S T D M INTER COLLEGE SORON — Your privacy matters to us
PRIVACY POLICY
protecting the privacy and personal data of all Users of the Easy Education
Digital School Management Platform ("Platform").
we collect, how we use, store, and protect that information, and the rights
Users have regarding their data.
Teachers, Principals, and Administrators, as well as visitors to the
Platform's public-facing pages (news, gallery, online registration).
DESCRIBED IN THIS POLICY. IF YOU DO NOT AGREE WITH THIS POLICY, YOU MUST
DISCONTINUE USE OF THE PLATFORM.
govern the overall use of the Platform.
- Full name (first name, last name)
- Student ID and Sr. No.
- Class, section, and roll number
- Date of birth and gender
- Father's name and mother's name
- Phone number and email address
- Residential address
- Apaar ID(if available)
- Profile picture
- Full name
- Teacher ID
- Qualifications, age, and gender
- Subject specialization
- Father's name and mother's name
- Phone number and email address
- Residential address
- Profile picture
- Full name
- Email address and phone number
- Role designation
- Account creation and modification timestamps
- Marks and test results
- Attendance records
- Homework assignments and submissions
- Subject enrollments
- Scholarship records
- Class assignments
- Profile pictures
- Certificate documents (Transfer Certificates, Character Certificates)
- Admit cards with QR codes
- Homework attachments (images)
- Gallery images
- Digital book files and pages
- Fee payment receipts (generated PDFs)
- Site logo and branding assets
- IP address at time of login
- Login timestamp and logout timestamp
- Session duration
- User-Agent string (browser and device information)
- Day of the week and date of login
- Login success/failure status
- OTP verification records
- User edit logs (field changes, performed by, timestamp)
- Fee payment edits (old values, new values, edit reason, editor)
- Fee action logs (additions, deletions, modifications)
- Content management actions (news, gallery, FAQ creation/deletion)
- Certificate and admit card generation records
- App install tracking data (device info, timestamp)
- Client tracking data (IP address, user-agent, client info)
- IP block records and rate limiting events
- Applicant name, parent/guardian details
- Class applied for
- Contact information
- Referral code usage
- Registration status and approval records
- Ticket subject and message content
- Ticket type classification
- Ticket status and resolution records
of the Institution's educational and administrative functions, and
for the fulfillment of contractual obligations arising from the
User's enrollment or employment.
applicable laws, regulations, or orders of competent authorities,
including the Right of Children to Free and Compulsory Education
Act, 2009, and the Information Technology Act, 2000.
interests of the Institution, including security monitoring, fraud
prevention, and system integrity, provided such interests are not
overridden by the User's rights and freedoms.
from Users or their parent/guardian before processing data for
purposes not covered by the above bases.
relies on the consent of the parent or legal guardian, which is obtained
at the time of enrollment or registration, in accordance with applicable
law.
- Maintaining student academic records, attendance, and marks
- Generating certificates, admit cards, and reports
- Managing homework, tests, and scholarship records
- Facilitating digital library access
- User authentication and session management
- Role-based access control and authorization
- Fee payment processing and receipt generation
- Support ticket management
- Online registration processing and approval workflow
- Referral code management
- Detecting and preventing unauthorized access
- Rate limiting and brute-force attack prevention
- IP blocking for suspicious activity
- Login anomaly detection (device fingerprinting)
- CSRF and session security enforcement
- Sending OTP codes for authentication
- Sending fee payment confirmations
- Sending certificate and registration approval notifications
- Responding to support tickets
- Analyzing usage patterns and system performance
- Improving Platform features and user experience
- Generating administrative reports and analytics
- Maintaining records as required by educational regulations
- Responding to lawful requests from authorities
- Preserving evidence in case of disputes or investigations
personnel.
are not exposed in source code.
execution disabled and access controlled through a PHP intermediary
that enforces permission checks.
direct web access via server configuration.
plus seven (7) years after last attendance, or as required by
applicable educational regulations.
of creation, after which they may be automatically purged.
from the date of transaction, in compliance with financial and
tax regulations.
of the logged action.
processing, unless the applicant enrolls, in which case the data
is incorporated into the student record.
thirty (30) days after expiration.
securely deleted or anonymized, except where retention is required
by law.
THE PERSONAL DATA OF ANY USER TO ANY THIRD PARTY.
teachers, principals, and administrators as necessary for the
performance of their official duties, strictly on a need-to-know
basis consistent with their assigned role.
regulation, court order, or governmental authority, including but
not limited to:
- Responses to lawful subpoenas, court orders, or legal process;
- Compliance with educational regulatory requirements;
- Cooperation with law enforcement investigations.
rights, safety, or property of the Institution, its Users, or
the public, including fraud prevention and security incident
response.
assist in operating the Platform (e.g., email delivery services
for OTP and notification emails, hosting providers), subject to
contractual obligations of confidentiality and data protection.
marketing, advertising, or commercial purposes under any circumstances.
