Privacy Policy.
How Infoiles handles personal data, for visitors to this site and for the schools we serve.
Effective: 5 June 2025 · Last updated: 11 September 2026This Privacy Policy explains how Infoiles handles personal data, both for visitors to this website and for the schools that use the Infoiles Ed platform. The platform holds the personal data of students, many of them minors, and we handle it in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1 Who we are & scope
The Infoiles brand and platform are owned by Infoiles Inc., a holding company registered in Ontario, Canada. All operations, data processing, legal responsibility and compliance for infoiles.com and ed.infoiles.com rest solely with its Indian subsidiary, Infoiles Ed Private Limited (based in Delhi, India; full registered address in section 13). Throughout this policy, "Infoiles", "we", "us" and "our" mean Infoiles Ed Private Limited unless stated otherwise; Infoiles Inc. acts only as a holding company and is not involved in data processing.
This policy covers: (a) this marketing website at infoiles.com, including its contact / demo-request form; and (b) the Infoiles Ed platform we provide to schools, comprising the web portal at ed.infoiles.com and the Infoiles Ed mobile app for students (Android), where the school makes it available. Where a school's own agreement with us says something more specific about its data, that agreement also applies.
2 Controller vs processor: an important distinction
Who is responsible for personal data depends on whose data it is and why it is being handled. This distinction shapes the rest of the policy.
The school is the controller
For students, guardians, staff, attendance, fees, documents and Aadhaar-linked identity, the school is the data controller (data fiduciary) and Infoiles is the processor; we act only on the school's documented instructions.
Infoiles is the controller
For data a visitor gives us about themselves through this website (for example, a demo enquiry), Infoiles is the controller and decides how that data is used.
3 Data we collect
(a) Marketing / contact-form data, given to us directly
When you contact us or request a demo through this website, we collect what you provide:
- your name, school name and role;
- your email address and phone number;
- any message you choose to send us; and
- basic technical metadata recorded with the submission (such as the time, IP address and browser) to help prevent spam and abuse.
(b) School-side data, processed on behalf of schools
When a school uses Infoiles Ed, we process the data it puts into the platform to run the service. This is collected and controlled by the school; we process it on the school's instructions. It can include:
- student, guardian and staff details (demographics, contact details and profiles);
- academic records (classes and sections, attendance, marks and report cards);
- fees, invoices and receipts, and supporting documents the school uploads; and
- Aadhaar-related data: Aadhaar numbers, identity documents the school uploads (which can include Aadhaar card scans) and, for staff, the result of an optional DigiLocker verification, handled as described in section 5.
(c) Technical & usage data
When you use the web portal or the app, we record basic technical and usage data (such as device and browser type, IP address and logs of key interactions) to keep the service secure, reliable and working correctly.
4 How & why we use it; legal basis
Marketing data. We use the details you submit through the form solely to respond to your enquiry and arrange a demo. As the controller for this data, our basis is your consent (given when you submit the form) and our legitimate interest in responding to a request you have made of us.
School data. We use school-side data only to provide and operate the platform on the school's instructions (for example, generating receipts, producing report cards, or running attendance). We process it under the school's authority as the data fiduciary.
We do not sell personal data, and we do not use it for unrelated profiling or advertising.
5 DigiLocker / Aadhaar handling
Where a school chooses to verify a staff member's identity, Aadhaar is verified through the government's DigiLocker (Meri Pehchaan) service, at hiring or at any time afterwards. This verification is optional: schools can onboard staff without it. Admissions no longer use DigiLocker; records of student and guardian verifications carried out earlier are retained.
From a DigiLocker verification, the Aadhaar number is recorded only in masked form (for example, XXXXXXXX1234, where only the last four digits are readable), together with a DigiLocker reference showing that the verification took place. Aadhaar numbers entered on admission forms and student records are also saved in masked form.
Identity documents that a school uploads, which can include scans of Aadhaar cards, are kept in private, access-controlled storage: in the platform, only school users whose role covers those student or staff records can open them.
6 Payment data (CCAvenue)
Online fee payments are processed through CCAvenue's hosted checkout. Card details, UPI IDs and bank details are entered on CCAvenue's secure pages, not on ours.
