Back to Home
Legal · Privacy

Privacy Policy

ZeroSuite provides School ERP, Coaching ERP, HRMS & Payroll, ZeroClash Timetable and web-development services to educational institutions and enterprises. Because we process data about students, guardians and staff, this notice is written as an education and HR data policy.

This policy applies to institutions and users in India and in other countries where ZeroSuite offers its services, including the United States. It aligns with India’s Digital Personal Data Protection Act, 2023 (DPDP) and its Rules, and it sets out the additional commitments that apply to United States schools, including FERPA-aligned contractual controls and the Children’s Online Privacy Protection Act (COPPA) for children under 13. Additional provisions may apply depending on where the institution is located.

Last updated: 11 July 2026

We never sell your data No targeted ads · no AI training on student data Sensitive IDs encrypted at rest DPDP-aligned rights · FERPA-aligned controls

In short

  • Your institution owns and controls its data. ZeroSuite processes it on the institution’s behalf.
  • We collect only what the platform needs to run your school, coaching centre or HR operations.
  • We never sell data, never run targeted ads, and never train public AI models on student records.
  • Sensitive IDs (Aadhaar, PAN, bank) are encrypted at rest; we don’t store card numbers or UPI PINs.
  • For U.S. schools, we support FERPA-aligned contractual controls and COPPA obligations for children under 13.
  • You can access, correct, export, erase data and withdraw consent. See Your rights.

1.Our role & who we are

ZeroSuite (“we”, “us”) is operated from India. For school, coaching and HRMS modules, ZeroSuite generally acts as a service provider / data processor on behalf of the institution. The institution is the data controller (the Data Fiduciary under Indian law) and decides what data is uploaded, makes sure it is collected lawfully, and obtains the consent required from students, parents, guardians and staff. For your own account and billing data, ZeroSuite is the controller.

2.International & U.S. customers

ZeroSuite serves institutions in India and in other countries where we offer our services, including the United States. This policy applies to all of them. Where a country has specific rules for student or personal data, those rules are handled through this policy together with the contract we sign with the institution.

For institutions in India, our processing follows the DPDP Act, 2023 (see Your rights). For schools in the United States, the sections on children under 13 and United States student data set out the additional commitments we make, and we back those commitments with a signed Student Data Privacy Addendum or Data Processing Agreement.

We describe our controls in plain language and support FERPA-aligned contractual controls where they apply. We do not claim to be “FERPA certified” or “100% FERPA compliant,” because FERPA compliance rests with the school. We support schools in meeting applicable student-data privacy requirements, including FERPA-aligned contractual controls where applicable.

3.Data we collect

Depending on the modules an institution enables, the platform may process the following categories of personal data:

CategoryExamples
Student dataName, class/division, roll & admission number, photo, attendance, marks, report cards, academic history
Parent / guardian dataName, relationship, phone, email, address, emergency contact
Health & safetyBlood group, allergies, medical notes; transport / bus route (where the module is used)
Staff / teacher dataName, contact, role, qualifications, timetable, attendance, leave
HR & payrollSalary, payslips, PF/TDS, leave, bank account details, KYC & contract documents
Government IDsAadhaar (students/parents), PAN (staff) and similar identifiers — collected only where enabled by the institution for a lawful purpose, kept optional wherever possible, and stored encrypted at rest
Biometric, device & locationBiometric device PIN/IDs, biometric/QR punch logs, and geo-fence punch location (where those attendance modules are used)
Payment dataInvoice amount, status, transaction / payment ID, gateway reference, receipts
Inquiry / CRMAdmission inquiries, leads, demo requests and follow-up notes
Usage & security logsIP address, browser/device, login and audit logs

4.How we use data

We use personal data to:

  • Provide, operate, secure and maintain the platform and its modules.
  • Run institution operations: admissions, attendance, grading, fees, scheduling, HR and payroll.
  • Authenticate users and keep sessions and records secure.
  • Communicate service, support and security notices.
  • Process payments through our payment partner.
  • Improve reliability and features using aggregated or de-identified data where possible.

