Privacy Policy
Last updated: July 25, 2026
Contents
- 1. Overview
- 2. Scope of This Privacy Policy
- 3. Roles of the Institution and ERPfied
- 4. Information We Process
- 5. Information Processed Through Mobile Applications
- 6. Grounds and Purposes for Processing
- 7. Notice and Consent
- 8. Data Minimisation and Purpose Limitation
- 9. Data Ownership and Control
- 10. Student and Children's Information
- 11. Mobile Login and Account Management
- 12. Device Information and Notifications
- 13. Accuracy and Updating of Information
- 14. Data Sharing and Service Providers
- 15. Third-Party Services and Integrations
- 16. AI-Assisted and Automated Processing
- 17. Data Storage and Security
- 18. Personal-Data Breaches
- 19. Data Retention
- 20. International and Cross-Border Processing
- 21. Rights of Data Principals
- 22. How to Submit a Privacy Request
- 23. Correction, Completion, Updating and Erasure
- 24. Withdrawal of Consent
- 25. Grievance Redressal and Privacy Contact
- 26. Nomination
- 27. Mobile Access Deactivation
- 28. Cookies, Sessions and Technical Logs
- 29. Advertising and Sale of Data
- 30. Changes to This Privacy Policy
- Contact
1. Overview
This Privacy Policy explains how ERPfied collects, receives, processes, stores, uses, shares and protects personal data and other information through its website, enterprise resource planning platform, mobile applications and related services.
ERPfied provides technology, ERP, finance, academic, administrative, hostel/boarding management and mobile-application services to educational institutions.
Most personal and operational information processed through ERPfied is supplied, managed and controlled by the relevant school or educational institution.
ERPfied intends to process personal data in accordance with applicable data-protection laws, including the Digital Personal Data Protection Act, 2023, the rules made under it, and the Information Technology Act, 2000 to the extent still applicable.
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- the ERPfied website;
- ERPfied-hosted ERP environments;
- ERPfied mobile applications;
- implementation, hosting, maintenance and support services;
- platform administration;
- direct business enquiries and communications;
- billing, service and account-management information handled directly by ERPfied.
Individual schools and institutions may maintain their own privacy policies, notices and data-handling procedures.
Users should contact their institution where a request relates to institution-controlled student, parent, guardian, staff, academic, attendance, fee, payment, hostel or operational records.
3. Roles of the Institution and ERPfied
Depending on the context and applicable contractual arrangements:
- the school or institution generally acts as the Data Fiduciary for personal data contained in its ERP environment;
- ERPfied generally acts as a Data Processor when processing institution-controlled personal data under the institution's instructions;
- ERPfied may act as a Data Fiduciary for information whose processing purposes and means are determined directly by ERPfied, including website enquiries, support requests, billing contacts, service administration and direct business communications.
The institution generally determines:
- what student, parent, guardian, staff, hostel and operational information is entered into the platform;
- who may access that information;
- how institutional records are used;
- how long those records must be retained;
- how requests concerning institutional records are handled.
ERPfied does not independently create or collect student records without authorization from the relevant institution.
4. Information We Process
Depending on the ERPfied services used by an institution, personal data and related information processed through the platform may include:
- institution and school information;
- student names, identifiers, photographs and academic details;
- parent and guardian details;
- staff and employee information;
- addresses and contact information;
- attendance information, including biometric attendance data where an institution enables it;
- fee schedules, invoices, receipts and payment information;
- transport, hostel and boarding-service information, including room and bed allocation, gate movement and check-in/check-out timestamps;
- circulars, messages and communication records;
- login and account information;
- support requests;
- usage, audit, security and system logs;
- device and notification information where mobile services are enabled;
- information necessary for reporting, audit, regulatory or institutional operations.
Biometric attendance data is treated as a more sensitive category of information. Institutions enabling biometric attendance are responsible for obtaining any additional consent required under applicable law and for instructing ERPfied on appropriate access restrictions.
ERPfied seeks to process only information reasonably necessary to provide, secure, maintain and support the relevant services.
5. Information Processed Through Mobile Applications
ERPfied mobile applications may process:
- the institution or school code entered by the user;
- institution configuration returned through the school lookup service;
- login credentials submitted to the selected institution's ERP environment;
- secure authentication or session information stored on the device;
- linked student, parent, guardian or staff information;
- academic, attendance, fee, payment, hostel and circular information;
- notification preferences;
- device notification tokens where push notifications are enabled;
- limited technical and diagnostic information required for security, reliability and troubleshooting.
