Skip to main content

Digital Personal Data Protection Policy

Effective Date: 13 September 2026

Last Updated: 13 September 2026

Platform: Campus 24x7 - School ERP Software

Legal Entity: Campus 24x7

Registered Address: Penta Homes, VIP Road, Zirakpur, Punjab, India

At Campus 24x7, we recognize that personal data is entrusted to us by educational institutions, students, parents, teachers, staff members, administrators and other users. We are committed to protecting personal data and handling it responsibly, transparently and securely.

Campus 24x7 is a cloud-based education management platform that enables schools and educational institutions to manage students, parents, teachers, staff, attendance, academics, fees, communication, transport, documents and related administrative operations.

This Data Protection Policy explains how Campus 24x7 approaches the collection, use, storage, protection, disclosure and deletion of personal data in connection with our platform and services.

This policy should be read together with our Privacy Policy, Terms & Conditions, Security Policy, applicable customer agreements and, where applicable, our Data Processing Agreement (DPA).

Compliance status: The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023 and the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. Commencement of the Act is staggered, and several core operational provisions come into force on their own notified dates. Campus 24x7 is designed and operated towards compliance with the DPDP Act and Rules, and implements applicable obligations in line with their effective dates. We do not claim any certification, government approval or accreditation under the DPDP framework.

1. Our Commitment to Data Protection

Campus 24x7 is committed to:

  • Collecting and processing personal data only for legitimate and specified purposes
  • Limiting personal data collection to what is reasonably necessary for those purposes
  • Maintaining appropriate security safeguards
  • Protecting personal data against unauthorized access, disclosure, alteration, loss or destruction
  • Maintaining appropriate access controls and authorization mechanisms
  • Retaining personal data only for as long as necessary for the applicable purpose or as required by law or contractual obligations
  • Supporting applicable rights of individuals relating to their personal data
  • Maintaining appropriate records and operational controls for data protection
  • Requiring appropriate data-protection obligations from relevant service providers and processors
  • Responding appropriately to personal-data incidents and breaches

The DPDP Act, 2023 establishes India's framework for processing digital personal data, while the Digital Personal Data Protection Rules, 2025 provide further operational requirements.

2. Scope

This Policy applies to personal data processed through or in connection with Campus 24x7, including:

  • Campus 24x7 web applications
  • School and administration portals
  • Student portals
  • Parent portals
  • Teacher and staff portals
  • Mobile interfaces (where applicable)
  • APIs and integrations
  • Communication services
  • WhatsApp integrations
  • Email, SMS and notification systems
  • Support services
  • Websites and related digital services
  • Other services provided by Campus 24x7

This Policy applies to personal data processed on behalf of educational institutions as well as personal data processed by Campus 24x7 for its own legitimate business and service purposes.

3. Understanding Our Role

Campus 24x7 operates primarily as a technology service provider and Data Processor when it processes personal data on behalf of a school or educational institution.

  • School / Educational Institution - Data Fiduciary
  • Campus 24x7 - Data Processor

The educational institution determines why and for what purposes student, parent, teacher and staff data is processed, while Campus 24x7 processes such data to provide the contracted software and services.

However, Campus 24x7 may act as a Data Fiduciary for personal data that it processes for its own purposes, such as:

  • Customer account administration
  • Billing and payment records
  • Business communications
  • Support requests
  • Website inquiries
  • Lead management
  • Recruitment
  • Security and fraud prevention
  • Legal and regulatory compliance
  • Other purposes independently determined by Campus 24x7

The applicable role depends on the particular processing activity.

4. Categories of Personal Data

Depending on how the platform is configured and used by an institution, Campus 24x7 may process the following categories of personal data.

4.1 Student Information

  • Name
  • Date of birth
  • Gender
  • Student ID / admission number
  • Class and section
  • Academic information
  • Attendance information
  • Examination records
  • Photographs
  • Contact information
  • Address
  • Admission information
  • Documents uploaded by the institution
  • Transport information
  • Fee-related information
  • Other information configured by the institution

4.2 Parent / Guardian Information

  • Name
  • Relationship with student
  • Mobile number
  • Email address
  • Residential address
  • Occupation or other information provided by the institution
  • Communication preferences
  • Account information

4.3 Teacher and Staff Information

  • Name
  • Employee ID
  • Contact information
  • Email address
  • Employment-related information
  • Attendance information
  • Assigned responsibilities
  • Qualification information
  • Payroll-related information where enabled by the institution
  • Other information required for institutional administration

4.4 Account and Technical Information

  • Login identifiers
  • Account information
  • Authentication information (passwords are stored only as bcrypt hashes)
  • IP addresses
  • Device information
  • Browser information
  • Application logs
  • Security and audit logs
  • Session information
  • Other technical information necessary for operating and securing the service

