Privacy Policy

Last Updated: September 2026

1. Introduction and Commitment to Privacy

ScholarAI Systems (OPC) Private Limited, operating the ScholarSync platform ("ScholarSync", "we", "us" or "our"), provides technology-enabled educational and institutional services for schools, coaching centres, education authorities, teachers, students, parents and other authorised users.

We recognise that the ScholarSync ecosystem may involve substantial processing of personal data relating to students, including children. We therefore seek to design and operate ScholarSync around lawful purpose, transparency, data minimisation, accuracy, security, accountable processing, appropriate retention and enhanced protection for children.

This Privacy Policy explains the categories of digital personal data that may be processed through ScholarSync, why such data is processed, how it may be shared, the safeguards we apply, the choices and rights available to Data Principals, and the additional measures applicable to children and persons with disability who have lawful guardians.

This Policy is intended to operate consistently with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), as and when the relevant provisions are in force.

2. Scope

This Policy applies to digital personal data processed by ScholarSync within India and, where the DPDP Act applies, to processing outside India in connection with offering goods or services to Data Principals within India. It applies to the ScholarSync website, web and mobile applications, student and parent portals, teacher and administrator interfaces, assessment and learning features, institutional ERP functionality, communications, support services, integrations, security systems and other ScholarSync services that refer to this Policy.

This Policy does not govern information that is not personal data, personal data processed by an individual for a personal or domestic purpose, or personal data made publicly available by the Data Principal or by another person under a legal obligation to make it publicly available, to the extent excluded from the DPDP Act.

3. Key DPDP Terms

Data Principal: the individual to whom personal data relates. Where the Data Principal is a child, the expression includes the child's parent or lawful guardian; where the Data Principal is a person with disability who has a lawful guardian, it includes that lawful guardian, as provided by the DPDP Act.

Child: an individual who has not completed eighteen years of age, unless the applicable legal framework is subsequently modified or a lawful notification applies.

Personal Data: any data about an individual who is identifiable by or in relation to such data.

Processing: a wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, indexing, sharing, disclosure, dissemination, restriction, erasure or destruction.

Data Fiduciary: a person who alone or in conjunction with others determines the purpose and means of processing personal data.

Data Processor: a person who processes personal data on behalf of a Data Fiduciary.

Consent: a freely given, specific, informed, unconditional and unambiguous indication of the Data Principal's wishes by clear affirmative action, signifying agreement to processing for the specified purpose.

4. ScholarSync's Role and Institutional Deployments

ScholarSync may act as a Data Fiduciary for processing where it determines the purpose and means of processing. In institutional deployments, a school, coaching centre, education authority or other customer may itself determine important purposes for which student, parent, teacher or staff data is processed. The precise allocation of responsibilities will depend on the relevant processing activity, contractual arrangement and applicable law.

Where an institution instructs ScholarSync to process data for the institution's educational or administrative purposes, ScholarSync will process such data within the scope of the relevant arrangement and applicable law. This Policy does not reduce an institution's independent obligations under the DPDP Act where the institution is a Data Fiduciary.

Where ScholarSync engages a Data Processor, ScholarSync will do so under a valid contract and will remain responsible for complying with applicable obligations imposed on ScholarSync as Data Fiduciary.

5. Personal Data We May Process

The exact data depends on the user's role, the institution's configuration and the ScholarSync modules enabled. ScholarSync seeks to limit collection to data necessary for specified purposes.

CategoryIllustrative Personal DataTypical Purpose
Identity and accountName, user ID, email, mobile number where used, role, institution, class/grade/section, account credentials and account status.Account creation, authentication, access control and service administration.
Student and academicEnrolment, attendance, subjects, curriculum, assignments, submissions, marks, grades, assessment responses, progress, mastery/recall indicators, teacher feedback and learning history.Teaching, learning, assessment, reporting, academic administration and personalised educational support.
Parent/guardianName, contact details, relationship to child, linked student account, consent/verification records and communications.Parental access, notices, consent, verification, communication and student support.
Teacher/staffName, professional contact details, institution, role, classes, subjects, permissions, attendance/administrative activity and communications.Institutional administration, teaching workflows, access management and communications.
CommunicationsIn-app messages, notices, acknowledgements, support requests and related metadata.Service delivery, support, institutional communication and audit.
Device/securityIP address, device/browser details, session identifiers, login timestamps, authentication events, activity logs and security events.Security, fraud/abuse prevention, troubleshooting, access control and audit.
Assessment integrityReal-time liveness/face-presence signals, gaze or attention-related signals, tab/application switching events, integrity events and integrity scores, where enabled.Assessment integrity and review by authorised institutional personnel.
AI interactionsPrompts, questions, submitted educational content, generated responses, feedback and relevant learning context.Providing AI-assisted educational features and improving service reliability as permitted.
Website/enquiryName, institution, professional role, email/phone and enquiry content.Demo requests, business communications and support.