User data:
- Role-based access control (RBAC) with four defined roles:
Student, Teacher, Principal, Administrator
- Session-based authentication with secure cookie parameters
(HttpOnly, Secure, SameSite=Lax)
- Multi-factor authentication via OTP for login verification
- Strict mode session management to prevent session fixation
- Device fingerprinting for login anomaly detection
- Password hashing using bcrypt (PASSWORD_BCRYPT) via PHP's
password_hash() function
- CSRF token generation and validation for all state-changing
operations
- Prepared statements (parameterized queries) for all database
operations to prevent SQL injection
- Output encoding (htmlspecialchars) to prevent cross-site
scripting (XSS)
- Path traversal protection for file access
- File upload validation (type, size, content verification)
- Server-side script execution disabled in upload directories
- Sensitive directories blocked from direct web access
- Security headers (X-Content-Type-Options, X-Frame-Options,
Referrer-Policy, Permissions-Policy)
- Rate limiting and brute-force protection for authentication
- IP blocking for suspicious activity
- Error display suppressed in production; errors logged only
- Database credentials stored in environment variables, not
in source code
- Comprehensive logging of administrative actions
- Login activity tracking with IP and device information
- Edit history for fee payments and user profile changes
- Rate limiting event logging
employs industry-standard security practices but cannot guarantee
absolute security against all possible threats. Users acknowledge
this inherent limitation.
any other person;
Institution;
immediately through the support ticket system or by contacting
shared or public devices;
role privileges.
access resulting from a User's failure to comply with these
responsibilities.
authentication. These cookies are strictly necessary for the
Platform to function and cannot be disabled.
- HttpOnly: Not accessible via JavaScript
- Secure: Transmitted only over HTTPS (when available)
- SameSite=Lax: Protected against cross-site request forgery
advertising cookies, or analytics cookies from external providers.
and time, user-agent string, session duration, and day of the
week.
and administrative reporting.
Principals.
monitoring and improvement, including: page access patterns,
feature utilization, and system performance metrics.
beyond what is already collected as part of normal Platform
operation.
login attempts, rate limiting triggers, IP blocking events, and
session anomalies.
security purposes.
integrity of the Platform and its Users' data.
data held about them by contacting [email protected] or using
the Platform's support ticket system.
inaccurate or incomplete personal data. Students and Teachers
may update certain fields through their profile page on the
Platform. For other corrections, Users should contact the
Institution through the support ticket system.
personal data, subject to the following limitations:
- Data required by law or regulation to be retained cannot
be deleted until the applicable retention period expires;
- Academic records, fee payment records, and certificates
cannot be deleted during the mandatory retention period;
- Deletion of a User account may be requested but is subject
to institutional policy and administrative approval.
personal data in a structured, commonly used, and
machine-readable format, where technically feasible.
personal data on grounds relating to their particular
situation, subject to legitimate interests of the Institution.
through the Platform's support ticket system or by emailing
[email protected]. The Institution will respond to such requests
within thirty (30) days.
request before processing it, to prevent unauthorized data access.
of age). The Institution recognizes the heightened responsibility
associated with processing children's personal data.
- The student themselves (view-only access to their own data)
- Assigned teachers (limited to academic data relevant to
their classes)
- Principals and Administrators (full access for
administrative purposes)
other than those specified in Section 6.
controlled access mechanism that verifies permissions before
allowing access.
cannot modify academic records, attendance, marks, or fee
information.
legal guardian consents to the collection, processing, and
storage of the student's personal data as described in this
Policy.
parent/guardian for minors) provides consent as part of the
registration process.
contacting the Institution through official channels.
Children to Free and Compulsory Education Act, 2009, the
Protection of Children from Sexual Offences (POCSO) Act, 2012,
and the Information Technology Act, 2000, as they relate to
children's data protection.
- SMTP service via Gmail for sending OTP codes, notifications,
and institutional communications
- Email addresses used for sending: [email protected]
- SMTP credentials are stored as environment variables and are
not exposed in source code
- The Platform is hosted on a web server with PHP and MySQL
- Cloudflare is used for DDoS protection and web application
firewall (WAF) services
- PHPMailer: Email transmission
- mPDF: PDF generation for certificates and receipts
- FPDF: PDF generation for fee receipts
- PHP QR Code: QR code generation for certificates and
admit cards
- Random Compatibility Library: Cryptographic random number
generation
data handling practices. The Institution selects services that
maintain reasonable data protection standards.
third-party services and encourages Users to review the privacy
policies of such services where applicable.
equivalent responsible person to oversee data protection compliance.
protection laws;
and complaints;
Platform's support ticket system.
and compliance purposes, including:
including which fields were changed, by whom, and when;
modifications, including old and new values, edit reason,
and the identity of the editor;
deletions, and modifications;
and timing information;
FAQ creation and deletion;
all certificate and admit card issuances.
accessible only to authorized Administrators and Principals.
compliance, security, or investigative purposes.
Policy at any time at its sole discretion.
Platform or upon notification to Users through the Platform's
communication channels.
POLICY CONSTITUTES THE USER'S ACCEPTANCE OF SUCH MODIFICATIONS.
affect the processing of User data, the Institution will make
reasonable efforts to notify Users through the Platform or via
email, where feasible.
or the Institution's data practices, Users may contact:
Institution: Easy Education
Platform: Easy Education
UDISE Code: 09722102002
Website: sbintercollege.dpdns.org
Email: [email protected]
Address: Village Hodalpur, Soron, Kasganj
Platform's built-in support ticket system.
within seven (7) business days.
within thirty (30) business days of receipt.
escalate the matter to the appropriate regulatory authority
under the Information Technology Act, 2000, or the applicable
data protection authority.
support ticket system accessible at the "Support" section of the
Platform.
unenforceable, the remaining provisions shall continue in full force
and effect.
the remaining provisions of this Policy.
END OF PRIVACY POLICY