Privacy Policy
Last updated 19 August 2026
This policy explains what information Vidya handles on behalf of schools, why we handle it, how long we keep it and the choices available to schools, parents and staff.
1. Who is responsible for your data
Each school that uses Vidya decides what information is collected about its students, parents and staff. The school is the data controller. Vidya operates the software and stores the data on the school's instructions, acting as the data processor.
If you are a parent or staff member and want your records corrected or removed, contact your school first. We will help the school action the request.
2. Information we handle
- Student records — name, class and section, admission number, date of birth, guardian details, photo, attendance, marks, fee status, documents uploaded by the school.
- Parent and staff accounts — name, mobile number, email (when provided), role, login identifiers and password hashes.
- Communication — in-app messages, announcements, leave requests and WhatsApp or email notifications triggered by school activity.
- Transport — bus routes, stops and, during an active trip, the vehicle's live location. We do not track personal devices outside an active trip.
- Technical data — sign-in timestamps, audit entries for sensitive actions, error diagnostics and basic device information needed to keep the service working.
We do not sell data, and we do not use school data for advertising.
3. Why we handle it
- To provide the modules the school has enabled (attendance, fees, exams, transport, messaging and similar).
- To authenticate users and enforce role-based access.
- To send notifications the school configures, such as fee reminders, absence alerts and bus updates.
- To keep audit trails so schools can see who changed sensitive records.
- To diagnose faults, prevent abuse and improve reliability.
4. Children's data
Student accounts and records exist because a school asked for them as part of running its academic operations. Children do not sign up on their own, and parent or guardian accounts are created by the school. We limit student data visibility to the staff roles the school assigns and to the child's own linked guardians.
5. Sharing with service providers
We share data only with providers needed to run the service:
- Cloud hosting and managed database, for storage and application delivery.
- Messaging providers, to deliver WhatsApp and email notifications the school triggers.
- AI model providers, to process the specific text a user submits to assistant features. Prompts are used to generate a response, not to train third-party models on your school's data.
- Mapping and routing services, to draw bus routes.
We may also disclose data where required by law or to protect the safety of users.
6. Storage, retention and deletion
Data is stored in managed cloud infrastructure with encryption in transit and at rest, and is separated per school by database access rules. Records are retained for as long as the school keeps its account active, because academic history (attendance, marks, fee receipts) is normally required for several years.
When a school closes its account, we delete or return its data within 90 days of the request, except where records must be retained for a legal or accounting obligation.
7. Your choices
- Ask your school for a copy or correction of your records.
- Opt out of non-essential notifications by asking the school to change your preferences. Safety and account notices cannot be switched off.
- Withdraw consent for optional features, such as publishing a student photo.
8. Changes and contact
We will update this page when our practices change and revise the date above. Questions about this policy can be sent through our contact page. More detail about our technical safeguards is on the Data & Security page.