Skip to content

ScolaOS Privacy Policy.

Effective Date: 19 July 2026 Last Updated: 19 July 2026 Version: 0.1

1. Introduction

Welcome to ScolaOS, a cloud-based, multi-tenant School Management Platform developed and operated by Terra System Labs Pvt. Ltd. ("Terra System Labs", "ScolaOS", "we", "our", or "us").

This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use the ScolaOS website, web application, mobile applications, and related services (collectively, the "Services"). It applies to students, parents and guardians, staff and employees, institution administrators, and visitors to our website.

By accessing or using the Services, you agree to the practices described in this Policy. If you do not agree, please do not use the Services.

2. About Us

ScolaOS is a product of Terra System Labs Pvt. Ltd., which develops secure cloud software for educational institutions worldwide. Our registered office is at Terra System Labs Pvt Ltd, BHIVE Premium, No.467/468, Krishna Temple Road, Indiranagar, Bengaluru, India - 560038.

3. Our Two Roles: Processor and Controller

ScolaOS is a multi-tenant, multi-branch platform. Each educational institution (a "tenant") operates in a logically isolated environment, with access further scoped by branch and role, so that one institution's data is segregated from every other institution's.

  • Institution Data (we are the Data Processor). For personal data an institution uploads to or generates through the Services - student, parent, staff, and operational records - the institution is the Data Fiduciary / Controller and Terra System Labs acts as a Data Processor on the institution's documented instructions. We process this data only to provide and support the Services, and never for our own purposes, profiling, or advertising.
  • Website and business data (we are the Data Controller). For information collected through our marketing website and for our own account, billing, security, and business operations, Terra System Labs is the Data Fiduciary / Controller.

The allocation of responsibilities between the institution and Terra System Labs is set out in the DPA.

4. Information We Collect

A. Information you provide (account & billing). Name; email; phone/mobile; organization or institution name; job title or role; profile photo/avatar; billing and subscription details; support requests; feedback and survey responses.

B. Student and educational data (Institution Data). Across the platform's modules, an institution may store: student names and profiles; admission and enrolment details; class and section assignments; attendance; academic and examination records; homework and assignment submissions; timetables and calendar entries; fee, invoice, and payment records; parent/guardian information and emergency contacts; transport enrolment and route details; hostel allocation records; canteen and meal/purchase records; library membership and borrowing records; discipline and incident records; online-learning activity, course progress, and uploaded/transcoded video content; ID card data and photographs; notes and dynamic form submissions; and notices and communications.

C. Staff and employee data (Institution Data). Staff profiles and contacts; HR records; payroll and salary information, including salary structures and earnings/deduction components; staff attendance; and roles, permissions, and access assignments.

D. Automatically collected information. IP address; browser type; device information; operating system; login and session timestamps; session and authentication identifiers; usage statistics; audit logs of security-relevant actions; error logs and performance metrics; cookies and similar technologies.

E. Uploaded files. Files uploaded to the platform (documents, images, ID photos, learning materials, etc.) are automatically scanned for malware before being made available. Files identified as malicious are quarantined or rejected.

We do not knowingly collect more personal data than is necessary for the purposes described in this Policy.

5. How We Use Information

We use information to: provide, operate, maintain, and secure the Services; authenticate users and manage sessions; enforce tenant isolation and branch- and role-based access controls; process transactions and payments; improve performance and reliability; provide customer support; send service notifications; detect, prevent, and investigate fraud, abuse, and security incidents; comply with legal obligations; and develop new features.

For Institution Data, we act only on the institution's documented instructions. We do not sell personal information, and we do not use Institution Data for our own purposes, for profiling, or for advertising.

6. Legal Basis for Processing

Where required, we process personal information on the basis of: consent (including, for children, verifiable parental or lawful-guardian consent); contractual necessity; legitimate uses permitted by law; and compliance with legal obligations. For Institution Data, the institution is responsible for establishing and maintaining a valid legal basis and for obtaining all required consents (see Section 12).