We process personal data to deliver the services requested by you or your institution. In India this rests on consent and the legitimate purpose grounds of the DPDP Act, 2023. For institutions elsewhere, our processing is governed by the contract we sign with the institution and the applicable local law. Where the law requires consent, the institution is responsible for obtaining it before entering data, and we support the institution in meeting its own obligations. You may withdraw consent at any time (see Your rights).

6.Children under 13 (COPPA)

ZeroSuite is provided to students through participating schools. It is not intended for children to create accounts on their own without school or parent authorisation. For users under 13, we process information only as authorised by the participating institution and as permitted under applicable law, including the Children’s Online Privacy Protection Act (COPPA) in the United States.

  • We collect only the information the school needs us to process for the service (data minimisation).
  • We protect that information with the security measures described below.
  • We support the school’s requests to review, export or delete a child’s information, and to stop further collection.
  • We do not collect children’s information for advertising, and we do not build advertising or marketing profiles.

Both the school and ZeroSuite have responsibilities here. The school authorises the processing and handles parental notice and consent as required. ZeroSuite, as the service operator, provides the notices and controls the school needs, limits use to authorised educational purposes, and honours deletion and review requests. We do not place sole responsibility for compliance on the school.

We do not sell children’s (or any) personal data, do not use student data for targeted advertising, and do not use student records to train public or third-party AI models.

7.United States student data

When ZeroSuite processes a U.S. school’s records, the following commitments apply. They are also written into the Student Data Privacy Addendum or Data Processing Agreement we sign with the school.

  • The school owns and controls its data. We process it only to deliver the services the school has contracted for.
  • We do not sell student data.
  • We do not use student data for advertising, profiling or unrelated commercial purposes.
  • We do not use student data to train public or third-party AI models.
  • We do not disclose student data except to the authorised sub-processors listed on our sub-processor page.
  • We help the school respond to access, correction, export and deletion requests from students or parents.
  • When the contract ends, we return or delete the school’s data, and we provide written confirmation of deletion when the school asks for it.

FERPA. For schools that are subject to FERPA, a vendor that handles education records under the “school official” route must stay under the school’s direct control, use the records only for the authorised purpose, and not redisclose them without permission. ZeroSuite operates on that basis when a school uses us under the school official exception.

Private and parochial schools. Many private and parochial K–12 schools are not directly subject to FERPA, because they generally do not receive the U.S. Department of Education funding that triggers it. Those schools can still require FERPA-style protections through their contract with us, and state student-privacy laws may also apply. We are happy to sign FERPA-aligned terms in either case. For that reason we do not display a “FERPA Certified” or “100% FERPA Compliant” badge. Instead: ZeroSuite supports schools in meeting applicable student-data privacy requirements, including FERPA-aligned contractual controls where applicable.

8.Sharing & sub-processors

We do not sell or trade personal data. We share data only with vetted providers who help us run the platform, and only as needed. The named providers we use, their location and what each one does are listed on our public sub-processor page. Categories of sub-processors include:

  • Cloud hosting and database / storage providers.
  • Email, SMS and WhatsApp notification providers.
  • Payment gateway (Razorpay).
  • Authentication providers (e.g. Google sign-in, where used).
  • Analytics and error-monitoring tools.
  • Biometric / RFID / attendance-device integration providers, where applicable.
  • Authorities, when required by law or to protect rights and safety.

Each provider may use the data only to perform its service for us.

9.Payment data

Payments are processed by our payment partner (Razorpay). We do not store full card numbers, UPI PINs, passwords or banking credentials. We retain only transaction references such as payment IDs, invoice numbers, amount and status, needed for billing, reconciliation and refunds.

10.Audit logs & access control

Access is role-based, so users see only what their role allows. ZeroSuite may maintain audit logs of logins, role-based actions and record changes — for example attendance edits, fee/payment status changes and administrative activity — for security, accountability and dispute resolution.

