1. Overview & Scope
This Privacy Policy ("Policy") describes how CodeLadder Technologies Private Limited ("we", "us", or "our"), the developer of the AiraNexus school management platform, collects, uses, stores, discloses, and protects personal information about you when you:
- Visit our public website at https://campus.airanexus.in ("Site")
- Request a product demo, contact us, or submit an inquiry form
- Use the AiraNexus school management platform as an administrator, teacher, staff member, or parent (“Platform”)
- Communicate with our support or sales team by phone, email, or WhatsApp
This Policy applies to all personal data we process, regardless of the medium or format, and complies with India's Digital Personal Data Protection Act, 2023 (DPDPA 2023) and applicable international data protection principles.
By accessing our Site or Platform, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree, please discontinue use and contact us to request data deletion.
2. Information We Collect
2.1 Information You Provide Directly
- Contact information: name, school name, designation, phone number, email address, city, state
- Demo request details: number of students, curriculum, current software in use
- Account registration: username, role, school identification, password (stored as bcrypt hash — never plain text)
- Support communications: content of emails, calls, WhatsApp messages to our team
- Payment information: processed exclusively through PCI-DSS compliant third-party gateways (Razorpay, PayU, CCAvenue) — we do not store card numbers
2.2 Student & School Data (Platform Only)
When your school subscribes to the AiraNexus platform, the school acts as the Data Principal / Data Fiduciary for student data. We process this data solely on your school's behalf:
- Student names, enrollment numbers, class, section, date of birth
- Attendance records
- Examination marks and report card data
- Fee payment history and outstanding balances
- Parent/guardian name and contact details (for notifications)
- Health records (optional, school discretion)
- Transport route assignments (optional)
We process student data strictly under a Data Processing Agreement (DPA) with each school. Schools retain full ownership and control of their student data at all times.
2.3 Automatically Collected Technical Data
- IP address and approximate geographic location (city/region level)
- Browser type, version, operating system, device type
- Pages visited, time spent, referral source (analytics)
- Service Worker cache version and update events (PWA diagnostics)
- Form interaction data for conversion analysis (only if you consent to analytics cookies)
3. How We Use Your Information
- To respond to demo requests, inquiries, and support tickets
- To configure and operate the AiraNexus platform for your school
- To send transactional notifications: attendance alerts, fee reminders, exam results
- To send service communications: platform updates, maintenance notices, policy changes
- To process fee payments through our integrated payment gateway partners
- To improve platform features using aggregated, anonymised usage analytics
- To comply with legal obligations under Indian law, including DPDPA 2023, IT Act 2000, and Income Tax regulations
- To detect and prevent fraud, abuse, and unauthorised access
- To send marketing communications about AiraNexus features or events — only if you have explicitly opted in, and always with a clear unsubscribe option
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. Ever.
4. Legal Basis for Processing
Under DPDPA 2023 and applicable data protection law, we process personal data based on:
| Processing Purpose | Legal Basis |
|---|---|
| Responding to inquiries & demos | Consent / Legitimate Interest |
| Platform account creation & operation | Contract performance |
| Student data processing for school | Data Processing Agreement with the school (Data Fiduciary) |
| Fee payment processing | Contract performance |
| Platform improvement analytics | Consent (analytics cookies) |
| Marketing emails / communications | Explicit opt-in consent |
| Legal compliance & fraud prevention | Legal obligation / Legitimate Interest |
| Security incident response | Legitimate Interest / Legal obligation |
7. Data Security
We implement industry-standard security controls to protect your personal data:
- AES-256 encryption for all data at rest on AWS infrastructure
- TLS 1.2+ (enforced TLS 1.3 where supported) for all data in transit
- Role-Based Access Control (RBAC) — each user can only access data their role permits
- OTP-based two-factor authentication (2FA) for admin and teacher accounts
- Automated daily backups with 30-day retention stored in encrypted AWS S3
- Regular security vulnerability scanning and penetration testing
- Incident response plan: security breaches notified to affected schools within 72 hours of detection
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Website inquiry / contact form data | 2 years from last interaction, or until deletion request |
| Platform account data (active subscription) | Duration of subscription + 90 days post-termination |
| Student academic & attendance records | As required by school; exported to school on termination |
| Fee transaction records | 7 years (Indian Income Tax Act retention requirement) |
| Support tickets and communications | 3 years from resolution |
| Security and access logs | 1 year rolling |
| Backup copies | 30 days post-creation, then automatically deleted |
9. Your Rights Under DPDPA 2023
Under India's Digital Personal Data Protection Act, 2023, you have the following rights in relation to your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Correction
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data (subject to legal retention obligations).