7. AI Features and Processing

Some parts of the Services may use artificial intelligence or automated processing (for example, to assist with content generation, summaries, or analytics). Where such features are offered:

  • Human review. AI-generated outputs are provided as assistance only and may contain errors. They should be reviewed by a person before being relied upon or acted on.
  • No model training on your data. Institution Data is not used to train publicly available or third-party AI models, and is not shared with AI providers for their own model-training purposes, unless the institution explicitly agrees in writing.
  • Same protections. Any AI processing of Institution Data is carried out on the institution's documented instructions and is subject to the same confidentiality and security obligations as the rest of the Services.

We identify in our documentation which features involve AI processing and any third-party AI providers engaged as sub-processors.

8. Product-Specific Privacy Features

Certain platform features have specific privacy characteristics:

  • QR code verification. QR codes may encode identifiers used to verify ID cards, certificates, or attendance. They are validated within the institution's tenant and do not expose personal data publicly beyond what the institution configures.
  • Digital certificates. Certificates may contain student names, achievements, and issuing details. Institutions control their content, issuance, and distribution.
  • Location-based attendance. Where enabled by the institution, attendance may process device location at the moment of marking. Location is used only for that attendance purpose and is not tracked continuously.
  • Video learning and recordings. Online-learning videos and, where enabled, session recordings may capture participants' images, voices, and activity. The institution is responsible for notifying participants and obtaining any required consent before recording.
  • Push notifications. Notifications are delivered based on your role and the institution's settings. You can manage them in your device settings.
  • File uploads. Uploaded files are scanned for malware and stored within the institution's tenant.
  • Biometric or facial recognition. ScolaOS does not currently process biometric or facial-recognition data. If such features are introduced in the future, they will be offered only with appropriate notices, a lawful basis, and any consent required by applicable law, and this Policy will be updated accordingly.

9. Mobile Application Permissions

The ScolaOS mobile applications may request the following device permissions, which you can grant or deny in your device settings. Some features will not work if a permission is denied. We request only the permissions needed for the features you use:

  • Camera - to capture photos, scan QR codes, and upload documents or profile images.
  • Location - to support location-based features such as attendance or transport tracking, where enabled by the institution.
  • Notifications - to deliver announcements, reminders, and alerts.
  • Storage / Files - to upload and download documents and media.
  • Microphone - to support audio in video or voice features, where offered.

Institutions may enable or disable certain features, so the availability of permission-dependent features depends on the institution's configuration.

10. Cookies and Similar Technologies

We use cookies and similar technologies to maintain secure login sessions and tenant/branch context, remember preferences, improve performance, analyze traffic, and enhance the user experience. Cookies are grouped as strictly necessary, functional, performance/analytics, and (where used) preference cookies. Where required by law, non-essential cookies are set only after you consent through our cookie banner or preference center, and you may change your choices at any time. You may also disable cookies in your browser, but some features may not function properly.

11. Marketing and Website Analytics

On our marketing website, we may use analytics tools that might collect information such as pages visited, referring source, approximate location, and device/browser details, to understand and improve our website. You can manage cookie preferences through the cookie banner or preference center (Section 10), and you can opt out of marketing emails at any time using the unsubscribe link. These analytics apply to our own website and are separate from Institution Data processed within the platform.

12. Children's Privacy

The Services are designed for educational institutions, and much of the Institution Data relates to children (in India, individuals under 18 years of age). We treat this data with particular care:

  • The institution is responsible for collecting and managing student information, establishing a valid legal basis, and obtaining any legally required parental or lawful-guardian consent before collecting or uploading children's personal information to ScolaOS. The institution warrants this in the DPA and is responsible for verifying parental/guardian identity and authority.
  • Terra System Labs does not use children's personal data for tracking, behavioral monitoring, profiling, or targeted advertising, and does not undertake processing likely to cause a detrimental effect on a child.
  • We do not knowingly collect personal data directly from children without authorization from the relevant institution. If we learn we have inadvertently done so without a lawful basis, we will delete it.

