Privacy Policy
How we collect, use, store, and protect personal data of students, parents, and staff.
1. Introduction
Vidyarthi Sahayyak Samiti Warora ("Institution", "we", "us", or "our") operates the school portal at https://dnyanda.ac.in and related services delivered through the Aethon ERP by Trecsa Technologies platform ("Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you access our website, parent/staff portal, mobile-friendly interfaces, fee payment pages, and communication channels including email and WhatsApp.
This Policy is designed to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and applicable rules, and institutional obligations as an educational body processing data of students (including minors) and their parents or guardians.
By using our Services, you acknowledge that you have read this Privacy Policy. Where consent is required by law, we obtain it separately and in a clear manner.
2. Data Fiduciary & Contact
For personal data processed through this portal, Vidyarthi Sahayyak Samiti Warora acts as the Data Fiduciary (or equivalent controlling entity) for institutional records relating to students, parents, and staff.
Trecsa Technologies (https://trecsa.in) provides the Aethon technology platform as a Data Processor / service provider on our instructions. Trecsa Technologies does not sell your personal data.
Institutional contact
- Institution: Vidyarthi Sahayyak Samiti Warora
- Address: Satefal, Hinganghat
- Email: dnyanda@vss.ac
- Phone: +91 78218 36236
- Data protection queries: dnyanda@vss.ac
3. Personal Data We Collect
We collect only data that is necessary for legitimate educational, administrative, safety, and communication purposes.
Student data (often relating to minors)
- Identity and demographic details: name, date of birth, gender, photograph, admission number, class, section, roll number.
- Academic records: attendance, examinations, assignments, report cards, disciplinary notes where applicable.
- Health and safety: medical incidents, hostel/nurse notes, emergency contacts (processed on a need-to-know basis).
- Hostel and activity participation where the student is enrolled in residential programmes.
Parent / guardian data
- Name, relationship to student, mobile number, email address, address.
- Fee payer details and payment transaction references (card/UPI/netbanking data is processed by Razorpay — we do not store full card numbers).
- Communication preferences for portal, email, SMS, and WhatsApp notifications.
Staff data
- Employment identifiers, contact details, role, attendance, payroll-related references where integrated.
- System audit logs: login timestamps, IP address, device/browser type for security.
Automatically collected technical data
- Cookies, session identifiers, and similar technologies (see our Cookie Policy).
- Server logs, error diagnostics, and security event records.
4. Purposes & Legal Basis
We process personal data for specified, explicit, and legitimate purposes including:
- Admission, enrolment, and student lifecycle management.
- Academic delivery, attendance, examinations, and progress reporting.
- Fee invoicing, collection, receipts, and financial reconciliation.
- Parent and staff communication regarding academics, fees, medical, hostel, and emergencies.
- Safety, security, and compliance with applicable laws and board regulations.
- Portal authentication, including magic-link login and optional two-factor authentication.
- Improving service reliability, preventing fraud, and maintaining audit trails.
Consent & minors
Where a student is a minor, we rely on verifiable consent or authorisation from a parent or lawful guardian, and process student data strictly for educational and safeguarding purposes.
You may withdraw consent for optional processing (e.g. non-essential marketing messages) without affecting core educational services, subject to legal retention requirements.
6. Retention & Security
We retain personal data only for as long as necessary for the purposes described, including statutory retention for educational and financial records. When data is no longer required, we delete or anonymise it in accordance with our retention schedule.
We implement reasonable technical and organisational measures including access controls, role-based permissions, encrypted transport (HTTPS), audit logging, and staff training. No method of transmission over the Internet is 100% secure; we encourage strong passwords and prompt reporting of suspected unauthorised access.
7. Your Rights
Subject to applicable law (including the DPDP Act), you may have the right to access, correction, erasure, grievance redressal, and nomination of a person to exercise rights in the event of death or incapacity.
To exercise rights, contact dnyanda@vss.ac or see our Grievance Redressal & Data Rights policy at https://dnyanda.ac.in/legal.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date and version are shown at the top of this page. Material changes will be communicated through the portal or other appropriate channels.
Effective date: 28 June 2026 · Version 1.0