Privacy Policy
DRAFT FOR LEGAL REVIEW — not yet in force. Written from what Learnwise Academy actually does today. Text in [square brackets] is a placeholder or a question for the lawyer. Nothing here is legal advice.
Last updated: [date] · Version: 0.1 (draft)
1. Who this is for
Learnwise Academy is a learning portal used by schools in India (CBSE, Grades 1–12). This policy explains what personal data Learnwise handles, why, who sees it, and what rights people have. It is written for parents and guardians, students, teachers and school administrators.
Who is responsible for the data. Each school decides why and how its students' and staff's data is used: the school is the "Data Fiduciary" under the Digital Personal Data Protection Act, 2023 (DPDP Act). Learnwise, run by [LEGAL ENTITY NAME, address, CIN/registration] ("Learnwise", "we"), acts as the school's "Data Processor": we handle the data only on the school's behalf and instructions, under a Data Processing Agreement signed with each school. [Lawyer: confirm this split, and whether Learnwise is a fiduciary in any respect, e.g. for platform security logs or support queries.]
For questions about a particular child's data, contact the school office first. For questions about how Learnwise itself works, contact us at [privacy email]. Our Grievance Officer is [name, email, phone]. [Lawyer: DPDP Rules may require specific contact details to be published.]
2. What data we handle
| Whose | What | Where it comes from |
|---|---|---|
| Students | Full name; roll number (also used as the login ID); class (grade and section); the date on which the school recorded the parent's consent, and a short note; the student's own password (stored only as a one-way hash by our sign-in provider); answers to worksheets, scores, dates and times of attempts; written answers and the teacher's marks and feedback; questions raised with support | The school (enrolment); the student (their work) |
| Teachers and school administrators | Name; staff ID; designation; login ID; optional email; optional 10-digit mobile number; the classes and subjects assigned; marks and feedback they give; actions in the portal needed for security and support | The school; the person |
| Parents / guardians | Nothing. Learnwise does not collect parents' names, phone numbers or email addresses. The school keeps the consent form and the parent's details in its own records. | — |
What we do not collect: no student or parent phone numbers, no photographs, no location, no device identifiers for tracking, no government ID numbers, no payment details, no biometric data. [Lawyer: confirm this list stays true if profile photos are ever added — the prototype had an avatar upload; the product does not.]
Technical data. Our hosting and database providers keep the technical logs they need to run a secure service (for example IP addresses in server logs, sign-in timestamps). We use them for security and fault-finding only. [Lawyer/engineering: confirm retention periods with each provider.]
3. Why we use it
Only to run the service the school has asked for:
- to let students, teachers and administrators sign in, each seeing only what their role and class allow;
- to deliver worksheets, grade them, show students their own progress and class position, and let teachers see their own classes' results and mark written answers;
- to answer support queries raised by users;
- to keep the service secure, to limit AI use per school, and to find and fix faults.
What we never do with children's data: we do not track or monitor children's behaviour for any purpose beyond the educational features above, we do not show advertising of any kind, we do not build marketing profiles, and we do not sell or rent data to anyone. [Lawyer: confirm wording against DPDP Act s.9 and the Rules, including any exemptions the school may rely on.]
4. Parental consent for children
Students under 18 are children under the DPDP Act. A student cannot use Learnwise until the school has recorded verifiable parental consent.
- The school collects the consent from the parent or guardian, on its own form, before enrolling the child in Learnwise. [Lawyer: provide the model consent wording the school should use, and a statement of what "verifiable" means for the school's process.]
- A School Administrator then records, in Learnwise, the date on the consent form (and optionally a short note, such as a batch number). Learnwise does not store the form itself.
- Until that date is recorded, the student's account cannot sign in, and the database shows the student nothing. If consent is withdrawn, the School Administrator records the withdrawal and access stops immediately, even for a student who is already signed in. The record of the withdrawal and its date is kept.
- Who recorded or withdrew consent, and when, is stored with the student's record.
5. Who can see the data
- A student sees only their own work and their own class's subjects. A student never sees another student's name, answers or marks. A class position is shown as a number only ("2nd of 31").
- A teacher sees only the classes and subjects the School Administrator assigned to them: their students' names, results and written answers for those. A teacher cannot see other teachers' classes.
