Skip to content

You are handling children’s data. So are we.

Where the data sits, who can reach it, how it is protected, and what you can ask us to do with it — written plainly, so you can hand this page to your management committee.

The short version

The data is yours. We only process it.

Under India’s Digital Personal Data Protection Act, 2023, your institution is the Data Fiduciary for the personal data of its students, their parents and its staff. You decide what is collected and why. Lamda Infotech is a Data Processor: we hold and process that data on your instruction, for the purpose of running the software you have bought, and for nothing else.

In practice that means we do not sell your data, we do not share it with anyone you have not asked us to share it with, and we do not use it to train anything or to market to your parents. If you tell us to export it, we export it. If you tell us to delete it, we delete it.

Because most of your students are minors, the Act treats their data as needing additional care — including verifiable parental consent and a bar on behavioural tracking or targeted advertising aimed at children. The platform is built so that neither is possible: there is no advertising in the application and no third-party tracking inside the parent app.

AWS
Where it is hosted
TLS
Encrypted in transit
Daily
Automated backups
24×7
Incident contact

Need this for a tender?

We will complete your security questionnaire, sign a data processing agreement, and put the specifics in writing on your letterhead.

Ask for the paperwork
Controls

How the data is protected

Hosted on Amazon Web Services

The application and database run on AWS rather than on a machine in an office. That buys managed power, cooling, physical security and hardware redundancy that no institution — and no small vendor — can match on its own premises.

Encrypted in transit

Every connection — browser to server, app to server — runs over TLS with certificates from a recognised authority. Nothing about a student travels over the network in the clear, including on a school’s shared Wi-Fi.

One institution cannot see another

Each institution’s records are separated, and every query is scoped to the account of the person making it. A teacher at one school has no path to a record at another, and no path to a class they do not teach.

Role-based access, set by you

Management, teachers, clerks, accountants, students and parents each see a different slice. Your administrator grants and revokes those rights from inside the application — when a teacher leaves, you close the account yourself, immediately, without calling us.

Backed up daily

Automated daily backups, kept separately from the running database, so a mistake in the office — a class deleted, a fee structure overwritten — is recoverable and not a catastrophe.

Actions are traceable

Marks entered, fees receipted, records amended — the application records who did what and when, so a disputed change has an answer. Faults are reported to us automatically, which is often how we find a problem before it is raised.

We never hold card details

Online fee payments are handed to a regulated payment gateway — PayU, Paytm, PayPal or BillDesk. Card and account numbers are entered on their systems, not ours. We store the result of a payment, not the instrument.

Tested before it ships

Changes go through a dedicated QA pass against written test cases before release, and updates roll out to the platform rather than being applied school by school — so no institution is left on an old, unpatched version.

Your control

What you can ask us to do, at any time

These are not favours — they are how the arrangement is meant to work. Write to info@lamdainfotech.com from an authorised address and we will act on it.

Students, staff, attendance, marks, fees, accounts and documents, in a readable format you can open and keep. No charge, whether or not you are leaving.
Most corrections your administrator can make directly in the application, which is faster than asking us. Where a record is locked — a published result, a receipted payment — we will make the change on your written instruction and leave the audit trail intact.
On written instruction we delete your institution’s data from the live system, and it ages out of the backup rotation after that. We will confirm in writing when it is done. Take your export first — deletion is not reversible.
A parent asking what is held about their child should come to the institution, not to us — you are the Data Fiduciary and the relationship is yours. We will give you whatever you need to answer them, promptly and at no charge.
If we become aware of a breach affecting your institution’s data, we tell you — what happened, what was affected and what we are doing — so that you can meet your own obligations under the Act. You will hear it from us, not from somewhere else.
Shared responsibility

The half we cannot do for you

Most incidents at institutions are not a broken server. They are a shared login, or an account nobody closed. Four habits do more for your students’ privacy than anything on the list above.

One login per person

A staffroom account that everyone knows is the single most common weakness we see. It also makes the audit trail useless — nobody can say who changed a mark.

Close accounts the day someone leaves

Your administrator can do it in seconds. A former teacher with a live login is a live risk, and it is the thing an auditor asks about first.

Grant the narrowest role that works

A class teacher rarely needs the fee ledger; a clerk rarely needs marks. Narrow roles limit the damage when a password does get out.

Collect only what you will use

The Act expects data minimisation, and it is good practice regardless. If a field on the admission form serves no purpose, turn it off.

Have a question this page does not answer?

Ask it directly. If your committee or your auditor needs something in writing, say so and we will put it on letterhead.