Privacy Policy

S B INTER COLLEGE SORON — Your privacy matters to us

Table of Contents

PRIVACY POLICY

EFFECTIVE DATE: 01/03/2026
PLATFORM: Easy Education — Digital School Management Platform
OPERATED BY: Easy Education
UDISE CODE: 09722102002
WEBSITE: sbintercollege.dpdns.org
CONTACT: [email protected]
1. INTRODUCTION
1.1 Easy Education ("Institution," "we," "us," or "our") is committed to

protecting the privacy and personal data of all Users of the Easy Education

Digital School Management Platform ("Platform").

1.2 This Privacy Policy ("Policy") describes the types of personal information

we collect, how we use, store, and protect that information, and the rights

Users have regarding their data.

1.3 This Policy applies to all Users of the Platform, including Students,

Teachers, Principals, and Administrators, as well as visitors to the

Platform's public-facing pages (news, gallery, online registration).

1.4 BY ACCESSING OR USING THE PLATFORM, YOU CONSENT TO THE DATA PRACTICES

DESCRIBED IN THIS POLICY. IF YOU DO NOT AGREE WITH THIS POLICY, YOU MUST

DISCONTINUE USE OF THE PLATFORM.

1.5 This Policy should be read in conjunction with the Terms of Service, which

govern the overall use of the Platform.

2. INFORMATION COLLECTED
2.1 PERSONAL IDENTIFICATION INFORMATION:

- Full name (first name, last name)

- Student ID and Sr. No.

- Class, section, and roll number

- Date of birth and gender

- Father's name and mother's name

- Phone number and email address

- Residential address

- Apaar ID(if available)

- Profile picture

- Full name

- Teacher ID

- Qualifications, age, and gender

- Subject specialization

- Father's name and mother's name

- Phone number and email address

- Residential address

- Profile picture

- Full name

- Email address and phone number

- Role designation

- Account creation and modification timestamps

2.2 ACADEMIC RECORDS:

- Marks and test results

- Attendance records

- Homework assignments and submissions

- Subject enrollments

- Scholarship records

- Class assignments

2.3 UPLOADED DOCUMENTS:

- Profile pictures

- Certificate documents (Transfer Certificates, Character Certificates)

- Admit cards with QR codes

- Homework attachments (images)

- Gallery images

- Digital book files and pages

- Fee payment receipts (generated PDFs)

- Site logo and branding assets

2.4 LOGIN AND DEVICE DATA:

- IP address at time of login

- Login timestamp and logout timestamp

- Session duration

- User-Agent string (browser and device information)

- Day of the week and date of login

- Login success/failure status

- OTP verification records

2.5 ADMINISTRATIVE LOGS AND ANALYTICS:

- User edit logs (field changes, performed by, timestamp)

- Fee payment edits (old values, new values, edit reason, editor)

- Fee action logs (additions, deletions, modifications)

- Content management actions (news, gallery, FAQ creation/deletion)

- Certificate and admit card generation records

- App install tracking data (device info, timestamp)

- Client tracking data (IP address, user-agent, client info)

- IP block records and rate limiting events

2.6 ONLINE REGISTRATION DATA:

- Applicant name, parent/guardian details

- Class applied for

- Contact information

- Referral code usage

- Registration status and approval records

2.7 SUPPORT TICKET DATA:

- Ticket subject and message content

- Ticket type classification

- Ticket status and resolution records

3. LEGAL BASIS FOR PROCESSING
3.1 The Institution processes personal data on the following legal bases:

of the Institution's educational and administrative functions, and

for the fulfillment of contractual obligations arising from the

User's enrollment or employment.

applicable laws, regulations, or orders of competent authorities,

including the Right of Children to Free and Compulsory Education

Act, 2009, and the Information Technology Act, 2000.

interests of the Institution, including security monitoring, fraud

prevention, and system integrity, provided such interests are not

overridden by the User's rights and freedoms.

from Users or their parent/guardian before processing data for

purposes not covered by the above bases.

3.2 For Students who are minors (below 18 years of age), the Institution

relies on the consent of the parent or legal guardian, which is obtained

at the time of enrollment or registration, in accordance with applicable

law.

4. USE OF INFORMATION
4.1 The Institution uses collected information for the following purposes:

- Maintaining student academic records, attendance, and marks

- Generating certificates, admit cards, and reports

- Managing homework, tests, and scholarship records

- Facilitating digital library access

- User authentication and session management

- Role-based access control and authorization

- Fee payment processing and receipt generation

- Support ticket management

- Online registration processing and approval workflow

- Referral code management

- Detecting and preventing unauthorized access

- Rate limiting and brute-force attack prevention

- IP blocking for suspicious activity

- Login anomaly detection (device fingerprinting)

- CSRF and session security enforcement

- Sending OTP codes for authentication

- Sending fee payment confirmations

- Sending certificate and registration approval notifications

- Responding to support tickets

- Analyzing usage patterns and system performance

- Improving Platform features and user experience

- Generating administrative reports and analytics

- Maintaining records as required by educational regulations

- Responding to lawful requests from authorities

- Preserving evidence in case of disputes or investigations

5. DATA STORAGE AND RETENTION
5.1 STORAGE PRACTICES:

personnel.

are not exposed in source code.

execution disabled and access controlled through a PHP intermediary

that enforces permission checks.

direct web access via server configuration.