The mobile application does not provide public account signup or self-registration.
Accounts are created, issued or approved by the relevant institution. The mobile app connects users only to the institution selected or identified through the school-code configuration.
6. Grounds and Purposes for Processing
Personal data may be processed based on:
- consent, where consent is the applicable basis and has been given for a specified purpose;
- legitimate uses recognized under applicable law, which may include data voluntarily provided by an individual for a specified purpose, processing necessary for employment-related purposes, compliance with a legal obligation or court order, and processing necessary to respond to a medical emergency or to protect life, health or safety;
- contractual obligations between ERPfied and the institution;
- legal or regulatory requirements;
- other permitted uses under applicable law.
Information may be used to:
- provide and operate the ERPfied platform;
- authenticate authorized users;
- display institution-authorized academic, attendance, fee, payment, hostel and operational information;
- generate reports, receipts, statements and records;
- send institution communications and notifications;
- provide implementation, support and troubleshooting;
- protect the platform from unauthorized access;
- detect, prevent and investigate security incidents;
- monitor availability and performance;
- maintain backups and business continuity;
- administer service contracts and billing;
- meet contractual, audit, regulatory and legal obligations.
ERPfied does not use school, student, parent, guardian or staff information for unrelated marketing or behavioural advertising.
7. Notice and Consent
Where ERPfied relies on consent as the basis for processing personal data, the relevant notice will explain, in clear and plain language:
- what personal data is being collected;
- the purpose for which it will be processed;
- how consent may be withdrawn;
- how the individual may exercise applicable rights;
- how a grievance may be submitted;
- where relevant, the identity of any Consent Manager involved in managing consent.
Where the institution collects personal data and determines the purpose of processing, the institution is generally responsible for providing the required notice and obtaining consent or another lawful basis.
ERPfied may assist institutions with platform functionality required to communicate notices, record preferences, manage consent artefacts, or respond to privacy requests.
Withdrawal of consent does not affect processing already carried out lawfully before the withdrawal.
Withdrawal may also be subject to records that must continue to be retained for academic, contractual, regulatory, finance, audit, legal or institutional purposes.
8. Data Minimisation and Purpose Limitation
ERPfied seeks to limit processing to personal data reasonably necessary for the stated service, operational, security, contractual or legal purpose.
Institution-controlled personal data should not be used by ERPfied for unrelated purposes.
ERPfied does not use institutional data to build advertising profiles or for behavioural advertising.
9. Data Ownership and Control
Operational and institutional data entered into ERPfied remains under the ownership and control of the relevant school or educational institution, subject to applicable contractual and legal requirements.
ERPfied does not sell, rent or trade school, student, parent, guardian or staff data.
The institution determines access to its records and remains responsible for the accuracy, completeness and lawful use of institution-controlled information.
10. Student and Children's Information
Student information is processed as part of services provided to educational institutions. Applicable law generally treats an individual under 18 years of age as a child for this purpose.
Institutions are responsible for ensuring that they have the authority, consent or other lawful basis required to provide and process children's personal data through ERPfied, including obtaining verifiable consent from a parent or lawful guardian where required.
ERPfied does not:
- use children's personal data for behavioural advertising;
- direct targeted advertising at children;
- knowingly undertake tracking or behavioural monitoring of children for advertising or marketing purposes.
Where an institution enables safety-related features — such as attendance tracking, biometric attendance, transport tracking, or hostel gate movement and check-in/check-out logging — this processing is treated as being for the child's health, safety or education, and is carried out under the institution's instructions and not for advertising or profiling purposes.
Any processing of children's information should be limited to legitimate educational, institutional, safeguarding, administrative and related purposes.
11. Mobile Login and Account Management
Parent, guardian, staff and other mobile-user accounts are created, issued or approved by the relevant institution.
The mobile application does not allow users to create an independent public account.
Users who need to:
- correct account details;
- update linked students or guardians;
- correct institutional records;
- disable mobile access;
- withdraw an applicable consent;
- submit a privacy-related request
should contact their institution or ERPfied support.
Logging out removes the active mobile session from the device but does not delete official records maintained by the institution.
12. Device Information and Notifications
Where mobile notifications are enabled, ERPfied may process:
- device notification tokens;
- mobile platform information;
- notification preferences;
- notification delivery and read status;
- limited device information required to maintain notification reliability.
