1. Purpose of this notice
The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India. This notice explains how the Act applies to Learner Lead, who carries which obligation, and what a student, guardian or member of staff can do about their own data.
It sits alongside the privacy policy, which covers the same ground in less statutory language, and the terms of service, which is the contract with the institution.
2. Who is the Data Fiduciary
This is the question everything else follows from.
Your institution is the Data Fiduciary. A school, college or trust decides that it will enrol students, record their attendance, examine them, charge fees and employ staff. Those decisions are what create the personal data, and the Act places the duty on whoever determines the purpose and means of processing. That is the institution, not us.
Learner Lead is a Data Processor. We process personal data on the institution’s behalf, under a contract, for the purposes it sets. We do not decide what a school collects. We do not repurpose institution data, and we do not disclose it to anyone except as the institution instructs or the law compels.
Where Learner Lead is itself a Data Fiduciary. For a narrow set of data we determine the purpose ourselves: the contact details of the administrators and billing contacts we deal with, and correspondence from people who approach us about buying the product. For that data the obligations in this notice are ours directly.
3. What institutions must do
Because the institution is the Data Fiduciary, the Act’s core duties sit with it. In practice an institution using Learner Lead is responsible for:
- Giving notice. Telling parents, students and staff what personal data is collected, for what purpose, and how to exercise their rights and raise a grievance.
- Obtaining consent. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose.
- Verifiable parental consent for children. Processing the personal data of anyone under eighteen requires the verifiable consent of a parent or lawful guardian. For a school this is most of the register.
- Data minimisation. Not collecting fields the institution has no purpose for. A custom-field builder makes it easy to add a column; the Act asks why it exists.
- Answering requests. Responding to access, correction and erasure requests from the people whose data it holds.
- Publishing a grievance route and naming the person who answers it.
The platform provides the mechanisms for each of these: consent capture, per-tenant retention configuration, a data export, correction workflows, an erasure workflow, an immutable audit trail, and role-based masking so staff see only the fields their role requires. Configuring and operating them is the institution’s decision.
4. What Learner Lead does as processor
As a Data Processor we:
- process personal data only on the institution’s documented instructions;
- apply the technical and organisational security measures described on our security page, including tenant isolation enforced independently by the database, encryption of Aadhaar and bank fields with a distinct key per value, and an append-only audit log;
- keep all institution data within India, in the AWS Asia Pacific (Mumbai) region;
- engage sub-processors only under equivalent written terms, and publish the current list on the sub-processors page;
- assist the institution in responding to a Data Principal’s request, and in meeting its own breach-notification duties;
- notify the institution without undue delay on becoming aware of a personal data breach affecting its data;
- on the institution’s instruction, return or delete institution data at the end of the engagement.
We do not use institution data to train machine-learning models, to profile individuals, to advertise, or for any purpose of our own.
5. Rights of a Data Principal
A Data Principal is the individual the personal data is about: a student, a guardian, a teacher, an administrator. Under the Act you have the right to:
- Access a summary of the personal data being processed and the processing activities undertaken;
- Correct, complete or update personal data that is inaccurate or incomplete;
- Erase personal data where it is no longer needed for the purpose it was collected for, unless a law requires it to be kept;
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity;
- Grievance redressal, meaning a readily available means of raising a complaint and receiving a response.
You also carry duties under the Act, including not impersonating another person, not suppressing material information, and not filing a false or frivolous complaint.
Where to send a request
Almost always, to your institution. Your school holds your records, decides who may see them, and can correct or erase them directly. Approaching us first will normally slow you down, because we would have to refer your request to the school anyway.
To us, using the grievance address at the foot of this page, if you are an administrator or billing contact whose data we control, if your institution has directed you to us, or if the institution has not responded to a request you made to it.
We verify identity before acting on a request. Acting on an unverified request would itself be a privacy failure. We respond within thirty days.
6. Grievance redressal
If you are dissatisfied with how a request or a privacy concern has been handled, escalate in this order:
- The institution’s own grievance contact. Every institution is required to publish one under the Act.
- Learner Lead. Write to the grievance address at the foot of this page. Our grievance officer, named there, is responsible for acknowledging your complaint and responding substantively.
- The Data Protection Board of India. If the response still does not resolve matters, the Act gives you the right to complain to the Board.
We acknowledge grievances within seven working days and aim to resolve them within thirty days. Where a resolution will take longer, we will say so and tell you why.
7. Children’s data
The Act treats anyone under eighteen as a child and requires verifiable parental consent before their personal data is processed. It also prohibits tracking, behavioural monitoring and targeted advertising directed at children.
The platform contains no advertising, no third-party tracking and no behavioural profiling of any user. The consent-capture workflow exists so that an institution can record parental consent against the child’s record and evidence it later.
Learner Lead does not collect or store biometric data. It is among the most sensitive personal data a school could hold, and the platform does not ask institutions for it.
8. Breach notification
On becoming aware of a personal data breach we will notify the affected institutions without undue delay, with what happened, which categories of data were involved, what we are doing, and what the institution should do. Where the Act requires notification to the Data Protection Board of India, we will make it, and we will support each affected institution in meeting its own duty to notify the individuals concerned.
9. Significant Data Fiduciary obligations
The Act allows the Central Government to designate a Data Fiduciary, or a class of them, as a Significant Data Fiduciary, which brings additional duties including appointing a Data Protection Officer resident in India, an independent data auditor and periodic impact assessments. An institution processing a large volume of children’s data may fall within a designation. If your institution is designated, tell us: the platform’s audit, export and retention tooling is what an independent audit will need to draw on, and we would rather prepare it with you than be asked for it during the audit.
10. Changes to this notice
Rules under the Act continue to be issued, and this notice will change as they are. The effective and last-updated dates are shown at the top of this page, and material changes are notified to institution administrators before they take effect.