5. Purposes of Processing

5.1 Educational Administration

  • Student admission
  • Student records
  • Academic management
  • Attendance
  • Examination management
  • Timetable management
  • Assignments
  • Academic reporting
  • Institutional administration

5.2 Financial Administration

  • Fee management
  • Invoices
  • Receipts
  • Payment records
  • Outstanding-fee notifications
  • Financial reporting

5.3 Communication

  • School announcements
  • Attendance notifications
  • Fee reminders
  • Academic notifications
  • Event notifications
  • Transport notifications
  • Parent communication
  • Staff communication
  • WhatsApp communication
  • Email and SMS communication
  • In-app notifications

5.4 Platform Operations

  • Authentication
  • Account management
  • Customer support
  • System administration
  • Service monitoring
  • Troubleshooting
  • Security
  • Fraud prevention
  • Backup and recovery
  • Maintaining platform availability

5.5 Legal and Compliance

Personal data may also be processed where necessary to:

  • Comply with applicable law
  • Respond to lawful governmental or regulatory requests
  • Establish, exercise or defend legal claims
  • Prevent fraud or abuse
  • Protect the rights, property and safety of Campus 24x7, customers and users

6. Data Minimization

Campus 24x7 follows a data-minimization approach.

We seek to process only personal data that is reasonably necessary for the relevant purpose.

Educational institutions are responsible for configuring the platform appropriately and should avoid uploading unnecessary personal information.

Institutions should also ensure that information entered into Campus 24x7 is accurate and kept appropriately updated.

7. Processing of Children's Data

Campus 24x7 is designed for use by educational institutions and therefore may process personal data relating to children.

The DPDP Act contains specific requirements relating to processing children's personal data, including requirements concerning verifiable parental consent and restrictions concerning detrimental processing, tracking or behavioural monitoring, and targeted advertising directed at children, subject to statutory exceptions.

Where Campus 24x7 acts as a Data Processor, the educational institution remains responsible for determining the appropriate lawful basis and obtaining any consent or authorization required for its processing activities.

  • Campus 24x7 does not use student data processed on behalf of a school for targeted advertising
  • Campus 24x7 does not use school-provided student data to create advertising or behavioural profiles for students
  • Campus 24x7 does not sell student, parent or staff data to any third party

8. Consent and Lawful Processing

Where consent is required, the relevant Data Fiduciary is responsible for obtaining valid consent in accordance with applicable law.

Consent should be:

  • Informed
  • Specific
  • Clear
  • Voluntary
  • Capable of being withdrawn
  • Limited to the purpose for which it was provided

The DPDP Act describes consent as free, specific, informed, unconditional and unambiguous, given through clear affirmative action.

Campus 24x7 supports customers in implementing appropriate operational processes but does not replace the customer's legal responsibility as Data Fiduciary.

9. Data Security

Campus 24x7 implements technical and organizational safeguards intended to protect personal data. Depending on the service and configuration, safeguards include:

  • Role-based access control (RBAC) enforced at API and service layers
  • Authentication controls, including token-based authentication (JWT)
  • Multi-factor authentication for privileged roles
  • Least-privilege access for administrative and internal accounts
  • Secure, authenticated API access with input validation and sanitization
  • Encryption in transit (HTTPS, TLS 1.2 or above)
  • Encryption of sensitive fields where applicable
  • Password hashing using bcrypt
  • Access logging and exportable audit logs
  • Centralized system monitoring and alerting
  • Automated periodic backups with restoration testing
  • Server hardening, firewall rules and rate limiting at the infrastructure layer
  • Vulnerability management and prompt application of security patches
  • Separation of production, staging and development environments
  • Logical tenant isolation, with all queries scoped by institution
  • Documented incident-response procedures
  • Periodic review of security controls

Full details are set out in our Security Policy. The DPDP Rules contemplate reasonable security safeguards including measures such as encryption, access controls, monitoring, backups, logging and appropriate contractual controls for Data Processors.

10. Access Control

Access to personal data within Campus 24x7 is controlled according to authorized roles and responsibilities. Depending on the institution's configuration, different users have different levels of access, for example:

  • Super Administrators
  • School Administrators
  • Principals
  • Teachers
  • Accountants
  • Transport Staff
  • HR and other staff
  • Students
  • Parents

Users must not share their passwords, authentication credentials or account access with other individuals.

Educational institutions are responsible for appropriately configuring user roles and promptly disabling accounts that are no longer authorized.