5.2 RETENTION DURATION:

plus seven (7) years after last attendance, or as required by

applicable educational regulations.

of creation, after which they may be automatically purged.

from the date of transaction, in compliance with financial and

tax regulations.

of the logged action.

processing, unless the applicant enrolls, in which case the data

is incorporated into the student record.

thirty (30) days after expiration.

5.3 Upon expiration of the applicable retention period, data will be

securely deleted or anonymized, except where retention is required

by law.

6. DATA SHARING AND DISCLOSURE
6.1 THE INSTITUTION DOES NOT SELL, RENT, TRADE, OR OTHERWISE MONETIZE

THE PERSONAL DATA OF ANY USER TO ANY THIRD PARTY.

6.2 Data may be shared ONLY in the following circumstances:

teachers, principals, and administrators as necessary for the

performance of their official duties, strictly on a need-to-know

basis consistent with their assigned role.

regulation, court order, or governmental authority, including but

not limited to:

- Responses to lawful subpoenas, court orders, or legal process;

- Compliance with educational regulatory requirements;

- Cooperation with law enforcement investigations.

rights, safety, or property of the Institution, its Users, or

the public, including fraud prevention and security incident

response.

assist in operating the Platform (e.g., email delivery services

for OTP and notification emails, hosting providers), subject to

contractual obligations of confidentiality and data protection.

6.3 The Institution does not share Student data with third parties for

marketing, advertising, or commercial purposes under any circumstances.

7. DATA SECURITY MEASURES
7.1 The Institution implements the following security measures to protect

User data:

- Role-based access control (RBAC) with four defined roles:

Student, Teacher, Principal, Administrator

- Session-based authentication with secure cookie parameters

(HttpOnly, Secure, SameSite=Lax)

- Multi-factor authentication via OTP for login verification

- Strict mode session management to prevent session fixation

- Device fingerprinting for login anomaly detection

- Password hashing using bcrypt (PASSWORD_BCRYPT) via PHP's

password_hash() function

- CSRF token generation and validation for all state-changing

operations

- Prepared statements (parameterized queries) for all database

operations to prevent SQL injection

- Output encoding (htmlspecialchars) to prevent cross-site

scripting (XSS)

- Path traversal protection for file access

- File upload validation (type, size, content verification)

- Server-side script execution disabled in upload directories

- Sensitive directories blocked from direct web access

- Security headers (X-Content-Type-Options, X-Frame-Options,

Referrer-Policy, Permissions-Policy)

- Rate limiting and brute-force protection for authentication

- IP blocking for suspicious activity

- Error display suppressed in production; errors logged only

- Database credentials stored in environment variables, not

in source code

- Comprehensive logging of administrative actions

- Login activity tracking with IP and device information

- Edit history for fee payments and user profile changes

- Rate limiting event logging

7.2 NOTWITHSTANDING THE ABOVE, NO SYSTEM IS 100% SECURE. The Institution

employs industry-standard security practices but cannot guarantee

absolute security against all possible threats. Users acknowledge

this inherent limitation.

8. USER RESPONSIBILITIES
8.1 Users are responsible for:

any other person;

Institution;

immediately through the support ticket system or by contacting

[email protected];

shared or public devices;

role privileges.

8.2 The Institution is not liable for data breaches or unauthorized

access resulting from a User's failure to comply with these

responsibilities.

9. COOKIES, TRACKING, AND LOGS
9.1 COOKIES:

authentication. These cookies are strictly necessary for the

Platform to function and cannot be disabled.

- HttpOnly: Not accessible via JavaScript

- Secure: Transmitted only over HTTPS (when available)

- SameSite=Lax: Protected against cross-site request forgery

advertising cookies, or analytics cookies from external providers.

9.2 LOGIN TRACKING:

and time, user-agent string, session duration, and day of the

week.

and administrative reporting.

Principals.

9.3 USAGE ANALYTICS:

monitoring and improvement, including: page access patterns,

feature utilization, and system performance metrics.

beyond what is already collected as part of normal Platform

operation.

9.4 SECURITY MONITORING:

login attempts, rate limiting triggers, IP blocking events, and

session anomalies.

security purposes.

integrity of the Platform and its Users' data.

10. USER RIGHTS
10.1 Users have the following rights regarding their personal data:

data held about them by contacting [email protected] or using

the Platform's support ticket system.

inaccurate or incomplete personal data. Students and Teachers

may update certain fields through their profile page on the

Platform. For other corrections, Users should contact the

Institution through the support ticket system.

personal data, subject to the following limitations:

- Data required by law or regulation to be retained cannot

be deleted until the applicable retention period expires;

- Academic records, fee payment records, and certificates

cannot be deleted during the mandatory retention period;

- Deletion of a User account may be requested but is subject

to institutional policy and administrative approval.

personal data in a structured, commonly used, and

machine-readable format, where technically feasible.

personal data on grounds relating to their particular

situation, subject to legitimate interests of the Institution.

