1. Introduction
Codeat Education is a multi-school education platform used for campus administration, teaching operations, and student self-service. By accessing the website, staff portal, student portal, or Android app, you agree to the practices described in this Privacy Policy.
If you do not agree with this policy, please do not use the Service. For school accounts, the school administrator remains responsible for obtaining any local consents required from parents/guardians of minor students.
2. Who we are
Product: Codeat Education (School ERP / Education Portal)
Operator: Codeat Infotech
Managed by: Codeat Infotech
Region focus: Schools in India (including Gujarat board workflows)
Schools that subscribe to the platform act as controllers of their own student and staff records. Codeat Infotech processes that data to provide the Service on behalf of each school.
3. Who this policy covers
- School administrators & clerks — school operations, scholarships, accounts, certificates, ID cards, admissions.
- Teachers / staff — attendance, class lists, results entry, timetable, activities, staff chat.
- Students (and parents/guardians using student login) — profile view, documents, exam seats, holidays, limited self-service.
- CA / auditor users — financial year audit access where enabled by the school.
- Visitors — public pages such as login, landing, ID-card scan links, and this privacy policy.
4. Data we collect
Depending on your role and school configuration, we may process:
4.1 Account & authentication
- Name, email address, role (admin, clerk, teacher, student, CA)
- School code / UDISE linkage
- Password (stored as a secure hash — never in plain text)
- Login sessions, device/session identifiers, IP address, login time
- Email verification / OTP codes for account setup
4.2 Student academic & personal records
- Name, gender, date of birth, class, section, roll / GR numbers
- Contact mobile, address, parent/guardian names
- Government identifiers where the school enters them for scholarships or registers (for example Aadhaar / APAAR / child UID) — processed only as required by that school’s workflows
- Bank details for scholarship disbursement (if entered by school)
- Photos / signatures used for ID cards and certificates
- Attendance, exam marks, report cards, seat numbers, activities
4.3 Staff / HR records
- Employee profile, designation, contact details
- Attendance and payroll-related figures entered by the school
- Optional income-tax / salary statement data when that module is used
4.4 School operations data
- Classes, subjects, timetable, holidays, results configuration
- Accounting vouchers, financial years, audit notes (if enabled)
- Certificates, letterheads, ID-card share links
- Help-desk / support messages and staff chat messages
4.5 Technical & diagnostics
- App version, device type/OS (mobile), browser type (web)
- Crash / error logs needed to keep the Service reliable
- Approximate network metadata (IP) for security and abuse prevention
We do not sell personal data. Schools decide which modules are enabled and what records they enter.
5. Staff panel (admin, clerk, teacher)
The staff-facing product helps schools run day-to-day campus work. Typical processing includes:
- Managing student and staff directories
- Marking / reviewing attendance and results
- Generating certificates, ID cards, and board-related reports
- Scholarship import / submission tools configured by the school
- Accounting books and CA audit collaboration (when licensed)
- Internal staff messaging and help conversations
Staff accounts must use credentials issued or approved by the school. Staff should not share passwords and should log out on shared devices.
6. Student panel
The student portal is a limited self-service area. Students typically can view information the school has already recorded, such as:
- Basic profile and class information
- Documents / notices the school makes available
- Exam seat numbers, holidays, and selected academic views
Student accounts may start with a temporary password and email OTP verification. Students (or guardians) should change temporary passwords promptly and keep login details private.
7. Mobile app & Android permissions
Our Android application provides access to the same staff and student experiences available on the web, optimized for phones. Depending on features you use, the app may request:
Internet
Required to sign in and sync school data securely.
Camera / photos
Optional — for profile/ID photos or document capture when a school feature needs an image.
Notifications
Optional — for login alerts, notices, or operational reminders if enabled.
Storage
Optional — to save/share downloaded PDFs such as certificates or reports.
The app does not require continuous background location tracking for core school workflows. Permission prompts appear only when a feature needs that access.
8. How we use data
- Provide and operate school ERP features for authorised users
- Authenticate users and protect accounts against misuse
- Generate academic, administrative, and financial documents
- Support multi-school tenancy so one school cannot see another’s data
- Send transactional emails / OTPs related to account security
- Diagnose outages, improve reliability, and provide customer support
- Comply with applicable law and respond to lawful requests
10. Security
- Role-based access control (admin, clerk, teacher, student, CA)
- Password hashing and session-based authentication
- School-code scoped login for school users
- HTTPS transport for web and API traffic
- Operational monitoring and access logging for sensitive admin actions
No method of transmission or storage is 100% secure. Schools and users must also follow good practices (strong passwords, limited shared-device use, timely revocation of staff who leave).
11. Retention & deletion
We retain school data for as long as the school’s subscription / account remains active and as needed to provide the Service. Schools may update or remove student/staff records from within the portal according to their own policies.
After a school requests account closure, or when data is no longer needed for the Service or legal obligations, we delete or anonymise personal data within a reasonable period, subject to backup cycles and mandatory retention rules.
To request deletion of a personal account or school dataset, contact your school administrator first. Platform-level requests can be sent via the contact channel in section 15.
12. Children’s privacy
Codeat Education is used by schools that may enrol children under 18. Student accounts and records are created and supervised by the school. We do not knowingly allow children to create independent consumer accounts outside school provisioning.
Parents or guardians who want to review or correct a child’s information should contact the school administration. The school can update records in the staff panel or escalate to platform support when needed.
13. Your rights
Subject to applicable law and school policies, you may request to:
- Access personal data held about you in the Service
- Correct inaccurate profile or contact information
- Delete or restrict certain personal data where feasible
- Withdraw optional consents (for example notification permissions)
Staff and students should normally raise requests with their school admin. Super-admin / platform requests can use the contact details below.
14. Changes to this policy
We may update this Privacy Policy to reflect product, legal, or security changes. The “Last updated” date at the top will change when we do. For material updates, we may also notify schools through the portal or email. Continued use of the Service after an update means you accept the revised policy.
15. Contact
For privacy questions, data requests, or Play Store / app support related to Codeat Education:
Codeat Infotech · Codeat Education
Email support.codeateducation@gmail.com · Phone +91 8735995467. Or use the contact page for the full office address and map.
This page is provided for transparency and Google Play Data safety / privacy disclosure. It is not legal advice. Schools remain responsible for complying with local education and data-protection obligations for the records they upload.