13. Data Security

We implement, and require our sub-processors to implement, reasonable technical and organizational measures appropriate to the risk, including (as applicable to the relevant environment and as further described in our security documentation):

  • Multi-tenant data isolation, with every record scoped to its owning institution
  • Branch- and role-based access control (RBAC) and least-privilege access
  • Encryption in transit (TLS), and encryption at rest where applicable
  • Token-based authentication and secure session management
  • Multi-factor authentication (MFA) where available and enabled
  • Password complexity and account-lockout policies
  • Malware scanning of uploaded files
  • Input validation and output encoding to guard against injection and related attacks
  • Audit logging of security-relevant actions
  • Vulnerability management and periodic security testing, including penetration testing
  • A secure software development lifecycle (Secure SDLC) with code review
  • Encryption key management
  • Infrastructure monitoring and logging
  • Backup and disaster-recovery procedures

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Institutions and users are responsible for safeguarding their credentials and for configuring roles and permissions appropriately.

14. Compliance and Certifications

Where applicable, Terra System Labs maintains ISO/IEC 9001:2015, ISO/IEC 27001:2022 and undergoes periodic penetration testing/assessment. Summaries or reports may be made available to customers under confidentiality on request. We do not represent that we hold any certification we have not actually obtained.

15. Data Sharing and Sub-Processors

We do not sell or rent personal information. We share information only with the categories of recipients needed to operate the Services:

  • Cloud hosting and infrastructure providers
  • Payment gateway providers
  • Email and SMS delivery providers
  • Video conferencing and media/transcoding providers
  • Analytics providers
  • Customer support tools
  • Government or regulatory authorities where required by law (see Section 16)

All such recipients (sub-processors) are engaged under written agreements requiring them to protect personal data and to process it only as needed to provide their services. A current list of our sub-processors - including each sub-processor's name, the service it provides, and its processing location - is published at [insert URL] and available on request. We update this list when sub-processors change, as described in the DPA.

16. Legal Requests and Disclosures

We may disclose personal information where we believe in good faith that disclosure is required by applicable law, regulation, legal process, court order, or an enforceable governmental or lawful request; is necessary to protect the rights, safety, or property of Terra System Labs, our customers, or the public; or is needed to establish, exercise, or defend legal claims. We assess such requests for validity and disclose only what is legally required. Where permitted by law, we will inform the affected institution (as Data Fiduciary/Controller) of a request relating to Institution Data.

17. Business Transfers

If Terra System Labs is involved in a merger, acquisition, financing, reorganization, insolvency, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will require the recipient to continue protecting personal information in a manner consistent with this Policy and applicable law, and we will notify affected customers where required.

18. Data Breach Notification

If we become aware of a personal data breach affecting Institution Data, we will notify the affected institution (as Data Fiduciary/Controller) without undue delay and provide the information reasonably available to help it meet its own notification obligations to the Data Protection Board of India and to affected data principals. Where Terra System Labs is the Data Fiduciary/Controller (e.g., for the marketing website and our own operations), we will notify the relevant authority and affected individuals as required by law. Timelines and procedures are detailed in the DPA.

19. Data Residency, Hosting, and International Transfers

Institution Data is hosted in cloud. Where offered, institutions may select a preferred hosting region during onboarding; the available regions are described in our documentation or order form. Your information may be processed or stored in countries other than your own. Where personal data is transferred across borders, we apply the safeguards required by applicable law, which may include contractual protections such as standard contractual clauses and processing only in jurisdictions permitted under applicable law. Hosting and transfer details are set out in the DPA.

