Privacy Policy
1. About this privacy policy
This Privacy Policy describes how EduBlast Technologies Private Limited ("EduBlast", "Data Fiduciary", "we", "us") collects, uses, stores, shares, and protects personal data of users ("Data Principals") of the EduBlast platform in accordance with the Digital Personal Data Protection Act 2023 (DPDP Act), the Information Technology Act 2000, and associated rules and regulations.
This Policy applies to all users of the EduBlast platform — students, teachers, parents, and guardians — regardless of whether they use the Platform on a paid or free basis.
2. Data fiduciary and contact details
3. Personal data we collect
| Category | Data collected | Collection method |
|---|---|---|
| Identity | Full name, date of birth, gender, profile photo | Registration form, profile settings |
| Contact | Email address, mobile number (+91 country code) | Registration, OTP verification |
| Location | State, city/town (user-selected), IP-based region | Registration, device |
| Academic | Class/board, stream, target exam, school/college name, uploaded marksheets | Profile completion, uploads |
| Activity | DailyDose scores, mock test results, questions asked/answered, RDM earned, streaks, time spent | Platform usage |
| Payment | Subscription tier, payment method type, transaction IDs (no card/UPI details stored) | Razorpay gateway (tokenised) |
| Device & technical | Device type, OS, browser, IP address, session tokens | Automatic collection |
| UGC content | Questions, answers, comments, Instacues, uploaded files | User submission |
| Edufundz | Income certificate, family income declaration, bank details (for disbursement only) | Grant application (explicit consent) |
| Google Calendar (teachers) | Calendar account email, event IDs, class schedules, event titles, descriptions, attendee email addresses, and Google Meet links | Teacher-authorised Google Calendar connection |
EduBlast collects only the minimum personal data necessary for each specific purpose. Where data can be anonymised or pseudonymised for a purpose (such as AI model training or analytics), we do so by default. You may choose not to provide optional data fields — your ability to use core platform features will not be affected, though certain features like Edufundz applications require complete information.
4. Google Calendar data for teachers
Teachers may choose to connect their Google Calendar account to EduBlast to schedule and manage live classes. We access Google Calendar data only after the teacher authorises the connection and only to provide the teacher-facing Calendar and Google Meet features.
How we use Google Calendar data
- Create, update, and delete Google Calendar events for live classes scheduled by the teacher in EduBlast.
- Add enrolled students as event attendees and include a Google Meet link when the teacher schedules a class.
- Maintain the minimum connection and event identifiers needed to manage teacher-created class schedules.
Google API Services User Data Policy — Limited Use
EduBlast uses Google Calendar data solely to provide and improve the user-facing Calendar and live-class scheduling features requested by the connected teacher. We do not sell, rent, use for advertising, use for behavioural profiling, or transfer Google Calendar data to third parties for their own purposes. We do not use Google Calendar data to develop, train, or improve general-purpose artificial intelligence or machine-learning models.
Google Calendar data is not shared with analytics providers. Access by EduBlast personnel is limited to what is necessary to operate, secure, support, or comply with applicable law in relation to the Calendar feature.
Disconnecting Google Calendar
A teacher may disconnect Google Calendar at any time from the Teacher Portal or through their Google Account security settings. When a teacher disconnects in EduBlast, we revoke the connection and delete the stored Google Calendar refresh token. Disconnecting does not automatically delete events already created in the teacher's Google Calendar.
5. Purpose and legal basis for processing
| Purpose | Data used | Legal basis (DPDP Act) |
|---|---|---|
| Account creation and authentication | Name, email, mobile, DOB | Consent (registration) |
| Delivering educational services (classes, mocks, Gyan++) | Identity, academic, activity | Contract performance |
| RDM calculation and Edufundz eligibility tracking | Activity data, verified documents | Consent + legitimate interest |
| Payment processing | Subscription data, transaction IDs | Contract performance |
| Edufundz grant application and disbursement | Income documents, bank details | Explicit consent (separate notice) |
| Platform safety — detecting fraud, abuse, prohibited content | Activity, UGC, device data | Legitimate interest / legal obligation |
| AI model improvement (non-Google data only) | Anonymised interaction data, excluding Google API data | Consent (opt-in preference) |
| Marketing communications | Email, notification preferences | Consent (opt-in, withdrawable) |
| Legal compliance and law enforcement requests | As required by order | Legal obligation |
| Parent/guardian access to student activity | Student activity data | Consent of parent/guardian at registration |
6. Data retention
- Active account data: Retained for the duration of the account plus 3 years from the date of last activity, to enable account reactivation and address any legal claims.
- Edufundz financial documents (income certificates, bank details): Retained for 7 years from the date of the grant application in accordance with financial record-keeping requirements under the Income Tax Act.
- Transaction records (subscription payments, RDM logs): Retained for 7 years from the date of transaction.
- UGC (questions, answers, comments): Retained as long as it forms part of the community knowledge base. Upon account deletion, UGC is anonymised (user identity removed) unless the content is illegal, in which case it is deleted.
- Device and technical logs: Retained for 180 days for security purposes, then deleted.
- After account deletion: All remaining personal data is deleted within 30 days of the account deletion request, subject to the above retention obligations.
