IQdigit Educational ERP Platform
This Privacy Policy and Terms of Data Processing (“Privacy Policy” or “Policy”) constitutes a legally binding electronic agreement between IQwing EduInfotech Private Limited (“Company”, “We”, “Us”, or “Our”), having its registered office at 3rd Ward No.-7, Dev Paul Chowk, Hamirpur, Himachal Pradesh, India - 177001, and any individual, entity, or institution (“You”, “Your”, “User”, or “Client Institution”) accessing, registering with, or utilizing www.IQdigit.com (“Website”), the IQdigit ERP Software, and/or the IQdigit Parents & Staff Mobile Applications (collectively referred to as the “Platform”).
This Policy is published in strict adherence with Section 43A and Section 79 of the Information Technology Act, 2000 (“IT Act”), Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and aligns with the statutory principles established under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
Legal Framework & Role Distinction:
The Platform is purpose-built for comprehensive institutional administration and educational engagement across all age demographics, including minor students (K-12 and pre-primary education), parents, legal guardians, teachers, and school personnel. Consequently, no general minimum age bar (such as an 18-year cap) applies to user access to the Platform.
Conditions of Minor Data Processing:
The Platform processes data strictly necessary for fulfilling contractual, educational, and operational requirements:
Whenever a User interacts with the Platform, our servers automatically record technical telemetry, including: Internet Protocol (IP) addresses, device hardware models, operating system versions, browser user-agents, unique device identifiers (UUID/FCM Tokens for push alerts), network provider data, crash diagnostics, timestamps, and session activity logs.
To execute specific ERP functionalities, the IQdigit Mobile Application may request explicit operating system runtime permissions. Each permission is restricted exclusively to user-initiated tasks:
Users may modify or revoke application permissions via their device operating system settings; however, certain dependent features of the Platform may become unavailable as a consequence.
Personal data processed on the Platform is utilized exclusively for legitimate business, educational, and statutory objectives, including: (a) provisioning and managing ERP software licenses; (b) managing academic student life cycles and grading systems; (c) automating fee reconciliation; (d) maintaining verifiable audit trails for institutions; (e) dispatching administrative, transactional, and emergency alerts; (f) debugging, patch deployment, and infrastructure optimization; and (g) complying with applicable statutory, regulatory, and judicial orders.
The Company engages reputable third-party infrastructure and service partners (“Vendor Partners”) to deliver seamless enterprise functionality. Data is disclosed to such Vendor Partners strictly on a need-to-know, confidential basis:
THIRD-PARTY VENDOR LIABILITY DISCLAIMER:
WHILE THE COMPANY SELECTS REPUTABLE VENDOR PARTNERS, THE COMPANY EXERCISES NO DIRECT OPERATIONAL CONTROL OVER INDEPENDENT THIRD PARTIES. TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY EXPRESSLY DISCLAIMS ALL LIABILITY FOR ANY DEFICIENCY, SERVICE OUTAGE, LATENCY, SECURITY VULNERABILITY, DATA BREACH, OR ACT/OMISSION ATTRIBUTABLE TO THIRD-PARTY PAYMENT GATEWAYS, TELECOM OPERATORS, SMS AGGREGATORS, CLOUD HOSTING PROVIDERS, OR EXTERNAL API INTEGRATIONS.
The Company maintains comprehensive, documented administrative, technical, operational, and physical security control practices in compliance with Section 43A of the IT Act, 2000 and SPDI Rules. These measures include: (a) 256-bit SSL/TLS cryptographic encryption for data in transit; (b) perimeter network firewalls and DDoS mitigation; (c) strict role-based access controls (RBAC); (d) encrypted database backups; and (e) systematic vulnerability assessments.
Acknowledgment of Inherent Internet Vulnerabilities: You expressly acknowledge that no transmission over the public Internet or electronic cloud storage system is 100% immune from security compromise. Transmission of information to and through the Platform is undertaken with full knowledge and acceptance of these inherent systemic risks.
