Privacy Policy
This Privacy Policy describes how Giby Technologies Private Limited ("Company"), operating the EduEagle platform ("Platform"), collects, uses, stores, shares, and protects information about you when you access or use the Company's services. This Policy applies to all users of the Platform including institutional administrators, faculty members, students, parents, and any other persons who access the Platform.
By accessing or using EduEagle, you confirm that you have read, understood, and agreed to this Privacy Policy. If you do not agree, you must discontinue use of the Platform immediately.
1. About the Company
Company: Giby Technologies Private Limited
Product: EduEagle — Multi-Tenant School & College ERP Platform
Registered Address: Jaipur, Rajasthan, India
Data Controller Email: privacy@edueagle.in
Giby Technologies Private Limited is the data controller and data processor for all personal data processed through the EduEagle Platform.
2. Legal Basis for Processing
The Company processes personal data in compliance with the following applicable laws:
- The Information Technology Act, 2000 (India) and its amendments
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- The Digital Personal Data Protection Act, 2023 (DPDP Act) — to the extent applicable and as notified
- The Consumer Protection Act, 2019
The Company's legal bases for processing include: (a) performance of a contract with the institution; (b) compliance with legal obligations; (c) legitimate interests of operating and improving the Platform; and (d) consent, where specifically obtained.
3. What Data the Company Collects
3.1 Institutional Data (Collected from Institutions)
- Institution name, registered address, department structure, branding assets
- Billing and subscription information
- Admin account credentials (name, work email, role)
3.2 User Profile Data
- Full name, date of birth, gender, photograph
- Contact details: email address, mobile number, residential address
- Government-issued ID references (Aadhar number — for admission purposes only, not stored in full)
- Blood group, category (for statutory/admission compliance)
- Academic history, qualifications, roll numbers, employee ID numbers
- Parent/guardian name, contact details, and email (for linked parent accounts)
3.3 Operational Data (Generated During Use)
- Attendance records: present, absent, leave status per class session
- Examination marks, result cards, exam schedules
- Fee payment records: amount, method, transaction status, payment proofs uploaded
- Assignment submissions, grades, and faculty feedback
- Timetable allocations and classroom assignments
- Notice board communications sent and received
3.4 Technical Data (Automatically Collected)
- IP address, browser type, operating system, device information
- Login timestamps, session duration, pages accessed
- Firebase Cloud Messaging (FCM) device tokens for push notifications
- Audit log entries: action type, actor ID, timestamp, request ID
3.5 Uploaded Files
- Profile photographs (stored on Cloudinary)
- Assignment submission files: PDFs, images, archives (stored on Cloudinary)
- Fee payment proof screenshots (stored on Cloudinary)
All uploaded files are stored on Cloudinary's enterprise infrastructure. Local temporary copies are deleted immediately after successful upload.
4. How the Company Uses Your Data
- To create and manage user accounts and institutional tenants
- To deliver platform features: admissions, attendance, examinations, fee collection, HR, timetable, notices
- To send transactional communications: login credentials, payment receipts, admission status updates
- To send push notifications via Firebase for attendance alerts, notices, and updates
- To compute and display fee balances, attendance percentages, and exam results
- To maintain audit logs for institutional compliance and administrative oversight
- To provide customer support and resolve helpdesk tickets
- To maintain platform security: detect fraud, prevent unauthorised access, enforce account lockouts
- To improve platform performance, fix bugs, and develop new features
- To generate SaaS subscription invoices for institutions
5. Data Sharing & Third-Party Processors
The Company does not sell, rent, or trade your personal data to any third party. The Company shares data only with the following categories of processors, strictly for the purpose of operating the Platform:
5.1 Third-Party Sub-Processors
- Cloudinary Inc. — File storage for profile photos, assignment files, and payment proofs
- Google Firebase (Firebase Admin SDK) — Push notification delivery (FCM)
- SMTP Mail Provider — Transactional email delivery (credentials, receipts, alerts)
- MongoDB Atlas (or equivalent) — Database hosting and infrastructure
Each sub-processor is bound by their respective data processing agreements and applicable data protection laws. The Company conducts due diligence on all sub-processors before engagement.
5.2 Institutional Administrators
Within your institution's tenant, authorised administrators (collegeAdmin, principal, HOD, accountant) can access data of students, faculty, and parents within their institution. Cross-tenant data access is structurally prevented at the database level.
5.3 Legal Disclosure
The Company may disclose personal data if required by law, court order, or lawful government request under Indian law. The Company will notify the relevant institution where legally permissible before making any such disclosure.
6. Data Retention
- Active user accounts: retained for the duration of the institution's active subscription
- Audit logs: retained for a minimum of 3 years from the date of the logged action
- Fee transaction records: retained for 7 years to comply with financial record-keeping requirements under Indian law
- Admission application records (rejected/pending): deleted after 1 year from application date
- Uploaded files (Cloudinary): retained for the duration of the user's active account; deleted within 30 days of account termination upon institution request
- Support ticket data: retained for 2 years from ticket closure
On termination of an institution's subscription, the Company will delete or anonymise all institution data within 60 days, unless a longer retention period is required by law. Institutions may request early deletion in writing to privacy@edueagle.in.
7. Data Security
The Company implements the following technical and organisational security measures:
- All data in transit is encrypted using HTTPS/TLS
- Passwords are hashed using bcrypt with appropriate salt rounds — plaintext passwords are never stored
- JWT-based session management with token verification on every request
- Account lockout after three consecutive failed login attempts
- Multi-tenant data isolation enforced at the database query level via collegeId and branchId scoping
- Role-based access control (RBAC) ensuring users access only data their role permits
- Comprehensive audit logging of all administrative actions with IP address, browser, OS, and request ID
- File uploads processed via Multer with immediate local cleanup post-Cloudinary upload
Despite these measures, no system is completely secure. In the event of a personal data breach that is likely to result in risk to individuals, the Company will notify the affected institution and, where required, the appropriate authority, within 72 hours of the Company becoming aware of the breach.
8. Your Rights as a Data Principal
Under applicable Indian data protection law, you have the following rights:
- Right to access: request a copy of personal data the Company holds about you
- Right to correction: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of your personal data, subject to legal retention obligations
- Right to grievance redressal: raise a complaint about how your data is handled
- Right to nominate: nominate another individual to exercise rights on your behalf in the event of death or incapacity
To exercise any of these rights, contact the Company at privacy@edueagle.in. The Company will respond within 30 days. For student and parent data, requests must be submitted through the institution's authorised administrator.
9. Children's Data
The Platform is used by educational institutions and necessarily processes data of students who may be minors (under 18 years of age). Such data is processed solely for the purpose of providing educational administration services to the institution. Parental or guardian consent is obtained by the institution as part of the admission process before student data is entered into the Platform. The Company does not use minor student data for any commercial, advertising, or profiling purpose.
10. Cookies & Tracking
The EduEagle Platform uses session cookies managed via js-cookie to maintain user login state. The Company does not use third-party advertising cookies, behavioural tracking, or cross-site tracking technologies. For full details, refer to the Cookie Policy.
11. Changes to This Policy
The Company may update this Privacy Policy from time to time. When the Company makes material changes, the Company will notify institutions via email and display a notice on the Platform. Continued use of the Platform after the effective date of the updated Policy constitutes acceptance of the changes.
12. Contact & Grievance Officer
Giby Technologies Private Limited
Grievance Officer: privacy@edueagle.in
Address: Jaipur, Rajasthan, India
The Company will acknowledge your complaint within 48 hours and resolve it within 30 days.