6. Data We Do Not Seek for Unrelated Purposes

ScholarSync does not seek to collect personal data merely because it may be technically available. Unless required for a specified, lawful and disclosed purpose, ScholarSync does not intend to collect precise continuous geolocation of children, payment-card data directly from children, government identity documents from children, or information about a child's religion, political opinions, sexual life or health for unrelated commercial purposes.

If a user or institution uploads unnecessary personal data, ScholarSync may restrict, return, de-identify or erase such data where appropriate and legally permissible.

7. Sources of Personal Data

  • Directly from Data Principals, including students, parents, teachers, administrators and website visitors.
  • From schools, coaching centres, education authorities and other authorised institutions that create accounts, enrol users or upload institutional records.
  • From parents or lawful guardians, including information required to link or authorise a child's account.
  • Automatically from use of ScholarSync, including security, session, device and activity information.
  • From integrations or service providers authorised by ScholarSync or the relevant institution, where permitted and necessary for the specified purpose.

8. Purposes of Processing

ScholarSync processes personal data only for lawful purposes. Depending on the service and the relevant notice, specified purposes may include:

  • creating, provisioning and administering user accounts;
  • authenticating users and applying role-based permissions;
  • managing student enrolment, classes, curriculum, timetables, attendance, grades, fees or other enabled institutional functions;
  • delivering assignments, assessments, learning materials and educational content;
  • recording assessment responses, results, progress and learning outcomes;
  • providing dashboards and reports to authorised students, parents, teachers and administrators;
  • providing AI-assisted learning, content generation, translation, voice or educational support features;
  • providing assessment-integrity functionality where enabled and lawfully permitted;
  • communicating service, academic, security and administrative information;
  • responding to support requests and resolving technical issues;
  • detecting, preventing and investigating unauthorised access, misuse, fraud and security incidents;
  • maintaining legally required, security and audit records;
  • improving reliability, accessibility, security and performance using appropriately minimised, aggregated or de-identified information where reasonably practicable; and
  • complying with applicable law, court orders or lawful governmental requirements.

9. Notice and Transparency

Where ScholarSync seeks consent, ScholarSync will provide or make available a notice that is clear, standalone and understandable, and that enables the Data Principal to understand the personal data and specified purpose for which consent is sought. When the relevant DPDP Rules are in force, the notice will include an itemised description of the personal data and a clear description of the specified purpose, including an itemised explanation of the goods, services or uses enabled by such processing.

The notice will also identify a communication mechanism through which the Data Principal may, as applicable, withdraw consent, exercise rights under the DPDP Act and make a complaint to the Data Protection Board of India.

Where consent was obtained before the relevant notice provisions became applicable, ScholarSync will provide the notice required by law as soon as reasonably practicable in the manner required by the DPDP framework.

10. Consent

Where consent is the applicable basis for processing, ScholarSync will seek consent that is freely given, specific, informed, unconditional and unambiguous, through clear affirmative action, and limited to personal data necessary for the specified purpose.

A Data Principal may withdraw consent at any time with ease comparable to the manner in which consent was given. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal. Following withdrawal, ScholarSync will cease the relevant processing and cause its Data Processors to cease processing unless continued processing is required or authorised under applicable law.

ScholarSync will not make access to a service conditional on consent to processing that is unnecessary for that service, except where lawfully permitted.

11. Certain Legitimate Uses Under the DPDP Act

The DPDP Act permits processing without consent in specified circumstances described as certain legitimate uses. Where applicable and in force, ScholarSync may process personal data under such provisions only when the statutory conditions are satisfied. Examples may include processing voluntarily provided for a specified purpose where the Data Principal has not indicated non-consent, processing required for compliance with a judgment or legal order, responding to a medical emergency or disaster where applicable, or processing for employment-related purposes where the statutory conditions are met.