7. Data sharing and third parties
EduBlast does not sell personal data to any third party. We do not permit third parties to use your personal data for their own marketing purposes.
| Recipient | Data shared | Purpose | Safeguards |
|---|---|---|---|
| Razorpay | Payment session data (tokenised) | Payment processing | PCI DSS, data processing agreement |
| AWS / Cloud hosting | All platform data | Data storage and computing | Encryption at rest and transit, DPA |
| Partner NGOs (Edufundz) | Verified portfolio (with explicit consent) | Grant evaluation | Explicit consent required before sharing |
| Analytics providers | Anonymised, aggregated usage data excluding Google API data | Platform improvement | Anonymisation before sharing |
| Law enforcement | As required by valid legal order | Legal compliance | Verification of legal authority; notification to user where permissible |
EduBlast stores all primary data on servers located within India. Where third-party service providers (such as analytics or AI tools) process data outside India, we ensure that such transfers comply with applicable Indian law and that equivalent data protection standards are contractually imposed on the recipient. We will update this policy and seek additional consent if cross-border transfer requirements change under the DPDP Act upon relevant rules being notified.
8. Your rights under the DPDP Act 2023
Under the Digital Personal Data Protection Act 2023, you have the following rights as a Data Principal. These rights can be exercised by contacting dpo@edublast.in. We will respond within 72 hours of receiving a request and act upon it within the timeframes prescribed under the Act.
To exercise any right, contact: dpo@edublast.in with subject line "DPDP Rights Request — [Right Type]" and include your registered email address for identity verification.
9. Consent management
- EduBlast obtains consent through a clear, plain-language consent notice at registration. Consent is obtained separately for each distinct purpose where required under the DPDP Act.
- Consent for sensitive purposes (Edufundz financial documents, AI model training, marketing communications) is obtained through an explicit opt-in mechanism with a separate notice.
- Consent is not bundled — agreeing to these Terms does not constitute blanket consent for all data processing. Each consent notice specifies the exact data to be collected, the purpose, and the right to withdraw.
- You may manage your consent preferences at any time from Account Settings > Privacy & Consent.
- Withdrawal of consent takes effect within 48 hours of submission and is prospective only.
10. Data security
- All data transmitted to and from the Platform is encrypted using TLS 1.2 or higher (in-transit encryption).
- All personal data stored on EduBlast servers is encrypted at rest using AES-256 standard.
- Access to personal data is restricted to EduBlast employees and contractors who require it to perform their duties, and is subject to confidentiality obligations.
- EduBlast conducts periodic security audits and vulnerability assessments in accordance with the Reasonable Security Practices Rules under the IT Act 2000.
- In the event of a data breach involving personal data, EduBlast will notify affected users and the relevant regulatory authority within the timeframes prescribed under applicable law.
- Passwords are stored as salted hashes and are never stored in plaintext. Payment data is tokenised by Razorpay and not stored on EduBlast servers.
11. Minors and child data protection
The DPDP Act 2023 imposes heightened obligations for processing data of children (persons under 18 years). EduBlast treats all registered users who indicate they are under 18, or who are otherwise identified as minors, with these enhanced protections.
- Verifiable parental consent: Before processing data of a user who is a minor, EduBlast will obtain verifiable consent from the parent or guardian through a separate consent flow at registration. The parent/guardian must confirm their identity via OTP or email verification.
- No tracking or behavioural advertising: EduBlast does not engage in tracking, profiling for advertising, or targeted marketing in relation to minor users.
- No social media-style engagement loops for minors: While EduBlast operates a social learning feed, features that could be considered detrimental to the well-being of minors (e.g. aggressive streak penalties, exposure to adult content) are disabled for accounts identified as minors.
- Parental access: Parents and guardians who register under the parent account type may access their linked child's activity dashboard at any time. This includes activity logs, quiz scores, and time-on-platform data.
- Strict age enforcement: Accounts found to belong to users under 13 will be deleted within 24 hours of discovery without prior notice.
- School-facing obligations: Where EduBlast serves students through institutional licences held by schools or coaching institutes, the institution acts as a co-fiduciary and bears responsibility for ensuring parental consent is obtained before student enrolment.
12. Cookies and tracking technologies
- Essential cookies: Required for basic platform functionality (authentication sessions, security tokens, language preferences). These cannot be disabled without preventing platform use.
- Analytics cookies: Used to understand aggregate usage patterns and improve the platform. These are anonymised before processing. You may opt out from Account Settings > Privacy.
- No third-party advertising cookies: EduBlast does not use cookies or tracking pixels for third-party advertising purposes. The platform is ad-free and we do not share data with advertising networks.
- EduBlast uses browser localStorage for storing non-personal session preferences (such as dark mode preference and language setting).
- You may clear all non-essential cookies at any time through your browser settings. This will not affect your account data.
13. Grievance officer and escalation
In accordance with the DPDP Act 2023 and the IT (Intermediary Guidelines) Rules 2021, EduBlast has appointed a Grievance Officer to address privacy complaints and data-related requests. All complaints must first be directed to the Grievance Officer. If your complaint is not resolved within 30 days, you may escalate to the Data Protection Board of India once constituted under the DPDP Act.
Escalation path
- Step 1: Submit complaint to grievance@edublast.in. EduBlast acknowledges within 72 hours and resolves within 30 days.
- Step 2: If unresolved, escalate to the Data Protection Board of India (upon notification of constitution under Section 18 of the DPDP Act 2023).
- Step 3: Appellate Tribunal under the DPDP Act for appeals against Board orders, or civil courts of competent jurisdiction in Bengaluru, Karnataka.
This Privacy Policy was last reviewed and approved on 10 August 2026. EduBlast will review and update this Policy at least annually, or sooner if required by changes in applicable law, regulatory guidance, or significant changes to data processing activities. Material changes will be notified to registered users by email at least 14 days before taking effect.