Edship

Privacy Policy

Effective Date: January 2025 · Last Updated: June 2026

At Edship Technologies Private Limited ("Edship", "we", "us", "our"), we are deeply committed to protecting the privacy and security of all personal data entrusted to us — especially student data. This Privacy Policy describes how we collect, use, store, share, and protect information when you use our products and services, including Nora Pulse, Nora Connect, Nora Transit, Bueagle, Simi AI, and Facy.

1. Information We Collect

We collect the following categories of information:

a) Information Provided by Institutions

  • Student details: name, date of birth, class, section, roll number, parent/guardian contact information, address, photograph, medical information (if provided).
  • Staff details: name, employee ID, designation, contact details, qualification, salary information.
  • Institutional details: school name, affiliation number, address, management details.

b) Information Collected Automatically

  • Device information: device type, operating system, browser type, IP address.
  • Usage data: pages visited, features used, session duration, interaction patterns.
  • Location data: GPS coordinates from IoT devices (Bueagle trackers) and mobile apps (with explicit consent).
  • Biometric data: facial recognition templates for attendance (Facy) — stored as encrypted mathematical representations, not raw images.

c) Information from Third Parties

We may receive information from payment gateways (transaction status), SMS/WhatsApp providers (delivery reports), and biometric hardware partners (device health data).

2. How We Use Your Information

  • Providing and maintaining our educational technology services.
  • Processing fee payments, generating invoices, and financial reporting.
  • Sending notifications about attendance, grades, transport updates, and school events.
  • Enabling real-time GPS tracking and geofencing alerts for student transport safety.
  • Processing facial recognition for touchless attendance marking.
  • Powering AI-driven features like Simi chatbot responses and predictive analytics.
  • Improving product quality through anonymized usage analytics.
  • Communicating service updates, security alerts, and support responses.
  • Complying with legal obligations and regulatory requirements.

3. Student Data Protection

We take special care to protect student data:

  • Student data is never used for advertising, marketing, or profiling purposes.
  • We do not sell, rent, or trade student information to any third party.
  • Access to student data is strictly role-based — teachers see only their class data, parents see only their child's data.
  • Access is provisioned and controlled by the subscribing institution, which decides which of its users may view or export data; data exported or downloaded by an authorized institutional user is thereafter handled under that institution's own control and policies.
  • Student biometric data (facial templates) is encrypted using AES-256 and stored separately from personal identifiers.
  • All student data processing is carried out in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the rules made thereunder, and with other applicable Indian law.
  • Parents/guardians retain the right to access, correct, or request deletion of their child's data.

4. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Access Control: Role-based access control (RBAC) with multi-factor authentication for administrative accounts.
  • Infrastructure: Hosted on enterprise-grade cloud infrastructure with ISO 27001 compliance.
  • Monitoring: 24/7 security monitoring, intrusion detection, and automated threat response.
  • Backups: Regular automated backups with geographic redundancy and disaster recovery protocols.
  • Auditing: Comprehensive audit logs for all data access and modifications.

5. Audit Logging, Activity Monitoring & Governance

To meet legal record-keeping obligations and to protect the security and integrity of the platform, Edship maintains governance and audit records of activity on its systems. Specifically, we record:

  • Authentication events — successful and failed logins, logout, token refresh, lockouts, and password changes, together with date/time, IP address, device/browser (user-agent), and access channel (web or mobile app).
  • Data-access and change activity — which user accessed, created, modified, exported, deleted, or viewed a personal-data record, and through which module. Sensitive field values are masked in these logs (for example passwords, contact numbers, and dates of birth are stored as [masked]); only the fact of the access and the names of changed fields are retained — not their sensitive contents.
  • Page-view / usage telemetry — the pages or screens a user navigates to within the web and mobile applications (navigation metadata only). Query parameters are stripped before storage, so no record-level content is captured by this telemetry.
  • Database/schema-integrity events and automated anomaly alerts (for example off-hours access, bulk export or deletion, repeated failed logins, or cross-account access).

Access to these governance records is restricted to authorized administrators for the purposes described below. We do not use audit or usage telemetry for advertising, and we do not sell it.

