Privacy Policy
This Privacy Policy explains how Vedorix Technologies Private Limited ("Vedorix", "Company", "we", "us", or "our"), a company incorporated under the Companies Act, 2013, with its registered office at 10, Ganga Nagar, Near Samadhan Vipati, Gangotri, Agriculture Institute, Allahabad, Allahabad – 211007, Uttar Pradesh (CIN: U62013UP2026PTC250993), collects, uses, discloses, and protects personal data in connection with the Vedorix school management platform (the "Platform"), available via web and mobile applications.
This Policy is framed in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and rules made thereunder, and other applicable Indian data protection law.
1. Scope and Who This Applies To
This Policy applies to personal data we process in connection with:
- Schools, educational trusts, and institutions ("Institution" or "Customer") that subscribe to the Platform;
- Staff, teachers, and administrators of an Institution who access the Platform under the Institution's account;
- Parents/guardians and students who access the Platform's parent portal or mobile app, as authorised by the Institution; and
- Visitors to our marketing website at vedorix.com.
2. Our Role: Data Fiduciary and Data Processor
Under the DPDP Act, the Institution is the Data Fiduciary for personal data of its students, parents/guardians, and staff that it enters into or collects through the Platform — the Institution determines the purpose and means of processing that data (e.g. maintaining academic records, collecting fees, running payroll), and is responsible for obtaining any consents required from data principals before entering their data into the Platform.
Vedorix acts as a service provider / processor, processing that data only on the Institution's behalf and instructions, to provide the Platform's functionality (hosting, storage, computation, notifications, payment processing, etc.). Where this Policy refers to "you" as a parent, student, or staff member, your primary point of contact for data-related requests is your Institution — Vedorix supports the Institution in fulfilling such requests but does not independently decide how your data is used.
For our own direct relationship with an Institution as a paying customer (billing contacts, account administrators, marketing website visitors), Vedorix is the Data Fiduciary.
3. Personal Data We Collect
3.1 Student Data (entered by the Institution)
- Identity and demographic details — name, date of birth, gender, photograph, admission number, nationality, category, religion (where an Institution's admission process requires it)
- Academic records — attendance, marks, report cards, exam results, learning outcomes, disciplinary records
- Family and contact details — parent/guardian names, phone, email, address
- Health-related information, where an Institution records it — allergies, medical conditions, disabilities, vaccination records
- Financial data related to fee payment — invoices, payment history, concessions
- Biometric/identification data where an Institution enables RFID-based attendance — a student's RFID tag mapping (Vedorix does not process fingerprint or facial biometric data as a core feature)
- Location data, where an Institution enables school bus tracking — the bus's GPS location while in transit, associated with a route a student is enrolled on
3.2 Parent/Guardian Data
- Name, contact details, relationship to student, occupation (optional, if collected by the Institution)
- Login credentials for the parent portal/app
- Payment details processed through our payment gateway partners (Vedorix does not store full card numbers — see Section 6)
3.3 Staff Data
- Identity, contact, and employment details — designation, department, date of joining, qualifications
- Payroll and statutory data — salary structure, bank account details, PAN, PF/ESI/UAN numbers, TDS records
- Attendance and leave records
- Location data for staff whose role involves school transport (e.g. drivers), while on duty
3.4 Website Visitor Data
- Contact details submitted through demo request or contact forms
- Standard web analytics — IP address, browser type, pages visited (see Section 11, Cookies)
4. How We Use Personal Data
We (as processor, on the Institution's instructions, or as fiduciary for our own customer relationship) use personal data to:
- Provide the Platform's core functionality — academics, attendance, fee collection, HR & payroll, admissions, transport tracking, library, communication, and compliance modules
- Send transactional notifications (fee due reminders, attendance alerts, circulars) via email, SMS, WhatsApp, or push notification, as configured by the Institution
- Process fee payments through our payment gateway partners
- Generate statutory reports the Institution needs (e.g. UDISE+ data exports, payroll compliance filings)
- Maintain platform security, prevent fraud, and debug technical issues
- Respond to support requests and, where you've consented, send product updates or marketing communications
- Comply with legal obligations, including responding to lawful requests from government or regulatory authorities
We do not sell personal data to third parties, and we do not use student data for targeted advertising.