10.2 To exercise any of these rights, Users should submit a request

through the Platform's support ticket system or by emailing

[email protected]. The Institution will respond to such requests

within thirty (30) days.

10.3 The Institution may verify the identity of the User making the

request before processing it, to prevent unauthorized data access.

11. CHILDREN'S DATA PROTECTION
11.1 The Platform is used by Students who may be minors (below 18 years

of age). The Institution recognizes the heightened responsibility

associated with processing children's personal data.

11.2 SPECIAL PROTECTIONS FOR STUDENT DATA:

- The student themselves (view-only access to their own data)

- Assigned teachers (limited to academic data relevant to

their classes)

- Principals and Administrators (full access for

administrative purposes)

other than those specified in Section 6.

controlled access mechanism that verifies permissions before

allowing access.

cannot modify academic records, attendance, marks, or fee

information.

11.3 PARENT/GUARDIAN CONSENT:

legal guardian consents to the collection, processing, and

storage of the student's personal data as described in this

Policy.

parent/guardian for minors) provides consent as part of the

registration process.

contacting the Institution through official channels.

11.4 The Institution complies with the provisions of the Right of

Children to Free and Compulsory Education Act, 2009, the

Protection of Children from Sexual Offences (POCSO) Act, 2012,

and the Information Technology Act, 2000, as they relate to

children's data protection.

12. THIRD-PARTY SERVICES
12.1 The Platform utilizes the following third-party services:

- SMTP service via Gmail for sending OTP codes, notifications,

and institutional communications

- Email addresses used for sending: [email protected]

and [email protected]

- SMTP credentials are stored as environment variables and are

not exposed in source code

- The Platform is hosted on a web server with PHP and MySQL

- Cloudflare is used for DDoS protection and web application

firewall (WAF) services

- PHPMailer: Email transmission

- mPDF: PDF generation for certificates and receipts

- FPDF: PDF generation for fee receipts

- PHP QR Code: QR code generation for certificates and

admit cards

- Random Compatibility Library: Cryptographic random number

generation

12.2 Each third-party service is bound by its own privacy policy and

data handling practices. The Institution selects services that

maintain reasonable data protection standards.

12.3 The Institution is not responsible for the privacy practices of

third-party services and encourages Users to review the privacy

policies of such services where applicable.

13. DATA PROTECTION OFFICER (DPO)
13.1 The Institution designates a Data Protection Officer (DPO) or

equivalent responsible person to oversee data protection compliance.

13.2 The DPO is responsible for:

protection laws;

and complaints;

13.3 To contact the DPO, Users may email [email protected] or use the

Platform's support ticket system.

14. AUDIT LOGS AND COMPLIANCE
14.1 The Platform maintains comprehensive audit logs for accountability

and compliance purposes, including:

including which fields were changed, by whom, and when;

modifications, including old and new values, edit reason,

and the identity of the editor;

deletions, and modifications;

and timing information;

FAQ creation and deletion;

all certificate and admit card issuances.

14.2 Audit logs are retained for a minimum of three (3) years and are

accessible only to authorized Administrators and Principals.

14.3 Audit logs may be reviewed by the Institution at any time for

compliance, security, or investigative purposes.

15. POLICY UPDATES
15.1 The Institution reserves the right to modify, amend, or update this

Policy at any time at its sole discretion.

15.2 Modifications will be effective immediately upon posting on the

Platform or upon notification to Users through the Platform's

communication channels.

15.3 CONTINUED USE OF THE PLATFORM FOLLOWING THE POSTING OF A MODIFIED

POLICY CONSTITUTES THE USER'S ACCEPTANCE OF SUCH MODIFICATIONS.

15.4 In the event of material changes to this Policy that significantly

affect the processing of User data, the Institution will make

reasonable efforts to notify Users through the Platform or via

email, where feasible.

15.5 Users are encouraged to review this Policy periodically for changes.
16. CONTACT AND GRIEVANCE REDRESSAL
16.1 For questions, concerns, or complaints regarding this Privacy Policy

or the Institution's data practices, Users may contact:

Institution: Easy Education

Platform: Easy Education

UDISE Code: 09722102002

Website: sbintercollege.dpdns.org

Email: [email protected]

Address: Village Hodalpur, Soron, Kasganj

16.2 GRIEVANCE REDRESSAL MECHANISM:

Platform's built-in support ticket system.

within seven (7) business days.

within thirty (30) business days of receipt.

escalate the matter to the appropriate regulatory authority

under the Information Technology Act, 2000, or the applicable

data protection authority.

16.3 For technical support, Users may also use the Platform's built-in

support ticket system accessible at the "Support" section of the

Platform.

17. SEVERABILITY
17.1 If any provision of this Policy is held to be invalid, illegal, or

unenforceable, the remaining provisions shall continue in full force

and effect.

17.2 The invalidity of any provision shall not affect the validity of

the remaining provisions of this Policy.

END OF PRIVACY POLICY