IQdigit Educational ERP Platform

Privacy Policy & Terms of Data Processing

Published & Enforceable Pursuant to the Information Technology Act, 2000 & Applicable Data Protection Laws | Last Updated: 31 August, 2026

1. Corporate Identification, Legal Scope & Capacity

This Privacy Policy and Terms of Data Processing (“Privacy Policy” or “Policy”) constitutes a legally binding electronic agreement between IQwing EduInfotech Private Limited (“Company”, “We”, “Us”, or “Our”), having its registered office at 3rd Ward No.-7, Dev Paul Chowk, Hamirpur, Himachal Pradesh, India - 177001, and any individual, entity, or institution (“You”, “Your”, “User”, or “Client Institution”) accessing, registering with, or utilizing www.IQdigit.com (“Website”), the IQdigit ERP Software, and/or the IQdigit Parents & Staff Mobile Applications (collectively referred to as the “Platform”).

This Policy is published in strict adherence with Section 43A and Section 79 of the Information Technology Act, 2000 (“IT Act”), Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and aligns with the statutory principles established under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).

Legal Framework & Role Distinction:

  • Intermediary & Technology Service Provider: The Company operates strictly as an intermediary and technology infrastructure service provider (Data Processor) facilitating educational enterprise resource planning.
  • Principal Data Fiduciary / Controller: The respective educational institution (school, college, trust, or society) that contracts the Platform acts as the primary Data Fiduciary / Data Controller regarding all institutional, employee, parent, and student records uploaded, processed, or managed on the Platform.

2. User Eligibility & Processing of Minor / Student Data

The Platform is purpose-built for comprehensive institutional administration and educational engagement across all age demographics, including minor students (K-12 and pre-primary education), parents, legal guardians, teachers, and school personnel. Consequently, no general minimum age bar (such as an 18-year cap) applies to user access to the Platform.

Conditions of Minor Data Processing:

  • Institutional Authorization & Parental Consent: Minor accounts and profiles are provisioned exclusively under the express directive, control, and authority of the Client Institution. By onboarding students and parents onto the Platform, the Client Institution warrants, covenants, and confirms that it has procured all requisite parental, guardian, or legal consents required under applicable law.
  • Parental Supervisory Access: Parents and legal guardians are provided designated access to monitor attendance, academic performance, assignments, fees, circulars, and teacher communications.
  • Prohibition of Commercial Exploitation: The Company does not sell, trade, license, or monetize student personal data. Student data is never processed for third-party commercial profiling, behavioral ad targeting, or commercial surveillance.

3. Categories of Data Collected and Processed

The Platform processes data strictly necessary for fulfilling contractual, educational, and operational requirements:

3.1 Data Provided Directly by Client Institutions and Users

  • Student Master Data: Full legal name, gender, date of birth, blood group, photograph, student registration/admission number, roll number, class/grade, section, house/batch, academic grades, examination scores, disciplinary remarks, and timetable schedules.
  • Parent / Guardian Data: Father’s, mother’s, or guardian’s name, residential address, billing address, official contact numbers, emergency contact details, and occupation/designation (where provided).
  • Faculty & Staff Records: Employee ID, full name, official email address, mobile number, biometric attendance logs (if integrated with the school’s on-premise hardware), subject allotments, and salary/payroll slips (where module is deployed).
  • Financial & Transactional Records: Fee invoice summaries, transaction reference numbers, payment gateway transaction IDs, payment statuses, and fee concession classifications. (Note: Credit/debit card numbers, CVVs, and net-banking credentials are processed directly by RBI-regulated Payment Gateways and are never stored on the Company's servers.)
  • Transportation & Bus Tracking: Route numbers, designated pickup/drop-off stops, and vehicle tracking coordinates (if opted for by the Client Institution).

3.2 Technical, Diagnostic and Device Information

Whenever a User interacts with the Platform, our servers automatically record technical telemetry, including: Internet Protocol (IP) addresses, device hardware models, operating system versions, browser user-agents, unique device identifiers (UUID/FCM Tokens for push alerts), network provider data, crash diagnostics, timestamps, and session activity logs.

4. Mobile Application Hardware & OS Permissions

To execute specific ERP functionalities, the IQdigit Mobile Application may request explicit operating system runtime permissions. Each permission is restricted exclusively to user-initiated tasks:

  • Camera: Accessed solely when a teacher, parent, or student initiates image capture for profile images, student assignments, answer sheets, or school notice attachments.
  • Storage / Media Files: Accessed to save or retrieve PDF report cards, fee receipts, digital circulars, syllabus documents, and offline study materials.
  • Push Notifications: Utilized to deliver urgent transactional notifications, daily attendance status, fee dues, exam dates, emergency school closure alerts, and homework postings.
  • Location Services (Optional): Accessed strictly if the Client Institution implements live transport/school bus tracking or GPS-fenced staff attendance. Location data is never shared with advertisers or third parties.

Users may modify or revoke application permissions via their device operating system settings; however, certain dependent features of the Platform may become unavailable as a consequence.