5. Children's Data and Parental Consent
The Platform necessarily processes personal data of children (individuals under 18 years of age) as students of the Institution. In accordance with Section 9 of the DPDP Act:
- The Institution, as Data Fiduciary, is responsible for obtaining verifiable consent from a parent or lawful guardian before a child's personal data is processed on the Platform — typically obtained at the time of admission, and reaffirmed for platform-specific processing such as the parent portal/app or, in this Platform's exam-proctoring feature, webcam capture during online exams (see the in-app consent flow for that feature specifically).
- We do not undertake, and contractually restrict Institutions from directing us to undertake, any processing of a child's data that is likely to cause detrimental effect on the child's well-being.
- We do not carry out tracking or behavioural monitoring of children, or targeted advertising directed at children, on the Platform.
Parents/guardians may contact their Institution, or Vedorix's Grievance Officer (Section 12), to review, correct, or request deletion of their child's data, subject to the Institution's academic record-keeping obligations under applicable education law.
6. Sharing and Disclosure of Personal Data
We share personal data only as necessary to operate the Platform, with:
| Recipient | Purpose |
|---|---|
| Payment gateway providers (e.g. Razorpay, Cashfree) | Processing online fee payments — Vedorix does not store full card/UPI credentials; these are handled directly by the gateway, which is independently PCI-DSS compliant. |
| SMS, WhatsApp Business, and email delivery providers | Sending notifications and communications the Institution configures. |
| Cloud infrastructure and hosting providers | Storing and processing data (see Section 7, Data Storage). |
| Government and regulatory bodies | Where legally mandated — e.g. UDISE+ reporting, statutory payroll filings (PF/ESI/TDS), or a lawful request from a court or authority. |
| Professional advisors | Auditors, legal counsel, where necessary and under confidentiality obligations. |
We do not share personal data with third parties for their own independent marketing purposes.
7. Data Storage, Location, and Security
Platform data is primarily hosted on servers located in India. Where any processing occurs outside India (e.g. a sub-processor located abroad), we ensure this is permitted under the DPDP Act and Central Government notifications in force at the time.
We apply reasonable security practices and procedures, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Role-based access control — Institution staff only see data relevant to their role and branch/section
- Access logging and audit trails for sensitive operations
- Regular security reviews of the Platform's authentication and authorisation systems
No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we take industry-standard measures to protect personal data against unauthorised access, alteration, disclosure, or destruction.
8. Data Retention
We retain personal data for as long as the Institution's subscription is active and data is necessary to provide the Platform, and thereafter as required to comply with the Institution's legal obligations (e.g. statutory record-keeping requirements under the Right to Education Act, Income Tax Act records for payroll, or as instructed by the Institution). On termination of an Institution's subscription, data is retained for a limited export/transition window and then deleted or anonymised in accordance with our Terms of Service, unless a longer retention period is legally required.
9. Your Rights as a Data Principal
Subject to the DPDP Act and its exceptions, you have the right to:
- Access a summary of the personal data we process about you and the processing activities undertaken
- Correction and completion of inaccurate or incomplete personal data
- Erasure of personal data that is no longer necessary for the purpose it was collected, subject to legal retention requirements
- Withdraw consent at any time, where processing is based on consent (this does not affect the lawfulness of processing before withdrawal, and the Institution may still be required to retain certain records by law)
- Grievance redressal — raise a complaint with us, and if unresolved, escalate to the Data Protection Board of India
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
Because the Institution is typically the Data Fiduciary for student/parent/staff data, we ask that you first raise data requests with your Institution; we will support the Institution in responding, and you may also contact our Grievance Officer directly.
10. Cookies and Website Analytics
Our marketing website (vedorix.com) uses essential cookies for site functionality and may use analytics cookies to understand visitor behaviour. You can control cookies through your browser settings. The Platform application (web and mobile) uses session tokens necessary for you to stay logged in — these are not third-party advertising cookies.
11. Grievance Officer
In accordance with applicable law, you may contact our Grievance Officer for any questions, concerns, or complaints regarding this Policy or our data practices:
Grievance Officer: Yogesh Tiwari
Email: vedorix19@gmail.com
Phone: +91-9260985338
Address: 10, Ganga Nagar, Near Samadhan Vipati, Gangotri, Agriculture Institute, Allahabad, Allahabad – 211007, Uttar Pradesh
If you are not satisfied with our response, you may approach the Data Protection Board of India constituted under the DPDP Act.
12. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or applicable law. We will post the updated Policy on this page with a revised "Last Updated" date, and for material changes, notify Institutions through the Platform or by email.
13. Governing Law
This Policy is governed by the laws of India.
14. Contact Us
For any questions about this Privacy Policy, write to us at vedorix19@gmail.com.