In short
- Your institute decides why and how student and staff data is used — it is the Data Fiduciary.
- LigimeX only processes that data on your instructions — it is the Data Processor.
- All data is hosted and backed up in India, encrypted in transit and at rest.
- We do not sell personal data and never use student data for advertising.
This page explains the roles, safeguards and processes that sit behind our privacy policy and terms of service. It is written as a plain-language data processing summary that an institute can rely on under the DPDP Act. It is not a substitute for your own legal advice.
1. Who is responsible for what
Under the DPDP Act, responsibilities depend on who decides the purpose of the processing:
- Your institute is the Data Fiduciary for the student, parent and staff data it enters into LigiLearn. You decide what to collect, why, and the consents you rely on (including parental consent for minor students, obtained through your admission process).
- LigimeX is the Data Processor for that data. We process it only to provide, secure and support the Service, strictly on your instructions and as described in the privacy policy — never for our own purposes.
- LigimeX is the Data Fiduciary for the limited data it collects directly — demo enquiries, billing contacts and website usage — and handles that data under its own privacy policy.
2. How we process personal data
- We process institute data only to run the modules you use, generate the reports you request and send the alerts you configure.
- We act on documented instructions from the institute's authorised administrators.
- Our staff access institute data only when needed for support or operations, under confidentiality obligations, and every such access is logged.
- We do not use student data to train advertising or profiling systems, and we do not sell personal data to anyone.
3. Security measures
- Encryption of data in transit (TLS) and at rest.
- Role-based access control so every user sees only what their role permits.
- Hashed passwords, account lockout after repeated failed sign-ins, and anti-forgery protection on every state-changing action.
- Audit logs recording who changed important records and when.
- Daily backups, stored in India, so data is not lost.
- Periodic security reviews of the platform.
4. Sub-processors
We use a small, carefully chosen set of providers to deliver specific parts of the Service. Each receives only the data that part needs, over encrypted connections, and under its own data protection terms.
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Razorpay | Online fee payments (PCI-DSS compliant) | Payment amount and reference; card and bank details go directly to Razorpay and are never stored by us |
| SMS, email and WhatsApp gateways | Notifications you configure | Recipient contact detail and the message content only |
| Cloud hosting (India) | Storage and daily backups | Encrypted institute data at rest |
We will give advance notice of any material change to this list so you can raise concerns before it takes effect.
5. Data localisation
Personal data processed through LigiLearn is stored and backed up on servers located in India. We do not transfer your personal data outside India in the ordinary course of providing the Service.
6. Children's data
Most students in a school are children (under 18), so their data gets the extra protection the DPDP Act requires:
- Student data is entered by the institute on the basis of verifiable parental or guardian consent obtained during admission.
- We do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
- A child's records are visible only to the institute's authorised staff and the child's own parents or guardians.
- Parents and guardians can view and request correction of their child's data through the institute.
7. Data Principal rights
Individuals whose data is processed ("Data Principals") have rights under the DPDP Act:
- Access — a summary of the personal data being processed.
- Correction and completion — have inaccurate or incomplete data put right.
- Erasure — have data deleted when it is no longer needed or consent is withdrawn.
- Grievance redressal — a clear way to raise and have concerns addressed.
- Nomination — nominate someone to exercise these rights in the event of death or incapacity.
For data held on an institute's behalf, requests are made to that institute as the Data Fiduciary; we support institutes in responding. For data where LigimeX is the Data Fiduciary, contact our Grievance Officer below.
8. Personal data breaches
If a personal data breach occurs, we will act promptly to contain it, inform the affected institute without undue delay with the facts and the steps being taken, and support any notification the DPDP Act requires to the Data Protection Board of India and to affected Data Principals.
9. Retention and deletion
We retain personal data only for as long as the institute's account is active or as needed to provide the Service. On a verified deletion request, or after account closure, data is permanently deleted within 90 days, except records we are required by law to keep (for example payment records), which are retained only for the legally required period. Full details are in the privacy policy.
10. Grievance Officer
In line with the DPDP Act, we have designated a Grievance Officer as the point of contact for questions and complaints about personal data and the exercise of your rights:
- Name: Bhavya Pandey
- Designation: Grievance Officer, LigimeX
- Email: ligimex@gmail.com
- Address: LigimeX, [registered office address], Lucknow, Uttar Pradesh, India
We acknowledge grievances promptly and aim to resolve them as quickly as possible, and in any case within the timeframe required under the DPDP Act and its rules.
11. Changes
We may update this page as the DPDP Act's rules and our practices evolve. Material changes are announced by email or an in-app notice, and the "Last updated" date above shows the latest revision.