5. Purpose and Legal Basis of Processing

Personal data processed on the Platform is utilized exclusively for legitimate business, educational, and statutory objectives, including: (a) provisioning and managing ERP software licenses; (b) managing academic student life cycles and grading systems; (c) automating fee reconciliation; (d) maintaining verifiable audit trails for institutions; (e) dispatching administrative, transactional, and emergency alerts; (f) debugging, patch deployment, and infrastructure optimization; and (g) complying with applicable statutory, regulatory, and judicial orders.

6. Third-Party Integrations, Service Providers & Vendor Disclaimer

The Company engages reputable third-party infrastructure and service partners (“Vendor Partners”) to deliver seamless enterprise functionality. Data is disclosed to such Vendor Partners strictly on a need-to-know, confidential basis:

  • Cloud Hosting & Data Centers: Enterprise-grade hosting providers and database clusters operating under stringent security standards.
  • Telecom & Communication Gateways: TRAI-compliant SMS bulk aggregators and Meta/WhatsApp Business API service providers for dispatching one-time passwords (OTPs), attendance notifications, and institutional circulars.
  • Payment Aggregators: RBI-licensed payment gateways providing encrypted PCI-DSS compliant checkout interfaces for school fee payments.
  • YouTube API Services: Where institutions embed educational YouTube streams, operations comply with the YouTube Terms of Service and Google Privacy Policy. Application access may be revoked anytime via the Google Security Settings Page.

THIRD-PARTY VENDOR LIABILITY DISCLAIMER:

WHILE THE COMPANY SELECTS REPUTABLE VENDOR PARTNERS, THE COMPANY EXERCISES NO DIRECT OPERATIONAL CONTROL OVER INDEPENDENT THIRD PARTIES. TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY EXPRESSLY DISCLAIMS ALL LIABILITY FOR ANY DEFICIENCY, SERVICE OUTAGE, LATENCY, SECURITY VULNERABILITY, DATA BREACH, OR ACT/OMISSION ATTRIBUTABLE TO THIRD-PARTY PAYMENT GATEWAYS, TELECOM OPERATORS, SMS AGGREGATORS, CLOUD HOSTING PROVIDERS, OR EXTERNAL API INTEGRATIONS.

7. Data Security Safeguards (Section 43A IT Act Compliance)

The Company maintains comprehensive, documented administrative, technical, operational, and physical security control practices in compliance with Section 43A of the IT Act, 2000 and SPDI Rules. These measures include: (a) 256-bit SSL/TLS cryptographic encryption for data in transit; (b) perimeter network firewalls and DDoS mitigation; (c) strict role-based access controls (RBAC); (d) encrypted database backups; and (e) systematic vulnerability assessments.

Acknowledgment of Inherent Internet Vulnerabilities: You expressly acknowledge that no transmission over the public Internet or electronic cloud storage system is 100% immune from security compromise. Transmission of information to and through the Platform is undertaken with full knowledge and acceptance of these inherent systemic risks.

8. Comprehensive Limitation of Liability, Cyber Attack Exclusions & Force Majeure

EXCLUSION OF LIABILITY FOR CYBER ATTACKS, DATA BREACHES & MALICIOUS INTRUSION:

NOTWITHSTANDING ANYTHING CONTAINED IN THIS POLICY OR ANY ANCILLARY AGREEMENT, UNDER NO CIRCUMSTANCES SHALL THE COMPANY, ITS DIRECTORS, OFFICERS, SHAREHOLDERS, EMPLOYEES, AFFILIATES, AGENTS, OR REPRESENTATIVES BE LIABLE FOR ANY LOSS, DAMAGE, SYSTEM CORRUPTION, UNAUTHORIZED DISCLOSURE, COMPROMISE OF PERSONAL DATA, OR BUSINESS INTERRUPTION ARISING OUT OF OR RESULTING FROM:

  • CYBER INCIDENTS & ATTACKS: ZERO-DAY EXPLOITS, SOPHISTICATED HACKING, MALWARE, RANSOMWARE, DISTRIBUTED DENIAL OF SERVICE (DDOS) ATTACKS, BRUTE-FORCE INTRUSIONS, PHISHING, OR ADVANCED PERSISTENT THREATS (APTS) BY STATE OR NON-STATE MALICIOUS ACTORS THAT CIRCUMVENT INDUSTRY-STANDARD SECURITY SAFEGUARDS;
  • USER NEGLIGENCE: COMPROMISE, LEAK, OR SHARING OF LOGIN CREDENTIALS, PASSWORDS, OR ONE-TIME PASSWORDS (OTPS) BY USERS, SCHOOL ADMINISTRATORS, STAFF, OR PARENTS;
  • FORCE MAJEURE EVENTS: ACTS OF GOD, PANDEMICS, EPIDEMICS, GOVERNMENT RESTRICTIONS, TELECOMMUNICATION OR UNDERSEA CABLE BREAKDOWNS, GRID OUTAGES, WAR, CIVIL DISTURBANCES, NATURAL DISASTERS, STRIKES, OR ANY EVENT BEYOND THE REASONABLE COMMERCIAL CONTROL OF THE COMPANY.