11.Data security

We use reasonable technical and organisational safeguards including HTTPS/TLS in transit, encryption at rest for sensitive identifiers, role-based access controls, audit logs, backups and restricted administrative access. However, no internet-based system can be guaranteed 100% secure.

12.Breach notification

If we become aware of a personal-data breach, we will take reasonable steps to contain, investigate and remediate the incident. Where required by law, we will notify affected institutions, users and authorities (including the Data Protection Board in India) in plain language, with the nature of the breach, its likely consequences, the remedial steps taken, and contact details for assistance.

For institutions we work with under a contract or Data Processing Agreement, ZeroSuite will notify the institution without undue delay after confirming a security incident that affects the institution’s personal data, within the timeline agreed in that contract.

13.Data retention

We keep personal data only as long as needed for the purpose collected, or as the law requires:

Data typeTypical retention
Institution & student recordsWhile the institution’s account is active, or as agreed with the institution
Attendance & operational logsAs configured by the institution or as legally required
Payment & invoice recordsUp to 7 years (tax / accounting obligations)
Support messages1–3 years
Security / login logs6–12 months
Deleted-account dataDeleted or anonymised within 90 days of a verified request, unless the law requires longer

14.Cookies

We use cookies and similar technologies to keep you signed in, remember preferences and understand usage. You can manage cookies in your browser settings; disabling some may limit platform features.

15.Your rights under the DPDP Act

Subject to the DPDP Act, 2023, users, parents, guardians, staff and authorised institutional representatives may request to:

  • Access the personal data we hold.
  • Correct or update inaccurate or incomplete data.
  • Erase data.
  • Withdraw consent (without affecting prior lawful processing).
  • Nominate another person to exercise your rights.
  • Raise a grievance and have it addressed.

Students, guardians and staff should usually raise requests with their institution (the data controller); we will support the institution in responding. We act on valid requests within the timelines set by law, and in any case within the statutory maximum of 90 days. For U.S. schools, we assist with access, correction, export and deletion requests as set out in the United States student data section.

16.Data deletion requests

To request deletion of your personal data, email grievance@zerosuite.in or support@zerosuite.in from your registered address. For student or staff data held on behalf of an institution, we route the request to that institution as the data controller. Once we confirm a valid request, an administrator deletes or anonymises the data within 90 days, except where we must retain it to meet a legal or accounting obligation. When a contract ends, we return or delete the institution’s data and provide written confirmation of deletion on request.

17.Where data is stored

Platform data is hosted on managed cloud infrastructure in the Asia (Singapore) region, with sensitive identifiers (such as Aadhaar, PAN and bank details) encrypted at rest. U.S. customer data may be hosted and processed in Singapore, India or other locations used by our authorised service providers. We apply appropriate contractual, organisational and technical safeguards to cross-border processing, in line with this policy and, for Indian data, the DPDP Act, 2023, which permits such transfers except to countries restricted by the Government of India.

During procurement we are glad to confirm, in writing, which cloud provider we use, where backups are stored, and which countries our support staff can access data from. A school that requires U.S.-region hosting can raise it with us before signing, and we will confirm what we can offer.

18.Brand & affiliation

This policy applies to ZeroSuite at zerosuite.in, our education and HR platform. We are not affiliated with zerosuite.dev or any other similarly named third-party service, and that service’s policies do not apply to us.

19.Changes to this policy

We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date. Please review it periodically.

Grievance officer & contact

For privacy questions, data-rights requests or complaints, contact us. We acknowledge complaints promptly and address valid requests within the timelines required by law. Schools can also request our sub-processor list, security overview and Data Processing Agreement.

Privacy requests: support@zerosuite.in

Grievance / Privacy Officer: grievance@zerosuite.in

Sub-processors: zerosuite.in/subprocessors

WhatsApp Us