AcademyX ERP — Privacy Policy

Your Privacy Matters

We are committed to protecting the personal data of students, parents, and staff in the AcademyX School Management System.

Effective: 01 January 2026
Last Updated: 23 March 2026
Jurisdiction: India
Overview

Introduction & Scope

This Privacy Policy describes how AcademyX ERP ("AcademyX", "we", "our", or "us"), operated by Siddhu Public School, collects, uses, stores, and protects personal information when you use the AcademyX School Management System — including the web application, student portal, parent portal, and associated services.

By using AcademyX, the school management, staff, students, and parents agree to the practices described in this Policy. If you do not agree, please refrain from using the system and contact your school administrator.

This policy applies to all data processed through AcademyX regardless of whether it is collected through the admin dashboard, parent portal, student portal, mobile app, or API integrations.

Who This Applies To

This policy covers school administrators, teachers, office staff, students, and parents/guardians who interact with the AcademyX platform — either directly or through their school's subscription.

Schools & Administrators
Institutional data, branch configuration, academic year setup, user access control.
Staff & Teachers
Employment details, subject assignments, contact information, login credentials.
Students
Admission records, academic performance, fee transactions, and personal details.
Parents / Guardians
Contact details, payment records, portal access logs, and communication history.
Data Collected

Information We Collect

We collect the following categories of personal data, depending on your role:

CategoryExamplesCollected From
Identity DataFull name, date of birth, gender, photograph, Aadhaar/ID numberSchool registration forms
Contact DataMobile number, email address, home address, WhatsApp numberAdmission forms, staff records
Academic DataClass, section, marks, grades, rank, attendance recordsExam system, teacher entry
Financial DataFee amounts, payment dates, challan numbers, bank details (cheque/DD)Fee collection module
Technical DataIP address, browser type, session tokens, login timestampsAutomatic collection on login
Usage DataPages visited, actions performed, time spent on modulesApplication server logs
Communication DataSMS/email notification logs, parent portal messagesNotification system
Sensitive Personal Data

Financial information (bank account details, cheque numbers) and government-issued ID numbers are treated as Sensitive Personal Data (SPD) under the Indian IT Act and are subject to heightened protection measures.

How We Use It

Purpose & Legal Basis for Processing

PurposeData UsedLegal Basis
Student Admission & Enrollment Identity, contact, academic data Contract
Fee Collection & Invoicing Identity, financial data Contract
Exam Management & Results Academic data, identity Legal Obligation
AI-Assisted Answer Evaluation Answer scripts (anonymised where possible) Consent
Parent/Student Portal Access Identity, academic, financial data Contract
SMS / Email Notifications Contact data, fee/exam data Legitimate Interest
System Security & Fraud Prevention Technical, usage data Legal Obligation
Analytics & Reporting (Internal) Aggregated, anonymised data Legitimate Interest
TC & Student Discontinuation Records Identity, academic, status data Legal Obligation
Audit Logs & Compliance All data categories (log records) Legal Obligation
Sharing

Data Sharing & Disclosure

We do not sell, rent, or trade personal data to third parties. Data may be shared only in the following circumstances:

  • Within your School: Authorised staff (admin, teachers, accountants) access data relevant to their role only, enforced by our role-based access control (RBAC) system.
  • Service Providers: We engage trusted vendors (hosting, SMS gateway, email service) under strict data processing agreements who may not use the data for their own purposes.
  • Analytics Portal (Siddhu Analytics): Exam results, fee summaries, and class strength data may be synced to the associated analytics server for cross-school reporting. Only aggregated or role-appropriate data is transferred.
  • AI Processing (Anthropic Claude): For AI-assisted exam evaluation, anonymised answer scripts are sent to Anthropic's API. No personally identifiable student information is included in these requests.
  • Legal Compliance: We may disclose data to comply with applicable law, court orders, or requests from government authorities under Indian law.
  • Business Transfer: In the event of a merger, acquisition, or asset sale, personal data may be transferred. Users will be notified in advance.
We Never

Sell student or parent data to advertisers. Share financial data (bank details, cheque numbers) with any third party except your school's authorised bank. Use student data for marketing purposes without explicit consent.

Storage & Security

Data Storage & Security

Encryption at Rest
All database records containing personal or financial data are encrypted at rest using AES-256.
HTTPS / TLS in Transit
All communications between your browser and AcademyX servers are encrypted via TLS 1.2+.
Access Control (RBAC)
Role-based permissions ensure each user accesses only the data their role requires.
Audit Logs
All data access, modifications, and deletions are logged with timestamps and user ID for compliance.
Regular Backups
Automated daily backups with 30-day retention. Backups are stored in an encrypted, geographically separate location.
Breach Response
In the event of a data breach, affected schools and users will be notified within 72 hours as required by applicable law.

Data is hosted on servers within India. Any transfer of data outside India (e.g., AI processing via Anthropic's API for exam evaluation) is done with appropriate contractual safeguards and data is anonymised before transfer where technically feasible.

