Get your free school ERP demo today.Book now

Privacy at Maskeen Edutech

Privacy Policy

This Policy explains how Maskeen Edutech collects, uses, shares, protects, retains, and deletes information across its website, school ERP, mobile experiences, subscriptions, support services, and Institution-authorised integrations.

Last updated: 3 September 2026

1. About this Privacy Policy

This Privacy Policy explains how Maskeen Edutech collects, receives, uses, shares, protects, retains, and deletes personal data when people visit our website, request a demonstration, contact support, purchase a subscription, or use a Maskeen Edutech school management product that links to this Policy (collectively, the “Services”).

In this Policy, “Maskeen Edutech”, “we”, “us”, and “our” mean the Maskeen Edutech supplier identified in the applicable proposal, order form, invoice, or subscription record. “Institution” or “Customer” means the school, pre-school, college, coaching centre, trust, society, group, or other organisation that subscribes to the Services. “Authorised User” means a school administrator, staff member, teacher, student, parent, guardian, or other person permitted to use an Institution workspace.

This Policy does not replace an Institution's own privacy notice. Institutions decide why student, parent, staff, academic, and operational information is entered into their workspace and remain responsible for the notices, permissions, and lawful basis required for that use.

2. Our data-protection roles

Our role depends on why the information is processed. We generally determine the purpose and means of processing website inquiries, demo requests, account administration, subscriptions, security, product usage, support, and our direct commercial relationship with an Institution.

For information that an Institution or its Authorised Users submit to or generate through the school ERP—referred to in this Policy as “Institution Data”—Maskeen Edutech generally acts on the Institution's instructions as a service provider or data processor. The Institution controls the workspace, user access, educational purpose, enabled modules, integrations, exports, and applicable retention decisions.

If your information is held in an Institution workspace because you are a student, parent, guardian, employee, applicant, or other member of its community, please normally contact that Institution first. We will assist the Institution with verified requests as required by the applicable agreement and law.

3. Personal data we process

The information processed depends on the modules selected by the Institution, the role assigned to each user, the integrations enabled, and the records the Institution chooses to maintain. An Institution should configure the Services to collect only information that is relevant, lawful, and necessary for its educational and administrative purposes.

Account, Institution, and user information

  • Name, work email, phone number, profile photograph, role, designation, department, school or organisation, language, timezone, and user preferences.
  • Password hashes, one-time verification records, session and device identifiers, account status, school assignments, role-based permissions, invitations, and login history.
  • Institution profile, campus, board, academic year, classes, sections, subjects, departments, branding, addresses, and administrator contact details.

Student, parent, and guardian information

  • Student name, photograph, admission and roll numbers, date of birth, gender, contact details, address, class, section, academic year, category, and status.
  • Parent or guardian names, relationship, phone numbers, email addresses, addresses, occupations, emergency-contact details, and portal identity.
  • Admission inquiries, applications, submitted documents, verification history, enrolment decisions, previous-school information, transport assignment, and identifiers generated by the Institution.
  • Health, accessibility, emergency, identity, or other sensitive details only when the Institution chooses to collect them and has an appropriate lawful basis and safeguards.

Academic and school-operation information

  • Attendance, leave, timetable, subject allocation, lesson and syllabus progress, homework, assignments, submissions, teacher feedback, and classroom activity.
  • Examinations, schedules, marks, grades, report cards, promotion or graduation records, certificates, and academic performance reports.
  • Library catalogue, issue and return history, transport route, vehicle and stop assignments, digital IDs, school documents, templates, and operational reports.
  • Staff records, attendance, leave, responsibilities, class or subject assignments, and related HR information where the selected plan includes those modules.

Fees, subscriptions, communications, and files

  • Fee structures, invoices, concessions, dues, receipts, payment status, transaction references, and reconciliation records maintained by the Institution.
  • Maskeen Edutech plan, active-student slab, billing cycle, add-ons, storage allocation, taxes, invoices, subscription payment, and renewal information.
  • Announcements, notices, diary entries, support requests, messages, push-notification records, email or SMS delivery status, and communication attachments.
  • Uploaded photographs, admission documents, certificates, homework, study material, receipts, exports, and file metadata such as name, type, size, storage key, and access association.

