K12 Safe (“we”, “our”, “us”, or “Platform”) is a SaaSbased compliance management platform for K12 educational institutions, trusts, and school groups in India. We help schools track, automate, and document their statutory, academic, HR, operational, and financial compliance obligations.
Important: K12 Safe is a B2B workflow tool. We do not collect, store, or process any student personal data (e.g., student names, photos, academic records, health information). All student and parent data remains with the school. Our platform manages compliance tasks, documents, and workflows – not student databases.
This Privacy Policy explains how we collect and use institutional data, school staff data, and compliance-related documents in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025.

1. Definitions

• Data Fiduciary – Under the DPDP Act, the school or educational trust that collects student/parent data is the Data Fiduciary. K12 Safe is a Data Processor (and a separate Data Fiduciary only for its own institutional data).
• Child – Any individual below 18 years. K12 Safe does not collect child data.
• Institutional Data – Data about the school/trust itself (e.g., registration certificates, NOCs, audit reports, employee compliance records).

2. Categories of Data We Collect & Process

We explicitly do NOT collect:
• Student names, class, roll number, date of birth, attendance, grades, health information.
• Parent/guardian names, contact details, or IDs.
• Any biometric or behavioural data of students.
• Any special category data under DPDP Act relating to children.
How it works in practice:
A school uses K12 Safe to track “Fire NOC renewal due on 15 Aug”. The school uploads a Fire NOC certificate (an institutional document). The school does not upload student lists or parent contacts into our platform. If a compliance task relates to student-teacher ratios (RTE), the school enters only the aggregate number (e.g., “25 students in Class 1”) – not individual student identities.

3. Legal Basis & Purpose of Processing

We process institutional and school staff data only:
• To provide the compliance tracking, alerting, document repository, workflow automation, and audit reporting features as described on our website.
• With the school’s consent (via the school’s authorised signatory agreeing to our Terms of Service).
• To comply with legal obligations (e.g., retaining audit logs for 3 years).
We do not process any child data. Accordingly, Verifiable Parental Consent under DPDP Act is the school’s sole responsibility – not K12 Safe’s.

4. Data Localization & CrossBorder Transfer

• All institutional data and user account data are stored only on servers located in ________.
• We do not transfer any data outside India unless the destination country is notified by the Government of India as permissible under DPDP Rules (currently none are notified for this category). We will update this policy if that changes.

5. Data Retention & Deletion

• School institutional data: Retained as long as the school is an active subscriber. After contract termination, data is deleted within 90 days unless a longer retention is required by law (e.g., audit trail for 3 years).
• User account data: Retained for 1 year after account closure, then anonymized.
• Audit logs: Retained for 3 years as required by standard compliance practices.
• Schools may export and delete their own data from the platform at any time via the dashboard.

6. Security Measures

We implement:
• Encryption at rest and in transit (AES256, TLS 1.3).
• Rolebased access with mandatory multifactor authentication for school users.
• Regular security audits and penetration testing.
• Annual Data Protection Impact Assessments (DPIA) for any new feature that could indirectly involve schoolsupplied data.

7. Our Role vs. School’s Role (Critical for DPDP Compliance)

If a parent contacts K12 Safe asking to access or delete their child’s data, we will:
• Respond within 7 business days explaining that we do not hold student data.
• Provide the parent with the contact information of their child’s school.
Keep a record of the query for audit purposes.

8. Grievance Redressal (For School Users & Parents Redirected to Us)

The following individuals may raise grievances with K12 Safe:
• Authorised school personnel (Principal, HR, Finance, Compliance Officer) regarding platform functionality, data accuracy of institutional records, or security concerns.
• Parents only if the parent believes K12 Safe directly holds their child’s data (which we do not – we will clarify and redirect).
To raise a grievance, contact our Grievance Officer (see Section 9). We respond within 7 business days and resolve within 30 days.

9. Grievance Officer (Mandatory under DPDP Act)

We have appointed a Grievance Officer as required by Section 16 of the DPDP Act, 2023.
Name:
Designation: Data Protection Office
Email: grievance@k-12safe.com
Phone:
Postal Address:
Working Hours: Monday to Friday, 10:00 AM – 6:00 PM IST
You may also file a complaint directly with the Data Protection Board of India (https://dpbi.gov.in) if you are not satisfied with our resolution.

10. Breach Notification

In case of a personal data breach affecting school institutional data or user accounts that is likely to cause harm:
• We notify the affected school(s) within 72 hours.
• We notify the Data Protection Board of India if required under DPDP Act.

11. Changes to This Policy

We will notify all school clients via email of any material changes at least 30 days in advance.

12. Contact for Sales & Support

For nonprivacy related queries:
Email: hello@k-12safe.com