11. Data Storage and Hosting

Campus 24x7 uses cloud infrastructure and technology service providers to operate its platform. Personal data is processed and stored through the following infrastructure:

  • Application hosting on Hostinger VPS infrastructure (Hostinger International Ltd.)
  • Data storage in a MySQL database with institution-scoped tenant isolation
  • Backups stored securely with controlled access

We require relevant service providers to maintain appropriate security and confidentiality protections consistent with the services they provide. Where Campus 24x7 processes customer data as a Data Processor, processing by service providers is governed by appropriate contractual and technical controls.

12. Data Processors and Sub-Processors

Campus 24x7 engages carefully selected third-party service providers to support the operation of its services. These currently include providers supporting:

  • Cloud infrastructure and hosting (Hostinger International Ltd.)
  • Payment processing (third-party certified payment gateways)
  • Transactional SMS and email delivery
  • WhatsApp messaging (Meta Platforms - WhatsApp Business Cloud API)
  • Monitoring and logging
  • Customer support

Such providers may process personal data only to the extent necessary to provide their services and subject to appropriate contractual and security requirements. The current list of authorized sub-processors, with the purpose, data shared and processing location for each, is maintained in our Data Processing Agreement. Material changes to sub-processors are communicated to institutions.

13. Data Retention

Campus 24x7 follows a purpose-based retention approach. Personal data is not retained indefinitely when it is no longer required for the purpose for which it was collected or processed, unless retention is required or permitted by applicable law, contractual obligations, legitimate operational requirements or dispute-resolution requirements.

Retention periods vary depending on:

  • The type of data
  • The purpose of processing
  • The customer's contractual requirements
  • Applicable legal requirements
  • Accounting requirements
  • Security requirements
  • Ongoing disputes or investigations

Indicative retention periods:

  • During an active subscription, institutional and user data is retained and remains accessible
  • After termination of a subscription, data is retained for a maximum of 12-24 months to allow account reactivation, legal and audit requirements, and dispute resolution
  • Verified early deletion requests from an institution are processed within 30 days
  • WhatsApp delivery status and message identifiers are retained for a maximum of 90 days

When personal data is no longer required, appropriate deletion, anonymization or other disposal measures are applied.

14. Customer-Controlled School Data

Where Campus 24x7 processes student, parent, teacher or staff data on behalf of a school, the school determines:

  • What data is collected
  • Why the data is collected
  • Who should have access
  • How long the data should be retained
  • When records should be corrected
  • When records should be deleted
  • What lawful purpose applies to the processing

Campus 24x7 provides the technology required to support those operations.

15. Individual Data Rights

Subject to applicable law and the applicable role of Campus 24x7, individuals may have rights relating to their personal data, including rights to:

  • Obtain information about processing
  • Access applicable personal data
  • Request correction of inaccurate information
  • Request erasure where applicable
  • Withdraw consent where processing is based on consent
  • Exercise applicable grievance rights
  • Nominate another individual to exercise rights in prescribed circumstances
  • Exercise other rights available under applicable law

Where Campus 24x7 processes information on behalf of a school, requests relating to that school's student, parent or staff records should be directed to the relevant school or institution, which is the Data Fiduciary for that data.

16. How to Submit a Data Request

If your personal data is maintained by a school using Campus 24x7, please contact the relevant school or educational institution first. The school may then coordinate with Campus 24x7 where technical assistance is required.

For personal data for which Campus 24x7 acts as the Data Fiduciary, requests may be submitted to:

Campus 24x7 - Privacy & Data Protection Contact

Email: info@campus24x7.in

Address: Penta Homes, VIP Road, Zirakpur, Punjab, India

Website: https://campus24x7.in

Please include enough information to identify your records and the nature of your request. We may need to verify your identity before acting on a request.

17. Grievance Redressal

We take privacy-related concerns seriously.

If you believe that your personal data has been processed improperly or that your privacy rights have not been adequately addressed, you may contact our designated privacy and grievance contact. We will review the complaint and take appropriate action in accordance with applicable law and our internal procedures.

Grievance Officer / Designated Contact:

Name: Dheeraj Singh

Designation: Co-Founder & Grievance Officer

Email: info@campus24x7.in

Address: Penta Homes, VIP Road, Zirakpur, Punjab, India

Where Campus 24x7 acts as a Data Processor, grievances relating to a school's records should first be raised with that school as the Data Fiduciary.

18. Personal Data Breach Management

Campus 24x7 maintains processes for detecting, investigating, containing and responding to personal-data security incidents. Where a personal-data breach occurs, we assess the incident and take appropriate measures, which may include:

  1. Identifying and containing the incident
  2. Assessing the nature and scope of affected data
  3. Investigating the cause
  4. Taking remedial and preventive measures
  5. Maintaining appropriate incident records
  6. Coordinating with and notifying affected customers
  7. Making legally required notifications to relevant authorities and affected individuals

Where an incident involves the Meta WhatsApp Business Cloud API integration, affected institutions are notified within 48 hours and the incident is reported to Meta through the appropriate developer reporting channel, as set out in our Security Policy.

