Effective date: 24 July 2026 · Version 1.0 · TechnoLab TMS, operated by TechnoLab, Siliguri, West Bengal, India
This Privacy Policy explains what information TechnoLab TMS ("we", "us") collects, why, how it's stored and protected, and what rights you have over it — both as the institute using our Service, and as someone whose data an institute has entered into it (a student, guardian, or staff member). It should be read together with our Terms & Conditions and License Agreement.
1. Who This Policy Covers
Two categories of people interact with our Service, and this policy covers both:
Institute account holders — the coaching institute that signs up, and its staff who log in to use the Service.
Data subjects entered by an institute — students, guardians, and staff whose personal details an institute enters into the Service (e.g. admissions, attendance, fee records). We process this data on the institute's behalf and instructions; the institute itself is the primary controller of that data under applicable law.
2. What We Collect
Category
Examples
Collected from
Account & billing
Institute name, contact email, phone, location, logo, payment/transaction records
You, at signup and during use
Student & academic records
Name, date of birth, guardian details, mobile number, address, admission and course details, attendance, fees, exam marks, certificates
Entered by the institute
Staff records
Name, mobile, email, role, login credentials (password stored as a salted hash, never in plain text)
Entered by the institute
Usage data
Login timestamps, pages visited within the Service, device/browser type, IP address
Automatically, as you use the Service
Communications
Support tickets and their contents, WhatsApp messages you choose to send through the Service's WhatsApp links
You, when contacting support or using messaging features
3. How We Use This Data
To provide, operate, and maintain the Service (running the software, generating reports, sending the notifications you configure).
To process payments and manage your subscription or license.
To respond to support requests and communicate service-related updates.
To maintain security, detect and prevent fraud or abuse, and enforce our Terms.
To improve the Service, understand usage patterns, and fix bugs.
To comply with legal obligations, including tax, accounting, and regulatory requirements.
We do not sell personal data to third parties, and we do not use student or staff data entered by institutes for advertising purposes.
4. Where Data Is Stored and Who We Share It With
Hosting infrastructure: the Service runs on Cloudflare's global cloud infrastructure (Cloudflare Pages, Workers, and D1 database). Cloudflare acts as our infrastructure sub-processor.
Payments: payment processing is handled by Razorpay, a licensed payment aggregator. We do not store your full card or bank details ourselves — Razorpay handles this in compliance with RBI and PCI-DSS requirements.
WhatsApp: messages sent via WhatsApp deep-links open directly in the sender's own WhatsApp app/account — we do not route, store, or have access to the content of those messages ourselves.
We do not share Customer Data with any other third party except as required to operate the Service, comply with law, or as you separately direct.
5. Data Retention
We retain Customer Data for as long as your account remains active, plus a reasonable period afterward to allow for account recovery, legal, tax, and backup purposes. Upon account termination, you are responsible for exporting any data you wish to retain (via the Reports module) before closure; we may delete retained data after a reasonable retention window.
6. Security Measures
All traffic to and from the Service is encrypted in transit (HTTPS/TLS).
Passwords are never stored in plain text — they are salted and hashed (PBKDF2-SHA256).
Session cookies are httpOnly and marked Secure, reducing exposure to common web attacks.
Role-based access controls let institute admins restrict which staff can see which modules.
API responses are marked non-cacheable to prevent session data from being inadvertently cached or replayed.
No system can guarantee absolute security — see the Data Protection Risk Factors section of our Terms & Conditions for a fuller discussion of this.
7. Children's / Minors' Data
Given the nature of a coaching institute, the Service will typically hold data about minors (students). We do not collect this data directly from minors ourselves — it is entered by the institute, which is responsible for obtaining appropriate parental/guardian consent as required under applicable law, including India's Digital Personal Data Protection Act, 2023.
8. Your Rights
Depending on applicable law, you (or, for a student/staff data subject, the institute acting on their behalf) may have rights to access, correct, or request deletion of personal data held in the Service. Institute admins can directly edit or delete most records themselves within the Service. For anything not directly editable, contact us using the details below.
9. Cookies
We use only strictly necessary cookies (session authentication) to keep you logged in. We do not use third-party advertising or tracking cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the Service after an update constitutes acceptance of the revised policy. Material changes will be reflected in the effective date above.
11. Contact Us
For any privacy-related question or request, see our Contact Us page, or message us on WhatsApp at +91-9749446885.