Privacy Policy — AiduEdSuite
Last updated: 21 July 2026
This Privacy Policy explains how AIAWT APPS, a sole proprietorship operating under the brand "AiduEdSuite" ("AiduEdSuite", "we", "us", "our"), collects, uses, stores, shares and protects information in connection with the AiduEdSuite web application and related services (the "Service") available at https://aidued.com and its subdomains.
We are based in Aizawl, Mizoram, India. By using the Service you agree to this Policy. If you do not agree, please do not use the Service.
This Policy is designed to be consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and applicable rules.
1. Who this Policy covers, and our two roles
AiduEdSuite is sold to schools, colleges and other educational institutions ("Institutions"). It is important to understand two different roles in which we handle personal data:
- As a Data Fiduciary (for data we decide the purposes and means of): information about the Institution, the staff who register and administer accounts, billing/subscription data, referral-program participants, and people who contact us or visit our website.
- As a Data Processor / on behalf of the Institution (for data the Institution controls): student records, parent/guardian details, teacher and staff academic records, marks, attendance, admissions, fee records and any documents the Institution uploads or generates. For this data, the Institution is the Data Fiduciary and decides what is collected and why; we process it only under the Institution's instructions and our contract with them (the Terms of Service).
If you are a student, parent or guardian, your relationship for that data is primarily with your Institution. Please direct requests about student data to your Institution first; we will support the Institution in responding.
2. Information we collect
2.1 Account & Institution data (we are Fiduciary)
- Institution name, address, type, board affiliation, logo and branding.
- Administrator and staff names, email addresses, phone numbers, roles/permissions, and login credentials (passwords are stored only as salted hashes).
- Subscription tier (Essential / Professional / Premier), trial status, and usage/activity logs.
2.2 Billing & payment data (we are Fiduciary)
- Billing contact, GSTIN (if provided), invoices and transaction history.
- We do not store full card numbers, CVV, UPI PINs or bank credentials. Payments are processed by our payment gateway Cashfree Payments; card/UPI/netbanking details are collected and handled directly by Cashfree under its own security and PCI-DSS obligations. We receive only limited transaction metadata (e.g., payment status, order ID, masked instrument, amount).
2.3 Student & institutional records (Institution is Fiduciary; we are Processor)
Depending on how the Institution uses the Service, this may include:
- Student personal details (name, roll/admission number, class/section, date of birth, gender, photograph, guardian names and contact, address, category/board identifiers).
- Academic data: marks, grades, mark sheets, results, report cards, certificates.
- Attendance records, admissions data, fee and payment-to-institution records, timetables, and ID-card data.
- Documents and images uploaded or scanned by Institution staff (including mark-sheet images processed by our OCR feature).
2.4 Technical, usage & website-analytics data (we are Fiduciary)
- IP address, browser and device type, operating system, log timestamps, pages/features used, and error diagnostics.
- Website & app visit analytics. To understand how our website and app are used — and to keep them secure — we record visits, including the visitor's IP address, an approximate location (country, region and city) derived from that IP address, the page or route visited, the referring source, device/browser type, and the time of the visit. We use this for aggregate visitor statistics, product improvement, and security / abuse prevention. We do not use it to profile students, for advertising, or to identify individuals beyond what is necessary for security. These visit logs are retained for a limited period (see Section 8).
- Cookies and local storage used to keep you signed in, remember preferences, enable offline functionality, and secure the Service (see Section 9).
2.5 Communications
- Support requests, emails, feedback and referral-program information you submit.
We do not knowingly collect sensitive personal data beyond what an Institution chooses to store for legitimate educational administration, and we do not sell personal data.
3. Children's / minors' data
The Service is not directed to children as end-users. Accounts are created and operated by adult staff of Institutions. However, Institutions use the Service to process records about minors (students).
- For such data the Institution is the Data Fiduciary and is responsible for obtaining any consent required from parents/guardians under the DPDP Act and applicable law before entering student data into the Service.
- We process minors' data only on the Institution's instructions, solely to provide the administrative features requested (e.g., generating a report card or ID card).
- We do not use minors' data for behavioural tracking, targeted advertising, or profiling, and we do not undertake activity likely to cause harm to a child.
- Parents/guardians who wish to access, correct or delete a student's data should contact the Institution; we will assist the Institution as its processor.
4. How we use information
We use information to:
- Provide, operate, secure and maintain the Service and its features (mark sheets, results, report cards, ID cards, certificates, fees, attendance, admissions, timetables).
- Provide AiEng features such as OCR mark-scanning and AI assistants (see Section 6).
- Authenticate users and enforce role-based permissions.
- Process subscriptions, trials, invoices and payments, and administer the referral program.
- Provide customer support and respond to requests.
- Send service-related and transactional communications (e.g., trial expiry, billing, security notices).
- Monitor, debug, prevent fraud/abuse, and improve reliability and performance.
- Comply with legal obligations.
Legal bases (DPDP Act): we rely on consent, the necessity of performing our contract with the Institution, and other legitimate/legal uses permitted under the DPDP Act. For data we process on behalf of an Institution, the lawful basis is established by the Institution.
We do not use student/institutional records to train, fine-tune or improve any AI model, and we do not sell personal data to third parties.
