Official Policy

Data Privacy & Security Policy

Detailed Data Handling Methodologies And Privacy Bindings Governing the ISMS Core, Admin ERP Portal, Parents App, and Teacher App.

COMPILED : March 11, 2026
VERSION : v3.4.1
ENDPOINTS : ERP Portal, Parents App, Teacher App
Core Privacy Operations ISMS Core, Including The ERP Portal, Parents App, And Teacher App, Intercepts Strictly Bounded API Structures Owned Implicitly By The Registered School Infrastructure. No Independent Behavioral Analytics, Third-Party Advertising Tracking, Or Location Tracking Exist Within The Apps Or Web Platforms. Data Is Kept Secure Behind Encrypted Storage And Robust Server-Side Safeguards.

Policy Sections

01 Architecture Origin & Authority

Durgaai Solutions Holds The Primary Source Code Authority Of The ISMS Core, ERP Portal, Parents App, And Teacher App. Our Platforms Do Not Operate Like Social Networks; Instead, They Act As Secure Remote Views Into The Institution's Private Database Relying On Secure APIs To Retrieve And Update Academic And Administrative Records.

02 Data Collection Scope

The ERP Portal, Parents App, And Teacher App Do Not Use Background Location Or Tracking Loops. Data Updates Occur Exclusively When Users Explicitly Request Information Via Authenticated APIs.

CategoryData StructureERP Function
User AuthenticationEncrypted Identity TokensMaintains Secure Logins
User ProfilesName, Roll Number, Phone MatrixDisplays Accurate Student/Staff Data
Fee RecordsCompiled Invoices, PaymentsTracks Pending Dues And Historical Receipts
Attendance InfoDaily Presence/Absence MarkingPopulates Class Dashboards And Parent Alerts
Exam ScoresTheory/Practical Marks, GradesGenerates Structured Report Cards
Platform AccessAssigned School Code ValidationGuarantees Connection To The Correct School
Strict Privacy Enforcement We Fundamentally Prohibit Retrieval of Hardware MEIDs, AD-IDs, GPS Geofencing Traces, or Unauthorized Biometric Integrations Within the ISMS Core, Parents App, Teacher App, and ERP Portal. Period.

03 App Functionality & Utility

Data Retrieved From The School's Central Database Is Processed Efficiently To Power Features Inside The Portal And Apps:

04 Cryptography Standards & Wipes

Local Storage: Critical Authentication Tokens Are Secured Inside The Native Android EncryptedSharedPreferences Mechanism. Logging Out Manually Automatically Purges All Stored Credentials On The Device.

Network Transit: All Data Transfers Passing Between The Mobile Apps, The Web Portal, And Our Cloud Servers Mandate Strict TLS v1.3 Network Encryption. Plaintext Requests Are Universally Denied.

Secure Session Expiry Login Sessions Rely On Time-Stamped JSON Web Tokens. Manually Logging Out Or Failing To Ping Within The Expiration Timeline Naturally Expires The Active Session And Prevents Any Further Data Access On That Device Until Full Re-Authentication.

05 Institutional Data Isolation

This ERP System Operates Entirely Inside A Secure Closed-Ecosystem:

06 Data Retention & Account Deletion

Google Play Account Deletion Policy Users Firmly Retain The Right To Delete Their Accounts And Completely Wipe Their Associated Data. To Request Account Termination And Permanent Profile Deletion:

1. Contact Your Respective School Administrator Directly, As They Locally Manage The Active ERP Records.
2. Alternatively, Submit A Formal Deletion Request To contact@durgaaisolutions.in Strictly Including Your School Code And Admission/Employee ID. Verified Account Data Will Be Permanently Wiped From Our Active Databases Within A 14-Day SLA.

Device Retention: Data Retention On Device Automatically Ceases When The User Clears Their Native App Cache, Explicitly Logs Out, Or Uninstalls The Mobile App Package. All Persistent Academic Histories And Fee Records Contained Firmly On Our Centralized Database Clusters Remain Strictly Governed By The Registering School's Own Retention Policies Until A Deletion Request Is Initiated.

07 Access Hierarchies & Children's Privacy

The Entire Ecosystem Enforces Strict Role-Based Access Controls (RBAC). PARENT Accounts Hold Read-Only Privileges To Their Child's Specific Reports, Whereas TEACHER Accounts Hold Localized Write Access To Mark Attendance Solely In Designated Enrolled Classes. ADMIN Roles Possessing Access To The Web Portal Manage Overriding Capabilities.

Crucially Regarding Children's Privacy (COPPA): These Applications Are Targeted Exclusively At Adults (Parents, Teachers, School Administrative Staff) To Manage Structural Educational Records Securely. Minor Students Under The Age Of 13 Do Not Possess Dedicated App Generation Logins Under Our Centralized Architecture, Avoiding Direct Child Data Collection Entirely.

08 Verified External Dependencies

To Establish Safe Internet Connectivity Without Building Untested Code, The Mobile Apps Seamlessly Utilize Standard Underlying Open-Source Utilities Globally Recognized For Integrity:

Compliance & Support Contact

Users Or Parents Wishing To Process Explicit Data Deletion Actions Or Request Privacy Clarifications Can Contact Our Dedicated Team With An Internal Response SLA Of ~3 To 5 Business Days.

contact@durgaaisolutions.in