20. Data Retention

We retain personal information only for as long as necessary to provide the Services, meet contractual obligations, resolve disputes, enforce our agreements, and comply with legal requirements. Institution Data is retained for the duration of the institution's subscription and is returned and/or deleted on termination as set out in Section 21 and the DPA, except where retention is required by law. Certain records (e.g., audit logs and backups) may be retained for a limited additional period for security, legal, and integrity purposes. Specific retention periods or criteria are set out in [insert schedule / DPA Annex].

21. Account Closure and Data Deletion

When a subscription ends or an institution closes its account, the institution may request the return and/or deletion of its Institution Data. Unless a longer period is required by law or agreed in the DPA, we will delete or irreversibly anonymize Institution Data within 180 days of termination. Residual copies in routine backups are deleted on our backup-retention cycle and remain protected by this Policy and the DPA until deleted. Audit logs and records we are legally required to keep may be retained for the period required by law. Individual users who wish to have their personal data deleted while their institution continues to use the Services should follow the process in Section 22.

22. Your Rights

Subject to applicable law, you may have the right to: access your personal information; correct inaccurate information; request deletion; restrict or object to certain processing; withdraw consent (where processing is based on consent); request data portability; nominate another individual to exercise your rights in the event of death or incapacity; and lodge a complaint with the Data Protection Board of India (or your local supervisory authority).

Because most personal data in ScolaOS is controlled by the institution, requests concerning Institution Data should be directed to your institution, which we will support as its Data Processor. For information for which Terra System Labs is the Controller, contact our Grievance/Data Protection Officer (Section 26). We will respond within the time required by applicable law.

Some rights are not absolute. Where the institution is required by law to retain certain records (for example, academic, examination, fee, tax, or employment records), or has a legal basis other than consent to continue processing while an individual remains enrolled or employed, a deletion request may be declined or limited to the data that is no longer required. In that case, the institution will explain what is being retained, the reason, and for how long. Choosing which software the institution uses is the institution's decision as Data Fiduciary/Controller; an individual's data rights are exercised over their personal data, not over the institution's choice of service provider.

23. Automated Decision-Making and Profiling

The Services provide reporting and analytics features (for example, attendance summaries, fee status, and academic reports) that assist institutions in their decisions. Terra System Labs does not use these features to make decisions producing legal or similarly significant effects about an individual without human involvement, and does not use Institution Data to profile individuals for its own purposes. Where an institution configures the Services to support its own decisions, the institution remains responsible, as Data Fiduciary/Controller, for the lawfulness of those decisions and for any human review required by applicable law.

24. Third-Party Services

ScolaOS may integrate with third-party services such as payment gateways, email and SMS providers, video conferencing/transcoding platforms, cloud storage providers, and authentication providers. Use of those services is governed by their respective privacy policies. We are not responsible for the privacy practices of third parties.

25. Language and Accessibility

This Policy is published in English. Where required by applicable law, it is also made available in other languages (including the languages specified under Indian law) so that data principals can understand it, and it is available in an accessible format on request. If there is any conflict between translations, the version prevails, except where applicable law requires otherwise. To request an accessible format, contact us at the details in Section 26.

26. Contact Us / Grievance Officer

Terra System Labs Pvt. Ltd. - Product: ScolaOS

27. Changes to This Policy

We may update this Policy periodically. Material changes will be communicated through our website or the Services and, where required, we will seek fresh consent. The updated version becomes effective on the date published, and the version number and change log below will be updated.

28. Data Controller & Processor Summary

  • Educational Institution - Data Fiduciary / Controller for Institution Data.
  • Terra System Labs Pvt. Ltd. - Data Processor for Institution Data processed on the institution's behalf, and Data Fiduciary / Controller for marketing-website and business-operations data.

The parties' respective obligations are set out in the ScolaOS Data Processing Agreement, and commercial and liability terms in the ScolaOS Terms of Service.


Version History

Version Date Summary of changes
0.1 19 July 2026 Initial published version.

© 2026 Terra System Labs Pvt. Ltd. All rights reserved. ScolaOS is a registered product and trademark of Terra System Labs Pvt. Ltd.