This information is used to provide institution-related notifications and maintain mobile-service functionality. Users may manage available notification preferences through the application or their device settings.
Disabling notifications does not necessarily stop other institution-authorized communications such as email, SMS or WhatsApp messages.
13. Accuracy and Updating of Information
ERPfied and the relevant institution may take reasonable steps to ensure that personal data is complete, accurate and consistent where the information is likely to be used to make decisions affecting an individual or disclosed to another party.
Users should notify their institution where school-controlled information is inaccurate, incomplete or outdated.
Requests concerning ERPfied-controlled support, website or business-contact information may be submitted to support@erpfied.com.
14. Data Sharing and Service Providers
Information may be shared only where necessary with:
- authorized institution users;
- parents, guardians, staff or other users authorized by the institution;
- ERPfied employees or contractors with a legitimate service need;
- service providers required to operate and support the platform;
- payment, banking, messaging, hosting or infrastructure providers;
- professional advisers where required for audit, security, insurance or legal purposes;
- government, law-enforcement or regulatory authorities where disclosure is required by law.
Service providers are expected to process information only for the required service purpose and according to applicable contractual obligations.
ERPfied does not disclose institution-controlled personal data for third-party advertising.
15. Third-Party Services and Integrations
ERPfied may integrate with services such as:
- payment gateways;
- banks and payment-service providers;
- SMS and WhatsApp providers;
- email providers;
- Firebase and other mobile-infrastructure services;
- cloud-hosting and infrastructure providers;
- biometric, attendance and other hardware systems;
- document, file-storage and backup providers;
- AI and large-language-model providers used to power platform features such as reporting assistance, drafting support or workflow automation.
Where AI or large-language-model providers are used to process institution-controlled personal data, ERPfied intends to limit the data shared to what is reasonably necessary for the relevant feature, and to use providers that agree not to use institution data to train their own models except where separately agreed. This section will be updated with named providers as such features are deployed to institutions.
Use of these services may also be governed by the privacy terms of the respective third-party providers.
ERPfied should disclose or document material service providers where required by contract or applicable law.
16. AI-Assisted and Automated Processing
Where ERPfied platform features use AI or automated processing (for example, to draft communications, summarize records, or suggest routine actions), such features are intended to assist authorized institution users rather than make final decisions affecting a student, parent, guardian or staff member without human review.
ERPfied does not use AI processing to make solely automated decisions that produce a legal or similarly significant effect on an individual without an opportunity for institution-level human review, except where an institution has specifically configured and authorized such a workflow.
Institutions remain responsible for reviewing AI-assisted outputs before relying on them for decisions affecting individuals.
17. Data Storage and Security
ERPfied uses reasonable technical and organizational safeguards intended to protect personal data. These safeguards may include:
- role-based access controls;
- authenticated access;
- encrypted network communication;
- secure hosting;
- access and system logging;
- backups;
- monitoring;
- session controls;
- restricted administrative access;
- software updates;
- security reviews;
- incident-response procedures;
- access limitation based on job responsibility.
No electronic system can guarantee absolute security.
ERPfied continually works to reduce operational and security risks and expects institutions to maintain appropriate user-access, password and administrative controls.
18. Personal-Data Breaches
ERPfied maintains processes intended to identify, assess, contain and respond to personal-data breaches.
Where a breach affects institution-controlled data, ERPfied will notify and cooperate with the relevant institution according to contractual and legal requirements.
ERPfied or the relevant institution may provide notice to affected individuals, the Data Protection Board of India or another competent authority where required by applicable law.
The timing, form and content of any notification will depend on the nature of the incident and applicable legal requirements.
19. Data Retention
Information may be retained:
- for the duration of the contractual relationship with the institution;
- according to the institution's instructions;
- for as long as necessary to provide the relevant service;
- for security, fraud prevention and dispute resolution;
- for audit, finance, legal or regulatory purposes;
- according to agreed exit and data-handling procedures.
ERPfied seeks to delete or anonymize personal data when it is no longer required for the relevant purpose and no contractual, legal, audit, security or operational reason requires retention.
Official academic, attendance, finance, fee, payment, hostel, statutory and audit records may be retained by the institution after a user's mobile access has been disabled.
20. International and Cross-Border Processing
Depending on the hosting infrastructure and service providers selected for an institution, personal data may be processed in countries other than the individual's country of residence.
