InfovionLegalSign in →
Terms of ServicePrivacy PolicyData Processing AgreementSub-processorsAcceptable Use PolicyService Level AgreementRefund & Cancellation PolicyCookie PolicyGrievance Redressal

Data Processing Agreement

Version 1.0 · Effective 6 October 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the institution subscribing to Infovion ("School", the Data Fiduciary) and Infovion Technologies ("Infovion", the Data Processor) under the Terms of Service. It sets out how Infovion processes personal data on the School's behalf, as required by section 8(2) of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Digital Personal Data Protection Rules, 2025 and the Information Technology Act, 2000.

1. Scope and roles

1.1 The School determines the purposes and means of processing of personal data entered into the Service ("School Personal Data") and is the Data Fiduciary. Infovion processes School Personal Data only as Data Processor, on the School's behalf.

1.2 The details of processing (subject matter, duration, nature, purpose, data types and Data Principals) are in Annex 1.

2. Instructions

2.1 Infovion will process School Personal Data only on the School's documented instructions, which are: the Terms, this DPA, the School's configuration and use of the Service, and other written instructions agreed by the parties. Infovion will inform the School if, in its opinion, an instruction infringes the law.

2.2 Infovion will not: sell School Personal Data; use it for advertising or profiling; carry out tracking, behavioural monitoring or targeted advertising directed at children; or process it for its own purposes, except aggregated, de-identified statistics that do not identify any School or individual.

3. School's obligations

The School is responsible for: the lawfulness of the data it enters; giving notice to Data Principals under section 5 of the DPDP Act; obtaining verifiable parental consent for children's data under section 9 where required (or relying on an applicable exemption); the accuracy of the data; and handling Data Principals' requests. Infovion provides a template parent notice on request.

4. Confidentiality

Infovion ensures that persons authorised to access School Personal Data are bound by confidentiality obligations, access it only as needed to provide, secure or support the Service, and receive appropriate instruction. Support access to a School's data is limited to what is necessary to resolve the School's request.

5. Security

Infovion implements reasonable security safeguards to prevent personal data breaches, including the measures in Annex 2, and keeps them under review. Infovion may update the measures provided the overall level of protection is not reduced.

6. Sub-processors

6.1 The School authorises Infovion to engage the sub-processors listed at /legal/subprocessors (Annex 3).

6.2 Infovion will impose on each sub-processor written obligations on confidentiality, security and data protection no less protective than this DPA, and remains responsible for their performance.

6.3 Infovion will give at least 15 days' notice (by email to the School's operator or by updating the list and notifying) before adding or replacing a sub-processor. The School may object on reasonable data-protection grounds within that period; the parties will discuss in good faith, and if no solution is found the School may terminate the affected Service and receive a pro-rata refund of prepaid fees.

7. Cross-border processing

School Personal Data is hosted in Singapore and may be processed by sub-processors in other countries listed in Annex 3. Infovion will not transfer School Personal Data to any country or territory restricted by the Central Government under section 16 of the DPDP Act.

8. Assistance with Data Principal requests

Taking into account the nature of processing, Infovion will assist the School, through features of the Service (view, correct, export and delete records) and otherwise on request, to respond to requests to access, correct, complete, update or erase personal data, withdraw consent, nominate, and to redress grievances. If Infovion receives a request directly, it will forward it to the School without undue delay and not respond itself unless instructed.

9. Personal data breaches

9.1 Infovion will notify the School without undue delay, and where feasible within 24 hours, after becoming aware of a personal data breach affecting School Personal Data, so that the School can inform affected Data Principals and the Data Protection Board of India (including the detailed report due within 72 hours under the DPDP Rules).

9.2 The notification will include, to the extent known: the nature, extent, timing and location of the breach; categories and approximate number of persons and records affected; likely consequences; measures taken or proposed to mitigate; and a contact point. Infovion will provide updates as more information becomes available and cooperate with the School's notifications.

