SmartHisaab Education (the “Service”) is developed and operated by Swayam Digital Systems, a sole proprietorship of Sitanshu Panda. In this Policy, “we”, “us” and “our” refer to Swayam Digital Systems. The Service helps coaching and tuition institutes manage admissions, students, attendance, fees, communication, academics, assessments, staff and reports.
1. Data we collect and where it comes from
From institutes
- Institute profile, contact information, branches, departments and optional logo
- Authorised Owner, Admin, Teacher and Student account information and access assignments
- Passwords for issued accounts, stored only in securely hashed form and not as readable text
About students and guardians
- Admission, identity, contact, batch, class and lifecycle records
- Parent or guardian identity and contact details used for institute-authorised communication
- Attendance, academic work, assessments, marks, results and related learning records
- Fee amounts, due dates, invoices, instalments and payment records
About staff
- Staff identity, contact, employment, department and assignment records
- Account role, granted access and security-relevant credential lifecycle events
Security and operation records
- Login attempts and network information used for rate limiting and account protection
- Authentication and session records used to keep authorised users signed in and revoke access
- Audit records of relevant administrative actions
- Delivery status of supported messages, such as sent, delivered, read or failed
2. How we use this data
- Provide the institute-management modules and role-specific workspaces
- Maintain the institute's operational, academic and money records
- Deliver institute-authorised messages, reminders, alerts and receipts
- Protect accounts through rate limiting, session management and auditability
- Support institutes and investigate reported problems
3. WhatsApp and service providers
Messages are delivered through the WhatsApp Business Platform, operated by Meta Platforms. To deliver a message, the recipient's phone number and message content may be transmitted to Meta. Meta describes its handling in the WhatsApp Business terms and WhatsApp Privacy Policy.
The Service currently uses Vercel for web delivery, Render for the backend application and Neon for the PostgreSQL database in Singapore. These providers process data as needed to host and deliver the Service. Supported public traffic is encrypted in transit using HTTPS/TLS.
We disclose personal data only to providers needed to operate the Service, where required by law, or on the relevant institute's lawful instruction. We do not sell, rent or trade personal data.
4. Payments
5. Children's data
Student information is entered by institutes from their admission, academic and administrative records to provide and manage educational services. We do not invite children to create an independent commercial relationship with Swayam Digital Systems. Where a guardian relationship is recorded, institute-authorised external communication goes to the guardian contact. A parent or guardian may ask the institute—or us directly—to correct or remove a child's details.
6. How long we keep data
- Institute, student, staff, academic, fee and message records: kept while the institute's account is active so it has a continuous operational record
- Security and audit records: kept for a limited period appropriate to account protection, investigation and applicable obligations
- After account closure: institute data is deleted within 30 days of a confirmed closure request, except where law requires a record to be retained longer
7. Correction and deletion requests
- Students and guardians: ask your institute to correct or remove its record, or contact us with the institute name and enough information to verify the request.
- Institutes: contact us to close the account. The institution's data will be permanently deleted within 30 days of confirmed closure, subject to any legal retention requirement.
Write to privacy@smarthisaab.in. We aim to acknowledge requests within 7 working days and will verify authority before changing protected records.
8. Security
- Passwords are stored as one-way cryptographic hashes
- Authentication and session records support expiry and revocation
- Institution context and role boundaries restrict access to tenant data
- Repeated failed authentication attempts are rate-limited or locked out
- Supported public traffic uses HTTPS
See Trust for our public control boundaries or Security Reports to report a suspected vulnerability.
9. Your choices
- Ask for correction or deletion through the institute or our privacy address
- Institute-authorised users can maintain records within the access provided to their role
- Use the official addresses on our Contact page for privacy, support or formal legal correspondence
10. Changes to this policy
If this Policy changes materially, we will update this page and its revision date. Changes needed before a new provider or payment-processing activity begins will be published before that processing starts.
11. Contact
Swayam Digital Systems, a sole proprietorship of Sitanshu Panda · UDYAM-OD-19-0176589 · Odisha, India.
Privacy and data-protection requests: privacy@smarthisaab.in
Formal legal notices: legal@smarthisaab.in
Phone: +91 80938 03809