1. Shared responsibility
Data protection is shared. Schools decide who should have access, what records are necessary, how long they are retained, and which integrations are enabled. Alethron Solution provides platform controls, processes authorized instructions, and operates the service under the applicable agreement.
2. Platform controls
- School, branch, session, membership, and role-aware access boundaries.
- Authenticated private-file delivery and ownership checks for protected documents.
- Login, session, export, sensitive-access, and administrative audit records where configured.
- Password, first-login, logout-all, device, network, and multi-factor policy capabilities.
- Encrypted backup and restore verification workflows where production storage is configured.
3. Data minimization and access
Institutions should enable only required modules, collect only necessary fields, use the least-privileged role, and periodically review users, exports, trusted devices, integrations, and public links. Shared accounts should not be used.
4. Files, exports, and documents
Receipts, payslips, marksheets, identity documents, student files, exports, and generated reports may contain sensitive information. They should use authenticated delivery, short-lived compatibility links only where unavoidable, permission checks, school ownership checks, and access logging.
5. Backup and recovery
Production deployments should configure encryption keys, primary and offsite backup storage, automated schedules, failure alerts, and recurring restore drills. A backup is not considered reliable until integrity and restoration have been verified.
6. Security incidents
Suspected unauthorized access, credential exposure, incorrect school context, public document access, malware, or lost devices should be reported immediately. We may preserve logs, restrict sessions, isolate affected features, and coordinate investigation and notification with the subscribing institution.
7. Individual requests and grievances
Schools should maintain a verified process for access, correction, erasure, consent, nomination, and grievance requests that apply to their records. Alethron Solution assists the institution where required by the agreement and applicable law.
8. Legal framework
EduSaarthi's policies are intended to support responsible processing under applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023 and phased requirements under the Digital Personal Data Protection Rules, 2025. Each institution remains responsible for obtaining legal guidance appropriate to its operations.
9. Production checklist
- Confirm school, branch, session, plan, role, and permission assignments.
- Configure private storage, backup encryption, offsite verification, and restore drills.
- Review provider credentials, webhooks, sender approvals, and data-sharing settings.
- Remove sample users and data, enforce password and MFA policies, and test logout-all.
- Test cross-school access blocking, sensitive file access, export permissions, and incident contacts.
Official references
Questions about this policy?
Contact amitedge69@gmail.com. Requests involving school-managed records may be referred to the relevant institution for identity and authority checks.