1. About this Privacy Policy
This Privacy Policy explains how Maskeen Edutech collects, receives, uses, shares, protects, retains, and deletes personal data when people visit our website, request a demonstration, contact support, purchase a subscription, or use a Maskeen Edutech school management product that links to this Policy (collectively, the “Services”).
In this Policy, “Maskeen Edutech”, “we”, “us”, and “our” mean the Maskeen Edutech supplier identified in the applicable proposal, order form, invoice, or subscription record. “Institution” or “Customer” means the school, pre-school, college, coaching centre, trust, society, group, or other organisation that subscribes to the Services. “Authorised User” means a school administrator, staff member, teacher, student, parent, guardian, or other person permitted to use an Institution workspace.
This Policy does not replace an Institution's own privacy notice. Institutions decide why student, parent, staff, academic, and operational information is entered into their workspace and remain responsible for the notices, permissions, and lawful basis required for that use.
2. Our data-protection roles
Our role depends on why the information is processed. We generally determine the purpose and means of processing website inquiries, demo requests, account administration, subscriptions, security, product usage, support, and our direct commercial relationship with an Institution.
For information that an Institution or its Authorised Users submit to or generate through the school ERP—referred to in this Policy as “Institution Data”—Maskeen Edutech generally acts on the Institution's instructions as a service provider or data processor. The Institution controls the workspace, user access, educational purpose, enabled modules, integrations, exports, and applicable retention decisions.
If your information is held in an Institution workspace because you are a student, parent, guardian, employee, applicant, or other member of its community, please normally contact that Institution first. We will assist the Institution with verified requests as required by the applicable agreement and law.
3. Personal data we process
The information processed depends on the modules selected by the Institution, the role assigned to each user, the integrations enabled, and the records the Institution chooses to maintain. An Institution should configure the Services to collect only information that is relevant, lawful, and necessary for its educational and administrative purposes.
Account, Institution, and user information
- Name, work email, phone number, profile photograph, role, designation, department, school or organisation, language, timezone, and user preferences.
- Password hashes, one-time verification records, session and device identifiers, account status, school assignments, role-based permissions, invitations, and login history.
- Institution profile, campus, board, academic year, classes, sections, subjects, departments, branding, addresses, and administrator contact details.
Student, parent, and guardian information
- Student name, photograph, admission and roll numbers, date of birth, gender, contact details, address, class, section, academic year, category, and status.
- Parent or guardian names, relationship, phone numbers, email addresses, addresses, occupations, emergency-contact details, and portal identity.
- Admission inquiries, applications, submitted documents, verification history, enrolment decisions, previous-school information, transport assignment, and identifiers generated by the Institution.
- Health, accessibility, emergency, identity, or other sensitive details only when the Institution chooses to collect them and has an appropriate lawful basis and safeguards.
Academic and school-operation information
- Attendance, leave, timetable, subject allocation, lesson and syllabus progress, homework, assignments, submissions, teacher feedback, and classroom activity.
- Examinations, schedules, marks, grades, report cards, promotion or graduation records, certificates, and academic performance reports.
- Library catalogue, issue and return history, transport route, vehicle and stop assignments, digital IDs, school documents, templates, and operational reports.
- Staff records, attendance, leave, responsibilities, class or subject assignments, and related HR information where the selected plan includes those modules.
Fees, subscriptions, communications, and files
- Fee structures, invoices, concessions, dues, receipts, payment status, transaction references, and reconciliation records maintained by the Institution.
- Maskeen Edutech plan, active-student slab, billing cycle, add-ons, storage allocation, taxes, invoices, subscription payment, and renewal information.
- Announcements, notices, diary entries, support requests, messages, push-notification records, email or SMS delivery status, and communication attachments.
- Uploaded photographs, admission documents, certificates, homework, study material, receipts, exports, and file metadata such as name, type, size, storage key, and access association.
Website, device, usage, and security information
- IP address, browser and operating-system details, user agent, device identifiers, app version, approximate location derived from network information, and timestamps.
- Feature usage, page visits, performance metrics, request identifiers, diagnostics, error information, security events, rate-limit records, administrative activity, and audit logs.
- Demo, contact, partnership, or support form details, including name, phone number, work email, Institution name, role, student range, preferred time, and message.
4. How we receive information
We receive information directly from people who complete a form, register, sign in, make a payment, upload a file, contact support, or otherwise use the Services. We also receive Institution Data from school administrators and authorised staff who create users, import records, configure modules, or record academic and operational activity.
Information may also come from parents, students, staff, applicants, payment providers, communication services, identity providers, cloud infrastructure, mobile applications, Institution-enabled integrations, and devices used to access the Services. Browsers, applications, servers, logs, cookies, and similar technologies may collect limited usage and security information automatically.
5. Why we process personal data
We process personal data only for defined service, support, security, commercial, and legal purposes. When we process Institution Data, those purposes are determined primarily by the Institution and the functionality its Authorised Users choose to use.
- Create and secure accounts, workspaces, schools, academic years, roles, and permissions.
- Operate admissions, student records, academics, attendance, examinations, fees, communication, transport, library, staff, reporting, and mobile experiences.
- Process subscriptions, taxes, invoices, payments, add-ons, storage, renewals, and plan entitlements.
- Provide onboarding, data migration, training, technical support, service notices, and requested integrations.
- Monitor reliability, troubleshoot errors, prevent misuse, investigate security incidents, and maintain auditability.
- Improve product usability and performance, understand aggregate feature usage, and develop relevant functionality.
- Comply with accounting, tax, contractual, regulatory, court, and lawful government requirements.
- Send promotional information where permitted and respect applicable unsubscribe or objection requests.
