Privacy & Data Protection

Privacy policy.

How the Ahmedabad Gandhinagar Sahodaya collects, uses, protects, and retains your information.

For legal review

Sample content — for legal review. This policy is a working draft provided for review by a qualified legal advisor before publication. It is not yet legal advice and may not fully reflect your final obligations under the Digital Personal Data Protection Act, 2023 (DPDP) or other applicable law.

Last updated: 19 June 2026

This Privacy Policy explains what personal data we process when a school registers for and uses Sahodaya membership, why we process it, the legal basis and your rights under India's Digital Personal Data Protection Act, 2023 (DPDP), and how long we keep it. By registering, the school's authorised representative (the Principal) consents to the processing described here.

1. What data we collect

We collect only what we need to provide and secure membership:

  • School details — name, CBSE affiliation number, address, city, and state.
  • Principal / contact details — name, mobile number, and email address used for verification, receipts, and notices.
  • Account credentials — a password, stored only as a salted bcrypt hash (we never store or can see your actual password).
  • Security & device data — your IP address, browser/device (user-agent), and timestamps for sign-up, log-in, payment, and password-reset events, captured to protect accounts and prevent fraud.
  • Payment data — the amount, GST, receipt number, and gateway order/payment references. Card, UPI, and bank details are entered on the payment gateway (Razorpay) and are NOT collected or stored by us.
  • Communication logs — a record that an SMS or email was sent (masked recipient, type, and delivery status). We never store the OTP value itself.
  • Email open status — for transactional emails we record, on a best-effort basis, whether and when an email was opened (via our email provider's open-tracking). This is used only to confirm delivery and help support; it is unreliable because many mail apps block or proxy tracking, and you can disable it by blocking remote images in your mail client.

2. Why we use it (purposes)

We process your data for these purposes only:

  • Membership — to register your school, verify your contact details, activate membership, and issue payment receipts.
  • Security & fraud prevention — to detect and investigate unauthorised access, abuse, and fraudulent payments.
  • Legal & regulatory compliance — to meet accounting, tax (GST), and statutory record-keeping obligations.
  • Communication — to send OTPs, payment receipts, renewal reminders, notices, and service updates.

3. Service providers we share with

We use trusted processors strictly to deliver the service, under their own security and privacy terms. We do not sell your data or share it for advertising.

  • Razorpay — payment processing.
  • ZeptoMail (Zoho) — transactional email delivery and open-tracking.
  • Our SMS aggregator — OTP and notification delivery over DLT-registered templates.
  • Amazon Web Services (Mumbai region) — database and file hosting within India.

4. Where your data is stored

Your data is hosted in India (AWS Mumbai region) to support data-residency expectations, encrypted in transit (TLS) and at rest. Access is restricted to authorised personnel on a need-to-know basis. Security audit records are access-controlled and are never exposed publicly.

5. How long we keep it (retention)

We retain data only as long as necessary for the purpose it was collected:

  • Security & audit logs (IP/device/event trail) — retained for 180 days, then purged.
  • Financial & transaction records (receipts, payments, ledger) — retained for approximately 8 years to meet accounting and tax obligations; these are kept separately and are NOT deleted on the 180-day security schedule.
  • Membership & contact records — retained for the duration of membership and as required thereafter for legal and audit purposes.

6. Your rights under DPDP

As a Data Principal, you have the right to:

  • Access — request a copy of the personal data we hold about your school.
  • Correction & updating — ask us to correct inaccurate or outdated details.
  • Erasure — request deletion of data we are not legally required to retain.
  • Grievance redressal — raise a complaint about how your data is handled (see below).
  • Withdraw consent — withdraw consent for processing that relies on it, subject to legal retention requirements.

7. Cookies & sessions

We use strictly necessary cookies to keep you signed in and to hold registration/password-reset state securely (encrypted, server-only). We do not use advertising or third-party tracking cookies.

8. Grievance & contact

For any privacy question, data-rights request, or grievance, contact the Sahodaya office. We aim to acknowledge requests promptly and respond within the timelines required by law.

Office
Prakash Higher Secondary School, Sandesh Press Road, Ahmedabad, Gujarat