ScholarSync will not rely on a "legitimate use" merely as a substitute for consent where the conditions prescribed by the DPDP Act are not satisfied.

12. Children's Personal Data

Children's privacy receives enhanced protection under the DPDP framework. For purposes of this Policy, a child is a person who has not completed eighteen years of age, subject to any lawful exemption, notification or change in applicable law.

12.1 Verifiable Parental Consent

Before processing personal data of a child where Section 9(1) applies, ScholarSync will obtain verifiable consent of the child's parent or lawful guardian in the manner required by applicable law. ScholarSync may rely on information already available to it or voluntarily provided identity and age details, or an authorised virtual token mapped to such details, including through a Digital Locker service provider or other legally permitted mechanism, where the DPDP Rules allow.

ScholarSync may also coordinate with the relevant institution in implementing age-assurance, parent-linking and consent workflows. The fact that an institution uses ScholarSync does not by itself permit ScholarSync to disregard a statutory parental-consent requirement.

12.2 Persons with Disability Who Have Lawful Guardians

Where the Data Principal is a person with disability who has a lawful guardian and the applicable provisions require guardian consent, ScholarSync will take reasonable steps to verify that the person claiming to be the lawful guardian has been appointed by a court, designated authority or local-level committee under applicable guardianship law, as contemplated by the DPDP Rules.

12.3 No Detrimental Processing

ScholarSync will not knowingly undertake processing of a child's personal data that is likely to cause a detrimental effect on the well-being of the child.

12.4 Tracking, Behavioural Monitoring and Targeted Advertising

ScholarSync does not use children's personal data for targeted advertising. ScholarSync does not sell student data or create advertising profiles from a child's academic activity.

Where Section 9(3) applies, ScholarSync will not undertake tracking or behavioural monitoring of children except to the extent a lawful statutory or rules-based exemption applies and all applicable conditions are satisfied. Product analytics, security monitoring, learning-progress measurement and assessment-integrity functionality involving children must therefore be evaluated and configured against the applicable DPDP child-processing rules before use.

12.5 Educational and Safety-Related Exceptions

The DPDP Rules prescribe limited classes and purposes for which certain child-related obligations may not apply, subject to stated conditions. ScholarSync will rely on any such exception only where the processing falls squarely within the prescribed class or purpose and complies with every applicable condition. No exception will be interpreted as a general permission to profile, advertise to or commercially exploit children.

12.6 Parental Visibility

Where enabled by an institution, a verified parent or lawful guardian may be given access to information relating to their own child, such as attendance, academic performance and progress. Access controls are intended to prevent a parent from accessing another student's information.

13. Assessment Integrity and Proctoring

Certain ScholarSync assessments may use real-time integrity checks. ScholarSync's published architecture states that liveness and related proctoring checks are processed in real time and that raw biometric data, face templates, images and recordings are not retained; only an integrity score is retained for the relevant attempt. ScholarSync should maintain this architecture unless this Policy and the applicable notice are updated and any required consent and legal conditions are satisfied.

Assessment-integrity signals may include face/liveness presence, gaze-related signals, tab switching or similar events. Such signals are intended to assist authorised institutional personnel and should not be treated as an infallible finding of misconduct. Institutions should apply appropriate human review before taking material adverse academic action.

Where an integrity feature constitutes tracking or behavioural monitoring of a child, it will be enabled only where permitted by the DPDP Act and Rules, including any applicable educational exception and conditions.

14. Artificial Intelligence and Automated Educational Features

ScholarSync may use artificial intelligence to generate educational materials, assist learning, provide multilingual or voice-enabled experiences, analyse permitted academic information or support teachers and administrators. Personal data supplied to an AI-enabled feature will be limited to what is reasonably necessary for the specified purpose.

ScholarSync will not use identifiable children's educational data to create targeted advertising profiles. ScholarSync should not use identifiable institutional student data to train a general-purpose model for unrelated commercial purposes unless a separate lawful purpose, valid notice and any required consent have been established.

Where AI outputs may materially affect a student, ScholarSync encourages appropriate teacher or institutional review because AI-generated content and inferences may be incomplete or incorrect.

