Next-Gen Multi-Tenant SaaS: Independent branding, websites, and ERP for every school.
Back to Home
Enterprise Student Data Privacy

Privacy Policy & Data Protection

Last Updated: August 2026 • Effective across all PrinciDesk SaaS services and tenant micro-sites.

Zero-Trust Isolation

Every school tenant’s academic, student, and financial records are strictly isolated at the database query layer.

FERPA & COPPA Ready

We uphold the strictest global regulations for student records, guardian consent, and minor data safety.

No Ads or Data Selling

We will never monetize, profile, sell, or license pupil or parent records to third-party advertisers.

1. Information We Collect

When educational institutions, staff, parents, and students use PrinciDesk, we collect information necessary to deliver educational administration services:

  • Student Academic & Demographic Data: Names, roll numbers, class/section assignments, attendance logs, gradebook marks, report cards, and disciplinary records.
  • Parent & Guardian Information: Contact emails, phone numbers, billing relationships, and emergency contacts.
  • Staff & Faculty Records: Staff credentials, payroll structures, qualifications, biometric attendance timestamps, and department allocations.
  • Financial & Fee Records: Invoices, payment receipts, tuition transactions, scholarship adjustments, and discount ledgers.
  • Technical Metadata: Encrypted session cookies, IP addresses for security audit logging, browser types, and access timestamps.

2. Multi-Tenant Architecture & Data Segregation

PrinciDesk operates on a multi-tenant cloud architecture where every school entity is provisioned a unique organizational identifier (organizationId). All database operations, backups, and search index queries enforce strict tenant scoping to prevent cross-institution data exposure.

3. Compliance with Student Privacy Laws (FERPA, COPPA, GDPR)

We adhere strictly to global student data protection standards:

FERPA (Family Educational Rights and Privacy Act):

PrinciDesk acts as an authorized “School Official” with legitimate educational interests. Student educational records remain under the direct control of the subscribing institution.

COPPA (Children's Online Privacy Protection Act):

Consent for students under 13 is obtained directly by the subscribing school institution acting as an agent on behalf of parents for educational purposes.

4. Cookies and Authentication Storage

We use strictly necessary HTTP-only, secure cookies (princidesk_session) to maintain encrypted user sessions and enforce role-based access. We do not use non-essential marketing or cross-site tracking cookies.

5. Data Retention, Portability & Deletion

Subscribing schools retain full ownership of their data. Institution administrators can export complete student directories, academic records, and financial statements at any time in standard formats (JSON, CSV, PDF). Upon subscription termination, all tenant databases and media assets are securely purged in accordance with our data retention schedule.

6. Contact Our Data Protection Officer (DPO)

For privacy inquiries, audit requests, or compliance questions, please contact our security team at:

PrinciDesk Privacy & Trust Operations

Email: privacy@princidesk.in

Compliance Desk: compliance@princidesk.in