DPDP Act (India) Compliant

Privacy Policy

Last Updated: September 2026 • Effective for all institutions and authorized users

Clariadesk is an institutional school operating system developed and operated by Clariadesk (“we,” “us,” or “our”). We are committed to safeguarding the confidentiality and integrity of all administrative, staff, and student data entrusted to our platform.

1Information We Collect

We only collect and process data strictly necessary to deliver campus management, automated payroll, and attendance workflows:

Institutional Accounts

School name, registration/affiliation number, campus address, GSTIN, principal and administrator email addresses, and phone numbers.

Staff & Faculty Records

Teacher names, employee IDs, designated subjects/classes, salary baselines, QR check-in timestamps, and leave requests.

Student & Cohort Data

Student names, admission/roll numbers, grade/section enrollments, daily attendance markers, and curriculum progress logs.

Financial & Fee Ledgers

Fee invoice amounts, payment receipts, UPI/Cashfree transaction references, and dues ledgers. We do not store raw credit card numbers.

2Data Protection & Security Standards

We enforce enterprise-grade security protocols across every layer of the Clariadesk software infrastructure:

  • Zero Commercial Monetization: Institutional data is strictly proprietary to the subscriber. We never sell, rent, license, or monetize student or staff information to third-party advertisers or data brokers.
  • Encryption at Rest & Transit: All database volumes, network requests, and API payloads are encrypted using industry-standard TLS 1.3 in transit and AES-256 at rest.
  • Isolated Multi-Tenant Security: Row-Level Security (RLS) policies ensure that institutional data is completely segregated and accessible only by authenticated users belonging to that specific school ID.
  • Cloud Infrastructure: Hosted on ISO-27001 and SOC-2 compliant cloud data centers located in India to ensure data sovereignty.

3Cookies & Local Session Storage

Clariadesk utilizes only essential, strictly functional cookies and session tokens:

Authentication Cookies: Secure, HTTP-only JWT session tokens required to authenticate principals, teachers, and staff across dashboard sessions.
Security Cookies: Anti-CSRF verification tokens and PKCE code verifiers ensuring safe authentication transactions.
No Third-Party Tracking: We do not load third-party ad retargeting pixels or behavioral tracking scripts on authenticated dashboard routes.

4Institutional Rights (DPDP Act)

In full alignment with the Digital Personal Data Protection (DPDP) Act, 2023, subscribing institutions and designated data principals retain comprehensive rights:

  • Right to Data Portability & Export: Administrators may export student registries, attendance logs, and fee reports in standard formats (CSV, Excel) at any time.
  • Right to Rectification: School administrators hold real-time administrative permissions to correct, update, or modify student and faculty profiles.
  • Right to Erasure upon Termination: Upon termination of service and conclusion of the 90-day retention grace period, institutions may request complete cryptographic purging of all tenant records.

Data Protection Officer Contact

For any data protection inquiries, audit requests, or DPDP compliance questions, please contact our designated privacy desk:

Clariadesk Privacy & Compliance Officesupport@clariadesk.inNew Delhi, India • Response SLA: Within 48 business hours
Clariadesk Institutional Platform

© 2026 Clariadesk. All rights reserved.