Privacy Policy

What personal data the Service handles, why, for how long, and the rights that attach to it.

Version
2026-09-21-draft
Effective
21 September 2026

This is a draft pending legal review. It states our current practice and is binding as our stated policy, and it will be replaced by a reviewed version under a new version identifier.

1. The two roles in this policy

Almost all of the personal data in this Service is entered by a School about its own students, guardians and staff. For that data the School decides why and how it is processed — it is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 — and we process it on the School's instructions as its Data Processor.

A small amount of data is ours to decide about: the accounts of the School's administrators that we create, our correspondence with a School, and the operational logs and security records described below. For that data SheepByte AI Tech is the Data Fiduciary.

If you are a parent, student or member of staff asking about your own records, your School is the right first point of contact. We will assist a School in answering you.

2. What is processed

Student and guardian records
Name, admission number, date of birth, class and section, guardian names and contact details, attendance, marks and results, fee records, transport assignment, and documents a School chooses to upload.
Staff records
Name, contact details, role and designation, employment and attendance records, leave, payroll-related figures where the School uses them, and documents a School chooses to upload.
Account and authentication data
Email address, display name, role, the School the account belongs to, sign-in timestamps, failed sign-in counters and lockout state. Passwords are never stored in a readable form and are handled by Firebase Authentication.
Operational and audit records
A record of significant actions taken in the Service — who changed what, and when — kept so that a School can investigate its own records, and so that we can investigate a security incident.
Payment records
For a School's own subscription: the amount, the plan, the order and payment identifiers returned by our payment processor, and the outcome. Card and bank credentials are handled by the payment processor and never reach our systems.

3. Children's data

The Service holds records about children as a matter of course, because that is what a school runs on. It is not directed at children as users: student-facing sign-in is not offered, and a parent account sees only the records of the children it is linked to.

We do not use children's personal data for advertising, behavioural profiling, or tracking of any kind.

4. Why it is processed

  • To provide the Service to the School that entered the data.
  • To authenticate users and to keep accounts and records secure.
  • To provide support when a School asks for it.
  • To administer a School's own subscription and payments.
  • To meet a legal obligation, or to establish or defend a legal claim.

We do not use School data for marketing, profiling, or automated decision-making that produces a legal or similarly significant effect on an individual.

5. Who it is shared with

We do not sell personal data. It is disclosed only to:

Infrastructure providers
Google Firebase (authentication, database, file storage) and our hosting provider. These process data on our instructions under their own data-processing terms.
Payment processor
Razorpay, for a School's own subscription payments. It receives the amount, the order reference and the payer's payment details, which it collects directly.
Lawful requests
A competent authority where we are legally required to disclose, after satisfying ourselves that the request is valid.

6. Where it is stored

Data is stored in Google Cloud regions in India. Support access from outside India is not routine; where it is unavoidable it is limited to what the request requires, and logged.

7. How long it is kept

  • School records are kept for as long as the School's account is active, and are deleted after termination in line with the Data Processing Addendum and any retention period the School has asked for.
  • Audit and security records are kept for a period proportionate to their purpose, and are not used to build a profile of an individual.
  • Acceptance records for legal documents are retained for the life of the relationship and afterwards, because they are the evidence that an agreement was made.

8. Security

  • Each School's records are isolated from every other School's, structurally, by the way they are stored.
  • What a user can see and change is determined by their role, and is enforced on the server on every request — never by hiding a button.
  • Passwords are subject to a minimum-strength policy and administrator-issued temporary passwords must be changed at first sign-in.
  • Transport is encrypted; data is encrypted at rest by the storage platform.
  • Significant actions are recorded in an audit trail.

9. Your rights

Under the Digital Personal Data Protection Act, 2023, a Data Principal may ask for access to their personal data, for correction or completion of it, for erasure where it is no longer needed, and may nominate another person to exercise these rights.

For records held by a School, these requests should go to that School, which can fulfil them within the Service. Where we hold data as Data Fiduciary, write to us directly.

10. Grievances

Complaints about how personal data is handled may be sent to our Grievance Officer at contact@sheepbyte.com. We acknowledge a complaint within 7 working days and aim to resolve it within 30 days. A Data Principal who remains dissatisfied may approach the Data Protection Board of India.

11. Changes

Each version of this policy carries a version identifier and an effective date, shown at the top of this page. Material changes are notified to Schools and require their administrators to accept the new version.