Website, device, usage, and security information

  • IP address, browser and operating-system details, user agent, device identifiers, app version, approximate location derived from network information, and timestamps.
  • Feature usage, page visits, performance metrics, request identifiers, diagnostics, error information, security events, rate-limit records, administrative activity, and audit logs.
  • Demo, contact, partnership, or support form details, including name, phone number, work email, Institution name, role, student range, preferred time, and message.

4. How we receive information

We receive information directly from people who complete a form, register, sign in, make a payment, upload a file, contact support, or otherwise use the Services. We also receive Institution Data from school administrators and authorised staff who create users, import records, configure modules, or record academic and operational activity.

Information may also come from parents, students, staff, applicants, payment providers, communication services, identity providers, cloud infrastructure, mobile applications, Institution-enabled integrations, and devices used to access the Services. Browsers, applications, servers, logs, cookies, and similar technologies may collect limited usage and security information automatically.

5. Why we process personal data

We process personal data only for defined service, support, security, commercial, and legal purposes. When we process Institution Data, those purposes are determined primarily by the Institution and the functionality its Authorised Users choose to use.

  • Create and secure accounts, workspaces, schools, academic years, roles, and permissions.
  • Operate admissions, student records, academics, attendance, examinations, fees, communication, transport, library, staff, reporting, and mobile experiences.
  • Process subscriptions, taxes, invoices, payments, add-ons, storage, renewals, and plan entitlements.
  • Provide onboarding, data migration, training, technical support, service notices, and requested integrations.
  • Monitor reliability, troubleshoot errors, prevent misuse, investigate security incidents, and maintain auditability.
  • Improve product usability and performance, understand aggregate feature usage, and develop relevant functionality.
  • Comply with accounting, tax, contractual, regulatory, court, and lawful government requirements.
  • Send promotional information where permitted and respect applicable unsubscribe or objection requests.

7. Children and student data

Maskeen Edutech is supplied to educational Institutions and is not offered directly to children for independent consumer use. A student account or record must be created, authorised, and supervised through the relevant Institution and, where required, a parent or guardian.

Institutions must provide age-appropriate notices, obtain parental or guardian consent where required, limit access according to educational roles, and avoid collecting student information that is unnecessary for the selected school process. Authorised Users must not place passwords, complete payment credentials, unrelated medical records, or other unnecessary sensitive information in free-text fields or support messages.

If you believe a child's information was submitted outside an authorised Institution relationship, contact us and identify the relevant school and record. We may refer the request to the Institution and take proportionate steps to restrict or remove the data after authority and identity are verified.

Note: Parents and guardians should direct routine requests about attendance, marks, fees, profile corrections, or school records to the Institution that controls the relevant workspace.

8. When information is shared

We do not sell Institution Data or student personal data, and we do not use it for cross-context behavioural advertising. Information is disclosed only as needed to provide the Services, follow an Institution's authorised configuration, operate our business, protect users, or meet legal obligations.

Service providers and connected services

  • Cloud hosting, databases, storage, backups, content delivery, email, SMS, push notification, monitoring, customer support, analytics, and security providers.
  • Payment gateways, banks, and billing providers used for Institution subscriptions or school fee transactions configured by the Institution.
  • App stores, communication platforms, biometric or transport providers, and other integrations selected or authorised by the Institution.

Other permitted recipients

  • Institution administrators and Authorised Users whose role and school scope permit access.
  • Professional advisers, auditors, insurers, financing or corporate-transaction participants subject to appropriate duties.
  • Courts, regulators, law-enforcement bodies, or government authorities when disclosure is lawfully required or reasonably necessary to protect rights, safety, and service integrity.

9. Payments and financial information

Subscription and school-fee payments may be processed by an independent payment gateway selected by Maskeen Edutech or configured by the Institution. The provider may collect card, bank, UPI, wallet, mandate, or other payment credentials under its own privacy terms. Maskeen Edutech is not intended to store complete card numbers, CVV values, UPI PINs, or online-banking passwords.

We may receive and retain limited transaction information such as payer or billing identity, amount, currency, payment method category, invoice or receipt number, provider order and payment references, status, tax information, failure reason, refund reference, and timestamps for reconciliation, support, fraud prevention, and legal recordkeeping.

10. Security and access controls

We use administrative, technical, and organisational safeguards designed for the nature of a multi-tenant school ERP. These may include scoped Institution and school access, role-based permissions, authentication controls, protected credentials, encrypted network transport, restricted file access, logging, backups, rate limits, monitoring, and security or audit events.