CONSEQUENTIAL LOSS EXCLUSION & AGGREGATE LIABILITY CAP:

TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW:

  1. NO CONSEQUENTIAL DAMAGES: IN NO EVENT SHALL THE COMPANY BE LIABLE FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO LOSS OF REPUTATION, GOODWILL, REVENUE, DATA, OR ANTICIPATED PROFITS), REGARDLESS OF THE LEGAL THEORY (WHETHER IN CONTRACT, TORT, STRICT LIABILITY, NEGLIGENCE, INDEMNITY, OR OTHERWISE), EVEN IF APPRISED OF THE POSSIBILITY THEREOF.
  2. MAXIMUM AGGREGATE MONETARY LIABILITY: THE ENTIRE AND AGGREGATE MONETARY LIABILITY OF THE COMPANY ARISING FROM, CONNECTED WITH, OR RELATING TO THIS PRIVACY POLICY, DATA PROCESSING, OR PLATFORM USAGE SHALL BE STRICTLY CAPPED AT AND LIMITED TO: (A) THE TOTAL NET SERVICE FEE ACTUALLY RECEIVED BY THE COMPANY FROM THE SPECIFIC CLAIMANT INSTITUTION FOR THE PRECEDING THREE (3) MONTHS IMMEDIATELY PRIOR TO THE OCCURRENCE OF THE EVENT GIVING RISE TO LIABILITY; OR (B) INR 10,000/- (INDIAN RUPEES TEN THOUSAND ONLY), WHICHEVER IS LOWER.

9. Indemnification

You and/or the Client Institution agree to defend, indemnify, and hold harmless the Company, its directors, employees, affiliates, licensors, and service contractors against any and all third-party claims, liabilities, damages, losses, costs, penalties, or expenses (including reasonable attorneys' fees) arising out of or related to: (a) unauthorized submission or upload of personal data without requisite parental or statutory consent; (b) breach of any representation, warranty, or covenant contained herein; (c) violation of any applicable law, rule, or regulation (including the IT Act and DPDP Act) by the User or Client Institution; or (d) compromise of user login accounts caused by user negligence.

10. Absolute Right to Modify Policy & Deemed Binding Acceptance

UNILATERAL AMENDMENT CLAUSE:

The Company reserves the absolute, unilateral, and unencumbered right to amend, alter, update, revise, add, or repeal any portion of this Privacy Policy at any time, in its sole and absolute discretion, without any requirement of prior individual notice, prior written communication, or prior consent from any User or Client Institution.

All amendments shall become immediately effective, valid, and enforceable upon the publication of the revised Policy on the Website (www.iqdigit.com/privacy_policy) and/or within the Mobile Application, with an updated “Last Updated” timestamp.

Affirmative Duty of User Review: It is the sole responsibility and affirmative duty of every User and Client Institution to periodically inspect, review, and familiarize themselves with the updated Privacy Policy. Your continued access, browsing, login, or utilization of the Platform following the publication of any modifications constitutes Your conclusive, irrevocable, and deemed acceptance of the revised Policy. If You do not agree to any updated provision, Your sole and exclusive remedy is to immediately discontinue all use of the Platform.

11. Data Retention, Correction & Deletion Protocol

Data is retained on the Platform for the duration of the institutional service contract and as mandated by educational, tax, audit, and statutory guidelines. Because institutional data belongs to the Client Institution, individual requests from parents, students, or staff for data access, rectification, correction, or account deactivation must be routed directly through the respective School Administration. The Company shall process validated institutional requests in accordance with contractual terms and statutory mandates.

12. Governing Law, Dispute Resolution & Exclusive Jurisdiction

This Privacy Policy, its interpretation, validity, and any dispute or claim arising out of or in connection with it or its subject matter shall be governed by, construed, and enforced strictly in accordance with the substantive and procedural laws of the Republic of India, without giving effect to any principles of conflicts of law.

Subject to mutual preliminary amicable discussions, any legal suit, action, arbitration, or proceeding arising out of or related to this Policy or Platform operations shall be subject to the exclusive territorial and subject-matter jurisdiction of the competent courts situated in District Hamirpur, Himachal Pradesh, India. All parties irrevocably waive any objection to the laying of venue or forum non-conveniens.

13. Statutory Grievance Redressal Mechanism & Grievance Officer

In strict compliance with Section 5(9) of the SPDI Rules, 2011, Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act framework, the details of the designated Grievance Officer for the Company are as follows:

Designation: Grievance Officer & Compliance Lead

Company Name: IQwing EduInfotech Private Limited

Product Platform: IQdigit Educational ERP (www.iqdigit.com)

Official Postal Address: 3rd Ward No.-7, Dev Paul Chowk, Hamirpur, Himachal Pradesh, India - 177001

Official Grievance Email: info@iqwing.in

Timelines: Grievances submitted with complete details will be acknowledged within forty-eight (48) hours and resolved within the statutory timelines prescribed under Indian IT Rules.