Data Processing Agreement
Version 1.1, effective 7 October 2026.
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between DeinX Technologies ("we", "us", the "Processor"), which provides the Dein School service, and the school that uses the Service (the "School"). It applies whenever Dein School processes personal data on the School's behalf.
1. Roles
- The School decides why and how personal data about its students, parents, staff and visitors is processed. It is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the "DPDP Act").
- Dein School processes that data only to provide the Service to the School. It is the School's Data Processor.
- Words used in this DPA have the meanings given in the DPDP Act and its rules.
2. Scope of processing
| Purpose | Providing, securing and supporting the Service |
| Data principals | Students, parents and guardians, staff, administrators and visitors of the School |
| Personal data | As described in section 2 of the Privacy Policy, limited to what the School chooses to record |
| Sensitive data the School may choose to record | Religion, caste and category, disability, blood group, family income. The Service does not hold identity card numbers or copies of identity cards |
| Children's data | Yes. Most students are under 18 |
| Duration | For the term of the School's use of the Service, then until deletion under section 9 |
3. The School's instructions
Dein School processes School Data only on the School's documented instructions. The Terms of Service, this DPA and the School's use and configuration of the Service are the School's complete instructions. If Dein School believes an instruction breaks the law, it will tell the School and need not follow it.
4. The School's obligations
The School is responsible for:
- having a lawful basis for all personal data it records, and giving data principals the notices the DPDP Act requires;
- obtaining verifiable consent from a parent or lawful guardian before processing a child's data, where the law requires it and no exemption applies;
- responding to requests from its data principals to access, correct or erase their data;
- deciding which staff may see which data, and removing access when someone leaves;
- keeping the data it records accurate and complete.
5. Dein School's obligations
Dein School will:
- process School Data only for the purpose in section 2, and never sell it or use it for advertising;
- never use children's data for tracking, behavioural monitoring or targeted advertising;
- ensure that its personnel with access to School Data are bound by confidentiality;
- apply the security safeguards described in section 7;
- help the School respond to data principal requests, using the tools in the Service where possible;
- give the School the information reasonably needed to show compliance with this DPA.
6. Sub-processors
The School authorises Dein School to use sub-processors for hosting, database and file storage, SMS, push notifications, app updates, WhatsApp messages, maps and product analytics. The current list is in section 6 of the Privacy Policy, and Dein School will give the School any further detail on request at info@deinxtechnologies.com. If a school user connects an AI assistant through AI Connect, the AI provider is chosen by that user and is not a sub-processor of Dein School. Dein School will bind each sub-processor to data protection terms no less protective than this DPA, and remains responsible for their performance.
Dein School will notify Schools at least 30 days before adding a sub-processor that processes School Data. A School that objects on reasonable data protection grounds may terminate the affected Service without penalty.
7. Security
Dein School maintains reasonable security safeguards to protect School Data against personal data breach, including:
- encryption of data in transit and at rest;
- database rules that keep each school's data separate from every other school's, checked by an automated test suite;
- sign in by one time password, with rate limits and lockouts;
- access for staff that is off by default and granted per feature by the School;
- private file storage, served through links that expire;
- audit records of changes to attendance, marks, staff records and access.
More detail is on the Security page.
8. Personal data breaches
If Dein School becomes aware of a personal data breach affecting School Data, it will:
- notify the School without undue delay, and within 24 hours;
- give the School the facts known at the time: the nature and extent of the breach, the data and people likely affected, the likely consequences, and what has been done to contain it;
- update the School as more facts become known, and help it meet its own duty to inform the Data Protection Board of India and affected data principals;
- report the incident to CERT-In where the law requires.
9. Deletion and return of data
- While the Service is active, the School can delete records through the Service.
- When the School's account closes, the School may ask for an export of its data within 30 days. Account data is kept for the subscription plus those 30 days.
- After that period, Dein School permanently deletes School Data from its live systems. Backups expire within 30 days and are not restored except to recover the Service.
- Dein School may keep data only where the law requires it, and will protect it under this DPA for as long as it is kept.
10. Cross-border transfer
Some sub-processors process data outside India. Dein School transfers School Data only to countries the Government of India has not restricted under section 16 of the DPDP Act.
11. Audits
On reasonable written notice, and not more than once a year unless a breach has occurred, Dein School will answer the School's written questions about its compliance with this DPA and share relevant summaries of its security practices.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Terms of Service. If this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.
13. Contact
Questions about this DPA: info@deinxtechnologies.com. Grievance Officer: Saravanan Krishnasamy, info@deinxtechnologies.com.