EXCLUSION OF LIABILITY FOR CYBER ATTACKS, DATA BREACHES & MALICIOUS INTRUSION:
NOTWITHSTANDING ANYTHING CONTAINED IN THIS POLICY OR ANY ANCILLARY AGREEMENT, UNDER NO CIRCUMSTANCES SHALL THE COMPANY, ITS DIRECTORS, OFFICERS, SHAREHOLDERS, EMPLOYEES, AFFILIATES, AGENTS, OR REPRESENTATIVES BE LIABLE FOR ANY LOSS, DAMAGE, SYSTEM CORRUPTION, UNAUTHORIZED DISCLOSURE, COMPROMISE OF PERSONAL DATA, OR BUSINESS INTERRUPTION ARISING OUT OF OR RESULTING FROM:
CONSEQUENTIAL LOSS EXCLUSION & AGGREGATE LIABILITY CAP:
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW:
You and/or the Client Institution agree to defend, indemnify, and hold harmless the Company, its directors, employees, affiliates, licensors, and service contractors against any and all third-party claims, liabilities, damages, losses, costs, penalties, or expenses (including reasonable attorneys' fees) arising out of or related to: (a) unauthorized submission or upload of personal data without requisite parental or statutory consent; (b) breach of any representation, warranty, or covenant contained herein; (c) violation of any applicable law, rule, or regulation (including the IT Act and DPDP Act) by the User or Client Institution; or (d) compromise of user login accounts caused by user negligence.
UNILATERAL AMENDMENT CLAUSE:
The Company reserves the absolute, unilateral, and unencumbered right to amend, alter, update, revise, add, or repeal any portion of this Privacy Policy at any time, in its sole and absolute discretion, without any requirement of prior individual notice, prior written communication, or prior consent from any User or Client Institution.
All amendments shall become immediately effective, valid, and enforceable upon the publication of the revised Policy on the Website (www.iqdigit.com/privacy_policy) and/or within the Mobile Application, with an updated “Last Updated” timestamp.
Affirmative Duty of User Review: It is the sole responsibility and affirmative duty of every User and Client Institution to periodically inspect, review, and familiarize themselves with the updated Privacy Policy. Your continued access, browsing, login, or utilization of the Platform following the publication of any modifications constitutes Your conclusive, irrevocable, and deemed acceptance of the revised Policy. If You do not agree to any updated provision, Your sole and exclusive remedy is to immediately discontinue all use of the Platform.
Data is retained on the Platform for the duration of the institutional service contract and as mandated by educational, tax, audit, and statutory guidelines. Because institutional data belongs to the Client Institution, individual requests from parents, students, or staff for data access, rectification, correction, or account deactivation must be routed directly through the respective School Administration. The Company shall process validated institutional requests in accordance with contractual terms and statutory mandates.
This Privacy Policy, its interpretation, validity, and any dispute or claim arising out of or in connection with it or its subject matter shall be governed by, construed, and enforced strictly in accordance with the substantive and procedural laws of the Republic of India, without giving effect to any principles of conflicts of law.
Subject to mutual preliminary amicable discussions, any legal suit, action, arbitration, or proceeding arising out of or related to this Policy or Platform operations shall be subject to the exclusive territorial and subject-matter jurisdiction of the competent courts situated in District Hamirpur, Himachal Pradesh, India. All parties irrevocably waive any objection to the laying of venue or forum non-conveniens.
In strict compliance with Section 5(9) of the SPDI Rules, 2011, Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act framework, the details of the designated Grievance Officer for the Company are as follows:
Designation: Grievance Officer & Compliance Lead
Company Name: IQwing EduInfotech Private Limited
Product Platform: IQdigit Educational ERP (www.iqdigit.com)
Official Postal Address: 3rd Ward No.-7, Dev Paul Chowk, Hamirpur, Himachal Pradesh, India - 177001
Official Grievance Email: info@iqwing.in
Timelines: Grievances submitted with complete details will be acknowledged within forty-eight (48) hours and resolved within the statutory timelines prescribed under Indian IT Rules.