6. Lawful Basis & Purpose of Audit Processing

We process the governance and audit data described above on the basis of (i) legal obligation — to maintain demonstrable accountability and records as expected under the DPDPA and applicable law; and (ii) legitimate interests — to secure the platform, prevent and investigate fraud, misuse, and data breaches, and to operate the service reliably.

7. Data Sharing & Disclosure

We do not sell personal data. We may share data only in the following limited circumstances:

  • With service providers (payment gateways, SMS/email providers, cloud hosting) who process data on our behalf under strict contractual obligations.
  • With the subscribing institution — schools retain full access to their institutional data.
  • When required by law, regulation, legal process, or enforceable government request.
  • To protect the rights, safety, or property of Edship, its users, or the public.

8. Location & IoT Data

Our transport and fleet management services (Bueagle, Nora Transit) collect real-time GPS data from IoT devices installed in vehicles. This data is used exclusively for student safety — tracking vehicle locations, triggering geofence alerts, and optimizing routes. Location data is retained for 90 days for operational purposes and then automatically archived. Parents can view their child's transport location only during active trip hours.

9. Cookies & Analytics

Our websites and web applications use essential cookies for authentication, session management, and security. We may use analytics tools to understand usage patterns and improve our services. We do not use cookies for advertising or cross-site tracking. You can manage cookie preferences through your browser settings.

10. Data Retention

We retain institutional data for the duration of the active service agreement plus an additional 90-day grace period. After this period, data is securely deleted unless the institution requests an extension or data export. Student academic records may be retained longer if required by educational regulations. Biometric templates are deleted within 30 days of a student's de-enrollment or upon institutional request.

Governance and audit logs are retained for a limited period — currently approximately three (3) months in active ("hot") storage and up to twelve (12) months in a compressed archive, after which they are permanently purged. Page-view / usage telemetry is retained for approximately sixty (60) days and then permanently deleted. These periods are configured to keep records long enough to investigate late-discovered incidents while ensuring the audit store does not become a permanent repository of personal data (data minimization).

11. Your Rights as a Data Principal

As a Data Principal under the Digital Personal Data Protection Act, 2023, and subject to your role and applicable law, you have the following rights:

  • Right to Access: Obtain a summary of the personal data we hold about you or your child and of our processing activities.
  • Right to Correction, Completion & Updating: Request correction of inaccurate or misleading data, and completion or updating of incomplete data.
  • Right to Erasure: Request deletion of personal data that is no longer necessary for the purpose for which it was processed (subject to legal and contractual obligations).
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent, as easily as it was given.
  • Right to Grievance Redressal: Raise a grievance with us about how your personal data is handled, through the contact below.
  • Right to Nominate: Nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity.
  • Right to Data Portability: Request your data in a structured, commonly used format.

12. Children's Privacy

Our services are designed for use by educational institutions and are not directed at children under the age of 13 without institutional and parental oversight. We collect student data only through authorized institutional channels and with appropriate consent. If we become aware that we have collected personal data from a child without proper authorization, we will take immediate steps to delete such data.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, or legal requirements. Material changes will be communicated via email notification to institutional administrators and through an in-app banner at least 15 days before taking effect.

14. Grievance Redressal & Data Protection Contact

For any privacy question, to exercise your rights as a Data Principal, or to raise a grievance about how your personal data is handled, please contact our Data Protection team:

Edship Technologies Private Limited

BB Arcade, Near Infopark Phase1, Edachira-Millumpady Road, Kochi, Kerala 682042

Email: info@edship.in

Phone: +91 623 850 6588

We will acknowledge and respond to grievances and rights requests within the timelines prescribed under the DPDPA and the rules made thereunder.

From the Founding Team

At Edship, we don't just build software — we build the infrastructure for India's educational future. Every line of code we write is guided by one question: does this make a school safer, a teacher more effective, or a parent more connected?

We started with a simple belief — that technology should serve educators, not complicate their lives. Today, with 20+ schools trusting our platform, we're proving that belief right, one classroom at a time.

Founding Team

Edship Technologies Pvt. Ltd.