5. Sharing and third-party processors ("Data Processors")
We share personal data only with service providers that help us run the Service, under contractual confidentiality and security obligations, and only as needed. Key processors include:
| Processor | Purpose | Data involved |
|---|---|---|
| Supabase / PostgreSQL cloud database & hosting | Cloud database, authentication and storage of application data | Account, institutional and student records, uploaded files |
| Cashfree Payments | Payment processing for subscriptions | Billing/payment details (handled by Cashfree), transaction metadata |
| AiEng processing providers | Powering OCR and AI-assistant features | Content you submit to an AI feature (e.g., a mark-sheet image or a prompt) |
| Email / communication provider | Sending transactional and support emails | Email address, message content |
| Cloud infrastructure / CDN provider | Hosting, delivery and reliability of the website and app | Technical/log data |
We use AiEng as the brand name for our AI capabilities. The specific underlying AI technology providers are our confidential sub-processors and are engaged under agreements that require them to keep your content confidential and, to the extent within our control, not to use your content to train their models. We do not disclose the identity of underlying AI providers.
We may also disclose information:
- To comply with law, valid legal process, or a lawful government request.
- To protect the rights, safety, property or security of AiduEdSuite, our users, or the public, and to prevent fraud or abuse.
- In connection with a business transfer (e.g., sale or reorganization of the proprietorship), subject to this Policy.
We do not sell or rent personal data, and we do not share it for third-party advertising.
6. AI features (AiEng)
Some features use artificial intelligence — for example, OCR scanning of mark sheets and AI assistants.
- When you use an AI feature, the relevant content (such as an uploaded image or your text prompt) is sent to our AI processing provider to generate a result, then returned to you.
- AI outputs may be inaccurate or incomplete. OCR-extracted marks and AI-generated text must be reviewed and verified by a human before being relied upon, published, or used in any official document. You are responsible for the accuracy of final records.
- We do not use your data to train AI models, and we instruct our AI processors not to do so with your content.
7. Data storage, location and security
- Application data is stored in a cloud database (Supabase / PostgreSQL) and associated cloud infrastructure. Depending on provider configuration, data may be stored or processed on servers located in the Asia-Pacific region (currently Mumbai, India). Where data is transferred outside India, we do so in a manner permitted by the DPDP Act and applicable law.
- We apply reasonable technical and organizational safeguards, including encryption in transit (HTTPS/TLS), hashed passwords, role-based access controls (RBAC), tenant isolation between Institutions, and access logging.
- No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we work to protect your data and to respond promptly to incidents.
- Personal Data Breach: in the event of a breach affecting personal data, we will notify the affected Institution(s) and the Data Protection Board of India as required under the DPDP Act.
8. Data retention
- We retain account and institutional data for as long as the Institution's account is active and as needed to provide the Service.
- We retain billing/tax records for the period required by Indian tax and accounting law.
- We retain website / app visit-analytics logs (including IP address and approximate location) for up to 180 days, after which they are deleted or reduced to non-identifying aggregates.
- For student/institutional records processed on behalf of an Institution, retention is directed by the Institution. On termination of the subscription, we will, at the Institution's request, return or delete such data within 60 days, except where longer retention is required by law or for legitimate backup cycles.
- We may retain limited data as necessary to comply with legal obligations, resolve disputes, prevent fraud and enforce our agreements.
9. Cookies and local storage
We use strictly necessary cookies/local storage to keep you signed in, maintain security, remember preferences (such as language, including Mizo/English), and support offline use. We do not use third-party advertising cookies. You can control cookies through your browser, but disabling them may affect functionality.
10. Your rights (Data Principals under the DPDP Act)
Subject to the DPDP Act and to your relationship with us or your Institution, you may:
- Access a summary of your personal data and how it is processed.
- Correct, complete or update inaccurate or incomplete personal data.
- Erase personal data that is no longer needed for the purpose it was collected.
- Withdraw consent where processing is based on consent.
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Grievance redressal — raise a complaint with our Grievance Officer (Section 12) and, if unsatisfied, with the Data Protection Board of India.
For data held on behalf of an Institution (e.g., student records), please submit requests to your Institution, which is the Data Fiduciary. We will assist the Institution as its processor.
To exercise rights for data where we are the Fiduciary, contact us at admin@aiawtapps.com. We may need to verify your identity before acting and will respond within the timelines required by law.
11. Duties of Data Principals
Under the DPDP Act, you must not impersonate another person, suppress material information, or file false or frivolous complaints, and you must furnish only authentic information. Institution staff must only upload data they are authorized to process.
12. Grievance Officer / Data Protection contact
In accordance with the DPDP Act and applicable Indian law, our contact for privacy grievances is:
- Name: Jack Vanlalthalawra
- Designation: Grievance Officer, AiduEdSuite (AIAWT APPS)
- Email: admin@aiawtapps.com
- Address: V-134-2, Bawngkawn, Aizawl, Mizoram, India – 796014
- Phone: Available on request via admin@aiawtapps.com
We aim to acknowledge grievances promptly and resolve them within the timelines required by law.
13. Third-party links
The Service may link to third-party websites (e.g., our payment gateway). We are not responsible for the privacy practices of those third parties; please review their policies.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified via the Service or by email, and the "Last updated" date will be revised. Continued use after changes take effect constitutes acceptance.
15. Contact
Questions about this Policy? Email admin@aiawtapps.com or write to AIAWT APPS, V-134-2, Bawngkawn, Aizawl, Mizoram, India – 796014.
AiduEdSuite
Open app →