Privacy Policy & Data Protection
Last Updated: August 2026 • Effective across all PrinciDesk SaaS services and tenant micro-sites.
Zero-Trust Isolation
Every school tenant’s academic, student, and financial records are strictly isolated at the database query layer.
FERPA & COPPA Ready
We uphold the strictest global regulations for student records, guardian consent, and minor data safety.
No Ads or Data Selling
We will never monetize, profile, sell, or license pupil or parent records to third-party advertisers.
1. Information We Collect
When educational institutions, staff, parents, and students use PrinciDesk, we collect information necessary to deliver educational administration services:
- Student Academic & Demographic Data: Names, roll numbers, class/section assignments, attendance logs, gradebook marks, report cards, and disciplinary records.
- Parent & Guardian Information: Contact emails, phone numbers, billing relationships, and emergency contacts.
- Staff & Faculty Records: Staff credentials, payroll structures, qualifications, biometric attendance timestamps, and department allocations.
- Financial & Fee Records: Invoices, payment receipts, tuition transactions, scholarship adjustments, and discount ledgers.
- Technical Metadata: Encrypted session cookies, IP addresses for security audit logging, browser types, and access timestamps.
2. Multi-Tenant Architecture & Data Segregation
PrinciDesk operates on a multi-tenant cloud architecture where every school entity is provisioned a unique organizational identifier (organizationId). All database operations, backups, and search index queries enforce strict tenant scoping to prevent cross-institution data exposure.
3. Compliance with Student Privacy Laws (FERPA, COPPA, GDPR)
We adhere strictly to global student data protection standards:
PrinciDesk acts as an authorized “School Official” with legitimate educational interests. Student educational records remain under the direct control of the subscribing institution.
Consent for students under 13 is obtained directly by the subscribing school institution acting as an agent on behalf of parents for educational purposes.
4. Cookies and Authentication Storage
We use strictly necessary HTTP-only, secure cookies (princidesk_session) to maintain encrypted user sessions and enforce role-based access. We do not use non-essential marketing or cross-site tracking cookies.
5. Data Retention, Portability & Deletion
Subscribing schools retain full ownership of their data. Institution administrators can export complete student directories, academic records, and financial statements at any time in standard formats (JSON, CSV, PDF). Upon subscription termination, all tenant databases and media assets are securely purged in accordance with our data retention schedule.
6. Contact Our Data Protection Officer (DPO)
For privacy inquiries, audit requests, or compliance questions, please contact our security team at:
PrinciDesk Privacy & Trust Operations
Email: privacy@princidesk.in
Compliance Desk: compliance@princidesk.in