The DPDP Rules provide requirements relating to security safeguards and breach notification, including prescribed communications to affected Data Principals and to the Data Protection Board in applicable circumstances.

19. Data Accuracy

Campus 24x7 seeks to maintain accurate personal data within the information provided to us.

Where an educational institution controls the underlying data, the institution is responsible for ensuring that information entered into the platform is accurate, relevant and appropriately updated.

Users should notify the relevant institution when information requires correction.

20. International Data Processing

Depending on the infrastructure, integrations and service providers used, personal data may be processed in locations outside India. In particular, hosting infrastructure is provided by Hostinger International Ltd., which operates data centres in the European Union, and WhatsApp message delivery is performed by Meta Platforms through the WhatsApp Business Cloud API.

Where data is processed outside India:

  • Transfers are limited to what is necessary to provide the service
  • Appropriate contractual and technical safeguards are implemented
  • Data is transmitted over encrypted channels
  • Equivalent data protection obligations are required from the receiving service provider

Where applicable, Campus 24x7 will comply with restrictions or requirements concerning transfers of personal data prescribed under Indian law.

21. Third-Party Integrations

Campus 24x7 integrates with third-party services, including:

  • WhatsApp (Meta Platforms - WhatsApp Business Cloud API)
  • Email providers
  • SMS providers
  • Payment gateways
  • Cloud infrastructure providers
  • Notification services

When a customer enables an integration, relevant data is transmitted to that service to perform the requested function. Such third parties have their own privacy policies and terms. Educational institutions should review and configure integrations appropriately before enabling them.

22. WhatsApp and Communication Data

Campus 24x7 operates as a Meta-approved Tech Provider. Where WhatsApp communication is enabled by an institution, Campus 24x7 processes information necessary to:

  • Send approved template messages
  • Deliver notifications
  • Manage communication workflows
  • Maintain message status
  • Process delivery information
  • Provide communication functionality to the institution

Only the minimum data required for message delivery is transmitted to Meta's API:

  • The recipient's phone number in E.164 format
  • The approved message template name and variable values
  • The institution's WhatsApp Business Account (WABA) identifier

No student academic records, financial data or other sensitive personal data beyond the above is included in API payloads. Each institution's WABA is logically isolated within the Campus 24x7 Tech Provider account.

WhatsApp-related processing is subject to the applicable Meta and WhatsApp terms and policies in addition to Campus 24x7's contractual and privacy obligations. Campus 24x7 does not use school-provided student or parent data for unrelated advertising purposes.

23. Employee and Internal Data

Campus 24x7 also processes personal data relating to:

  • Employees
  • Applicants
  • Contractors
  • Consultants
  • Business contacts

Such information may be processed for:

  • Recruitment
  • Employment administration
  • Payroll
  • Communication
  • Access management
  • Security
  • Legal compliance
  • Business administration

24. Privacy by Design

Campus 24x7 incorporates privacy and security considerations into product development and operational processes. This includes:

  • Minimizing unnecessary data collection
  • Role-based access
  • Secure authentication
  • Controlled administrative access
  • Auditability and exportable audit logs
  • Secure API design with validation and sanitization
  • Access logging
  • Secure storage and tenant isolation
  • Backup and recovery
  • Incident management
  • Controlled third-party integrations

25. Changes to This Policy

We may update this Data Protection Policy from time to time to reflect:

  • Changes in our services
  • Changes in applicable law
  • Changes in regulatory requirements
  • Changes in technology
  • Changes in our processing practices
  • Improvements to our privacy and security practices

The latest version will be published on this page with the applicable Last Updated date.

26. Applicable Law and Jurisdiction

This Policy describes Campus 24x7's approach to data protection in the context of applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, to the extent applicable and effective from time to time.

  • The DPDP Act was enacted on 11 August 2023
  • The DPDP Rules, 2025 were notified on 13 November 2025
  • Different provisions have different commencement dates, so this Policy is interpreted and applied according to the provisions that are legally effective at the relevant time

This Policy is governed by the laws of India. Courts located in Punjab shall have exclusive jurisdiction.

Official Government references:

27. Contact Us

For privacy, data protection or personal-data related questions, please contact:

Campus 24x7 - Privacy & Data Protection Team

Grievance Officer: Dheeraj Singh, Co-Founder & Grievance Officer

Registered Address: Penta Homes, VIP Road, Zirakpur, Punjab, India

Email: info@campus24x7.in

Website: https://campus24x7.in