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Restrict Processing
Request restriction of processing in certain circumstances.
Right to Withdraw Consent
Withdraw consent at any time where processing is consent-based.
Right to Grievance Redressal
Lodge a complaint with our Grievance Officer or the Data Protection Board of India.
Right to Nominate
Nominate a person to exercise your rights in case of death or incapacity (DPDPA provision).
To exercise any of these rights, email privacy@airanexus.in with "Data Rights Request" in the subject line. We will respond within 30 days.
10. Children's Privacy
Our public website (https://campus.airanexus.in) is intended for school administrators, teachers, and parents — not directly for children. We do not knowingly collect personal data from children under 18 on the website.
Within the Platform: Schools process student data (including minors) under strict Data Processing Agreements. The school — as Data Fiduciary — is responsible for obtaining parental/guardian consent for student data under applicable law.
11. International Data Transfers
All personal and student data is stored on AWS infrastructure located in India (Mumbai — ap-south-1 region). We do not routinely transfer personal data outside India.
Certain third-party tools (e.g., Google Analytics — if consented to) may transfer anonymised usage data to servers outside India. These tools are configured to anonymise IP addresses before any transfer.
12. Third-Party Links
Our website may contain links to third-party websites (e.g., Google Classroom, Razorpay, WhatsApp). These sites have their own privacy policies and we are not responsible for their practices. We encourage you to review the privacy policy of any third-party site you visit.
13. Policy Updates
We may update this Policy from time to time to reflect changes in law, technology, or our practices. When we make material changes, we will:
- Post the updated Policy on this page with a revised “Last Updated” date
- Send an email notification to registered platform users
- Display a prominent banner on the website for at least 14 days
- Increment the Cookie Consent version if consent re-collection is required
14. Mobile App Privacy (iOS & Android)
AiraNexus provides native mobile applications for parents and school staff, available on the Apple App Store (iOS) and Google Play Store (Android).
14.1 Data Collected by the Mobile Apps
| Data Type | Collected? | Linked to Identity? | Used for Tracking? |
|---|---|---|---|
| Full name & parent/staff role | Yes | Yes | No |
| Phone number (login identifier) | Yes | Yes | No |
| Session token (JWT) | Yes | Yes | No — stored in Keychain/Keystore only |
| mPIN hash (4-digit unlock) | Yes | Yes | No — never transmitted |
| Child academic data (marks, attendance, fees) | Yes | Yes | No |
| Push notification token (FCM/APNs) | Yes | Yes | No — used only to deliver school alerts |
| Precise location | No | — | — |
| Camera / microphone | No | — | — |
14.2 Secure Credential Storage
- iOS: JWT session tokens and mPIN hash are stored in the iOS Keychain — encrypted by the device Secure Enclave, inaccessible to other apps and excluded from iCloud backup.
- Android: JWT session tokens and mPIN hash are stored in the Android Keystore — hardware-backed encryption, inaccessible via ADB backup.
- Neither the token nor the mPIN is ever stored in plain text, SharedPreferences, or AsyncStorage.
14.3 Push Notifications
- iOS: Push requires explicit permission granted through the iOS system prompt.
- Android 13+: Push requires explicit POST_NOTIFICATIONS permission at runtime.
- Your device push token (FCM/APNs) is transmitted to our server solely to route notifications to your device.
- You can withdraw notification permission at any time in your device Settings.
14.4 No Third-Party Advertising SDKs
The AiraNexus mobile app does not include any advertising SDKs, ad networks, or analytics SDKs that track users across apps or websites. The only third-party SDK used for remote services is Firebase Cloud Messaging (FCM) solely for push notification delivery.
15. Contact & Grievance Officer
Privacy Queries
privacy@airanexus.inFor data rights requests, consent withdrawal, and privacy concerns. Response within 30 days.
Grievance Officer
CodeLadder Technologies Private LimitedEmail: privacy@airanexus.in · Response within 30 days
Data Protection Board
If your complaint is not resolved within 30 days, you may escalate to the Data Protection Board of India (DPDPA 2023).
This policy was last reviewed and updated on 30 April 2026.
It is effective from 1 February 2025. If you have any questions, please email privacy@airanexus.in.