6. Legal grounds and consent
Where applicable law requires a legal ground, we rely as appropriate on performance of a contract, steps requested before entering a contract, compliance with legal obligations, legitimate interests that are not overridden by individual rights, consent, and other grounds recognised by law.
The Institution is responsible for determining the lawful basis for Institution Data, including student and employee records, and for obtaining any parent, guardian, staff, or student authorisation required for its use of the Services. Withdrawal of consent does not affect processing already carried out lawfully and may not prevent retention required by law or contract.
7. Children and student data
Maskeen Edutech is supplied to educational Institutions and is not offered directly to children for independent consumer use. A student account or record must be created, authorised, and supervised through the relevant Institution and, where required, a parent or guardian.
Institutions must provide age-appropriate notices, obtain parental or guardian consent where required, limit access according to educational roles, and avoid collecting student information that is unnecessary for the selected school process. Authorised Users must not place passwords, complete payment credentials, unrelated medical records, or other unnecessary sensitive information in free-text fields or support messages.
If you believe a child's information was submitted outside an authorised Institution relationship, contact us and identify the relevant school and record. We may refer the request to the Institution and take proportionate steps to restrict or remove the data after authority and identity are verified.
Note: Parents and guardians should direct routine requests about attendance, marks, fees, profile corrections, or school records to the Institution that controls the relevant workspace.
9. Payments and financial information
Subscription and school-fee payments may be processed by an independent payment gateway selected by Maskeen Edutech or configured by the Institution. The provider may collect card, bank, UPI, wallet, mandate, or other payment credentials under its own privacy terms. Maskeen Edutech is not intended to store complete card numbers, CVV values, UPI PINs, or online-banking passwords.
We may receive and retain limited transaction information such as payer or billing identity, amount, currency, payment method category, invoice or receipt number, provider order and payment references, status, tax information, failure reason, refund reference, and timestamps for reconciliation, support, fraud prevention, and legal recordkeeping.
10. Security and access controls
We use administrative, technical, and organisational safeguards designed for the nature of a multi-tenant school ERP. These may include scoped Institution and school access, role-based permissions, authentication controls, protected credentials, encrypted network transport, restricted file access, logging, backups, rate limits, monitoring, and security or audit events.
No online service can guarantee absolute security. Institutions must apply least-privilege access, maintain accurate user lists, protect administrator accounts, promptly disable departed users, review exports and integrations, secure devices, and report suspected compromise without sending passwords, one-time codes, payment credentials, or secret keys.
If we become aware of a personal-data incident, we will investigate and take containment, recovery, communication, and assistance measures appropriate to our role, the affected data, the agreement, and applicable law.
11. Retention, export, and deletion
We retain personal data only for as long as reasonably necessary for the relevant service purpose, Institution instructions, account security, dispute resolution, backup continuity, and legal, tax, accounting, or regulatory duties. The period varies by record type, selected module, subscription status, workspace settings, and applicable agreement.
Institutions should use available archive, export, correction, and deletion controls as part of their own retention programme. After cancellation, access and data-handling follow the subscription terms, order form, and any agreed transition period. Deleted information may remain temporarily in protected backups, security logs, or provider systems until their normal overwrite or deletion cycles complete.
We may retain limited billing, consent, opt-out, security, audit, and request records where necessary to meet law, prevent fraud, document compliance, or establish and defend legal claims. Anonymised or aggregated information that no longer identifies an individual may be retained for analytics and service improvement.
12. Data location and international transfers
Maskeen Edutech, its infrastructure providers, payment and communication services, and Institution-authorised integrations may process information in different states or countries. Those locations may apply different privacy and data-protection rules.
Where required, we use contractual, organisational, and technical measures intended to support lawful transfers. Institutions that require a particular hosting region, localisation commitment, or transfer mechanism should ensure that requirement is documented in the applicable order form or written agreement before affected data is uploaded.
13. Privacy rights and requests
Depending on the applicable law and processing context, an individual may have rights to receive information, access personal data, obtain a copy, correct inaccurate data, request erasure, restrict or object to processing, withdraw consent, request portability, opt out of eligible marketing, nominate another person, or raise a grievance with a competent authority.
Rights are not absolute. A request may be limited where identity or authority cannot be verified, the Institution controls the data, another person's rights would be affected, or retention is required for law, security, payments, contract, or legal claims.
Institution-controlled records
For student profiles, guardian details, attendance, marks, fees, staff records, certificates, or other Institution Data, contact the relevant Institution first. We may refer a request to its authorised administrator and assist with the response.
Requests handled by Maskeen Edutech
Email support@maskeenedutech.com from the address associated with the account. State the relevant Institution, your relationship to it, the right you wish to exercise, and the records involved. Do not email passwords, OTPs, full payment details, or unnecessary identity documents. We may request proportionate information to verify identity and authority.
15. Service and marketing communications
We may send essential authentication, account, security, billing, support, maintenance, policy, and operational messages while an account or commercial relationship is active. These communications are necessary to administer the Services and may not contain an unsubscribe option.
Product education, offers, events, or other promotional communications are sent where permitted. Recipients may use the unsubscribe method provided or contact support. An opt-out from Maskeen Edutech marketing does not stop essential service messages or communications independently sent by an Institution through its own workspace.
16. Policy changes, questions, and complaints
We may update this Policy when our Services, providers, legal requirements, or processing practices change. The current version and last-updated date will remain available on this page. Where required, material changes affecting existing account data will receive additional notice through the website, platform, email, or another suitable channel.
Questions, privacy requests, complaints, and requests for the appropriate grievance or data-protection contact can be sent to support@maskeenedutech.com. Include the relevant Institution and enough detail to route the request, but never send a password, OTP, payment PIN, complete card or bank credential, or unrelated sensitive document.
