1. The distinction this policy turns on
Learner Lead handles personal data in two different capacities, and almost every question about privacy has a different answer depending on which one applies.
Data your institution controls. Student records, guardian details, attendance, marks, fees, staff records and everything else inside a school’s tenant. Your institution decides what is collected and why. Under the Digital Personal Data Protection Act, 2023, the institution is the Data Fiduciary and we are a Data Processor acting on its written instructions. We do not decide what goes into those records, we do not use them for our own purposes, and we act on them only as the institution directs or as the law requires.
Data we control. The details of the people who run and buy the platform: an administrator’s name and work email, billing contacts, correspondence with our sales team, and visitors to this website. Here we are the Data Fiduciary and this policy describes what we do.
If you are a parent, a student or a teacher asking about your own records, the answer is almost always in the first category, and your school is the right first contact. Section 8 explains what to do if that does not resolve it.
2. Personal data in the platform
Acting as processor, we store whatever the institution configures the platform to collect. In practice that includes:
| Category | Typical contents |
|---|---|
| Student identity | Name, admission number, date of birth, photograph, address, category and religion where the school records them |
| Guardians | Names, relationship, phone numbers, email addresses, occupation, emergency contacts |
| Academic | Enrolment, batch, subjects, attendance, marks, grades, assignment submissions, discipline records |
| Financial | Fee heads, invoices, payments, concessions, refunds, and staff payroll |
| Staff | Employment records, qualifications, leave, salary structure, bank details |
| Documents | Birth certificates, transfer certificates, previous school records and other files the school uploads |
| Technical | Sign-in times, IP address and device, and the audit trail of who changed what |
Two categories get additional handling. Aadhaar numbers and bank account details are encrypted with a separate key for each individual value, so the stored form reveals nothing, not even which records share a value. Sensitive fields are masked by role, and the masking happens before the response leaves our servers rather than in the browser, so a class teacher’s device never receives a bank account number at all.
Learner Lead does not collect or store biometric data.
3. Personal data we control
| What | Why | How long |
|---|---|---|
| Administrator name, work email and phone | To operate the account, send service notices and provide support | For the subscription, then three years |
| Billing contact and GST details | To invoice, and to meet tax and accounting law | Eight years, as Indian tax law requires |
| Sales enquiries and demo bookings | To respond, and to follow up on a request you made | Three years from last contact, or until you ask us to erase it |
| Security and error logs | To investigate faults and attacks | Ninety days, other than an entry forming part of an open investigation |
We do not sell personal data, we do not rent it, we do not share it with advertisers, and we do not use any of it to train machine-learning models.
4. This website
This page and the rest of learnerlead.com are static files. The site sets no cookies, runs no analytics, embeds no tracking pixels, and makes no third-party requests. Fonts are served from our own domain rather than a font provider, partly for privacy and partly because a good number of Indian school networks block outside font hosts.
We do not need a cookie banner because there is nothing to consent to. If that changes, this section changes first.
Inside the signed-in product, one cookie is used: an authentication cookie holding a refresh token. It is httpOnly, restricted to the authentication path, and strictly necessary to keep you signed in. It carries no advertising or analytics purpose.
5. Where the data is, and who else touches it
All institution data is stored and processed in India, in the AWS Asia Pacific (Mumbai) region. Databases, caches, object storage and application servers are all provisioned there. The content delivery network in front of this marketing website caches public assets at edge locations worldwide, and no institution data passes through it.
We use a small number of sub-processors to deliver parts of the service, such as sending email or processing card payments. Each one is listed, with what it does, where it runs and whether it is live yet, on the sub-processors page, which we keep current. We enter into data-processing terms with each of them and remain responsible to you for what they do.
We disclose personal data outside that list only when a law, a court or a regulator with jurisdiction compels it. Where we are lawfully able to tell the affected institution first, we will.
6. How long data is kept
For data your institution controls, the institution sets the retention schedule and we apply it. Where none is set, records are kept for as long as the subscription lasts.
When a subscription ends, institution data stays available for export for thirty days. After that we delete it, except where a law requires us to keep something specific. Backup copies age out on their own cycle, which means a deleted record can persist in a backup for a short window before that copy expires. Backups are encrypted and are not used to serve requests.
7. Security
The measures behind this are set out in full on our security page. In summary: isolation between institutions is enforced in the application and independently by the database, so a query that forgets which school it belongs to returns nothing rather than someone else’s rows. Passwords are hashed with argon2id. Access tokens are short-lived and refresh tokens rotate, with replay of an old token revoking the whole family. Sensitive fields are encrypted with per-value keys. The audit log cannot be edited or deleted, because the database grant that would permit it has been withdrawn.
No system is perfectly secure. If a personal data breach occurs we will notify the affected institutions and the Data Protection Board of India as the DPDP Act requires, with what we know, what we are doing about it, and what the institution should do.
8. Your rights
The DPDP Act gives a Data Principal, meaning the individual the data is about, the right to access a summary of their personal data, to have it corrected or completed, to have it erased, to nominate someone to exercise these rights on their behalf, and to raise a grievance.
If the data is held by your institution, which covers almost every student, guardian and staff record, exercise these rights with the institution. It holds the records and decides who may see them, and it can act far faster than we can. The platform gives every school the tools to respond: consent capture, a data export, a correction workflow and an erasure workflow. Where an institution asks for our help in answering a request, we assist.
If the data is ours, meaning you are an administrator, a billing contact or someone who contacted our sales team, write to the privacy address at the foot of this page. We will verify who you are before acting, because acting on an unverified request is itself a privacy failure, and we will respond within thirty days.
You can withdraw consent for anything you consented to, and it is as easy to withdraw as it was to give. Withdrawing it does not undo processing that already happened lawfully.
9. Children
The platform exists to hold records about children, and nearly all of them are entered by a school rather than by the child. Under the DPDP Act, processing a child’s personal data requires the verifiable consent of a parent or lawful guardian. Obtaining that consent is the institution’s obligation as Data Fiduciary; the platform provides the consent-capture workflow that records it.
We do not use children’s data for tracking, behavioural monitoring or advertising, and the platform contains no advertising of any kind.
10. Changes
We will update this policy as the product changes. The effective and last-updated dates are at the top of this page. For a change that materially affects how personal data is handled, we will notify institution administrators before it takes effect rather than relying on you to notice a new date.
11. Contact
Privacy questions, requests about data we control, and data-processing agreements go to the privacy address at the foot of this page. Grievances under the DPDP Act follow the escalation route in the DPDP notice.