- A School Administrator sees their own school's data only, never another school's.
- Learnwise staff (the platform owner) can see all schools' data for support, administration and security, under confidentiality obligations. [Lawyer: describe access controls and logging; confirm named roles.]
- No other school can ever see a school's data. This is enforced inside the database itself (row-level security), not just in the screens, and is covered by automated tests.
6. Service providers (sub-processors) and where data goes
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage | India (Mumbai, ap-south-1) |
| Vercel | Hosting the website and server code | [India (Mumbai, bom1) — to be confirmed at deployment] |
| Anthropic (the "Claude" AI service) | Optional AI features, described below | [United States — confirm] |
AI features, precisely. AI is used in two ways, both optional and both started by a teacher or administrator, never by a student:
- Writing questions. The request contains the grade, subject, chapter and topic names. It contains no student data.
- Suggesting marks for written answers. The request contains the question, the model answer and the student's written answer, without the student's name, roll number or class. The teacher decides the final mark; the suggestion is never shown to the student.
Anthropic's terms for its business API state that content sent through the API is [not used to train its models — verify the current terms and attach the agreement]. [Lawyer: this is the one place student-written text leaves India. Advise whether the school's consent form must mention it, whether to offer schools an "AI marking off" setting, and any cross-border transfer notice required under DPDP s.16 and the Rules. Engineering: a per-school switch can be built if needed.]
7. How long we keep it
- Student data is kept while the student is enrolled at the school, and the school may remove a student at any time (this deletes their sign-in, record and attempts for good).
- When a school ends its agreement, we delete or return all of that school's data within [30] days, unless the law requires otherwise.
- Backups held by our database provider expire on the provider's schedule: [N] days. [Engineering: daily backups are planned and not yet switched on — fill in after they are.]
- Support queries are kept while open and for [12] months afterwards. [Lawyer: confirm.]
8. Keeping it safe
Passwords are never stored in readable form. New accounts start with a temporary password that must be changed at first sign-in and stops working after 7 days. Each school's data is separated from every other school's inside the database. Our secret keys never reach a user's browser. Sign-in attempts are limited. AI use is capped per school. [Lawyer/engineering: add encryption in transit and at rest statements once confirmed with each provider; add error monitoring, backups and an incident procedure once in place.]
If we discover a breach affecting personal data, we will tell the affected school without delay and within [72] hours so that it can meet its own duty to notify the Data Protection Board and affected families. [Lawyer: confirm period.]
9. Rights
Under the DPDP Act, a parent or guardian (for a child) and every adult user can:
- ask what data is held about them or their child;
- ask for correction of wrong data (a teacher who is a student's Class Teacher can correct names; the School Administrator can correct anything);
- ask for erasure of the data;
- withdraw consent at any time, as described in section 4;
- nominate another person to exercise these rights;
- make a complaint to the school, to our Grievance Officer, and then to the Data Protection Board of India.
How to ask: parents and students should ask the school office, which will pass requests to us or action them itself. We act on a school's request within [7] working days. [Lawyer: confirm timelines; confirm whether families may contact Learnwise directly.]
10. Changes to this policy
If we change it in a way that matters, we will tell the schools before the change takes effect, and publish the new version here with its date.
11. Contact
[LEGAL ENTITY NAME], [address]. Privacy: [privacy email]. Grievance Officer: [name, email].
Notes for the lawyer (not part of the published policy)
- Roles. The design assumes school = fiduciary, Learnwise = processor, with a DPA (see
data-processing-agreement.md). Please confirm, and tell us if the school's own privacy notice must also be changed. - Consent mechanics. The school collects and holds the consent form; Learnwise stores only the date, a note and who recorded it. Is that sufficient evidence for the school and for us?
- Under-18s who are close to 18. Students in Grades 11–12 may turn 18 during the year. Do we need a mechanism to move them to their own consent?
- AI and cross-border transfer (section 6). The only place student-written text is sent outside India.
- Retention and deletion periods marked in [brackets].
- Children's data exemptions and restrictions (DPDP s.9 and Rules): please check that nothing in the product — including class position and the "this month" averages shown to a student — counts as prohibited "behavioural monitoring". We believe it is educational feedback, not tracking.
- Name and contact details to publish for the Grievance Officer.