No online service can guarantee absolute security. Institutions must apply least-privilege access, maintain accurate user lists, protect administrator accounts, promptly disable departed users, review exports and integrations, secure devices, and report suspected compromise without sending passwords, one-time codes, payment credentials, or secret keys.

If we become aware of a personal-data incident, we will investigate and take containment, recovery, communication, and assistance measures appropriate to our role, the affected data, the agreement, and applicable law.

11. Retention, export, and deletion

We retain personal data only for as long as reasonably necessary for the relevant service purpose, Institution instructions, account security, dispute resolution, backup continuity, and legal, tax, accounting, or regulatory duties. The period varies by record type, selected module, subscription status, workspace settings, and applicable agreement.

Institutions should use available archive, export, correction, and deletion controls as part of their own retention programme. After cancellation, access and data-handling follow the subscription terms, order form, and any agreed transition period. Deleted information may remain temporarily in protected backups, security logs, or provider systems until their normal overwrite or deletion cycles complete.

We may retain limited billing, consent, opt-out, security, audit, and request records where necessary to meet law, prevent fraud, document compliance, or establish and defend legal claims. Anonymised or aggregated information that no longer identifies an individual may be retained for analytics and service improvement.

12. Data location and international transfers

Maskeen Edutech, its infrastructure providers, payment and communication services, and Institution-authorised integrations may process information in different states or countries. Those locations may apply different privacy and data-protection rules.

Where required, we use contractual, organisational, and technical measures intended to support lawful transfers. Institutions that require a particular hosting region, localisation commitment, or transfer mechanism should ensure that requirement is documented in the applicable order form or written agreement before affected data is uploaded.

13. Privacy rights and requests

Depending on the applicable law and processing context, an individual may have rights to receive information, access personal data, obtain a copy, correct inaccurate data, request erasure, restrict or object to processing, withdraw consent, request portability, opt out of eligible marketing, nominate another person, or raise a grievance with a competent authority.

Rights are not absolute. A request may be limited where identity or authority cannot be verified, the Institution controls the data, another person's rights would be affected, or retention is required for law, security, payments, contract, or legal claims.

Institution-controlled records

For student profiles, guardian details, attendance, marks, fees, staff records, certificates, or other Institution Data, contact the relevant Institution first. We may refer a request to its authorised administrator and assist with the response.

Requests handled by Maskeen Edutech

Email support@maskeenedutech.com from the address associated with the account. State the relevant Institution, your relationship to it, the right you wish to exercise, and the records involved. Do not email passwords, OTPs, full payment details, or unnecessary identity documents. We may request proportionate information to verify identity and authority.

14. Cookies, analytics, and similar technologies

The website and applications may use essential cookies or browser storage for authentication, security, interface preferences, and session continuity. Blocking essential technologies may prevent sign-in or core features from working.

Our public website currently uses performance and audience-measurement tooling to understand page usage, reliability, and speed. We do not use Institution Data or student records for advertising profiles. If non-essential advertising or materially different tracking is introduced, we will provide the notice and choice required by applicable law.

15. Service and marketing communications

We may send essential authentication, account, security, billing, support, maintenance, policy, and operational messages while an account or commercial relationship is active. These communications are necessary to administer the Services and may not contain an unsubscribe option.

Product education, offers, events, or other promotional communications are sent where permitted. Recipients may use the unsubscribe method provided or contact support. An opt-out from Maskeen Edutech marketing does not stop essential service messages or communications independently sent by an Institution through its own workspace.

16. Policy changes, questions, and complaints

We may update this Policy when our Services, providers, legal requirements, or processing practices change. The current version and last-updated date will remain available on this page. Where required, material changes affecting existing account data will receive additional notice through the website, platform, email, or another suitable channel.

Questions, privacy requests, complaints, and requests for the appropriate grievance or data-protection contact can be sent to support@maskeenedutech.com. Include the relevant Institution and enough detail to route the request, but never send a password, OTP, payment PIN, complete card or bank credential, or unrelated sensitive document.

Have a privacy or data request?

Write from your registered email and include the relevant Institution and your relationship to it. For Institution-controlled student or staff records, contact the school administrator first.

support@maskeenedutech.com