- No card data is stored on our systems: no card number, expiry date or CVV. This keeps the payment path within a reduced PCI scope (SAQ-A); CCAvenue is itself PCI-DSS compliant.
- We retain only non-sensitive transaction references (such as a transaction ID, amount and status) needed to reconcile payments and issue receipts.
- For how CCAvenue handles your payment data, see CCAvenue's privacy policy at ccavenue.com/privacy-policy.
7 Cookies & analytics
This marketing website sets no cookies and uses no analytics or advertising tools. The Infoiles Ed platform (web portal and app) uses essential cookies needed to keep you signed in and to operate the service, and records usage logs to keep the platform secure and reliable. The app uses no advertising or third-party tracking SDKs. You can manage cookies through your browser settings.
8 Sharing, sub-processors & international transfers
We do not sell personal data. We share data only with the limited sub-processors needed to run the service, each under appropriate terms:
- CCAvenue: online fee payments (hosted checkout).
- DigiLocker / Meri Pehchaan: optional Aadhaar identity verification of school staff.
- LiveKit: media for self-hosted live online classes.
- Our hosting / infrastructure provider: OVH.
We may also disclose personal data to legal or regulatory authorities where required by law or a valid court order.
International data transfers
We operate primarily from India. Because our holding company is in Canada, some data may be transferred to or accessed from outside India (for example, servers in Canada). Where data is transferred internationally, we apply appropriate safeguards, such as Standard Contractual Clauses (SCCs) or data anonymisation, consistent with applicable law.
9 Data retention
We keep personal data only as long as needed for the purpose it was collected:
- Marketing leads from the contact form are kept for as long as needed to respond to and follow up on your enquiry, and then deleted.
- School-side data is retained for as long as the school uses the service, and otherwise handled per the school's instructions and agreement (export, return or deletion on termination).
- Payment records and transaction metadata (transaction ID, amount and status; never card or UPI details) are retained for up to 10 years, as required by Indian tax and financial-reporting laws (including GST), then securely deleted or anonymised unless a longer period is required by law or to resolve a dispute.
- Audit logs are retained in line with the platform's audit-log retention policy and then securely removed.
10 Security measures
We take protecting personal data seriously and apply, among others:
- Per-school data isolation: each school runs in its own isolated database; one school's data is never mixed with another's;
- Protected credentials: sensitive credentials such as payment-gateway keys are encrypted, passwords are stored only as one-way hashes (never in readable form), logins are rate-limited and idle sessions time out;
- Access control (RBAC): staff access is role-based with per-user overrides, and deactivation can take effect mid-session; and
- an append-only audit log of key actions, such as sign-ins, staff access changes, data exports and online payments.
No method of storage or transmission is ever 100% secure, but we work to protect personal data using measures appropriate to its sensitivity.
11 Children's data
The platform handles the personal data of students, who are often minors, on behalf of schools. Under the DPDP Act 2023, the school is the data fiduciary and is responsible for obtaining the necessary parental / guardian consent. Infoiles processes children's data only on the school's instructions and does not use it for any independent purpose.
12 Your rights under the DPDP Act 2023
Subject to the DPDP Act and its rules, you may have the right to:
- access a summary of the personal data we hold about you and how it is processed;
- correct, complete or update inaccurate or incomplete data;
- erase data that is no longer needed for the purpose it was collected;
- withdraw consent you previously gave (without affecting earlier lawful processing); and
- grievance redressal: raise a concern and have it addressed.
If you are in Canada, you also have rights under PIPEDA, including the right to access your personal data and request corrections.
13 Grievance officer & contact
To exercise a right or raise a grievance, contact the Grievance Officer at Infoiles Ed Private Limited:
- Email: admin@infoiles.com
- Phone: +91 8448570294
- Registered address: B-83, Shakti Apartments, Sector-9, Rohini, Delhi 110085, India
We will acknowledge and respond to requests within the timelines required under the DPDP Act and its rules.
14 Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page reflects the latest version. Where changes are material, we will notify affected parties by email and/or an in-app or on-site notice.