ERPfied intends to use contractual, technical and organizational safeguards appropriate to the circumstances.
Cross-border processing will remain subject to any restrictions notified by the Central Government of India from time to time, including any list of restricted jurisdictions.
21. Rights of Data Principals
Subject to applicable law, identity verification and contractual arrangements, an individual may have the right to:
- obtain a summary of personal data being processed and the processing activities carried out;
- obtain information about the identities of other Data Fiduciaries or Data Processors with whom personal data has been shared;
- request correction of inaccurate personal data;
- request completion of incomplete personal data;
- request updating of personal data;
- request erasure where retention is no longer necessary or legally required;
- withdraw consent where processing is based on consent;
- have readily available means to submit a grievance;
- nominate another person to exercise applicable rights in the event of death or incapacity, where provided by law.
These rights are not absolute.
Requests may be restricted where information must be retained for academic, contractual, statutory, regulatory, audit, finance, security, dispute-resolution or legal purposes.
22. How to Submit a Privacy Request
Requests concerning school or institution-controlled records should generally be submitted to the relevant institution. This includes requests relating to:
- student records;
- parent or guardian details;
- attendance;
- academic records;
- fee and payment records;
- hostel and boarding records;
- staff or employee records;
- linked students;
- institutional login access.
Requests concerning ERPfied-controlled website enquiries, support records, billing contacts or direct business-contact information may be submitted to: support@erpfied.com
ERPfied may need to verify the requester's identity before acting on a request.
Where ERPfied acts as a Data Processor, it will forward the request to the relevant institution or assist the institution in responding.
23. Correction, Completion, Updating and Erasure
Where applicable, individuals may request correction, completion or updating of personal data.
Erasure may be requested where personal data is no longer necessary for the purpose for which it was processed and no legal, contractual, audit, academic, finance, security or institutional obligation requires continued retention.
ERPfied will generally act on requests concerning institution-controlled records only under the instructions or authorization of the relevant institution.
Disabling mobile access does not automatically erase institutional records.
24. Withdrawal of Consent
Where processing is based on consent, the individual may withdraw consent through the method communicated in the relevant notice or by contacting the institution or ERPfied.
Withdrawal should be as reasonably accessible as the method used to provide consent.
Withdrawal may affect the availability of services that require the relevant personal data.
Withdrawal does not require deletion of information that must continue to be retained for lawful, contractual, academic, finance, audit, security or regulatory reasons.
25. Grievance Redressal and Privacy Contact
Individuals may raise privacy concerns or grievances by contacting ERPfied's privacy contact at: support@erpfied.com
This inbox is monitored by a person designated to answer questions about ERPfied's processing of personal data.
Requests concerning institution-controlled records may be referred to the relevant institution.
ERPfied will acknowledge and review privacy-related grievances and will seek to respond within a reasonable period as required by applicable law, contract or internal procedure.
Where required by law, an individual may escalate an unresolved grievance to the Data Protection Board of India or another appropriate authority after first using the available grievance-redressal process.
26. Nomination
Where applicable law provides a nomination right, an individual may nominate another person to exercise applicable data-protection rights in the event of the individual's death or incapacity.
Any such request may be subject to identity verification, proof of nomination and applicable legal or institutional procedures.
27. Mobile Access Deactivation
Users may request that their mobile access be disabled by contacting their institution or ERPfied support. Disabling mobile access may:
- prevent future mobile logins;
- end active sessions;
- stop mobile notifications;
- remove mobile device-registration information.
Disabling mobile access does not automatically delete academic, attendance, fee, payment, hostel, statutory, audit or other official records maintained by the institution.
29. Advertising and Sale of Data
ERPfied does not:
- display third-party advertising in its mobile applications;
- sell personal data;
- rent or trade school or student information;
- use institution-controlled data for behavioural advertising;
- provide institution data to data brokers;
- direct targeted advertising at children using information processed through the ERPfied platform.
30. Changes to This Privacy Policy
ERPfied may update this Privacy Policy periodically to reflect changes in its services, technology, applicable law or business practices.
The latest version will be published on this page with its updated revision date.
Material changes may also be communicated through the platform, mobile application, email or institution where appropriate.
Contact
For privacy-related questions, support requests, grievances or mobile-access concerns, contact:
Email: support@erpfied.com
Website: https://erpfied.com
Users may also contact their school or institution for requests concerning institution-controlled records.