Retention

Data Retention Periods

Data TypeRetention PeriodReason
Student Academic Records10 years after graduation / TC issuanceLegal requirement for educational records in India
Fee Transaction Records8 years from transaction dateFinancial audit & IT compliance
Staff Employment Records7 years after leaving serviceLabour law compliance
Login & Audit Logs3 yearsSecurity audit and compliance
Parent Portal AccountsDuration of student enrollment + 2 yearsService continuity
SMS / Email Logs1 yearCommunication audit trail
Exam Answer Scripts (AI eval)1 academic year after result publicationRe-evaluation and grievance purposes
Cancelled Receipts / TC Records10 yearsAudit trail, legal evidence
Backup Data30 days rollingDisaster recovery
Data Deletion Requests

You may request deletion of your personal data where there is no legal obligation to retain it. Requests are reviewed within 30 days. Note that student academic records and fee transactions cannot be deleted while a legal retention obligation applies.

Cookies

Cookies & Session Data

AcademyX uses cookies and browser session storage to operate the application. We do not use advertising or tracking cookies.

No Third-Party Trackers

AcademyX products do not use Google Analytics, Facebook Pixel, or any other third-party advertising or tracking cookies. Your school data stays within the AcademyX system.

Your Rights

Your Rights & Choices

Under applicable Indian data protection law and as a matter of policy, you have the following rights with respect to your personal data:

👁️
Right to Access
Request a copy of all personal data we hold about you or your child.
✏️
Right to Rectification
Request correction of inaccurate or incomplete personal data.
🗑️
Right to Erasure
Request deletion of data where no legal obligation requires retention.
📦
Right to Portability
Receive your data in a structured, machine-readable format (Excel/CSV export).
🚫
Right to Object
Object to processing based on legitimate interest (e.g., marketing communications).
⏸️
Right to Restrict
Request restriction of processing while a dispute over accuracy or lawfulness is resolved.
🤖
Right re: Automated Decisions
Request human review of any automated AI-based exam scores that significantly affect your results.
📣
Right to Complain
Lodge a complaint with your school's Data Protection Officer or the relevant authority.

To exercise any of these rights, please contact your school's administrator or reach us at privacy@academyx.in. We will respond within 30 calendar days. Identity verification may be required before we act on your request.

Children

Children's Privacy

AcademyX serves schools that enroll students of all ages, including children under 18. We take extra care with data relating to minors.

  • Student data is collected and processed on behalf of the school and with implied consent from the parent/guardian at the time of admission.
  • Children cannot independently create accounts. All student portal access requires the parent/guardian to set up access using the student's admission number and date of birth.
  • We do not use children's personal data for advertising, profiling, or any purpose beyond direct educational service delivery.
  • Parents/guardians may request access to, correction of, or deletion of their child's personal data at any time by contacting the school or our support team.
  • AI-assisted exam evaluation of answer scripts submitted by minor students uses anonymised data only — student names and IDs are removed before transmission to the AI service.
Special Protection for Minors

Any school staff found misusing student data or accessing student records beyond their role will face immediate account suspension and will be reported to the school management. All access to student data is logged and audited.

Policy Changes

Changes to This Policy

v2.1
23 March 2025 — Current Version
Added section on AI-assisted exam evaluation (Anthropic Claude). Clarified data anonymisation for AI processing. Updated retention periods for answer scripts.
v2.0
01 January 2025 — Major Revision
Expanded to cover parent portal, student portal, and multi-school analytics sync. Added RBAC section. Aligned with updated IT Rules 2021 requirements.
v1.0
01 April 2024 — Initial Release
First published privacy policy covering core ERP modules — admissions, fees, and staff management.

We may update this Privacy Policy periodically. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Display a banner notification on login for school administrators.
  • Send an email notification to registered admin accounts for significant changes.

Continued use of AcademyX after the effective date of updated policy constitutes acceptance of the changes.

Contact

Contact Our Privacy Team

For any questions about this Privacy Policy, to exercise your data rights, or to report a concern, please use the following contacts:

🔒 Privacy & Data Protection Contacts
Data Controller
Siddhu Public, Madurai, Tamil Nadu, India
Privacy Email
Support Email
Response Time
Within 30 calendar days
Jurisdiction
India — IT Act 2000, DPDP Act 2023
Version
v2.1 — 01 Feb 2025
How do I request my personal data?
Email privacy@academyx.in with your full name, school name, admission number (for students), and a description of the data you want. We will verify your identity and respond within 30 days with a data export in Excel/PDF format.
Can parents opt out of SMS notifications?
Yes. Contact your school's admin to update your notification preferences. Critical notifications (fee receipts, TC issuance) may not be opt-out-able as they serve contractual purposes.
Is student data shared with other schools?
No. Data is strictly school-specific. If a student transfers between schools within the Siddhu Public, only the minimum required academic data is transferred and only with the school management's authorisation.
How is AI exam evaluation handled privately?
When descriptive answers are evaluated using the Claude AI (Anthropic), the student's name and admission number are stripped from the request. Only the answer text and model answer are sent. Anthropic's API is used under a Zero Data Retention (ZDR) agreement, meaning input data is not stored or used for training by Anthropic.