WhatsApp Live Desk Direct Helpline: +91 7709196316
OFFICIAL INSTITUTIONAL GOVERNANCE · DATA PROTECTION & PRIVACY CHARTER
Privacy Policy / Global Legal Suite

PRIVACY POLICY & DATA GOVERNANCE CHARTER

Learn how Ellifo ERP collects, uses, and protects student, faculty, and financial data, including our encryption practices and commitment to never selling institutional data.

event_available Effective Date: January 1, 2026 verified Version: 3.4 Enterprise gavel Compliance Scope: DPDP Act (India), FERPA & GDPR Ready
account_balance
100% Institutional
Total Customer Ownership

Zero platform claim or rights assertion on school student roster, academic, & financial records.

lock
AES-256 & TLS 1.3
Cryptographic Guarantee

Continuous bank-grade cryptographic protection in flight across all endpoints and isolated at rest.

block
0 Third-Party Ads
Absolute Commercial Pledge

Campus data is never sold, shared, commodified, or brokered to marketing and advertising networks.

shield_with_heart
SOC2 & ISO 27001
Automated Auditing

Continuous multi-region telemetry auditing on AWS cloud infrastructure with instant failovers.

1

Data Collection

SECTION 1.0

We collect information necessary to provide institutional management services, including student records, faculty details, and financial data provided by the user institution.

Student records typically include names, contact and guardian details, attendance, academic performance, and enrollment history entered by your institution. Faculty details cover staff profiles, roles, and attendance used to administer the platform on your behalf. Financial data includes fee structures, payment records, and invoices processed through the platform. This information is provided directly by the institution or its authorized users during setup and day-to-day use, and is never collected from students or parents independently of the institution's own workflows.

school Student Roster Records
Demographics, guardian ties, enrollment history, and grade book entries strictly ingested via school administration.
badge Faculty Administration
Instructor qualifications, departmental role assignments, attendance logs, and internal class scheduling profiles.
receipt_long Fee & Ledger Financials
Fee structures, payment gateway settlements, concession approvals, and cryptographic institutional tax invoices.
2

Data Usage

SECTION 2.0

Your data is used solely for the purpose of operating the Ellifo platform for your institution. We do not sell or share your institutional data with third-party advertisers.

In practical terms, this means your data powers features like attendance tracking, report card generation, fee reconciliation, and parent communication within your own institutional account. Limited, aggregated, and de-identified usage patterns may be reviewed internally to improve platform performance and reliability, but this is never used to build advertising profiles or sold to any external party. Where a trusted sub-processor (such as our cloud hosting or payment gateway provider) needs access to perform a specific function, access is limited strictly to what that function requires and is governed by contractual confidentiality obligations.

check_circle
Never Sold to Advertisers Zero tracking cookies, zero ad telemetry, zero student monetization.
cloud_sync
Isolated Sub-Processors Confidential contracts strictly bounded by operational need.
query_stats
De-Identified Telemetry Internal uptime and platform reliability metrics with zero PII.
3

Security

SECTION 3.0

We employ industry-standard AES-256 encryption and SSL protocols to protect data in transit and at rest on our secure AWS cloud infrastructure.

Access to institutional data within the platform is further restricted through role-based permissions, so staff members only see the records relevant to their responsibilities. Our infrastructure runs on AWS with regular backups and monitoring in place to guard against data loss and unauthorized access. While no system can guarantee absolute security, we continuously review and update our practices to align with current industry standards, and we encourage institutions to pair these protections with strong internal password and account-management habits as described in our Platform Policy.

enhanced_encryption AES-256 Encryption

Military-grade cryptographic envelopes guarding database storage volumes, media files, and active session streams.

cloud_queue AWS Isolated VPC

Multi-availability-zone infrastructure with automated cold-storage snapshots and zero cross-tenant database leakage.

admin_panel_settings Granular RBAC

Zero-trust privilege rings ensuring teachers only access designated gradebooks and financial officers view accounts.

4

Student & Minor Privacy Safeguards

SECTION 4.0

We uphold the highest standard of protection for minors and educational cohorts in complete alignment with FERPA, COPPA, and the Digital Personal Data Protection (DPDP) Act. Ellifo acts strictly as a certified Data Processor (or Service Provider) on behalf of the subscriber institution, which remains the sole Data Controller.

family_restroom
Guardian-Mediated Consent

All minor data credentials are provisioned exclusively through authorized guardian or school administrative channels. Ellifo never serves direct prompts to minors for unverified data collection.

visibility_off
Zero Behavioral Profiling

Minor student interactions, assessment marks, and attendance logs are never parsed for psychographic profiling, commercial recommender algorithms, or third-party syndication.

5

Institutional Data Portability & Retention

SECTION 5.0

We firmly believe that institutions must maintain unfettered custody over their institutional intelligence. Ellifo guarantees total data portability with no arbitrary export lock-in or proprietary schema barriers.

database Open Format Extraction

Super-administrators may trigger complete system exports (JSON, standardized CSV batches, or encrypted SQL dumps) at any time through the administration console.

history 90-Day Transition Grace

Upon subscription cancellation or contract conclusion, institutional data remains available in read-only encrypted cold custody for 90 calendar days prior to permanent DoD-standard purge.

6

Audit Logging & Incident Protocols

SECTION 6.0

Every data access, credential login, role permission mutation, grade override, and batch financial transaction within Ellifo generates an immutable, tamper-evident audit record.

Incident Notification Service Level < 24h SLA

In the highly improbable event of a validated security incident or unauthorized access attempt impacting your institution, our Information Security Officer will notify designated institutional contacts within 24 hours of confirmation, accompanied by full forensic telemetry and remediation steps.

Legal Clarifications

Frequently Asked Privacy Questions

Clear, unambiguous answers regarding school record ownership, cloud geography, and access controls.

Does Ellifo own or claim any rights to student records? expand_more
No. Ellifo has zero ownership claim over any data entered into the platform. Your institution retains 100% intellectual, administrative, and legal ownership over all student, parent, employee, and fee records at all times.
Can third parties or advertising brokers access school data? expand_more
Never. Ellifo does not display advertisements, does not run ad-tracking scripts, and strictly prohibits the sale or brokering of school rosters, performance metrics, or contact directories to any third-party marketing entities.
Where is our institution's data physically stored? expand_more
All production databases and secure backups run on enterprise AWS VPC clusters in your jurisdiction's designated region (e.g., AWS Mumbai / ap-south-1 for India, AWS us-east-1 for North America, and AWS Frankfurt / eu-central-1 for EU deployments) guaranteeing sovereign compliance.
How are parent and student logins protected? expand_more
Parent and student mobile apps connect via encrypted TLS 1.3 endpoints with salted multi-round password hashing (bcrypt), optional Multi-Factor Authentication (MFA), and automated brute-force intrusion locks.
What happens to our student data if we discontinue our subscription? expand_more
Your designated administrators receive a comprehensive data export package containing all historical rosters, grade records, and audit logs. A 90-day grace transition window is maintained, following which all cloud volumes associated with your instance are cryptographically wiped.
verified Enterprise Accreditation Support

Require a custom Data Processing Agreement (DPA) or security audit review?

Our institutional compliance team assists university boards, school trusts, and government educational agencies with specialized SOC2 Type II reports, penetration testing summaries, and tailored DPA addendums.