9.3 Where an incident is reportable under the CERT-In Directions of 28 April 2022, Infovion will report it to CERT-In within six hours of noticing it, as required of service providers.

10. Retention, return and deletion

10.1 During the subscription the School controls retention through the Service. The Service also applies automatic retention periods described in Annex 1.

10.2 On termination, School Personal Data remains available for export for 30 days and is then permanently erased from production systems, including uploaded files. On written request (verified by a one-time code sent to Infovion's administrators) erasure can be carried out earlier. Copies in provider-managed backups expire under the provider's rotation and are not restored except for disaster recovery; this DPA continues to apply to them until they expire. Records that Infovion must keep by law (for example invoices) are retained as required.

11. Records, audits and information

Infovion will make available information reasonably necessary to demonstrate compliance with this DPA, including its security policies and this DPA's annexes. Not more than once a year (or after a personal data breach), on 30 days' written notice, the School may audit compliance through a written questionnaire or, where that is insufficient, a remote review at a mutually agreed time, at the School's cost, subject to confidentiality. Infovion retains logs of processing as required by the DPDP Rules.

12. Liability and term

The limitations in the Terms apply to this DPA. This DPA applies for as long as Infovion processes School Personal Data. If the DPDP Act or rules change, the parties will amend this DPA as needed to comply.


Annex 1 — Details of processing

ItemDetails
Subject matterProvision of the Infovion school management Service
DurationThe subscription term plus the 30-day export period and backup expiry
Nature of processingCollection via the Service, storage, organisation, retrieval, display to authorised users, computation (attendance, results, fee balances), document generation, transmission of notifications/emails, backup, deletion
PurposeAdministration of the School: admissions, student records, attendance, examinations, fees, certificates, communication with parents, staff administration, transport
Data PrincipalsStudents (including children), parents/guardians, school staff and teachers, drivers and attendants, other authorised users
Categories of dataAs listed in section 2 of the Privacy Policy: identification and contact details, academic records, fee records, staff and payroll records, transport records (including bus location during trips), communications, account and security data. Sensitive items (religion, caste category, Aadhaar number, health information such as blood group) only where the School chooses to record them
Automatic retention in the ServiceAttendance and bus-trip records: 12 months · audit logs: 6 months · in-app notifications: 90 days · bus location: until the trip ends · deleted school: erased after 30 days

Annex 2 — Security measures

  1. Encryption in transit: all traffic over HTTPS/TLS; HTTP Strict Transport Security in production.
  2. Encryption at rest: database and file storage encrypted at rest by the hosting providers.
  3. Authentication: passwords hashed with bcrypt; password strength rules; sign-in rate limiting and temporary lock-out per account and per IP; short-lived access tokens (minutes) with rotating refresh tokens in HttpOnly cookies; sessions revoked on password reset and on "sign out everywhere"; optional TOTP two-factor authentication; forced password change for accounts created with a temporary password.
  4. Administrative access: the Infovion console requires password plus an emailed one-time code; console actions are audited; deletion of a school requires a one-time code sent to Infovion's administrators.
  5. Authorisation and isolation: role-based permissions for every action; every record is bound to its institution and every request is scoped to the signed-in user's institution; parents can access only their own children.
  6. Application security: input validation on all endpoints; protection against cross-site request forgery and clickjacking; Content Security Policy; dependency updates; code review before release.
  7. Logging and monitoring: audit log of significant actions (who, what, when, from which IP); application logs at the hosting provider.
  8. Data minimisation: live bus location only during a trip and cleared when it ends; automatic retention periods (Annex 1).
  9. Resilience: managed database with provider backups; documented incident response and business continuity procedures.
  10. People: access to production limited to named personnel with a need; confidentiality obligations; access removed on exit.

Annex 3 — Sub-processors

The current list, with purposes and locations, is published at /legal/subprocessors.

© 2026 Infovion Technologies · contact@infovion.in