15. Data Sharing and Disclosures

ScholarSync does not sell student personal data. Personal data may be made available only as reasonably necessary for a specified purpose, including to:

  • the relevant institution and its authorised teachers, administrators and personnel;
  • verified parents or lawful guardians in relation to their linked child, subject to permissions;
  • Data Processors providing hosting, infrastructure, communications, security, support, analytics or other services on ScholarSync's behalf under contract;
  • authorised integration providers where the institution or Data Principal has enabled the integration and applicable requirements are satisfied;
  • professional advisers subject to appropriate confidentiality obligations where necessary; and
  • government authorities, courts or other persons where disclosure is required or authorised by applicable law.

Access is intended to be role-based and limited to the minimum reasonably necessary for the relevant function. ScholarSync's public security materials state that institutions are segregated using organisation-scoped controls and database row-level security.

16. Data Processors and Vendor Governance

Where ScholarSync engages a Data Processor, it will use a valid contract requiring processing consistent with ScholarSync's instructions and applicable law. ScholarSync will conduct proportionate diligence having regard to the nature of the processing, especially where student or children's personal data is involved.

ScholarSync will seek contractual and technical measures addressing confidentiality, security, incident notification, access restrictions, deletion/return of data, sub-processing and assistance with applicable Data Principal requests.

17. Data Accuracy and Completeness

Where personal data is likely to be used to make a decision affecting a Data Principal or is likely to be disclosed to another Data Fiduciary, ScholarSync will take reasonable efforts to ensure that the personal data is complete, accurate and consistent, as required by applicable provisions of the DPDP Act.

Users and institutions should keep account and academic information accurate and promptly request correction of material inaccuracies.

18. Security Safeguards

ScholarSync will implement reasonable security safeguards designed to prevent personal data breaches. The exact controls will evolve with risk, technology and legal requirements.

ScholarSync's currently published security controls include encryption in transit using TLS 1.3, encryption at rest using AES-256, application-level protection for sensitive fields, role-based access controls, organisation-level data isolation, session and activity monitoring, and authentication/session controls.

When the relevant DPDP Rules are in force, safeguards will be maintained having regard to the prescribed minimum measures, including appropriate encryption, obfuscation, masking or virtual-token measures; access controls; visibility through logs and monitoring; continuity measures such as backups; reasonable retention of relevant logs and personal data for detecting and investigating unauthorised access; contractual security requirements for Data Processors; and organisational measures to ensure adherence.

No method of electronic storage or transmission is absolutely secure. Accordingly, ScholarSync cannot guarantee that a security incident will never occur, but will maintain safeguards required by applicable law.

19. Personal Data Breaches

A personal data breach includes unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises confidentiality, integrity or availability.

ScholarSync maintains processes to identify, contain, investigate and remediate suspected personal data breaches. Where the applicable breach-notification provisions are in force, ScholarSync will notify affected Data Principals and the Data Protection Board of India in the form, manner and time required by the DPDP Rules.

The Data Principal notice will, where required, describe the nature, extent and timing of the breach, likely consequences, mitigation measures implemented or being implemented, safety measures the Data Principal may take, and appropriate business contact information.

Where required, ScholarSync will provide the Board with the initial information promptly and further prescribed details within the applicable period, including measures taken, findings concerning the person responsible where known, remedial measures and notifications made to affected Data Principals.

20. Data Principal Rights

When the relevant provisions are in force and subject to the DPDP Act, a Data Principal may exercise the rights in relation to personal data processed by ScholarSync.

21. Account Access, Authentication and Institutional Controls

ScholarSync uses role-based access controls for platform administrators, institution administrators, teachers, students and parents. Users must protect credentials and should not share passwords or authentication tokens.

Institutions are responsible for promptly updating user roles, disabling accounts that should no longer have access, and ensuring that personnel receive only permissions appropriate to their duties.

ScholarSync may suspend or restrict an account where reasonably necessary to protect personal data, investigate suspected misuse, comply with law or preserve platform security.

22. Changes to This Privacy Policy

ScholarSync may update this Privacy Policy to reflect changes in law, the commencement of additional DPDP provisions, regulatory guidance, platform functionality, security practices or data-processing activities.

Where a change materially affects the processing for which consent is required, ScholarSync will provide an appropriate notice and obtain fresh consent where required by law. The current version will identify its effective date and last-updated date.

Contact

Questions or concerns regarding this Privacy Policy may be directed to:

ScholarAI Systems (OPC) Private Limited
Bengaluru, Karnataka, India
Email: [email protected]

ScholarSync Learning Platform - AI-Powered Education