contractual obligations to protect your data:

  • Razorpay -- for secure payment processing. Razorpay is PCI-DSS Level 1 compliant and regulated by the Reserve Bank of India (RBI).
  • MSG91 -- for SMS and WhatsApp message delivery. Used to send attendance alerts, fee reminders, exam notifications, and other communications to parents, teachers, and staff.
  • Google Analytics -- for aggregated, anonymised usage analytics that help us understand how our platform is used and where we can improve.
  • Microsoft Clarity -- for session replay and heatmap analytics to improve user experience.

We Do NOT Sell Your Data

EdPayU does not sell, rent, or trade personal data to third parties for advertising, marketing, or any other commercial purpose. Your data is used solely for the purpose of delivering and improving our school management services.

Section 04

Data Storage & Security

We take the security of your data seriously and implement industry-standard measures to protect it:

  • Data residency -- All data is stored on secure cloud servers located within India, in compliance with Indian data localisation requirements.
  • Encryption in transit -- All data transmitted between your device and our servers is encrypted using HTTPS/TLS protocols.
  • Encryption at rest -- Data stored on our servers is encrypted at rest using AES-256 encryption.
  • Role-based access control (RBAC) -- Access to data within the platform is strictly controlled based on user roles (Principal, Teacher, Student, Parent, Board Admin). Each role can only access data relevant to their function.
  • Regular security audits -- We conduct periodic security assessments and vulnerability testing to ensure our infrastructure remains secure.
  • Secure authentication -- User accounts are protected with OTP-based phone authentication and JWT-based session management.
Section 05

Children's Data

As a school management platform, we recognise the sensitivity of processing data belonging to minors. We take the following approach:

Institutional Responsibility

Educational institutions that use EdPayU are the Data Fiduciaries (data controllers) for student information under the Digital Personal Data Protection (DPDP) Act, 2023. EdPayU acts as a Data Processor, processing student data solely on behalf of and under the instructions of the institution.

  • We process student data only as directed by the educational institution and for the purposes of providing school management services.
  • Institutions are responsible for obtaining any necessary consents from parents or guardians before uploading student data to the platform.
  • Parents or guardians can request access to, correction of, or deletion of their child's data by contacting their respective educational institution directly.
  • We do not use children's data for advertising, profiling, or any purpose beyond the educational services requested by the institution.
Section 06

Your Rights

Under the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000, you have the following rights regarding your personal data:

  • Right to access -- You have the right to obtain confirmation of whether your personal data is being processed and to access a summary of your data.
  • Right to correction -- You have the right to request correction of inaccurate or incomplete personal data, and to have outdated data updated.
  • Right to erasure -- You have the right to request deletion of your personal data, subject to any legal obligations that may require us to retain certain information.
  • Right to grievance redressal -- You have the right to file a complaint with our Grievance Officer or, if unresolved, with the Data Protection Board of India established under the DPDP Act, 2023.
  • Right to nominate -- You have the right to nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity, as provided under the DPDP Act, 2023.

To exercise any of these rights, please contact us at privacy@edpayu.com. We will respond to your request within 30 days.

Section 07

Cookies

EdPayU uses cookies and similar technologies to ensure the proper functioning of our platform and to improve your experience:

  • Essential cookies -- Required for session management, authentication, and core platform functionality. These cookies are strictly necessary and cannot be disabled.
  • Analytics cookies -- Used by Google Analytics and Microsoft Clarity to collect anonymised usage data, helping us understand how users interact with our platform and identify areas for improvement.

No Advertising Cookies

EdPayU does not use any advertising or tracking cookies. We do not serve ads on our platform, and we do not allow third-party advertisers to place cookies on your device through our services.

Section 08

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy:

  • Active accounts -- Data is retained for as long as the institution's account remains active and the services are in use.
  • Deleted accounts -- Upon account deletion or service termination, all associated personal data is securely purged from our systems within 90 days.
  • Legal obligations -- Certain data may be retained beyond the 90-day period where required by applicable Indian law, including tax and financial regulations, or to resolve disputes and enforce our agreements.
  • Anonymised data -- We may retain anonymised, aggregated data (which cannot identify any individual) indefinitely for analytical and statistical purposes.
Section 09

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes:

  • We will update the "Last updated" date at the top of this page.
  • For significant changes, we will notify institutions through in-app notifications or email.
  • Your continued use of EdPayU after any changes constitutes acceptance of the updated policy.

We encourage you to review this page periodically to stay informed about how we protect your data.

Current Version

This policy was last updated on February 24, 2026.

Section 10

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please reach out to us through any of the following channels:

Email
privacy@edpayu.com
💬
WhatsApp
+91 80738 18604
📍
Address
Karnataka, India

For data protection related queries, you may also write to our designated Grievance Officer at privacy@edpayu.com. We aim to respond to all enquiries within 30 days.