Data Protection Policy
This Data Protection Policy sets out the principles, responsibilities, and practices of Giby Technologies Private Limited in relation to the collection, processing, storage, transfer, and deletion of personal data on the EduEagle Platform. It applies to all data subjects whose data is processed through the Platform, and to all personnel of Giby Technologies Private Limited who handle such data.
1. Applicable Law
Giby Technologies Private Limited processes personal data in compliance with:
- The Information Technology Act, 2000 (India)
- The IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — governing the processing of Sensitive Personal Data or Information (SPDI)
- The Digital Personal Data Protection Act, 2023 (DPDP Act) — to the extent applicable provisions have been notified
- The Consumer Protection Act, 2019
- Any sector-specific regulations applicable to educational institutions under the UGC, AICTE, CBSE, or state education boards
2. Categories of Personal Data Processed
2.1 Ordinary Personal Data
- Name, contact details, role, and login credentials of institutional users
- Student academic records: attendance, marks, timetable allocations
- Faculty employment and qualification records
- Parent contact information linked to student profiles
2.2 Sensitive Personal Data or Information (SPDI)
Under the IT (SPDI) Rules 2011, the following data processed by the Platform may qualify as SPDI:
- Biometric data (if institutional photo attendance verification is enabled)
- Financial information: fee payment records, bank transfer details
- Health information: blood group (collected for admission compliance)
SPDI is processed only to the extent necessary for the provision of Platform services, collected with appropriate institutional consent, and protected with enhanced security controls.
2.3 Data of Minors
The Platform necessarily processes data of students who may be minors. Such processing is:
- Conducted solely for educational administration purposes
- Based on parental/guardian consent obtained by the institution at admission
- Not used for any commercial, advertising, or profiling purpose
- Subject to heightened access controls — minor student data is accessible only to authorised institutional roles
3. Data Processing Principles
The Company adheres to the following principles in all data processing activities:
Lawfulness: Data is processed on a lawful basis — contract performance, legal obligation, or consent
Purpose Limitation: Data is collected for specified, explicit purposes and not processed in a manner incompatible with those purposes
Data Minimisation: Only data necessary for the stated purpose is collected
Accuracy: Reasonable steps are taken to ensure data is accurate and up to date
Storage Limitation: Data is retained only for as long as necessary for its purpose or as required by law
Integrity & Confidentiality: Data is processed with appropriate technical and organisational security measures
Accountability: The Company maintains records of processing activities and can demonstrate compliance
4. Data Subject Rights
Individuals whose data is processed through the Platform have the following rights under applicable Indian law:
- Right to access personal data held about them
- Right to correct inaccurate personal data
- Right to erasure (deletion) of personal data, subject to legal retention requirements
- Right to grievance redressal — to raise a complaint with the Grievance Officer
- Right to nominate — to nominate a person to exercise rights on their behalf (DPDP Act)
Requests from individual users (students, parents, faculty) must be submitted through the institution. Institutions submit requests to privacy@edueagle.in. The Company responds within 30 days.
5. Data Transfers
Personal data processed through the Platform may be transferred to the following third-party processors operating outside India:
- Cloudinary Inc. (USA) — file storage
- Google LLC / Firebase (USA) — push notification infrastructure
Such transfers are necessary for the operation of the Platform. The Company ensures these transfers are conducted subject to appropriate contractual protections consistent with applicable Indian law. The Company does not transfer personal data to any other jurisdiction without adequate safeguards.
6. Data Breach Procedure
In the event of a personal data breach:
- The Company's security team will assess and contain the breach within 4 hours of detection
- Affected institutions will be notified within 72 hours
- A detailed incident report (nature of breach, data categories affected, number of individuals affected, remediation steps) will be provided within 7 days
- Where required by the DPDP Act or other applicable law, the Data Protection Board of India will be notified
- The Company will maintain a written record of all data breaches, their effects, and remedial actions taken
7. Data Retention Schedule
- Active user and institutional data: retained for the duration of the active subscription
- Fee and financial transaction records: 7 years (as required under Indian financial law)
- Audit logs: minimum 3 years
- Admission applications (rejected/pending): 1 year from application date
- Support ticket records: 2 years from closure
- Uploaded files (Cloudinary): duration of active account; deleted within 30 days of subscription termination on written request
On subscription termination, all institutional data is deleted or anonymised within 60 days unless a written request for a different period is received.
8. Internal Data Governance
- Access to production institutional data by Giby Technologies Private Limited personnel is strictly limited to those with a demonstrated operational need
- All Giby Technologies Private Limited personnel with access to personal data are bound by confidentiality obligations
- Data access events by internal personnel are logged and subject to periodic review
- This Data Protection Policy is reviewed at least annually and updated to reflect changes in law, technology, or business practice
9. Grievance Officer
Grievance Officer — Giby Technologies Private Limited
Email: privacy@edueagle.in
Address: Jaipur, Rajasthan, India
Complaints will be acknowledged within 48 hours and resolved within 30 days.
10. Policy Review
This Data Protection Policy is effective from 1 August 2026. It will be reviewed annually or following any material change in applicable law, Platform architecture, or data processing activities. The current version is always published at www.edueagle.in/legal/data-protection.